Privacy Policy
Last updated July 2026
Information about personal data processing on the METAVITAL Booking platform.
I. Controller
The controller within the meaning of the GDPR and other data protection laws is:
METAVITAL GmbH
Tannenhof 47
22397 Hamburg
Germany
Phone: +49 40 412 63 85 – 00
Email: info@metavital.eu
Website: https://www.metavital.eu
Platform: METAVITAL Booking
II. Data protection officer
The controller’s data protection officer is:
DataCo GmbH
Dachauer Straße 65
80335 München
Germany
Phone: +49 89 7400 45840
Website: www.dataguard.de
III. General information on processing
1. Scope
We process personal data only as necessary to provide a functional booking platform and our services. Processing usually takes place on the basis of consent, unless obtaining consent is not possible and processing is permitted or required by law.
2. Legal bases
- Art. 6(1)(a) GDPR – consent
- Art. 6(1)(b) GDPR – contract / pre-contractual steps (e.g. booking, account, payments)
- Art. 6(1)(c) GDPR – legal obligation (e.g. retention under commercial/tax law)
- Art. 6(1)(f) GDPR – legitimate interests (e.g. IT security, abuse prevention)
3. Deletion and retention
Personal data are deleted or restricted once the purpose ceases to apply, unless statutory retention periods require otherwise. Specific retention periods are described in the sections below.
IV. Your rights
If we process your personal data, you are a data subject under the GDPR and may exercise, in particular:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- Complaint with a supervisory authority (Art. 77 GDPR)
V. Website provision and log files
When you use METAVITAL Booking, technical data are processed automatically (browser type/version, operating system, IP address, date/time, referrer and requested resources). These data may be stored in server or application logs. They are not combined with other profile data for marketing.
Legal basis: Art. 6(1)(f) GDPR. Session data end with the session; logs are typically deleted or anonymised after at most 31 days unless longer retention is needed to investigate security incidents.
VII. Registration and user account
When you create an account we process email, hashed password, name fields, optional phone number, address/billing data (including company VAT ID where applicable) and account preferences. Legal basis: Art. 6(1)(b) and (f) GDPR.
VIII. Appointments and events
For bookings we process the data needed to schedule and deliver the service (contact details, appointment, specialist, service/event data, notes, consents and status history). Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(a) where consent is collected. Relevant data may also be documented in our CRM.
IX. Messaging and voice messages
The messenger stores message content, metadata, attachments and technical transmission data to enable communication between clients and specialists. Legal basis: Art. 6(1)(b) GDPR.
X. Payments and invoices
Online payments are processed via Stripe and/or PayPal. We store transaction/status data and related order information. Invoicing may involve Lexware. EU VAT IDs may be checked via VIES. Legal bases: Art. 6(1)(b) and (c) GDPR.
XI. Email notifications
We send transactional emails (confirmations, reminders, verification codes, status updates) via SMTP. Legal basis: Art. 6(1)(b) and (f) GDPR.
XII. SMS notifications
If you provide a phone number and enable SMS (or use phone verification), data are transmitted to Infobip. Legal basis: Art. 6(1)(a) and/or (b) GDPR. You can disable SMS notifications in account settings where not required for verification.
XIII. Online meetings (Microsoft Teams)
Online appointments may use Microsoft Teams / Microsoft Graph for meeting links and calendar sync. Data may be transferred to third countries under appropriate safeguards. Legal basis: Art. 6(1)(b) and (f) GDPR.
XIV. Hosting
METAVITAL Booking is hosted on servers commissioned by us (generally in the EU/Germany). Server logs and uploaded files are processed to operate the platform. Legal basis: Art. 6(1)(f) GDPR.
XV. Processors and plugins
Key processors include Cloudflare Turnstile (bot protection), Stripe and PayPal (payments), Microsoft Graph/Teams, Infobip (SMS), IONOS/SMTP (email), VIES, Lexware, CentralStationCRM, Vimeo (landing videos) and optionally Google Ads/Tag Manager on landing pages with consent. See the Cookie Policy for cookie details.
XVI. Third-country transfers
Some providers may transfer data outside the EEA (including the USA). Where required, we rely on Art. 46 GDPR safeguards (e.g. Standard Contractual Clauses) and, where applicable, the EU-US Data Privacy Framework.
XVII. Changes
We may update this privacy policy to reflect legal or product changes. This policy applies specifically to METAVITAL Booking; other METAVITAL websites may have separate notices.