
Privacy Policy
1. Introduction
Below we provide information about the processing of personal data in connection with the use of
- our website https://heydata.eu
- our services offered free of charge under https://platform.heydata.eu/register, including registration for them (hereinafter the "Freemium Services")
- our profiles on social media platforms.
Personal data is any data that can be related to a specific natural person, e.g., their name or IP address.
1.1. Contact Details
The controller within the meaning of Art. 4 No. 7 of the EU General Data Protection Regulation (GDPR) is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany, email: info@heydata.eu. We are legally represented by Milos Djurdjevic and Daniel Deutsch.
Our Data Protection Officer can be reached c/o heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, email: datenschutz@heydata.eu.
1.2. Scope of Data Processing, Purposes of Processing, and Legal Bases
The scope of data processing, the purposes of processing, and the legal bases are set out in detail below. As a general matter, the following legal bases may apply to data processing:
- Art. 6(1)(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent.
- Art. 6(1)(1)(b) GDPR is the legal basis where processing of personal data is necessary for the performance of a contract, e.g., where a website visitor purchases a product from us or we perform a service for them. This legal basis also applies to processing required for pre-contractual measures, such as inquiries about our products or services.
- Art. 6(1)(1)(c) GDPR applies where we process personal data to comply with a legal obligation, as may be the case, for example, under tax law.
- Art. 6(1)(1)(f) GDPR serves as the legal basis where we may rely on legitimate interests for the processing of personal data, e.g., for cookies that are necessary for the technical operation of our website.
1.3. Data Processing Outside the EEA
Where we transfer data to service providers or other third parties outside the European Economic Area (EEA), the security of the data in the course of transfer is, where available, guaranteed by adequacy decisions of the European Commission pursuant to Art. 45(3) GDPR, as is the case, for example, for the United Kingdom, Canada, and Israel.
For data transfers to service providers in the United States, the legal basis for the transfer is an adequacy decision of the European Commission, provided the service provider has additionally certified under the EU-U.S. Data Privacy Framework.
In other cases (e.g., where no adequacy decision exists), the legal basis for the data transfer is, as a rule — i.e., unless we state otherwise — Standard Contractual Clauses. These are a set of rules adopted by the European Commission and form part of the contract with the respective third party. Pursuant to Art. 46(2)(b) GDPR, they ensure the security of the data transfer. Many providers have given contractual guarantees that go beyond the Standard Contractual Clauses in order to provide additional protection for the data. These include, for example, guarantees regarding the encryption of data or an obligation on the part of the third party to notify data subjects if law enforcement authorities seek access to the data.
1.4. Storage Period
Unless expressly stated otherwise in this privacy policy, data stored by us will be deleted as soon as it is no longer required for the purpose for which it was collected and no statutory retention obligations preclude deletion. Where data is not deleted because it is required for other, legally permissible purposes, its processing will be restricted, i.e., the data will be blocked and not processed for other purposes. This applies, for example, to data that we must retain for commercial or tax law reasons.
1.5. Rights of Data Subjects
Data subjects have the following rights against us with respect to personal data concerning them:
- Right of access
- Right to rectification or erasure
- Right to restriction of processing
- Right to object to processing (see below)
- Right to data portability
- Right to withdraw a consent given at any time
Data subjects also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of their personal data. Contact details for the data protection supervisory authorities are available at https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html.
1.6. Right to Object
Where we process personal data on the basis of legitimate interests (Art. 6(1)(1)(f) GDPR), data subjects have the right to object at any time, on grounds relating to their particular situation, to such processing. We will then no longer process the personal data, unless we can demonstrate compelling legitimate grounds for the processing which override the interests of the data subject, or the processing serves the establishment, exercise, or defense of legal claims.
Where we process personal data for direct marketing purposes, data subjects may object at any time, including to any associated profiling.
We will then no longer process the personal data for these purposes.
The objection is not subject to any particular form and can be declared using the contact details provided above.
1.7. Obligation to Provide Data
In the context of a business relationship or other relationship, customers, prospective customers, or third parties are only required to provide us with the personal data that is necessary for the establishment, performance, and termination of the business relationship or other relationship, or that we are legally obliged to collect. Without this data, we will generally be unable to conclude a contract or provide a service, or will no longer be able to perform an existing contract or other relationship.
Mandatory information is marked as such.
