Bramfelder Straße 140
22305 Hamburg
E-Mail:
Network access is essential since the TK-App can only be used in online mode. The only function available offline is the display of any Covid certificates you have added.
When using the TK-App, security-relevant data are encrypted and stored locally. Some of the settings in the TK-App can also be stored locally, for example your consent to the data privacy policy or information about screens that should no longer be displayed.
Your device must undergo a security check before you can use it to access the TK-App. This involves the detection and analysis of your device status.
Your insurance number and/or username serve as your unique identifiers with our online service "Meine TK". You also need this username to log in to the TK-App.
If your device's technology supports biometric log-in, the log-in process is classified as secure and you have activated this function on the device, you will be asked if you would like to use these identifiers to log in to the TK-App. Your consent is voluntary. You can decline this offer or, should you choose to accept it, you can withdraw your consent at any time by changing the settings. The TK-App uses the operating system's mechanisms for checking biometric identifiers. The TK-App does not receive any of these biometric identifiers; it only receives the result. When you configure the app, TK uses the biometric identifiers in the system to generate cryptographic material and store it on the device. At no time does TK receive any data about your biometric identifiers. Devices with Android operating systems use the Google Play Integrity service to perform regular checks to ensure that the device is functioning at the necessary security level. The result is transmitted to TK. TK does not transmit or store any of your personal data during this process.
For identification purposes you need to use an activation code. It is a security code which will be delivered via mail. Always keep the activation code safe from third-party access.
TK collects and stores the following data when registering your device:
To access the data in the prescription service, you have to confirm your identity. This is because only you or your representative and the doctor's practice which issued the prescription and the redeeming pharmacy may access the data in the prescription service.
Once you are registered, your prescriptions saved in the prescription service are downloaded and displayed. The prescriptions which have been called up are only kept in the working memory whilst the app is in use. The data are deleted again as soon as you close the TK-App.
You can redeem a prescription using the app by assigning it to a pharmacy. Communication in this case is via the prescription service; there is no direct communication between the TK-App and the pharmacy. If the prescription is assigned to a pharmacy, this is logged in the prescription service and the prescription status is changed to "in Einlösung" [to be redeemed]. The status of a prescription can be viewed in the app at any time.
To assign a prescription to a pharmacy, your search criteria are sent to a pharmacy directory service and a search is performed. A search can also be carried out based on your current location. This function is optional. For it to be enabled, you must allow access to your location in your device's settings. Based on the search criteria provided, a list of suitable pharmacies is shown in the app.
Communication with pharmacies is via the prescription service; the messages from pharmacies are stored here and downloaded by the TK-App. The called-up messages are only stored in the working memory whilst the app is being used. The data are deleted as soon as the TK-App is closed.
You can delete the prescriptions saved in the prescription service at any time via the app. Furthermore, the prescriptions in the prescription service are deleted automatically 100 days after being issued or following the last status change (Section 360, para. 11 SGB V [German Social Code, book V]).
Access to your system camera is essential if you wish to send TK a document for processing (a photo of your fit note, for example). Your device memory is also accessed if you wish to send TK a photo or PDF file that you have already stored.
You can receive push notifications from the TK-App (section 4.3).
You can authorise access to any exercise data recorded by your smartphone for use with our TK-Fit service (section 6.4).
When you install the app, older Android operating systems (OS) will ask you to consent to the use of your phone (the app is able to initiate and manage phone calls). This is because older operating systems included access to your device status within the scope of this consent. This authorisation is necessary for the TK-App to execute its basic functions (section 4.1). At no time does TK use your contact or call data. Newer operating systems no longer issue this authorisation request since it is one of the basic functions of your operating system.
If you wish to search for a pharmacy based on your location within the scope of the e-prescription functionality (section 4.7), you need to authorise this function.
When registering for our TK-Safe service (section 6.4), there is one specific constellation that requires access to your microphone. This authorisation is necessary to review the authenticity of your device and generate your TK-Safe security key.
The "Settings > Security > System Authorisations" menu item in the TK-App allows you to track the authorisations you have granted and withdraw these at any time. You can also view and revoke your authorisations in the respective operating systems.
You can delete your device registration at any time in the TK-App, "Meine TK" or via our telephone support hotline. When you delete your device registration, we will erase all the data collected for this purpose (section 4.2.3). The same applies to the deletion of your "Meine TK" user account. If you reinstall the TK-App, the data collected to register your device will be erased and replaced by the more recent data.
Uninstalling the TK-App will erase the following locally stored data:
b) Right to rectification (Section 16 GDPR)
c) Right to erasure (deletion) (Section 17 GDPR)
d) Right to restriction of processing (Section 18 GDPR)
e) Right to object (Section 21 GDPR)
Beauftragter für den Datenschutz
Bramfelder Str. 140
22305 Hamburg
E-Mail: datenschutz@tk.de
Der BfDI:
The BAS: