Privacy Policy — AVOR Assistant
1. Data Controller
The controller for the processing described in this policy is:
Avor Medical Intelligence UG (haftungsbeschränkt)
In der Lake 5b
33739 Bielefeld
Germany
Email: datenschutz@avor.med
2. Scope of This Policy
This policy covers the AVOR Assistant and the two forms through which access to it is granted:
- app.avor.med — the assistant itself, available after sign-in
- signup.avor.med — the waiting list
- register.avor.med — the access request
It does not cover our website avor.med. That site runs with a different provider and processes different data; our general privacy policy applies to it.
AVOR is a research prototype and not an approved medical device. Our terms of use apply in addition — in particular the instruction not to enter identifiable patient data.
3. Hosting and Server Location
The assistant and both forms run on a server we rent from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Nuremberg, Germany. A data-processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
We operate the software ourselves; no external form, analytics or chat service is embedded. The one exception is the processing of your input by GWDG, described in section 9.
The TLS certificates for the three addresses are obtained from Let's Encrypt (Internet Security Research Group, USA). As part of that process the host names — not your data — are published in publicly readable Certificate Transparency logs.
4. Registration: Waiting List and Access Request
Access to AVOR is reserved for medical professionals. Through the two forms you either join the waiting list or request access directly. Both collect the same information:
- title, first name, last name
- email address
- state medical association (Ärztekammer)
- lifelong physician number (LANR) or continuing-education number (EFN)
- optional: specialist status, type of workplace (practice, medical care centre, hospital), city
- your declaration that you are a licensed physician, with date and time
The purpose is to verify your professional status and — depending on the form — to set up access or to add you to the waiting list and notify you once a place becomes available. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract) and Art. 6(1)(f) GDPR; our legitimate interest is to restrict an offering aimed exclusively at medical professionals to that group.
The information is stored on our own server. No external form service is involved.
5. Verification of Professional Status (LANR/EFN)
We use the LANR or EFN once, to check your details against the physician directory of the state medical association you named. This check is carried out by people, not by an automated procedure.
The LANR and the EFN are professional identifiers, not health data; we do not process special categories of personal data within the meaning of Art. 9 GDPR through these forms.
We delete the number immediately after the check — both when access is granted and when a place on the waiting list is confirmed. If we cannot confirm your professional status, we keep your details including the number for a further 30 days after our reply, so that we can match any follow-up question to the right case; after that we delete them entirely.
6. Your Place on the Waiting List
Once we have confirmed your professional status, your name, email address, medical association and optional details remain stored until we can set up access for you — the waiting list consists of precisely these entries. There is no fixed retention period for them, because one would defeat the purpose: after it expired we could no longer notify you.
You may object at any time. An informal message to register@avor.med is enough — a reply to our confirmation email will do — and we will remove your entry and delete the associated data.
7. Your User Account
When we set up access for you, a user account is created in the assistant. It holds your name, a user name derived from it, your email address and your password as a cryptographic hash. We do not issue passwords for you and do not know yours; you set it yourself through the assistant's password function.
In addition there are technical details that belong to running the account: your role, whether your email address has been confirmed, whether you have accepted the terms of use, and — if you enable two-factor authentication — the associated secret and your recovery codes. Session data (sign-in tokens) is stored for the duration of your session; an access token is renewed every 15 minutes and a session ends after eight hours at the latest.
Your professional details from section 4 do not travel into the user account. They stay in the separate registration database, and only your name, user name and email address reach the account.
8. Using the Assistant: Input, Conversations, Files
What you enter in the assistant is stored on our server so that you can find your conversations again: your questions, the model's answers, the link to your account, timestamps and the conversation's label. That label is generated automatically by sending your first question and the first answer through a language model once more (see section 9).
You can attach text files and PDF documents (up to five files, each no larger than 10 MB). They are stored on our server and their content feeds into the processing of your question. Please do not attach documents containing identifiable patient data.
To let you search within your conversations we run a search index on the same server, which holds the content of your messages a second time. It does not leave the server.
The legal basis is Art. 6(1)(b) GDPR — without this processing the function you are using would not exist.
We do not delete your conversations automatically. You can delete individual conversations yourself in the assistant at any time; on request we will delete your account entirely, see section 15.
