Mahana Secures Permanent Reimbursement in Germany for its Cara Care for Irritable Bowel Syndrome (IBS) Digital Therapeutic. Click here to learn more.
Service-Hotline:030 3080 9546(Mo-Thu 9-18 & Fri 9-16:30)

Privacy policy

(These terms apply to our websites. The privacy policy for the Cara App and Cara Care can be found here. A German version of this document is available here)

HiDoc Technologies GmbH (hereinafter "HiDoc") processes personal data on this website in accordance with the principles described below. HiDoc attaches great importance to the protection of your personal data and other information collected. We can therefore assure you that we always handle your data in a trustworthy and responsible manner. In particular, we use your personal data strictly in accordance with the legal requirements.

1. responsible party

The responsible party within the meaning of the data protection regulations for the processing of personal data on this website is HiDoc Technologies GmbH, Hohe Bleichen 22, 20354 Hamburg. For further contact details, please refer to the imprint of this website. HiDoc has appointed Mr. Michael Panienka, attorney-at-law, as data protection officer, who can be contacted via the email address

2. collection and processing of personal data

When you visit our website, our web servers store by default your IP address, the website from which you visit us, e.g. if you have followed a link, the web pages you visit on our site, information about the Internet browser used and its display properties and language settings, the operating system used, and the date and duration of the visit. In addition, personal data is only collected and processed if you provide it to us independently, e.g. in the context of a registration, the use of a contact form or an inquiry.

Personal data collected in this way is deleted by us immediately as soon as it is no longer required for the purpose for which it was collected.

3. Use and disclosure of personal data and purpose limitation

HiDoc uses this personal data for purposes of technical administration of the Internet pages, in particular to provide you with access, as well as for statistical evaluations of usage. We also use this technical access information to continuously improve the attractiveness and usability of our Internet pages as well as their contents and to detect possible technical problems in our Internet offer. HiDoc will not pass on the personal data provided by you to third parties without your express consent. Details are regulated by this data protection notice.

The legal basis for the processing of personal data for this purpose results from Art 6 para.1 lit. b) GDPR.

4. contact form, e-mail contact, recipe service

Our website contains contact forms via third-party providers (Sumo, Typeform), which can be used for electronic contact. If a user takes advantage of this option, the data entered in the input mask will be transmitted to us and stored. These data are the first and last name as well as e-mail address, or also a telephone number. Alternatively, it is possible to contact us via the email address provided. In this case, the user's personal data transmitted with the email will be stored.

We use the service provider Zammad (operator: Zammad GmbH, Marienstraße 18, 10117 Berlin, Germany) to process email inquiries via our helpdesk. The processing is based on our legitimate interest pursuant to Article 6 para. 1 lit f) GDPR in providing a communication option in the context of customer and prospect support. Your inquiries will be stored for a period of two years unless longer storage is necessary in individual cases (enforcement or defence of claims).

In addition, an individual meeting request can also be arranged via contact forms. In this case, a telephone number as well as information about the type of health insurance and health insurance company are also collected in order to enable billing of the HiDoc service via a health insurance company, if necessary. If you use the service of direct billing of HiDoc with your insurance company or the prescription service for transmitting your prescription to your health insurance company and transmit a prescription issued to you for the Cara Care app, for example, by email or by mail to HiDoc, you expressly agree to the processing of the information on the same prescription, as well as the request for the app access code and processing of the reimbursement of the service with the respective insurance company on your behalf.

If you enter health information in the comment field or otherwise submit this information to HiDoc, you expressly agree that HiDoc may use this information for your individual consultation and forward it to a HiDoc consultant or forward this information to your health insurance company on your behalf.

If you enter your telephone number in the comment field or otherwise submit it to HiDoc, you expressly agree that HiDoc may use this information for an individual contact and pass it on to a HiDoc advisor.

You can revoke these consents at any time with effect for the future. The prescription service is a voluntary service offered by HiDoc, there is no obligation for you to use it.

HiDoc uses the company Typeform based in Spain as a technical service provider for the processing of contact forms and questionnaires, the company Zapier Inc. based in the USA for sending emails and Google Ireland Ltd. based in Ireland for evaluating the questionnaires and sending emails. To process the booking of the consultation appointments, we use the platform of Cituro, based in Germany, or Calendly, based in the USA. To process the prescription service for forwarding prescriptions to your health insurance company, services of Deutsche Post (Deutsche Post AG, Charles-de-Gaulle Str. 20, 53113 Bonn, Germany) may also be used.

