Privacy Policy

Introduction

This Privacy Policy explains the nature, scope and purpose of the processing of personal data (hereinafter referred to as data). Data is processed within our online software mite, its functions and contents, the websites linked to it and external online presences such as social media profiles (hereinafter jointly referred to as Online Service):

  • The first section of this Privacy Policy contains information about the data controller and an overview of our processing operations.
  • The second section contains information about your rights, the relevant legal standards and general information about our data processing.
  • The third section contains information on the individual processing operations.
  • The fourth and final section contains explanations and descriptions of the terms used in this Privacy Policy. If you are unfamiliar with terms such as cookie, please refer to the last section.

Section I – Controller and Overview of Data Processing

Controller

mite GmbH
Oranienstraße 166, 10999 Berlin, Germany
Managing directors: Sebastian Munz & Julia Soergel

Phone: +49 176 20772667
E-Mail: [email protected]
Complete legal information: https://mite.de/en/imprint.html
The Controller is hereinafter also referred to as we or us.

Description of our services and objectives

mite is an online tool for recording and evaluating working hours for users of mite.

Type of processed data

  • Customer master data (company name, contact person, address, VAT registration number, e-mail address);
  • Account data (name, e-mail address, cryptographic hash of the password);
  • Payment data (account data and/or credit card data);
  • Contract data (type of service, fee, term, contract history, payment history);
  • Content data that is entered in mite by customers/users themselves (time entries, customers, projects, services);
  • Usage data/ metadata (server logging: IP address, user agent, request parameter, time stamp).

Processing of special categories of Data (Art. 9 (1) GDPR)

In general, no special categories of data are processed, unless these are submitted by the user for processing, e.g. in online forms.

Categories of data subjects

  • Customers, test users, business partners.
  • Visitors and users of the online offer.

In the following, we will also summarise the data subjects as users.

Purpose of Processing

  • Provision of the Online Service, its contents and functions.
  • Providing and operating mite (Software as a Service) and related services (computing capacities, databases, software, maintenance and development).
  • Security measures.
  • Response to contact requests and communication with users.
  • Marketing, advertising and market research.

Automated individual decision-making (Art. 22 GDPR)

We do not use exclusively automated individual decision-making.

As of

February 2023

Section II - Rights of data subjects, legal basis for the processing and general information

Rights of Data Subjects

You have the right to obtain from the controller confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the further information and a copy of the data in accordance with Art. 15 GDPR.

In accordance with Article 16 of the GDPR, you have the right to obtain from the controller the rectification of inaccurate personal data concerning you, or the completion of the data concerning you.

In accordance with Art. 17 GDPR, you have the right to demand that relevant data be erased without undue delay or, alternatively, to demand a restriction of the processing of the data in accordance with Art. 18 GDPR.

You have in accordance with Art. 20 GDPR the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller.

In accordance with Art. 77 GDPR, you also have the right to file a complaint with a supervisory authority.

Right of Withdrawal

You have the right to withdraw consents granted pursuant to Art. 7 (3) GDPR with effect for the future.

Right to Object

You can object to the future processing of the data concerning you in accordance with Art. 21 GDPR at any time. The objection may be lodged in particular against processing for direct marketing purposes.

Cookies

We use temporary and permanent cookies, i.e. small files that are stored on the user's devices (for the explanation of the term and function, see last section of this Privacy Policy). Our cookies serve security purposes or are required for the operation of our Online Services (e.g., for the appearance of the website).

If users do not want cookies to be stored on their computer, they are advised to deactivate the corresponding option in the system settings of their browser. Stored cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this Online Services.

Solely Automated individual decision-making

In accordance with Art. 22 GDPR, you have the right not to be subject to a decision based exclusively on automated processing - including profiling - which has legal effect concerning you or similarly significantly affects you.

We inform you that we do not use exclusively automated individual decision-making.

Erasure of data and archiving obligations

The data processed by us will be erased or its processing restricted in accordance with Articles 17 and 18 GDPR. Unless expressly stated in this Privacy Policy, the data stored by us will be erased as soon as it is no longer required for its intended purpose and there are no legal obligations to retain it. If the data are not erased because they are necessary for other and legally permissible purposes, their processing is restricted. This means that the data is excluded and not processed for other purposes. This applies, for example, to data that must be retained for commercial or taxation reasons.

In accordance with statutory provisions in Germany, the records are kept in particular for 10 years in accordance with Sections 147 (1) German Financial Act (AO) , Sections 257 (1) No. 1 and 4, (4) German Commercial Code (HGB) (books, records, management reports, accounting documents, trading books, documents relevant to taxation, etc.) and for 6 years in accordance with Sections 257 (1) No. 2 and 3, (4) HGB (commercial letters).

