Privacy Policy

Preamble

With the following data protection declaration, we would like to inform you about the types of your personal data (hereinafter also referred to as “data” for short) that we process, for what purposes and to what extent. The data protection declaration applies to all processing of personal data carried out by us, both as part of the provision of our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “Online Offer”).

The terms used are not gender-specific.

Status: May 20, 2023

Table of contents

  • Preamble
  • Person responsible
  • Overview of the processing operations
  • Relevant legal bases
  • Security measures
  • Transfer of personal data
  • Data processing in third countries
  • Deletion of data
  • Business services
  • Use of online platforms for offering and sales purposes.
  • Provision of the online offer and web hosting
  • Special notes on applications (apps)
  • Purchase of applications via app stores
  • Registration, login and user account
  • Community functions
  • Contact and request management
  • Push messages
  • Newsletter and electronic notifications
  • Web analytics, monitoring and optimization
  • Modification and updating of the privacy policy
  • Rights of data subjects
  • Definitions of terms

 

Person Responsible

MP Technologies UG (haftungsbeschränkt)

Rieslingweg 1468309 Mannheim

E-Mail-Adress: data-security@mindpals.de

Overview of the processing operations

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

Types of processed data:

  • Inventory data
  • Payment data.
  • Location data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication, and procedural data

Categories of affected persons:

  • Customers
  • Prospects
  • Communication partners
  • Users
  • Business and contract partners

Purposes of processing:

  • Provision of contractual services and customer service
  • Contact inquiries and communication
  • Security measures
  • Direct marketing
  • Reach measurement
  • Office and organizational procedures
  • Conversion measurement
  • A/B testing
  • Administration and response to inquiries
  • Feedback
  • Marketing
  • Profiles with user-related information
  • Provision of our online offer and user-friendliness
  • Information technology infrastructure

 

Significant Legal Bases

Below you will find an overview of the legal bases of the GDPR (General Data Protection Regulation) on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. If more specific legal bases are applicable in individual cases, we will inform you about them in the privacy policy.

  • Consent (Art. 6 para. 1 p. 1 lit. a) GDPR) – The data subject has given consent to the processing of their personal data for a specific purpose or multiple specific purposes.
  • Contractual Performance and Pre-contractual Inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR) – The processing is necessary for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures at the data subject’s request.
  • Legal Obligation (Art. 6 para. 1 p. 1 lit. c) GDPR) – The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate Interests ((Art. 6 para. 1 p. 1 lit. f) GDPR) – The processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. This includes in particular the Act on the Protection against Misuse of Personal Data in Data Processing (Bundesdatenschutzgesetz – BDSG). The BDSG contains special provisions regarding the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transmission as well as automated decision-making on a case-by-case basis, including profiling. Furthermore, it regulates the processing of data for the purposes of employment relationships (§ 26 BDSG), particularly with regard to the establishment, implementation, or termination of employment relationships, as well as the consent of employees. Additionally, state data protection laws of individual federal states may be applicable.

Security Measures

We implement appropriate technical and organizational measures, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk. These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, input, disclosure, availability, and separation of the data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the erasure of data, and responses to data breaches. We also consider data protection principles in the development or selection of hardware, software, and procedures, including privacy by design and by default. IP Address Anonymization: If IP addresses are processed by us or by the service providers and technologies we use, and the processing of the full IP address is not necessary, the IP address is truncated (also referred to as “IP masking”). In this case, the last two digits or the last part of the IP address after a dot are removed or replaced with placeholders. The purpose of IP address anonymization is to prevent or significantly impede the identification of a person based on their IP address. TLS Encryption (https): To protect the data transmitted via our online services, we use TLS encryption. You can recognize such encrypted connections by the prefix https:// in the address bar of your browser.

Transfer of personal data

As part of our processing of personal data, it may be necessary to transmit the data to other entities, companies, legally independent organizational units, or individuals, or to disclose them to them. Recipients of this data may include, for example, IT service providers or providers of services and content that are integrated into a website. In such cases, we comply with legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.