9. Processing of Your Input by GWDG
The assistant's answers are not produced by our server but by a language model provided by Gesellschaft für wissenschaftliche Datenverarbeitung mbH Göttingen (GWDG) through its SAIA interface. We transmit what is needed to answer:
- the text of your question and the history of that conversation so far
- the content of files you attached to that conversation
- a fixed professional instruction that we prepend to every request
- for the automatic naming of a conversation, additionally your first question and the first answer
Your name, email address, account identifier and IP address are not transmitted. The request is authenticated to GWDG with an access key that we assign to your account on the server side; GWDG can therefore attribute a request to a key, but not to you personally.
Processing takes place within the European Union. The legal basis for the transfer is Art. 6(1)(b) GDPR — without it the assistant could not answer your question.
To ground its answers, GWDG draws on a collection of public guideline and reference documents held there. That collection contains no user data.
10. Email Communication
As part of registration you receive up to two messages from us: confirmation of your place on the waiting list or the activation of your access — or our reply if we could not confirm your professional status. Each of these messages is also copied to our mailbox register@avor.med, so that your reply arrives in the same case there. Internally, a further message notifies us of your registration; it contains the details from section 4.
Messages are sent through the mail server of our domain provider Variomedia AG, Kronprinzendamm 21, 10711 Berlin, Germany. The connection to it is encrypted. The assistant additionally sends email when you reset a password.
The legal basis is Art. 6(1)(b) GDPR. If you reply to us, we process your message in order to answer it (Art. 6(1)(f) GDPR).
11. Log Data, Security and Usage Statistics
Accessing the three addresses creates technical log data, including your IP address and the time and target of the request. It serves operation and security; the legal basis is Art. 6(1)(f) GDPR. These logs are not kept indefinitely but overwritten on a rolling basis once a set volume is reached.
To protect against automated bulk submissions, the two forms limit the number of registrations per sending address. Your IP address is held in memory for at most one hour for that purpose; it does not enter the registration database.
Sign-in events at the assistant are logged separately with email address, IP address and time, in order to detect abusive sign-in attempts. We delete these records after 91 days.
For cost control and capacity planning we record the volume of text processed per request and attribute it to your account. We do not evaluate the content of your conversations for that purpose.
12. Retention at a Glance
- LANR/EFN: deleted immediately after the check; if we decline, 30 days after our reply
- Declined registrations: 30 days after our reply
- Approved access requests: 30 days after the decision; the user account is not affected
- Waiting-list entries: until access is granted or until you object
- User account and conversations: until you delete them or we delete your account at your request
- Session data: eight hours at most
- Sign-in logs: 91 days
- Technical log data: volume-limited, overwritten on a rolling basis
For recovery in the event of a failure, our hosting provider creates automatic snapshots of the server state, which are kept for seven days and then overwritten.
13. Recipients
We do not pass your data on to third parties. Only the following service providers are involved:
- Hetzner Online GmbH — operation of the server on which all three services run
- Gesellschaft für wissenschaftliche Datenverarbeitung mbH Göttingen (GWDG) — processing of your input by the language model, see section 9
- Variomedia AG — sending our emails
No transfer to a country outside the EU takes place. We do not use analytics or advertising services on these three addresses, and no fonts or scripts are loaded there from third-party servers.
14. No Automated Decision-Making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Your professional status is decided by people; the assistant produces text but makes no decisions about you.
We do not use your input to train models of our own, and we do not read your conversations for the purpose of content analysis.
15. Your Rights
You have the following rights with regard to your data stored by us:
- Right of access: You may request information about your personal data processed by us (Art. 15 GDPR).
- Right to rectification: You may request the correction of inaccurate data (Art. 16 GDPR).
- Right to erasure: You may request the deletion of your data, provided no legal retention obligations apply (Art. 17 GDPR).
- Right to restriction of processing: You may request the restriction of processing of your data (Art. 18 GDPR).
- Right to data portability: You may request to receive your data in a structured, commonly used, and machine-readable format (Art. 20 GDPR).
- Right to object: You may object to the processing of your data if it is based on legitimate interests (Art. 21 GDPR).
To exercise your rights, please contact datenschutz@avor.med. An informal message is enough to be removed from the waiting list or to have your account deleted.
16. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). The competent authority for us is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen).
17. Updates to This Privacy Policy
This privacy policy is currently valid and dated August 2026. Further development of the assistant or changes in legal or regulatory requirements may make it necessary to adapt it. The current version can be accessed on this page at any time.
← Back to Home