Preamble
With the following privacy policy we would like to inform you which types of your personal data (hereinafter also referred to as “data”) we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online services”).
The terms used are not gender-specific.
Controller
MindsMerger GmbH
Hansaallee 190
40547 Düsseldorf
Germany
Authorised representative: Houssam Sammour
Email: contact@mindsmerger.com
Phone: +49 173 73 63 292
Legal notice: mindsmerger.com/impressum/
Overview of processing
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects.
Types of data processed
- Master data
- Contact data
- Content data
- Usage data
- Meta, communication and process data
- Log data
Categories of data subjects
- Communication partners
- Users
Purposes of processing
- Communication
- Security measures
- Direct marketing
- Organisational and administrative procedures
- Feedback
- Marketing
- Provision of our online services and usability
- Information technology infrastructure
- Public relations
- Sales promotion
Relevant legal bases
Relevant legal bases under the GDPR: Below is an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6 (1) (1) (a) GDPR) – The data subject has given consent to the processing of personal data concerning them for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6 (1) (1) (b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legitimate interests (Art. 6 (1) (1) (f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include in particular the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains in particular special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated individual decision-making including profiling. Data protection laws of the individual federal states may also apply.
Note on the application of the GDPR and the Swiss FADP: This privacy notice serves to provide information under both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For this reason, please note that the terms of the GDPR are used because of their broader territorial application and comprehensibility. In particular, instead of the terms used in the Swiss FADP, “processing” of “personal data”, “overriding interest” and “particularly sensitive personal data”, the GDPR terms “processing” of “personal data”, “legitimate interest” and “special categories of data” are used. However, the legal meaning of the terms continues to be determined by the Swiss FADP within its scope of application.
Security measures
In accordance with the legal requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input, disclosure, securing the availability and separation of the data. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the deletion of data and responses to threats to the data. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in line with the principle of data protection by design and by default.
Securing online connections with TLS/SSL encryption (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), protecting the data from unauthorised access. TLS, the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL. This serves as an indicator to users that their data is transmitted securely and in encrypted form.
General information on data retention and deletion
We delete the personal data we process in accordance with the legal provisions as soon as the underlying consents are withdrawn or there are no further legal grounds for the processing. This applies to cases in which the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule exist where legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data that applies specifically to certain processing operations.
Where there are several statements on the retention period or deletion deadlines for an item of data, the longest period always applies.
If a period does not expressly begin on a specific date and is at least one year, it begins automatically at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in which data is stored, the event triggering the period is the time at which the termination or other ending of the legal relationship takes effect.
Data that is no longer retained for its originally intended purpose, but on the basis of legal requirements or for other reasons, is processed exclusively for the reasons that justify its retention.
Further information on processing operations, procedures and services:
Retention and deletion of data: The following general periods apply to retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets and the work instructions and other organisational documents required to understand them, accounting vouchers and invoices (§ 147 (3) in conjunction with (1) nos. 1, 4 and 4a AO, § 14b (1) UStG, § 257 (1) nos. 1 and 4, (4) HGB).
- 6 years – Other business documents: commercial or business letters received, copies of commercial or business letters sent, other documents insofar as they are relevant for taxation, e.g. hourly wage slips, operating accounting sheets, calculation documents, price labels, but also payroll documents insofar as they are not already accounting vouchers, and till receipts (§ 147 (3) in conjunction with (1) nos. 2, 3, 5 AO, § 257 (1) nos. 2 and 3, (4) HGB).
- 3 years – Data required to take into account potential warranty and damage claims or similar contractual claims and rights, and to process related enquiries, based on previous business experience and common industry practice, is stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to access this data as well as further information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without delay or, alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Provision of the online services and web hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device.
- Types of data processed: Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and process data (e.g. IP addresses, times, identification numbers, persons involved); log data (e.g. log files relating to logins, the retrieval of data or access times). Content data (e.g. text or image messages and posts and information relating to them, such as authorship or time of creation).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online services and usability; information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers etc.)). Security measures.
- Retention and deletion: Deletion as set out in the section “General information on data retention and deletion”.
- Legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Further information on processing operations, procedures and services:
- Collection of access data and log files: Access to our online services is logged in the form of so-called “server log files”. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes, e.g. to prevent the servers from being overloaded (especially in the event of abusive attacks, so-called DDoS attacks), and to ensure the load and stability of the servers; Legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidence purposes is excluded from deletion until the incident in question has been finally clarified.
- STRATO: Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: STRATO AG, Pascalstraße 10, 10587 Berlin, Germany; Legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); Website: https://www.strato.de; Privacy policy: https://www.strato.de/datenschutz/. Data processing agreement: Provided by the service provider.
- Fonts: The fonts used on this website are stored on our own server and loaded from there. No connection to third-party servers (e.g. Google Fonts) is made when the website is visited.
Contact and enquiry management
When you contact us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, the information provided by the enquiring persons is processed insofar as this is necessary to answer the contact enquiries and any requested measures.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts and information relating to them, such as authorship or time of creation); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and process data (e.g. IP addresses, times, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online services and usability.
- Retention and deletion: Deletion as set out in the section “General information on data retention and deletion”.
- Legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR). Performance of a contract and pre-contractual enquiries (Art. 6 (1) (1) (b) GDPR).
Further information on processing operations, procedures and services:
- Contact form: When you contact us via our contact form, by email or other means of communication, we process the personal data transmitted to us in order to answer and handle your enquiry. This usually includes information such as name, contact information and, where applicable, further information provided to us that is necessary for handling the enquiry appropriately. We use this data exclusively for the stated purpose of contact and communication; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 (1) (1) (b) GDPR), legitimate interests (Art. 6 (1) (1) (f) GDPR).
- Transmission of the contact form: The information entered in the contact form (name, email address, optionally company, type of enquiry, message) is transmitted in encrypted form to our web server and forwarded from there to us by email. It is not stored in a database on the web server. To protect against automatically sent enquiries (spam), the time at which the form was opened and a check field invisible to people are evaluated; no third-party services are used for this.
Promotional communication by email, post, fax or telephone
We process personal data for the purposes of promotional communication, which may take place via various channels, such as email, telephone, post or fax, in accordance with the legal requirements.
Recipients have the right to withdraw consent given at any time or to object to promotional communication at any time.
After withdrawal or objection, we store the data required to prove the previous authorisation to contact or send for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is limited to the purpose of a possible defence against claims. On the basis of the legitimate interest in permanently observing the withdrawal or objection of users, we also store the data required to avoid renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. text or image messages and posts and information relating to them, such as authorship or time of creation).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (e.g. by email or post); marketing. Sales promotion.
- Retention and deletion: Deletion as set out in the section “General information on data retention and deletion”.
- Legal bases: Consent (Art. 6 (1) (1) (a) GDPR). Legitimate interests (Art. 6 (1) (1) (f) GDPR).
Changes and updates
Please inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time, and please check the information before contacting them.
Presences on social networks (social media)
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
Please note that user data may be processed outside the European Union. This may result in risks for users, for example because it could make it more difficult to enforce users’ rights.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behaviour and the resulting interests of users. These may in turn be used to place advertisements within and outside the networks that presumably correspond to users’ interests. For this reason, cookies are generally stored on users’ computers, in which the usage behaviour and interests of users are stored. In addition, data may be stored in the usage profiles independently of the devices used by users (especially if they are members of the respective platforms and logged in there).
For a detailed description of the respective forms of processing and the options to object (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the latter have access to the user data and can take appropriate measures and provide information directly. Should you nevertheless require assistance, you can contact us.
Further information on processing operations, procedures and services:
We have concluded a special agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum”, https://legal.linkedin.com/pages-joint-controller-addendum), which regulates in particular which security measures LinkedIn must observe and in which LinkedIn has agreed to fulfil the rights of data subjects (i.e. users can, for example, send requests for information or deletion directly to LinkedIn). The rights of users (in particular the right of access, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. The joint responsibility is limited to the collection and transfer of data to LinkedIn Ireland Unlimited Company, a company based in the EU. The further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, in particular with regard to the transfer of data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (1) (f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: Data Privacy Framework (DPF). Option to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.