Data Processing in Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if the processing takes place as part of using third-party services or disclosing/transferring data to other individuals, entities, or companies, we do so in accordance with legal requirements. Unless expressly consented to or contractually or legally required, we only process or allow data to be processed in third countries with a recognized level of data protection. This can be ensured through contractual obligations, such as the EU Commission’s Standard Contractual Clauses, certifications, or binding corporate rules (Articles 44 to 49 of the GDPR). For more information, you can visit the European Commission’s website on the international dimension of data protection: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en.

Deletion of Data

The data processed by us will be deleted in accordance with the legal requirements as soon as their consents permitted for processing are revoked or other permissions cease to apply (e.g. if the purpose of processing this data has ceased to apply or it is not required for the purpose). If the data are not deleted because they are required for other and legally permissible purposes, their processing will be limited to these purposes. That is, the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for reasons of commercial or tax law or whose storage is necessary for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person.

Our data protection notices may also contain further details on the retention and deletion of data, which take priority for the respective processing operations.

Business services

We process data of our contractual and business partners, e.g. customers and interested parties (collectively referred to as “contractual partners”) in the context of contractual and comparable legal relationships as well as related measures and in the context of communication with contractual partners (or pre-contractual), e.g. to answer inquiries.

We process this data in order to fulfill our contractual obligations. This includes, in particular, the obligations to provide the agreed services, any update obligations and remedies in the event of warranty and other service disruptions. In addition, we process the data to protect our rights and for the purpose of administrative tasks associated with these obligations and company organization. Furthermore, we process the data on the basis of our legitimate interests in proper and business management as well as security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information and rights (e.g. for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the framework of applicable law, we only disclose the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners will be informed about further forms of processing, e.g. for marketing purposes, within the scope of this data protection declaration.

We inform the contractual partners which data is required for the aforementioned purposes before or in the course of data collection, e.g. in online forms, by means of special marking (e.g. colors) or symbols (e.g. asterisks or similar), or in person.

We delete the data after expiry of legal warranty and comparable obligations, i.e., in principle after 4 years, unless the data is stored in a customer account, e.g., as long as it must be kept for legal archiving reasons. The statutory retention period is ten years for documents relevant under tax law as well as for commercial books, inventories, opening balances, annual financial statements, the work instructions required to understand these documents and other organizational documents and accounting records, and six years for received commercial and business letters and reproductions of sent commercial and business letters. The period shall commence at the end of the calendar year in which the last entry was made in the book, the inventory, the opening balance sheet, the annual financial statements or the management report was prepared, the commercial or business letter was received or dispatched or the accounting document was created, furthermore the recording was made or the other documents were created.

Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and data protection notices of the respective third-party providers or platforms shall apply in the relationship between the users and the providers.

  • Types of data processed: inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., e-mail, telephone numbers); contract data (e.g., subject matter of contract, term, customer category); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
  • Data subjects: Customers; prospective customers; business and contractual partners.
  • Purposes of processing: provision of contractual services and customer service; security measures; contact requests and communication; office and organizational procedures; administration and response to requests.
  • Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR); Legal obligation (Art. 6 para. 1 p. 1 lit. c) GDPR); Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR).

Further guidance on processing operations, procedures and services:

  • Customer Account: Customers can create an account within our online offering (e.g., customer or user account, hereinafter referred to as “customer account”). If registration of a customer account is required, customers will be informed about this requirement and the necessary information for registration. Customer accounts are not public and cannot be indexed by search engines. During registration, subsequent logins, and use of the customer account, we store customers’ IP addresses along with the access timestamps to verify the registration and prevent any misuse of the customer account. If the customer account is terminated, the data associated with the customer account will be deleted after the termination date, unless they need to be retained for purposes other than providing the customer account or for legal reasons (e.g., internal storage of customer data, order processes, or invoices). It is the responsibility of the customers to secure their data upon termination of the customer account; Legal basis: Contractual fulfillment and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR); Service provider: undefined; Website: undefined; Privacy policy: undefined.
  • Provision of Software and Platform Services: We process the data of our users, registered users, and potential test users (hereinafter collectively referred to as “users”) in order to provide them with our contractual services and, based on legitimate interests, to ensure the security and further development of our offering. The required information is indicated as such during the order, purchase, or similar conclusion of a contract, and includes the information necessary for service provision and invoicing, as well as contact information for potential communication; 
  • Legal basis: Contractual fulfillment and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR).

