Privacy information
Information about personal data processed on vampirelab.de under Article 13 GDPR.
1. Controller
Janina Schönn · Heilpraktikerin · VampireLab
Krossener Str. 2 · 10245 Berlin · Email: nina@vampirelab.de
2. Data processed
- When visiting the website: IP address, browser and device information, access time, and pages requested in technically necessary server and security logs.
- When choosing and booking an appointment: requested appointment, name, email address, optional telephone number, language, and booking status.
- During payment: name, email address, billing and payment information, and payment status. Full card details are processed by Stripe and are not stored by VampireLab.
- During communication: sender and recipient addresses, time, and message content.
3. Purposes and legal bases
- Booking, payment, confirmation, and performance of the purchased service: Article 6(1)(b) GDPR.
- Secure and reliable website operation, troubleshooting, and abuse prevention: Article 6(1)(f) GDPR.
- Compliance with statutory documentation, accounting, and retention duties: Article 6(1)(c) GDPR.
4. Service providers
- Vercel for website hosting, delivery, and technical logs.
- Stripe for payment processing, payment status, and refunds.
- Cal.com for appointment availability, booking, and appointment management.
- Neon for the separate VampireLab booking database and minimal technical calendar coordination.
- Google Workspace and Gmail for VampireLab appointment, transactional, and support emails.
5. Transfers outside the European Economic Area
Some providers or their subprocessors may process data outside the European Economic Area. Where no adequacy decision applies, transfers rely on appropriate safeguards, in particular the EU Standard Contractual Clauses. Information about the applicable safeguards may be requested at nina@vampirelab.de.
6. Health and laboratory data
The public website, calendar, and normal payment process are not intended for symptoms, laboratory reports, or other health information. Health and laboratory information is processed only within the separate practice process. Additional clinical privacy information and statutory documentation duties apply.
7. Cookies, map, and analytics
VampireLab does not use advertising or analytics trackers. Technically necessary cookies or similar storage may be used during booking, payment, or protected communication. The location map is delivered locally; an external mapping website is contacted only when the directions link is opened.
8. Retention
- Technical logs are retained only for as long as required for operation, security, and troubleshooting.
- Booking and communication data is retained for contract performance and afterwards in accordance with statutory limitation and evidence requirements.
- Tax-relevant accounting records are generally retained for eight years; other statutory periods may be longer in individual cases.
- Data is deleted or anonymised when the relevant purpose and statutory retention duties no longer apply.
9. Your rights
- Access, correction, deletion, and restriction under Articles 15 to 18 GDPR.
- Data portability under Article 20 GDPR.
- Objection to processing based on legitimate interests under Article 21 GDPR.
- Complaint to the Berlin Commissioner for Data Protection and Freedom of Information.
10. Last updated
Last updated: August 2026.