Privacy Policy

Last updated: 17 August 2026

1. Controller

The controller responsible for the processing of personal data on this website is:

Fresenius Medical Care Data Solutions GmbH
Krausenstraße 9-10
10117 Berlin
Germany

Commercial register: Amtsgericht Charlottenburg, HRB 216288 B
VAT ID: DE811127677
Managing Directors: Armin Heber, Sebastian Kehrlein

Email: sabine.jesse@freseniusmedicalcare.com
Telephone: +49 6172 609-0

2. Data Protection Officer

You can reach our Data Protection Officer at:

datenschutzbeauftragter@freseniusmedicalcare.com

3. Scope

This policy applies to the website www.fmc-data-solutions.com operated by Fresenius Medical Care Data Solutions GmbH. It does not apply to other websites of the Fresenius group, even where these are linked from this website. Those websites are operated by their respective controllers and have their own privacy policies.

4. What this website does and does not do

This is an informational corporate website. It does not contain contact forms, registration forms or newsletter sign-ups. It does not process job applications, does not use web analytics or measurement tools to analyse visitor behaviour, does not use advertising, retargeting or conversion tracking, does not embed video players, social media plugins or share buttons, and does not offer user accounts or log-ins. No profiles are created, and no identifiers are assigned across sessions or devices.

The processing described below is limited to what is technically necessary to deliver the website, plus the third-party services listed in section 7. The web font service described in section 7.1 records aggregate usage figures for licensing purposes; this is described there in full.

5. Server log files and hosting

5.1 Log data

When you access this website, your browser automatically transmits information which is recorded in server log files:

  • IP address of the requesting device
  • date and time of the request
  • name and URL of the requested resource
  • referrer URL, where applicable
  • browser type and version, operating system
  • HTTP status code and volume of data transferred

Purpose: delivering the website, ensuring stability and operational security, detecting and investigating attacks and misuse.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of this website. This data is not merged with other data sources and is not used to identify individual visitors.

Retention: 7 days

5.2 Hosting

This website is hosted by:

Mittwald CM Service GmbH & Co. KG
Königsberger Straße 4–6
32339 Espelkamp
Germany

The servers are located in Germany. Mittwald CM Service GmbH & Co. KG processes the data described above exclusively on our behalf and in accordance with our instructions. We have concluded a data processing agreement pursuant to Art. 28 GDPR with Mittwald CM Service GmbH & Co. KG.

6. Cookies and consent management

6.1 How consent works on this website

We use a consent management platform to obtain, record and allow you to withdraw your consent for cookies and comparable technologies that are not strictly necessary.

Cookies and comparable technologies that are not strictly necessary are not set until you have given your consent. The web fonts described in section 7.1 are not covered by consent; they are loaded on the basis of Art. 6(1)(f) GDPR, and section 7.1 sets out what this involves.

You can change or withdraw your consent at any time via the Cookie Settings link in the footer of every page, which opens the privacy preference centre. Withdrawing consent is as straightforward as giving it and has effect for the future.

6.2 Consent management platform

To operate the consent banner and preference centre we use the OneTrust platform provided by OneTrust, LLC, 1200 Abernathy Rd NE, Atlanta, GA 30328, USA.

The banner script is loaded from the OneTrust content delivery network. In doing so, your IP address is transmitted to OneTrust. The following cookies are set:

OptanonConsent
Stores which cookie categories you have consented to. Duration: 12 months.

OptanonAlertBoxClosed
Records that you have interacted with the consent banner. Duration: 12 months.

Legal basis: § 25(2)(2) TDDDG in conjunction with Art. 6(1)(c) and (f) GDPR. Storing your consent decision is strictly necessary in order to comply with our obligation to document consent and to avoid asking you again on every visit. These cookies therefore do not themselves require consent.

Third-country transfer: OneTrust, LLC is based in the USA. The transfer is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR). OneTrust, LLC is certified under the framework.

Further information: https://www.onetrust.com/privacy/

6.3 Cookie categories

  • Strictly necessary (no consent required): consent cookies, session integrity
  • Functional (consent required): this category exists in the preference centre but currently contains no cookies
  • Performance (consent required): not used on this website
  • Targeting (consent required): not used on this website

A complete, current list of the cookies used is available in the preference centre.

7. Third-party services

7.1 Adobe Fonts

This website uses web fonts provided by Adobe Inc., 345 Park Avenue, San Jose, CA 95110, USA, delivered via the domains use.typekit.net and p.typekit.net.