Changes and Updates to this Privacy Policy

We ask you to keep yourself regularly informed about the contents of our Privacy Policy. We will adapt the Privacy Policy as soon as any changes in data processing carried out by us make this necessary. We will inform you as soon as the changes require your cooperation (e.g. consent) or other individual notification.

Relevant Legal Basis for the Processing

In accordance with Art. 13 GDPR, we inform you of the legal basis of our data processing. If the legal basis is not explicitly stated in the Privacy Policy, the following applies: The legal basis for obtaining consents is Art. 6 (1) a and Art. 7 GDPR, the legal basis for processing for the performance of our services and performance of contractual measures as well as for answering inquiries is Art. 6 (1) b GDPR, the legal basis for processing to fulfil our legal obligations is Art. 6 (1) c GDPR, and the legal basis for processing to protect our legitimate interests is Art. 6 (1) f GDPR. In the event that the vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) GDPR serves as the legal basis.

The principles for commercial communications outside of business relations, in particular by post, telephone, fax and e-mail, are contained in § 7 of the German Unfair Competition Act (UWG).

Security of Data Processing

We shall take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk in accordance with Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons; the measures include in particular ensuring the confidentiality, integrity and availability of data by controlling physical access to the data, as well as the access, input, transfer, integrity and pseudonymity. Furthermore, we have established procedures that guarantee the assertion of data subjects' rights, the erasure of data and the response to data hazards. Furthermore, we already consider the protection of personal data during the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design of technology and by data protection-friendly presettings (Art. 25 GDPR).

The security measures include in particular the encrypted transmission of data between your browser and our server.

Disclosure and Transmission of Data

If we disclose data to other persons and companies (processors or third parties) within the scope of our processing, transfer the data to them or otherwise grant them access to the data, this will only be carried out on the basis of a legal permission (e.g. if a transfer of the data to third parties, such as to payment service providers, is required for contract fulfilment pursuant to Art. 6 (1) b GDPR), if you have consented, if a legal obligation requires this or on the basis of our legitimate interests (e.g. when using agents, web hosting services, etc.).

If we commission third parties with the processing of data on the basis of a so-called Data Processing Agreement, this is done on the basis of Art. 28 GDPR.

Transfers to Third Countries

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA) or if this occurs in the context of the use of third-party services or disclosure or transmission of data to third parties, this only takes place if it is necessary to fulfil our (pre)contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or let the data being processed in a third country only if the special requirements of Art. 44 ff GDPR are met. This means, for example, processing is carried out on the basis of special guarantees, such as the officially recognised adequate data protection level corresponding to the EU (e.g. for the USA by a ruling of the EU commission) or compliance with officially recognised special contractual obligations (so-called Standard Contractual Clauses or standard data protection clauses).

Section III - Processing operations

The following section provides an overview of our processing activities, which we have subdivided into other areas of operation. Please note that the areas of operation are for guidance only and that processing activities may overlap (e.g. the same data may be processed in several operations).

For reasons of clarity and comprehensibility, you will find the frequently repeated terms in Section IV of this data protection declaration.

Contractual services (mite)

We process the data of our customers within the scope of mite's services in order to provide our contractual services.

  • Data processed: Customer master data (company name, contact person, address, VAT registration number, e-mail address), user and account data (name, e-mail address, cryptographic hash of password), payment data (account data and/or credit card data), contract data (type of service, fee, term, contract history, payment history), content data which are entered by customers/users themselves in mite (time entries, customers, projects, services), usage data/ metadata (server logging: IP address, user agent, request parameter, time stamp).
  • Special categories of personal data: In general, no special categories of data are processed unless they are submitted by the user.
  • Data subjects: Customers, test users, business partners
  • Purpose of Processing: infrastructure and platform services, computing capacity, storage and database services, security services, technical maintenance services.
  • Legal basis: Art. 6 (1) b GDPR (performance of the contract).
  • Necessity / interest in processing: The data are necessary to establish and fulfil the contractual performance.
  • External disclosure and purpose: For hosting purposes only or within the scope of legal permissions and obligations towards legal consultants and authorities.
  • Processing in third countries: none.
  • Deletion of data: Content data entered into mite by customers themselves will be deleted 14 days after termination of the account; data of test users will be deleted 28 days after expiry of the trial account or termination; customer master data will be stored indefinitely, unless they are no longer required; the necessity of storing the data will be checked every three years; in the case of statutory archiving obligations the deletion will take place after their expiry (end of retention obligation - commercial, 6 years / tax, 10 years).

