Privacy
Preamble
This privacy policy explains what types of personal data we process, for which purposes and to what extent. It applies to all processing of personal data that we carry out, both when providing our services and, in particular, on our websites, in mobile applications and on external online profiles, such as our social media profiles. These are collectively referred to below as our "online services".
The terms used are gender-neutral.
Last updated: 28 March 2025
Contents
- Preamble
- Controller
- Overview of processing
- Applicable legal bases
- Security measures
- Transfer of personal data
- International data transfers
- General information on data retention and deletion
- Rights of data subjects
- Provision of our online services and web hosting
- Use of cookies
- Contact and enquiry management
- Web analytics
- Order processing through Shopify
- Communication via messaging services
- Newsletters and electronic notifications
- Social media profiles
Controller
Titanom Solutions GmbHc/o MyMiloGabriele-Münter-Str. 382110 Germering
Authorised representative: Andrija Vuksanovic
Email address: datenschutz@mymilo.de
Legal notice: https://mymilo.de/impressum
Overview of processing
The following overview summarises the types of data processed, the purposes of processing and the people concerned.
Types of data processed
- Master data.
- Contact data.
- Content data.
- Usage data.
- Metadata, communication and procedural data.
- Log data.
Special categories of data
- Health data
Categories of data subjects
- Communication partners
- Users
Purposes of processing
- Communication.
- Security measures.
- Direct marketing.
- Organisational and administrative procedures.
- Feedback.
- Provision of our online services and ease of use.
- Information technology infrastructure.
- Public relations.
Applicable legal bases
Applicable legal bases under the GDPR: The following provides an overview of the GDPR legal bases on which we process personal data. Please note that national data protection rules in your country of residence or our country of establishment may apply in addition to the GDPR. Where more specific legal bases apply in individual cases, we explain them in this privacy policy.
Consent, Article 6(1)(a) GDPR: The data subject has given consent to the processing of their personal data for one or more specific purposes.
Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR: Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at their request before entering into a contract.
Legitimate interests, Article 6(1)(f) GDPR: Processing is necessary for the legitimate interests pursued by the controller or a third party, unless these are overridden by the interests or fundamental rights and freedoms of the data subject that require protection of personal data.
National data protection rules in Germany: In addition to the GDPR, national German data protection rules apply. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains specific provisions on rights of access, erasure and objection, processing of special categories of personal data, processing for other purposes, data transfers and automated individual decision-making, including profiling. The data protection laws of individual German federal states may also apply.
Application of the GDPR and Swiss FADP: This privacy policy provides information under both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For broader geographical applicability and clarity, we use GDPR terminology. In particular, we use the GDPR terms "processing", "personal data", "legitimate interests" and "special categories of data" rather than the corresponding Swiss statutory terms. Where the Swiss FADP applies, the legal meaning of these terms continues to be determined by that Act.
Security measures
In accordance with legal requirements, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. We consider the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons.
These measures include, in particular, safeguarding data confidentiality, integrity and availability by controlling physical and electronic access, access permissions, input, disclosure, availability and separation. We have also established procedures to ensure that data subject rights can be exercised, data can be deleted and threats to data can be addressed. We also consider personal data protection when developing or selecting hardware, software and procedures, following the principles of data protection by design and by default.
Securing online connections with TLS/SSL encryption (HTTPS): We use TLS/SSL encryption to protect data transmitted through our online services against unauthorised access. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are fundamental technologies for secure data transmission on the internet. They encrypt information transmitted between a website or app and a person's browser, or between two servers, protecting it against unauthorised access. TLS, the more advanced and secure successor to SSL, ensures that data transfers meet the highest security standards. A website secured with an SSL/TLS certificate displays HTTPS in its URL, indicating that data is transmitted securely and in encrypted form.
Transfer of personal data
When we process personal data, it may be transferred or disclosed to other bodies, companies, legally independent organisational units or people. Recipients may include service providers commissioned to carry out IT tasks or providers of services and content embedded in a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with recipients to protect your data.
International data transfers
Data processing in third countries: Whenever we transfer data to a third country, meaning outside the European Union (EU) or the European Economic Area (EEA), or this occurs through the use of third-party services or disclosure or transfer to other people, bodies or companies, we always comply with legal requirements. Such transfers can be identified from the provider's postal address or an explicit reference to third-country data transfers in this privacy policy.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), recognised as a safe legal framework by the European Commission's adequacy decision of 10 July 2023. We have also entered into standard contractual clauses with the relevant providers, meeting the European Commission's requirements and establishing contractual obligations to protect your data.
This twofold safeguard provides comprehensive protection for your data: the DPF is the primary layer of protection, while standard contractual clauses provide additional security. If the DPF changes, the standard contractual clauses act as a reliable fallback. This ensures that your data remains adequately protected even in the event of political or legal changes.
For each service provider, we explain whether they are certified under the DPF and whether standard contractual clauses are in place. Further information about the DPF and a list of certified companies are available on the US Department of Commerce website at https://www.dataprivacyframework.gov/ in English.
Transfers to other third countries are subject to appropriate safeguards, in particular standard contractual clauses, explicit consent or transfers required by law. Information about third-country transfers and applicable adequacy decisions is available from the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General information on data retention and deletion
We delete personal data in accordance with legal requirements as soon as the underlying consent is withdrawn or there is no further legal basis for processing. This includes cases where the original processing purpose no longer applies or the data is no longer needed. Exceptions apply where legal obligations or particular interests require longer retention or archiving.
In particular, data that must be retained for commercial or tax law reasons, or whose retention is necessary to pursue legal claims or protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information on data retention and deletion that applies to specific processing activities.
Where several retention or deletion periods apply to a piece of data, the longest period always takes precedence.
If a period does not expressly begin on a specific date and lasts at least one year, it automatically begins at the end of the calendar year in which the triggering event occurred. For ongoing contractual relationships in which data is stored, the triggering event is the date on which termination or another ending of the legal relationship takes effect.
Data retained beyond its original purpose due to legal requirements or other reasons is processed solely for the reasons that justify its retention.
Further information about processing activities, procedures and services
Data retention and deletion: The following general periods apply to retention and archiving under German law.
10 years: Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the work instructions and other organisational documents required to understand them (Section 147(1) no. 1 in conjunction with (3) AO, Section 14b(1) UStG, Section 257(1) no. 1 in conjunction with (4) HGB).
8 years: Accounting records, such as invoices and expense receipts (Section 147(1) nos. 4 and 4a in conjunction with (3), sentence 1 AO, and Section 257(1) no. 4 in conjunction with (4) HGB).
6 years: Other business documents, including commercial or business correspondence received, copies of commercial or business correspondence sent, and other documents relevant to taxation, such as timesheets, cost allocation sheets, costing records and price lists, as well as payroll documents that are not already accounting records, and till rolls (Section 147(1) nos. 2, 3 and 5 in conjunction with (3) AO, Section 257(1) nos. 2 and 3 in conjunction with (4) HGB).
3 years: Data needed to address potential warranty claims, claims for damages or similar contractual claims and rights, and to handle related enquiries, based on previous business experience and customary industry practice, is retained for the regular statutory limitation period of three years (Sections 195 and 199 BGB).
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, particularly those set out in Articles 15 to 21:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing, you have the right to object at any time to processing for that purpose, including profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent at any time.
- Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed, access to that data, further information and a copy of the data in accordance with legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request the completion of personal data concerning you or the correction of inaccurate personal data concerning you.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that personal data concerning you be deleted without undue delay or, alternatively, that its processing be restricted.
- Right to data portability: In accordance with legal requirements, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transfer to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Provision of our online services and web hosting
We process personal data to provide our online services. For this purpose, we process IP addresses, which are necessary to transmit the content and functions of our online services to people's browsers or devices.