1.8. No Automated Individual Decision-Making
We do not, as a general rule, use fully automated decision-making within the meaning of Article 22 GDPR to establish or perform a business relationship or other relationship. Should we use such procedures in individual cases, we will provide separate information about this where legally required.
1.9. Contacting Us
When you contact us, e.g., by email or telephone, the data you provide to us (e.g., name and email address) is stored by us in order to answer your questions. The legal basis for this processing is our legitimate interest (Art. 6(1)(1)(f) GDPR) in responding to inquiries addressed to us. We delete the data arising in this context once storage is no longer necessary, or we restrict processing where statutory retention obligations apply.
1.10. Sweepstakes and Prize Draws
We occasionally offer sweepstakes or prize draws via our website or by other means. We process the data collected in this context in order to determine and notify the winners. We then delete the data. It is also possible that we offer sweepstakes only to existing customers. In that case, we process only the name for the purpose of determining winners and the contact details in order to notify winners. It is our legitimate interest to offer sweepstakes for the purpose of customer acquisition or to interact with our existing customers. The legal basis for the data processing is Art. 6(1)(1)(f) GDPR.
1.11. Customer Surveys
From time to time we conduct customer surveys in order to gain a better understanding of our customers and their wishes. In doing so, we collect the data requested in each case. It is our legitimate interest to gain a better understanding of our customers and their wishes, so that the legal basis for the associated data processing is Art. 6(1)(1)(f) GDPR. We delete the data once the survey results have been evaluated.
1.12. Whitepapers
Prospective customers may obtain free whitepapers from us. In return for making the whitepapers available free of charge, we are permitted to contact prospective customers by email and telephone in order to make them a contractual offer. The legal basis for the processing is the contract concluded with the prospective customer for the free provision of the whitepaper and the promotional use of their contact details.
Prospective customers may object to being contacted at any time, e.g., using the contact details provided above.
2. Newsletter
We reserve the right to inform customers who have already used our services or purchased goods from us, from time to time, by email or other means, about our offers, provided they have not objected to this. The legal basis for this data processing is Art. 6(1)(1)(f) GDPR. Our legitimate interest lies in direct marketing (Recital 47 GDPR).
Customers may object at any time, free of charge, to the use of their email address for advertising purposes, for example via the link at the end of each email or by email to our email address stated above.
Prospective customers have the option of subscribing to a free newsletter. We process the data provided at the time of registration exclusively for the purpose of sending the newsletter. Registration takes place by selecting the corresponding field on our website, by ticking the corresponding box on a paper document, or by another unambiguous act by which prospective customers give their consent to the processing of their data, so that the legal basis is Art. 6(1)(1)(a) GDPR. Consent can be withdrawn at any time, e.g., by clicking the corresponding link in the newsletter or by notifying us at our email address stated above. Processing of the data carried out prior to the withdrawal remains lawful notwithstanding the withdrawal.
On the basis of the consent of the recipients (Art. 6(1)(1)(a) GDPR), we also measure the open and click-through rates of our newsletters in order to understand which content is relevant to our recipients.
We send newsletters using the tool HubSpot, provided by HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin. In doing so, the provider processes content data, usage data, meta/communications data, and contact data in the EU. Further information is available in the provider's privacy policy at https://legal.hubspot.com/privacy-policy.
3. Data Processing on Our Website
3.1. Notice for Website Visitors from Germany
Our website stores information on the terminal equipment of website visitors (e.g., cookies) or accesses information already stored on such terminal equipment (e.g., IP addresses). The specific information involved is set out in the following sections.
This storage and access takes place on the basis of the following provisions: Insofar as such storage or access is strictly necessary to provide a service of our website expressly requested by website visitors (e.g., to ensure the IT security of our website), it takes place on the basis of Section 25(2) No. 2 of the German Telecommunications-Digital-Services-Data Protection Act (TDDDG).
In all other cases, such storage or access takes place on the basis of the consent of website visitors (Section 25(1) TDDDG).
Subsequent data processing takes place in accordance with the following sections and on the basis of the provisions of the GDPR.
3.2. Informational Use of the Website
In the case of informational use of the website, i.e., where visitors do not separately transmit information to us, we collect the personal data that the browser transmits to our server in order to ensure the stability and security of our website. This constitutes our legitimate interest, so that the legal basis is Art. 6(1)(1)(f) GDPR.