 

Use of online platforms for offering and sales purposes

We offer our services on online platforms operated by third-party service providers. In this context, in addition to our privacy notices, the privacy notices of the respective platforms also apply. This applies particularly to the payment process and the usage of measurement methods and interest-based marketing techniques employed on the platforms.

  • Processed data types: Master data (e.g., names, addresses), payment data (e.g., bank details, invoices, payment history), contact data (e.g., email, phone numbers), contract data (e.g., contract subject, duration, customer category), usage data (e.g., visited websites, interest in content, access times), meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Data subjects:
  • Purposes of processing: Provision of contractual services and customer support, marketing.
  • Legal basis: Contractual performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR). 

Further information on processing procedures, methods, and services:

  • Google Play: App and software sales platform; Legal basis: Legitimate interests (Art. 6(1)(f) of the GDPR); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://play.google.com/store/apps?hl=en; Privacy Policy: https://policies.google.com/privacy.
  • Apple App Store: App and software sales platform; Service provider: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; Legal basis: Legitimate interests (Art. 6(1)(f) of the GDPR); Website: https://www.apple.com/ios/app-store/; Privacy Policy: https://www.apple.com/legal/privacy/en-ww/.

Provision of the online offer and web hosting

We process user data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functionality of our online services to the user’s browser or device.

  • Processed data types: Usage data (e.g., visited web pages, interests in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g., website visitors, users of online services); Customers.
  • Purposes of processing: Provision of our online offerings and user-friendliness; Information technology infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.); Security measures; Provision of contractual services and customer support.
  • Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR).

Here are additional notes on processing operations, procedures, and services

  • Provision of online services on rented storage space: To provide our online services, we utilize storage space, computing capacity, and software obtained from a server provider (also referred to as “web hoster”); Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); Service provider: Undefined; Website: Undefined; Privacy policy: Undefined.
  • Collection of access data and log files: Access to our online services is logged in the form of server log files. Server log files may include the address and name of accessed web pages and files, date and time of access, data volumes transferred, message about successful access, browser type and version, user’s operating system, referrer URL (previously visited page), and typically, IP addresses and the requesting provider. Server log files may be used for security purposes, such as preventing server overload (especially in the case of abusive attacks, such as DDoS attacks), as well as ensuring server performance and stability; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); Data deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data that needs to be retained for evidentiary purposes will be exempt from deletion until the respective incident is finally resolved; Service provider: Undefined; Website: Undefined; Privacy policy: Undefined.
  • netcup: Services in the field of providing information technology infrastructure and related services (such as storage space and/or computing capacity); Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); Data processing agreement: https://www.netcup-wiki.de/wiki/Zusatzvereinbarung_zur_Auftragsverarbeitung; Service provider: netcup GmbH, Daimlerstraße 25, D-76185 Karlsruhe, Germany; Website: https://www.netcup.de/; Privacy policy: https://www.netcup.de/kontakt/datenschutzerklaerung.php.
  • Sentry: Monitoring system stability and identifying code errors – Device information or error timestamps are collected pseudonymously and subsequently deleted; Service provider: Functional Software Inc., Sentry, 132 Hawthorne Street, San Francisco, California 94107, USA; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); Website: https://sentry.io; Security measures: Defined (Undefined), Undefined (Undefined), Undefined (Undefined), Undefined (Undefined); Privacy policy: https://sentry.io/privacy; Standard Contractual Clauses (ensuring an adequate level of data protection for processing in third countries): https://sentry.io/legal/dpa/.

Special notes on applications (apps)

We process user data in our application to provide users with the application and its functionalities, monitor their security, and further develop the application. In accordance with legal requirements, we may also contact users for administrative or usage purposes related to the application. For further details regarding the processing of user data, please refer to the privacy policy in this privacy statement.

Legal basis: The processing of data necessary for providing the application’s functionalities is based on the fulfillment of contractual obligations. This also applies when the provision of functions requires user authorization (e.g., device permissions). If the processing of data is not necessary for providing the application’s functionalities but serves the application’s security or our business interests (e.g., data collection for optimizing the application or security purposes), it is based on our legitimate interests. If users are explicitly asked for their consent to process their data, the processing of data covered by the consent is based on their consent.

