Website Privacy Policy

General

Our privacy policy explains which personal data is collected when you use our websites.

in which way are processed.

Responsible for the processing of your personal data within the meaning of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) is:

Echometer GmbH
Tondernstrasse 1
48149 Münster
E-mail: [email protected]

We only process personal data if this is permitted by law. Personal data will only be passed on to recipients whom we expressly designate in these data protection provisions.

As soon as the purpose of the processing no longer applies, personal data will be deleted or blocked for further use by technical and organizational measures. This also takes place when a prescribed storage period expires, unless there is a need for further storage of the personal data for the conclusion or fulfillment of a contract.

Unless we are legally obliged to store the data for a longer period of time or to pass it on to third parties (in particular law enforcement authorities), the decision as to which personal data we collect, how long it is stored and to what extent you may have to disclose it depends on which functions of our website or service are used in each individual case.

External links

Links on our Internet pages and services may lead to other Internet pages and services that are not operated by us, but by third parties. Such links are either clearly marked by us or are recognizable by a change in the address line of the browser.

We are not responsible for compliance with data protection regulations and the secure handling of personal data on these websites and services operated by third parties.

Definitions

These data protection provisions use the terms of the legal text of the GDPR. You can find the definitions (Art. 4 GDPR) under, for example https://dejure.org/gesetze/DSGVO/4.html can be viewed.

What data we collect

We collect various types of data when you use our website and our service.

The first type is data that is directly and consciously provided to us. This includes the information that is entered when creating an account for the service (name, email address and password) as well as data that users create while using the service, e.g. feedback, interactions in the retrospective, measures created, etc. This data belongs to the data subjects. This data belongs to the data subjects. By using our service, users give us permission to store this data and process it in accordance with this privacy policy. They can decide to withdraw this consent at any time, but this may reduce or even prevent the usability of our service.

The second type is data that we collect automatically when data subjects use our website and services. This data is only used to operate and improve our service.

Data subject rights

In accordance with the European GDPR in accordance with Chapter 3, the following "data subject rights" apply:

Those affected have the right...

  • for information about data processing acc. Art. 15 GDPR
  • correction of data acc. Art 16 GDPR
  • Submit a complaint to a supervisory authority in accordance with Art. 77 GDPR
  • for deletion (also known as “right to be forgotten”) in accordance with Art. 17 GDPR
  • to restrict processing in accordance with Art. 17 GDPR
  • on data portability acc. Art. 20 GDPR
  • Objection to the processing, provided that this takes place on the basis of Art. 6 Para. 1 Letter e or f GDPR.

Note that we can change our privacy policy. Updates are made available directly on this page. In the event of significant changes, we will also inform you on the registration screen or by email. If you do not agree to future changes to this privacy policy, you must stop using our services and delete your account. We are obliged to inform you about the correction or deletion of personal data or the restriction of processing.

Use of cookies

Cookies are text files that are stored or read by a website on end devices. They contain combinations of letters and numbers, e.g. to recognize the data subject when reconnecting to the cookie-setting website, to restore the previous settings, to enable the data subject to remain logged in to a customer account or to statistically analyze certain usage behavior.

We use cookies to:

  • Save preferences for our website
  • save the login status

Informational use

When data subjects access our website and use it purely for information purposes, personal data is automatically collected. This is the following information: Browser type and browser version, operating system used, address of the previously visited website, address of the end device with which you access the website (IP address) and time of access to the website. This information is transmitted by the browser, unless the browser suppresses the transmission of the information through appropriate settings.

This personal data is processed for the purposes of the functionality and optimization of the website, as well as to ensure the security of our information technology systems. This is also our legitimate interest, which is why processing is permitted under Article 6 (1) (f) GDPR.

Contact options

If you have any questions about our privacy policy, security measures or the exercise of data subject rights, please contact us by e-mail at [email protected].

Contact form

When using the contact form or contacting us via e-mail, the personal data contained therein is first processed for us by HubSpot as a marketing service provider and then made available to us for further processing. This information is transmitted by the browser or email client and stored in our information technology systems. The processing of this personal data is necessary for answering the inquiries. In addition, the IP address and the date and time of the contact request are stored.

The data processing serves to answer your request and to prevent misuse of the contact form and to ensure the security of our information technology systems. This processing is lawful because answering your request and protecting our information technology systems constitute legitimate interests within the meaning of Article 6 (1) (f) GDPR.

The personal data will be stored for as long as is necessary to answer the request. If the inquiry leads to the conclusion of a contract at a later date, the data will be stored for as long as is necessary to carry out pre-contractual measures or to fulfill the contract.

Newsletter

Users can subscribe to our newsletter on our website. When you register, the data you provide (name and email address) will be forwarded to HubSpot as a CRM tool. The IP address and time of registration are stored. The emails are sent via HubSpot or Brevo as an email marketing tool.

Registration for the newsletter is only valid once the e-mail address has been confirmed by clicking on the link in the confirmation e-mail (so-called double opt-in procedure).

