OrthoMetiQHandoutDownload
Menu
🇬🇧 EN
🇩🇪 Deutsch🇬🇧 English
OrthoMetiQ

Privacy Policy

Transparent information on data processing for the OrthoMetiQ website, OMQ WebChat, My OrthoMetiQ, WebPlanner, mobilePlanner iPad app, support/tickets, InAppMessages and push, appointment booking and Demo Room, service communications, protected case workflows, OMQ Service/Service Token offers, payments and technical security.

OMQ-PRIVACY v1.6 · dated 07.09.2026

Protected access

My OrthoMetiQ, WebPlanner and mobilePlanner access are permission-based and protected by server-side checks.

Health data

Medical images and DICOM data are treated as particularly sensitive data where they contain patient information.

Payment processing

Paid plans use an external payment service; full card data is not stored by OrthoMetiQ.

No advertising analytics

No external analytics, advertising pixels, captcha or font providers are used in ordinary website operation. The payment component is activated only in the deliberately started purchase flow; Demo Room STUN is function-specific.

Overview

This policy is tailored to the current OrthoMetiQ website, OMQ WebChat, WebPlanner and mobilePlanner architecture, including My OrthoMetiQ, protected case workflows, InAppMessages, optional APNs push delivery, WebPlanner licence handling, purchase/payment processing and optional DICOM/PACS-related functions.

This privacy policy reflects the implemented technical functions. Operational details such as hosting contracts, data processing agreements, deletion routines and payment-provider configuration must be kept consistent with the actual live operation.

1. Controller and contact

Controller for processing carried out by OrthoMetiQ for its own purposes is OrthoMetiQ a PESL.ME company Brand / PESL.ME | Mediengestaltung (Bastian Pesl), Mühlenstr. 36, 93176 Beratzhausen, Germany. Contact: info@orthometiq.com, telephone +49 (0) 9493 8289674.

Where OrthoMetiQ processes personal data solely on documented instructions of a business customer, that customer remains controller and OrthoMetiQ acts as processor under the separately documented DPA.

2. Scope

This privacy policy covers orthometiq.com, My OrthoMetiQ, registration/login, protected case workflows, OMQ FileDrop, WebPlanner, mobilePlanner, OMQ Service/Service Token requests and formal offers, support/tickets, InAppMessages/push, appointment booking and Demo Room, contract/invoice documentation, service communications and technical security.

The paid professional services are directed at business customers and professional organisations. Privacy rights of natural persons remain unaffected.

4. Website access and server logs

When the website is accessed, technically required connection and log data may be processed, including IP address, time, requested resource, browser/operating-system information, referrer where transmitted, response status and security/error information.

Purposes are delivery, stability, error diagnosis, abuse prevention and security. The legal basis is Art. 6(1)(f) GDPR. Logs are retained only for the operational/security period required for these purposes and are then deleted or anonymised unless an incident or statutory duty requires longer retention.

5. Sessions, cookies and local browser storage

OrthoMetiQ uses technically necessary first-party session cookies and comparable browser storage for login, protected areas, explicitly started WebChat/Demo Room sessions, technical preferences and WebPlanner work states. The portal session cookie uses HttpOnly and SameSite protection and, when transmitted over HTTPS, the Secure attribute.

Storage/access in the terminal device is limited to functions required for a service explicitly requested by the user; where applicable in Germany this is based on Section 25(2) no. 2 TDDDG. Optional analytics or advertising technologies are not used in ordinary website operation. The external payment component is loaded only after a deliberate purchase step.

6. Contact, OMQ WebChat and support

If you contact OrthoMetiQ by form, email, WebChat, ticket or another support channel, the information you submit and technical case metadata are processed to answer, document and secure the request.

The legal basis is Art. 6(1)(b) GDPR where the request relates to a contract or pre-contractual measures and otherwise Art. 6(1)(f) GDPR. Support records are retained as long as needed for case handling, proof and security and then deleted subject to statutory retention duties.

7. Registration, customer account and authentication

Customer accounts may contain name, email address, hashed password, company/practice, telephone, country, language, speciality, customer number, access/licence status and account/security history.

Processing is necessary for account administration, authentication, access control, licence management, security and contract performance under Art. 6(1)(b) and (f) GDPR. Passwords are not stored in plain text.

