Privacy Policy

Privacy Policy

Last updated: 16 June 2026

1. Controller

The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (“GDPR”) is:

Dr. med. Mussa Arvani, MBA
MAestro Medical Solutions

Email: connect@maestroms.net

No data protection officer has been appointed.

2. General Information on Data Processing

We process personal data only to the extent necessary to provide this website, respond to enquiries, arrange appointments and provide our professional services.

Depending on the specific processing activity, the legal basis is:

  • your consent pursuant to Article 6(1)(a) GDPR;

  • the performance of a contract or steps taken prior to entering into a contract pursuant to Article 6(1)(b) GDPR;

  • compliance with a legal obligation pursuant to Article 6(1)(c) GDPR; or

  • our legitimate interests pursuant to Article 6(1)(f) GDPR, particularly the secure, reliable and commercially appropriate operation of this website and communication with interested parties.

Personal data will not be sold.

3. Website Hosting and Technical Provision

This website is hosted using the website platform provided by:

Squarespace Ireland Limited
Squarespace House
Ship Street Great
Dublin 8, D08 N12C
Ireland

When you access this website, technical data may automatically be processed in order to display the website and ensure its security and stability. This may include:

IP address;

date and time of access;

requested page or file;

referrer URL;

browser type and version;

operating system;

device information;

access status; and

transferred data volume.

The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of the website.

Squarespace processes certain personal data on our behalf as a service provider. Squarespace may also process certain technical or usage-related information under its own responsibility in accordance with its own privacy information.

Data may be processed by Squarespace companies or service providers outside the European Economic Area, including in the United States. Where required, such transfers are based on an adequacy decision, participation in the EU–US Data Privacy Framework, European Commission Standard Contractual Clauses or other legally recognised safeguards.

4. Cookies and Similar Technologies

This website uses cookies and similar technologies.

Cookies are small data files stored on your device or information accessed from your device. They may be required for the technical operation of the website or used for analytics and performance purposes.

Essential Cookies

Essential cookies are required for functions such as:

website security;

navigation;

session management;

display settings; and

storage of your cookie preferences.

The storage of or access to information on your device is based on Section 25(2) of the German Telecommunications Digital Services Data Protection Act (“TDDDG”). Any subsequent processing of personal data is based on Article 6(1)(f) GDPR.

Analytics and Performance Cookies

Analytics and performance cookies help us understand how visitors use the website, which pages are accessed and how the website can be improved.

These cookies and related technologies are used only after you have given your consent through the cookie banner. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.

You may refuse non-essential cookies or withdraw your consent at any time through the Cookie Settings link on the website. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

5. Squarespace Analytics

We may use Squarespace Analytics to obtain statistical information about the use of this website.

Depending on your cookie selection and the technical configuration, the following information may be processed:

visited pages;

time and duration of visits;

approximate geographic region;

browser and device information;

referring website;

traffic source; and

interactions with website content.

The purpose of this processing is to understand website usage, improve content and optimise the presentation of our services.

Where consent is required, processing is based on Article 6(1)(a) GDPR and Section 25(1) TDDDG. Otherwise, strictly necessary technical processing is based on Article 6(1)(f) GDPR.

You can withdraw your consent through the website’s Cookie Settings.

6. Contact by Email or Contact Form

You may contact us by email or through the contact form available on this website.

In this context, we may process:

your name;

your email address;

your telephone number, if provided;

your company or professional role, if provided;

the content of your message; and

any other information you voluntarily provide.

The data is processed for the purpose of responding to your enquiry and communicating with you.

Where your enquiry relates to a potential or existing contractual relationship, processing is based on Article 6(1)(b) GDPR. For general enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in responding to enquiries and maintaining professional communication.

Your data will be deleted once the enquiry has been fully resolved, unless continued storage is necessary for contractual, tax, accounting, legal defence or statutory retention purposes.

Please do not submit patient data, medical records, health information or other special categories of personal data through the contact form or by ordinary email.