To store contact information and manage contacts, HiDoc uses HubSpot, a software solution offered by the company HubSpot Ireland Ltd. based in Ireland.

The data is used exclusively for processing the transmitted request. The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input mask of the contact form and those sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when the circumstances indicate that the matter in question has been conclusively clarified. In the case of billing for the service, the data will be stored accordingly until the end of the consultation or treatment and its billing. If you have given your consent for further contact, e.g. for the purpose of product information, your contact data will also be stored beyond this until you revoke your consent to this.

The legal basis for the processing of data transmitted in the course of sending an e-mail or using the contact form, as well as used for address management, is Art. 6 para. 1 lit. a and Art. 9 para.2 lit a GDPR. You can revoke your consent at any time with effect for the future.

5. links and references to other internet sites

This website contains links to other websites. Please note that HiDoc is not responsible for their data protection or the content of these other Internet offers. We recommend that all Internet users inform themselves about the respective data protection information (privacy statements, privacy policy, etc.) of the other Internet sites they visit when leaving the HiDoc Internet site.

In addition, this Internet site refers to Internet offers of HiDoc in social networks, such as Facebook and Twitter and Google+. In the context of using these third-party internet sites, personal data will be collected by them in accordance with their data protection provisions, over which HiDoc has no influence. In the case of Facebook, Twitter and Google+, this data processing may also take place outside the scope of European data protection laws. Please refer to the data protection provisions of the respective providers for details:

6. cookies and analyses

A cookie is text information that can be stored in the browser on the computer of the viewer in each case to a visited website (web server, server). The cookie is either sent to the browser by the web server, or generated in the browser by a script (JavaScript). The web server can read this cookie information directly from the server during subsequent, renewed visits to this page or transfer the cookie information to the server via a script on the website. The task of these cookies is, for example, the identification of the surfer (session ID), the storage of a login at an Internet application such as Wikipedia, Facebook, etc. or the storage of a shopping cart at an online retailer.

Once cookies have been set, you can also delete them at any time. You can find out how all this works in detail in the help function of your browser. Please note that a general deactivation of cookies may lead to functional restrictions of our website. This website uses the following types of cookies, the scope and functionality of which are explained below:

  • Absolutely necessary cookies (Necessary - Type I)
  • Functional and performance cookies (preferences - type II)
  • Cookies requiring consent (statistics and marketing - type III)

6.1. Cookies that are absolutely necessary (Necessary - Type I)

Essential cookies ensure functions without which you cannot use our websites as intended. These cookies are used exclusively by us and are therefore so-called "first party cookies". This means that all information stored in the cookies is returned to our website.

Essential cookies are used, for example, to ensure that you, as a logged-in user, always remain logged in when accessing various sub-pages of our website and thus do not have to re-enter your login data each time you call up a new page.

Legal basis is Art. 6 para. 1 lit. b GDPR

  • Cloudflare

Our pages use functions from CloudFlare. The provider is CloudFlare, Inc. 665 3rd St. #200, San Francisco, CA 94107, USA. The operator of this website uses the services of CloudFlare. CloudFlare offers a so-called worldwide distributed content delivery network with DNS. Technically, the information transfer between your browser and our web pages is routed through CloudFlare's network. CloudFlare is thus able to analyse the data traffic between users and our websites, for example, to detect and prevent attacks on our services. In addition, CloudFlare may store cookies on your computer for optimization and analysis.

Cookie used (Type I) Lifetime/ expiration
__cfduid 5 years
  • Hubspot

HiDoc uses HubSpot, an offering from HubSpot Ireland Ltd. as an integrated marketing solution to unify our email marketing, social media publishing & reporting, reporting, contact management and contact forms. HubSpot uses both necessity cookies (type I) and analytics cookies (type III). HiDoc uses the following necessary cookies from HubSpot on its website. These are used to implement and store your consents to the use of cookies on the site, to store which consents you have given for the use of cookies, and to allow or disallow the sending of tracking information via cookies.

