Protecting your personal data — in particular your health data — is Cannathera's highest priority. We process your data exclusively on the basis of the applicable law (GDPR, BDSG) and this privacy policy.
Cannathera, owner: Dominique Larkin, [address]. Email: [datenschutz@cannathera.de]
Master data (name, email address, date of birth), access data (passwords stored encrypted), health data within the therapy accompaniment (Art. 9 GDPR), and technical log data (audit log).
Your health data is processed exclusively on the basis of your explicit consent (Art. 9 (2) (a) GDPR), which you give at registration and may withdraw at any time. Other data is processed to perform the contract (Art. 6 (1) (b) GDPR) and to comply with legal obligations (Art. 6 (1) (c) GDPR).
Your course reports are transmitted to your treating doctors or your pharmacy only with your separate consent. Without consent, no data is shared.
Your data is processed encrypted (in transit and at rest) on servers in Germany (AWS Frankfurt, eu-central-1). Passwords are stored as hashes only. All access is logged.
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw consent at any time with future effect. You also have the right to lodge a complaint with a data protection supervisory authority.
We store personal data only for as long as is necessary for the stated purposes or as long as statutory retention obligations apply. After you withdraw your consent, health data is deleted unless a legal obligation to retain it exists.
Note: this privacy policy is a preliminary version. Placeholders will be completed before going live; the final version will undergo a data protection review.
Last updated: July 2026