Privacy policy
for the content and functions of the MOCO Community & the agencyflow.io website (hereinafter “Services”)
As of August 2026
Introduction
Privacy policies are often hard to read. We understand that. And we want to do things differently. With our privacy policy, we at
want to provide users with an easy-to-understand explanation of how we process personal data at
. To this end, we’ve organized our privacy policy in a clear and structured way for users at
and explain, for each topic, whether and how we process users’ personal data at
.
In this Privacy Policy, we explain to users whether and how we process personal data. Here at
, we describe to users all processing operations carried out by us, by third-party services commissioned by us or integrated via
, or by other third parties acting on our behalf in connection with the use of our website,
, our app, our software, our marketplace, our social media profiles, and the respective features available at
(hereinafter collectively referred to as “Services”) are carried out.
1. general
The protection of personal data and privacy is of the utmost importance to us. That is why we want to offer users of
full transparency regarding the processing of personal data (GDPR) as well as the
storage of information on the user’s device (TDDDG). Only when the processing of
personal data and information is transparent to users as data subjects are they
sufficiently informed about the scope, purposes, and benefits of the processing.
This Privacy Policy applies to all processing of personal data carried out by us, as well as to
the storage of information on end devices. It therefore applies to users both in connection with the provision of
services and within external online presences, such as our social media profiles.
Person responsible
The controller within the meaning of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and
other data protection regulations is the
Gropiusstraße 7
48163 Münster
Email: hallo@agencyflow.io
Hereinafter referred to as “controller” or “we”.
2. general information on data processing
2.1 Processing of personal data
Personal data (hereinafter also referred to as “data”) consists of specific information regarding the personal or factual circumstances
of an identified or identifiable natural person.
Examples of specific information regarding personal or factual circumstances include the following data, although
clarifies that not all of this data necessarily needs to be processed by our services:
- Personal data – name, age, marital status, date of birth
- Communication data – address, telephone number, e-mail address
- Account data – account number, credit card number
- Geodata – IP address & location data
The “processing” of personal data includes, for example, the following measures:
- Collection – The collection of data via contact forms, by e-mail or through processes and services used by us
- Transmission – The transmission of data to our service providers, integrated services or other third parties
- Storage – The storage of data in our databases or on our servers
- Change – The change of data due to changes of name, place of residence or details in our services
- Deletion – The deletion of data when we are no longer authorized to process it
2.2 Legal basis for the processing of personal data
We process personal data only within the limits permitted by law. We are required to do so by law
—specifically, the GDPR. As a result, we are obligated to ensure that all data processing operations are always based on a legal basis
. These legal bases are set forth in Article 6(1) of the GDPR.
Below, we list all the legal bases on which we rely when processing personal data
.
- Consent – Art. 6 para. 1 lit. a GDPR: Data is processed if users have actively consented to this processing, e.g. by means of an “opt-in”, after having been adequately informed by us about the scope and purposes of the processing. If users withdraw their consent or have not given their consent, we do not (or no longer) process our users’ data for purposes for which we require consent.
- To fulfill a contract – Art. 6 para. 1 lit. b: Data is processed if it is necessary for the fulfillment of a contract between us or for the implementation of pre-contractual measures. If the processing is no longer necessary for the fulfillment of the contract, we will no longer process the personal data of users.
- Fulfillment of a legal obligation . Art. 6 para. 1 lit. c GDPR: Data is processed if this processing is necessary to fulfill a legal obligation to which we as the controller are subject.
- Legitimate interest – Art. 6 para. 1 lit. f GDPR: Data is processed if this is necessary to safeguard a legitimate interest on our part and does not outweigh the interests or fundamental rights and freedoms of users with regard to the protection of data.
We process personal data only for specific purposes (Art. 5(1)(b) of the GDPR). As soon as
the purpose of the processing no longer applies, users’ personal data will be deleted or protected by
through technical and organizational measures (e.g., pseudonymization).
