Datenschutzhinweise zur Pulsonics-App
Diese Hinweise betreffen die Pulsonics-Apps für Android und iOS sowie die Web-Anwendung unter emr.pulsonics-emr.com. Für diese Website gilt die Datenschutzerklärung. English translation below.
1. Anbieter und Herausgeber
Pulsonics wird von der Pulsonics GmbH entwickelt und verantwortet. In den App-Stores wird die App von der ANTURICS GmbH im Auftrag der Pulsonics GmbH veröffentlicht.
Pulsonics GmbHBrunnenweg 7
61352 Bad Homburg, Deutschland
E-Mail: info@pulsonics-emr.com
2. Wer für Ihre Daten verantwortlich ist
Pulsonics wird von Gesundheitseinrichtungen wie Krankenhäusern eingesetzt. Verantwortlich für die Daten der Patientinnen und Patienten und für die Daten der Nutzerinnen und Nutzer (des Personals) ist stets die jeweilige Einrichtung. Welche Rolle die Pulsonics GmbH hat, hängt vom Betriebsmodell ab, das die Einrichtung wählt:
- Betrieb auf Servern der Pulsonics GmbH in Deutschland: Die Pulsonics GmbH verarbeitet die Daten als Auftragsverarbeiter (Art. 28 DSGVO) auf Grundlage eines Auftragsverarbeitungsvertrags. Die Daten sind mit einem Schlüssel verschlüsselt, den nur die Einrichtung besitzt; die Pulsonics GmbH kann ihren Inhalt nicht lesen.
- Betrieb in einer Cloud nach Wahl der Einrichtung oder bei einem lokalen IT-Dienstleister: Die Daten liegen dort. Die Pulsonics GmbH stellt lediglich die Software bereit und hat keinen Zugriff auf Patientendaten.
- Betrieb vor Ort (on premises): Die Pulsonics GmbH stellt lediglich die Software bereit und erhält keinen Zugriff auf Daten der Einrichtung.
Wenn Sie als Patientin, Patient oder Beschäftigte Fragen zu Ihren Daten haben oder Rechte geltend machen möchten, wenden Sie sich bitte an die Einrichtung, die Pulsonics einsetzt.
3. Welche Daten die App verarbeitet
- klinische Dokumentation zu Patientinnen und Patienten einschließlich Gesundheitsdaten (Art. 9 DSGVO) sowie Fotos, Videos und Dokumente, die Nutzerinnen und Nutzer anhängen;
- das Benutzerkonto des Personals (Name, Rolle, Zugangsdaten) und seine Berechtigungen;
- ein Prüfprotokoll darüber, wer wann welche Aktion ausgeführt hat.
Welche Daten erfasst werden, legt die Einrichtung fest.
4. Berechtigungen auf dem Gerät
- Kamera: um Fotos aufzunehmen und anzuhängen;
- Fotos und Videos: um vorhandene Bilder oder Videos auszuwählen und anzuhängen;
- Netzwerk und Hintergrunddienst: um Daten zu übertragen und laufende Übertragungen abzuschließen.
Die App greift nicht auf Ihren Standort, Ihre Kontakte oder Ihr Mikrofon zu.
5. Verschlüsselung und Speicherung auf dem Gerät
Jede Einrichtung erhält bei ihrer Einrichtung einen eigenen Schlüssel, den nur sie besitzt – nicht die Pulsonics GmbH. Sensible Daten werden vor der Übertragung auf dem Gerät verschlüsselt; die Verbindung ist zusätzlich per TLS geschützt. Auf dem Gerät wird keine dauerhafte Kopie der Patientenakte gespeichert.
6. Keine Werbung, kein Tracking
Die App enthält keine Werbung und keine Analyse-, Tracking- oder Werbebibliotheken Dritter. Daten werden weder verkauft noch für Werbezwecke verwendet.
7. KI-Analyse über eine Schnittstelle (optional)
Die Einrichtung kann ein Sprachmodell ihrer Wahl über eine URL anbinden. Ist dies eingerichtet, übermittelt die App eine anonymisierte Patientenakte zur Analyse oder sonstigen Verarbeitung an dieses Modell. Die Pulsonics GmbH stellt nur die Schnittstelle bereit, nicht das Modell. Welches Modell genutzt wird, wer es betreibt und auf welcher vertraglichen und rechtlichen Grundlage, entscheidet und verantwortet die Einrichtung. Pulsonics selbst zieht keine klinischen Schlussfolgerungen und gibt keine medizinischen Empfehlungen.
8. Rechtsgrundlagen
Die Rechtsgrundlage für die Verarbeitung von Patienten- und Beschäftigtendaten bestimmt die verantwortliche Einrichtung nach dem für sie geltenden Recht; innerhalb der EU kommen insbesondere Art. 6 Abs. 1 lit. c und e sowie Art. 9 Abs. 2 lit. h DSGVO in Verbindung mit nationalem Recht in Betracht. Soweit die Pulsonics GmbH Daten im Auftrag verarbeitet, geschieht dies nach Art. 28 DSGVO ausschließlich auf Weisung der Einrichtung.
