Privacy Policy

Data privacy statement

We take the protection of your data very seriously. We treat your personal data confidentially in accordance with the legal data protection regulations as stipulated in the General Data Protection Regulation as well as this Privacy Policy.

Responsible body
The responsible body for data processing is:
XClinical GmbH
Arnulfstr. 19
80335 Munich
+49 89 4522775 888

Data protection officer:
Jochen Lutz
+49 89 4522775 400

Rights of the person concerned
Natural persons have legal rights to personal data concerning them. To exercise your rights and for other queries about your personal data, you can always contact the data protection officer or the responsible body.
These rights are subject to conflicting statutory provisions.

Right to revoke your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke an existing consent at any time. To this end, an informal message to us by email is sufficient. The revocation does not affect the legality of the data processing carried out until the revocation.
Data processing operations that are for the purpose of fulfilling the business purpose under a contract and in relation to professional cooperation may be excluded from this revocation.

Right to information, transparency, blocking, deletion
You will receive information about your stored personal data and the underlying procedures at any time, without having to cite any reasons. You can block, correct or delete your data collected by us.

Right to complain
Furthermore, you have the right to file a complaint with the competent supervisory authority. The competent supervisory authority:

The Bavarian State Data Protection Officer
Dr. Thomas Petri
PO box 22 12 19
80502 Munich
Wagmüllerstr. 18
80538 Munich
Phone: 089/21 26 72-0
Fax: 089/21 26 72-50

Right to transfer data
You have the right to transfer data that we process automatically on the basis of your consent or in fulfillment of a contract, to yourself or to a third party in a standard, machine-readable format. Any data you want to transfer directly to another person in charge will only be transferred to the technically feasible extent.

Data processing
XClinical processes personal data in accordance with specified and documented procedures with the appropriately specified purpose. Only the minimum necessary data is collected to fulfill the purpose. If necessary, disclosure of this data to third parties will be made exclusively to the data processing contractor instead of supporting the fulfillment of the purpose. These data processing contractors are contractually bound to comply with data protection regulations.
There is no processing of data against the intended purpose or processing of personal data in advance.
XClinical only operates systems for the processing of personal data, whose security is ensured by appropriate technical and organizational measures.

Data collection on our website
Your personal data given by you is collected. This may be, e.g. data that you enter in a contact form.
Other, personally identifiable information of technical nature will be automatically collected by our IT systems when you visit the website. This data is automatically collected as soon as you enter our website.

a) Collected technical data
The provider of the pages automatically collects and stores information that your browser automatically transmits to us. This includes:
• Browser type and version
• Used operating system
• Referrer URL (website that refers you to our site)
• Host name of the accessing computer
• Time of the server request
• IP address
This data is not merged with other data sources. Data processing is governed by Art. 6 para. 1 lit. f GDPR (General Data Protection Regulation), which allows processing of data for fulfilment of a contract or pre-contractual measures.

b) Contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us in order to process the inquiry and in case we have follow-up questions. We will not share this information without your consent.
The processing of the data given in the contact form is therefore exclusively based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. To this end, an informal message to us by email is sufficient. The revocation does not affect the legality of the data processing operations carried out until the revocation.The information you provide in the contact form will remain with us until you request deletion, revoke your consent to storage, the deletion period of the process has elapsed or the purpose of the data storage is no longer applicable (for example, after your inquiry has been processed). Mandatory statutory provisions – especially retention periods – remain unaffected.

c) Job advertisements / online job applications
Your application data will be electronically collected and processed by us for processing the application. If your application is followed by the conclusion of an employment contract, then your data transmitted will be stored by us in your personnel records for the purpose of the usual organizational and administrative process according to the relevant legal requirements. In the event that your job application is rejected, the data transmitted by you is automatically deleted two months after announcement of the rejection. This does not apply if longer storage is necessary due to legal requirements (for example, the burden of proof according to the General Act on Equal Treatment), or if you have expressly consented to a longer storage in our database of potential candidates.

Analysis tools and advertising
Your surfing behavior may be statistically evaluated when you visit our website. This is done mainly using cookies and the so-called analysis programs. The analysis of your surfing behavior is anonymous; usually, the surfing behavior cannot be traced back to you.

a) Google Analytics
This website uses features of the web analysis service Google Analytics. Provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses so-called “Cookies”. These are text files that are stored on your computer and enable the analysis of the website used by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.
The Google Analytics cookies are stored pursuant to Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize its website and advertising.