This data includes:
- IP address
- Date and time of the request
- Time zone difference from Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- Volume of data transferred in each case
- Website from which the request originates
- Browser
- Operating system and its interface
- Language and version of the browser software
This data is also stored in log files. It is deleted once it is no longer required for storage, and at the latest after 14 days.
3.3. Web Hosting and Provision of the Website
Our website is hosted by Webflow. The provider is Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA. The provider processes personal data transmitted via the website, e.g., content data, usage data, meta/communications data, or contact data, in the USA. Further information can be found in the provider's privacy policy at https://webflow.com/legal/eu-privacy-policy.
It is our legitimate interest to make a website available, so that the legal basis for the described data processing is Art. 6(1)(1)(f) GDPR.
The legal basis for the transfer to a country outside the EEA is an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
We use the Cloudfront (Amazon AWS) content delivery network for our website. The provider is Amazon Web Services, Inc., P.O. Box 81226, Seattle, WA 98108-1226, USA. The provider processes personal data transmitted via the website, e.g., content data, usage data, meta/communications data, or contact data, in the USA.
Further information can be found in the provider's privacy policy at https://d1.awsstatic.com/legal/privacypolicy/AWS_Privacy_Notice__German_Translation.pdf.
We have a legitimate interest in using sufficient storage and delivery capacity in order to ensure optimal data throughput even during periods of high load. The legal basis for the described data processing is therefore Art. 6(1)(1)(f) GDPR.
The legal basis for the transfer to a country outside the EEA is an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
3.4. Contact Forms
When you contact us using the contact forms on our website, we store the data requested there and the content of the message. The legal basis for the processing is our legitimate interest in responding to inquiries addressed to us. The legal basis for the processing is therefore Art. 6(1)(1)(f) GDPR. We delete the data arising in this context once storage is no longer necessary, or we restrict processing where statutory retention obligations apply.
3.5. Job Postings
We publish job postings on our website, on pages linked to the website, or on third-party websites. The data provided as part of an application is processed in order to carry out the application process. Insofar as this data is necessary for the decision to establish an employment relationship, the legal basis is Art. 6(1)(1)(b) GDPR, since the processing is necessary for the performance of pre-contractual measures at the request of the applicant. We additionally base the processing on Art. 6(1)(1)(f) GDPR; it is our legitimate interest to select suitable applicants and to conduct the application process properly. We have marked, or otherwise indicated, the data required to carry out the application process. If applicants do not provide this data, we will not be able to process the application.
Additional data is provided voluntarily and is not required for an application. If applicants provide additional information, the basis for this is their consent (Art. 6(1)(1)(a) GDPR).
We ask applicants to refrain from including information about political opinions, religious beliefs, and similarly sensitive data in their CV and cover letter. This information is not required for an application. If applicants nevertheless provide such information, we cannot prevent its processing in the course of processing the CV or cover letter. In that case, the processing is also based on the applicant's consent (Art. 9(2)(a) GDPR).
Finally, we process applicants' data for further application processes where they have given their consent to this. In that case, the legal basis is Art. 6(1)(1)(a) GDPR.
We share applicants' data with the responsible employees of the human resources department, with our processors in the field of recruiting, and with the other employees involved in the application process.
If, following the application process, we enter into an employment relationship with the applicant, we delete the data only after the employment relationship has ended. Otherwise, we delete the data at the latest six months after an applicant has been rejected.
Where applicants have given us their consent to use their data for further application processes as well, we delete their data only one year after receipt of the application.
3.6. Booking Appointments
Website visitors can book appointments with us via our website. For this purpose, we process meta or communications data in addition to the data entered. We have a legitimate interest in offering prospective customers a user-friendly way to arrange appointments. The legal basis for the data processing is therefore Art. 6(1)(1)(f) GDPR. Where we use a third-party tool for scheduling, the relevant information can be found under "Third-Party Providers."
3.7. Login Area
We maintain a login area for customers. In this context, we process data on the basis of the data processing agreement concluded with the customer.
3.8. Technically Necessary Cookies
Our website uses cookies. Cookies are small text files that are stored in the web browser on a website visitor's device. Cookies help make our offering more user-friendly, effective, and secure. Insofar as these cookies are necessary for the operation of our website or its functions (hereinafter "technically necessary cookies"), the legal basis for the associated data processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in providing customers and other website visitors with a functional website. We use technically necessary cookies in order to retain language settings.