The same applies to the expiration of a required retention period, except in cases where further storage at
is necessary for the conclusion or performance of a contract. In addition, a legal obligation at
to store data for a longer period or to disclose it to third parties (particularly law enforcement agencies) may arise at
. In other cases, the retention period, the type of data collected, and the nature of the
data processing depend on which features users utilize in each specific instance. We are happy to provide users with information on this on a
case-by-case basis, in accordance with Article 15 of the GDPR.
2.3 We process these categories of data
Data categories are in particular the following data:
- Master data (e.g. names, addresses, dates of birth),
- Contact data (e.g. e-mail addresses, telephone numbers, messenger services),
- Content data (e.g. text entries, photographs, videos, contents of documents/files),
- Contract data (e.g. subject matter of the contract, terms, customer category),
- Payment data (e.g. bank details, payment history, use of other payment service providers),
- Usage data (e.g. history in our services, use of certain content, access times),
- Connection data (e.g. device information, IP addresses, URL referrer).
2.4 We take these security measures
In accordance with legal requirements and taking into account the state of the art,
implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the
varying probabilities and severity of threats to rights and freedoms,
we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk at
.
These measures include, in particular, ensuring that our users’ data is stored and processed confidentially, with integrity, and
at all times. Furthermore, the security measures we implement include controls on access to data as well as
controls over access, data entry, data disclosure, ensuring data availability, and the separation of data from that of other
natural persons. Furthermore, we have established procedures
that ensure the exercise of data subjects’ rights (see Section 3), the deletion of data, and
responses in the event of a threat to our users’ data. Furthermore, we take the protection
of personal data into account from the very beginning of our software development and through procedures that comply with the principle of
data protection by design and by default.
2.5 How we transfer or disclose personal data to third parties
As part of our processing of personal data, this data may be transferred to
other entities, companies, legally independent organizational units, or individuals, or disclosed at
. These third parties may include, for example, payment institutions in connection with payment transactions, service providers contracted to perform IT tasks
, or providers of services and content that we have integrated into our services
. Should we transfer or disclose users’ personal data to third parties, we comply with
the legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of the data that serve to protect the data in accordance with
.
2.6 How a third country transfer takes place
If this Privacy Policy states that we transfer users’ personal data to a third country
—that is, a country outside the EU or the EEA—the following applies. A transfer to a third country
is carried out only in accordance with legal requirements. We assure users that
we have contractual or legal authorization to transfer and process data in the
relevant third country. Furthermore, we only allow our users’ data to be processed by service providers in third countries
that, in our view, maintain a recognized level of data protection. This means that there is, for example, an appropriate adequacy decision
in place between the
EU and the country to which we transfer users’ personal data.
Alternatively—for example, if there is no adequacy decision—a transfer to a third country will only take place if
there are contractual obligations between us and the service provider in the third country, such as the so-called
Standard Contractual Clauses of the European Commission, and if further technical safeguards
have been implemented, which ensure a level of protection equivalent to that in the EU, or if the service provider
in the third country can demonstrate data protection certifications and processes our users’ data only in accordance with internal
data protection regulations (Articles 44–49 of the GDPR. EU Commission information page:
https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
Under the so-called “Data Privacy Framework” (“DPF”), the European Commission has recognized the level of data protection provided by
certain U.S. companies as adequate
pursuant to the Adequacy Decision of July 10, 2023. Users can find a list of certified companies as well as further information on the DPF on the U.S. Department of Commerce’s website at
under
https://www.dataprivacyframework.gov/
(in English). In this Privacy Policy, we inform users which of the services we use at
are certified under the Data Privacy Framework.
2.7 Deletion of data
The data we process is deleted in accordance with legal requirements as soon as the consent authorizing its processing at
is revoked or other legal grounds for processing no longer apply (e.g., if the purpose
of processing this data no longer applies or if the data is no longer necessary for that purpose). If the data is not deleted
because it is required for other legally permissible purposes, its processing will be limited to
these purposes. This means that the data will be blocked and will not be processed for any other purposes.
This applies, for example, to data that must be retained for commercial or tax law purposes, or whose storage
is necessary to assert, exercise, or defend legal claims, or to protect the rights
of another natural or legal person.