- Types of data processed: Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions; metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved; log data, such as logs of sign-ins, data retrieval or access times. Content data, such as text or image messages and posts, and related information such as authorship or creation time.
- Data subjects: Users, such as website visitors and users of online services.
- Purposes of processing: Provision of our online services and ease of use; information technology infrastructure, including the operation and provision of information systems and technical devices such as computers and servers. Security measures.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Further information about processing activities, procedures and services
Collection of access data and log files: Access to our online services is recorded in server log files. These may include the addresses and names of pages and files requested, date and time of access, data volumes transferred, confirmation of successful retrieval, browser type and version, operating system, referrer URL (the previously visited page), and usually IP addresses and the requesting provider. Server log files may be used for security purposes, such as preventing server overload, particularly through abusive attacks known as DDoS attacks, and to monitor server utilisation and stability. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Data deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data that must be retained as evidence is excluded from deletion until the relevant incident has been fully resolved.
Figma Sites: Hosting and software for creating, providing and operating websites, blogs and other online services. Service provider: Figma Inc., 760 Market Street, San Francisco. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://figma.com. Privacy policy: https://www.figma.com/legal/privacy/.
Use of cookies
The term "cookies" refers to functions that store information on people's devices and read information from them. Cookies may serve various purposes, including the functionality, security and convenience of online services, and analysis of visitor traffic. We use cookies in accordance with legal requirements and obtain prior consent where required. Where consent is not required, we rely on our legitimate interests. This applies where storing and reading information is essential to provide content and functions explicitly requested, such as remembering settings or ensuring the functionality and security of our online services. Consent can be withdrawn at any time. We clearly explain its scope and which cookies are used.
Legal bases for data protection: Whether we process personal data using cookies depends on consent. Where consent has been given, it forms the legal basis. Without consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and procedures.
General information on withdrawing consent and opting out: People can withdraw their consent at any time and object to processing in accordance with legal requirements, including through their browser's privacy settings.
- Types of data processed: Metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved.
- Data subjects: Users, such as website visitors and users of online services.
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Contact and enquiry management
When you contact us, for example by post, contact form, email, telephone or social media, or as part of an existing relationship with us, we process the information you provide to the extent necessary to respond to your enquiry and carry out any requested measures.
- Types of data processed: Master data, such as full name, home address, contact information and customer number; contact data, such as postal and email addresses or telephone numbers; content data, such as text or image messages and posts, and related information such as authorship or creation time; usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions. Metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved.
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback, such as collecting feedback through online forms. Provision of our online services and ease of use.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal bases: Legitimate interests, Article 6(1)(f) GDPR. Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR.
Further information about processing activities, procedures and services
Contact form: When you contact us through our contact form, by email or through other channels, we process the personal data you provide to respond to and handle your enquiry. This usually includes your name, contact details and any other information you provide that is necessary to handle the enquiry appropriately. We use this data solely for the stated purpose of contact and communication. Legal bases: Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR; legitimate interests, Article 6(1)(f) GDPR.
Web analytics
We use web analytics to collect statistics about how our website is used. These statistics help us continually improve our website and its content. Privacy is our highest priority, which is why we use the analytics tool Plausible. Unlike other trackers such as Google Analytics, Plausible deliberately avoids cookies and does not store personal data in the browser or on its servers. Only general data is analysed, such as pages viewed, browsers and devices used, and traffic sources. A complete overview of the data collected is available in Plausible's data policy. Provider: OÜ Plausible Insights, Västriku tn 2, Tartu 50403, Estonia.
Order processing through Shopify
We use the Shopify e-commerce platform to process orders. When you want to place an order with us, you are redirected to our Shopify shop. Personal data needed to process the order, such as your name, billing and delivery addresses, email address and payment information, is collected and processed on Shopify's servers.
Processing is based on Article 6(1)(b) GDPR for the performance of the contract and to take pre-contractual steps. An order cannot be placed without providing this data.
Shopify processes some data on our behalf as a processor and some under its own responsibility, to the extent necessary to provide and improve its services.
Transfers of data to third countries, such as Canada or the USA, cannot be ruled out. Shopify ensures an adequate level of data protection through EU standard contractual clauses.
Further information about privacy at Shopify is available at: https://www.shopify.com/de/legal/datenschutz.
Communication via messaging services
We use messaging services for communication. Please read the following information about how these services work, encryption, the use of communication metadata and your options for objecting.
You can also contact us by other means, such as telephone or email. Please use the contact details provided to you or listed in our online services.
Where content is end-to-end encrypted, the contents of your messages and attachments, such as images, are encrypted from one end to the other. This means that message contents cannot be viewed, even by the messaging service providers themselves. You should always use a current version of the messaging service with encryption enabled to ensure that message contents are encrypted.
We also inform communication partners that, although messaging service providers cannot view message contents, they may learn that and when someone communicates with us. Technical information about the person's device and, depending on its settings, location information may also be processed. This is known as metadata.
Information on legal bases: If we ask communication partners for permission before communicating through a messaging service, their consent forms the legal basis for processing their data. Otherwise, where we do not request consent and they contact us on their own initiative, for example, we use messaging services as a contractual measure with our contractual partners and when initiating a contract. For other interested parties and communication partners, we rely on our legitimate interests in fast, efficient communication and meeting their needs for communication through messaging services. We also note that we do not initially transfer contact details provided to us to messaging services without consent.
Withdrawal, objection and deletion: You can withdraw your consent at any time and
- Purposes of processing: Communication.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal bases: Consent, Article 6(1)(a) GDPR. Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR. Legitimate interests, Article 6(1)(f) GDPR.
Newsletters and electronic notifications
We send newsletters, emails and other electronic notifications, collectively referred to as "newsletters", only with recipients' consent or on a legal basis. Where newsletter content is specified during sign-up, that description determines the scope of consent. An email address is normally sufficient to subscribe. To offer a personalised service, we may also ask for a name to address the recipient personally or for further information if necessary for the newsletter's purpose.
Deletion and restriction of processing: We may retain unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, so that we can demonstrate that consent was previously given. Processing is restricted to the potential defence of claims. Individual deletion requests are possible at any time, provided the previous existence of consent is also confirmed. Where we are obliged to honour objections permanently, we reserve the right to retain the email address on a blocklist solely for that purpose.
We record the sign-up process on the basis of our legitimate interests in demonstrating that it was carried out correctly. Where we commission a service provider to send emails, this is based on our legitimate interests in an efficient and secure delivery system.
Content
Information about us, our services, promotions and offers.
- Types of data processed: Master data, such as full name, home address, contact information and customer number; contact data, such as postal and email addresses or telephone numbers; metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved. Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions.
- Special categories of personal data: Health data.
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing, for example by email or post.
- Legal bases: Consent, Article 6(1)(a) GDPR. Legitimate interests, Article 6(1)(f) GDPR.
- Opt-out: You can unsubscribe from our newsletter at any time, withdrawing your consent or objecting to further receipt. An unsubscribe link is provided at the end of each newsletter. Alternatively, you can use one of the contact methods listed above, preferably email.
Further information about processing activities, procedures and services
Measuring open and click rates: Newsletters contain a web beacon, a pixel-sized file retrieved from our server, or our delivery provider's server, when the newsletter is opened. This retrieval initially collects technical information, such as details about your browser and system, your IP address and the time of access. This information is used to improve the newsletter technically, using technical data or information about audiences and their reading behaviour based on access locations, which can be inferred from IP addresses, or access times. The analysis also determines whether and when newsletters are opened and which links are clicked. This information is assigned to individual recipients and stored in their profiles until deletion. These evaluations help us understand reading habits, adapt our content or send different content according to people's interests. The legal basis for measuring open and click rates and storing the results in people's profiles is consent, Article 6(1)(a) GDPR.
