Skip to content

Privacy policy

For customers resident in Germany

Last updated: 10 June 2026

This English translation is provided for your convenience. Only the German version is legally binding. If the two versions differ, the German version prevails.

This privacy policy describes how Ahead Health AG (hereinafter “Ahead”, “we”, “us”) processes personal data (“data”) in the course of providing our services. We process data exclusively in accordance with the General Data Protection Regulation (GDPR) and the BDSG (German Federal Data Protection Act).

1. Controller / contact / management

The controller responsible under data protection law for the processing of your data within the meaning of Art. 4(7) GDPR is:

Ahead Health AG
Uraniastrasse 31
8001 Zürich, Switzerland
UID: CHE-213.692.684
Email: privacy@aheadhealth.com
Phone: +41 44 797 69 46

2. Representative in the EU pursuant to Art. 27 GDPR

As we offer services to persons resident in Germany, we have appointed a representative in the EU:

IT.LAW GmbH
Colmanstr. 15
53115 Bonn, Germany
Phone: +49 228 74 898 0
Fax: +49 228 74 898 66
Email: info@it.law

3. Scope

This privacy policy applies to data processing by Ahead (website www.aheadhealth.com/de/de, platform/app, booking coordination (booking.aheadhealth.com/de/de), preparation of the health report, membership membership.aheadhealth.com/de/de). For the on-site examination (blood draw, MRI) at the German partner practice, that practice’s own privacy policy applies.

Ahead and the partner practice are each separate controllers (Art. 4(7) GDPR) for the processing carried out in their respective areas. We do not receive part of the health data (laboratory values as well as MRI images and findings) directly from you, but from the partner practice as the data source (Art. 14 GDPR). The transfer from the partner practice to us takes place on the basis of your release from medical confidentiality (§ 203 StGB, German Criminal Code) and your explicit consent pursuant to Art. 9(2)(a) GDPR.

4. Data processed and legal bases

4.1 Visiting the website

  • Server log files (IP address, time, content accessed, browser): Art. 6(1)(f) GDPR; storage period max. 30 days.
  • Cookies and analytics/marketing technologies: only with your consent via the cookie banner (Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act)). Details of the providers in section 6.

4.2 Booking, account and communication

We process master data (name, date of birth, address, contact details), appointment and booking data, payment data and communication content in order to maintain your user account, coordinate appointments, provide the platform, communicate with you and invoice our services.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for queries and communication, additionally Art. 6(1)(f) GDPR.

4.3 Provision of services: health data (Art. 9 GDPR)

In the course of the service, we process the information you provide in the health questionnaire, the laboratory values as well as MRI images and findings from the partner practice and (where a medical consultation takes place) the associated consultation notes, in order to prepare and provide your health report from them.

Legal basis: your explicit consent pursuant to Art. 9(2)(a) GDPR, given at the time of booking, and Art. 6(1)(b) GDPR for the platform and report contract.

4.4 Billing and legal obligations

For invoicing and to comply with retention obligations under commercial and tax law, we process the master and billing data required for this purpose. Legal basis: Art. 6(1)(b) and (c) GDPR in conjunction with § 257 HGB (German Commercial Code) and § 147 AO (German Fiscal Code).

4.5 Newsletter and direct marketing

If you subscribe to our newsletter, we process your email address on the basis of your consent (Art. 6(1)(a) GDPR) using the double opt-in procedure. You can unsubscribe from the newsletter at any time and object to processing for advertising purposes at any time (Art. 21(2) GDPR).

5. Relationship with the German partner practices

You conclude an examination contract with the German partner practice for the physical examination. The partner practice has a cooperation agreement with Ahead Health AG under which we are engaged to carry out the booking coordination, the interpretation of findings by our Swiss doctors and the pre- or post-consultations.

The German partner practice and Ahead Health AG are each separate controllers for the data processing carried out in their respective areas. The disclosure of data from the practice to us takes place on the basis of your release from confidentiality (§ 203 StGB) and your consent pursuant to Art. 9(2)(a) GDPR. We do not receive part of the health data (laboratory values as well as MRI images and findings) directly from you, but from the German partner practice as the data source (Art. 14 GDPR).

6. Recipients and service providers used

We use carefully selected service providers with whom (insofar as they act as processors) we have concluded contracts pursuant to Art. 28 GDPR. Transfers to third countries are explained in section 7.

