Legal Notice and Privacy Policy
Last updated: August 9, 2026
Company information
Contact: [email protected]
Local court:
München HRB 270276
Managing director:
Dr. Christiaan Adrianus (Karsten) Miermans
V.A.T. identification number:
DE348156268
Information about the processing of personal data
Care and transparency are the basis for trusting cooperation with hema.to’s customers and website visitors. This policy explains how hema.to processes personal data and how data subjects can exercise their rights under the General Data Protection Regulation (GDPR). The personal data processed and the purpose of processing depend on the relevant relationship with hema.to.
1. Who is responsible for data processing (Controller)?
The Controller is:
hema.to GmbH
Metzstraße 14B
81667 Munich
Germany
2. How can the data protection officer be reached?
Rhenus Office Systems GmbH
Patrick Wellbrock ([email protected])
Rhenus-Platz 1
59439 Holzwickede
Germany
3. Which personal data does hema.to use?
If you make an enquiry, order documents for a haematological analysis, or conclude a contract with hema.to, personal data is processed. Personal data may also be processed to fulfil legal obligations, protect a legitimate interest, or on the basis of consent. Depending on the legal basis and the relevant relationship, this may include the following categories:
- First name and last name;
- Address;
- Communication data, such as telephone number and email address;
- Date of birth;
- Contract master data, in particular order number, order date, and type of contract;
- Invoice and sales data;
- Payment and bank details;
- Website usage, device, and security data described below; and
- Information submitted through contact forms or other communications.
4. What are the sources of the data?
hema.to primarily receives personal data directly from customers, prospective customers, and website visitors. Technical website data is transmitted automatically by a visitor’s browser or device. Data relating to hema.to’s LinkedIn company profile may be received from LinkedIn or from users who interact with that profile.
5. For what purposes and on what legal basis does hema.to process personal data?
Personal data is processed on the following legal bases:
- Consent under Art. 6(1)(a) GDPR, where consent is requested for a specific purpose. Consent can be withdrawn at any time with effect for the future.
- Performance of a contract or steps taken at the data subject’s request before entering into a contract under Art. 6(1)(b) GDPR.
- Compliance with a legal obligation under Art. 6(1)(c) GDPR, for example tax and commercial retention obligations.
- Legitimate interests under Art. 6(1)(f) GDPR, following a balance between those interests and the data subject’s interests, fundamental rights, and freedoms. hema.to’s interests include operating its business, answering enquiries, providing and improving a reliable website, preventing abuse, and maintaining information security.
The specific purposes and legal bases for website-related processing are described in the sections below.
6. Who receives personal data?
Personal data is disclosed only where permitted by law, necessary to provide hema.to’s services, or covered by consent. Recipients may include contracted processors, such as Cloudflare, Attio, and Postmark, as well as professional advisers, public authorities, or other recipients where disclosure is legally required.
Processors may use personal data only in accordance with hema.to’s instructions and the applicable data processing agreement. A provider’s independent legal obligations remain applicable.
7. Is personal data transferred outside the European Economic Area?
Some providers operate globally or are based outside the European Economic Area (EEA). Personal data may therefore be processed in countries outside the EEA.
Cloudflare serves and protects this website through a global network, so website and security data may be processed outside the EEA, including in the United States. Cloudflare states that it relies on the EU-U.S. Data Privacy Framework and, where required, the European Commission’s Standard Contractual Clauses and supplementary safeguards. More information is available in Cloudflare’s Privacy Policy and Cloudflare’s Data Processing Addendum.
hema.to’s Attio workspace is hosted in the European Union. Attio Limited is based in the United Kingdom, for which the European Commission has adopted an adequacy decision. If Attio or its subprocessors transfer personal data to another country outside the EEA, Attio states that it uses an adequacy decision or approved transfer mechanisms such as the European Commission’s Standard Contractual Clauses. More information is available in Attio’s Privacy Policy and Attio’s Data Processing Addendum.
Postmark, the email service described in section 12, is provided by AC PM LLC, which is based in the United States. Personal data contained in such an email is therefore processed outside the EEA. AC PM LLC states that it has certified its compliance with the EU-U.S. Data Privacy Framework and that, where that framework does not apply, it relies on the European Commission’s Standard Contractual Clauses. More information is available in ActiveCampaign’s Privacy Policy, which applies to Postmark, and in Postmark’s Data Processing Addendum.
Additional processing outside the EEA may occur when a visitor voluntarily follows an external link or interacts with hema.to’s LinkedIn profile. Details are provided below.
8. How long is personal data stored?
Personal data is stored only for as long as necessary for the relevant purpose and to fulfil legal or contractual obligations. Data is then deleted or anonymised. Statutory retention obligations and the establishment, exercise, or defence of legal claims may require continued storage. Specific retention periods for website logs and contact-form submissions are described below.
9. What rights do data subjects have?
Subject to the applicable legal requirements and limitations, data subjects have the following rights:
- The right of access under Art. 15 GDPR;
- The right to rectification under Art. 16 GDPR;
- The right to erasure under Art. 17 GDPR;
- The right to restriction of processing under Art. 18 GDPR;
- The right to data portability under Art. 20 GDPR;
- The right to object to processing based on Art. 6(1)(e) or (f) GDPR under Art. 21 GDPR;
- The right to withdraw consent at any time under Art. 7(3) GDPR; processing completed before withdrawal remains lawful; and
- The right to lodge a complaint with a supervisory authority under Art. 77 GDPR.
To exercise these rights, contact the Controller or data protection officer using the details above, or email [email protected]. Requests will be handled in accordance with the applicable legal requirements.
10. Is there an obligation to provide personal data?
To enter into or perform a business relationship, you must provide the personal data required for the contractual relationship or by law. Without this data, hema.to may be unable to enter into or perform the relevant contract.