The processing of the personal data you have entered is used to send the newsletter. This processing is based on your consent in accordance with Art. 6 Para. 1 Letter a GDPR. The storage of the IP address and the time of registration serves the purpose of ensuring the security of our systems.

The personal data entered will be stored until the subscription is canceled. Data will not be passed on to third parties.

Integrated third-party providers

Cloudflare

We use the Content Delivery Network (CDN) of Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich Germany (Cloudflare) to increase the security and delivery speed of our website. This corresponds to our legitimate interest (Art. 6 para. 1 lit. f DSGVO). A CDN is a network of [globally] distributed servers that is able to deliver optimized content to the website user. For this purpose, personal data may be processed in server log files by Cloudflare.

Cloudflare has implemented compliance measures for international data transfers. These apply to all global activities where Cloudflare processes personal data of individuals in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs). More information about Cloudflare: https://www.cloudflare.com/cloudflare_customer_SCCs-German.pdf

Google Analytics

Google Analytics is used on our website and in our service, a web analytics service provided by Google Ireland Limited ("Google"). Use includes the "Universal Analytics" operating mode. This makes it possible to assign data, sessions and interactions across multiple devices to a pseudonymous user ID and thus analyze the activities of a user across devices.

Google Analytics uses so-called “cookies”, text files that are stored on your computer and that enable an analysis of your use of the website and our service. The information generated by the cookie about your use of this website and the service is usually transferred to a Google server in the USA and stored there. If IP anonymization is activated, your IP address will be shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. We would like to point out that on this website and in our Google Analytics service, IP anonymization has been added to ensure that IP addresses are recorded anonymously (so-called IP masking). The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You can find more information on terms of use and data protection at https://www.google.com/analytics/terms/de.html or under https://policies.google.com/?hl=de.

As an extension of Google Analytics, this website also uses the Google Signals service. Google Signals can be used to create cross-device reports on the use of the website by Google. If you have activated "personalized ads" in your Google account, Google can analyze user behavior across devices if you have given your consent to the use of Google Analytics in accordance with Art. 6 (1) a DSGVO (see above). We do not receive any personal data from Google in this regard, but only statistics compiled on the basis of Google Signals. You have the option to deactivate the "personalized ads" function in the settings of your Google account and thus turn off the cross-device analysis. See: https://support.google.com/ads/answer/2662922?hl=de

You can find more information here: https://support.google.com/analytics/answer/7532985?hl=de

Purposes of processing

On behalf of the operator of this website, Google will use this information to evaluate your use of the website and the service, to compile reports on website activity and to provide other services related to Echometer related to website, service and internet usage.

Legal basis

Google Analytics is used for the purposes of economic optimization and the needs-based design of our website. This represents a legitimate interest within the meaning of Article 6 (1) (f) GDPR. In addition, we have concluded an order processing contract with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

Recipients / categories of recipients

The recipient of the data collected is Google.

Transmission to third countries

The personal data is transferred to the USA under the EU-US Privacy Shield based on the adequacy decision of the European Commission. You can use the certificate right here recall.

Duration of data storage

The data sent by us and linked with cookies, user IDs (e.g. user ID) or advertising IDs will be automatically deleted after 14 months. Data whose retention period has expired is automatically deleted once a month.

Data subject rights

You can prevent the effect of using Google Analytics at any time with future effect by preventing the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website or the service to their full extent.

You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website and the service (including your IP address) and from processing this data by Google by doing this Browser add-on download and install. Opt-out cookies prevent the future collection of your data when you visit our website. In order to prevent the acquisition by Universal Analytics across different devices, you have to perform the opt-out on all used systems. If you click here, the opt-out cookie will be set: Deactivate Google Analytics

Google Tag Manager

When you visit our website, Google Tag Manager is loaded as a service of Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA (“Google”) to manage website tags. The Tag Manager makes it easier for us to integrate and manage our tags. Tags are small code elements that serve, among other things, to measure traffic and visitor behavior, to record the impact of online advertising and social channels, to set up remarketing and targeting groups and to test and optimize websites.

The Google Tag Manager tool, which implements the tags, is a cookie-free domain and does not collect any personal data itself, Google Tag Manager triggers other tags, which in turn may be able to collect data. However, Google Tag Manager does not access this data. If deactivation has been carried out at the domain or cookie level, this remains in place for all tracking tags that are implemented with Google Tag Manager.

Google Tag Manager is used for the purpose of managing website tags and for measuring application requests and contact requests. This represents a legitimate interest within the meaning of Article 6 (1) (f) GDPR. The data transfer to the USA is carried out in accordance with Implementing Decision (EU) 2016/1250 of the EU Commission (EU-US data protection shield).

You can find more information about Google Tag Manager at https://www.google.com/intl/de/tagmanager/faq.html, Google's privacy policy can be found at https://www.google.com/policies/privacy/.