3.9. Third-Party Providers
3.9.1. LinkedIn Insight Tag
We use LinkedIn Insight Tag for conversion tracking. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The provider processes:
- Meta/communications data (e.g., device information, IP addresses)
- Usage data (e.g., websites visited, interest in content, access times)
in the EU.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.linkedin.com/legal/privacypolicy.
3.9.2. Usercentrics
We use Usercentrics to manage consents. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich. The provider processes meta/communications data (e.g., device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in managing website visitors' cookie consents in a simple manner.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://usercentrics.com/privacy-policy/.
3.9.3. HubSpot
We use HubSpot for analytics, marketing automation, and lead generation. The provider is HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin. The provider processes usage data (e.g., websites visited, interest in content, access times), meta/communications data (e.g., device information, IP addresses), and content data (e.g., entries in online forms) in the EU.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligations preclude deletion. Further information is available in the provider's privacy policy at https://legal.hubspot.com/privacy-policy.
3.9.4. LinkedIn Ads
We use LinkedIn Ads for advertising. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://www.linkedin.com/legal/privacy-policy.
3.9.5. Stape
We use Stape for data analysis and analytics. The provider is Stape Europe OÜ, Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://stape.io/privacy-notice.
3.9.6. Livestorm
We use Livestorm for webinars and for videos on the website. The provider is Livestorm SAS, 60 rue François 1er, 75008 Paris, France. The provider processes usage data (e.g., websites visited, interest in content, access times), contact data (e.g., email addresses, telephone numbers), and meta/communications data (e.g., device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in making our communications particularly engaging through the use of videos.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://livestorm.co/privacy-policy.
3.9.7. Spotify Ads
We use Spotify Ads for promotions and advertising. The provider is Spotify AB, Regeringsgatan 19, SE-111 53 Stockholm, Sweden. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.spotify.com/de/legal/privacypolicy/.
3.9.8. Make
We use Make for automation between applications. The provider is Celonis, Inc., One World Trade Center, 87th Floor, New York, NY, 10007, USA. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in easily connecting the applications within our company and thereby optimizing our way of working.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.make.com/en/privacy-notice.
3.9.9. Google Analytics
We use Google Analytics for analytics purposes. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
3.9.10. Google Tag Manager
We use Google Tag Manager for advertising and analytics purposes. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection. We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
3.9.11. Webflow
We use Webflow to build websites. The provider is Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in setting up and maintaining a website and thereby presenting ourselves externally. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection. We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://webflow.com/legal/eu-privacy-policy.
3.9.12. Meta Pixel
We use Meta Pixel for analytics purposes. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
With respect to the collection of data on our website and its transmission to the provider, we and the provider are joint controllers within the meaning of Art. 26 GDPR. Under the agreement concluded with the provider, we are responsible for informing data subjects and for ensuring a legal basis for the collection and transmission. The provider is responsible for fulfilling the rights of data subjects with respect to the data stored with it. The provider is solely responsible for any further processing of the data. Data subjects may assert their rights both against us and against the provider; for inquiries regarding data stored with the provider, we recommend contacting the provider directly. We will make the essential content of the agreement available on request using the contact details provided above.
3.9.13. YouTube Videos
We use YouTube videos on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes meta/communications data (e.g., device information, IP addresses) and usage data (e.g., websites visited, interest in content, access times) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of consent.
Further information is available in the provider's privacy policy at https://policies.google.com/privacy.
3.9.14. Google Conversion Tag
We use Google Conversion Tag for conversion tracking. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
3.9.15. Taboola
We use Taboola for conversion tracking. The provider is Taboola, Inc., 16 Madison Square West, 7th fl., New York, NY, 10010, USA. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of Standard Contractual Clauses. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured by standard data protection clauses adopted pursuant to the examination procedure under Art. 93(2) GDPR (Art. 46(2)(c) GDPR), which we have agreed with the provider. Data collected directly for the purpose of placing advertisements is deleted no later than thirteen months after the website visitor's last interaction with the services. Further information is available in the provider's privacy policy at https://www.taboola.com/de/policies/datenschutzerklaerung.