Information about application features: To create an account, entering a phone number is required. This number is encrypted and transmitted to our servers solely for registration purposes, where it is stored only as an irreversible hash value. During each registration process, the phone number is also transmitted once to a service provider for the purpose of delivering a verification code via SMS. The phone number is automatically deleted from the service provider’s system within a maximum of 90 days.

 

  • Processed data types: Master data (e.g., names, addresses), meta-communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status), payment data (e.g., bank details, invoices, payment history), contract data (e.g., contract object, duration, customer category).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and customer support.
  • Legal bases: Consent (Art. 6 para. 1 p. 1 lit. a) GDPR), contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR).

 

Further information on processing operations, procedures, and services:

  • Commercial use: We process the data of the users of our application, registered users and any test users (hereinafter uniformly referred to as “users”) in order to be able to provide our contractual services to them and on the basis of legitimate interests in order to be able to guarantee the security of our application and to develop it further. The required information is identified as such in the context of the conclusion of the use, order, purchase order or comparable contract and may include the information required for the provision of services and for any billing, as well as contact information in order to be able to hold any consultations; legal basis: contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR).
  • Storage of a universal and unique identifier (UUID): The Application stores a so-called universal and unique identifier (UUID) for the purpose of analyzing the use and functionality of the Application as well as storing the settings of the Users. This identifier is generated when this application is installed (but is not associated with the device, so it is not a device identifier in this sense), remains stored between the launch of the application as well as its updates, and is deleted when users remove the application from their device; Service provider: undefined; Website: undefined; Privacy policy: undefined.
  • ClickSend: Cloud communication platform that can be used, for example, to make and receive calls programmatically, send and receive text messages, and perform other communication functions using the web service interfaces; Legal Grounds: Legitimate Interests (Art. 6(1) p. 1 lit. f) GDPR); Standard Contractual Clauses (ensuring level of data protection for processing in third countries): https://clicksend-api-downloads.s3.ap-southeast-2.amazonaws.com/_public/_legal/ClickSend+-+Part+E+-+Standard+Contractual+Clauses.pdf; Service Provider: ClickSend Pty Ltd of Level 24, 367 Collins Street, Melbourne VIC Australia 3000; website: https://www.clicksend.com; privacy policy: https://www.clicksend.com/de/legal/privacy-policy/.

Purchase of applications via app stores

Our app is obtained via special online platforms operated by other service providers (so-called “app stores”). In this context, the data protection notices of the respective app stores apply in addition to our data protection notices. This applies in particular with regard to the methods used on the platforms for reach measurement and interest-based marketing as well as any obligation to pay costs.

  • Types of data processed: inventory data (e.g., names, addresses); payment data (e.g., bank details, invoices, payment history); contact data (e.g., e-mail, telephone numbers); contract data (e.g., subject matter of contract, term, customer category); usage data (e.g., websites visited, interest in content, access times). e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, time data, identification numbers, consent status); content data (e.g., entries in online forms).
  • Data subjects: Customers; users (e.g., website visitors, users of online services).
  • Purposes of processing: provision of contractual services and customer service; marketing.
  • Legal grounds: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR).

Further notes on processing operations, procedures and services:

  • Apple App Store: App and software sales platform; Service provider: Apple Inc, Infinite Loop, Cupertino, CA 95014, USA; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); Website: https://www.apple.com/de/ios/app-store/; Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
  • Google Play: App and software sales platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 (1) p. 1 lit. f) GDPR); Website: https://play.google.com/store/apps?hl=de; Privacy policy: https://policies.google.com/privacy.

Registration, login and user account

Users can create a user account. In the course of registration, users are provided with the required mandatory data and processed for the purpose of providing the user account on the basis of contractual obligation fulfillment. The processed data includes in particular the login information (username, password as well as an e-mail address).

In the context of the use of our registration and login functions as well as the use of the user account, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests as well as those of the users in protection against misuse and other unauthorized use. As a matter of principle, this data is not passed on to third parties unless it is necessary for the prosecution of our claims or there is a legal obligation to do so.