As part of this Privacy Policy, we may provide information regarding the deletion and retention of data at
that applies specifically to the respective processing operations.
2.8 Storage of and access to data on the user’s end device
Unless we obtain consent from users, the storage of or access to
information on the user’s device is carried out in accordance with Section 25(2)(2) of the Act on Data Protection and the
Protection of Privacy in Telecommunications and Digital Services (TDDDG), since the storage of and
access to this information is absolutely necessary to provide the desired functions of our services at
. If we obtain consent for this, the legal basis is Section 25(1) of the TDDDG.
Our services use cookies, tokens, or other technologies that may be stored on end devices
and without which we would not be able to provide our services.
Cookies, tokens, or other technologies are generally text files that are stored on the user’s device
and can be read by us and third parties when our services are accessed. Many of the technologies mentioned above
contain their own ID. Such an ID is a unique identifier for the respective technology used
.
A “user” consists of a string of characters that allows websites and servers to associate a specific Internet browser or
with the specific service or device being used, in which cookies, tokens, or other
technologies have been stored. This enables the operators of websites and analytics services to identify users as
users and distinguish them from others.
2.9 Order processing
Should we use external service providers to process data, we carefully select and engage them at
. If the services provided by these service providers constitute
data processing on our behalf within the meaning of Article 28 of the GDPR, the service providers are bound by our instructions
and are regularly monitored. Our data processing agreements comply with the
strict requirements of Article 28 of the GDPR as well as the guidelines of the German data protection authorities.
3. rights of data subjects
If our users’ personal data is processed, they are data subjects within the meaning of the GDPR, and as users of
, they have the following rights vis-à-vis the controller:
3.1 Right to information
Users may request confirmation from the controller as to whether we are processing personal data relating to them at
.
If such processing has taken place, users can request the following information from the controller:
- the purposes for which the personal data are processed;
- the categories of personal data that are processed;
- the recipients or categories of recipients to whom the personal data concerning the user has been or will be disclosed;
- the planned duration of storage of the personal data concerning the user or, if specific information on this is not possible, criteria for determining the storage period;
- the existence of a right to rectification or erasure of personal data concerning the user, a right to restriction of processing by the controller or a right to object to such processing;
- the existence of a right of appeal to a supervisory authority;
- all available information about the origin of the data if the personal data is not collected from the data subject;
- the existence of automated decision-making, including profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
- Users have the right to request information as to whether the personal data concerning them is transferred to a third country or to an international organization. In this context, users may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
3.2 Right to rectification
Users have the right to request that the controller correct and/or complete their personal data, provided that the personal data processed by
concerning them is inaccurate or incomplete. The controller,
, must make the correction without delay.
3.3 Right to restriction of processing
Under the following conditions, users may request the restriction of the processing of personal data concerning them:
- if users contest the accuracy of the personal data concerning them for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and users refuse the erasure of the personal data and instead request the restriction of the use of the personal data;
- the controller no longer needs the personal data for the purposes of the processing, but they are required by the user for the establishment, exercise or defense of legal claims, or
- if users have objected to processing pursuant to Art. 21 (1) GDPR and it has not yet been established whether the legitimate grounds of the controller override those of the user.
- If the processing of personal data concerning the user has been restricted, this data – apart from its storage – may only be processed with consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
If processing has been restricted in accordance with the above conditions, users will be notified by the data controller,
, before the restriction is lifted.
3.4 Right to erasure
3.4.1
Users may request that the data controller immediately delete the personal data concerning them,
, and the data controller is obligated to delete this data immediately if any of the following grounds apply:
- The personal data concerning users are no longer necessary for the purposes for which they were collected or otherwise processed.
- Users withdraw consent on which the processing is based according to Art. 6 para. 1 lit. a or Art. 9 para. 2 lit. a GDPR, and where there is no other legal ground for the processing.
- Users object to the processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the processing, or users object to the processing pursuant to Art. 21 (2) GDPR.
- The personal data concerning the user has been processed unlawfully.
- The deletion of personal data concerning users is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the controller is subject.
- The personal data concerning users were collected in relation to information society services offered in accordance with Art. 8 para. 1 GDPR.
3.4.2
If the controller has made personal data concerning users public and is obligated to erase such data pursuant to Article 17(1) of the GDPR,
then the controller shall, taking into account available technology and the cost of implementation, take reasonable measures, including technical measures,
to inform the controllers processing the personal data that users, as data subjects, have requested the deletion
of all links to such personal data or of copies or replicas of such personal data.
3.4.3
The right to erasure does not exist if the processing is necessary
- to exercise the right to freedom of expression and information;
- for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health in accordance with Art. 9 para. 2 lit. h and i and Art. 9 para. 3 GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89 para. 1 GDPR, insofar as the right referred to in para. 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing, or
- for the assertion, exercise or defense of legal claims.
3.5 Right to information
If users have exercised their right to rectification, erasure, or restriction of processing with the controller,
the controller is obligated to notify all recipients to whom the personal data concerning the users has been disclosed of such rectification or
erasure of the data or restriction of processing, unless this proves impossible or involves a disproportionate
effort.
Users have the right to be informed about these recipients by the controller.
3.6 Right to data portability
Users have the right to receive the personal data concerning them that they have provided to the controller in a structured,
commonly used, and machine-readable format. In addition, users have the right to transmit this data to another controller without hindrance from the
controller to whom the personal data was provided, provided that the processing is based on consent pursuant to Art. 6(1)(a)
of the GDPR or Art. 9(2)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) of the GDPR, and the processing is carried out by automated means.
In exercising this right, users also have the right to have their personal data transferred directly from one controller
to another controller, provided that this is technically feasible. This must not infringe upon the freedoms and rights of others.
The right to data portability does not apply to the processing of personal data that is necessary for the performance of a task carried out in the public
interest or in the exercise of official authority vested in the controller.
3.7 Right of objection
Users have the right, for reasons arising from their particular situation, to object at any time to the processing of personal data concerning them,
which is carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions.
The controller will no longer process personal data relating to users unless it can demonstrate compelling legitimate grounds for the processing
that override the interests, rights, and freedoms of our users, or the processing is necessary for the establishment, exercise, or defense of
legal claims.
If personal data relating to users is processed for the purpose of targeted advertising, users have the right to object at any time to the
processing of their personal data for such advertising purposes; this also applies to profiling, to the extent that it is related to such
targeted advertising.
If users object to the processing of their personal data for the purposes of targeted advertising, such personal data will no longer be processed for those purposes.
Users have the option, in connection with the use of information society services—notwithstanding Directive 2002/58/EC—to exercise their right to object
through automated procedures that use technical specifications.
3.8 Right to revoke the declaration of consent under data protection law
Users have the right to revoke their consent under data protection law at any time. Revoking consent does not affect the lawfulness of the processing carried out by
based on that consent up until the time of revocation. Processing is lawful until consent is revoked—the revocation therefore takes effect
only with respect to processing that occurs after the revocation is received.
Users may submit their withdrawal of consent informally by mail or email. The processing of personal data will then cease, unless
provides another legal basis for such processing. If this is not the case, our users’ data must be deleted immediately following revocation in accordance with Art. 17(2) of the GDPR.
The right to revoke consent, subject to the above conditions, is guaranteed.
The revocation is to be sent to:
JDF Consulting GmbHGropiusstraße 7
48163 Münster
Email: hallo@agencyflow.io
3.9 Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, users have the right to lodge a complaint with a supervisory authority, in particular
in the Member State of their residence, their workplace, or the location of the alleged infringement, if users believe that the processing of their personal data
violates the GDPR.
The supervisory authority to which the complaint was submitted shall inform the complainant of the status and outcome of the complaint, including the
option to seek judicial remedy under Article 78 of the GDPR.
3.10 Automated decisions in individual cases including profiling
Automated decisions in individual cases, including profiling, do not take place.