9. Speicherort und Empfänger
Beim Betrieb auf Servern der Pulsonics GmbH werden die Daten in Deutschland gespeichert und verlassen die EU nicht – außer dorthin, wo die Einrichtung selbst sie in ihrem Land nutzt. Eingesetzte Unterauftragsverarbeiter sind im Auftragsverarbeitungsvertrag aufgeführt. Bei den anderen Betriebsmodellen und für ein angebundenes Sprachmodell bestimmt die Einrichtung, wo die Daten liegen und wer sie erhält.
10. Speicherdauer
Wie lange Daten gespeichert werden, legt die Einrichtung fest, in der Regel nach den für Patientenakten geltenden Aufbewahrungsfristen. Beim Betrieb auf Servern der Pulsonics GmbH werden die Daten nach Vertragsende nach Wahl der Einrichtung zurückgegeben oder gelöscht, soweit keine Pflicht zur Speicherung besteht.
11. App-Stores
Beim Herunterladen der App verarbeiten Google (Google Play) und Apple (App Store, TestFlight) Daten nach ihren eigenen Datenschutzbestimmungen. Die Stores stellen dem Herausgeber Statistiken bereit, etwa zu Installationen und Abstürzen.
12. Ihre Rechte
Ihre Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch (Art. 15 bis 21 DSGVO) richten sich an die verantwortliche Einrichtung; die Pulsonics GmbH unterstützt sie dabei als Auftragsverarbeiter. Sie haben außerdem das Recht, sich bei einer Datenschutz-Aufsichtsbehörde zu beschweren.
Stand: Oktober 2026
Privacy notice for the Pulsonics app
English translation for convenience; the German text above is binding. This notice covers the Pulsonics apps for Android and iOS and the web application at emr.pulsonics-emr.com. This website is covered by the website privacy policy (in German).
1. Provider and publisher
Pulsonics is developed by Pulsonics GmbH, which is responsible for it. In the app stores, the app is published by ANTURICS GmbH on behalf of Pulsonics GmbH. Contact: Pulsonics GmbH, Brunnenweg 7, 61352 Bad Homburg, Germany, info@pulsonics-emr.com.
2. Who is responsible for your data
Pulsonics is used by healthcare organisations such as hospitals. The organisation is always the controller for its patients' data and for its staff users' data. The role of Pulsonics GmbH depends on the operating model the organisation chooses:
- On Pulsonics GmbH's servers in Germany: Pulsonics GmbH processes the data as a processor (Art. 28 GDPR) under a data processing agreement. The data is encrypted with a key only the organisation holds; Pulsonics GmbH cannot read its content.
- In a cloud of the organisation's choice, or with a local IT provider: the data stays there. Pulsonics GmbH only supplies the software and has no access to patient data.
- On premises: Pulsonics GmbH only supplies the software and never gets access to the organisation's data.
If you are a patient or a staff member with a question about your data, or want to exercise your rights, please contact the organisation that uses Pulsonics.
3. What data the app processes
- clinical documentation about patients, including health data (Art. 9 GDPR), and photos, videos and documents users attach;
- staff user accounts (name, role, credentials) and their permissions;
- an audit trail of who did what and when.
The organisation decides which data is recorded.
4. Device permissions
- Camera: to take and attach photos;
- Photos and videos: to select and attach existing images or videos;
- Network and background service: to transmit data and complete transfers in progress.
The app does not access your location, contacts or microphone.
5. Encryption and storage on the device
Each organisation gets its own encryption key when it is set up, held by that organisation alone — not by Pulsonics GmbH. Sensitive data is encrypted on the device before it is sent, and the connection itself is additionally protected with TLS. No persistent patient record is stored on the device.
6. No advertising, no tracking
The app contains no advertising and no third-party analytics, tracking or advertising libraries. Data is not sold and not used for advertising.
7. AI analysis through an interface (optional)
The organisation can connect a language model of its choice by URL. Once that is set up, the app sends an anonymised patient record to that model for analysis or other processing. Pulsonics GmbH provides only the interface, not the model. Which model is used, who operates it and on what contractual and legal basis is the organisation's decision and responsibility. Pulsonics itself draws no clinical conclusions and does not provide medical advice.
8. Legal bases
The organisation, as controller, determines the legal basis for processing patient and staff data under the law that applies to it; within the EU this is typically Art. 6(1)(c) and (e) and Art. 9(2)(h) GDPR together with national law. Where Pulsonics GmbH processes data on the organisation's behalf, it does so under Art. 28 GDPR and only on the organisation's instructions.
9. Storage location and recipients
When Pulsonics runs on Pulsonics GmbH's servers, the data is stored in Germany and does not leave the EU, other than to the organisation itself where it uses the data in its own country. Any sub-processors are listed in the data processing agreement. In the other operating models, and for a connected language model, the organisation decides where the data is held and who receives it.
10. Retention
The organisation decides how long data is kept, usually according to the retention periods for medical records. When Pulsonics runs on Pulsonics GmbH's servers, the data is returned or deleted at the end of the contract, as the organisation chooses, unless it must be retained.
11. App stores
When you download the app, Google (Google Play) and Apple (App Store, TestFlight) process data under their own privacy policies. The stores provide the publisher with statistics, for example on installations and crashes.
12. Your rights
Your rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15 to 21 GDPR) are exercised against the organisation that is the controller; Pulsonics GmbH supports it as processor. You also have the right to lodge a complaint with a data protection supervisory authority.
Last updated: October 2026