Users may be informed by e-mail about processes relevant to their user account, such as technical changes.

  • Types of data processed: inventory data (e.g., names, addresses); contact data (e.g., e-mail, telephone numbers); content data (e.g., entries in online forms); meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: provision of contractual services and customer service; security measures; administration and response to inquiries; provision of our online offer and user-friendliness.
  • Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR); Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR).

Further notes on processing operations, procedures and services:

  • Registration with pseudonyms: Users are allowed to use pseudonyms as usernames instead of plain names; legal basis: contract performance and pre-contractual requests (Art. 6 para. 1 p. 1 lit. b) GDPR); service provider: undefined; website: undefined; privacy policy: undefined.
  • Deletion of data after termination: If users have terminated their user account, their data with regard to the user account will be deleted, subject to any legal permission, obligation or consent of the users; Legal basis: Contract performance and pre-contractual requests (Art. 6 para. 1 p. 1 lit. b) GDPR); Service provider: undefined; Website: undefined; Privacy policy: undefined.

Community Functions

The community functions provided by us allow users to engage in conversations or other exchanges with each other. Please note that the use of the community functions is only permitted in compliance with the applicable legal situation, our terms and guidelines and the rights of other users and third parties.

  • Types of data processed: Usage data (e.g., web pages visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: provision of contractual services and customer service; security measures.
  • Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR).

Further notes on processing operations, procedures and services:

  • Limited deletion of conversation posts: Out of consideration for other users, user’s conversation posts remain stored even after cancellation and account deletion so that conversations, comments, advice or similar. Communication between and among users does not lose its meaning or reverse. User names are deleted or pseudonymized if they were not already pseudonyms. Users can assert the complete deletion of conversation contributions at any time with us; Legal basis: contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR); Service provider: undefined; Website: undefined; Privacy policy: undefined.
  • Protection of own data: Users decide for themselves what data they disclose about themselves within our online offering. For example, when users provide information about themselves or participate in conversations. We ask users to protect their data and to disclose personal data only with caution and only to the extent necessary; legal basis: contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR).

Contact and request management

When contacting us (e.g. by mail, contact form, e-mail, telephone or via social media) as well as in the context of existing user and business relationships, the information of the inquiring persons is processed to the extent necessary to respond to the contact requests and any requested measures.

  • Types of data processed: contact data (e.g., e-mail, telephone numbers); content data (e.g., entries in online forms); usage data (e.g., web pages visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
  • Data subjects: Communication partners.
  • Purposes of processing: contact inquiries and communication; managing and responding to inquiries; feedback (e.g. collecting feedback via online form); providing our online offer and user friendliness.
  • Legal bases: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR).

Further notes on processing operations, procedures and services:

  • Contact form: If users contact us via our contact form, e-mail or other communication channels, we process the data communicated to us in this context to process the communicated request; Legal basis: Contract performance and pre-contractual inquiries (Art. 6 para. 1 p. 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); Service provider: undefined; Website: undefined; Privacy policy: undefined.

Push Notifications

With the consent of users, we may send users so-called “push notifications”. These are messages that are displayed on users’ screens, devices or browsers, even if our online service is not being actively used at the time.

In order to sign up for the push messages, users must confirm their browser or terminal device’s request to receive the push messages. This consent process is documented and stored. The storage is necessary to recognize whether users have agreed to receive the push messages and to be able to prove the consent. For these purposes, a pseudonymous identifier of the browser (so-called “push token”) or the device ID of an end device is stored.

On the one hand, the push messages may be necessary for the fulfillment of contractual obligations (e.g., technical and organizational information relevant to the use of our online offer) and are otherwise sent on the basis of user consent, unless specifically mentioned below. Users can change the receipt of push messages at any time using the notification settings of their respective browsers or end devices.

Content: Information about new contacts, notifications about new chat messages and other chat content, notifications about community features, notices and information about special promotions.

Our settings and unsubscribe options:

Push notifications can be customized or unsubscribed via the app’s system settings.

