Website Privacy Policy
General Information
Our privacy policy explains which personal data is processed in the context of the use of our websites
and how it is processed.
The responsible party within the meaning of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) for the processing of your personal data is
Echometer GmbH
Tondernstraße 1
48149 Münster
Email: [email protected]
We only process personal data if this is permitted by law. Personal data is only passed on to those recipients that we expressly designate in these data protection provisions.
As soon as the purpose of the processing no longer applies, personal data is deleted or blocked for further use by means of technical and organizational measures. This also occurs if a prescribed storage period expires, unless there is a need for further storage of the personal data for the conclusion or fulfillment of a contract.
Unless we are legally obliged to store it for a longer period or to pass it on to third parties (in particular law enforcement authorities), the decision as to which personal data is collected by us, how long it is stored and to what extent you may have to disclose it depends on which functions of our website or our service are used in individual cases.
External Links
Links on our website and services may lead to other websites and services that are operated not by us, but by third parties. Such links are either clearly marked by us or can be identified by a change in the address bar of the browser.
We are not responsible for compliance with data protection regulations and the secure handling of personal data on these websites and services operated by third parties.
Definitions
These data protection regulations use the terms of the legal text of the GDPR. The definitions (Art. 4 GDPR) can be viewed, for example, at https://dejure.org/gesetze/DSGVO/4.html.
What data we collect
We collect various types of data during the use of our website and our service.
The first type is data that you provide to us directly and consciously. This includes the information entered when creating an account for the service (name, email address and password) as well as data that users create while using the service, e.g. B. Feedbacks, interactions in the retrospective, created measures, etc. This data belongs to the data subjects. By using our service, users give us permission to store this data and process it within the scope of this data protection declaration. You can decide to withdraw this consent at any time, which may reduce or even prevent the usability of our service.
The second type is data that we collect automatically while data subjects use our website and services. This data is only used to operate and improve our service.
Rights of data subjects
In accordance with the European GDPR according to chapter 3, the following "rights of data subjects" apply:
Data subjects have the right...
- to information about data processing in accordance with Art. 15 GDPR
- to correction of data in accordance with Art. 16 GDPR
- to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR
- to deletion (also known as the "right to be forgotten") in accordance with Art. 17 GDPR
- to restriction of processing in accordance with Art. 17 GDPR
- to data portability pursuant to Art. 20 GDPR
- To object to the processing, provided that this takes place on the basis of Art. 6 Para. 1 Letter e or f GDPR.
Our privacy policy may change. Updates will be made available directly on this page. In the event of significant changes, we will also inform you on the login screen or by email. If data subjects do not agree with future changes to this privacy policy, they must discontinue using our services and delete their account. We are obliged to inform data subjects about the correction or deletion of personal data or the restriction of processing.
Use of cookies
Cookies are text files that are stored on end devices by a website or read from there. They contain combinations of letters and numbers, e.g. to recognize the person concerned when reconnecting to the cookie-setting website, to restore the previous settings, to enable staying logged in to a customer account or to statistically analyze certain usage behavior.
We use cookies to:
- Save preferences for our website
- Save the login status
Informational use
When data subjects access our website and use it purely for information purposes, personal data is automatically collected. This includes the following information: browser type and browser version, operating system used, address of the previously visited website, address of the end device with which you access the website (IP address) and time of accessing the website. This information is transmitted by the browser, provided that the browser does not suppress the transmission of the information through appropriate settings.
This personal data is processed for the purposes of the functionality and optimization of the website, as well as to ensure the security of our information technology systems. This is also our legitimate interest, which is why the processing is permitted in accordance with Art. 6 Para. 1 Letter f GDPR.
Contact options
If you have any questions about our data protection regulations, security measures or to exercise your rights as a data subject, please contact us by email at [email protected].
Contact form
When using the contact form or contacting us via email, the personal data contained therein is initially processed for us by HubSpot as a marketing service provider and then made available to us for further processing. This information is transmitted by the browser or email client and stored in our information technology systems. The processing of this personal data is necessary to answer the requests. In addition, the IP address and date and time of the contact request are saved.