3.11 Notification obligations of the controller
If users’ personal data has been disclosed to other recipients (third parties) on a lawful basis, we will notify them of any rectification, erasure, or
restriction of the processing of personal data (Art. 16, Art. 17(1), and Art. 18 of the GDPR). The obligation to notify does not apply if it involves
a disproportionate effort or is impossible. We will also inform users about the recipients upon request.
4. information on the cookies and other technologies used
We use cookies and other technologies to provide and analyze our services, and to conduct marketing based on the analyzed data. Cookies, such as
, are small text files that contain data from visited websites or domains and are stored on a device (computer, tablet, or smartphone). When users access a website at
, the cookie stored on their device sends information to the party that placed the cookie.
4.1 How we use cookies and other technologies
We want users to be able to make an informed decision for or against the use of cookies and other technologies that are not strictly necessary for the technical functionality of the services at
. Therefore, in cases where we use cookies and other technologies
that require consent, we allow users to choose—as part of a voluntary decision upon their first visit to our services and subsequently on an ongoing basis through the relevant settings—
which cookies and other technologies they wish to allow.
Please note that functional cookies and other technologies are essential for using our services and are therefore already enabled by default.
Analytics and marketing cookies and other technologies are optional. Users can enable them by giving their consent to the use of these cookies and other technologies in the consent banner at
. Alternatively, users can reject statistics and marketing cookies and other technologies.
4.2 Storage duration of cookies and other technologies
Unless we provide users with explicit information regarding the retention period for cookies and other technologies (e.g., via the consent banner), users may assume
that the retention period may be up to two years. If cookies and other technologies were set based on consent, users have the option at any time to revoke their consent at
or to object to the processing of data by cookies or other technologies (collectively referred to as “opt-out”).
5. data processing in connection with the use of our services
The use of our services and all their functions involves the processing of personal data. We explain to users exactly how this happens here.
5.1 Informational use of our services
Accessing our services for informational purposes only requires the processing of the following personal data and information: device type and version, operating system used (
), IP address of the end device used by the user to access our services, and the time at which our services were accessed. All of this information is automatically transmitted from a device to
, unless users have configured their device to prevent such transmission.
This personal data is processed for the purpose of ensuring the functionality and optimization of our services, as well as to guarantee the security of our information technology systems at
. These purposes also constitute legitimate interests under Article 6(1)(f) of the GDPR; therefore, the processing is carried out on a legal basis.
5.2 Use by or after registration
5.2.1 Registration
In addition to simply browsing our services for informational purposes, users have the option to register for our services and take advantage of our full range of offerings. In doing so,
we process, in particular, master data and contact information such as your name, email address, and password. In addition, we automatically process connection data at
, such as the date, device information, and IP address.
Some processing steps may also be carried out by third-party providers. Data processing by third-party providers is subject to the terms of the respective privacy policies.
In the case of data processing by third-party providers, this may constitute processing on behalf of the controller within the meaning of Article 28 of the GDPR. This is subject to strict legal requirements,
, which we comply with through our contractual agreements with our processors.
Use of the site during or after registration and login, as well as the associated data processing operations, may differ from use for purely informational purposes.
The collection of this data, which is associated with a profile, is carried out for the purpose of verifying the status and the associated fulfillment of our contractual obligations
toward users. These are legitimate purposes pursuant to Art. 6(1)(b) of the GDPR.
If consent is required for the processing operation, we will obtain it at the appropriate point (e.g., via the opt-in option in a consent
banner when you first use our service). If users have any further questions, we are happy to assist them in accordance with the right of access under Article 15(1) of the GDPR.
5.2.2 Setting up and using a user account
Users can create a user account on our services to access our services and their features. When users do so, the personal data they provide there
is transmitted to us via their device and stored in our IT systems. We also store the IP address and the time
of registration.
When users log in to their user accounts, our service stores tokens on their devices to allow them to remain logged in—even if they need to reload our services at
in the meantime. By creating a user account, users can access the features of our services.
The data processing operations associated with creating a user account serve the purpose of being able to track future usage and access the full range of our services at
. When ordering products or booking services, the processing of data also serves to fulfill the contract; it is therefore purpose-limited and necessary
in accordance with Article 6(1)(b) of the GDPR.