– IP anonymization
We have activated the IP anonymization function on this website. As a result, your IP address will be truncated by Google within member states of the European Union or other parties to the Agreement on the European Economic Area prior to transmission to the United States. Only in exceptional cases will the full IP address be sent to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activities and to provide other services related to your website activity and Internet usage to the website operator. The IP address provided by your browser as part of Google Analytics will not be merged with other data from Google. For information about the functioning principle of IP anonymization, please visit:

– Browser plugin
You can prevent the storage of cookies by applying a corresponding setting of your browser software; however, please note that you may not be able to fully use all features of this website in this case. You may also opt out from Google’s collection and processing of the data, generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plugin available under the following link:

– Objection to data collection
You can prevent the collection of your data by Google Analytics by clicking on the following link. This sets an opt-out cookie that prevents the collection of your data on future visits to this website. If you want to prevent setting of cookies by, e.g. Google Analytics, you can set this up using these browser add-ons

– Demographic features from Google Analytics
This website uses the function “demographics features” from Google Analytics. This allows creation of reports that contain information on the age, gender and interests of the site visitors. These data come from interest-based advertising by Google and third-party visitor data. These data cannot be assigned to a specific person. You can disable this feature at any time through the ad settings in your Google Account, or generally prohibit the collection of your data by Google Analytics as outlined in the “Objection to data collection” section.
We do not evaluate demographic features.

b) Google AdWords and Google Conversion Tracking
This website uses Google AdWords. AdWords is an online advertising program of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”). As part of Google AdWords, we use the so-called conversion tracking. A cookie is set for the conversion tracking when you click on an ad placed by Google. Cookies are small text files that the web browser stores on the user’s computer. These cookies lose their validity after 30 days and are not used for the personal identification of the users. If the user visits certain pages of this website and the cookie has not yet expired, it can be recognized by both Google and us that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie. The cookies cannot be tracked through the websites of AdWords customers. The information gathered using the conversion cookie are used to generate conversion statistics for AdWords customers, who have opted for conversion tracking. Customers get to know the total number of users, who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive information that personally identifies users. If you do not want to participate in the tracking, you can opt-out from this by easily disabling the Google Conversion Tracking cookie via your internet browser under User preferences. You will not be included in the conversion tracking statistics.
The “Conversion cookies” are stored pursuant to Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize its website and advertising.

For further information about Google AdWords and Google Conversion Tracking, please refer to the privacy policy of Google at:
You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, block the acceptance of cookies for certain cases or all of them, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Plugins and tools

a) Google Web Fonts
This site uses so-called Web Fonts, provided by Google, for the uniform display of fonts. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.To do this, the browser you use must connect to Google’s servers. As a result, Google comes to know that our website has been accessed via your IP address. Google Web Fonts is used for consistent and attractive presentation of our online services. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If your browser does not support Web Fonts, a default font will be used by your computer.
For further information about Google Web Fonts, please visit and refer to Google’s privacy policy:

b) Google Maps plugin
We use a plugin of the Internet service Google Maps on our website. Google Maps is operated by Google Inc., headquartered in the USA, CA 94043, 1600 Amphitheatre Parkway, Mountain View. By using Google Maps on our website, information about the use of this website and your IP address will be transmitted to a Google server in the USA and also stored on this server. We neither have any knowledge of the exact content of the transmitted data nor about its use by Google. In this context, the company denies any merging of data with information from other Google services and the collection of personal data. However, Google may transmit the information to third parties. If you disable Javascript in your browser, you prevent the operation of Google Maps. This also prevents you from viewing a map on our website. By using our website, you consent to the collection and processing of the information described by Google Inc. For further information about the privacy policy and terms of use of Google Maps, please visit:

Data security

SSL or TLS encryption
This site uses an SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as requests via the contact form, which you send to us, acting as the site operator. An encrypted connection can be recognized by the change in the browser’s address bar from “http://” to “https://” as well as the lock icon in your browser’s address bar.
If SSL or TLS encryption is enabled, the data that you submit to us via the contact form cannot be read by third parties.

Update and amendment to this data privacy statement
This version of the data privacy statement is dated May 22 2019.