Updated: August 06, 2026
Privacy policy for the online courses
This privacy policy contains information about the processing of your personal data in the HelloBetter online courses. This privacy policy does not apply to data processing on our websites outside of the course. You can find the privacy policy for our website here. By clicking on the respective headings, you will receive further information.
1. Contact details of the responsible person
HelloBetter is a trademark of the
GET.ON Institute for Online Health Trainings GmbH
Schrammsweg 11
20249 Hamburg
Tel.: +49 (0)40 / 532 528 67
Email: kontakt@hellobetter.de
which is responsible for the processing of your personal data.
2. Contact details of the data protection officer
Data protection officer of HelloBetter
GET.ON Institute for Online Health Trainings GmbH
Oranienburger Str. 86a
10178 Berlin
Email: datenschutz@hellobetter.de
3. Data processing within the framework of the online course
3.1 Scope of the processing of personal data
We process the following registration and health data as part of the use of our online courses:
- User name
- Email address
- Gender
- Telephone number
- Your answers within questionnaires (screening)
- Symptoms
- Date of birth
- Information entered in free text fields during the course in order to work on exercises or to get in contact with us
- Messages to us via the encrypted messaging function of the course platform (only for courses accompanied by psychologists)
- Language setting
- Branch Cookie ID
If you participate in our courses as part of an offer of your health insurance company (e.g. preventive care offers, additional offers, offers of special care), additional data may be collected for billing purposes towards your health insurance, e.g.:
- Insurance number
- Insurance company
3.2 Purposes of data processing
We process personal data of our users only insofar as this is necessary for the provision of a functional platform as well as our content and services. The health data collected during the course is used exclusively to carry out the course and thus to improve your mental state of health.
Some courses are accompanied by psychologists and offer a built-in messenger to allow a direct exchange with the psychologist.
Personal data of our users is regularly processed only with the consent of the user.
3.3 Legal basis for data processing
The processing of your personal data within the course is based on your consent according to Article 6 (1) (a) GDPR for registration data and Article 9 (2) (a) GDPR for medical data. If you do not give us your consent, participation in the online course is not possible.
You can revoke your consent to the processing of personal data at any time. You can do this in your profile settings. If you revoke your consent, you can no longer use the online course. Please note that the revocation is only effective for the future. Data processing that took place before the revocation is not affected.
3.4 Recipients
In general, your medical data will not be passed on to third parties (e.g. your health insurance company).
For the provision of our service, we use the AWS European Sovereign Cloud, in which your data is stored. The operator is Amazon Web Services EMEA SARL (38. Avenue John F. Kennedy, L-1855 Luxembourg). Your data will be processed in the Paris AWS region.
To route users to the correct in-app content after clicking a link (deep linking) and for attribution and analytics reporting, we use the service provider Branch (Branch Metrics, Inc., 1975 W El Camino Real Ste. 102, Mountain View, CA 94040, USA). Via the Branch SDK, device data (e.g. operating system, device model, screen size, language setting) and a Branch Cookie ID are processed. No user identities or advertising identifiers are transmitted to Branch.
If your participation is based on an offer from your health insurance company, registration data required for billing the service provided will be transmitted to the health insurance company. A transmission of course data to the health insurance company is excluded.
3.5 Storage period
As long as you use your account, your data will be stored. If you want to delete your data, you can do so within your profile settings.
Data for billing purposes will be kept as long as required by legal retention periods (up to 6 years).
For data processed via Branch, the following retention periods apply:
- Device-matching data is deleted after 30 days of inactivity.
- Identifiable usage logs are deleted after a maximum of 14 days.
- Pseudonymised logs are deleted after 12 months.
4. Server logs
When using our servers (e.g. when registering and going through the course), technical connection data is processed that is transmitted to us by your device. This includes the following data:
- IP address
- Browser and version number
- Date and timestamp of the web page access
4.1 Purposes, legal basis and obligation to provide personal data
The processing is carried out within the scope of our legitimate interest pursuant to Article 6 (1) (f) GDPR for the provision of our online platform, to secure our systems and to ensure technical functionality.
Providing this data is technically necessary so that the retrieved content can be delivered to you.
4.2 Transmission and storage period of the data
In principle, this data is not passed on to third parties. However, in the event of an attack on our systems, the data in question may be passed on to the law enforcement authorities.
The data is automatically deleted after six months. In the event of criminal proceedings, the data will be deleted after the proceedings have been concluded.
5. Scientific evaluation
You have the option during registration and in your profile settings to give consent to participate in a scientific evaluation of your course data.
The following section provides information about the data processing in case you give your consent. Your data will not be processed for these purposes without your consent. Your participation is voluntary. There will be no negative consequences if you do not give your consent.
5.1 Purposes and legal basis
Scientific evaluation is used to conduct studies to explore intervention effects in routine care. The use of this research data provides insights into the actual effectiveness of the intervention under routine conditions and enables the ongoing optimization of our products.
Your data will not be processed without your consent pursuant to Article 6 (1) (a) GDPR and Article 9 (2) (a) GDPR.
If you give your consent, your data will be anonymized as far as possible within the framework of the scientific evaluation so that it is impossible to draw conclusions about your person. The evaluation will only be carried out with anonymized data.