3.9.16. Facebook Conversion API
We use Facebook Conversion API for analytics purposes. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
With respect to the collection of data on our website and its transmission to the provider, we and the provider are joint controllers within the meaning of Art. 26 GDPR. Under the agreement concluded with the provider, we are responsible for informing data subjects and for ensuring a legal basis for the collection and transmission. The provider is responsible for fulfilling the rights of data subjects with respect to the data stored with it. The provider is solely responsible for any further processing of the data. Data subjects may assert their rights both against us and against the provider; for inquiries regarding data stored with the provider, we recommend contacting the provider directly. We will make the essential content of the agreement available on request using the contact details provided above.
3.9.17. Microsoft Advertising (Bing Ads)
We use Microsoft Advertising (Bing Ads) for conversion tracking and analytics purposes. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://privacy.microsoft.com/de-de/privacystatement.
3.9.18. Reddit Conversion Pixel
We use Reddit Conversion Pixel for analytics purposes. The provider is Reddit, Inc., 548 Market St. #16093, San Francisco, California 94104, USA. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of Standard Contractual Clauses. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured by standard data protection clauses adopted pursuant to the examination procedure under Art. 93(2) GDPR (Art. 46(2)(c) GDPR), which we have agreed with the provider.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.reddit.com/policies/privacypolicy.
3.9.19. Google Ads
We use Google Ads for advertising. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection. We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
3.9.20. G2
We use G2 to obtain product ratings and customer reviews. The provider is G2.com, Inc., 100 S. Wacker Dr., Ste. 600, Chicago, IL 60606, USA. The provider processes usage data (e.g., websites visited, interest in content, access times), contact data (e.g., email addresses, telephone numbers), meta/communications data (e.g., device information, IP addresses), and master data (e.g., names, addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in improving our product on the basis of customer reviews. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://legal.g2.com/privacy-policy.
3.9.21. Reddit Ads
We use Reddit Ads for advertising. The provider is Reddit, Inc., 548 Market St. #16093, San Francisco, California 94104. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of Standard Contractual Clauses. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured by standard data protection clauses adopted pursuant to the examination procedure under Art. 93(2) GDPR (Art. 46(2)(c) GDPR), which we have agreed with the provider.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.reddit.com/policies/privacypolicy.
3.9.22. Meta Ads
We use Meta Ads for advertising. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g., websites visited, interest in content, access times) and meta/communications data (e.g., device information, IP addresses) in the USA.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects may withdraw their consent at any time, e.g., by contacting us using the contact details provided in our privacy policy. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country provides an adequate level of protection. We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
3.9.23. heyData
We have integrated a data protection seal on our website. The provider is us. We process meta/communications data (e.g., IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in providing website visitors with confirmation of our data protection compliance. At the same time, the provider has a legitimate interest in ensuring that only customers with existing contracts use its seal, which is why a mere image copy of the certificate does not constitute a viable alternative for confirmation. The data is masked after collection so that it can no longer be related to a specific person. Further information is available in the provider's privacy policy at https://heydata.eu/datenschutzerklaerung.
4. Data Processing in Connection with Our Freemium Services
We make certain services on our platform available to businesses free of charge (hereinafter the "Freemium Services"). The following sections apply to registration for the Freemium Services and to their subsequent use.
4.1. Responsibility and Delimitation
For the registration process and for the processing described in this section, we are the controller within the meaning of Art. 4 No. 7 GDPR.
Registration establishes a usage agreement between us and the registering business (hereinafter the "Customer"). Insofar as, in the course of performing this agreement, we process personal data that the Customer enters into the platform or that arises from use of the platform by the Customer's users, we act as a processor within the meaning of Art. 28 GDPR. In this respect, the Customer is the controller.
The basis for this processing is the data processing agreement concluded with the Customer. In this case, data subjects should contact the Customer to exercise their rights. We forward any inquiries we receive to the Customer.
4.2. Notice for Users from Germany
Also in connection with registration for and use of the Freemium Services, we store information on users' terminal equipment (e.g., cookies) or access information already stored on such terminal equipment (e.g., IP addresses). The specific information involved is set out in the following sections.
This storage and access takes place on the basis of the following provisions: Insofar as such storage or access is strictly necessary to provide the service expressly requested by users, in particular to prevent automated registrations and to maintain the logged-in session, it takes place on the basis of Section 25(2) No. 2 TDDDG.
In all other cases, such storage or access takes place on the basis of the consent of users (Section 25(1) TDDDG).