Hosting mite.data

The hosting services we use serve to provide the following services: Infrastructure and platform services, computing capacity, storage and database services, security services, technical maintenance services.

  • Data processed: Inventory data, contact data, content data, contract data, usage data, meta/communication data.
  • Special categories of personal data: none.
  • Legal basis: Art. 6 (1) f GDPR.
  • Data subjects: customers, prospective customers.
  • Special security measures: Data Processing Agreement.
  • Processing in third countries: none.
  • External disclosure and purpose: SysEleven GmbH, Umspannwerk – Aufgang C, Ohlauer Straße 43, 10999 Berlin, Germany (hosting mite).
  • Privacy Policy: https://www.syseleven.de/datenschutz-nutzungsbedingungen.
  • Necessity / interest in processing: Security, efficiency, business interests.

Hosting Mail Server

The hosting services we use serve to provide the following services: Infrastructure services, security services, technical maintenance services.

  • Data processed: Inventory data, content data, contract data, meta/communication data.
  • Special categories of personal data: none.
  • Legal basis: Art. 6 (1) f GDPR.
  • Data subjects: customers, prospective customers, business partners.
  • Processing in third countries: none.
  • External disclosure and purpose: Heinlein Hosting GmbH, Schwedter Straße 8/9A, 10119 Berlin, Germany (hosting mail server).
  • Necessity / interest in processing: Sending and receiving e-mails to fulfill contractual obligations and inquiries, security, efficiency, business interests.

Hosting Info Website and Blog

The hosting services we use serve to provide the following services: Infrastructure services, computing capacity, storage services, security services, technical maintenance services.

  • Data processed: Contact data, meta/communication data.
  • Special categories of personal data: none.
  • Legal basis: Art. 6 (1) f GDPR.
  • Data subjects: customers, prospective customers, visitors of the website.
  • External disclosure and purpose: Linode LLC, LLC, 249 Arch St., Philadelphia, PA 19106, USA (hosting info website, blog).
  • Privacy Policy: https://www.linode.com/privacy.
  • Processing in third countries: none
  • Necessity / interest in processing: Security, efficiency, business interests.

Answering Inquiries and Customer Service

Information in inquiries that we receive via our contact form and other means, e.g. via e-mail, we process in order to answer the inquiries.

  • Data processed: Inventory data, contact data, contract data, meta/communication data.
  • Data subjects: customers, prospective customers, business partners, website visitors.
  • Purpose of processing: Answering inquiries.
  • Type, scope and mode of operation of the processing: registration process, termination option.
  • Necessity / interest in processing: Necessary to answer queries.
  • Legal basis: Art. 6 (1) b./f GDPR.
  • External disclosure and purpose: Heinlein Hosting GmbH, Schwedter Straße 8/9A, 10119 Berlin, Germany (hosting mail server).
  • Processing in third countries: none.
  • Retention of data: We delete the inquiries if they are no longer required. We review the requirement every two years; requests from customers who have a customer account are stored permanently and are linked to the customer account details for deletion. In the case of statutory archiving obligations, the erasure takes place after their expiry (end of commercial law (6 years) and tax law (10 years) storage obligation).

Administration, Financial Accounting, Office Organization, Archiving

We process data within the framework of administrative tasks as well as the organization of our company, financial accounting and compliance with legal obligations, such as archiving.

  • Data processed: Data that we process in the course of our Online Services.
  • Special categories of personal data: none.
  • Legal basis: Art. 6 (1) c GDPR, Art. 6 (1) f GDPR.
  • Data subjects: customers, prospective customers, business partners, website visitors.
  • Purpose of processing: administration, financial accounting, office organization, archiving.
  • Necessity / interest in processing: The processing is necessary to maintain our business and our services.
  • External disclosure and purpose: financial administration, tax consultants, other fee agencies, payment service providers to carry out contractual or legal payment transactions; payment data is only stored at the following payment service providers (=no own storage or processing): 1&1 Internet SE (iPayment), Germany; InterCard AG, Germany; BS PAYONE GmbH, Germany.
  • Processing in third countries: none.
  • Retention of data: The erasure of the data with regard to contractual services and contractual communication corresponds to the information provided in these processing activities.

Blog

User comments on the blog are stored and can be validated to ensure they are not spam.

