Skip to main content

Privacy Policy for Karuna Care

We are delighted that you are interested in Karuna Care. The protection of your personal data is of particular importance to us. Personal data is always processed in accordance with the General Data Protection Regulation (GDPR) and the supplementary German data protection provisions.

Use of our website is generally possible without providing personal data. However, if you wish to take part in the recruitment process via our platform, processing of personal data may become necessary. Where there is no legal basis for such processing, we obtain your consent.

With this privacy policy we inform you about the nature, scope and purpose of the personal data we collect and process, as well as about the rights to which you are entitled. (Note: The German version is authoritative; any English translation is provided for your information only.)

§ 1 Definitions

This privacy policy uses the terms of the GDPR. To make it easy to understand, we explain the most important terms in advance:

  • Personal data: Any information relating to an identified or identifiable natural person (e.g. name, address, email address, phone number or online identifier).
  • Special categories of personal data: Data under Art. 9(1) GDPR that enjoys heightened protection (in particular data concerning health, ethnic origin, religious beliefs and biometric data).
  • Processing: Any operation related to personal data (e.g. collecting, storing, using, transmitting or erasing).
  • Restriction of processing: The marking of stored data with the aim of limiting its future processing.
  • Profiling: Any automated processing in which data is used to evaluate personal aspects of a person.
  • Pseudonymisation: Processing in such a way that the data can no longer be attributed to a person without additional information that is kept separately.
  • Controller: The natural or legal person who determines the purposes and means of the processing.
  • Processor: An entity that processes personal data on behalf of and under the instructions of the controller (e.g. our hosting provider).
  • Consent: Any freely given, informed and unambiguous indication of your wishes by which you agree to the processing of your data.

§ 2 Data Controller

The controller within the meaning of the GDPR is:

Moin Ul Haq

Gerhart-Hauptmann-Ring 290

60439 Frankfurt am Main, Germany

Phone: 0173 2375913

Email: info@karunacare.de

Website: https://karunacare.de

§ 3 What Data We Collect

Which personal data we process depends on the role in which you use our platform.

Data of nursing professionals (candidates)

During registration and use, we collect:

First and last name, email address, phone number, nationality, country and state, medical education (type and duration), graduation year, last employment in nursing, German language level, profile photos, and uploaded documents (passport/national ID, name change certificate, CV, qualification certificates, transcript of records, work references, declaration of intent, B2 language certificate).

Note: Passwords are stored exclusively as cryptographic hashes; your plain-text password is never known to us.

Employer data (clinics/facilities)

During registration, we collect:

Company name, street and house number, postal code, city, contact person name, position, department, business phone number and business email address.

Server log files & technical data

When our platform is accessed, the system automatically collects general data to ensure operation and prevent abuse (rate limiting). This is stored in server log files:

  • Browser type and version used, operating system
  • Previously visited page (referrer)
  • Date and time of access
  • IP address and internet service provider

This data does not allow us to draw any direct conclusions about your identity. IP addresses are processed temporarily and deleted from memory after a maximum of one hour. We do not use tracking cookies, analytics tools or advertising networks.

§ 4 Special Categories of Personal Data (Art. 9 GDPR)

As part of the recruitment process, we process data that qualifies as, or may contain, special categories of personal data within the meaning of Art. 9(1) GDPR:

  • CV and work references may allow conclusions about health data (e.g. areas of deployment and patient contact).
  • Passport, national ID and profile photo contain biometric data and may indicate ethnic origin.
  • Name change and marriage certificates may indicate marital status and, indirectly, religious beliefs.

Legal basis: This processing is carried out exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR, which you give during registration via a separate selection field. Without this consent, participation in the recruitment process is not possible. We store the wording of your consent in a versioned manner. You may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR).

§ 5 Purposes of Data Processing

We process your data exclusively for the following purposes:

  • Carrying out the recruitment process for nursing professionals from India to Germany.
  • Selecting and assigning candidates to suitable healthcare facilities (matching) by our administration team.
  • Managing and tracking the process status (application, pool, assignment, B2 language phase, recognition, visa, completion).
  • Communication between us, candidates and employers via email and in-app notifications.
  • Ensuring account security (password validation, login protection, email verification).