The data processing serves the purpose of answering your request and preventing misuse of the contact form and ensuring the security of our information technology systems. These processing operations are lawful because answering the request and protecting our information technology systems represent legitimate interests within the meaning of Art. 6 Para. 1 Letter f GDPR.
The personal data is stored for as long as is necessary to answer the request. Should the request lead to a subsequent contract, storage will take place for as long as this is necessary to carry out pre-contractual measures or to fulfill the contract.
Newsletter
Users can subscribe to our newsletter on our website. When registering, the data you provide (name and email address) will be forwarded to HubSpot as a CRM tool. The IP address and time of registration are saved. The emails are sent via HubSpot or Brevo as an email marketing tool.
Registration for the newsletter is only valid if the email address has been confirmed by clicking on the link in the confirmation email (so-called double opt-in procedure).
The processing of the personal data entered serves to send the newsletter. This processing is based on your consent in accordance with Art. 6 Para. 1 Letter a GDPR. The storage of the IP address and time of registration serves the purpose of ensuring the security of our systems.
The personal data entered will be stored until the subscription is canceled with us. Data will not be passed on to third parties.
Embedded Third-Party Providers
Cloudflare
We use the Content Delivery Network (CDN) from Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany (Cloudflare), to increase the security and delivery speed of our website. This corresponds to our legitimate interest (Art. 6 Para. 1 lit. f GDPR). A CDN is a network of [worldwide] distributed servers that can deliver optimized content to website users. For this purpose, personal data can be processed in server log files by Cloudflare.
Cloudflare has implemented compliance measures for international data transfers. These apply to all global activities in which Cloudflare processes personal data of natural persons in the EU. These measures are based on the EU standard contractual clauses (SCCs). Further information on Cloudflare: https://www.cloudflare.com/cloudflare_customer_SCCs-German.pdf
Hetzner
Our website is hosted in data centers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Further information about the company can be found in our legal notice.
Contact for data protection: [email protected]; postal address: Hetzner Online GmbH, Datenschutz, Industriestr. 25, 91710 Gunzenhausen; phone: +49 (0)9831 505216; fax: +49 (0)3745 744472361.
Purposes of Processing
Providing the technical infrastructure and hosting of our website in German data centers.
Legal Basis
The described purposes constitute a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.
Recipient / Categories of Recipients
Hetzner Online GmbH as the hosting provider.
Transfer to Third Countries
No transfer to third countries takes place; processing occurs within Germany or the EU.
Google Analytics
Our website and service use Google Analytics, a web analytics service provided by Google Ireland Limited (“Google”). The use includes the “Universal Analytics” operating mode. This makes it possible to assign data, sessions, and interactions across multiple devices to a pseudonymous user ID and thus analyze a user's activities across devices.
Google Analytics uses so-called “cookies,” text files that are stored on your computer and that enable an analysis of your use of the website and our service. The information generated by the cookie about your use of this website and the service is usually transmitted to a Google server in the USA and stored there. However, if IP anonymization is activated, your IP address will be truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area beforehand. We would like to point out that Google Analytics has been extended to include IP anonymization on this website and in our service in order to ensure anonymized collection of IP addresses (so-called IP masking). The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. Further information on terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html or at https://policies.google.com/?hl=de.
As an extension to Google Analytics, this website also uses the Google Signals service. Google Signals enables Google to create cross-device reports on website usage. If you have activated “personalized ads” in your Google account, Google can analyze user behavior across devices with your consent to the use of Google Analytics in accordance with Art. 6 Para. 1 lit. a GDPR (see above). We do not receive any personal data from Google, but only statistics created on the basis of Google Signals. You have the option of deactivating the “personalized ads” function in the settings of your Google account and thus stopping the cross-device analysis. See: https://support.google.com/ads/answer/2662922?hl=de
Further information can be found here: https://support.google.com/analytics/answer/7532985?hl=de
Purposes of Processing
On behalf of the operator of this website, Google will use this information to evaluate your use of the website and the service, to compile reports on website activity, and to provide other services related to website usage, the use of the service, and internet usage to Echometer.