Rapidmail: Email delivery and automation services. Service provider: rapidmail GmbH, Augustinerplatz 2, 79098 Freiburg i.Br., Germany. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.rapidmail.de. Privacy policy: https://www.rapidmail.de/datenschutz. Data processing agreement: https://www.rapidmail.de/hilfe/datenschutzvertrag-nach-eu-dsgvo-abschliessen.
Social media profiles
We maintain profiles on social networks and process personal data in that context to communicate with people active there or provide information about us.
Please note that personal data may be processed outside the European Union. This may create risks, for example by making it harder to exercise data subject rights.
Personal data within social networks is also generally processed for market research and advertising. For example, usage profiles may be created from people's behaviour and the interests inferred from it. These profiles may then be used to display advertisements within and outside the networks that are likely to match those interests. Cookies are therefore generally stored on people's computers to record their behaviour and interests. Profiles may also contain data collected independently of the devices used, particularly where people are members of a platform and are signed in.
For a detailed description of the respective processing activities and opt-out options, please refer to the privacy policies and information provided by the operators of each network.
Please also note that access requests and other data subject rights can be exercised most effectively directly with the providers. Only they have access to the relevant personal data and can take appropriate action and provide information directly. If you still need help, you can contact us.
- Types of data processed: Contact data, such as postal and email addresses or telephone numbers; content data, such as text or image messages and posts, and related information such as authorship or creation time. Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions.
- Data subjects: Users, such as website visitors and users of online services.
- Purposes of processing: Communication; feedback, such as collecting feedback through online forms. Public relations.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Further information about processing activities, procedures and services
Instagram: A social network for sharing photos and videos, commenting on and liking posts, sending messages, and following profiles and pages. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), Data Privacy Framework (DPF).
Facebook pages: Profiles on the Facebook social network. Together with Meta Platforms Ireland Limited, we are jointly responsible for collecting, but not subsequently processing, data from visitors to our Facebook page, also known as a "fan page". This data includes information about the types of content people view or interact with and the actions they take, as described under "Things you and others do and provide" in Facebook's privacy policy: https://www.facebook.com/privacy/policy/. It also includes information about the devices they use, such as IP addresses, operating systems, browser types, language settings and cookie data, as described under "Device information" in Facebook's privacy policy: https://www.facebook.com/privacy/policy/. As explained under "How do we use this information?" in Facebook's privacy policy, Facebook also collects and uses information to provide analytics services known as "Page Insights" to page operators, helping them understand how people interact with their pages and associated content. We have entered into a specific agreement with Facebook, the "Page Insights Controller Addendum", https://www.facebook.com/legal/terms/page_controller_addendum, which specifies the security measures Facebook must observe and under which Facebook agrees to fulfil data subjects' rights. For example, people can submit access or deletion requests directly to Facebook. These agreements do not restrict people's rights, in particular their rights of access, deletion, objection and complaint to the competent supervisory authority. Further information is available in "Information about Page Insights Data", https://www.facebook.com/legal/terms/information_about_page_insights_data. Joint responsibility is limited to the collection of data by and transfer of data to Meta Platforms Ireland Limited, a company established in the EU. Meta Platforms Ireland Limited is solely responsible for subsequent processing, including transfers to its parent company, Meta Platforms, Inc., in the USA. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.facebook.com. Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses, https://www.facebook.com/legal/EU_data_transfer_addendum, Data Privacy Framework (DPF), standard contractual clauses, https://www.facebook.com/legal/EU_data_transfer_addendum.
LinkedIn: A social network. Together with LinkedIn Ireland Unlimited Company, we are jointly responsible for collecting, but not subsequently processing, visitor data used to create "Page Insights", the statistics for our LinkedIn profiles. This data includes information about the types of content people view or interact with and the actions they take. It also includes details about their devices, such as IP addresses, operating systems, browser types, language settings and cookie data, and profile information such as job function, country, industry, seniority, company size and employment status. Information about LinkedIn's processing of personal data is available in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.We have entered into a specific agreement with LinkedIn Ireland, the "Page Insights Joint Controller Addendum", https://legal.linkedin.com/pages-joint-controller-addendum, which specifies the security measures LinkedIn must observe and under which LinkedIn agrees to fulfil data subjects' rights. For example, people can submit access or deletion requests directly to LinkedIn. These agreements do not restrict people's rights, in particular their rights of access, deletion, objection and complaint to the competent supervisory authority. Joint responsibility is limited to collecting and transferring data to LinkedIn Ireland Unlimited Company, a company established in the EU. LinkedIn Ireland Unlimited Company is solely responsible for subsequent processing, particularly transfers to its parent company, LinkedIn Corporation, in the USA. Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.linkedin.com. Privacy policy: https://www.linkedin.com/legal/privacy-policy. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses, https://legal.linkedin.com/dpa, Data Privacy Framework (DPF), standard contractual clauses, https://legal.linkedin.com/dpa. Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
YouTube: Social network and video platform. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF), Data Privacy Framework (DPF). Opt-out: https://myadcenter.google.com/personalizationoff.
Privacy
Preamble
This privacy policy explains what types of personal data we process, for which purposes and to what extent. It applies to all processing of personal data that we carry out, both when providing our services and, in particular, on our websites, in mobile applications and on external online profiles, such as our social media profiles. These are collectively referred to below as our "online services".
The terms used are gender-neutral.
Last updated: 28 March 2025
Contents
- Preamble
- Controller
- Overview of processing
- Applicable legal bases
- Security measures
- Transfer of personal data
- International data transfers
- General information on data retention and deletion
- Rights of data subjects
- Provision of our online services and web hosting
- Use of cookies
- Contact and enquiry management
- Web analytics
- Order processing through Shopify
- Communication via messaging services
- Newsletters and electronic notifications
- Social media profiles
Controller
Titanom Solutions GmbHc/o MyMiloGabriele-Münter-Str. 382110 Germering
Authorised representative: Andrija Vuksanovic
Email address: datenschutz@mymilo.de
Legal notice: https://mymilo.de/impressum
Overview of processing
The following overview summarises the types of data processed, the purposes of processing and the people concerned.
Types of data processed
- Master data.
- Contact data.
- Content data.
- Usage data.
- Metadata, communication and procedural data.
- Log data.
Special categories of data
- Health data
Categories of data subjects
- Communication partners
- Users
Purposes of processing
- Communication.
- Security measures.
- Direct marketing.
- Organisational and administrative procedures.
- Feedback.
- Provision of our online services and ease of use.
- Information technology infrastructure.
- Public relations.
Applicable legal bases
Applicable legal bases under the GDPR: The following provides an overview of the GDPR legal bases on which we process personal data. Please note that national data protection rules in your country of residence or our country of establishment may apply in addition to the GDPR. Where more specific legal bases apply in individual cases, we explain them in this privacy policy.
Consent, Article 6(1)(a) GDPR: The data subject has given consent to the processing of their personal data for one or more specific purposes.
Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR: Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at their request before entering into a contract.
Legitimate interests, Article 6(1)(f) GDPR: Processing is necessary for the legitimate interests pursued by the controller or a third party, unless these are overridden by the interests or fundamental rights and freedoms of the data subject that require protection of personal data.
National data protection rules in Germany: In addition to the GDPR, national German data protection rules apply. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains specific provisions on rights of access, erasure and objection, processing of special categories of personal data, processing for other purposes, data transfers and automated individual decision-making, including profiling. The data protection laws of individual German federal states may also apply.
Application of the GDPR and Swiss FADP: This privacy policy provides information under both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For broader geographical applicability and clarity, we use GDPR terminology. In particular, we use the GDPR terms "processing", "personal data", "legitimate interests" and "special categories of data" rather than the corresponding Swiss statutory terms. Where the Swiss FADP applies, the legal meaning of these terms continues to be determined by that Act.
