Privacy Policy "Tensana"
1. Data protection at a glance
General information
Tensana helps individual patients manage diagnosed high blood pressure. For this purpose, Tensana allows blood pressure data and, optionally, other health data to be recorded. The data is stored and can be accessed; analyses, including statistics and progress charts, are also generated. By using the service and storing data, you consent to its processing. You may withdraw this consent at any time. A function for deleting your user account is also available directly within the service. This will delete all stored data. You can also access all your data directly via the service and make corrections if necessary.
Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in the following sections of this Privacy Policy.
This Privacy Policy applies to the website and our app for the various operating systems. As the web app is part of our website, we have decided to create a single, consistent Privacy Policy for the website and the app across the different operating systems. This is intended to make the information easier for you to navigate.
- No collection of data that is not strictly necessary for the service or its operation (principle of data minimization)
- It is possible to use the Tensana service under a pseudonym or anonymously*
- No unsolicited disclosure of data to third parties
- We collect only anonymized statistical usage data, including anonymized analyses for the website and app; no so-called "profiling"
* A piece of data is considered personal data if we can associate it with the same person. Of course, we associate your data with you; that is the purpose of a user account. However, we cannot directly identify you from the email address you provide and a freely chosen username, so we consider the account pseudonymous. You are welcome to use a new email address that is not otherwise linked to you. With guest access, we do not have this information either and consider the use anonymous. When you connect to our servers, we always have your IP address, which is considered personal data. However, we have no way of identifying a person from the IP address.
We welcome questions and feedback about data protection.
Who is responsible for collecting data on our website and in the app?
Data is processed by the manufacturer. You can find the manufacturer's contact details in the Imprint.
How do we collect your data?
Your data is collected, firstly, when you provide it to us. This may include, for example, data that you enter into a form. It also includes health data that is stored and processed by Tensana. This primarily consists of blood pressure data, but you can also choose to record other health-related data.
Other data is collected automatically by our IT systems when you visit the website and use the app. For more information, please refer to the section “Server log files” in Chapter 4.
What data is collected or can be recorded in the app?
each including the date and time
- Username
- Email address
- Blood pressure
- Pulse
- Measurement site
- Weight
- Glucose
- Temperature
- Fluid intake/output
- Personal notes on measurements
- Events
- Medication plan
- Other health data
- Internal technical logs
What do we use your data for?
Some of the data is collected to ensure that the website and app function properly. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right at any time to obtain, free of charge, information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the rectification or deletion of this data. If you have consented to data processing, you may withdraw your consent at any time with future effect. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
For this and any other questions on the subject of data protection, you can contact us at any time at the address provided in the Imprint.
Analytics tools and third-party tools
When you visit our website, your browsing behavior may be statistically analyzed. This is done primarily using cookies and so-called analytics programs. Your browsing behavior is generally analyzed anonymously; the browsing behavior cannot be traced back to you. You may object to this analysis or prevent it by not using certain tools. Detailed information can be found in the following privacy policy.
2. Hosting
External Hosting
The services are hosted by an external service provider (hosting provider). The personal data collected on this website and in the app is stored on the hosting provider's servers. This may primarily include IP addresses, contact requests, metadata and communication data, contract data, contact details, names, website access data and other data generated through a service.
The hosting provider is engaged for the purpose of fulfilling contracts with our prospective and existing customers (Art. 6(1)(b) GDPR) and in the interest of ensuring the secure, fast and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR).
Our hosting provider will process your data only to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data. The servers are located in Germany.
Further information can be found on the following website of the hosting provider: https://docs.hetzner.com/de/general/general-terms-and-conditions/data-privacy-faq/
3. General information and mandatory disclosures
Data Protection
The operators of these websites and apps take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various types of personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
Please note that data transmission over the Internet (e.g. when communicating by email) may have security vulnerabilities. It is not possible to fully protect data against access by third parties.
Information about the controller
The controller responsible for data processing is:
klier.net International S.L., Arona, Spain
You can contact us at the following email address: dsb@klier.net.
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Data Protection Officer:
Horst Klier, Avenida de Chayofita 18, Arona, Spain, dsb@klier.net
Notice regarding data transfers to the USA
Our website includes tools from companies based in the USA, among others. When these tools are active, your personal data may be transferred to the US servers of the respective companies. Please note that the USA is not considered a safe third country under EU data protection law. US companies are required to disclose personal data to security authorities without you, as the data subject, being able to challenge this in court.
It therefore cannot be ruled out that US authorities (e.g. intelligence agencies) may process, evaluate and permanently store your data held on US servers for surveillance purposes. We have no influence over these processing activities.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your explicit consent. You may withdraw consent you have already given at any time. An informal notification by email to us is sufficient. The withdrawal does not affect the lawfulness of data processing carried out before the withdrawal.
Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ESTABLISH, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR). IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL THEN NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).Right to lodge a complaint with the competent supervisory authority
In the event of data protection violations under the GDPR, the data subject has the right to lodge a complaint with the competent supervisory authority, particularly in the Member State of their habitual residence, place of work, or the place of the alleged violation.
For companies based in Spain, the competent supervisory authority for data protection matters is the Agencia Española de Protección de Datos (AEPD). The AEPD's contact details are as follows:
Agencia Española de Protección de Datos
C/ Jorge Juan, 6
28001 Madrid
Spain
Website: www.aepd.es
The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in the performance of a contract provided to you or a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will be done only where technically feasible.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as data entries, orders or enquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the browser's address bar changing from “http://” to “https://” and by the padlock icon in your browser bar.
If SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
Access, deletion and rectification
Within the scope of the applicable legal provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients, and the purpose of the data processing, as well as, where applicable, the right to have this data corrected or deleted. You may contact us at any time at the address provided in the Imprint regarding this or any other questions about personal data.
Right to restriction of processing
You have the right to request that the processing of your personal data be restricted. You can contact us at any time at the address provided in the Imprint. The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the review, you have the right to request that the processing of your personal data be restricted.
- If the processing of your personal data was/is unlawful, you may request that the processing of your data be restricted instead of having it deleted.
- If we no longer need your personal data, but you need it to establish, exercise or defend legal claims, you have the right to request that the processing of your personal data be restricted instead of having it deleted.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, your interests must be weighed against ours. Until it has been determined whose interests prevail, you have the right to request that the processing of your personal data be restricted.
If you have restricted the processing of your personal data, this data may – apart from being stored – be processed only with your consent, for the establishment, exercise or defense of legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
Objection to Advertising Emails
We hereby object to the use of contact details published as part of the Imprint requirement for sending unsolicited advertising and informational materials. The website operators expressly reserve the right to take legal action in the event of unsolicited advertising information being sent, for example via spam emails.
4. Data collection on our website and in the apps
Cookies
Our websites use so-called “cookies”. Cookies are small text files and do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted after your visit ends. Persistent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.
In some cases, cookies from third-party companies may also be stored on your device when you visit our website (third-party cookies). These allow us or you to use certain services provided by the third-party company (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies are used to analyze user behavior or display advertising.
Cookies that are required to carry out the electronic communication process (necessary cookies), to provide certain functions that you have requested (functional cookies, e.g. for the shopping cart function), or to optimize the website (e.g. cookies used to measure the web audience) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies to ensure that its services are provided in a technically error-free and optimized manner. If consent to the storage of cookies has been requested, the cookies concerned are stored exclusively on the basis of this consent (Art. 6(1)(a) GDPR); consent can be withdrawn at any time.
You can configure your browser to notify you when cookies are set and to allow cookies only on a case-by-case basis, to reject cookies in certain cases or in general, and to automatically delete cookies when you close your browser. Disabling cookies may limit the functionality of this website.
If cookies from third-party companies or for analytical purposes are used, we will inform you separately about this in this privacy policy and, where applicable, ask for your consent.
Server log files
The website provider automatically collects and stores information in server log files, which your browser or our app automatically transmits to us. This information includes:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
These data will not be combined with data from other sources.
The legal basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or in order to take steps prior to entering into a contract. This data is also collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in ensuring that its website is displayed without technical errors and in optimizing it – for this purpose, the server log files must also be collected.
Technical log files
When used, our app creates technical log files (logs), which can be transmitted to us either automatically in the background or manually by users. These data are not combined with data from other sources.
What data are collected?
- General app logs
- BLE logs (Bluetooth)
- Analysis and correction of software and transmission errors
- Ensuring the stability, security and interoperability of the app and BLE communication
- Optimizing performance and energy consumption
- Supporting additional operating system versions and device models, as well as new BLE peripherals
The processing is based on Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest is to provide a technically reliable, stable and secure app and to ensure compatibility with future devices, operating system versions and BLE peripherals. In balancing the interests involved, we have taken into account that only the information required for these purposes is collected and processed.
Enquiries by email and telephone
If you send us inquiries by email or telephone, we will store the information you provide, including your contact details, in order to process your inquiry and in case of follow-up questions. We may use third-party providers to process your inquiries.
These data are processed on the basis of Art. 6(1)(b) GDPR if your request relates to the performance of a contract or is necessary in order to take steps prior to entering into a contract. In all other cases, the processing is based on our legitimate interest in effectively handling requests addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if this was requested.
The data you provide will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your request has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Registration on the website or app and use of the service
You can register on our website or in the app to use our service. We use the data you enter for this purpose only to enable you to use the respective offering or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration. The data entered when using the service is processed to provide and further develop the service. It may also be used within our secure systems to create anonymized analyses.
