Privacy policy
Booking system of AionX Longevity UG — as of July 2026.
1. Controller
AionX Longevity UG (haftungsbeschränkt), Adalharstraße 42, 85391 Allershausen, Germany, email: info@aionxlongevity.com, phone: +49 176 79222303. This privacy policy covers the booking system (buchung.aionxlongevity.com); the privacy policy of our main site www.aionxlongevity.com/datenschutz applies in addition.
2. Data we process
Account data (name, email, phone, address), booking and appointment data, payment and invoice data and — with your explicit consent (Art. 9(2)(a) GDPR) — health information from the patient intake form. Health data is additionally stored encrypted (AES-256); every access by our team is logged.
3. Purposes and legal bases
Appointment management and contract fulfilment (Art. 6(1)(b) GDPR), statutory retention obligations for invoices (Art. 6(1)(c) GDPR, §§ 147 AO, 257 HGB), safety and suitability screening prior to HBOT based on your consent (Art. 9(2)(a) GDPR), appointment reminders by email (Art. 6(1)(b) GDPR).
4. Processors and recipients
Supabase (database & authentication, Frankfurt/EU data centre), Vercel (hosting), Stripe (payment processing; receives no health data), Brevo/Sendinblue (email, EU). Data processing agreements are in place with all providers. Health data is never shared with third parties.
5. Retention
Invoices and booking records: 10 years (statutory retention). Account and health data: until you withdraw consent or delete your account; upon deletion, health data is erased completely and remaining personal data is anonymized.
6. Cookies
The booking system uses strictly necessary cookies only (login session, language preference). There is no tracking and no advertising; therefore no consent is required.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw any consent at any time with effect for the future. Contact info@aionxlongevity.com. Supervisory authority: Bavarian Data Protection Authority (BayLDA), Ansbach.