Storing the IP address and the time of registration is necessary to ensure the security of our information technology systems. This also constitutes our legitimate
interest, which is why the processing is lawful under Article 6(1)(f) of the GDPR.
Personal data entered by users is stored until such time as it is deleted from the user account or, at the latest, until the user account is completely deleted from our system at
.
Notwithstanding the above, we process certain personal data of users only to the extent that we have legal or contractual authorization to do so. This is the case, for example, when we are permitted to retain contract
, or payment data even after the user account has been deleted, for billing or other reasons necessary for the proper fulfillment of our contractual relationship.
5.3 Functions of our services
Subject to registration, users have access to the features listed at www.agencyflow.io. We provide users with all of the features listed there so that they can take full advantage of the
scope of our services—depending on the plan they have selected—and so that we can achieve the best possible results through our collaboration. We only disclose the data entered by users to third parties authorized by
and process this data to fulfill the contractual relationships entered into with users, in particular to fulfill the user agreement that users have entered into regarding the use of our services at
. Therefore, the legal basis for data processing is Article 6(1)(b) of the GDPR.
5.4 Member spot
We use Memberspot to display and provide the features in our services. Memberspot is a platform that enables the creation of custom-configured
membership areas. We use Memberspot to provide our secure members-only area and to conduct online courses and digital training programs.
The recipient of the data in this context is Memberspot GmbH, Rilkestr. 26, 71642 Ludwigsburg. The categories of data concerned are all data listed in Section 2.3. The legal basis for the use of
Memberspot and for the processing of data for the aforementioned purposes is Article 6(1)(b) of the GDPR.
To the extent that usage and log data are processed in addition to this, such processing is based on our legitimate interest in ensuring the secure, stable, and functional operation of the
member area, in accordance with Article 6(1)(f) of the GDPR. Further information on data processing by Memberspot can be found in the provider’s privacy policy:
https://www.memberspot.de.
5.5 Chat and messaging system
We provide users of our services with the opportunity to connect with other users via built-in chat and messaging features, to exchange information, and, where applicable, to initiate and conclude contracts
. The categories of data processed in this context include master data, contact information, and, where applicable, content data, contract data, and payment data.
We transmit this data to the person contacted by users to the extent that users themselves authorize the data transmission or include this data in their messages. In addition,
is notified of the time and the parties involved when contact is made via our chat and messaging features.
The use of the chat and messaging features is an essential part of our services; therefore, the processing of data serves the purpose of fulfilling the contract and is thus purpose-limited and necessary
in accordance with Article 6(1)(b) of the GDPR.
The storage of IP addresses and the time of use of our chat and messaging features is necessary to ensure the security of our information technology systems. This also constitutes
’s legitimate interest, which is why the processing is lawful under Article 6(1)(f) of the GDPR.
We store the personal data entered by users until the profile is deleted from our system; beyond that, we store it only for as long as processing is necessary to fulfill any contracts
. We do not intend to disclose this data to any other third parties.
5.6 Community function
Through our services, we give users the opportunity to view and comment on other users’ posts and to interact publicly with others through them. The categories of data processed at
include master data, contact information (if applicable), and content data (if applicable). We publish this data in our publicly accessible areas.
The use of the community feature is an essential part of our services; therefore, the processing of data is necessary for the performance of the contract and is thus limited to that specific purpose and required under Article 6(1)(b) of the GDPR.
Storing IP addresses and the time of use of our community feature is necessary to ensure the security of our information technology systems. This also constitutes our legitimate interest, which is why the processing is lawful under Article 6(1)(f) of the GDPR.
We store the personal data entered by users until the profile is deleted from our system; beyond that, we store it only for as long as processing is necessary to fulfill any contractual obligations and to the extent that it is technically possible. We do not intend to disclose this data to any other third parties.
6. communication services
6.1 Contact form / contact by e-mail
We process the personal data of users that they provide to us when contacting us for the purpose of responding to an inquiry, an email, or a request for a callback.
