Privacy Policy
Version 1.6 · As of: 12 September 2026
This is a translation for convenience. In case of discrepancies, the German version shall prevail.
1. Controller
The controller within the meaning of the GDPR is:
BGGI GmbH Rostocker Straße 43 53117 Bonn Germany
E-mail: datenschutz@bggi.de · Telephone: +49 228 50446780
Please address data protection enquiries to this postal address or this e-mail address. Data export and deletion requests are additionally available in the portal under “Privacy”.
2. Categories of Data Processed
Master data: name, e-mail address, phone number, date of birth, nationality, address.
Health data (Art. 9 GDPR): medical documents you upload as well as case, appointment and treatment information.
Usage data: IP address, login timestamps, log data (tamper-proof audit log).
Billing data: cost estimates, invoices, payments.
Communication and translation data: messages within a case, their source language and machine translations; original and translation are stored separately.
Speech and voice data: spoken segments in the AI interpreter, the text recognised from them, its translation and the voice generated from it (section 13).
Location data: during an ongoing assignment the assigned interpreter or driver can transmit their own location (section 14).
Credential documents: authorisation, permit and licence records of physicians, hospitals, pharmacies as well as delivery and courier services; passport, visa and identity documents of patients and accompanying persons.
Payment and bank data: bank details for payouts and refunds, announcements of bank transfers and incoming payments.
Order and delivery data: prescriptions, pharmacy orders, delivery address and delivery status.
Employee data: working-time data of administrative staff (section 12).
Device and session data: one entry per login with the designation of the device, the browser identifier, the application (app for patients, app for team members, administration app or ordinary browser), the truncated IP address, the time of login, the time of last use and any revocation (section 19).
Scan data: pages of documents captured with the camera, the PDF file generated from them, the text of the pages recognised on your device, the details read out from it (sender, recipient, date, invoice, customer and case reference numbers, amount and currency, bank details, e-mail address, phone number, address) and the machine classification (type, title, date, issuer, language) — section 20.
Subscription data: for a purchase via the Apple App Store or via Google Play, the transaction or purchase identifier, the product identifier, start and end of the paid period, the state of the subscription, the environment (production or test environment) and a pseudonymous account identifier — section 21. We do not receive payment data from the stores.
3. Purposes of Processing
Coordination of international medical treatments (case management, clinic and doctor matching, appointment scheduling).
Account management and authentication, including optional two-factor authentication.
Billing and fulfilment of statutory retention obligations.
Security, error analysis and abuse prevention.
4. Legal Bases
Performance of a contract — Art. 6(1)(b) GDPR.
Explicit consent to the processing of health data — Art. 9(2)(a) GDPR.
Legal obligation (e.g. commercial and tax retention duties) — Art. 6(1)(c) GDPR.
Legitimate interest in the security of the platform — Art. 6(1)(f) GDPR.
5. Recipients
Treating hospitals and physicians only receive access to your case data after your case has been assigned, and only to the extent of the documents released by BGGI.
We use the following processors under Art. 28 GDPR: • Google Cloud EMEA Ltd. (Ireland) — operation of the application, database and file storage, data centre Frankfurt am Main (europe-west3), incl. Firebase Hosting as delivery layer. • Stripe Payments Europe Ltd. (Ireland) — payment processing and payouts to physicians; card data remains exclusively with Stripe. • Resend (USA) — sending and receiving transactional and case e-mails via their SMTP access; the sender domain is our medical subdomain (EU standard contractual clauses). • Daily.co (USA) — video consultations; media servers in the EU region (eu-central-1), no recording (EU standard contractual clauses). • Anthropic (USA) — AI-assisted pre-analysis of submitted documents, classification of scanned documents (type, title, date, issuer, language) as well as machine translation of messages, texts and within the AI interpreter, in each case only after your separate consent; results are reviewed by BGGI staff (EU standard contractual clauses). • ElevenLabs (USA) — speech recognition and speech output for the AI interpreter and the read-aloud function (EU standard contractual clauses). • Sentry (Functional Software, Inc., USA) — technical error diagnostics; personal and medical content is automatically removed or masked before transmission (EU standard contractual clauses). • Lexoffice (Germany) — handover of invoice documents to our accounting; the name and country of the invoice recipient and the invoice data are transmitted, no health data.
Transfers to third countries outside the EU/EEA only take place where appropriate safeguards under Art. 44 et seq. GDPR exist (in particular EU standard contractual clauses) or where you have expressly consented (Art. 49(1)(a) GDPR).