Cookie used (Type I) Lifetime/ expiration
__hs_opt_out 6 months
__hs_d_not_tracking 6 months
__hs_initial_opt 7 days
__hs_cookie_cat_pref 6 months
  • CookieHub

Functional cookies allow our website to store information you have already provided (such as registered name or language selection) and offer you improved and personalised features based on this information. These cookies collect and store only anonymized information, so they cannot track your movements on other websites. The legal basis for the use is basically Art. 6 para. 1 lit. f GDPR.

6.2 Functional and performance cookies (preferences - type II)

Functional cookies allow our website to store information you have already provided (such as registered name or language selection) and offer you improved and personalised features based on this information. These cookies collect and store only anonymized information, so they cannot track your movements on other websites.

The legal basis for the use is basically Art. 6 para. 1 lit. f GDPR.

  • SumoMe

Our website uses SumoMe, a service provided by Sumo Group Inc, 1305 E. 6th St 3, Austin, TX 78702, USA. SumoMe uses, among other things, cookies that are stored on your computer and that allow an analysis of the use of the website. In the course of use, data, such as in particular the IP address and activities of the user, may be transmitted to a server of the company Sumo Group Inc. and stored there.

Cookie used (Type II) Lifetime/ expiration
__smSessionId 1 day
__smSmartbarShown 30 years
__smToken 1 year
__smVID 30 days
__smOptOut 10 years
__smVID 30 days

6.3 Cookies requiring consent (statistics and marketing - type III)

We reserve the right to also use information obtained by means of cookies from an anonymized analysis of the usage behaviour of visitors to our websites in order to display specific advertising for certain of our products to you on our own websites. We believe that you as a user benefit from this because we display advertising or content that we assume, based on your browsing behaviour, matches your interests and you are thus shown less randomly scattered advertising or specific content that may be of less interest to you.

The legal basis for data processing here is Art. 6 para. 1 lit. a GDPR. The following description of the tracking and analysis tools also shows the respective processing purposes and the processed data.

By using our website, you hereby expressly consent to the use of cookies and the use of your personal data for the use of our website for the purpose of improving our internet offer and for marketing purposes. This consent includes in particular the use of service providers commissioned by HiDoc, such as in particular Google Ireland Ltd,** **Facebook Inc, Facebook Ireland ltd, Intercom R&D Unlimited Company, Cloudflare Inc,Sumo Group Inc, Issuu Inc, HubSpot Inc and Sanofi Aventis Deutschland GmbH as well as the transfer of data to these service providers for the above-mentioned purpose

You can revoke your consent at any time and delete existing cookies by turning them off and removing them via your Internet browser. You can find more information about deleting or preventing cookies in the help texts for your browser or on the Internet, for example, under the search terms "disable cookies" or "delete cookies.

  • Google Analytics

This website uses Google Analytics, a web analytics service provided by Google, Inc ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyse how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. In the event that IP anonymization is activated on this website, however, your IP address will be truncated beforehand by G oogle within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. We use Google Analytics to analyse and regularly improve the use of our website. The statistics obtained allow us to improve our offer and make it more interesting for you as a user.

Cookie used (Type III) Lifetime/ expiration
_ga 2 years
_gat 1 day
_gid 1 day
  • Google Ads Remarketing

We use the remarketing function within the Google Ads service. The remarketing function allows us to present users of our website with advertisements based on their interests on other websites within the Google advertising network (in Google Search or on YouTube, so-called "Google Ads" or on other websites). For this purpose, the interaction of the users on our website is analysed, e.g. which offers the user was interested in, in order to be able to display targeted advertising to the users on other sites even after they have visited our website. For this purpose, Google stores a number in the browsers of users who visit certain Google services or websites in the Google display network. This number is used to uniquely identify a web browser on a specific end device and not to identify a person; personal data is not stored.

Cookie used (Type III) Lifetime/ expiration
_gcl_au 3 months
__utmx 18 months
__utmxx 18 months
_gaexp 90 days
  • Google Analytics advertising functions

We use Google Analytics advanced features on this website in addition to the standard features. The Google Analytics advertising features implemented on this website include:

  • Google Display Network Impressions Reports;
  • Google Analytics reports on performance by demographic characteristics and interests.
  • Integrated services for which Google Analytics collects data for advertising purposes, including the collection of data via cookies for ad preferences and anonymous identifiers.

For this purpose, in addition to the data collected by the Google Analytics analysis tool, additional data is collected via Google cookies for ad preferences and anonymous identifiers on accesses. We use this information to improve our web offerings.