8. Business-customer and legal-version confirmation

Before professional trial or purchase workflows, OrthoMetiQ may record that the user confirmed acting as an entrepreneur/professional organisation, agreed to incorporation of the current Terms, acknowledged the Privacy Policy and, where Article 28 GDPR processing applies, acknowledged the DPA/TOMs. The stored evidence may include timestamp, account, language and the Terms, Privacy and DPA version identifiers.

This processing serves contract formation, fulfilment of electronic-commerce duties and proof of the agreed legal basis under Art. 6(1)(b), Art. 6(1)(c) where applicable and Art. 6(1)(f) GDPR.

9. Trial, licence and usage status

Trial requests, approvals, licence plan/status, start/end dates and technical usage/status events are processed to provide and secure protected WebPlanner/mobilePlanner access. The regular trial period is 3 days. Inactivity information may be used to apply the documented 48-hour trial activity rule and to determine whether trial access can be deactivated, reactivated or deleted/restricted when no longer required.

The legal bases are Art. 6(1)(b) and (f) GDPR. Usage data are not used for advertising profiling.

10. Protected case upload and planning workflows

The standard OrthoMetiQ case-upload workflow is designed for anonymised material and requires the user to confirm anonymisation. Depending on the function, case ID, account assignment, planning type, side, manufacturer/template information, notes, filenames, image/DICOM data, results and status data may be processed.

If material nevertheless contains personal or health data, the customer must have a lawful basis and all necessary permissions. Where OrthoMetiQ acts solely on customer instructions, the DPA governs that processing. A workflow in which OrthoMetiQ determines purposes or essential means beyond a processor role requires a separate role/legal-basis assessment before non-anonymised health data are used.

11. WebPlanner, mobilePlanner, cloud saving and exports

Planner functions may process imported images, DICOM metadata, measurements, planning steps, implant/template data, notes, screenshots, reports and export files. Browser-local storage or IndexedDB may be used for technical settings and temporary work states; cloud saving is used only where the corresponding function is selected.

Exported files are under the responsibility of the customer/user after download. Users must verify whether exported files contain personal or health data before further disclosure.

12. Optional PACS / DICOMweb interfaces

Where configured by a professional customer, OrthoMetiQ may process endpoint/configuration data, DICOMweb URLs, protected access information and study/series/image metadata required for the interface.

The customer operating or authorising the PACS/DICOMweb connection is responsible for the legal basis and local access authorisations. A customer-controlled PACS does not become an OrthoMetiQ subprocessor merely because an interface is configured.

13. Purchases, subscriptions and payment processing

For paid plans, the selected external payment service may receive data required for purchase processing, payment security and fraud prevention, such as account/contact data, billing data, selected plan, amount, currency and transaction/subscription status. Full payment-card data are not stored on OrthoMetiQ servers.

Depending on the specific payment function, the payment service may act as processor or independent controller. The legal bases for OrthoMetiQ are Art. 6(1)(b), Art. 6(1)(c) for accounting/retention duties and Art. 6(1)(f) for payment security.

14. Contract generator, OMQ Service offers, invoices and OMQ FileDrop

For electronic contract and offer evidence OrthoMetiQ processes customer master/address data, customer, offer and contract identifiers, plan or Service Token quantity, price/billing, purchase/service date, purchase reference, document/version identifiers, offer acceptance/signature status, invoice number, hashes, FileDrop assignment and download/status history. Contract, offer and invoice PDFs are stored in protected private server storage or provided through the designated protected communication channels.

Contract and offer documents are version snapshots. Formal OMQ Service Token offers record in particular offer number, validity, quantity/price, dispatch/acceptance status and the legal-document versions documented for the offer. Accounting vouchers, including invoices, are retained for the statutory period applicable to booking records; under Section 147(3) AO this is currently eight years. Other business correspondence and proof records are retained only for the applicable statutory or limitation period. Patient or health data are not intended for offer, contract or invoice documents.

15. Transactional email and service communications

Account activation, password reset, security, licence, purchase/contract, FileDrop, support and comparable operational messages may be sent by email or in-app channels. These are not advertising merely because they relate to the service.

Marketing/newsletter messages are sent only where a separate legal basis exists, in particular consent where required. Consent can be withdrawn for the future without affecting processing already carried out lawfully.

16. InAppMessages, push and app integrity

The mobilePlanner may use InAppMessages and, where enabled by the user, push notifications. Push delivery can involve device/push tokens and message metadata through the platform push infrastructure. Apple App Attest/DeviceCheck can be used to verify app integrity and prevent abuse.