Visiting the public website does not require registration or the voluntary submission of personal data. Technical data required to deliver and secure the website is processed automatically.
11. Website delivery, security, and server logs
When you visit this website, your browser automatically transmits technical information required to deliver the requested content. This may include:
- IP address of the requesting device;
- Requested domain, page, file, and URL;
- Date and time of the request;
- Referring page or URL;
- Browser type, device type, and operating system;
- HTTP response status and transferred data volume; and
- Security and diagnostic identifiers associated with the request.
hema.to uses Cloudflare Pages, Cloudflare’s content delivery network, and related security services to host, deliver, cache, and protect the website. The provider is Cloudflare Germany GmbH, with services also provided by Cloudflare, Inc. and other Cloudflare group companies.
This processing is necessary to provide a reliable website, prevent attacks and abuse, diagnose technical problems, and maintain information security. The legal basis is hema.to’s legitimate interest under Art. 6(1)(f) GDPR. Operational and security log data is retained for up to 30 days and is then deleted or anonymised. A security incident or legal obligation may require longer retention.
12. Contact and demo request forms; processing in Attio and Postmark
When you submit a contact or demo request form, hema.to processes the information entered in the form. This includes your name, email address, and company, as well as your message where that field is provided. The form type and technical submission data are also processed.
Submissions are stored and processed in hema.to’s Attio customer relationship management system. Attio Limited processes this data on hema.to’s behalf. The Attio workspace used by hema.to is hosted in the European Union.
hema.to may also be notified of a submission by email at an internal hema.to address. Such an email is delivered by Postmark, a service of AC PM LLC, which processes the data on hema.to’s behalf and is based in the United States. Section 7 describes the safeguards for this transfer.
The data is used only to answer the enquiry, arrange or discuss the requested demo, and conduct sales follow-up related to that enquiry. Processing is based on Art. 6(1)(b) GDPR where the request concerns a contract or pre-contractual steps, and otherwise on hema.to’s legitimate interest in handling enquiries effectively under Art. 6(1)(f) GDPR.
Contact-form data is deleted from Attio, and any related notification email is deleted, when the enquiry and related follow-up have been resolved. A legal retention obligation or resulting contractual relationship may require further processing.
13. Cloudflare Turnstile
hema.to uses Cloudflare Turnstile on contact and demo request forms to distinguish legitimate submissions from automated abuse. When a page containing one of these forms is loaded, the Turnstile component connects to Cloudflare. Turnstile may process signals such as the IP address, TLS fingerprint, user-agent header, site key and associated origin, and the result of the abuse check. The visitor’s IP address may also be sent to Cloudflare when the result is verified.
According to Cloudflare, these signals support bot detection and blocking. Cloudflare acts as hema.to’s processor when providing the website-protection service and as an independent controller when using signals to improve Turnstile’s bot-detection capabilities.
Processing is based on hema.to’s legitimate interest in protecting forms and systems from spam, fraud, and automated attacks under Art. 6(1)(f) GDPR. Cookies or similar storage used by Turnstile are strictly necessary for this security purpose. Further information is available in Cloudflare’s Turnstile Privacy Addendum.
14. Requests by email or telephone
If you contact hema.to by email or telephone, the enquiry and the personal data arising from it are processed to handle the request and any follow-up questions.
Processing is based on Art. 6(1)(b) GDPR where the request concerns a contract or pre-contractual steps. In other cases, it is based on hema.to’s legitimate interest in handling enquiries effectively under Art. 6(1)(f) GDPR, or on consent under Art. 6(1)(a) GDPR where consent has been requested.
The data is retained until you request deletion, withdraw applicable consent, or the relevant processing purpose concludes. Statutory retention obligations remain applicable.
15. Cookies and similar technologies
Cloudflare may use strictly necessary cookies or similar technologies to deliver and secure the website, apply rate limits, and provide Turnstile. Their purpose is website delivery and security under Section 25(2), number 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG).
16. CellStudio and external links; hema.to’s LinkedIn company profile
The website contains a hyperlink to CellStudio at app.hema.to. Displaying the link does not connect the visitor’s browser to CellStudio. If a visitor follows the link, the browser requests the separate service and transmits technical request data, such as the IP address, browser information, and the date and time of the request.
CellStudio is a separate software service provided by hema.to. Application-specific processing, including account, authentication, and service data, is described in CellStudio’s privacy policy.
The website also provides hyperlinks to third-party websites, including LinkedIn company and team-member profiles. Following an external link initiates a connection to the destination, where the provider processes data under its own terms and privacy policy.
hema.to maintains a company profile on LinkedIn, and the website presents it as an external link. The LinkedIn service is provided in the EEA by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
When you visit or interact with hema.to’s LinkedIn company profile, LinkedIn processes personal data under its own responsibility. LinkedIn may provide hema.to with profile information, messages, comments, reactions, interaction data, and aggregated page analytics. hema.to processes information you provide through LinkedIn to respond to messages and comments, manage the company profile, and understand engagement with its public communications.
This processing is based on hema.to’s legitimate interests in public communication and responding to enquiries under Art. 6(1)(f) GDPR and, where an enquiry concerns a contract or pre-contractual steps, Art. 6(1)(b) GDPR. Data received by hema.to is deleted after these purposes conclude, subject to legal retention obligations.
For LinkedIn Page Insights data, hema.to and LinkedIn may act as joint controllers. The applicable arrangement is available in LinkedIn’s Page Insights Joint Controller Addendum. LinkedIn may process data outside the EEA using the safeguards described in LinkedIn’s Privacy Policy.
17. Changes to this information
If there is a material change in the purpose or manner in which personal data is processed, this policy will be updated in a timely manner. The date at the top shows when the policy was last revised.