Subsequent data processing takes place in accordance with the following sections and on the basis of the provisions of the GDPR.
4.3. Registration
For registration, we process the personal data of the person carrying out the registration on behalf of the Customer, who is set up as the administrator in the process. This is generally:
- First and last name
- Business email address
- Company name
The specific information required is set out in the registration form. Mandatory fields are marked as such. Without this information, we are unable to carry out the registration.
We process this personal data in order to carry out the registration, to set up and administer the user account, and to perform the usage agreement concluded with the Customer regarding the Freemium Services.
The legal basis is Art. 6(1)(1)(f) GDPR. It is our legitimate interest to initiate and perform the contract with the Customer via the persons acting on its behalf, and to provide users with personalized and secure access to our platform. Where a natural person registers in their own name, the legal basis is Art. 6(1)(1)(b) GDPR.
To confirm the registration, we send an email to the address provided, through which the registration is completed. This allows us to ensure that the registration was in fact initiated by the holder of the email address provided. It is our legitimate interest to prevent fraudulent registrations, so that the legal basis is Art. 6(1)(1)(f) GDPR.
For the same reason, and because the Freemium Services are aimed at businesses, we cross-check the email address provided against a list of domains that preclude registration, in particular domains of general email services and disposable email address services. The legal basis is Art. 6(1)(1)(f) GDPR.
After registration, the administrator can invite additional users of the Customer to the platform. The processing of the personal data of these users takes place on the basis of the data processing agreement concluded with the Customer.
4.4. Deletion of Registration Data
We delete the personal data collected during registration once the user account has been terminated and the data is no longer required for the purposes for which it was collected. Where statutory retention obligations apply, or where we require the data for the establishment, exercise, or defense of legal claims, we restrict processing rather than deleting the data. For personal data that we process on behalf of the Customer, the provisions of the data processing agreement apply.
4.5. Advertising to Customers of the Freemium Services
We reserve the right to inform customers who have registered for the Freemium Services, by email, about our own similar goods or services, provided they have not objected to this. We obtained the email address in connection with the provision of our services. The legal basis for this data processing is Art. 6(1)(1)(f) GDPR. Our legitimate interest lies in direct marketing (Recital 47 GDPR); the permissibility of such contact is additionally governed by Section 7(3) of the German Act Against Unfair Competition (UWG).
Customers may object at any time to the use of their email address for advertising purposes, at no cost other than the transmission costs based on the basic rates. The objection may be made via the link at the end of each email, via the settings in the user account, or by email to the address stated above. We provide notice of this option already at the time of registration and in every marketing email.
We send any further-reaching advertising only on the basis of consent (Art. 6(1)(1)(a) GDPR). Consent given may be withdrawn at any time with effect for the future. Processing carried out prior to the withdrawal remains lawful.
4.6. Single Sign-On
Users can register and log in using one or more single sign-on procedures. In doing so, they use login credentials already created with a provider. This requires that the user is already registered with the respective provider.
When a user logs in using a single sign-on procedure, we receive from the provider the information that the user is logged in with the provider, as well as, generally, the user's first and last name, email address, and an identifier with the provider. The provider receives the information that the user is using the single sign-on procedure with us. Depending on the user's settings in their account with the provider, the provider may make additional information available to us.
The legal basis for this processing is Art. 6(1)(1)(f) GDPR. We have a legitimate interest in providing users with a simple and secure login option. At the same time, users' interests are safeguarded, since use of the feature is voluntary and it remains possible at any time to log in without single sign-on. The storage of information on the terminal equipment and access to such information takes place on the basis of Section 25(2) No. 2 TDDDG, since both are strictly necessary to carry out the login process expressly selected by the user.
Providers of the procedures offered are:
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (privacy policy: https://policies.google.com/privacy)
- Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland (privacy policy: https://privacy.microsoft.com/de-de/privacystatement)
4.7. Services Used
4.7.1. Hosting of the Platform
The platform through which we provide the Freemium Services is hosted by Amazon AWS. The provider is Amazon Web Services EMEA SàRL, Avenue John F. Kennedy 38, 1855 Luxembourg. The provider processes personal data transmitted via the platform, e.g., content data, usage data, meta/communications data, or contact data, in the EU.