When a page is loaded, your browser requests the font files directly from Adobe’s servers. In doing so, your IP address, browser type and the referring page are transmitted to Adobe. Adobe additionally records the number of page views in which the fonts are used; this serves to account for our font licence. According to Adobe, no cookies are set for either purpose. The files are typically delivered from a European node of Adobe’s content delivery network; Adobe Inc. as the recipient is nevertheless established in the USA.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the consistent typographic presentation of our corporate identity.

Third-country transfer: Adobe Inc. is based in the USA. The transfer is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Adobe Inc. is certified under the framework.

Adobe privacy policy: https://www.adobe.com/privacy/policy.html

7.2 Services we do not use

For the avoidance of doubt: this website does not use Google Analytics, Google Tag Manager, Google Fonts, embedded video players, social media plugins, Facebook or Meta pixels, LinkedIn Insight Tag, or any comparable analytics or advertising technology. No content is loaded from third-party content delivery networks other than those named in sections 6.2 and 7.1.

8. Careers and job applications

We do not accept or process job applications through this website.

The link on our careers page takes you to the Fresenius Medical Care job portal at jobs.freseniusmedicalcare.com. That portal is operated by a different entity within the Fresenius Medical Care group and is subject to its own privacy policy. Once you follow the link, the processing of your data is governed by the information provided there.

9. External links

This website contains links to external websites, including websites operated by other entities within the Fresenius group. We have no influence over the content of those websites or over how their operators process personal data. Following a link means leaving the scope of this privacy policy.

10. Recipients of personal data

We disclose personal data only where this is necessary and lawful:

  • to the processors named in this policy, on the basis of a data processing agreement pursuant to Art. 28 GDPR
  • to the third-party providers named in section 7, who act as independent controllers for their own purposes
  • to public authorities and courts, where we are legally obliged to do so

We do not sell personal data and do not disclose it for third-party advertising purposes.

11. Third-country transfers

Where personal data is transferred to countries outside the European Economic Area, we ensure an adequate level of protection through one of the following mechanisms:

  • an adequacy decision of the European Commission pursuant to Art. 45 GDPR, including the EU-U.S. Data Privacy Framework for certified US recipients
  • Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, supplemented where necessary by additional technical and organisational measures following a transfer impact assessment

The specific mechanism applicable to each recipient is stated in sections 6.2 and 7. You may request a copy of the relevant safeguards using the contact details in section 1.

12. Retention

We retain personal data only for as long as necessary for the purposes described in this policy, or for as long as statutory retention obligations require.

Server log data is deleted after 7 days. Consent records are retained for the duration of the consent plus the period required to demonstrate compliance with Art. 7(1) GDPR. Cookie durations are stated in sections 6 and 7.

13. Your rights

You have the following rights in relation to personal data we process about you:

  • Access (Art. 15 GDPR), to obtain confirmation as to whether we process your data, and a copy of that data
  • Rectification (Art. 16 GDPR), to have inaccurate data corrected and incomplete data completed
  • Erasure (Art. 17 GDPR), to have your data deleted where one of the grounds in Art. 17(1) applies
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR), to receive data you provided in a structured, machine-readable format
  • Objection (Art. 21 GDPR), to object at any time to processing based on Art. 6(1)(f) GDPR, on grounds relating to your particular situation. This includes the loading of web fonts described in section 7.1
  • Withdrawal of consent (Art. 7(3) GDPR), to withdraw consent at any time with effect for the future. For cookies, use the Cookie Settings link in the footer of every page

To exercise any of these rights, contact us using the details in section 1 or contact our Data Protection Officer directly.

We will respond within one month of receipt. Where a request is complex or where we receive a large number of requests, this period may be extended by up to two further months; we will inform you of any extension and the reasons for it.

14. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement.

The authority competent for the controller is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin
Germany
https://www.datenschutz-berlin.de

15. Automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR on this website.

16. Minors

This website is not directed at children or young people under the age of 16. We do not knowingly collect personal data from individuals in this age group. If you believe that a child has provided us with personal data, please contact us using the details in section 1.

17. Data security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse. This includes transport encryption via TLS for all connections to this website.

18. Changes to this policy

We may amend this privacy policy to reflect changes in our website, in the services we use, or in the applicable legal framework. The version published here always applies. The date of the current version is stated at the top of this document.