Cookie used (Type III) Lifetime/ expiration
_gac_<property-id> 90 days
_opt_awcid 24 hours
_opt_awmid 24 hours
_opt_awgid 24 hours
_opt_awkid 24 hours
_opt_utmc 24 hours
  • Campaign Manager - DoubleClick by Google

This website continues to use the online marketing tool Campaign Manager by Google. Campaign Manager uses cookies to serve ads that are relevant to users, to improve campaign performance reports, or to prevent a user from seeing the same ads more than once. Using a cookie ID, Google records which ads are served in which browser and can thus prevent them from being displayed more than once. In addition, Campaign Manager can use cookie IDs to record so-called conversions that are related to ad requests. This is the case, for example, when a user sees a Campaign Manager ad and later uses the same browser to visit the advertiser's website and make a purchase. According to Google, Campaign Manager cookies do not contain any personal information.

Cookie used (Type III) Lifetime/ expiration
IDE 1 year
test_cookie 1 year
  • Facebook-Pixel, Conversion Tracking, Custom Audiences

Within our online offer, the so-called "Facebook pixel" of the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or if you are a resident of the EU, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook"), is used for the optimization and economic operation of our online offer.

The website uses the remarketing function "Custom Audiences" of Facebook Inc ("Facebook") to be able to address you again within 6 months. With the help of the Facebook pixel, it is possible for Facebook, on the one hand, to determine the visitors to our online offer as a target group for the display of advertisements (so-called "Facebook Ads"). Accordingly, we use the Facebook pixel to display the Facebook ads placed by us only to those Facebook users who have also shown an interest in our online offer or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited) that we transmit to Facebook (so-called "Custom Audiences"). With the help of the Facebook pixel, we also want to ensure that our Facebook ads correspond to the potential interest of users and do not have a harassing effect. With the help of the Facebook pixel, we can also track the effectiveness of the Facebook ads for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook ad (so-called "conversion").

Cookie used (Type III) Lifetime/ expiration
__fbp 3 months
fr 3 months
  • Issuu

On this website, components of the Issuu web service (operated by Issuu Inc. - 131 Lytton Ave - Palo Alto - CA 94301 - USA) are integrated, which enable the publication and distribution of magazines and catalogues as well as their viewing. In addition, Issuu calls up the Google Analytics tracker. This is Issuu's own tracking, to which we have no access.

Cookie used (Type III) Lifetime/ expiration
_awl 3 years
  • Hubspot

We use HubSpot to analyse and regularly improve the use of our website. The statistics obtained enable us to improve our offer and make it more interesting for you as a user.

Cookie used (Type III) Lifetime/ expiration
_hstc 6 months
_hubspotuk 6 months
_hssc 30 minutes
_hssrc Session

7. data protection level of third party providers

The third party providers used by HiDoc and mentioned above are either based in the EU or in a country in which the EU has determined an adequate level of data protection. With companies from the USA, HiDoc has agreed to so-called EU standard contractual clauses as well as supplementary protective measures to ensure an adequate level of data protection in accordance with Art. 46 para.2 lit c.) GDPR.

8. security

As required by law, HiDoc uses the technical and organisational security measures to protect your data managed by us against accidental or intentional manipulation, loss, destruction or against access by unauthorised persons. Our security measures are continuously improved in line with technological developments.

9. your rights

As a user of our website, you have the right to request information from us about the data stored about you or your pseudonym. Upon your request, the information can also be provided electronically. You have the right to request deletion or restriction of your personal data processed by us or transfer to third parties in a common format used by us. You may request that incorrect data be corrected. You can revoke any consent given, e.g. to the use of analyses by cookies, at any time. Corresponding requests can be addressed to HiDoc or our data protection officer. Complaints about the processing of personal data by us can be directed to the competent supervisory authority.

10. scope of application

This data protection notice applies exclusively to the Internet offer and the newsletter service of HiDoc. In addition, we point out that this data protection information is subject to constant adaptation to current requirements.

Status: January 2023

CE-certified Medical DeviceGDPR Compliant
Cara.Care All Rights Reserved. The Cara Care website is for informational purposes only and is not a substitute for medical advice, diagnosis or treatment.
Privacy PolicyTerms & ConditionsImprint