Security measures
In accordance with legal requirements, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. We consider the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons.
These measures include, in particular, safeguarding data confidentiality, integrity and availability by controlling physical and electronic access, access permissions, input, disclosure, availability and separation. We have also established procedures to ensure that data subject rights can be exercised, data can be deleted and threats to data can be addressed. We also consider personal data protection when developing or selecting hardware, software and procedures, following the principles of data protection by design and by default.
Securing online connections with TLS/SSL encryption (HTTPS): We use TLS/SSL encryption to protect data transmitted through our online services against unauthorised access. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are fundamental technologies for secure data transmission on the internet. They encrypt information transmitted between a website or app and a person's browser, or between two servers, protecting it against unauthorised access. TLS, the more advanced and secure successor to SSL, ensures that data transfers meet the highest security standards. A website secured with an SSL/TLS certificate displays HTTPS in its URL, indicating that data is transmitted securely and in encrypted form.
Transfer of personal data
When we process personal data, it may be transferred or disclosed to other bodies, companies, legally independent organisational units or people. Recipients may include service providers commissioned to carry out IT tasks or providers of services and content embedded in a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with recipients to protect your data.
International data transfers
Data processing in third countries: Whenever we transfer data to a third country, meaning outside the European Union (EU) or the European Economic Area (EEA), or this occurs through the use of third-party services or disclosure or transfer to other people, bodies or companies, we always comply with legal requirements. Such transfers can be identified from the provider's postal address or an explicit reference to third-country data transfers in this privacy policy.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), recognised as a safe legal framework by the European Commission's adequacy decision of 10 July 2023. We have also entered into standard contractual clauses with the relevant providers, meeting the European Commission's requirements and establishing contractual obligations to protect your data.
This twofold safeguard provides comprehensive protection for your data: the DPF is the primary layer of protection, while standard contractual clauses provide additional security. If the DPF changes, the standard contractual clauses act as a reliable fallback. This ensures that your data remains adequately protected even in the event of political or legal changes.
For each service provider, we explain whether they are certified under the DPF and whether standard contractual clauses are in place. Further information about the DPF and a list of certified companies are available on the US Department of Commerce website at https://www.dataprivacyframework.gov/ in English.
Transfers to other third countries are subject to appropriate safeguards, in particular standard contractual clauses, explicit consent or transfers required by law. Information about third-country transfers and applicable adequacy decisions is available from the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General information on data retention and deletion
We delete personal data in accordance with legal requirements as soon as the underlying consent is withdrawn or there is no further legal basis for processing. This includes cases where the original processing purpose no longer applies or the data is no longer needed. Exceptions apply where legal obligations or particular interests require longer retention or archiving.
In particular, data that must be retained for commercial or tax law reasons, or whose retention is necessary to pursue legal claims or protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information on data retention and deletion that applies to specific processing activities.
Where several retention or deletion periods apply to a piece of data, the longest period always takes precedence.
If a period does not expressly begin on a specific date and lasts at least one year, it automatically begins at the end of the calendar year in which the triggering event occurred. For ongoing contractual relationships in which data is stored, the triggering event is the date on which termination or another ending of the legal relationship takes effect.
Data retained beyond its original purpose due to legal requirements or other reasons is processed solely for the reasons that justify its retention.
Further information about processing activities, procedures and services
Data retention and deletion: The following general periods apply to retention and archiving under German law.
10 years: Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the work instructions and other organisational documents required to understand them (Section 147(1) no. 1 in conjunction with (3) AO, Section 14b(1) UStG, Section 257(1) no. 1 in conjunction with (4) HGB).
8 years: Accounting records, such as invoices and expense receipts (Section 147(1) nos. 4 and 4a in conjunction with (3), sentence 1 AO, and Section 257(1) no. 4 in conjunction with (4) HGB).
6 years: Other business documents, including commercial or business correspondence received, copies of commercial or business correspondence sent, and other documents relevant to taxation, such as timesheets, cost allocation sheets, costing records and price lists, as well as payroll documents that are not already accounting records, and till rolls (Section 147(1) nos. 2, 3 and 5 in conjunction with (3) AO, Section 257(1) nos. 2 and 3 in conjunction with (4) HGB).
3 years: Data needed to address potential warranty claims, claims for damages or similar contractual claims and rights, and to handle related enquiries, based on previous business experience and customary industry practice, is retained for the regular statutory limitation period of three years (Sections 195 and 199 BGB).
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, particularly those set out in Articles 15 to 21:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing, you have the right to object at any time to processing for that purpose, including profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent at any time.
- Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed, access to that data, further information and a copy of the data in accordance with legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request the completion of personal data concerning you or the correction of inaccurate personal data concerning you.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that personal data concerning you be deleted without undue delay or, alternatively, that its processing be restricted.
- Right to data portability: In accordance with legal requirements, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transfer to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Provision of our online services and web hosting
We process personal data to provide our online services. For this purpose, we process IP addresses, which are necessary to transmit the content and functions of our online services to people's browsers or devices.
- Types of data processed: Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions; metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved; log data, such as logs of sign-ins, data retrieval or access times. Content data, such as text or image messages and posts, and related information such as authorship or creation time.
- Data subjects: Users, such as website visitors and users of online services.
- Purposes of processing: Provision of our online services and ease of use; information technology infrastructure, including the operation and provision of information systems and technical devices such as computers and servers. Security measures.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Further information about processing activities, procedures and services
Collection of access data and log files: Access to our online services is recorded in server log files. These may include the addresses and names of pages and files requested, date and time of access, data volumes transferred, confirmation of successful retrieval, browser type and version, operating system, referrer URL (the previously visited page), and usually IP addresses and the requesting provider. Server log files may be used for security purposes, such as preventing server overload, particularly through abusive attacks known as DDoS attacks, and to monitor server utilisation and stability. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Data deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data that must be retained as evidence is excluded from deletion until the relevant incident has been fully resolved.
Figma Sites: Hosting and software for creating, providing and operating websites, blogs and other online services. Service provider: Figma Inc., 760 Market Street, San Francisco. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://figma.com. Privacy policy: https://www.figma.com/legal/privacy/.
Use of cookies
The term "cookies" refers to functions that store information on people's devices and read information from them. Cookies may serve various purposes, including the functionality, security and convenience of online services, and analysis of visitor traffic. We use cookies in accordance with legal requirements and obtain prior consent where required. Where consent is not required, we rely on our legitimate interests. This applies where storing and reading information is essential to provide content and functions explicitly requested, such as remembering settings or ensuring the functionality and security of our online services. Consent can be withdrawn at any time. We clearly explain its scope and which cookies are used.
Legal bases for data protection: Whether we process personal data using cookies depends on consent. Where consent has been given, it forms the legal basis. Without consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and procedures.
General information on withdrawing consent and opting out: People can withdraw their consent at any time and object to processing in accordance with legal requirements, including through their browser's privacy settings.
- Types of data processed: Metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved.
- Data subjects: Users, such as website visitors and users of online services.
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Contact and enquiry management
When you contact us, for example by post, contact form, email, telephone or social media, or as part of an existing relationship with us, we process the information you provide to the extent necessary to respond to your enquiry and carry out any requested measures.
- Types of data processed: Master data, such as full name, home address, contact information and customer number; contact data, such as postal and email addresses or telephone numbers; content data, such as text or image messages and posts, and related information such as authorship or creation time; usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions. Metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved.
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback, such as collecting feedback through online forms. Provision of our online services and ease of use.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal bases: Legitimate interests, Article 6(1)(f) GDPR. Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR.