  • Types of data processed: Usage data (e.g., web pages visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status); location data (information about the geographic position of a device or person); content data (e.g., input in online forms).
  • Data subjects: Communication partners; users (e.g. website visitors, users of online services).
  • Purposes of processing: provision of our online offer and user-friendliness; reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest/behavior-related profiling, use of cookies); conversion measurement (measurement of the effectiveness of marketing measures); A/B tests; marketing; profiles with user-related information (creation of user profiles).
  • Legal bases: Consent (Art. 6 para. 1 p. 1 lit. a) GDPR); Contract performance and pre-contractual requests (Art. 6 para. 1 p. 1 lit. b) GDPR); Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR).

Further notes on processing operations, procedures and services:

  • Firebase: Firebase is a development platform for mobile and web applications. It provides tools and infrastructure via a so-called software development kit, which are intended to enable a developer to provide functions more easily and efficiently via programming interfaces on various platforms; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal Grounds: Legitimate Interests (Art. 6 (1) p. 1 lit. f) GDPR); Website: https://firebase.google.com; Privacy Policy: https://policies.google.com/privacy; Order Processing Agreement: https://firebase.google.com/terms/data-processing-terms; Standard Contractual Clauses (ensuring level of data protection for processing in third countries): https://firebase.google.com/terms/data-processing-terms.

Newsletter and electronic notifications

We send newsletters, e-mails and other electronic notifications (hereinafter “newsletter”) only with the consent of the recipients or a legal permission. Insofar as the contents of the newsletter are specifically described in the context of a registration, they are decisive for the consent of the users. Otherwise, our newsletters contain information about our services and us.

In order to subscribe to our newsletters, it is generally sufficient to provide your e-mail address. However, we may ask you to provide a name, for the purpose of personal address in the newsletter, or further information, if this is necessary for the purposes of the newsletter.

Double opt-in procedure: The registration for our newsletter is always carried out in a so-called double opt-in process. This means that after registration you will receive an e-mail in which you are asked to confirm your registration. This confirmation is necessary so that no one can register with other e-mail addresses. The registrations for the newsletter are logged in order to be able to prove the registration process according to the legal requirements. This includes the storage of the registration and confirmation time as well as the IP address. Likewise, changes to your data stored with the dispatch service provider are logged.

Deletion and restriction of processing: We may store unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before deleting them in order to be able to prove consent previously given. The processing of this data will be limited to the purpose of a possible defense against claims. An individual request for deletion is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the e-mail address in a block list (so-called “block list”) for this purpose alone.

The logging of the registration process takes place on the basis of our legitimate interests for the purposes of proving its proper course. Insofar as we commission a service provider to send e-mails, this is done on the basis of our legitimate interests in an efficient and secure sending system.

Contents:

Information about us, our services, promotions and offers.

  • Types of data processed: inventory data (e.g., names, addresses); contact data (e.g., email, phone numbers); meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, consent status).
  • Data subjects: Communication partners.
  • Purposes of processing: direct marketing (e.g., via e-mail or postal mail).
  • Legal basis: Consent (Art. 6 (1) p. 1 lit. a) GDPR).
  • Option to object (opt-out): You can cancel receipt of our newsletter at any time, i.e. revoke your consent or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter or you can otherwise use one of the above contact options, preferably e-mail, for this purpose.

Web analysis, monitoring and optimization

Web analytics (also referred to as “reach measurement”) is used to evaluate the flow of visitors to our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can recognize, for example, at what time our online offer or its functions or content are most frequently used or invite re-use. Likewise, we can understand which areas need optimization.

In addition to web analytics, we may also use testing procedures, for example, to test and optimize different versions of our online offering or its components.

Unless otherwise stated below, profiles, i.e. data summarized for a usage process, may be created for these purposes and information may be stored in a browser, or in a terminal device, and read from it. The information collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times. If users have agreed to the collection of their location data from us or from the providers of the services we use, location data may also be processed.

The IP addresses of the users are also stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect users. Generally, in the context of web analysis, A/B testing and optimization, no clear data of the users (such as e-mail addresses or names) are stored, but pseudonyms. This means that we, as well as the providers of the software used, do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.

  • Types of data processed: Usage data (e.g., web pages visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal grounds: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR).