§ 6 Legal Bases for Processing

  • Art. 6(1)(b) GDPR: Performance of a contract and pre-contractual measures (carrying out the recruitment process and managing the user account).
  • Art. 6(1)(a) GDPR: Consent (where given); for special categories additionally Art. 9(2)(a) GDPR (explicit consent).
  • Art. 6(1)(c) GDPR: Legal obligation (e.g. to fulfil tax and commercial retention obligations).
  • Art. 6(1)(f) GDPR: Legitimate interest (platform security, abuse prevention and progressive account lockout on failed login attempts).

§ 7 Categories of Recipients and Third-Country Transfers

In order to provide our platform securely and reliably and to carry out the recruitment process, we share personal data with third parties or use external service providers. This only happens where it is legally permissible and necessary for the stated purposes.

Use of processors (IT service providers)

We use service providers bound by our instructions who process data exclusively on our behalf and according to our specifications (Art. 28 GDPR). These include service providers from the following categories:

  • Hosting and cloud providers: For providing our server infrastructure, databases and the secure storage of uploaded documents and profile photos.
  • Communication service providers: For the technical dispatch of system emails (e.g. password reset, verifications).

Insofar as we use service providers whose servers or parent companies are located in a third country (e.g. the USA), we ensure an adequate level of data protection. This is done primarily through the conclusion of EU Standard Contractual Clauses (Implementing Decision 2021/914) and certifications under the EU-US Data Privacy Framework.

Any further disclosure to external third parties only takes place where required by a legal obligation or where strictly necessary for the establishment, exercise or defence of legal claims.

§ 8 Cookies

The platform exclusively uses a technically necessary session cookie (next-auth.session-token) to maintain your login. This is an HTTP-only cookie with encrypted content (JWT). We do not use tracking, marketing or analytics cookies. Consent under Section 25 TDDDG is therefore not required.

§ 9 Data Retention

We store your personal data only for as long as is necessary for the stated purposes or as provided for by statutory retention periods.

Data of active candidates and employers is processed for the duration of the recruitment process. After completion, account data is archived and erased at your request, unless statutory retention obligations apply. Verification tokens are automatically deleted after 24 hours, password reset tokens after one hour.

§ 10 Your Rights as a Data Subject

Under the GDPR, you are entitled to the following rights:

a) Right of access (Art. 15) You can request confirmation of whether and which data we process about you, and obtain a copy.

b) Right to rectification (Art. 16) You can request the correction of inaccurate data and the completion of incomplete data.

c) Right to erasure (Art. 17) You can request erasure, provided no retention obligation or other exclusion applies.

d) Right to restriction of processing (Art. 18) Under certain conditions you can request the restriction of processing.

e) Right to data portability (Art. 20) You can receive your data in a structured, commonly used and machine-readable format.

f) Right to object (Art. 21) On grounds relating to your particular situation, you can object at any time to processing based on a legitimate interest.

g) Right to withdraw consent (Art. 7(3)) You can withdraw any consent you have given at any time with effect for the future.

h) Right to lodge a complaint (Art. 77) You have the right to lodge a complaint with a data protection supervisory authority.

To exercise your rights, an informal message to info@karunacare.de is sufficient. The supervisory authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.

§ 11 Automated Decisions and Profiling

We do not use any solely automated decisions within the meaning of Art. 22 GDPR that produce legal effects concerning you. Certain status changes are technically assisted (e.g. the change from “applicant” to “pool candidate” after an upload). These operations serve organisational purposes and are always carried out under the supervision of our administration team. The assignment of candidates to employers (matching) is carried out manually. No profiling for advertising purposes takes place.

§ 12 Data Security

We protect your data through appropriate technical and organisational measures:

  • Encrypted data transmission (HTTPS/TLS)
  • Passwords stored as hashes & encrypted session tokens (JWT)
  • Role-based access control (candidates only see their own data, employers only see assigned candidates)
  • Data-protection-compliant document filtering (identity and legal documents are never accessible to employers)
  • Progressive account lockout on suspicious login activity

Despite these measures, internet-based data transmission can in principle have security gaps; absolute protection is not possible.

§ 13 Necessity of Providing Data

The provision of certain data is partly required by law, partly required by contract or arises from the nature of the recruitment process. Without the required data and documents, we cannot carry out the recruitment process.

§ 14 Changes to this Privacy Policy

We reserve the right to amend this privacy policy in order to adapt it to changes in the legal situation or to changes in our service. The current version is always available on this page.