Further information about processing activities, procedures and services
Contact form: When you contact us through our contact form, by email or through other channels, we process the personal data you provide to respond to and handle your enquiry. This usually includes your name, contact details and any other information you provide that is necessary to handle the enquiry appropriately. We use this data solely for the stated purpose of contact and communication. Legal bases: Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR; legitimate interests, Article 6(1)(f) GDPR.
Web analytics
We use web analytics to collect statistics about how our website is used. These statistics help us continually improve our website and its content. Privacy is our highest priority, which is why we use the analytics tool Plausible. Unlike other trackers such as Google Analytics, Plausible deliberately avoids cookies and does not store personal data in the browser or on its servers. Only general data is analysed, such as pages viewed, browsers and devices used, and traffic sources. A complete overview of the data collected is available in Plausible's data policy. Provider: OÜ Plausible Insights, Västriku tn 2, Tartu 50403, Estonia.
Order processing through Shopify
We use the Shopify e-commerce platform to process orders. When you want to place an order with us, you are redirected to our Shopify shop. Personal data needed to process the order, such as your name, billing and delivery addresses, email address and payment information, is collected and processed on Shopify's servers.
Processing is based on Article 6(1)(b) GDPR for the performance of the contract and to take pre-contractual steps. An order cannot be placed without providing this data.
Shopify processes some data on our behalf as a processor and some under its own responsibility, to the extent necessary to provide and improve its services.
Transfers of data to third countries, such as Canada or the USA, cannot be ruled out. Shopify ensures an adequate level of data protection through EU standard contractual clauses.
Further information about privacy at Shopify is available at: https://www.shopify.com/de/legal/datenschutz.
Communication via messaging services
We use messaging services for communication. Please read the following information about how these services work, encryption, the use of communication metadata and your options for objecting.
You can also contact us by other means, such as telephone or email. Please use the contact details provided to you or listed in our online services.
Where content is end-to-end encrypted, the contents of your messages and attachments, such as images, are encrypted from one end to the other. This means that message contents cannot be viewed, even by the messaging service providers themselves. You should always use a current version of the messaging service with encryption enabled to ensure that message contents are encrypted.
We also inform communication partners that, although messaging service providers cannot view message contents, they may learn that and when someone communicates with us. Technical information about the person's device and, depending on its settings, location information may also be processed. This is known as metadata.
Information on legal bases: If we ask communication partners for permission before communicating through a messaging service, their consent forms the legal basis for processing their data. Otherwise, where we do not request consent and they contact us on their own initiative, for example, we use messaging services as a contractual measure with our contractual partners and when initiating a contract. For other interested parties and communication partners, we rely on our legitimate interests in fast, efficient communication and meeting their needs for communication through messaging services. We also note that we do not initially transfer contact details provided to us to messaging services without consent.
Withdrawal, objection and deletion: You can withdraw your consent at any time and
- Purposes of processing: Communication.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal bases: Consent, Article 6(1)(a) GDPR. Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR. Legitimate interests, Article 6(1)(f) GDPR.
Newsletters and electronic notifications
We send newsletters, emails and other electronic notifications, collectively referred to as "newsletters", only with recipients' consent or on a legal basis. Where newsletter content is specified during sign-up, that description determines the scope of consent. An email address is normally sufficient to subscribe. To offer a personalised service, we may also ask for a name to address the recipient personally or for further information if necessary for the newsletter's purpose.
Deletion and restriction of processing: We may retain unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, so that we can demonstrate that consent was previously given. Processing is restricted to the potential defence of claims. Individual deletion requests are possible at any time, provided the previous existence of consent is also confirmed. Where we are obliged to honour objections permanently, we reserve the right to retain the email address on a blocklist solely for that purpose.
We record the sign-up process on the basis of our legitimate interests in demonstrating that it was carried out correctly. Where we commission a service provider to send emails, this is based on our legitimate interests in an efficient and secure delivery system.
Content
Information about us, our services, promotions and offers.
- Types of data processed: Master data, such as full name, home address, contact information and customer number; contact data, such as postal and email addresses or telephone numbers; metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved. Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions.
- Special categories of personal data: Health data.
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing, for example by email or post.
- Legal bases: Consent, Article 6(1)(a) GDPR. Legitimate interests, Article 6(1)(f) GDPR.
- Opt-out: You can unsubscribe from our newsletter at any time, withdrawing your consent or objecting to further receipt. An unsubscribe link is provided at the end of each newsletter. Alternatively, you can use one of the contact methods listed above, preferably email.
Further information about processing activities, procedures and services
Measuring open and click rates: Newsletters contain a web beacon, a pixel-sized file retrieved from our server, or our delivery provider's server, when the newsletter is opened. This retrieval initially collects technical information, such as details about your browser and system, your IP address and the time of access. This information is used to improve the newsletter technically, using technical data or information about audiences and their reading behaviour based on access locations, which can be inferred from IP addresses, or access times. The analysis also determines whether and when newsletters are opened and which links are clicked. This information is assigned to individual recipients and stored in their profiles until deletion. These evaluations help us understand reading habits, adapt our content or send different content according to people's interests. The legal basis for measuring open and click rates and storing the results in people's profiles is consent, Article 6(1)(a) GDPR.
Rapidmail: Email delivery and automation services. Service provider: rapidmail GmbH, Augustinerplatz 2, 79098 Freiburg i.Br., Germany. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.rapidmail.de. Privacy policy: https://www.rapidmail.de/datenschutz. Data processing agreement: https://www.rapidmail.de/hilfe/datenschutzvertrag-nach-eu-dsgvo-abschliessen.
Social media profiles
We maintain profiles on social networks and process personal data in that context to communicate with people active there or provide information about us.
Please note that personal data may be processed outside the European Union. This may create risks, for example by making it harder to exercise data subject rights.
Personal data within social networks is also generally processed for market research and advertising. For example, usage profiles may be created from people's behaviour and the interests inferred from it. These profiles may then be used to display advertisements within and outside the networks that are likely to match those interests. Cookies are therefore generally stored on people's computers to record their behaviour and interests. Profiles may also contain data collected independently of the devices used, particularly where people are members of a platform and are signed in.
For a detailed description of the respective processing activities and opt-out options, please refer to the privacy policies and information provided by the operators of each network.
Please also note that access requests and other data subject rights can be exercised most effectively directly with the providers. Only they have access to the relevant personal data and can take appropriate action and provide information directly. If you still need help, you can contact us.
- Types of data processed: Contact data, such as postal and email addresses or telephone numbers; content data, such as text or image messages and posts, and related information such as authorship or creation time. Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions.
- Data subjects: Users, such as website visitors and users of online services.
- Purposes of processing: Communication; feedback, such as collecting feedback through online forms. Public relations.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Further information about processing activities, procedures and services
Instagram: A social network for sharing photos and videos, commenting on and liking posts, sending messages, and following profiles and pages. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), Data Privacy Framework (DPF).
Facebook pages: Profiles on the Facebook social network. Together with Meta Platforms Ireland Limited, we are jointly responsible for collecting, but not subsequently processing, data from visitors to our Facebook page, also known as a "fan page". This data includes information about the types of content people view or interact with and the actions they take, as described under "Things you and others do and provide" in Facebook's privacy policy: https://www.facebook.com/privacy/policy/. It also includes information about the devices they use, such as IP addresses, operating systems, browser types, language settings and cookie data, as described under "Device information" in Facebook's privacy policy: https://www.facebook.com/privacy/policy/. As explained under "How do we use this information?" in Facebook's privacy policy, Facebook also collects and uses information to provide analytics services known as "Page Insights" to page operators, helping them understand how people interact with their pages and associated content. We have entered into a specific agreement with Facebook, the "Page Insights Controller Addendum", https://www.facebook.com/legal/terms/page_controller_addendum, which specifies the security measures Facebook must observe and under which Facebook agrees to fulfil data subjects' rights. For example, people can submit access or deletion requests directly to Facebook. These agreements do not restrict people's rights, in particular their rights of access, deletion, objection and complaint to the competent supervisory authority. Further information is available in "Information about Page Insights Data", https://www.facebook.com/legal/terms/information_about_page_insights_data. Joint responsibility is limited to the collection of data by and transfer of data to Meta Platforms Ireland Limited, a company established in the EU. Meta Platforms Ireland Limited is solely responsible for subsequent processing, including transfers to its parent company, Meta Platforms, Inc., in the USA. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.facebook.com. Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses, https://www.facebook.com/legal/EU_data_transfer_addendum, Data Privacy Framework (DPF), standard contractual clauses, https://www.facebook.com/legal/EU_data_transfer_addendum.