Legal Basis
Google Analytics is used for the purposes of economic optimization and needs-based design of our website. This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. In addition, we have concluded a contract with Google for order processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Recipient / Categories of Recipients
The recipient of the collected data is Google.
Transfer to Third Countries
The personal data will be transferred to the USA under the EU-US Privacy Shield on the basis of the adequacy decision of the European Commission. You can access the certificate here.
Duration of Data Storage
The data sent by us and linked to cookies, user IDs (e.g. user ID) or advertising IDs is automatically deleted after 14 months. Data whose retention period has been reached is automatically deleted once a month.
Rights of the Data Subject
You can prevent the effect of using Google Analytics at any time with effect for the future by preventing the storage of cookies by a corresponding setting in your browser software; however, we would like to point out that in this case you may not be able to use all functions of this website or the service to their full extent.
You can also prevent Google from collecting the data generated by the cookie and related to your use of the website and the service (including your IP address) and from processing this data by downloading and installing the browser add-on. Opt-out cookies prevent future collection of your data when you visit our website. To prevent collection by Universal Analytics across different devices, you must perform the opt-out on all systems used.
Google Tag Manager
When you visit our website, the Google Tag Manager, a service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”), is loaded to manage website tags. The Tag Manager makes it easier for us to integrate and manage our tags. Tags are small code elements that are used, among other things, to measure traffic and visitor behavior, record the impact of online advertising and social channels, set up remarketing and targeting of target groups, and test and optimize websites.
The Google Tag Manager tool, which implements the tags, is a cookie-less domain and does not collect any personal data itself. Google Tag Manager triggers other tags that may collect data under certain circumstances. However, Google Tag Manager does not access this data. If deactivation has been carried out at domain or cookie level, this remains in place for all tracking tags that are implemented with Google Tag Manager.
Google Tag Manager is used for the purpose of managing website tags and measuring application requests and contact requests. This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. The data is transferred to the USA in accordance with the Implementing Decision (EU) 2016/1250 of the EU Commission (EU-US Privacy Shield).
Further information on Google Tag Manager can be found at https://www.google.com/intl/de/tagmanager/faq.html. Google's privacy policy can be found at https://www.google.com/policies/privacy/.
HubSpot
We use the inbound marketing tool “HubSpot” on our website, which is provided by HubSpot Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141 United States. HubSpot is a web-based all-in-one marketing software that is used to implement and control inbound marketing. It helps us to arouse your interest in our products. A personal contact is created within HubSpot as soon as a previously anonymous website visitor fills out a HubSpot form. At this moment, a contact is created based on your email address.
Purposes of Processing
HubSpot is used for the purposes of individualizing advertising and for market research purposes.
Legal Basis
The purposes described constitute a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.
Recipient / Categories of Recipients
The recipient of the collected data is HubSpot.
Transfer to Third Countries
The personal data will be transferred to the USA under the EU-US Privacy Shield. You can access the certificate here. In addition, we have concluded a contract with HubSpot for order processing and implement the strict requirements of the German data protection authorities when using HubSpot.
HubSpot's privacy policy can be found at https://legal.hubspot.com/de/privacy-policy.
Facebook Ads – Custom Audiences
We use the “Custom Audiences” remarketing function of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). With Custom Audiences, we can target users of our website with advertising by placing personalized and interest-based Facebook ads (https://de-de.facebook.com/business/products/ads) when they visit the Facebook social network.
We use Facebook Custom Audiences in the “Facebook Custom Audiences from Website” variant (Facebook Pixel). An invisible pixel is integrated on our website. If a potential customer looks at certain products on our website, this invisible pixel forwards the data to Facebook. The next time the potential customer logs into Facebook, they will receive targeted advertising for the product that they previously viewed, but may not have purchased, due to the integration of the pixel.
The processing of this personal data takes place for the purposes of optimizing our offers and individualizing advertising. These are also our legitimate interests, which is why the processing is permitted in accordance with Art. 6 Para. 1 lit. f GDPR. The data is transferred to the USA in accordance with the Implementing Decision (EU) 2016/1250 of the EU Commission (EU-US Privacy Shield). If you do not want Facebook to directly associate the collected information with your Facebook user account, you can deactivate the “Custom Audiences” remarketing function in the settings of your user account on Facebook. To do this, you must be logged in to Facebook.