It is our legitimate interest to provide our services in a technically secure and reliable manner, so that the legal basis for the described data processing is Art. 6(1)(1)(f) GDPR. Insofar as we process personal data on behalf of the Customer, the provider is engaged as a sub-processor on the basis of the data processing agreement concluded with the Customer.
Further information can be found in the provider's privacy policy at https://aws.amazon.com/de/privacy/.
4.7.2. Cloudflare Turnstile
We use Cloudflare Turnstile in the registration form for the Freemium Services to prevent automated registrations by bots. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
The provider processes the IP address, information about the browser used (user agent), and technical signals for detecting automated access. The provider may set its own cookie for this purpose. We transmit to the provider only the verification key and the token generated as part of the check. We do not transmit the content of the registration form, in particular name, email address, and company name, to the provider.
The legal basis for the processing is Art. 6(1)(1)(f) GDPR. It is our legitimate interest to protect our systems and our offering against abusive and automated use, and to ensure the security of our services (Recital 49 GDPR). The storage of information on the terminal equipment and access to such information takes place on the basis of Section 25(2) No. 2 TDDDG, since both are strictly necessary to securely provide the expressly requested registration service. The transfer of personal data to a country outside the EEA takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that providers certified under the EU-U.S. Data Privacy Framework provide an adequate level of protection. In addition, we have agreed Standard Contractual Clauses with the provider pursuant to Art. 46(2)(c) GDPR.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://www.cloudflare.com/de-de/privacypolicy/.
4.7.3. Amplitude
We use Amplitude for product analytics in order to understand the use of our platform and improve our offering. The provider is Amplitude, Inc., 631 Howard St., Floor 5, San Francisco, CA 94105, USA. We have selected the European Union as the storage location for our instance, so that the provider processes the data in the EU.
The provider generally processes the following personal data:
- Usage data, in particular pages and views accessed, sessions, clicks on interface elements, and information on the application's loading time and performance
- Meta and communications data, in particular information about the device, browser, operating system, and language setting, as well as the IP address, from which country and city are derived
- Information about the origin of the access, in particular the referring page and campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content)
- For registered users, additionally an internal user identifier and a company identifier, the language setting, the roles and frameworks stored in the user account, the setting for receiving emails, and first and last name and email address
The specific scope of the data collected may change as our platform is further developed. The list above describes the categories of data processed and is not exhaustive.
The legal basis for the processing is Art. 6(1)(1)(a) GDPR. The processing takes place exclusively on the basis of consent. Data subjects may withdraw their consent at any time by changing the corresponding settings in our application or by contacting us using the contact details provided above. The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal. The storage of information on the terminal equipment and access to such information takes place on the basis of Section 25(1) TDDDG.
Insofar as the provider may access personal data from the USA in connection with support and maintenance services, the transfer takes place on the legal basis of an adequacy decision. The security of the data transferred to the third country is ensured because the European Commission has determined, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that providers certified under the EU-U.S. Data Privacy Framework provide an adequate level of protection. In addition, we have agreed Standard Contractual Clauses with the provider pursuant to Art. 46(2)(c) GDPR.
The data is deleted once the purpose for which it was collected no longer applies and no retention obligation precludes deletion. Further information is available in the provider's privacy policy at https://amplitude.com/privacy.
5. Data Processing on Social Media Platforms
We maintain a presence on social media networks in order to present our organization and our services there. The operators of these networks regularly process the data of their users for advertising purposes. Among other things, they create user profiles based on online behavior, which are used, for example, to display advertising on the networks' pages and elsewhere on the internet that corresponds to users' interests. For this purpose, the network operators store information about usage behavior in cookies on users' devices. It also cannot be ruled out that the operators combine this information with further data. Further information, and notices on how users can object to processing by the page operators, can be found in the privacy policies of the respective operators listed below. It is also possible that the operators or their servers are located in non-EU countries, so that they process data there. This may give rise to risks for users, e.g., because the enforcement of their rights may be more difficult or because government authorities may access the data.
Where users of these networks contact us via our profiles, we process the data communicated to us in order to respond to the inquiries. This constitutes our legitimate interest, so that the legal basis is Art. 6(1)(1)(f) GDPR.
5.1. Facebook
We maintain a profile on Facebook. The operator is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available at https://www.facebook.com/policy.php. Users can object to the processing via the advertising settings: https://www.facebook.com/settings?tab=ads. The operator explains exactly which data is processed at https://www.facebook.com/legal/terms/information_about_page_insights_data.