LinkedIn: A social network. Together with LinkedIn Ireland Unlimited Company, we are jointly responsible for collecting, but not subsequently processing, visitor data used to create "Page Insights", the statistics for our LinkedIn profiles. This data includes information about the types of content people view or interact with and the actions they take. It also includes details about their devices, such as IP addresses, operating systems, browser types, language settings and cookie data, and profile information such as job function, country, industry, seniority, company size and employment status. Information about LinkedIn's processing of personal data is available in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.We have entered into a specific agreement with LinkedIn Ireland, the "Page Insights Joint Controller Addendum", https://legal.linkedin.com/pages-joint-controller-addendum, which specifies the security measures LinkedIn must observe and under which LinkedIn agrees to fulfil data subjects' rights. For example, people can submit access or deletion requests directly to LinkedIn. These agreements do not restrict people's rights, in particular their rights of access, deletion, objection and complaint to the competent supervisory authority. Joint responsibility is limited to collecting and transferring data to LinkedIn Ireland Unlimited Company, a company established in the EU. LinkedIn Ireland Unlimited Company is solely responsible for subsequent processing, particularly transfers to its parent company, LinkedIn Corporation, in the USA. Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.linkedin.com. Privacy policy: https://www.linkedin.com/legal/privacy-policy. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses, https://legal.linkedin.com/dpa, Data Privacy Framework (DPF), standard contractual clauses, https://legal.linkedin.com/dpa. Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
YouTube: Social network and video platform. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF), Data Privacy Framework (DPF). Opt-out: https://myadcenter.google.com/personalizationoff.
Privacy
Preamble
This privacy policy explains what types of personal data we process, for which purposes and to what extent. It applies to all processing of personal data that we carry out, both when providing our services and, in particular, on our websites, in mobile applications and on external online profiles, such as our social media profiles. These are collectively referred to below as our "online services".
The terms used are gender-neutral.
Last updated: 28 March 2025
Contents
- Preamble
- Controller
- Overview of processing
- Applicable legal bases
- Security measures
- Transfer of personal data
- International data transfers
- General information on data retention and deletion
- Rights of data subjects
- Provision of our online services and web hosting
- Use of cookies
- Contact and enquiry management
- Web analytics
- Order processing through Shopify
- Communication via messaging services
- Newsletters and electronic notifications
- Social media profiles
Controller
Titanom Solutions GmbHc/o MyMiloGabriele-Münter-Str. 382110 Germering
Authorised representative: Andrija Vuksanovic
Email address: datenschutz@mymilo.de
Legal notice: https://mymilo.de/impressum
Overview of processing
The following overview summarises the types of data processed, the purposes of processing and the people concerned.
Types of data processed
- Master data.
- Contact data.
- Content data.
- Usage data.
- Metadata, communication and procedural data.
- Log data.
Special categories of data
- Health data
Categories of data subjects
- Communication partners
- Users
Purposes of processing
- Communication.
- Security measures.
- Direct marketing.
- Organisational and administrative procedures.
- Feedback.
- Provision of our online services and ease of use.
- Information technology infrastructure.
- Public relations.
Applicable legal bases
Applicable legal bases under the GDPR: The following provides an overview of the GDPR legal bases on which we process personal data. Please note that national data protection rules in your country of residence or our country of establishment may apply in addition to the GDPR. Where more specific legal bases apply in individual cases, we explain them in this privacy policy.
Consent, Article 6(1)(a) GDPR: The data subject has given consent to the processing of their personal data for one or more specific purposes.
Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR: Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at their request before entering into a contract.
Legitimate interests, Article 6(1)(f) GDPR: Processing is necessary for the legitimate interests pursued by the controller or a third party, unless these are overridden by the interests or fundamental rights and freedoms of the data subject that require protection of personal data.
National data protection rules in Germany: In addition to the GDPR, national German data protection rules apply. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains specific provisions on rights of access, erasure and objection, processing of special categories of personal data, processing for other purposes, data transfers and automated individual decision-making, including profiling. The data protection laws of individual German federal states may also apply.
Application of the GDPR and Swiss FADP: This privacy policy provides information under both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For broader geographical applicability and clarity, we use GDPR terminology. In particular, we use the GDPR terms "processing", "personal data", "legitimate interests" and "special categories of data" rather than the corresponding Swiss statutory terms. Where the Swiss FADP applies, the legal meaning of these terms continues to be determined by that Act.
Security measures
In accordance with legal requirements, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. We consider the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons.
These measures include, in particular, safeguarding data confidentiality, integrity and availability by controlling physical and electronic access, access permissions, input, disclosure, availability and separation. We have also established procedures to ensure that data subject rights can be exercised, data can be deleted and threats to data can be addressed. We also consider personal data protection when developing or selecting hardware, software and procedures, following the principles of data protection by design and by default.
Securing online connections with TLS/SSL encryption (HTTPS): We use TLS/SSL encryption to protect data transmitted through our online services against unauthorised access. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are fundamental technologies for secure data transmission on the internet. They encrypt information transmitted between a website or app and a person's browser, or between two servers, protecting it against unauthorised access. TLS, the more advanced and secure successor to SSL, ensures that data transfers meet the highest security standards. A website secured with an SSL/TLS certificate displays HTTPS in its URL, indicating that data is transmitted securely and in encrypted form.
Transfer of personal data
When we process personal data, it may be transferred or disclosed to other bodies, companies, legally independent organisational units or people. Recipients may include service providers commissioned to carry out IT tasks or providers of services and content embedded in a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with recipients to protect your data.
International data transfers
Data processing in third countries: Whenever we transfer data to a third country, meaning outside the European Union (EU) or the European Economic Area (EEA), or this occurs through the use of third-party services or disclosure or transfer to other people, bodies or companies, we always comply with legal requirements. Such transfers can be identified from the provider's postal address or an explicit reference to third-country data transfers in this privacy policy.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), recognised as a safe legal framework by the European Commission's adequacy decision of 10 July 2023. We have also entered into standard contractual clauses with the relevant providers, meeting the European Commission's requirements and establishing contractual obligations to protect your data.
This twofold safeguard provides comprehensive protection for your data: the DPF is the primary layer of protection, while standard contractual clauses provide additional security. If the DPF changes, the standard contractual clauses act as a reliable fallback. This ensures that your data remains adequately protected even in the event of political or legal changes.
For each service provider, we explain whether they are certified under the DPF and whether standard contractual clauses are in place. Further information about the DPF and a list of certified companies are available on the US Department of Commerce website at https://www.dataprivacyframework.gov/ in English.
Transfers to other third countries are subject to appropriate safeguards, in particular standard contractual clauses, explicit consent or transfers required by law. Information about third-country transfers and applicable adequacy decisions is available from the European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General information on data retention and deletion
We delete personal data in accordance with legal requirements as soon as the underlying consent is withdrawn or there is no further legal basis for processing. This includes cases where the original processing purpose no longer applies or the data is no longer needed. Exceptions apply where legal obligations or particular interests require longer retention or archiving.
