Privacy Policy

Privacy Policy for the teamdecoder Website and the teamdecoder App

April 2023


This privacy policy applies to data processing by mytpt GmbH ("Controller", "we" or "us") when using the teamdecoder app ("App") and when visiting our websites "http://info.mytpt.work; www.mytpt.work; http://webinar1.mytpt.work; http://help.mytpt.work”; "www.teamdecoder.com"; "http://help.teamdecoder.com"; "http://app.teamdecoder.com", "http://webinar.teamdecoder.com"  ("Website").

mytpt offers software that helps analyse and optimize teams in organizations ("Service").

When you use our website or our App, we process your personal data. Personal data is any information relating to an identified or identifiable natural person. When we process personal data, this means that we collect, store, transmit, delete or otherwise use this data. When processing your personal data, we comply with the applicable data protection laws, in particular the General Data Protection Regulation ("GDPR") and the German Federal Data Protection Act ("BDSG").

With the following data protection information, we inform you about the type, scope and purposes of the collection, use and other processing of personal data when using our Website or our App.

If there are changes with regard to the data processing carried out by us, we will adapt our privacy policy. We therefore ask you to regularly inform yourself about the content of our privacy policy. If the change requires an act of cooperation on your part, such as consent, or other individual notification, we will inform you. 

1.             Data Controller

Data Controller is mytpt GmbH;

address: Leipziger Straße 48, 10117 Berlin

email: hello@teamdecoder.com

2.             Data protection officer

For all questions on the subject of data protection or to exercise your rights in accordance with Section 8 of this privacy policy in connection with the use of our Website or our App, you can contact our data protection officer at any time:

Email address: dpo@mytpt.work

3.             Collection and storage of personal data as well as the nature and purpose of their processing and the relevant legal basis

In the following, we inform you about which personal data we process when you use our Website or App and/or make use of our Services. We will also explain the purpose for which we process your data and the legal basis on which we do so. To the extent that the processing of personal data is based on Art. 6 para. 1 sentence 1 lit. f) GDPR, the aforementioned purposes also represent our legitimate interests.

3.1.         Visiting our Website

When you visit our Website for informational purposes, we collect, store and process so-called "log data". We store these temporarily and anonymously as so-called server log files on our web server in order to guarantee the display of our Website and its stability and security.

This applies for example to:

·       Operating system and information on the internet browser used, including installed add-ons;

·       IP address (internet protocol address) of the end device from which the online offer is accessed;

·       Internet address of the website from which the online offer was accessed (so-called origin or referrer URL);

·       Name of the service provider used to access the online offer;

·       Name of the files or information retrieved;

·       Date and time as well as duration of the retrieval.

The processing is carried out on the basis of a balancing of interests in accordance with Art. 6 para. 1 sentence 1 lit. f) GDPR, which always also takes your interests into account.

3.2.         Creating an account and subscribing

If you wish to register for our Service, we will collect the following data from you:

·       Your first and last name

·       Your email address

·       Company name

·       Website

·       Name of your first team for mytpt

If you decide to use a paid Service, we will collect the following additional data from you:

·       Your means of payment and your payment details

We process the aforementioned data in order to fulfil the contract with you for the services offered. The legal basis of the data processing is therefore Art. 6 para. 1 lit. b) of the GDPR.

3.3.         Contact form

When you use our contact form on our Website, we collect the following data from you:

·       Your name;

·       Your email address;

The data will only be used to answer your questions. The data will not be passed on to third parties unless this is expressly stated in this privacy policy. We process the aforementioned data in order to answer the questions or enquiries submitted via the contact form. The legal basis of the data processing is therefore our legitimate interest pursuant to Art. 6 para. 1 lit. f) GDPR.

 

3.4.         Website optimisation, analysis and marketing

(a)        Functional cookies

Our Website uses cookies. Cookies are text files that are stored in the internet browser or by the internet browser on your computer. The cookie contains a string of characters that allows your system to be uniquely identified when you return to the Website.

Most of the cookies we use ("Session Cookies") and the data stored and transmitted in them are automatically deleted at the end of your visit. Other cookies ("Persistent Cookies") remain stored on your end device until you delete them.

You can set your browser in such a way that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. You can delete cookies that have already been saved at any time. If you deactivate cookies, the functionality of the Website may be limited.

Some elements of our Website require that the calling browser can be identified even after a page change. Cookies may be stored for this purpose, which enable us to recognise your browser on your next visit.

If personal data are processed by the cookies, we process them on the basis of a balancing of interests pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR, which always also takes your interests into account.

(b)        Analysis and marketing cookies

When you visit our Website or use our app, cookies are also set that enable an analysis of your use of the Website for reach measurement and advertising purposes ("Analysis Cookies").