The data is stored locally on the respective device in the areas designated for this purpose by the relevant system or browser. Online, the data is stored on our own servers, which are used solely to operate the service.
We use the email address provided during registration to send you information related to the use of our service. This includes in particular:
- Help with getting started (e.g. a series of emails on how to use the service)
- Tips on making better use of individual features
- Reminders if the service has not been used or setup has not been completed
- Notifications in the event of prolonged inactivity and advance notice of the planned deletion of your user account
If this information is necessary for the operation and security of the service (e.g. notifications about account deletion), you cannot unsubscribe from it.
The data entered during registration and use is processed on the basis of your consent (Art. 6(1)(a) GDPR). You may withdraw your consent at any time. An informal notification by email to us is sufficient. The withdrawal of consent does not affect the lawfulness of data processing already carried out. Please note that if you withdraw your consent, you will no longer be able to use all of the app's features.
We store the data collected during registration and use for as long as you are registered with us, after which it is deleted. Statutory retention periods remain unaffected.
Unused accounts are deleted after 2 years of inactivity. You will receive relevant notifications by email beforehand. Unused guest accounts are deleted after one year. Unfortunately, we are unable to contact you in this case.
You can delete your user account, including all data, within the app at any time. Important: Uninstalling the app does NOT delete your account with us. We do not know how many devices you use to access your account with us via the app.
As we back up all data, we are able to restore accounts for a short time. We do not guarantee that this will be possible.
To provide a high quality of service, the app creates logs that can be sent to us if you require support. These are only sent in consultation with our support team, or you must proactively send them to us by email. An exception is the detection of serious errors (exceptions). In this case, the error details may be sent to us without prior consultation.
Anonymized analyses
We may automatically analyze and summarize the data stored in the service within our protected systems. Only the data required for the respective analysis is used. Only anonymized, aggregated results that do not allow any conclusions to be drawn about individual persons are published or shared with third parties. No individual user profiles are created, nor are decisions made about individual users.
Processing of Data (Customer and Contract Data)
We collect, process and use personal data only insofar as this is necessary to establish, define the content of or modify the legal relationship (master data). This is done on the basis of Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or in order to take steps prior to entering into a contract. We collect, process and use personal data relating to the use of our websites (usage data) only insofar as this is necessary to enable the user to use the service or to bill the user for it. Furthermore, personal data may be collected to demonstrate positive effects on healthcare provision as part of a trial pursuant to Section 139e(4) of Book V of the German Social Code.
The customer data collected will be deleted once the order has been completed or the business relationship has ended. Statutory retention periods remain unaffected.
Data transfer upon conclusion of a contract for the shipment of goods
We transmit personal data to third parties only when this is necessary for processing the contract, for example to companies entrusted with delivering the goods or service providers commissioned to process payments. The data will not be transmitted beyond this scope unless you have expressly consented to its transmission. Your data will not be disclosed to third parties without your express consent, for example for advertising purposes.
The legal basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or to take steps prior to entering into a contract.
Data transmission upon conclusion of a contract for services and digital content
We only transmit personal data to third parties when this is necessary for processing the contract, for example to the service provider commissioned to process payments.
No further transfer of data will take place unless you have expressly consented to the transfer. Your data will not be disclosed to third parties without your express consent, for example for advertising purposes.
The legal basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or to take steps prior to entering into a contract.
5. Use of Telemonitoring
When using the telemonitoring function to forward your data to the attending physician, prior consent is required (Art. 6(1)(a) GDPR). The data includes blood pressure and pulse readings, the time they were recorded, and statistics. The data is processed exclusively in Germany. When using the GDT export, the data is transmitted directly to your physician.6. Voice data collection, photo-based data collection, and AI-based analysis
Consent-based processing:
Your voice and image data are processed solely on the basis of your explicit consent pursuant to Art. 6(1)(a) GDPR. As health data (e.g. vital signs) are also processed in this context, your consent pursuant to Art. 9(2)(a) GDPR is additionally required. Before your data are collected, you will be explicitly asked for your consent.
Processing procedure:
Once you have given your consent, your voice or image data will be anonymized and transmitted via a secure proxy to the AI provider OpenAI Ireland Limited. The AI processes this data solely to extract your vital signs (e.g. blood pressure, pulse) using AI-assisted analysis. The vital signs identified are then displayed in an input form, where you can continue to use or save them.
Security Measures and Data Minimization:
We use extensive technical and organizational measures – including encryption (e.g. TLS/SSL) and strict access controls – to ensure that your data is protected during transmission and processing. Only the data strictly necessary for the analysis is collected and processed (principle of data minimization).
