Privacy Policy
LEO Primärversorgungszentrum für Allgemeinmedizin Dr. Brandl, Dr. Behr, Dr. Dworschak GmbH
Last updated: August 2026
This is a translation of the German original. In case of any discrepancy, the German version prevails.
1. Privacy at a Glance
General Information
The following notes give you an initial overview of what happens to your personal data when you visit this website or use our services. Personal data is any data by which you can be personally identified. You will find detailed information in the sections below.
Who is responsible for processing your data?
The operator of this website is the controller. You will find the contact details in the section "Controller".
How do we collect your data?
Some data you provide to us directly, for example by email, by telephone, through the online appointment booking or through our patient app. Other data is collected automatically by our IT systems when you access the website. This is mainly technical data such as browser type, operating system or the time of the page visit.
What do we use your data for?
Part of the data is collected to ensure the website is provided without errors. Other data is processed in order to answer your enquiry, arrange appointments or provide you with medical care.
Important note: Please do not send us any information about your state of health or that of another person by unencrypted email. For health related matters, please use our patient app 37.clinic, call us, or speak to us in person at the practice.
What rights do you have?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of the personal data we hold about you. You may also request that this data be corrected or deleted, withdraw any consent you have given at any time, request the restriction of processing under certain conditions, and lodge a complaint with the supervisory authority. Where we process data on the basis of legitimate interests, you may object to that processing.
2. Hosting
This website is hosted by an external service provider. The personal data collected on this website is stored on the servers of the host. This may include IP addresses, metadata and communication data, and other data generated through a website.
External hosting takes place in the interest of a secure, fast and reliable provision of our online offering (Art. 6(1)(f) GDPR). Where consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and § 165(3) of the Austrian Telecommunications Act (TKG 2021), insofar as the consent covers the storage of cookies or access to information on your device. You may withdraw your consent at any time.
Our host processes your data only to the extent necessary to fulfil its service obligations and follows our instructions in doing so. We have concluded a data processing agreement pursuant to Art. 28 GDPR with the provider.
Host used: Framer B.V., Zuidplein 126, 1077 XV Amsterdam, Netherlands Privacy statement: https://www.framer.com/legal/privacy-statement/
3. General Information and Mandatory Disclosures
Data protection
We take the protection of your personal data seriously and treat it confidentially, in accordance with statutory provisions and this privacy policy. As a medical institution, we are additionally bound by medical confidentiality pursuant to § 54 of the Austrian Medical Practitioners Act (Ärztegesetz 1998).
You are not obliged to provide us with your data. However, without certain information we may be unable to process an enquiry, and the functionality of the website may be limited.
Please note that data transmission over the internet, for example when communicating by email, can have security gaps. Complete protection against access by third parties is not possible.
Controller
LEO Primärversorgungszentrum für Allgemeinmedizin Dr. Brandl, Dr. Behr, Dr. Dworschak GmbH Taborstraße 113/1B-1C AT-1020 Vienna, Austria
Telephone: +43 1 361 4040
Email: info@leo.med
Authorised representatives: Dr. Rainer Brandl, Dr. Walther Behr, Dr. Jan Dworschak, Tobias Laenser Commercial register number: FN 669023 h VAT identification number: ATU82862314 Chamber membership: Medical Chamber of Vienna (Ärztekammer für Wien)
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
Storage period
Unless a more specific storage period is stated in this policy, your personal data remains with us until the purpose of processing no longer applies. If you make a legitimate request for deletion or withdraw your consent, your data will be deleted unless we have other legally permissible grounds for storing it. Medical records are subject to a retention period of at least ten years under § 51(3) Ärztegesetz 1998, and tax relevant documents to the retention period under § 132 of the Austrian Federal Fiscal Code (BAO).
Legal bases for processing
Where you have consented to processing, we rely on Art. 6(1)(a) GDPR, and additionally on Art. 9(2)(a) GDPR in the case of health data. Where your data is necessary for the performance of a contract or for pre-contractual measures, we process it under Art. 6(1)(b) GDPR. Where a legal obligation applies, processing takes place under Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR.
Health data is processed in particular on the basis of Art. 9(2)(h) GDPR in conjunction with § 8(3) of the Austrian Data Protection Act (DSG), that is, for the purposes of preventive healthcare, medical diagnosis, treatment and the management of health services. The legal basis applicable in each specific case is stated in the relevant section.
Recipients of personal data
We only pass on personal data where this is necessary for the performance of a contract, where we are legally obliged to do so, where we have a legitimate interest under Art. 6(1)(f) GDPR, or where another legal basis permits it. Where processors are used, data is passed on only on the basis of a valid data processing agreement.