7. Appointment Scheduling via Calendly

This website contains a link to the appointment scheduling service Calendly, provided by:

Calendly, LLC, United States

When you click the appointment-booking link, you leave this website and are redirected to Calendly. No data is transferred to Calendly through the external link before you actively click it.

When arranging an appointment, Calendly may process information such as:

your name;

your email address;

selected date and time;

time zone;

information entered in the booking form;

IP address;

browser and device information; and

technical usage data.

The processing serves to arrange, manage and confirm appointments.

The legal basis is Article 6(1)(b) GDPR where the appointment relates to pre-contractual or contractual communication. In other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in providing an efficient appointment-booking process.

Calendly processes data in the United States and potentially in other countries. Calendly states that transfers from the European Economic Area are based on the EU–US Data Privacy Framework and, where required, Standard Contractual Clauses approved by the European Commission.

Calendly is responsible for any additional processing performed on its own behalf. Further details are available in Calendly’s privacy information.

8. LinkedIn Links

This website contains links to LinkedIn profiles or company pages.

The LinkedIn service for users in the European Economic Area is generally provided by:

LinkedIn Ireland Unlimited Company
Wilton Plaza
Wilton Place
Dublin 2
Ireland

The links are not embedded social media plug-ins. No personal data is transferred to LinkedIn merely because you visit this website.

If you click a LinkedIn link, you will be redirected to LinkedIn. LinkedIn may then process information about your visit, particularly if you are logged into a LinkedIn account.

The subsequent processing is carried out under LinkedIn’s own responsibility and is governed by LinkedIn’s privacy information.

9. Recipients of Personal Data

Personal data may be disclosed only where necessary to:

hosting, website and IT service providers;

appointment-booking providers;

email and communication service providers;

professional advisers, such as tax advisers, lawyers or accountants;

public authorities or courts where legally required; or

other recipients where you have consented to the disclosure.

Where service providers process personal data on our behalf, appropriate data-processing agreements are concluded where required.

10. International Data Transfers

Some service providers used for this website are based outside the European Economic Area or use service providers located in third countries.

Where personal data is transferred to a country outside the European Economic Area, the transfer takes place only where an adequate level of protection is ensured, particularly through:

an adequacy decision of the European Commission;

participation in the EU–US Data Privacy Framework;

European Commission Standard Contractual Clauses;

additional technical and organisational safeguards; or

another legally permitted transfer mechanism.

11. Storage Periods

Personal data is stored only for as long as necessary for the respective purpose.

Longer storage may take place where required by:

statutory retention obligations;

tax or commercial law;

contractual documentation requirements;

the establishment, exercise or defence of legal claims; or

applicable limitation periods.

Once the relevant purpose and any applicable retention obligations no longer apply, the data will be deleted or anonymised.

12. Your Rights

Subject to the applicable legal requirements, you have the following rights:

Right of access under Article 15 GDPR;

Right to rectification under Article 16 GDPR;

Right to erasure under Article 17 GDPR;

Right to restriction of processing under Article 18 GDPR;

Right to data portability under Article 20 GDPR;

Right to object under Article 21 GDPR; and

Right to withdraw consent under Article 7(3) GDPR.

Where processing is based on Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.

Where processing is based on consent, you may withdraw your consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.

To exercise your rights, please contact:

connect@maestroms.net

We may request appropriate information to verify your identity before responding to a request.

13. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.

The supervisory authority responsible for North Rhine-Westphalia is:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany

Email: poststelle@ldi.nrw.de

You may also contact another supervisory authority responsible for your place of residence, workplace or the location of the alleged infringement.

14. Automated Decision-Making

We do not use personal data collected through this website for automated decision-making, including profiling, within the meaning of Article 22 GDPR.

15. Data Security

We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

This website uses encrypted communication through TLS/SSL. Nevertheless, data transmission over the internet cannot be guaranteed to be completely secure.

16. Changes to this Privacy Policy

We may update this Privacy Policy where changes to the website, the services used or applicable legal requirements make this necessary.

The current version is published on this website and identified by the date stated at the beginning of the policy.