Privacy Policy
1. Controller
Manuel Jean-Paul Lepage
Groussgaass, 10 L-8523 Beckerich, Luxemburg
E-mail: info@praxisgunvald.com
Website: praxisgunvald.com
No separate data protection officer has been appointed. The controller is your point of contact for data protection matters.
2. Scope and legal bases
This notice explains how personal data are processed when you visit this website, use the contact form and the website chat and—where enabled—when Google Analytics 4 and Google Maps are used. The legal bases are the General Data Protection Regulation (GDPR), the Law of 1 August 2018 on data protection in Luxembourg, and the ePrivacy rules on cookies.
3. Hosting and processing on our behalf (Wix)
This website is operated via the Wix platform (Wix.com Ltd., Tel Aviv). Wix processes data in distributed data centres and uses sub-processors. A data processing agreement (DPA) is in place with Wix. Transfers to third countries take place solely in accordance with the GDPR, in particular using Standard Contractual Clauses (SCCs) and—where applicable—EU Commission adequacy decisions.
4. Processing activities in detail
4.1 Visiting the website (server logs)
Data processed: IP address, date and time of access, pages viewed, referrer, browser used, operating system, error codes
Purposes: Provision of the website, stability and security, detection of misuse and attacks
Legal basis: legitimate interests (Art. 6(1)(f) GDPR)
4.2 Cookies and consent banner
We use a consent banner. Non-essential cookies (e.g. for statistics/analytics and maps via Google Maps) are set only after you have given consent; you can withdraw or adjust your choices at any time via the “Cookie settings” in the banner. Essential cookies are required for operation and security.
Note: The current full cookie list with purpose, provider and storage period is shown in the cookie banner.
4.3 Google Analytics 4 (if enabled; only with consent)
Provider: Google Ireland Limited, Dublin, Ireland
Categories of data: online identifiers, device/browser information, page views, events, approximate location (derived from technical signals), referrer
Purposes: audience measurement and analysis of website use
Legal basis: consent (Art. 6(1)(a) GDPR) via the cookie banner. Without your consent, Google Analytics is not loaded
Retention: event/user data are typically retained in the Analytics settings for 2 or 14 months; aggregated reports may persist longer
Recipients and international transfers: Google group companies; where applicable, transfers to the USA based on recognised safeguards
Withdrawal: you can withdraw consent at any time via the cookie settings on this website
4.4 Google Maps (if enabled; only with consent)
When the map is displayed, technical data such as your IP address and device/browser information are transmitted to Google; Google may use cookies and similar technologies for this. The map loads only after you have given consent.
Purpose: display of interactive maps and directions
Legal basis: consent (Art. 6(1)(a) GDPR)
International transfers: possible; recognised safeguards are used
4.5 Contact form
Data processed: name, e-mail address, message, optionally telephone number and other voluntary information
Purposes: handling enquiries, scheduling appointments, follow-up queries
Legal bases: pre-contractual communications and/or performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in efficient communication (Art. 6(1)(f) GDPR)
Important: Please do not send sensitive information via the form (e.g. detailed information on diagnoses, findings, prior conditions). If, by exception, you voluntarily provide such information, we process it solely on the basis of your explicit consent (Art. 9(2)(a) GDPR) and only for the stated purpose
4.6 Website chat
Data processed: chat content, timestamps, optionally name/e-mail (voluntary), usage and metadata
Purposes: direct communication, prompt handling of enquiries, appointment arrangements
Legal bases: Art. 6(1)(b) and (f) GDPR
Note on sensitive data: Please also avoid providing extensive health or other sensitive data in the chat; if you do so voluntarily, section 4.5 applies (explicit consent)
4.7 E-mail and telephone
Data processed: communication and metadata (e.g. sender, time), conversation/message content
Legal bases: Art. 6(1)(b) and (f) GDPR
5. Recipients of the data
Wix as processor, including listed sub-processors; where applicable, IT service providers bound by confidentiality and data-processing terms; public authorities where there is a legal obligation. We do not disclose data for advertising purposes.
6. International transfers
Where required for service provision, data may be transferred to countries outside the EEA. Such transfers take place only with the safeguards provided by law, in particular SCCs and—where applicable—EU Commission adequacy decisions.
7. Retention
Server logs are generally stored for up to 30 days; longer in the event of security-relevant incidents.
Contact/chat enquiries are kept until final handling and then deleted in line with statutory retention and limitation periods; as a rule, up to three years after last contact.
Cookies are stored according to the durations shown in the banner or until you withdraw consent.
For Google Analytics, the retention periods in section 4.3 apply.
8. Security
We implement technical and organisational measures to ensure a level of security appropriate to the risk (TLS/HTTPS, access restrictions, deletion and authorisation concepts). Wix applies additional security measures at infrastructure and application level.
9. Obligation to provide data
Certain technical data are required for the operation of the website. Details in the contact form/chat are necessary to handle your request. There is no statutory obligation to provide further information.
10. Automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
11. Your rights
Subject to the statutory conditions, you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(e) or (f) GDPR. You can withdraw any consent you have given at any time with effect for the future.
To exercise your rights, a simple message to the contact details above is sufficient.
Supervisory authority: Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg, e-mail: info@cnpd.lu.
12. Processing of sensitive information outside the website
We are a health practice for clients—not a medical doctor’s practice and not a medical facility. Our services focus on prevention and advice and do not replace medical diagnosis or treatment. Health information that you provide to us outside the website in the course of working together is treated confidentially and processed only for the intended purpose and—where required—on the basis of your explicit consent. On request, we can provide more appropriate channels for transmitting sensitive information.
13. Updates
We will update this privacy notice when services, the legal position or technical processes change.
Status: 7 October 2025