Location resolution (only upon your explicit button press in the address form): Google Ireland Ltd. — converting your device coordinates into an address to fill the fields. The coordinates are transmitted via our servers, not stored, and not used for any other purpose.
We use the same conversion of coordinates and addresses to calculate distances for medical transports.
Further recipients outside processing on our behalf are — in each case only to the extent required and only after assignment to your case: the treating hospitals and physicians, partner pharmacies, delivery and courier services (delivery data only, no prescription contents, diagnoses or prices), interpreters, drivers, mediating agencies as well as — where you so wish — insurers and foreign missions for invitation and visa documents. These recipients process your data on their own responsibility.
Tax advice and legal advice: for bookkeeping and for legal review we engage external professionals bound by professional secrecy. The tax adviser receives a separate, read-only access to invoices, payouts, the cash book of the cases, the status of the handover to accounting and the bank accounts of BGGI in abbreviated form; of you, this access contains only the case number and the country — no names, no diagnoses and no medical documents. The legal adviser sees exclusively the legal texts of this platform and confirms them; they receive no personal data. The legal basis is our legal obligation (Art. 6(1)(c) GDPR) as well as our legitimate interest in proper advice (Art. 6(1)(f) GDPR); the persons engaged are subject to their own professional duty of confidentiality.
Apple and Google (taking out the membership in the phone apps): if you take out the membership in one of our phone apps, the purchase is made via the Apple App Store or via Google Play. These companies process the payment on their own responsibility; we do not receive payment data from them. The following is transmitted between us and the store: a pseudonymous account identifier — a non-reversible string calculated from your user ID —, the transaction or purchase identifier, the product identifier, start and end of the paid period, the state of the subscription and the environment. Your name, your e-mail address and your health data are not transmitted to the store.
Push notifications: if you have allowed push notifications, they are delivered via the push service of your browser or your operating system (Apple, Google, Mozilla or Microsoft). The delivery address of your device and the encrypted content of the message are transmitted. The operators of these services are independent controllers in this respect.
6. Retention Periods
Account data: until your account is deleted or an erasure request has been completed.
Invoice and accounting data: 10 years pursuant to § 147 AO (German GoBD rules).
Audit logs: stored immutably and tamper-proof.
Case data and medical documents: for the duration of case handling and thereafter per the statutory retention obligations for treatment records (generally 10 years, analogous to § 630f German Civil Code); then deletion or anonymisation.
Communication with hospitals (email/portal): same as case data — it forms part of the case file.
Consent records: up to 3 years after revocation or account deletion (accountability, Art. 7(1) GDPR).
Server and security logs: maximum 90 days, unless a security incident requires longer retention.
Daily encrypted database backups: 30 days (daily states) and 12 months (monthly states), stored exclusively in the Frankfurt region.
Working-time data of employees: until the period set by BGGI expires (default 400 days, section 12); deleted automatically thereafter.
Access log of the interface for partner systems: until the period set by BGGI expires (default 400 days); deleted automatically thereafter.
Location details of an assignment: they are only transmitted and displayed during an ongoing assignment. The last reported point remains stored with the assignment and is deleted together with the associated case.
Video consultations: access to the video room only exists within the time window of the appointment (from 15 minutes before the start until 30 minutes after the scheduled end) and expires afterwards. Sound and image are not recorded; the appointment details remain stored as part of the case record.
Subtitles of the AI interpreter: stored only with separate consent; a withdrawal deletes them immediately.
Machine text translations within a case, including any generated speech output: as part of the case record and deleted with it.
Pharmacy access to a prescription: 30 days from handover of the order; the prescription record itself remains part of the case record.
Visibility after cancellation of the membership: your data remains visible in the portal for the period set by BGGI (default two years). Nothing is deleted in the process; the retention periods above apply.
Read notifications in the portal: 180 days.
Login: a login remains valid for up to 90 days and is extended with each use; without use it ends after 90 days. After a logout — by you, by the administration, after a password change or after a change to the second factor — it is no longer valid at the latest five minutes later.
Device list: the entry of a login remains stored with your account and is deleted with the account; logged-out devices continue to be listed as revoked. The list shows the 50 most recent entries.
Scanned documents: the individual camera captures are not retained separately after being combined into the PDF file; the PDF file is retained like any other uploaded document. The recognised text and the details read out from it belong to the document and are deleted with it.