The categories of data processed in this context include master data, contact data, content data, usage data (if applicable), connection data, and contract data (if applicable).
In specific cases, we may share this data with our affiliated companies or third parties who are authorized to process this data in accordance with our agreement for the purpose of fulfilling orders and reservations.
The legal basis for the processing depends on the purpose of the contact.
By submitting a request via the contact form or by contacting us via email, users indicate that they would like to receive responses or information on specific topics. To this end, users also provide their personal data.
We respond to inquiries as requested and process our users’ data for this purpose. Therefore, the legal basis for processing data is Article 6(1)(b) of the GDPR, as we process it to respond to an inquiry and thereby fulfill the contract relating to it.
6.2 Reporting illegal content in accordance with the Digital Services Act
We process data from our users that is provided to us by users when reporting illegal content. The data processed may fall into any of the data categories listed in Section 2.3.
We process this data to review the reported content for illegality and to fulfill the resulting legal obligations, such as blocking, deletion, or criminal prosecution.
The legal basis for processing data transmitted to us in connection with reports of unlawful content is Article 6(1)(c) of the GDPR.
Under the provisions of the EU Digital Services Act, we are legally obligated to review unlawful content and take appropriate action based on the findings.
6.3 Online communication tools
We use online communication tools to conduct conference calls, customer meetings, online meetings, video conferences, and/or webinars (hereinafter: “online meetings”).
The scope of data processing depends on the specific purpose for which we are hosting the online meeting and what information users provide before or during their participation in an “online meeting.”
The categories of data in question include master data, contact data, content data, usage data (if applicable), connection data, and contract data (if applicable).
The recipients of this data are the providers of online communication tools that we use, as listed below.
Our legal basis for the use of online communication tools is derived from Article 6(1)(b) of the GDPR (performance of a contract), provided that the online meeting takes place in connection with contract negotiations or based on a request expressed by users, such as when they contact us.
We use the online communication tools we have integrated to fully digitize communication between us.
Provider of the online communication tools we use
“Notion Meets”
Notion Ireland Ltd.Gordon House
Barrow Street
Dublin 4
Ireland
https://policies.google.com/privacy
6.4 Artificial intelligence
We use artificial intelligence services (“AI Services”) in our Services. These AI Services enable us to provide our Services with state-of-the-art quality and personalized precision, which is particularly valuable for our relationship with you.
Through the AI Services, we can provide users—as part of the data processing required to deliver our services—with an intelligent system that processes all interactions within our services where the AI Services are integrated in the most efficient and user-friendly manner possible.
The purpose of data processing by the AI services is therefore to provide such an advanced system that enables us to consistently deliver the best possible services to users.
The categories of data processed include master data, contact data, content data, usage data (if applicable), connection data, and contract data (if applicable).
Provider of the AI services we use
ChatGPT
OpenAI Ireland Limited1st Floor
The Liffey Trust Centre
117-126 Sheriff Street Upper
Dublin 1
D01 YC43
Ireland
https://openai.com/de-DE/policies/eu-privacy-policy/
Memberspot GmbH
Rilkestr. 26,, 71642 Ludwigsburg
www.memberspot.de
6.5 Polls and surveys with Notion Forms
We use the “Notion Forms” tool to conduct surveys and polls. Notion Forms is a service provided by Notion Labs, Inc., 2300 Harrison Street, San Francisco, CA 94110, USA.
The categories of data processed in this context typically include contact information, master data, and content data.
Additional information about data processing by Notion can be found here:
https://www.notion.com/de/help/gdpr-at-notion.
7. payment processing
We offer various payment methods for processing payment requests. To this end, we integrate the payment service providers described below. We do this to ensure that our services are provided properly and in accordance with your needs.
The data processed in this context includes usage data, connection data, master data, payment data, contact data, and contract data—such as account numbers, credit card numbers, passwords, TANs, and checksums—as well as information related to the contract, payment amounts, and recipients.