 

Further notes on processing operations, procedures and services:

  • Matomo (without cookies): Matomo is a privacy-friendly web analytics software that is used without cookies and in which the recognition of returning users takes place with the help of a so-called “digital fingerprint”, which is stored anonymously and changed every 24 hours; With the “digital fingerprint”, user movements within our online offering are recorded with the help of pseudonymized IP addresses in combination with user-side browser settings in such a way that conclusions about the identity of individual users are not possible. The user data collected as part of the use of Matomo is only processed by us and is not shared with third parties; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) GDPR); Website: https://matomo.org/.

Modification and update of the privacy policy

We ask you to regularly inform yourself about the content of our privacy policy. We adapt the data protection declaration as soon as the changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification. If we provide addresses and contact information of companies and organizations in this privacy statement, please note that the addresses may change over time and please check the information before contacting us.

Rights of the data subjects

As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If the personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to revoke any consent given at any time.
  • Right to information: you have the right to request confirmation as to whether data in question is being processed and to information about this data, as well as further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: You have the right, in accordance with the law, to request that data concerning you be completed or that inaccurate data concerning you be rectified.
  • Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to demand that data concerning you be erased without delay or, alternatively, to demand restriction of the processing of the data in accordance with the legal requirements.
  • Right to data portability: You have the right to receive data concerning you, which you have provided to us, in a structured, common and machine-readable format in accordance with the legal requirements, or to request its transfer to another controller.
  • Complaint to the supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the requirements of the GDPR.

Definitions

This section provides you with an overview of the terms used in this privacy policy. Many of the terms are taken from the law and defined primarily in Art. 4 of the GDPR. The legal definitions are binding. The following explanations, on the other hand, are primarily intended to aid understanding. The terms are sorted alphabetically.

  • A/B tests: A/B tests are used to improve the usability and performance of online offerings. For example, users are presented with different versions of a website or its elements, such as input forms, on which the placement of the content or the labels of the navigation elements may differ. Then, based on the users’ behavior, e.g., staying on the web page longer or interacting with the elements more frequently, it can be determined which of these web pages or elements are more likely to meet the users’ needs.
  • Conversion measurement: Conversion measurement (also referred to as “visit action evaluation”) is a procedure that can be used to determine the effectiveness of marketing measures. For this purpose, a cookie is usually stored on the users’ devices within the websites on which the marketing measures take place and then retrieved again on the target website. For example, this allows us to track whether the ads we have placed on other websites have been successful.
  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles with user-related information: The processing of “profiles with user-related information”, or “profiles” for short, includes any type of automated processing of personal data that consists of using this personal data to analyze, evaluate or, in order to predict (e.g., interests in certain content or products, click behavior on a website or location) certain personal aspects relating to a natural person (depending on the type of profiling, this may include different information concerning demographics, behavior and interests, such as interaction with websites and their content, etc.). Cookies and web beacons are often used for profiling purposes.
  • Reach measurement: Reach measurement (also referred to as web analytics) is used to evaluate the flow of visitors to an online offering and may include visitors’ behavior or interests in certain information, such as web page content. With the help of reach analysis, website owners can see, for example, at what time visitors visit their website and what content they are interested in. This enables them, for example, to better adapt the content of the website to the needs of their visitors. For reach analysis purposes, pseudonymous cookies and web beacons are often used to recognize returning visitors and thus obtain more precise analyses of the use of an online offering.
  • Location data: Location data is generated when a mobile device (or another device with the technical requirements of location determination) connects to a radio cell, a WLAN or similar technical means and functions of location determination. Location data is used to indicate the geographically determinable position on earth at which the respective device is located. Location data can be used, for example, to display map functions or other information dependent on a location.
  • Tracking: Tracking is when the behavior of users can be traced across several online services. As a rule, behavioral and interest information is stored in cookies or on servers of the providers of the tracking technologies with regard to the online offers used (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
  • Controller: “Controller” is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
  • Processing: “Processing” means any operation or set of operations which is performed upon personal data, whether or not by automatic means. The term is broad and includes virtually any handling of data, be it collection, evaluation, storage, transmission or deletion.