Membership events: every notification from the payment channel and the stores is logged with time, type, result and the state before and after the notification and retained with the membership (proof of billing).
7. Your Rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR).
You may withdraw any consent given at any time with effect for the future.
Data export and erasure requests are available directly in the portal under “Privacy”.
Right to lodge a complaint: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
8. Data Security
TLS transport encryption, encryption of sensitive secrets (AES-256-GCM), Argon2id password hashing, optional two-factor authentication, role-based access control and a tamper-proof audit log — technical and organisational measures pursuant to Art. 32 GDPR.
9. Cookies
We use technically necessary cookies for login and session, for the protection of forms, for the language setting, for storing your cookie choice and for recording which of our applications and which phone app shell you are using. These are required to operate the platform (§ 25 (2) TDDDG; Art. 6(1)(b) and (f) GDPR). The complete list with names, purpose and duration is set out in the cookie declaration.
Optional cookies (e.g. statistics) are only set with your consent via the cookie banner (Art. 6(1)(a) GDPR). Your choice is valid for 12 months and can be changed at any time via “Cookie settings” in the footer. If you choose “Accept all”, a cookie remembers for 30 days which advertising link of an agency brought you to us; without this consent it is not set. We currently do not use any statistics or marketing cookies.
10. Transfer to treating hospitals abroad
The platform's purpose is arranging medical treatment, predominantly in Germany. At your request, case data may also be transferred to treating hospitals or physicians outside the EU/EEA (e.g. in your home country).
Such transfers take place exclusively on the basis of your explicit consent (Art. 9(2)(a), Art. 49(1)(a) GDPR) and only to the extent of the documents you released. Third countries may not provide a level of data protection equivalent to the EU; we point this out before every transfer.
You can revoke your consent at any time with effect for the future (portal → privacy). Transfers already made remain unaffected.
11. Billing data and cost framework
For billing purposes, we process, per case, cost estimates, invoices, incoming payments (amount, date, purpose), the actual treatment costs, and refunds. This data is shown to physicians and the treating facilities to the extent necessary to ensure compliance with the agreed cost framework (legal basis: performance of a contract, Art. 6(1)(b) GDPR). Once the connection to our accounting system (Lexoffice, processor under Art. 28 GDPR) is active, the related receipts will be transferred to it.
12. Employee data (working-time recording)
For employees of the administration and the office system, we record working-time data while they are signed in to the administration area: the start and end of the session, the area or case accessed at one-minute intervals (identifier only, no content), whether an entry was made in the last minute, and the browser identifier. Keystrokes, texts, click targets and the contents of cases, messages or documents are not stored.
The purposes are proof of working time (Section 16 Working Hours Act (ArbZG)), the allocation of working time to treatment cases for billing, and evaluation by management by day, week and month. The legal basis is Art. 6(1)(b) and (c) GDPR in conjunction with Section 26(1) BDSG.
Short periods of inactivity up to the short break defined in the settings (default five minutes) count as working time; if every signal is absent for longer than the defined session gap (default thirty minutes), the session ends automatically. Recipients are exclusively the owner and the administration; no disclosure to third parties takes place.
The data is deleted automatically after the retention period defined in the settings (default 400 days). Every employee can view the data recorded for their account at any time under “My times”; the rights under Art. 15 to 21 GDPR apply without restriction.
13. Language, translation and AI interpreter
For mutual understanding we use machine translation: for messages within a case, for a separately bookable text translation with optional speech output, and for the AI interpreter in video consultations.
How the AI interpreter works: your microphone is cut into short segments in your browser at the pauses in speech — silence does not leave your device. Each segment goes via our server to ElevenLabs for speech recognition, the recognised text to Anthropic for translation, and the translation back to ElevenLabs for speech output. The audio recording is not stored in the process; it only exists for the duration of the processing of the respective segment.
Original and translation appear as subtitles during the conversation. They are only stored if you have additionally and separately consented to this; a withdrawal deletes the stored segments.
With the separately bookable text translation, the source text, the translation and — if you choose speech output — the generated audio file are stored in your case record. The audio file can only be retrieved via a short-lived address tied to your account.
When messages are translated, the original wording remains stored; the translation is filed separately and marked as machine-generated.
The legal basis is your explicit consent to the processing of health data (Art. 9(2)(a) GDPR) in conjunction with performance of the contract (Art. 6(1)(b) GDPR). Without active consent no machine translation takes place.