In particular, data that must be retained for commercial or tax law reasons, or whose retention is necessary to pursue legal claims or protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information on data retention and deletion that applies to specific processing activities.
Where several retention or deletion periods apply to a piece of data, the longest period always takes precedence.
If a period does not expressly begin on a specific date and lasts at least one year, it automatically begins at the end of the calendar year in which the triggering event occurred. For ongoing contractual relationships in which data is stored, the triggering event is the date on which termination or another ending of the legal relationship takes effect.
Data retained beyond its original purpose due to legal requirements or other reasons is processed solely for the reasons that justify its retention.
Further information about processing activities, procedures and services
Data retention and deletion: The following general periods apply to retention and archiving under German law.
10 years: Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the work instructions and other organisational documents required to understand them (Section 147(1) no. 1 in conjunction with (3) AO, Section 14b(1) UStG, Section 257(1) no. 1 in conjunction with (4) HGB).
8 years: Accounting records, such as invoices and expense receipts (Section 147(1) nos. 4 and 4a in conjunction with (3), sentence 1 AO, and Section 257(1) no. 4 in conjunction with (4) HGB).
6 years: Other business documents, including commercial or business correspondence received, copies of commercial or business correspondence sent, and other documents relevant to taxation, such as timesheets, cost allocation sheets, costing records and price lists, as well as payroll documents that are not already accounting records, and till rolls (Section 147(1) nos. 2, 3 and 5 in conjunction with (3) AO, Section 257(1) nos. 2 and 3 in conjunction with (4) HGB).
3 years: Data needed to address potential warranty claims, claims for damages or similar contractual claims and rights, and to handle related enquiries, based on previous business experience and customary industry practice, is retained for the regular statutory limitation period of three years (Sections 195 and 199 BGB).
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, particularly those set out in Articles 15 to 21:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing, you have the right to object at any time to processing for that purpose, including profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent at any time.
- Right of access: You have the right to obtain confirmation as to whether personal data concerning you is being processed, access to that data, further information and a copy of the data in accordance with legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request the completion of personal data concerning you or the correction of inaccurate personal data concerning you.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that personal data concerning you be deleted without undue delay or, alternatively, that its processing be restricted.
- Right to data portability: In accordance with legal requirements, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request its transfer to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Provision of our online services and web hosting
We process personal data to provide our online services. For this purpose, we process IP addresses, which are necessary to transmit the content and functions of our online services to people's browsers or devices.
- Types of data processed: Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions; metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved; log data, such as logs of sign-ins, data retrieval or access times. Content data, such as text or image messages and posts, and related information such as authorship or creation time.
- Data subjects: Users, such as website visitors and users of online services.
- Purposes of processing: Provision of our online services and ease of use; information technology infrastructure, including the operation and provision of information systems and technical devices such as computers and servers. Security measures.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Further information about processing activities, procedures and services
Collection of access data and log files: Access to our online services is recorded in server log files. These may include the addresses and names of pages and files requested, date and time of access, data volumes transferred, confirmation of successful retrieval, browser type and version, operating system, referrer URL (the previously visited page), and usually IP addresses and the requesting provider. Server log files may be used for security purposes, such as preventing server overload, particularly through abusive attacks known as DDoS attacks, and to monitor server utilisation and stability. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Data deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data that must be retained as evidence is excluded from deletion until the relevant incident has been fully resolved.
Figma Sites: Hosting and software for creating, providing and operating websites, blogs and other online services. Service provider: Figma Inc., 760 Market Street, San Francisco. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://figma.com. Privacy policy: https://www.figma.com/legal/privacy/.
Use of cookies
The term "cookies" refers to functions that store information on people's devices and read information from them. Cookies may serve various purposes, including the functionality, security and convenience of online services, and analysis of visitor traffic. We use cookies in accordance with legal requirements and obtain prior consent where required. Where consent is not required, we rely on our legitimate interests. This applies where storing and reading information is essential to provide content and functions explicitly requested, such as remembering settings or ensuring the functionality and security of our online services. Consent can be withdrawn at any time. We clearly explain its scope and which cookies are used.
Legal bases for data protection: Whether we process personal data using cookies depends on consent. Where consent has been given, it forms the legal basis. Without consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and procedures.
General information on withdrawing consent and opting out: People can withdraw their consent at any time and object to processing in accordance with legal requirements, including through their browser's privacy settings.
- Types of data processed: Metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved.
- Data subjects: Users, such as website visitors and users of online services.
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Contact and enquiry management
When you contact us, for example by post, contact form, email, telephone or social media, or as part of an existing relationship with us, we process the information you provide to the extent necessary to respond to your enquiry and carry out any requested measures.
- Types of data processed: Master data, such as full name, home address, contact information and customer number; contact data, such as postal and email addresses or telephone numbers; content data, such as text or image messages and posts, and related information such as authorship or creation time; usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions. Metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved.
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback, such as collecting feedback through online forms. Provision of our online services and ease of use.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal bases: Legitimate interests, Article 6(1)(f) GDPR. Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR.
Further information about processing activities, procedures and services
Contact form: When you contact us through our contact form, by email or through other channels, we process the personal data you provide to respond to and handle your enquiry. This usually includes your name, contact details and any other information you provide that is necessary to handle the enquiry appropriately. We use this data solely for the stated purpose of contact and communication. Legal bases: Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR; legitimate interests, Article 6(1)(f) GDPR.
Web analytics
We use web analytics to collect statistics about how our website is used. These statistics help us continually improve our website and its content. Privacy is our highest priority, which is why we use the analytics tool Plausible. Unlike other trackers such as Google Analytics, Plausible deliberately avoids cookies and does not store personal data in the browser or on its servers. Only general data is analysed, such as pages viewed, browsers and devices used, and traffic sources. A complete overview of the data collected is available in Plausible's data policy. Provider: OÜ Plausible Insights, Västriku tn 2, Tartu 50403, Estonia.
Order processing through Shopify
We use the Shopify e-commerce platform to process orders. When you want to place an order with us, you are redirected to our Shopify shop. Personal data needed to process the order, such as your name, billing and delivery addresses, email address and payment information, is collected and processed on Shopify's servers.
Processing is based on Article 6(1)(b) GDPR for the performance of the contract and to take pre-contractual steps. An order cannot be placed without providing this data.
Shopify processes some data on our behalf as a processor and some under its own responsibility, to the extent necessary to provide and improve its services.
Transfers of data to third countries, such as Canada or the USA, cannot be ruled out. Shopify ensures an adequate level of data protection through EU standard contractual clauses.
Further information about privacy at Shopify is available at: https://www.shopify.com/de/legal/datenschutz.
Communication via messaging services
We use messaging services for communication. Please read the following information about how these services work, encryption, the use of communication metadata and your options for objecting.
You can also contact us by other means, such as telephone or email. Please use the contact details provided to you or listed in our online services.
Where content is end-to-end encrypted, the contents of your messages and attachments, such as images, are encrypted from one end to the other. This means that message contents cannot be viewed, even by the messaging service providers themselves. You should always use a current version of the messaging service with encryption enabled to ensure that message contents are encrypted.
We also inform communication partners that, although messaging service providers cannot view message contents, they may learn that and when someone communicates with us. Technical information about the person's device and, depending on its settings, location information may also be processed. This is known as metadata.
Information on legal bases: If we ask communication partners for permission before communicating through a messaging service, their consent forms the legal basis for processing their data. Otherwise, where we do not request consent and they contact us on their own initiative, for example, we use messaging services as a contractual measure with our contractual partners and when initiating a contract. For other interested parties and communication partners, we rely on our legitimate interests in fast, efficient communication and meeting their needs for communication through messaging services. We also note that we do not initially transfer contact details provided to us to messaging services without consent.