ProviderPurposePersonal data processed
1. Practice and patient management (PIS)
zollsoft GmbH (tomedo), Ernst-Haeckel-Platz 5/6, 07745 Jena, GermanyPractice and patient information system (PIS): management of patient master data, treatment and findings documentation, and appointment and billing data. Processing within the EU.Patient master data (name, date of birth, contact details), health data (diagnoses, findings, treatment documentation), appointment and billing data.
2. Infrastructure, hosting and technical operations
Google Cloud EMEA Limited, Velasco Clanwilliam Place, Dublin 2, IrelandCloud infrastructure (Platform as a Service): provision of the server and database resources for operating the platform, and web hosting. All data is transmitted, stored and processed exclusively in encrypted form, with data storage in the EU. Insofar as intra-group transfers to the USA take place, these are based on the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR), supplemented by standard contractual clauses pursuant to Art. 46 GDPR.All personal data processed on the platform (e.g. account, appointment, health and billing data), encrypted.
Supabase, Inc., 65 Chulia Street #38-02/03, OCBC Centre Singapore, 049513 (hosting in the AWS region Zurich, Switzerland)Backend and database services (database, authentication, storage). Storage in the EU region; since the contracting party is a company headquartered in Singapore and access from third countries (e.g. USA) cannot be completely ruled out, safeguarded by standard contractual clauses (Art. 46 GDPR) and supplementary technical measures.Account and application data (where applicable, health and appointment data), authentication data.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland (Firebase)App backend services, e.g. authentication, push notifications, app usage analysis.Device and app identifiers, push tokens, usage data, where applicable account and authentication data.
Functional Software, Inc. (dba Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USAError and crash monitoring, and application stability. Transfer to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46 GDPR).Technical error and log data, IP address, device and browser information, where applicable pseudonymous user IDs.
3. Web and product analytics, and consent management
CookieYes Limited, 3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United KingdomConsent management (cookie banner and logging of consents). Transfer to the United Kingdom on the basis of the adequacy decision (Art. 45 GDPR).Consent status (accepted, rejected or partially accepted) including cookie categories, pseudonymised IP address, country, device and browser identifier, timestamp.
PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USAProduct analytics and usage analysis of the platform and app. Transfer to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46 GDPR).Usage and event data, device and browser information, IP address, pseudonymous user identifier.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland (Google Analytics 4, integrated via Google Tag Manager)Web analytics. Any intra-group transfers to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46 GDPR).Usage data, truncated IP address, device and browser data, cookie IDs, interaction data.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland (Google Ads, integrated via Google Tag Manager)Conversion tracking to measure the success of advertisements. Any intra-group transfers to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46 GDPR).Usage and interaction data, cookie IDs, truncated IP address, conversion events.
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, IrelandServer-side event transmission (Meta Conversions API) to measure the success of advertisements. Any transfers to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46 GDPR).Usage and interaction data (e.g. page views, completed bookings), IP address, where applicable pseudonymous user IDs.
4. Appointment booking and video calls
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland (Google Calendar)Online booking calendar and appointment management.Name, email address, appointment data (date, time, type of appointment).
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland (Google Meet)Video calls, e.g. consultations and results discussions.Name, email address, audio and video data, and conversation content during the session (where applicable, health data).
zollsoft GmbH (arzt-direkt), Ernst-Haeckel-Platz 5/6, 07745 Jena, GermanyVideo consultation and secure patient communication (pre- and post-consultation). Processing within the EU.Name, contact details, appointment data, audio and video data, and message content (where applicable, health data).
5. Payment processing and accounting
Stripe Payments Europe Limited (SPEL), 1 Grand Canal Street Lower, Dublin 2, IrelandPayment processing.Name, email address, billing address, payment data (e.g. tokenised card data or IBAN), transaction data.
bexio AG, Alte Jonastrasse 24, 8640 Rapperswil, SwitzerlandAccounting and invoicing.Name, postal address, invoice and payment data, where applicable description of services.
6. Email delivery and newsletter
Sendinblue SAS (Brevo), 17 rue Salneuve, 75017 Paris, France; for the German market, where applicable, Sendinblue Germany GmbH, Köpenicker Str. 126, 10179 BerlinTransactional communication and newsletter delivery.Name, email address, delivery and open data, content of the communications.
Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USADelivery of transactional emails. Transfer to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by standard contractual clauses (Art. 46 GDPR).Email address, name, content and metadata of the emails.
7. Support and telecommunications
Intercom R&D Unlimited Company, 18-21 St. Stephen’s Green, Dublin 2, IrelandTelecommunications services, categorisation and answering of support requests.Message text, subject, email address, name.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland (Google Voice)Telecommunications services, handling of support requests.Telephone number, where applicable call and conversation data.
8. CRM and process automation
Attio Limited, 42 St John’s Square, 2nd Floor, London, EC1M 4EA, United KingdomCRM, customer and contact management. Transfer to the United Kingdom on the basis of the adequacy decision (Art. 45 GDPR).Name, email address, telephone number, company and contact details, interaction history.
Relay, Inc., 2261 Market Street 5496, San Francisco, CA 94114, USAWorkflow automation. Transfer to the USA on the basis of standard contractual clauses (Art. 46 GDPR).Contact data processed depending on the workflow.
9. Forms and surveys
Typeform SL, Carrer Bac de Roda 163, 08018 Barcelona, SpainOnline forms and questionnaires.Form responses (name, email address, where applicable health-related information).
Restly, Inc. (Zite), 9450 SW Gemini Dr, PMB 39088 Beaverton, Oregon 97008, USAProvision of online forms (e.g. ambassador or referral form). Transfer to the USA on the basis of standard contractual clauses (Art. 46 GDPR).Form responses (name, email address and other information collected in the form).
10. Medical image analysis and AI evaluation
mediaire GmbH (mdbrain), Möckernstraße 63, 10965 Berlin, GermanyAI-assisted evaluation of MRI scans (in particular of the brain), e.g. volumetry and detection of lesions and abnormalities. Processing within the EU.MRI/image data (DICOM) and findings generated from it (health data), where applicable pseudonymised.
RedBrick AI, Inc., 2093 Philadelphia Pike, Suite 1940, Claymont, DE 19703, USAAnnotation and preparation of medical image data (MRI) for reporting and quality assurance. Transfer to the USA on the basis of standard contractual clauses (Art. 46 GDPR).MRI/image data and associated annotations (health data), where applicable pseudonymised.