We use Analysis Cookies exclusively on the basis of your consent in accordance with § 25 para. 1 TTDSG and Art. 6 para. 1 subpara. 1 lit. a GDPR via our cookie banner. You can also access further information about the cookies we use via our cookie banner. You can also use the cookie banner to revoke your consent to the processing of your data through analysis cookies at any time.

(c)         Google Analytics

To analyse your use of our Website and our App, we use "Google Analytics" a service provided by companies belonging to the Google LLC group, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"), on the basis of a contract on commissioned data processing pursuant to Art. 28 GDPR.

Google Analytics uses cookies. The information generated by cookies about your use of our Website is usually transferred to a Google server in the USA and stored there. The storage of Google Analytics cookies and the use of this analysis tool are based on your express consent in accordance with Art. 6 para. 1 lit. a) GDPR. Your consent can be revoked at any time.

We have activated the IP anonymisation function. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Google will use this information on our behalf for the purpose of evaluating your use of the Website, compiling reports on Website activity and providing other services relating to Website activity and internet usage to us.

You have the option to prevent the storage of cookies by changing the settings of your browser software accordingly. You can also prevent the collection of data generated by the cookie and related to your use of the Website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

For more information about the processing of user data by Google Analytics, please refer to Google's privacy policy at: https://support.google.com/analytics/answer/6004245?hl=en.

4.             Data recipient

In order to process your personal data, we also use the services of external service providers (IT providers, transport companies, payment service providers) in addition to the service providers mentioned in section 3.4. In part, these third parties act as our own data protection controllers, in part they act in the function of a processor on our behalf and in accordance with our instructions pursuant to Art. 28 GDPR.

4.1.         OVH/VPS

We process the data we store on servers operated by OVH Christophstraße 19, 50670 Köln Deutschland ("OVH"). We store data that you enter yourself on our Website or in our App on the servers of OVH (registration data such as email address) as well as data that we automatically collect from you when you visit our Website or use our app (such as your IP address and your location). We have concluded a dataprocessing agreement with OVH in accordance with Art. 28 GDPR. Your personal data is stored exclusively on servers in Frankfurt and is therefore not transferred to data recipients outside the European Union.

For more information on data protection at OVH, please visit https://www.ovhcloud.com/de/personal-data-protection/.

4.2.         Stripe

When you order a paid Service from mytpt, payment is processed through the payment service provider Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, ("Stripe"). We transmit to Stripe the information you provide during the ordering process together with information about your order (name, address, credit card information, invoice amount, currency and transaction number). Your data will only be passed on for the purpose of processing payment with Stripe and only to the extent that it is necessary for this purpose. The data entered is only processed by Stripe and stored by Stripe. I.e. we do not receive any account or credit card related information, but only information with confirmation or negative information of the payment.

The transmission of your data to Stripe is necessary for the processing of the purchase agreement with you and thus takes place on the basis of Art. 6 para. 1 lit. b) GDPR.

For more information on Stripe's privacy policy, please visit: https://stripe.com/de/privacy#translation.

4.3.         Livechat Inc.

The chat feature on our website gives you the opportunity to contact us directly so that we can clarify your questions in real time. To do this, we work with LiveChat, Inc. (One International Place, Suite 1400, Boston, MA 02110-2619). To use the real-time chat, a chat log is automatically created when you use it, which records your anonymized IP address or DNS entry, as well as the information you provided during your conversation with us. We can forward these chat logs to you and delete them upon request. We have concluded a data processing agreement pursuant to Art. 28 GDPR with LiveChat. The processing of your data is based on your express consent in accordance with Art. 6 para. 1 lit. a) GDPR. Your consent can be revoked at any time.

 

For more information on LiveChat data processing, please visit: https://www.livechat.com/legal/privacy-policy/.

5.             Website security

5.1.         We use appropriate technical and organisational security measures to protect stored personal data against manipulation, partial or complete loss and against unauthorised access by third parties. Our security measures are continuously improved in line with technological developments. In particular, we ensure that sensitive personal data is stored exclusively on servers hosted in the EU that are certified in accordance with DIN ISO/IEC 27001 (as amended).

5.2.         We use various service providers to maintain a high level of system security on our platform and to prevent and remedy faults. It is our legitimate interest to continuously monitor and maintain the security and performance of our platform. This is also in the interest of our customers. The legal basis for data processing for this purpose is Art. 6 para. 1 subpara. 1 lit. f GDPR.

6.             Will your data be transferred to third countries or international organisations?

6.1.         In the course of our business relationships, your personal data may be passed on or disclosed to third party companies. These may also be located outside the European Economic Area (EEA), i.e. in third countries. This applies to the use of the following services:

·       Google: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

·       LiveChat Inc: 101 Arch Street, 8th Floor, Boston MA 02110, USA.

6.2.         In the context of the transfer of personal data to a third country, we will regularly ensure through appropriate guarantees, for example by concluding the standard contractual clauses of the European Commission, that a transfer of data to a third country only takes place on the basis of a level of protection that complies with the GDPR.