Withdrawal, objection and deletion: You can withdraw your consent at any time and
- Purposes of processing: Communication.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal bases: Consent, Article 6(1)(a) GDPR. Performance of a contract and pre-contractual enquiries, Article 6(1)(b) GDPR. Legitimate interests, Article 6(1)(f) GDPR.
Newsletters and electronic notifications
We send newsletters, emails and other electronic notifications, collectively referred to as "newsletters", only with recipients' consent or on a legal basis. Where newsletter content is specified during sign-up, that description determines the scope of consent. An email address is normally sufficient to subscribe. To offer a personalised service, we may also ask for a name to address the recipient personally or for further information if necessary for the newsletter's purpose.
Deletion and restriction of processing: We may retain unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, so that we can demonstrate that consent was previously given. Processing is restricted to the potential defence of claims. Individual deletion requests are possible at any time, provided the previous existence of consent is also confirmed. Where we are obliged to honour objections permanently, we reserve the right to retain the email address on a blocklist solely for that purpose.
We record the sign-up process on the basis of our legitimate interests in demonstrating that it was carried out correctly. Where we commission a service provider to send emails, this is based on our legitimate interests in an efficient and secure delivery system.
Content
Information about us, our services, promotions and offers.
- Types of data processed: Master data, such as full name, home address, contact information and customer number; contact data, such as postal and email addresses or telephone numbers; metadata, communication and procedural data, such as IP addresses, timestamps, identification numbers and people involved. Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions.
- Special categories of personal data: Health data.
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing, for example by email or post.
- Legal bases: Consent, Article 6(1)(a) GDPR. Legitimate interests, Article 6(1)(f) GDPR.
- Opt-out: You can unsubscribe from our newsletter at any time, withdrawing your consent or objecting to further receipt. An unsubscribe link is provided at the end of each newsletter. Alternatively, you can use one of the contact methods listed above, preferably email.
Further information about processing activities, procedures and services
Measuring open and click rates: Newsletters contain a web beacon, a pixel-sized file retrieved from our server, or our delivery provider's server, when the newsletter is opened. This retrieval initially collects technical information, such as details about your browser and system, your IP address and the time of access. This information is used to improve the newsletter technically, using technical data or information about audiences and their reading behaviour based on access locations, which can be inferred from IP addresses, or access times. The analysis also determines whether and when newsletters are opened and which links are clicked. This information is assigned to individual recipients and stored in their profiles until deletion. These evaluations help us understand reading habits, adapt our content or send different content according to people's interests. The legal basis for measuring open and click rates and storing the results in people's profiles is consent, Article 6(1)(a) GDPR.
Rapidmail: Email delivery and automation services. Service provider: rapidmail GmbH, Augustinerplatz 2, 79098 Freiburg i.Br., Germany. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.rapidmail.de. Privacy policy: https://www.rapidmail.de/datenschutz. Data processing agreement: https://www.rapidmail.de/hilfe/datenschutzvertrag-nach-eu-dsgvo-abschliessen.
Social media profiles
We maintain profiles on social networks and process personal data in that context to communicate with people active there or provide information about us.
Please note that personal data may be processed outside the European Union. This may create risks, for example by making it harder to exercise data subject rights.
Personal data within social networks is also generally processed for market research and advertising. For example, usage profiles may be created from people's behaviour and the interests inferred from it. These profiles may then be used to display advertisements within and outside the networks that are likely to match those interests. Cookies are therefore generally stored on people's computers to record their behaviour and interests. Profiles may also contain data collected independently of the devices used, particularly where people are members of a platform and are signed in.
For a detailed description of the respective processing activities and opt-out options, please refer to the privacy policies and information provided by the operators of each network.
Please also note that access requests and other data subject rights can be exercised most effectively directly with the providers. Only they have access to the relevant personal data and can take appropriate action and provide information directly. If you still need help, you can contact us.
- Types of data processed: Contact data, such as postal and email addresses or telephone numbers; content data, such as text or image messages and posts, and related information such as authorship or creation time. Usage data, such as page views and time spent, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions.
- Data subjects: Users, such as website visitors and users of online services.
- Purposes of processing: Communication; feedback, such as collecting feedback through online forms. Public relations.
- Retention and deletion: Data is deleted as described in the section "General information on data retention and deletion".
- Legal basis: Legitimate interests, Article 6(1)(f) GDPR.
Further information about processing activities, procedures and services
Instagram: A social network for sharing photos and videos, commenting on and liking posts, sending messages, and following profiles and pages. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), Data Privacy Framework (DPF).
Facebook pages: Profiles on the Facebook social network. Together with Meta Platforms Ireland Limited, we are jointly responsible for collecting, but not subsequently processing, data from visitors to our Facebook page, also known as a "fan page". This data includes information about the types of content people view or interact with and the actions they take, as described under "Things you and others do and provide" in Facebook's privacy policy: https://www.facebook.com/privacy/policy/. It also includes information about the devices they use, such as IP addresses, operating systems, browser types, language settings and cookie data, as described under "Device information" in Facebook's privacy policy: https://www.facebook.com/privacy/policy/. As explained under "How do we use this information?" in Facebook's privacy policy, Facebook also collects and uses information to provide analytics services known as "Page Insights" to page operators, helping them understand how people interact with their pages and associated content. We have entered into a specific agreement with Facebook, the "Page Insights Controller Addendum", https://www.facebook.com/legal/terms/page_controller_addendum, which specifies the security measures Facebook must observe and under which Facebook agrees to fulfil data subjects' rights. For example, people can submit access or deletion requests directly to Facebook. These agreements do not restrict people's rights, in particular their rights of access, deletion, objection and complaint to the competent supervisory authority. Further information is available in "Information about Page Insights Data", https://www.facebook.com/legal/terms/information_about_page_insights_data. Joint responsibility is limited to the collection of data by and transfer of data to Meta Platforms Ireland Limited, a company established in the EU. Meta Platforms Ireland Limited is solely responsible for subsequent processing, including transfers to its parent company, Meta Platforms, Inc., in the USA. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.facebook.com. Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses, https://www.facebook.com/legal/EU_data_transfer_addendum, Data Privacy Framework (DPF), standard contractual clauses, https://www.facebook.com/legal/EU_data_transfer_addendum.
LinkedIn: A social network. Together with LinkedIn Ireland Unlimited Company, we are jointly responsible for collecting, but not subsequently processing, visitor data used to create "Page Insights", the statistics for our LinkedIn profiles. This data includes information about the types of content people view or interact with and the actions they take. It also includes details about their devices, such as IP addresses, operating systems, browser types, language settings and cookie data, and profile information such as job function, country, industry, seniority, company size and employment status. Information about LinkedIn's processing of personal data is available in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.We have entered into a specific agreement with LinkedIn Ireland, the "Page Insights Joint Controller Addendum", https://legal.linkedin.com/pages-joint-controller-addendum, which specifies the security measures LinkedIn must observe and under which LinkedIn agrees to fulfil data subjects' rights. For example, people can submit access or deletion requests directly to LinkedIn. These agreements do not restrict people's rights, in particular their rights of access, deletion, objection and complaint to the competent supervisory authority. Joint responsibility is limited to collecting and transferring data to LinkedIn Ireland Unlimited Company, a company established in the EU. LinkedIn Ireland Unlimited Company is solely responsible for subsequent processing, particularly transfers to its parent company, LinkedIn Corporation, in the USA. Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Website: https://www.linkedin.com. Privacy policy: https://www.linkedin.com/legal/privacy-policy. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses, https://legal.linkedin.com/dpa, Data Privacy Framework (DPF), standard contractual clauses, https://legal.linkedin.com/dpa. Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
YouTube: Social network and video platform. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Legitimate interests, Article 6(1)(f) GDPR. Privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF), Data Privacy Framework (DPF). Opt-out: https://myadcenter.google.com/personalizationoff.