Privacy Policy
Hope Fertility App — Hope Applications GmbH
As of: March 2026
1. DATA CONTROLLER
Hope Applications GmbH
Eggerstedtstr. 51, 22765 Hamburg, Germany
Email: hi@hope-app.net
Phone: +49 176 615 077 69
2. DATA PROTECTION OFFICER
DataCo GmbH (DataGuard)
Dachauer Straße 63, 80335 Munich, Germany
Email: datenschutz@dataguard.de
Phone: +49 (0) 89 452459 900
3. DATA WE PROCESS
For the basic operation of the Hope App, we process only the following technical identifier:
• Channel ID
When you actively use the app's features, the following personal data may additionally be processed:
We anonymize and encrypt your data in such a way that we never know where the data originates, to whom it is transmitted, or what it contains. Decryption keys are stored exclusively on your device and within your clinic's system (MedITEX). We have no access to unencrypted patient data at any time.
4. PURPOSE OF DATA PROCESSING
Processing takes place solely for the purpose of enabling fast digital communication between patients and fertility clinics, facilitating patient management, and ensuring the reliable and secure transmission of treatment-relevant information. Further processing for other purposes or disclosure to third parties is excluded.
5. LEGAL BASIS
We process personal data pursuant to Art. 6(1)(a) GDPR solely on the basis of your explicit, voluntary, and active consent. As health data within the meaning of Art. 9(1) GDPR is involved, processing additionally takes place on the basis of Art. 9(2)(a) GDPR.
6. TECHNICAL SECURITY AND DATA TRANSFER
Connection Setup (Offline Handshake)
The connection between the Hope App and your clinic is established by scanning a QR code generated within MedITEX. This process activates asymmetric end-to-end encryption. The private key is generated locally on your device and within MedITEX and is neither stored nor transmitted elsewhere.
Relay Server
All data is transmitted in encrypted form via our relay server located in Frankfurt am Main, Germany. The server retains data until it is retrieved by MedITEX or the app, for a maximum of two weeks, after which it is automatically and irreversibly deleted.
Note: Unencrypted metadata that exists for technical reasons (hashed message ID, timestamp, channel ID) cannot be linked to a specific individual by us — only your clinic can do so via MedITEX.
Platform Security
• Servers: DigitalOcean App Platform, Frankfurt am Main
• Encryption: End-to-end encryption plus TLS as an additional layer
• Access control: Server management restricted to our office's static IP
• API security: Individual API keys per clinic and service
• Error tracking: Sentry (with automatic and manual filtering of personal data)
• Logging: Solarwinds Papertrail and Datadog (with automatic and manual filtering)
7. THIRD-PARTY PROCESSORS
We work with the following carefully vetted service providers who act solely on our instructions and are contractually bound in accordance with Art. 28 GDPR:
Relay Server Hosting:
DigitalOcean, LLC — Frankfurt am Main, Germany
App Distribution:
Apple App Store (Apple Inc.) and Google Play Store (Google LLC)
Electronic Signature (eSignature):
Paperless GmbH (paperless.io)
For the eSignature function, we work with Paperless GmbH. Due to the nature of this service, data is briefly unencrypted before being transmitted to the eSignature provider. You will be informed in advance and must actively consent to the transmission. After completion, data is deleted immediately. All connections run through our own servers — there is no direct connection between Paperless GmbH and your clinic.
8. DATA RETENTION
Your data is deleted as soon as the purpose of storage no longer applies or the legal basis subsequently ceases to exist. Retrieved data is deleted immediately. Data that has not been retrieved is automatically deleted after 48 hours at the latest.
9. YOUR RIGHTS AS A DATA SUBJECT
Under Chapter 3 of the GDPR, you have the following rights:
• Right of access to stored data (Art. 15 GDPR)
• Right to rectification of inaccurate data (Art. 16 GDPR)
• Right to erasure or restriction of processing (Art. 17, 18 GDPR)
• Right to data portability (Art. 20 GDPR)
• Right to object to processing (Art. 21 GDPR)
• Right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR)
Competent supervisory authority:
Der Hamburgische Beauftragte fuer Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22 (7th floor), 20459 Hamburg, Germany
Phone: +49 40 4285 44040
Email: mailbox@datenschutz.hamburg.de
10. RIGHT TO WITHDRAW CONSENT
You may withdraw your consent at any time with effect for the future and without giving reasons. Please direct your withdrawal to: hi@hope-app.net or to our Data Protection Officer (see Section 2). Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Hope Applications GmbH | Eggerstedtstr. 51 | 22765 Hamburg, Germany
hi@hope-app.net | +49 176 615 077 69