Withdrawal of consent:
You have the right to withdraw your consent at any time. Withdrawal means that the processing of your voice and/or image data will cease from the time of withdrawal, without affecting the lawfulness of the processing carried out up to that point (Art. 7(3) GDPR). To withdraw your consent or if you have any questions about data protection, you can contact our Data Protection Officer.
7. Use of Apple Health (HealthKit) and Google Health Connect
Our app can – with your explicit consent – import and export health data from Apple Health (HealthKit) and Google Health Connect. This allows health data (e.g. blood pressure and pulse data) to be synchronized between our app and the aforementioned services.
Data is transferred exclusively via the interfaces provided by the respective operating system and is encrypted. The imported data may be stored on our servers to provide the app's features. The data is not shared with third parties or used for advertising or tracking purposes.
Processing is carried out only with your consent in accordance with Art. 6(1)(a) and Art. 9(2)(a) GDPR. You can revoke access permissions at any time in your device's system settings.
8. Analytics tools and advertising
VG WORT Tracking Pixel
We use VG WORT's METIS access counting system to measure access to online texts that we make available to you through our website. We do this so that the likelihood of these texts being copied can be recorded. The likelihood of a text being copied forms the basis for VG WORT's lawful distribution of remuneration to the authors and publishers of these texts under the German Copyright Act (UrhG).
For this purpose, as part of METIS access counting, a “tracking pixel” is embedded in the source code of the respective online text. This tracking pixel is an ID uniquely assigned to the respective text and allows a visit to a text marked in this way to be counted as an access to that text. In addition, as part of METIS access counting, a client ID is generated and a so-called “METIS session cookie” is placed on the device of the user of the marked text. This client ID and the session cookie can be used to determine whether or not this user has already accessed the text within a browser session. This is intended to prevent the text from being unlawfully counted multiple times when determining its likelihood of being copied. No personal data is processed either through the session cookie used or at any other time as part of METIS access counting. METIS access counting is carried out on behalf of VG WORT by Kantar GmbH, Landsberger Straße 284, 80687 Munich.
9. Infomail
Newsletter Data
To avoid unnecessary data transfer, graphics in our Infomail are only loaded when viewed. We also record this to identify when a recipient has not opened the emails for an extended period.
The data entered during registration is processed exclusively on the basis of your consent (Art. 6(1)(a) GDPR). You may withdraw your consent to the storage of the data and email address and to its use for sending the Infomail at any time, for example via the "Unsubscribe" link at the end of the Infomail. The withdrawal does not affect the lawfulness of data processing carried out prior to the withdrawal. However, the email address will remain stored to preserve the history, including confirmation of subscription and unsubscription and emails sent.
The data you have provided to us for the purpose of receiving Infomail will be stored by us until you unsubscribe from Infomail and will also be retained for legal reasons after you unsubscribe. Data stored by us for other purposes (e.g. email addresses for the members' area) remains unaffected.
10. Plugins and Tools
YouTube
Our website uses plugins from the Google-operated website YouTube. The operator of the website is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in enhanced privacy mode. According to YouTube, this mode means that YouTube does not store any information about visitors to this website before they watch the video. However, enhanced privacy mode does not necessarily prevent data from being shared with YouTube partners. For example, YouTube establishes a connection to the Google DoubleClick network – regardless of whether you watch a video.
When you visit one of our pages that has a YouTube plugin, a connection is established to YouTube's servers. The YouTube server is informed which of our pages you have visited. If you are logged in to your YouTube account, you allow YouTube to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, after a video is started, YouTube may store various cookies on your device or use comparable recognition technologies (e.g. device fingerprinting). This allows YouTube to obtain information about visitors to this website. This information is used, among other things, to compile video statistics, improve user-friendliness and prevent attempted fraud.
After a YouTube video is started, further data processing operations may be triggered over which we have no control.
YouTube is used in the interest of presenting our online services in an appealing manner. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR; consent may be withdrawn at any time.
Further information on how user data is handled can be found in YouTube's privacy policy at: https://www.google.de/intl/de/policies/privacy.11. Online Marketing and Affiliate Programs
Amazon Affiliate Program
The website operators participate in the Amazon EU Associates Program. Amazon advertisements and links to Amazon.de are integrated into our pages, allowing us to earn money through advertising reimbursements. Amazon uses cookies for this purpose to track the origin of orders. This allows Amazon to determine that you clicked the affiliate link on our website.
The storage of “Amazon cookies” is based on Art. 6(f) GDPR. The website operator has a legitimate interest in this, as the amount of its affiliate commission can only be determined through the cookies.
For more information about Amazon's use of data, please see Amazon's privacy policy: https://www.amazon.de/gp/help/customer/display.html/ref=footer_privacy?ie=UTF8&nodeId=3312401.

