HealthGrow

Privacy Policy

HealthGrow privacy policy covering personal-data processing, analytics, contact requests, data transfers and your rights under the GDPR.

Last updated: July 2026

1. Controller

  • HealthGrow
  • Proprietor: Fabian Mühlstädt
  • Am Tannhof 11a
  • 24536 Neumünster, Germany
  • Phone: +49 176 3118 3738
  • Email: kontakt@health-grow.de

2. General information

We process personal data in accordance with the GDPR and applicable German data-protection law. Personal data means any information relating to an identifiable person.

Internet transmission may have security vulnerabilities; complete protection against third-party access is not possible.

3. Hosting and server logs

This website is hosted through Railway. IP address, date and time, requested file, referrer URL, browser, operating system and transferred data may be processed for secure and stable operation under Art. 6(1)(f) GDPR.

More information: https://railway.com/legal/privacy

4. Contact

When you contact us through the contact form, by email or by phone, we process your details to respond. Contact-form requests are processed through our Railway infrastructure and stored in the Convex database (Convex Inc., USA); we use Plunk (UsePlunk) for the notification email. The legal basis is Art. 6(1)(b) GDPR for contractual matters and otherwise Art. 6(1)(f) GDPR.

5. Cookies and similar technologies

Strictly necessary storage is based on Section 25(2) TDDDG. Analytics and marketing technologies generally require consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent can be withdrawn at any time for the future.

6. Google Analytics 4

We use Google Analytics 4 (Google Ireland Limited) for website statistics. Usage, device and approximate location data may be processed, including in the United States. Processing is based on consent. More information: https://policies.google.com/privacy

7. Meta Pixel and Conversions API

We use Meta Pixel and, following a successful contact request, Meta Conversions API (Meta Platforms Ireland Limited) to measure advertising and create audiences. Browser, device, IP, page-view and interaction data as well as normalized and cryptographically hashed contact data may be processed, including in the United States. Free-text messages are not sent to Meta. Processing takes place only after marketing consent. More information: https://www.facebook.com/privacy/policy/

8. Recipients and international transfers

We disclose data only where legally permitted, necessary for a contract or covered by consent. Providers may rely on an adequacy decision such as the EU-U.S. Data Privacy Framework or EU Standard Contractual Clauses.

9. Retention

We retain personal data only as long as required for its purpose or by law. Consent-based data is deleted after withdrawal unless another legal basis applies.

10. Your rights

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection
  • Withdrawal of consent for the future
  • Complaint to a supervisory authority

11. Direct-marketing objection

You may object at any time to processing for direct marketing. After an objection, the data will no longer be used for that purpose.