Skip to content
vitagroup HIP
ContactBook a consultation

Privacy Policy for the E-Learning Platform at academy.vitagroup.ag

§ 1 General Information – Information on the Collection of Personal Data

  1. Below, we inform you in accordance with Art. 12 et seq. GDPR about the processing of your personal data when using our e-learning platform academy.vitagroup.ag. This privacy policy explains in particular which data we collect and for what purpose. It also explains how and for what purpose this is done.
  2. We treat personal data confidentially and in accordance with the applicable data protection laws and this privacy policy. The legal basis is primarily the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
  3. When using this e-learning platform, various personal data are processed depending on the type and extent of use. Personal data means any information relating to an identified or identifiable natural person; a person is considered identifiable if they can be identified directly or indirectly (e.g. via association with an online identifier). This includes, for example, name, address, email address, and user behaviour.

§ 2 Name and Address of the Controller

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g. names, email addresses, etc.). The controller within the meaning of Art. 4(7) GDPR and applicable national data protection laws (in particular BDSG) as well as other data protection provisions is:

vitagroup health intelligence GmbH
Hamburger Straße 273b
38114 Braunschweig
Phone: +49 (0) 621 121 849-0
Email: info@vitagroup.ag

§ 3 Contact Details of the Data Protection Officer

We have appointed a Data Protection Officer:

Data Protection Officer
vitagroup AG
Gottlieb-Daimler-Straße 8
68165 Mannheim
Email: datenschutz@vitagroup.ag

§ 4 Your Rights

1.  You have the following rights regarding your personal data:

  • Right of access
  • Right to rectification or erasure
  • Right to restriction of processing
  • Right to object to processing
  • Right to data portability

2.  You also have the right to lodge a complaint with a supervisory authority regarding our processing of your personal data.

§ 5 Collection of Personal Data When Using Our E-Learning Platform

a) Registration and use

For registration and use of our e-learning platform, we require the following data:

  • First and last name
  • Email address
  • Password (freely chosen)
  • Metadata and communication data: device information (number of active devices per user), browser type, operating system, pages visited/trainings & status, location and time of access, mood indicator.

Our e-learning platform also includes a community function. This allows active users to exchange information in a protected space with other users of the same customer account and to leave comments. Only platform administrators and users of the respective customer account have access to this information and comments. The content collected and exchanged in this context is also processed by us.

These data are required to provide access to the platform, verify access rights, store learning progress and course activities, and, if applicable, issue certificates.

Legal basis:

  • For customers, partners, or their employees: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (legitimate interests).
  • For our employees: Section 26(1) BDSG (employment relationship), Art. 6(1)(f) GDPR (legitimate interests).

b) Display of your profile in the community

If you wish, you may display your profile in the community (custom username, optional information such as role, and optional profile picture).

Legal basis: Art. 6(1)(a) GDPR (consent).

You can change your profile information at any time in your account settings and give or withdraw your consent for future display in the community at any time.

§ 6 Cooperation with Processors, Data Transfers to Third Countries

We use service providers to technically provide and operate our e-learning platform. These processors act only on our instructions and are contractually bound under Art. 28 GDPR.

In some cases, personal data may be transferred to service providers located outside the European Economic Area (EEA). Such processing is carried out solely for the purpose of fulfilling contractual use of the platform. We ensure an adequate level of data protection, in particular by concluding Standard Contractual Clauses (SCCs) of the European Commission pursuant to Art. 46(1), (2)(c) GDPR. For further information, please contact our Data Protection Officer.

§ 7 Technical and Organisational Measures (TOMs)

Our service provider for the operation of the e-learning platform guarantees the following technical and organizational measures for data security:

a) Confidentiality

  • Physical access control: Data stored with certified providers (Google Cloud, MongoDB) using encryption, two-factor authentication, and access restrictions.
  • Access control: Authentication via Google Cloud IAM and Firebase Security Rules; access limited to authorized users.
  • Authorization control: Individual user IDs, password hashing, regular access reviews.

b) Integrity and availability

  • Data integrity: Regular backups, logging of all access, automated abuse detection.
  • Availability: Highly available infrastructure (SLA ≥ 99.999%).
  • Pseudonymisation: AES-SIV encryption, format-preserving encryption, cryptographic hashing.

c) Data protection management

  • Regular review and updates of TOMs.
  • Incident response management for data protection incidents.
  • Support for data subject rights: Memberspot assists with requests under Art. 12–22 GDPR.

§ 8 Additional Processing Purposes

  1. We also process personal data to comply with legal obligations, in particular retention obligations under commercial or tax law. Legal basis: Art. 6(1)(c) GDPR.
  2. We also process personal data to assert and enforce legal claims, defend against legal claims, and prevent or prosecute criminal offenses. Legal basis: Art. 6(1)(f) GDPR (legitimate interests).

§ 9 Data Retention Period

We process and store personal data for as long as necessary for the respective purpose, including pre-contractual relationships and contract performance. Data are regularly deleted unless further processing is required for:

  • Compliance with statutory retention obligations (e.g. German Commercial Code (HGB) and Fiscal Code (AO), up to 10 years).
  • Preservation of evidence within limitation periods (up to 30 years; regular limitation period: 3 years).

§ 10 Obligation to Provide Data

Within the scope of a pre-contractual or contractual relationship, you must provide the personal data required for registration and use of the platform. Without this data, we will generally not be able to provide access to the platform.

§ 11 No Automated Decision-Making

We do not use automated decision-making pursuant to Art. 22 GDPR for establishing or conducting the business relationship.

§ 12 Objection to Processing

If we process your personal data based on Art. 6(1)(f) GDPR, you have the right to object. Please provide reasons for your objection. We will review the situation and either cease or adjust processing or demonstrate compelling legitimate grounds for continuing.

§ 13 Amendments to this Privacy Policy

We reserve the right to amend this privacy policy due to further development of the platform or changes in legal or regulatory requirements. The current version is available on our website under Privacy Policy (opens in new tab).