With respect to the statistics that the operator makes available to us regarding the use of our profile, we and the operator are joint controllers within the meaning of Art. 26 GDPR. We receive only aggregated evaluations and have no access to the underlying individual data. Under the agreement with the operator, the operator assumes responsibility for fulfilling GDPR obligations with respect to the statistics, in particular the exercise of data subjects' rights. Data subjects may exercise their rights both against us and against the operator. We are obliged to forward inquiries to the operator; data subjects will therefore receive a faster response if they contact the operator directly. We will make the essential content of the agreement available on request using the contact details provided above.
5.2. Instagram
We maintain a profile on Instagram. The operator is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available at https://help.instagram.com/519522125107875.
With respect to the statistics that the operator makes available to us regarding the use of our profile, we and the operator are joint controllers within the meaning of Art. 26 GDPR. We receive only aggregated evaluations and have no access to the underlying individual data. Under the agreement with the operator, the operator assumes responsibility for fulfilling GDPR obligations with respect to the statistics, in particular the exercise of data subjects' rights. Data subjects may exercise their rights both against us and against the operator. We are obliged to forward inquiries to the operator; data subjects will therefore receive a faster response if they contact the operator directly. We will make the essential content of the agreement available on request using the contact details provided above.
5.3. TikTok
We maintain a profile on TikTok. The operator is TikTok Technology Limited, whose registered office is at 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. The privacy policy is available at https://www.tiktok.com/de/privacy-policy.
5.4. YouTube
We maintain a profile on YouTube. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The privacy policy is available at https://policies.google.com/privacy?hl=de.
5.5. LinkedIn
We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy is available at https://www.linkedin.com/legal/privacy-policy?_l=de_DE. Users can object to the processing via the advertising settings: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
With respect to the statistics that the operator makes available to us regarding the use of our profile, we and the operator are joint controllers within the meaning of Art. 26 GDPR. We receive only aggregated evaluations and have no access to the underlying individual data. Under the agreement with the operator, the operator assumes responsibility for fulfilling GDPR obligations with respect to the statistics, in particular the exercise of data subjects' rights.
Data subjects may exercise their rights both against us and against the operator. We are obliged to forward inquiries to the operator; data subjects will therefore receive a faster response if they contact the operator directly. We will make the essential content of the agreement available on request using the contact details provided above.
5.6. Xing
We maintain a profile on Xing. The operator is New Work SE, Dammtorstraße 29-32, 20354 Hamburg. The privacy policy is available at https://privacy.xing.com/de/datenschutzerklaerung.
6. Data Processing in Connection with Conversations with Prospective Customers and Customers
6.1 Aircall
We use Aircall for phone calls. The provider is Aircall SAS, 11 Rue Saint-Georges, 75009 Paris, France. The provider processes metadata and communication data (e.g., contact numbers, IP addresses if applicable) in the United States. The legal basis for the processing is Article 6(1)(f) of the GDPR. We have a legitimate interest in contacting our customers. The transfer of personal data to a country outside the EEA is based on an adequacy decision. The security of the data transferred to the third country (i.e., a country outside the EEA) is guaranteed because the European Commission has determined, within the framework of an adequacy decision pursuant to Article 45(3) of the GDPR, that the third country provides an adequate level of protection. The data will be deleted once the purpose for which it was collected no longer applies and there are no legal retention requirements to the contrary. Further information is available in the provider’s privacy policy at https://aircall.io/privacy/.
6.2 Kickscale
We use Kickscale to record video calls and thereby simplify our internal record-keeping. The provider is Kickscale GmbH, Stella-Klein-Löw-Weg 8, 1020 Vienna. The provider processes recordings of calls and their content within the EU. The legal basis for the processing is Art. 6(1)(a) of the GDPR. Processing is based on consent. Data subjects may revoke their consent at any time, for example, by contacting us using the contact information provided in our
Privacy Policy. The revocation does not affect the lawfulness of the processing prior to the revocation. The data will be deleted once the purpose for which it was collected no longer applies and there are no legal retention requirements to the contrary. Further information is available in the provider’s privacy policy at https://www.kickscale.com/de/legal.
7. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy with future effect. The current version is always available here.
8. Questions and Comments
If you have any questions or comments regarding this Privacy Policy, please feel free to contact us using the contact information provided above.