Payment Service Provider
Stripe
If users choose a payment method offered by the payment service provider Stripe, payment processing is handled by the payment service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we will disclose the information provided during the ordering process, along with the order details (name, address, account number, bank routing number, credit card number if applicable, invoice amount, currency, and transaction number) in accordance with Article 6(1)(b) of the GDPR.
For more information on Stripe’s privacy policy, visit
https://stripe.com/de/privacy#translation.
Stripe reserves the right to conduct a credit check based on mathematical and statistical methods in order to safeguard its legitimate interest in determining the user’s ability to pay.
Users may object to this processing of data at any time by sending a message to Stripe or the designated credit reporting agencies. However, Stripe may still be entitled to process users’ personal data if this is necessary for the contractual processing of payments.
Invoice processing with MOCO
We use the cloud-based software MOCO to prepare quotes and invoices, as well as to manage customer, project, and billing data.
The recipient of this data is hundertzehn GmbH, In der Weid 15, 8122 Binz, Switzerland.
The data processed may come from any of the data categories listed in Section 2.3.
Further information on data processing by MOCO can be found in the provider’s privacy policy:
https://www.mocoapp.com/unternehmen/datenschutz.
8. hosting
8.1 Provision of our services
In order to provide our services to users, we use the services of a hosting provider, Memberspot GmbH. Our services are accessed via this hosting provider’s servers. For these purposes, we utilize the hosting provider’s infrastructure and platform services, computing capacity, storage space, and database services, as well as its security and technical maintenance services.
The data processed includes all data that users enter or that is collected from users in connection with their use of and communication regarding our services (e.g., IP address). Our legal basis for using a hosting provider to deliver our services is Article 6(1)(f) of the GDPR (legitimate interest).
8.3 Collection of access data and log files
We (or our hosting provider) collect data on every access to the server (server log files). The server log files may include the address and name of the services and files accessed, the date and time of the request, the amount of data transferred, a notification of a successful request, the device type and version, the operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider.
Server log files may be used, on the one hand, for security purposes—for example, to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks)—and, on the other hand, to ensure server capacity and stability. Our legal basis for using a hosting provider to collect access data and log files is derived from Article 6(1)(f) of the GDPR (legitimate interest).
9. transactional mails
Active Campaign
We use Active Campaign to send transactional emails as part of our services. Active Campaign is a service that allows us, among other things, to organize and analyze the sending of transactional emails.
The provider of Active Campaign—and thus the recipient of the data—is ActiveCampaign, LLC, 150 N. Michigan Ave, Suite 1230, Chicago, IL, US, USA.
Users can find more details in Active Campaign’s Privacy Policy at:
https://www.activecampaign.com/privacy-policy/.
10. profiles on social media websites
We maintain profiles on social media websites and, in this context, process personal data in order to communicate with users active on those platforms or to provide information about us.
We would like to inform users that their data may be processed outside the European Union when they visit our profiles. The operators of the respective social media platforms are responsible for this.
Instagram
We maintain a company profile on Instagram. When you visit our Instagram profile, Meta may analyze usage behavior and share the information obtained from this analysis with us (“Insights”). We use Page Insights to optimize our business operations and tailor our website and services to user needs.
The recipient of the data is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, acting as a joint controller pursuant to Article 26 of the GDPR.
Meta provides information about data subject rights at:
https://privacycenter.instagram.com/policy.
LinkedIn
We maintain a company profile on LinkedIn. When you visit and use our LinkedIn profile, LinkedIn may analyze your usage behavior and share the information obtained from this analysis with us.
The recipient of the data is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, as a joint controller pursuant to Article 26 of the GDPR.
LinkedIn provides information about data subject rights at:
https://de.linkedin.com/legal/privacy-policy.
YouTube
We operate a YouTube channel for our company. When you visit and use our YouTube channel, Notion may analyze your usage behavior and share the information obtained from this analysis with us.
The recipient of the data is Notion Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, as a joint controller pursuant to Article 26 of the GDPR.
YouTube provides information about data subject rights at:
https://www.youtube.com/howyoutubeworks/our-commitments/protecting-user-data/#privacy-guidelines.