  • Data processed: Inventory data (names, e-mail addresses, links to own website); content data (comment)
  • Special categories of personal data: none.
  • Processing principles: Art. 6 (1) b GDPR; Art. 6 (1) f GDPR.
  • Affected persons: Authors of comments
  • Purpose of the processing: storage of the comment.
  • Necessity / interest in processing: security purposes (spam check).
  • Protective measures: Users are welcome to use pseudonyms.
  • processing in third countries: no.
  • Deletion of data: Data within the spam check after four days, unless the comment was identified as spam, then the data remains permanently stored.

Online Presences in Social Media

We maintain online presences within social networks and platforms in order to communicate with active customers, interested parties and users and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and the privacy policy of their respective providers apply. Unless otherwise stated in our privacy policy, we will process the data of users who communicate with us within social networks and platforms, e.g. send us messages.

The links to social networks and platforms (hereinafter referred to as social media) used within our Online Services do not establish a data transmission between social networks and users until users click on the links and access the respective networks or their websites.

Social networks/platforms used by us: mastodon.social.

Responsible for data processing at mastodon.social is as a basic principle Mastodon gGmbH (Germany).

Server-Logs

The server on which this Online Service is hosted collects so-called log files each time the Online Service is accessed, in which user data is stored. The data is used for statistical analysis to maintain and optimize server operation and for security purposes, e.g. to detect potential unauthorized access attempts.

  • Data processed: Usage data and metadata (name of the accessed website, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, IP address).
  • Special categories of personal data: none.
  • Legal basis: Art. 6 (1) f GDPR.
  • Data subjects: customers, prospective customers, visitors of the Online Service.
  • Purpose of processing: Optimization of server operation and security monitoring.
  • Necessity / interest in processing: Security, business interests.
  • Processing in third countries: no.
  • Deletion of data: After 28 days from the time of the collection.

Server-Monitoring & Error-Tracking

We monitor servers and track errors to ensure the availability and integrity of our Online Services and use the data for technical and user-friendly optimisation.

  • Data processed: Aggregated performance data, in the event of an error or problem: pseudonymized requests (account ID).
  • Special categories of personal data: none.
  • Legal basis: Art. 6 (1) f GDPR, Art. 28 (3 p. 1 GDPR.
  • Data subjects: customers, users, business partners, website visitors
  • Purpose of processing: server logging; server monitoring & error tracking.
  • Type, scope and mode of operation of the processing: Third-party cookies, permanent cookies.
  • Special security measures: No transmission of IP addresses.
  • Necessity / interest in processing: Security, efficiency of the Online Service.
  • External disclosure and purpose: New Relic, Inc Attn: Legal Department 188 Spear Street, Suite 1200 San Francisco, CA 94105, provider of the services required to fulfil the purpose.
  • Privacy Policy: https://newrelic.com/termsandconditions/privacy.
  • Processing in third countries: USA.
  • Guarantee when processing in third countries: EU standard data protection clauses.
  • Retention of data: Aggregated data: 3 months; Pseudonymised data: 7 days

Section IV - Definitions

This section provides an overview of the terms used in this Privacy Policy. Many of the terms are taken from the law and defined above all in Art. 4 GDPR. The legal definitions are binding. The following explanations, on the other hand, are intended primarily for understanding. The terms are sorted alphabetically.

Consent

Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Controller

Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Cookies

Cookies are small files that are stored on the user's computer. Different data can be stored in the cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after his or her visit to a website. Temporary cookies or session cookies or transient cookies are cookies that are deleted after a user leaves a website and closes his browser. In such a cookie, for example, the login status can be stored. Cookies are referred to as permanent or persistent if they are stored even after the browser is closed. For example, the login status can be saved permanently.

Processor

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Processing

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Pseudonymisation / Pseudonyms

Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person; E.g. if an exact interest profile of the computer user is stored in a cookie, but not the name of the user, then data is processed pseudonymously. If his name is stored, e.g. as part of his e-mail address or his IP address is stored, then the processing is no longer pseudonymous.

Special categories of personal data

Data identifying racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data, biometric data uniquely identifying a natural person, health data or data relating to a natural person's sex life or sexual orientation.

Third countries

Third countries are countries in which the GDPR is not directly applicable law, i.e. in general states that do not belong to the European Union (EU) or the European Economic Area (EEA).

Third Party

Third Party means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Tracking

Tracking is defined as when the behaviour of users can be traced across several online offers, e.g. for remarketing purposes. The behavioural and interest information collected with regard to the online services used is stored as user profiles in cookies or on the servers of marketing service providers (e.g. Google or Facebook).