Privacy Policy
Last updated: December 28, 2023
Introduction
In this privacy policy, we explain how we process your personal data, for what purpose and to what extent. This policy applies to all processing of your personal data by us, whether in the course of our services or specifically on our websites, mobile apps and external online platforms.
The terms used in this statement are gender-neutral.
Overview of Processing
Types of Data Processed
- Master data
- Payment data
- Location data
- Contact data
- Content data
- Contract data
- Usage data
- Meta, communication and procedural data
Categories of Affected Persons
- Customers
- Prospects
- Communication partners
- Users
- Business and contract partners
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations
- Contact requests and communication
- Security measures
- Direct marketing
- Reach measurement
- Tracking
- Office and organizational procedures
- Conversion measurement
- Administration and answering of inquiries
- Feedback
- Marketing
- Profiles with user-related information
- Provision of our online services and user-friendliness
- Information technology infrastructure
Key Legal Bases
Below is a summary of the GDPR legal bases for our processing of personal data.
- Consent (Art. 6(1)(a) GDPR): The data subject has consented to the processing of their personal data for specific, clearly defined purposes.
- Contract fulfillment (Art. 6(1)(b) GDPR): Processing is necessary for the performance of a contract to which the data subject is party.
- Legal obligations (Art. 6(1)(c) GDPR): Processing is necessary for compliance with a legal obligation.
- Legitimate interests (Art. 6(1)(f) GDPR): Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party.
National Data Protection Regulations in Germany
In addition to the GDPR, national data protection laws apply in Germany, particularly the Federal Data Protection Act (BDSG). This law contains specific regulations regarding the right of access, the right to erasure, the right to object, processing of special categories of personal data, and automated decision-making and profiling.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements to ensure a level of protection appropriate to the risk. These include ensuring the confidentiality, integrity and availability of data.
TLS/SSL Encryption (https)
To protect user data during transmission via our online services, we use TLS/SSL encryption.
Transfer of Personal Data
In the course of our data processing, data may be transferred to or disclosed to other entities, companies or persons. We always comply with legal requirements and conclude appropriate contracts or agreements to protect your data.
International Data Transfers
We only process data in third countries (outside the EU or EEA) or transfer it there if this is in accordance with legal requirements. Under the Data Privacy Framework (DPF), the EU Commission has recognized the level of data protection for certain companies in the USA.
Deletion of Data
We delete processed data in accordance with legal requirements once consent to processing is withdrawn or other permissions lapse. Data required for other legally permissible purposes is blocked rather than deleted.
Rights of Data Subjects
As a data subject, you have various rights under the GDPR:
- Right to object: You may object to the processing of your personal data at any time.
- Right to withdraw consent: You may withdraw any consent given at any time.
- Right of access: You have the right to confirmation and information about your processed data.
- Right to rectification: You may request the completion or correction of your data.
- Right to erasure and restriction: You may request the deletion of your data or restriction of processing.
- Right to data portability: You have the right to receive your data in a structured, commonly used format.
- Complaint to supervisory authority: You have the right to lodge a complaint with a supervisory authority.
Use of Cookies
Cookies are small text or storage files that store and retrieve information on devices. We use cookies in accordance with legal requirements and obtain prior consent where required.
There are two types: Temporary cookies (session cookies), which are deleted when the user leaves the service, and Permanent cookies, which can be stored for up to two years.
Users may withdraw consent at any time. Opt-out of marketing cookies is possible via optout.aboutads.info and youronlinechoices.com.
Commercial Services
We process the data of our business partners in the context of contractual and comparable legal relationships. Data is deleted after the expiry of statutory warranty obligations, typically after 4 years. Tax-relevant documents are retained for ten years.
Our services include: agency services (consulting, campaign planning, software and design development), project and development services, technical services, and software and platform services.
Provision of Online Services and Web Hosting
We process user data to provide our online services. This includes processing the IP address, which is necessary to deliver content and functions to the user's browser.
Server log files: Access data is logged for security purposes and to ensure server stability. Log file information is stored for a maximum of 30 days and then deleted or anonymized.
Blogs and Digital Publications
Reader data is only processed insofar as this is necessary for the presentation of the medium and the interaction between authors and readers, or for security reasons. IP addresses from comments are stored for security purposes.
Contact and Inquiry Management
When contacting us (e.g. via contact form, email, phone or social media), we process the data of the inquiring persons insofar as this is necessary to answer the inquiries.
Newsletter and Digital Communications
We only send newsletters with the consent of the recipients or on the basis of legal authorization. Registration is done via a double opt-in procedure. Unsubscribed email addresses may be stored for up to three years to prove prior consent.
Services used: HubSpot (email delivery and automation) and Mailchimp (Rocket Science Group, LLC).
Web Analytics, Monitoring and Optimization
We use web analytics methods ("reach measurement") to evaluate visitor flows on our website. IP addresses are stored, but we use IP masking procedures (pseudonymization) to protect users.
Google Analytics 4: Measurement and analysis of usage with pseudonymous user identification numbers. No storage of individual IP addresses for EU users.
Google Tag Manager: Management of website tags via an interface, no creation of user profiles or storage of cookies.
Online Marketing
We process personal data for online marketing purposes, including the display of advertising content based on the potential interests of users. No clear-text user data is stored, only pseudonyms. Services used: Google Ads and Conversion Measurement, Google Adsense.
Affiliate Programs and Affiliate Links
We include affiliate links in our online offering. The attribution of affiliate links to business transactions serves solely the purpose of commission settlement and is discontinued as soon as it is no longer necessary.
Contact
SimplifyVision
Dominik Weber
Jöllenbecker Str. 143
33613 Bielefeld, Germany
Email: [email protected]