6.3.         To the extent that, when using the data mentioned in section 6.1, data is transferred to a third country, in particular the USA, for which there is no adequacy decision by the Commission, this is done on the basis of standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR in conjunction with appropriate technical and organisational measures to protect your data.

6.4.         A copy of the standard contractual clauses or further information on the standard contractual clauses used can be downloaded from the respective websites of the service providers we use:

·       Google: https://privacy.google.com/businesses/processorterms/mccs/

·       LiveChat: https://www.livechat.com/legal/data-processing-addendum/  

7.             When do we delete your data?

We delete your data when it is no longer needed for the purposes for which it was originally collected.

Irrespective of this, we store your data processed when you purchase our products or use our Services until the expiry of the statutory or possible contractual warranty rights. After expiry of this period, we retain the information of the contractual relationship required by commercial and tax law for the periods determined by law. For this period, the data will be processed again solely in the event of an audit by the tax authorities.

8.             Your rights

In relation to our processing of your personal data, you have the following rights free of charge:

8.1.         Right to information pursuant to Art. 15 GDPR

You have the right to receive information from us about whether and what data we process about you. This includes information on how long and for what purpose we process the data, the source of the data and the recipients or categories of recipients to whom we pass on the data. We can also provide you with a copy of this data.

8.2.         Right to rectification pursuant to Art. 16 GDPR

You have the right to request that we correct information about you that is not or no longer accurate without delay. In addition, you can request that we complete your incomplete personal data. If required by law, we will also inform third parties of this correction if we have disclosed your personal data to them.

8.3.         Right to erasure pursuant to Art. 17 GDPR

You have the right to request that we delete your personal data without delay in one of the following cases:

·       your data is no longer necessary for the purposes for which it was collected or otherwise processed or the purpose has been achieved;

·       you withdraw your consent and there is no other legal basis for the processing;

·       you object to the processing and there are no overriding legitimate grounds for the processing; where personal data is used for direct marketing, a mere objection by you to the processing is sufficient;

·       your personal data have been processed unlawfully;

·       the erasure of your personal data is necessary for compliance with a legal obligation under European Union law or the law of a member state to which we are subject.

Your right to erasure may be restricted on the basis of statutory provisions. This includes in particular the restrictions listed in Art. 17 GDPR and section 35 BDSG.

8.4.         Right to restriction of processing pursuant to Art. 18 GDPR

You have the right to request us to restrict the processing of your personal data if one of the following reasons applies:

·       you contest the correctness of your personal data for a period of time which allows us to verify the correctness of the personal data;

·       the processing is unlawful and you object to the erasure of the personal data and request instead the restriction of the use of your personal data;

·       we no longer need your personal data for the purposes of processing; however, you need it for the assertion, exercise or defence of legal claims; or

·       You have objected to the processing as long as it has not yet been determined whether our legitimate grounds outweigh yours.

If you have obtained a restriction on processing under the above list, we will inform you before the restriction is lifted.

8.5.         Right to data portability pursuant to Art. 20 GDPR

You have the right to obtain personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format and to transmit this data to others. The exercise of this right does not affect your right to erasure.

8.6.         Right to object pursuant to Art. 21 GDPR

According to Art. 21 GDPR, you have in particular the right to object to the processing of your data at any time for reasons arising from your particular situation, if we base this processing on legitimate interests pursuant to Art. 6 para. 1 lit. (f) GDPR. If you object, we will no longer process your personal data, except in two cases:

·       we can prove compelling legitimate reasons for the processing which override your interests, rights and freedoms, or

·       the processing serves the assertion, exercise or defence of legal claims.

8.7.         In particular, if we process your personal data for direct marketing, you have the right to object at any time to the processing of your data for the purpose of such marketing. If you object to the processing of your data for direct marketing purposes, we will no longer use your personal data for this purpose.

8.8.         Right to revoke consent pursuant to Art. 7 GDPR

You can revoke your consent given to us at any time with effect for the future. This revocation can be made in the form of an informal communication to the above contact addresses. If you revoke your consent, the legality of the data processing carried out up to that point will not be affected.

8.9.         Right to complain to the supervisory authority

If you believe that the processing of your data by us violates applicable data protection law, you have the right to lodge a complaint with one of the competent supervisory authorities. The supervisory authority responsible for us is:

 

Berlin Commissioner for Data Protection and Freedom of Information (“Berliner Beauftragte für Datenschutz und Informationsfreiheit”)

Phone: 030 13889-0

Fax: 030 2155050

email: mailbox@datenschutz-berlin.de

 

In addition, you can complain to the data protection supervisory authority responsible for you at your place of residence. You can find an overview of data protection supervisory authorities at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html

9.             Automated decisions in individual cases including profiling pursuant to Art. 22 GDPR

We do not process your data for automated decisions in individual cases, including profiling within the meaning of Art. 22 GDPR.