5.2 Recipients of scientific evaluation data
The anonymized data can be passed on to other researchers in universities and other research institutions for study purposes. Data will only be passed on after it has been anonymized.
5.3 Anonymization, right of withdrawal
The anonymization of your course data cannot completely exclude a later conclusion to your person by information that you may have published about yourself via other sources (e.g. by references on your social media profiles about your participation in the study).
You can revoke your consent in your profile settings at any time. A revocation is only effective for processing from the time we receive it. Processing that took place before the revocation is not affected.
Please note that a right of revocation does not apply to anonymized data, as an assignment of the data to your person will no longer be possible at this point.
6. Application-specific performance measurement
For the purposes of the mandatory application-accompanying performance measurement, we collect and process specific usage and health data (AbEM).
6.1 Scope, purpose and legal basis of data processing
The aim of this processing is to ensure transparency regarding the use, patient satisfaction and medical success of the digital health application (DiGA) in standard care.
The aggregated results are submitted to the Federal Institute for Drugs and Medical Devices (BfArM) every six months to fulfil our legal obligations.
The processing of data (including health data) for AbEM purposes takes place exclusively on the basis of your explicit consent in accordance with Article 6(1)(a) in conjunction with Article 9(2)(a) of the GDPR, in conjunction with Section 4(2), first sentence, No. 3 of the DiGAV.
Consent to data processing pursuant to Section 4(2) of the DiGAV may be withdrawn at any time with future effect; please note that withdrawal of this consent will result in the termination of DiGA use.
6.2 Recipients
The data collected as part of the post-marketing performance monitoring is transmitted to the Federal Institute for Drugs and Medical Devices (BfArM).
6.3 Retention period
Your data will only be stored for as long as is necessary for the purposes of application-related performance monitoring.
In principle, the storage period is linked to the duration of your DiGA prescription. Upon expiry of the prescription, upon withdrawal of your consent or once the legal purpose for evaluation no longer applies, your personal data will be deleted immediately, unless you have consented to a temporary extension (grace period) or statutory retention obligations apply.
7. Online Withdrawal Function (for self-paying customers only)
Where you purchase our programmes as a self-paying customer, you are entitled to an online withdrawal function (withdrawal button) in accordance with § 356a of the German Civil Code (BGB).
7.1 Scope, Purpose and Legal Basis of Data Processing
When you make use of this function, we collect your name, contract-identifying data, as well as the date and time of the declaration.
Processing is carried out for the technical and legal handling of the withdrawal and to fulfil our statutory obligations. The legal bases are Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (compliance with a legal obligation).
7.2 Retention Period
Following the completion of the contract reversal, we retain these data on the basis of Art. 6(1)(c) GDPR in order to fulfil statutory retention obligations under commercial and tax law pursuant to the German Commercial Code (HGB) and the German Fiscal Code (AO) for a maximum of 10 years, after which they are deleted.
8. Data subject rights
You can assert the rights listed below against HelloBetter. HelloBetter enables you to exercise numerous rights via the profile settings within the online courses. Please contact us to exercise any rights that are not covered by the profile settings within the course itself.
For the right to information and the right to deletion, the restrictions according to Sections 34 and 35 BDSG (German Federal Data Protection Act) apply.
8.1 Information according to Article 15 GDPR
You can request information about your personal data processed by HelloBetter, along with a copy of the data. In the online course, you have access to the data processed in the course at any time.
8.2 Right of rectification according to Article 16 GDPR
If your data is incorrect or incomplete, you have the right to request the correction or completion of your personal data. You can correct and complete your data via your profile settings within the online course.
8.3 Deletion of your personal data according to Article 17 GDPR
You can request the deletion of your personal data. You can delete your data within the options in the profile settings by choosing the option to delete your account. Please note that this cannot be undone.
8.4 Restriction of processing according to Article 18 GDPR
You have the right to request restriction of the processing of your personal data if one of the following requirements is met:
- You dispute the accuracy of your personal data.
- The processing is unlawful and you oppose the deletion of your personal data.
- We no longer need the data for the purposes of processing, but you require the data for the establishment, exercise or defence of legal claims.
- You have objected to the processing (see right of objection, Section 9) and the balancing of interests as part of the objection procedure has not yet been completed.
8.5 Data portability according to Article 20 GDPR
You have the right to receive the personal data which you have provided to HelloBetter in a structured, commonly used and machine-readable format and to transmit those data to another company without hindrance from HelloBetter.
8.6 Right to lodge a complaint with a supervisory authority according to Article 77 GDPR
You have a right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for HelloBetter is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Thomas Fuchs
Ludwig-Erhard-Str. 22, 7th floor
20459 Hamburg
Tel.: +49 (0)40 / 428 54 – 4040
Fax: +49 (0)40 / 428 54 – 4000
Email: mailbox@datenschutz.hamburg.de
9. Right of objection according to Article 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6 (1) (f) GDPR (data processing on the basis of a legitimate interest of HelloBetter).
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of establishing, exercising or defending legal claims.
10. Automated decision-making and profiling
Automated decision-making or profiling that produces a legal effect concerning you does not take place.