14. Location during an assignment
Interpreters and drivers can transmit their location during an ongoing assignment so that the patient can follow the journey. Transmission is switched on by the service provider themselves and ends when it is switched off or the page is left.
Only the last reported point (latitude and longitude) and its time are transmitted and stored, linked to the assignment. No movement profile outside the assignment is created; once the assignment is completed, the location is no longer displayed.
The location is only shown to the patient of the associated case and to BGGI's administration. The legal basis is performance of the contract with the service provider and with the patient (Art. 6(1)(b) GDPR).
15. Credentials, bank details and payouts
Physicians, hospitals, pharmacies as well as delivery and courier services prove their authorisation or permit when registering. We store the credential number, the uploaded document and — where provided for — the record of the check. The purpose is to ensure that only authorised bodies act (Art. 6(1)(b) and (f) GDPR).
For payouts and refunds we process bank details (account holder, IBAN, BIC, bank). The IBAN of BGGI's accounts and of physicians' payout accounts is stored encrypted (AES-256-GCM); only a shortened form is displayed.
Payouts to physicians can additionally be handled through our payment service provider. The details entered there by the recipient themselves are processed by the payment service provider on their own responsibility.
Uploaded documents are held in our storage in the Frankfurt am Main region. They can only be retrieved via short-lived addresses tied to the logged-in account and are checked for malware before being stored.
16. Pharmacy, prescription and delivery
If you order a medicine through the platform, we transmit the details required for processing to the responsible partner pharmacy and make the prescription available to it for a period limited to 30 days. Every access by the pharmacy to a prescription is logged.
To the commissioned delivery or courier service we transmit only the delivery data (name, address, means of contact, pick-up and destination, delivery status). It does not receive prescription contents, diagnoses or prices.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and your explicit consent to the processing of health data (Art. 9(2)(a) GDPR); a prescription is always health data.
17. Interface for partner systems
For cooperation with our own partner systems there is a strictly read-only interface. Only a few fields are released through it: for a person, first name, surname, date of birth, nationality, preferred language, telephone number, e-mail address and the file references of open cases; for a case, the file reference, status, department, creation date, treating physician and hospital, appointments with time, type, status and place, travel dates as well as the indication whether payments are outstanding.
Not released are diagnoses, findings, medical summaries, documents, messages, prescriptions, cost estimates, amounts, addresses, passport data and the freely worded subject of a case.
Access requires an assigned key, of which only a hash value is stored. Every access is logged — with time, endpoint, response status, sender address and browser identification; of a search term only a hash value is stored, never the term itself.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in the orderly cooperation of our own systems (Art. 6(1)(f) GDPR).
18. Care partners: rehabilitation, assistive devices and air ambulance
If you need follow-up treatment, an assistive device or transport by air ambulance, we ask a vetted care partner: a rehabilitation facility, a medical supply store or an air ambulance service.
Only what is needed for the price quotation is transmitted — the case number, the request in words and, where a prescription or order is involved, its content. The partner receives your name and address only once you have accepted the order and the service is carried out.
The legal basis is performance of the contract with you (Art. 6(1)(b) GDPR); where the request contains health data, it is additionally based on Art. 9(2)(h) GDPR. These partners also prove their licence on registration, where their country has one.
19. Staying logged in and device list
So that you do not have to log in again on every visit, a login remains in place for up to 90 days and is extended with each use. Each login receives its own entry in your device list.
Stored per entry are: a designation derived from the browser identifier (for example “iPhone · BGGI Health App”), the browser identifier itself in truncated form, the application used, the truncated IP address (for IPv4 without the last field, for IPv6 truncated to the first four groups), the time of login and the time of last use.
You can log out each device individually — also from another device, for instance in case of loss or theft — or all devices at once. The logout takes effect at the latest five minutes later. Only the device identifier and the designation enter the audit log, never the browser identifier and never the address.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR) as well as our legitimate interest in the security of the accounts (Art. 6(1)(f) GDPR).
20. Document scanner
If you capture documents with the camera, the sheet is detected, straightened and made more legible on your device. In the phone apps this is done by the device's own document scanner, in the browser by ours. Only then are the pages transmitted to our server; there they are checked, scanned for malware and combined into ONE PDF file. The individual captures are not retained separately afterwards.