In addition, data may be disclosed to supervisory authorities and to tax, legal and accounting advisers, each of whom acts on their own responsibility.

7. Data transfers to third countries

Insofar as data is processed outside the EEA, we base this on an adequacy decision of the EU Commission (Art. 45 GDPR; e.g. EU-US Data Privacy Framework, Switzerland, United Kingdom) or on appropriate safeguards such as standard contractual clauses (Art. 46 GDPR) together with supplementary measures. We will provide further information on this upon request.

8. Storage period

  • Master, appointment and billing data: until the end of the contractual relationship; beyond that, for the duration of statutory retention periods (§ 257 HGB, § 147 AO).
  • Health data and health report: for the duration of the contractual relationship or until you withdraw your consent; thereafter deletion, subject to statutory retention obligations.
  • Server log files: max. 30 days.
  • Newsletter: until withdrawal.

We store health-related data logically and physically separately from billing data. As the treating provider, the partner practice is subject to its own medical documentation and retention obligations (including § 630f BGB, German Civil Code).

9. Data security

We take appropriate technical and organisational measures pursuant to Art. 32 GDPR, in particular encryption in transit and at rest, access restrictions based on the need-to-know principle, separate storage of health and billing data, and regular review of our protective measures.

10. Data protection for minors

Our services are aimed at persons aged 18 and over. We do not knowingly process data of persons without the required consent; if we become aware of such data, we will delete it without undue delay.

11. Your rights

Under the GDPR, subject to the statutory requirements, you have the following data protection rights:

  • Right of access, rectification, erasure and restriction (Art. 15, 17, 18 GDPR): You have the right to request information at any time about your data stored by us (Art. 15 GDPR). When we process or use your data, we endeavour to ensure, through appropriate measures, that your data is accurate and up to date for the purposes for which it was collected. If your data is inaccurate or incomplete, you can request the rectification of this data (Art. 16 GDPR). You may also have the right to request the erasure (Art. 17 GDPR) or restriction of processing (Art. 18 GDPR) of your data if, for example, your data is no longer necessary for the purposes for which it was collected or otherwise processed and statutory retention obligations do not require further storage.
  • Right to data portability (Art. 20 GDPR): You may have the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to transmit this data to another controller (Art. 20 GDPR).
  • Right to withdraw your consent (Art. 7(3) GDPR): If you have consented to the collection, processing and use of your data, you can withdraw your consent at any time with effect for the future, without this affecting the lawfulness of the processing carried out on the basis of the consent before its withdrawal (Art. 7(3) GDPR).
  • Automated decision-making (including profiling) (Art. 22(1) GDPR): You have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. Please note that we do not use any such automated decision-making or profiling within the meaning of Art. 22 GDPR in connection with our app.

Right to object (Art. 21 GDPR): Insofar as we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object to this processing at any time on grounds relating to your particular situation. If your data is processed for the purpose of direct marketing, you have the right to object at any time; your data will then no longer be processed for these purposes (Art. 21(2) GDPR).

12. Contact

For data protection matters and to exercise your rights, you can contact us at privacy@aheadhealth.com.

13. Changes to the privacy policy

We update this privacy policy as necessary, for example due to changes in our services or in the legal situation. The current version is available on our website; we will inform you of material changes in advance by email and/or in the app.