Further information on the collection and use of data by Facebook, your rights in this regard and options for protecting your privacy can be found in Facebook's data protection information (https://www.facebook.com/about/privacy/).
LinkedIn Insight Tag
We use a service (“LinkedIn Conversion Tracking”) from LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”) on our website. The LinkedIn “Insight Tag” is used to support the service.
With LinkedIn Conversion Tracking, we can measure the effectiveness of our advertisements. Whenever you access one of our pages that contains LinkedIn functions, a connection is established to LinkedIn's servers. LinkedIn is informed that you have visited our website. At the same time, LinkedIn can place or read cookies on your device, provided that you have not prohibited the use of cookies in your browser. With the help of the LinkedIn Insight Tag, we can in particular analyze the success of our campaigns within LinkedIn or determine target groups for these campaigns based on the interaction of users with our online offering. If you are registered with LinkedIn, LinkedIn can assign your interaction with our online offering to your user account.
The LinkedIn Insight Tag enables the collection of data on visits by members to our website, including referrer URL, IP address, device and browser properties, time and page views. This data is deleted within seven days.
LinkedIn does not pass on the personal data to us, but only provides aggregated reports on the website target group and the advertising performance.
The data processing serves the display of personalized advertising and enables us to evaluate the use of our website. This is a legitimate interest in accordance with Art. 6 Para. 1 lit. f GDPR.
You can prevent the storage and reading of cookies by a corresponding setting in your browser software. You can also prevent LinkedIn from collecting the data generated by the cookie and relating to your use of the website and from processing this data by setting an opt-out cookie that prevents future collection of your data when you visit this website. To do this, click on this link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Further information on this can be found in LinkedIn's privacy policy (https://www.linkedin.com/legal/privacy-policy).
PostHog
We use the product analytics tool “PostHog” in our app, which is provided by:
PostHog Inc, 2261 Market Street #4008, San Francisco, CA 94114
Data Protection Officer: Charles Cook (VP Operations), [email protected]
PostHog is a product development and analysis platform that enables sequential rollout of new features as part of release management, ensuring their stability and analyzing their usage. To analyze usage behavior, so-called session replays are created without tracking inputs from the users. In addition, data is processed for support and analysis purposes.
Purposes of Processing
PostHog is used for the purpose of improving the website and analyzing website usage.
Legal Basis
The purposes described constitute a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.
Recipient / Categories of Recipients
The recipient of the collected data is PostHog Inc., whereby Echometer exclusively uses EU hosting.
Transfer to Third Countries
There is no transfer to third countries.
Brevo / Sendinblue SAS
We use the tool "Brevo" for marketing newsletters, which is provided by:
Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France
Data protection officer: [email protected]
Purposes of Processing
Brevo is used for the purposes of email communication.
Legal Basis
The purposes described constitute a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.
Recipient / Categories of Recipients
The recipient of the collected data is Sendinblue SAS.
Transfer to Third Countries
There is no transfer to third countries.
Google reCAPTCHA
We use "Google reCAPTCHA" for our contact form. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, as a sub-processor.
We use reCAPTCHA to check whether data entries in the contact form (e.g. in text fields) are made by a natural person. For this purpose, the service automatically analyzes various information (e.g. IP address, time spent, mouse movements) as soon as the contact form is opened and transmits it to Google.
Purposes of processing
Protection of the contact form against abusive, automated use (bots/spam) and ensuring the availability of our systems.
Legal basis
Legitimate interest pursuant to Art. 6 Para. 1 lit. f GDPR.
Recipient / categories of recipients
Google Ireland Limited as provider; Google LLC (USA) as sub-processor.
Transfer to third countries
Personal data may be transferred to the USA; Google relies on EU standard contractual clauses for this purpose.
Duration of data storage
Google stores the data collected by reCAPTCHA in accordance with its own deletion periods. Further information can be found in Google's privacy policy at https://policies.google.com/privacy?hl=de and in the terms of use at https://policies.google.com/terms?hl=de.