Push permission can be changed in device settings. Security/integrity processing is based on Art. 6(1)(f) GDPR; contract-related delivery may additionally be based on Art. 6(1)(b).

17. Appointment booking and Demo Room

For demo appointments OrthoMetiQ processes the booking/contact data entered and the selected appointment. Demo Room may process participant name/identifier, room/session metadata and technical connection information. Configured STUN services may be contacted solely to establish WebRTC connectivity.

Processing is based on Art. 6(1)(b) GDPR for requested demos/pre-contractual measures and Art. 6(1)(f) for secure technical operation.

18. Recipients and processors

Personal data are disclosed only where required for the relevant purpose, permitted by law or requested by the user. Recipient/processor categories can include hosting/server infrastructure, transactional email infrastructure, payment infrastructure, technical maintenance/support providers and platform services used for push/app integrity or function-specific WebRTC connectivity.

Processors are bound in accordance with Art. 28 GDPR where required. Customer-controlled systems and recipients designated by the customer are handled according to the relevant customer instruction and role allocation.

19. International transfers

Processing within the EU/EEA is preferred. Where use of a required technical service results in a transfer to a third country, the transfer is made only in accordance with Chapter V GDPR, for example on the basis of an applicable adequacy decision or appropriate safeguards.

The concrete transfer situation depends on the service actually activated and the provider configuration at the relevant time. Information about the safeguards used for a specific transfer and, where legally provided, how to obtain a copy or further information can be requested at info@orthometiq.com.

20. Security

OrthoMetiQ uses technical and organisational measures appropriate to the risk, including authenticated access, server-side permission checks, protected sessions, private storage areas, access/expiry checks for protected downloads, security logging and operational update/backup processes.

No internet service can guarantee absolute security. Security measures are reviewed and adjusted in light of risk, system changes and security events.

21. Retention and deletion

Data are retained only as long as necessary for the stated purpose, contract handling, proof, security or a statutory retention duty. Accounts and operational data are deleted or restricted when no longer required, subject to unresolved cases and statutory retention. Security logs are retained for the shortest period compatible with security and incident investigation.

Accounting vouchers are retained for the statutory period applicable to them (currently eight years under Section 147(3) AO). Backups are removed by the operational overwrite/retention cycle; data already deleted from the active system are not restored for normal productive use.

22. Data-subject rights and complaint

Subject to the statutory conditions, data subjects have rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent for the future. There is no automated decision-making within the meaning of Art. 22 GDPR producing legal or similarly significant effects.

A complaint may be lodged with a supervisory authority. The supervisory authority responsible for private-sector entities at the provider location is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

23. Special-category / health data

Medical images, DICOM data and patient-related information may constitute health data under Art. 9 GDPR. Such data must not be submitted merely because a technical upload is possible. The responsible customer must determine the lawful basis, necessity, data minimisation and required safeguards before processing.

Where OrthoMetiQ acts as processor, it processes such data only on documented instructions and under the DPA. Where anonymisation is sufficient for the purpose, anonymised data should be used.

24. Requirement to provide data

Master/contact/account/address/order/payment-status data required in the relevant mandatory field or purchase process are contractually required, or necessary for pre-contractual steps, contract conclusion, authentication, service delivery or invoicing. Without the required information, the relevant process or access may not be provided or completed.

Optional information is not a condition of the contract unless it becomes necessary for an expressly requested additional function. Patient or health data are not required for account creation, plan purchase, contract evidence or invoicing. Data minimisation applies to professional workflows; where anonymised data are sufficient, personal health data should not be submitted.

25. Data sources and roles where data are not collected directly

Where OrthoMetiQ acts as controller and receives personal data other than directly from the data subject, those data may in particular originate from a business customer, its authorised contacts/users or a technical service initiated by the user. The data categories are generally limited to those described in this Policy for the relevant process.

Where OrthoMetiQ acts solely as processor, transparency towards data subjects generally remains the responsibility of the controller/customer; OrthoMetiQ assists within the DPA and applicable legal duties.

26. Versioning and updates

This Privacy Policy is updated when legal requirements, technical functions or material processing operations change. The current version is published on the website.

For contract evidence, the Privacy version documented for the relevant transaction is stored as a version snapshot; later website versions do not retroactively change that historical record.