Privacy Policy
1. Controller
The controller responsible for data processing within the meaning of the
General Data Protection Regulation (GDPR) is:
Alexander Beck e.U., Schlossallee 52, A-3704 Heldenberg, office@becon.at
2. Storage location: data centre in Germany
The website and database are operated on servers in a German data centre. All data is therefore stored and processed exclusively within the European Union; no transfer to or storage outside the EU takes place. Operations comply with the GDPR.
3. Legal compliance & data security
When processing personal data we comply with the applicable data protection laws, in particular the GDPR and the relevant national data protection legislation.
We take appropriate technical and organisational measures: passwords are stored exclusively as a secure hash, and personal information (e.g. display name and personal notes) is stored encrypted (encryption “at rest”). Transmission takes place over encrypted connections (HTTPS).
4. What data we process
- Account data: email address and (optionally) a display name. The display name is stored encrypted.
- Health data: the conditions/allergies you select, voluntary personal notes and optionally stored medications (name, dosage, frequency). This information is stored encrypted. We process these special categories of personal data (Art. 9 GDPR) exclusively on the basis of your explicit consent and for the purpose you request.
- Subscription/purchase data: time and term of the card subscription.
- Security log: at registration and sign-in we store the time, IP address and device information (browser/device) to protect your account. This data is stored encrypted; the legal basis is our legitimate interest in IT and account security (Art. 6(1)(f) GDPR).
- Access/scan statistics: when a card is opened we store the chosen language, the time and the approximate country of origin. The country is determined solely server-side from the IP address; the IP address itself is not stored. No more precise location (city/GPS) or other identifiable characteristics of the accessing device are recorded. This information is visible in your dashboard as a scan log.
5. Purposes and legal bases
Processing takes place to provide the user account and the MyMediCard (Art. 6(1)(b) GDPR), on the basis of your consent for the health data (Art. 9(2)(a) GDPR) and to handle orders.
5a. Automatic translation (optional)
If you use the function to automatically translate your personal notes, only the note text you entered is transmitted to an external translation service — without any reference to your personal details (no name, no email address, no account or card data, and no information about which person the text belongs to) and exclusively for the purpose of translation. Transmission only happens on your explicit action (clicking “Translate”). This service is currently provided by Anthropic (USA); a switch to the EU-based service DeepL is planned. The legal basis is your consent (Art. 6(1)(a) GDPR); for the transfer to the USA we rely on the guarantees assured by the provider (standard contractual clauses).
6. Display of the card to third parties (consent)
Already at registration you explicitly consent to your stored conditions and allergies being made accessible via the QR code to third parties (e.g. restaurant staff). Registration is not possible without this consent.
Your MyMediCard is accessible via a QR code or a non-guessable link. When you present it, the information stored on the card is shown to the person scanning the code. This happens deliberately and at your instigation. You can withdraw your consent at any time by removing the relevant information or having your account deleted.
7. Retention period
We store your data for as long as your account exists. On request we will delete your account and the associated data.
8. Your rights
You have the right to access, rectification, erasure, restriction of processing and data portability, as well as the right to withdraw consent at any time and to lodge a complaint with a supervisory authority.
9. Contact
For data protection matters you can reach us at:
office@becon.at