In the treatment context, recipients may include the Austrian Health Insurance Fund (ÖGK) and other social insurance institutions, the Federation of Social Insurance Institutions in connection with the e-card system, co-treating and referring physicians, laboratories, hospitals, pharmacies, as well as IT service providers for our practice management software and our patient app. Data is only disclosed within the legally permitted framework and in compliance with medical confidentiality.
Withdrawal of your consent
Many processing operations are only possible with your express consent. You may withdraw consent already given at any time. The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.
Right to object (Art. 21 GDPR)
IF THE PROCESSING OF DATA IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THAT PROCESSING. THIS ALSO APPLIES TO PROFILING CONNECTED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES.
Right to lodge a complaint with the supervisory authority
In the event of infringements of the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority in Austria is:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority) Barichgasse 40-42, 1030 Vienna Telephone: +43 1 52 152-0 Email: dsb@dsb.gv.at Web: https://www.dsb.gv.at
This right exists without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine readable format. If you request direct transfer of the data to another controller, this will only be done where technically feasible.
Information, correction and deletion
Within the framework of the applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of processing, and where applicable a right to have this data corrected or deleted. Please note that statutory retention periods for medical documentation may prevent deletion. You can contact us at any time regarding these matters.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. This right applies in the following cases:
If you dispute the accuracy of the personal data we hold, we generally need time to verify this. For the duration of the review, you may request restriction of processing.
If the processing of your personal data was or is unlawful, you may request restriction instead of deletion.
If we no longer need your personal data but you require it to establish, exercise or defend legal claims, you may request restriction instead of deletion.
If you have lodged an objection under Art. 21(1) GDPR, a balance must be struck between your interests and ours. As long as it has not been determined whose interests prevail, you may request restriction of processing.
Where processing has been restricted, such data may, apart from being stored, only be processed with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest.
SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the change in the browser address bar from "http://" to "https://" and by the padlock symbol. When encryption is active, the data you transmit to us cannot be read by third parties.
Objection to promotional emails
We hereby object to the use of contact details published under our legal notice obligations for the purpose of sending unsolicited advertising and information material. We expressly reserve the right to take legal action in the event of unsolicited advertising being sent to us.
4. Data Collection on This Website
Server log files
The provider of these pages automatically collects and stores information in what are known as server log files, which your browser transmits automatically. These are:
browser type and version
operating system used
referrer URL
host name of the accessing computer
time of the server request
IP address
This data is not merged with other data sources. Collection takes place on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the technically error free presentation and optimisation of our website.
Contact by email or telephone
There is no contact form on this website. You can reach us by email at info@leo.med or by telephone at +43 1 361 4040.
If you contact us in this way, we store and process your enquiry together with all resulting personal data in order to handle your request. We do not pass this data on without your consent.
Processing takes place on the basis of Art. 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR).
Your data remains with us until you ask us to delete it, withdraw your consent, or the purpose of storage no longer applies. Where your enquiry becomes part of your medical record, the statutory retention periods apply.
Please do not send us any health data by unencrypted email. Please use our patient app 37.clinic or call us instead.
Online appointment booking (WISITOR)
For online appointment booking we use the WISITOR module, which is embedded on our website as a web frame. The provider is:
Dr. Wienzl Informationssysteme GmbH Parttartgasse 34/16a, A-1230 Vienna, Austria Web: https://www.wis.at
WISITOR is connected to our practice management software MEDSTAR from the same provider. When you open the page containing the booking frame, a connection is established to the provider's servers, during which technical data such as your IP address is transmitted.
When you reserve an appointment, you provide the information required for scheduling, in particular first and last name, date of birth, contact details, insurance number and the reason for the appointment. This data is stored on the provider's server and synchronised with the appointment planner in our practice management software.
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures and performance of a contract) together with the consent you give during the booking process. Where health data arises in the course of booking, for example through the stated reason for the appointment, we base the processing on Art. 9(2)(a) and (h) GDPR. We have concluded a data processing agreement pursuant to Art. 28 GDPR with the provider. Once the booking is complete, the data is transferred into our practice management software and is then subject to the retention periods applicable there.
Google Maps
This website uses the Google Maps mapping service. The provider is:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
In order to display the map, your browser must establish a connection to Google's servers. Google thereby learns that you have accessed our website and processes, among other things, your IP address. A transfer to the USA cannot be ruled out. Google is certified under the EU-US Data Privacy Framework.
Google Maps is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and § 165(3) TKG 2021. The map is only loaded after you have given your consent. You may withdraw your consent at any time with effect for the future.
Further information on Google's handling of user data can be found in Google's privacy policy at https://policies.google.com/privacy.