HubSpot

We use the inbound marketing tool "HubSpot" on our website, which is provided by HubSpot Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141 United States. HubSpot is a web-based all-in-one marketing software that is used to implement and control inbound marketing. It helps us to arouse your interest in our products. A personal contact within HubSpot is created as soon as a previously anonymous website visitor fills out a HubSpot form. At this moment, a contact will be created based on your email address.

Purposes of processing

HubSpot is used for the purposes of individualizing advertising and for market research purposes.

Legal basis

The purposes described represent a legitimate interest within the meaning of Article 6 (1) (f) GDPR.

Recipients / categories of recipients

The recipient of the data collected is HubSpot.

Transmission to third countries

The personal data are transferred to the USA under the EU-US Privacy Shield. You can use the certificate right here recall. We have also concluded a contract processing contract with HubSpot and implement the strict requirements of the German data protection authorities when using HubSpot.

HubSpot's privacy policy can be found at https://legal.hubspot.com/de/privacy-policy.

Facebook Ads - Custom Audiences

We use the remarketing function "Custom Audiences" from Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook"). With Custom Audiences, we can target the users of our website with advertising by using personalized and interest-related Facebook ads (https://de-de.facebook.com/business/products/ads) when you visit the social network Facebook.

We use Facebook Custom Audiences in the "Facebook Custom Audiences from Website" variant (Facebook Pixel). An invisible pixel is integrated on our website. When a potential customer looks at certain products on our website, this invisible pixel forwards the data to Facebook. The next time the potential customer logs in to Facebook, he will receive targeted advertising for the product due to the integration of the pixel, which he previously viewed but may not have acquired.

This personal data is processed for the purpose of optimizing our offers and individualized advertising. This is also where our legitimate interests lie, which is why processing is permitted under Article 6 (1) (f) GDPR. The data transfer to the USA takes place according to the implementation decision (EU) 2016/1250 of the EU Commission (EU-US data protection shield). If you do not want Facebook to assign the information collected directly to your Facebook user account, you can deactivate the remarketing function "Custom Audiences" in the settings of your Facebook user account. To do this, you must be logged in to Facebook.

You can find more information on the collection and use of data by Facebook, your rights in this regard and options for protecting your privacy in Facebook's data protection information (https://www.facebook.com/about/privacy/).

LinkedIn Insight Tag

We use a service on our website ("LinkedIn Conversion Tracking") from LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland ("LinkedIn"). The LinkedIn "Insight Tag" is used to support the service.

With LinkedIn conversion tracking, we can measure the efficiency of our advertisements. Every time one of our pages containing LinkedIn functions is accessed, a connection to the LinkedIn servers is established. LinkedIn is informed that you have visited our website. At the same time, LinkedIn can store or read cookies on your device, unless you have prohibited the use of cookies in your browser. With the help of the LinkedIn Insight Tag, we can in particular analyze the success of our campaigns within LinkedIn or determine target groups for these campaigns based on the interaction of the users with our online offer. If you are registered with LinkedIn, LinkedIn is able to assign your interaction with our online offer to your user account.

The LinkedIn Insight Tag enables the collection of data on visits by members to our website, including referrer URL, IP address, device and browser properties, time and page views. This data will be deleted within seven days.

LinkedIn does not pass on the personal data to us, but only offers aggregated reports on the website target group and the advertising performance.

The data processing serves to display personalized advertising and enables us to evaluate the use of our website. This is a legitimate interest in accordance with Art. 6 para. 1 letter f GDPR.

You can prevent cookies from being stored and read by setting your browser software accordingly. You can also prevent the collection of the data generated by the cookie and related to your use of the website on LinkedIn and the processing of this data by LinkedIn by setting an opt-out cookie that prevents the future collection of your data when you visit this website . To do this, click on this link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out

Further information can be found in LinkedIn's data protection declaration (https://www.linkedin.com/legal/privacy-policy).

PostHog

We use the product analytics tool "PostHog" in our app, which is provided by:

PostHog Inc, 2261 Market Street #4008, San Francisco, CA 94114

Data Protection Officer: Charles Cook (VP Operations), [email protected]

PostHog is a platform for product development and analysis that makes it possible to roll out new features sequentially as part of release management, ensure their stability and analyze their use. Session recordings are created to analyze user behavior without tracking user input. Data is also processed for support and analysis purposes.

Purposes of processing

PostHog is used for the purpose of improving the website and analyzing website usage.

Legal basis

The purposes described represent a legitimate interest within the meaning of Article 6 (1) (f) GDPR.

Recipients / categories of recipients

The recipient of the collected data is PostHog Inc. and Echometer uses EU hosting only.

Transmission to third countries

There is no transmission to third countries.

Brevo / Sendinblue SAS

We use the "Brevo" tool for marketing newsletters, which is provided by:

Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France

Data Protection Officer: [email protected]

Purposes of processing

Brevo is used for the purposes of email communication.

Legal basis

The purposes described represent a legitimate interest within the meaning of Article 6 (1) (f) GDPR.

Recipients / categories of recipients

The recipient of the data collected is Sendinblue SAS.

Transmission to third countries

There is no transmission to third countries.