If your device offers text recognition, the text of the pages is read there — on your device, not at our end. It is transmitted together with the pages, placed invisibly into the PDF file so that the file can be searched, and read out: sender, recipient, date, invoice, customer and case reference numbers, amount and currency, bank details as well as e-mail address, phone number and address, insofar as they appear on the document. The text and the details read out belong to the document and are deleted with it.
To classify the document — type, title, date, issuer and language — we transmit details to our processor Anthropic. If text was recognised on your device, this is exclusively that text; images of the pages are then not transmitted. Otherwise we transmit at most four pages as images, always the first and the last. The model makes no medical assessment; it only classifies and describes. The result remains marked on the document as machine-generated and can be changed.
If the model does not recognise a document, nothing is stored.
If you capture in the app for Android phones, the pages are handed over by the app to our server with a one-time key that expires after 15 minutes and are collected there by the web page; afterwards they are deleted. This is necessary because the app for Android cannot pass the pages directly to the web page.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR); if the document contains health data, the processing is additionally based on your explicit consent (Art. 9(2)(a) GDPR).
21. Membership via the Apple App Store and Google Play
In our phone apps the membership is taken out exclusively via the Apple App Store or via Google Play. So that the subscription can be assigned to your account rather than to the device, we pass a pseudonymous account identifier to the store. It is calculated from your user ID and cannot be traced back to it; your name and your e-mail address are not transmitted to the store.
The store notifies us of purchase, renewal, cancellation, payment failure, expiry and refund. For this we store the transaction or purchase identifier, the product identifier, start and end of the paid period, the state, the environment and the time of the notification as well as the content of the notification in the event log. Payment data — card, billing address, the store's amounts — we do not receive.
The legal basis is performance of the contract (Art. 6(1)(b) GDPR) as well as our record-keeping obligations under commercial and tax law (Art. 6(1)(c) GDPR).
22. Digital human in video consultations
On request, the AI interpreter appears as a photorealistic face (“digital human”). The face is generated by a commissioned provider; it moves the lips to the audio the platform has generated beforehand.
Only this audio and the identifier of the face used are transmitted to that provider. Not transmitted are: image and sound of the participants, subtitles, texts, names and other information about the case.
No recording takes place. The session at the provider is ended after the conversation. The provider's access key does not leave the server; the browser only receives a short-lived session token.
If a face shows a real person, it is used only with that person's consent; name, date and declaration are recorded.
The digital human is an addition to the audio. If it is not available or not switched on, the voice continues to interpret.
23. Responsibility of employees by country and department
BGGI employees do not see all cases. In addition to the role and the department, the scope decides: it is either worldwide or limited to certain countries.
Decisive is the country of the case: for patients their place of residence, failing that their nationality; for cases and invoices the country of the associated patient; for physicians and facilities their own country.
If no country is assigned to a person, they see nothing. An empty field means “not yet assigned”, not “all”. There is only one data set; the separation is a view, not a second system.
Accesses are logged. Changes to the scope are recorded with person, time and extent.
Change history
- 2026-09-12 — Version 1.6 — digital human in video consultations (only the audio goes to the provider, no recording); responsibility of employees by country and department.
- 2026-09-10 — Version 1.5 — document scanner: text recognition on the device, the recognised text and the details read out from it are stored with the document; where text has been recognised, no image is sent to the processor for the classification any more.
- 2026-09-10 — Version 1.4 — device and session data (login for up to 90 days, device list), document scanner with machine classification, membership via the Apple App Store and Google Play with a pseudonymous account identifier, external tax and legal advisers as professionals bound by secrecy, push services, cookie information completed.
- 2026-09-09 — Version 1.3 — care partners added: rehabilitation facilities, medical supply stores and air ambulance services.
- 2026-09-08 — Version 1.2 — processor list completed (ElevenLabs, Lexoffice), new data categories (speech and voice, location during an assignment, credentials, bank details, order and delivery data), further retention periods, and sections on translation and AI interpreter, assignment location, credentials and payouts, pharmacy and the partner interface; contact details switched to the provider information.
- 2026-09-07 — Employee data (working-time recording) added.
- 2026-09-07 — Billing data and accounting system added.
- 2026-08-12 — Version 1.1 — processors specified, retention periods added, transfer to treating hospitals abroad, payment/cancellation/refund rules, new documents (withdrawal, telemedicine, health-data consent, cookies).
- 2026-08-08 — Version 1.0 — initial publication.