Framer Analytics
To evaluate the use of our website statistically, we use the analytics function built into Framer, our host. Aggregated metrics such as page views, country of origin and device type are recorded. The evaluation takes place without cookies and without the creation of user profiles. It is therefore not possible for us to identify individual visitors.
The legal basis is Art. 6(1)(f) GDPR. We have a legitimate interest in understanding the use of our online offering and improving it.
Google Fonts (locally hosted)
This website uses Google Fonts for a consistent display of typefaces. The fonts are installed locally, so no connection to Google's servers is established. Further information can be found at https://developers.google.com/fonts/faq.
5. Patient App 37.clinic
For digital communication with our patients, we use the Austrian health platform 37.clinic, available at https://app.37.clinic and as a mobile app.
Platform operator:
FirstU GmbH
Rechtsform: Gesellschaft mit beschränkter Haftung (GmbH)
Große Pfarrgasse 23/1
1020 Wien, Österreich
Purpose and functions
Through 37.clinic you can, among other things, request prescriptions, submit medical findings, end a period of sick leave, initiate appointments, and send messages to the practice team or to a doctor. Use of the app is voluntary and does not replace contact by telephone or in person.
Data processed
registration data: email address and password
personal data: title, first and last name, gender, date of birth
contact data: address, telephone number, country
insurance data: social insurance number, or policy number in the case of private insurance
the content of your requests, including health data and uploaded medical findings
billing and payment data for chargeable functions
Legal bases
Processing takes place in order to perform the treatment contract under Art. 6(1)(b) GDPR and, where health data is concerned, on the basis of Art. 9(2)(h) GDPR in conjunction with § 8(3) DSG. Registration itself and the voluntary use of the app are based on your consent under Art. 6(1)(a) and Art. 9(2)(a) GDPR. You may withdraw your consent at any time by discontinuing use and requesting deletion of your account.
Encryption
Chats and personal data in 37.clinic are end to end encrypted. On your first login, a personal security key is generated for you, which you should store safely. The platform operator has no access to the content of your messages. Within the practice, a graduated access model applies: messages sent through the "doctor consultation" function are visible only to physicians, not to the rest of the practice team.
Processing on our behalf and account activation
The operator processes your data on our behalf on the basis of an agreement pursuant to Art. 28 GDPR. Your account is only activated once our practice has approved it, which ensures that a treatment relationship exists.
Payment processing
Some functions of 37.clinic are chargeable and are billed through a credit system. Payments are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The data required for payment is transmitted to Stripe. The legal basis is Art. 6(1)(b) GDPR. No health data is transmitted in this process. Details can be found at https://stripe.com/privacy.
Storage period
Content that becomes part of the medical record is subject to the statutory retention period of at least ten years under § 51(3) Ärztegesetz 1998. If you end the link to our practice, the content will no longer be visible to you in the app, while we retain access in order to comply with our documentation obligations.
6. Data Processing in the Context of Medical Treatment
Beyond the use of this website, we process personal data when you receive treatment from us.
What data we process
master data such as name, date of birth, address, contact details, social insurance number and insurance status
health data such as medical history, diagnoses, findings, proposed treatments, medication, laboratory and examination results, imaging data
billing data
correspondence with you and with co-treating and referring institutions
Purposes and legal bases
We process this data in order to provide you with medical care, to fulfil our statutory documentation obligations and to bill for our services. The legal bases are Art. 6(1)(b) and (c) GDPR in conjunction with Art. 9(2)(h) GDPR, § 8(3) DSG, the Ärztegesetz 1998 and the social insurance provisions of the ASVG. Where we process data beyond this, for example for appointment reminder services, we obtain your consent.
Practice management software
For administration and documentation we use the medical software MEDSTAR from Dr. Wienzl Informationssysteme GmbH, Parttartgasse 34/16a, A-1230 Vienna. The provider may gain access to data in the course of maintenance and support. This cooperation is governed by a data processing agreement pursuant to Art. 28 GDPR.
e-card and ELGA
For billing with the social insurance institutions, we use the e-card system of the Federation of Social Insurance Institutions. As a healthcare provider we are connected to the Austrian electronic health record system ELGA. Access to ELGA data takes place exclusively within an active treatment relationship and in accordance with the Health Telematics Act 2012 (GTelG 2012). Information about your rights in ELGA, in particular about opting out, can be found at https://www.elga.gv.at.
Retention
We retain medical documentation for at least ten years from the last medical service, in accordance with § 51(3) Ärztegesetz 1998. Longer periods may apply to X-ray images and certain other records. Billing records are additionally subject to the retention period under § 132 BAO.
Confidentiality
All staff at our primary care centre are bound to confidentiality and to compliance with data protection law. Medical staff are additionally bound by medical confidentiality pursuant to § 54 Ärztegesetz 1998.


