Cookie declaration
Version 1.2 · As of 10 September 2026
This is a translation for convenience. In case of discrepancies, the German version shall prevail.
1. Which cookies we actually set
This platform sets strictly necessary cookies only: • Sign-in (`__session`): keeps you signed in; lifetime up to 90 days, extended with every use; HttpOnly, Secure, SameSite=Lax. • Forgery protection (`__Host-authjs.csrf-token`): protects forms; valid only for the duration of the browser session; HttpOnly, Secure. • Return target after sign-in (`__Secure-authjs.callback-url`): remembers where you are taken after signing in; duration of the browser session; HttpOnly, Secure. • Language (`NEXT_LOCALE`): stores your language choice (one of the nine languages); 12 months. • Cookie choice (`bggi-cookie-consent`): stores your decision in the cookie banner; 12 months. • Application (`bggi_app`): remembers which of our applications you are using (patient application, application for team members or administration application) so that sign-in leads to the right area; 12 months; HttpOnly. It is not set in an ordinary browser. • Phone shell (`bggi_huelle`): records that the page is running in our iPhone or Android app; only there is the membership concluded through the store; 12 months; HttpOnly. It is not set in an ordinary browser.
Legal basis: § 25(2) TDDDG (strictly necessary) and Art. 6(1)(b) and (f) GDPR.
2. What we do NOT use
No statistics, analytics or marketing cookies. No third-party tracking. No advertising. A single cookie depends on your consent: if you choose "Accept all" in the banner, `bggi_ref` remembers for 30 days the referral link of the agency through which you came to us; it contains only the referral code, no name and no identifier. Without your consent it is not set, and you can have it removed again via the cookie settings. Error diagnostics works without cookies and without session replays; personal content is removed before transmission.
3. Changing your choice
Via "Cookie settings" in the footer you can reopen the banner at any time. Choosing "Accept all" has exactly one additional effect: the cookie `bggi_ref` mentioned above for an agency's referral link. Should further optional cookies be added, this declaration will be updated BEFORE their introduction and your consent will be requested again.
4. What else we store on your device
In addition to cookies, the platform stores three small entries in your browser's local storage, all strictly necessary and without personal reference: the time of the last refresh of your sign-in, your "Auto crop" setting in the document scanner and the note that you dismissed the prompt to install the app. These entries do not leave your device. You can delete them at any time via your browser's settings.
Change history
- 2026-09-10 — Version 1.2 — cookie table corrected and completed: the sign-in cookie is called __session and is valid for up to 90 days (not twelve hours), cookies for the application (bggi_app) and the phone shell (bggi_huelle) added, referral-link cookie (bggi_ref, only with consent) named, browser local storage added.
- 2026-08-12 — Version 1.1 — processors specified, retention periods added, transfer to treating hospitals abroad, payment/cancellation/refund rules, new documents (withdrawal, telemedicine, health-data consent, cookies).
- 2026-08-08 — Version 1.0 — initial publication.

