Data protection information of maloon GmbH in accordance with Art. 13 GDPR


A)General data protection information 

 

The protection of your personal data is important to us. 

We collect, use and store your personal data in accordance with the provisions of the applicable data protection laws such as the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Personal data is individual information about personal or factual circumstances of an identified or identifiable natural person. Below we inform you about the type, scope and purpose of the collection and use of personal data by the provider.

 

1.Who is responsible for data processing and who can you contact?

Responsible for data processing is: 

maloon GmbH
Schütterlettenweg 4
85053 Ingolstadt
Germany
Phone: 0049 (0)841 493 990-0
Mail: datenschutz@socialhub.io

Our data protection officer is available to answer any confidential questions you may have:

Dr. Stefan Krempl
E-Mail: dsb@socialhub.io 

2.Use of website and software

You can use our website without registering. If you register for a free trial account or as part of a paid account, please refer to the Special Privacy Notice for the SocialHub software under B. For the use of our websites including the SocialHub Blog (blog.socialhub.io) and the SocialHub social media channels, please refer to the Special Privacy Notice under C.

3.Your rights as a data subject

In accordance with Art. 15 GDPR, you have the right to request information free of charge about the personal data stored about you and the purpose of the data processing. In accordance with Art. 16, 17 and 18 GDPR, you also have the right to correct incorrect data and to block and delete your personal data. Under the conditions set out in Art. 20 GDPR, you are also entitled to receive your personal data stored by us in a structured, commonly used and machine-readable format and to transmit this data to another controller without hindrance from the provider. In addition, in accordance with Art. 21 para. 1 GDPR, you are entitled to object to the processing of personal data concerning you on the basis of Art. 6 para. 1 lit. e or f GDPR for reasons arising from your particular situation. We will fulfill the aforementioned rights of the data subject insofar as the legal requirements for the assertion of the rights are met. Please address any requests in this regard to the e-mail address or address given in the legal notice of our website. In addition, you have the right to lodge a complaint with a data protection supervisory authority about the processing of data when using the website.

4.Data protection information for applicants

We welcome applications for the published job advertisements. We will only use the data submitted to fill the advertised positions or comparable vacancies. If we do not consider your application, we will delete the data sent to us after 6 months at the latest. If you agree to be included in the applicant pool, we will keep your documents for 1 year and may write to you about suitable vacancies. You can object to the further processing of your application at any time, but we will then not be able to consider it for filling vacancies.  .  


B)Special data protection information for the SocialHub software (app.socialhub.io)

 

1.Which data is processed and from which sources does it originate?

We process personal data in our software (Art. 4 No. 1 GDPR), which we receive as part of our activities as a provider of cloud software for social media management. The personal data processed by us includes the following personal data Name, address, email addresses and communication content. We only process personal data that we have received from customers or employees of customers on the basis of a registration. In our software, we also process the data of people who contact our customers via the associated social media profiles. This data includes profile information (e.g. user name and user ID, profile picture, etc.) as well as all exchanged communication content, which we process on behalf of our customers on the basis of an order processing contract with them. 

2.For what purpose is the data processed and on what legal basis is the processing based?

Insofar as we act as the controller in the context of data processing, we process data in order to be able to provide our services as a cloud software provider. The data processing is then legitimized in accordance with Art. 6 para. 1 lit. b) GDPR.

3.SSL encryption

Our software uses SSL encryption for security reasons and to protect the transmission of confidential content, such as the requests you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. If SSL encryption is activated, the data you send to us cannot be read by third parties.

4.Server logfiles

We collect and store information about the use of our software in so-called server log files, which your browser automatically transmits to us, on the basis of Art. 6 para. 1 lit. f GDPR. These are:

  • IP-Adress
  • Browsertype/ -version
  • operating system
  • Referrer URL
  • Date and Time of the server request
  • Amount of data transferred

This data is collected exclusively for statistical purposes. This data is not merged with other data sources.

5.Use of cookies

Our software uses so-called “cookies” on the basis of Art. 6 para. 1 lit. b GDPR. A cookie stores the information that a user has logged in with their username and password.

6.Registration

When you register for an account, we store and process the data you have entered in the registration form as specified below. 

  • Your Name
  • Your Company
  • Your Corporate EMail
  • Your Phone Number

We do not pass on any personal data to third parties. Data is only used to communicate with you. The storage and processing of your personal data in this context is based on Art. 6 para. 1, lit. b GDPR.

7.YouTube

We can use the YouTube API of YouTube LLC located at 901 Cherry Ave, San Bruno CA 94066 for the SocialHub software. Via the YouTube API, our customers can integrate comments on their YouTube videos into their SocialHub account if they enter the corresponding account information in their SocialHub. In this case, we access the following information via the YouTube API as our customers' processor Title of the channel in which the commented video is located, title of the commented video, comment text, timestamp. Customers can also add their own comments within their SocialHub account or reply to imported comments. Their comments or replies to comments are then sent to YouTube via the API and displayed under the corresponding video.

8.Facebook

We can also use the Facebook API of Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland for the SocialHub software. Via the Facebook API, our customers can integrate comments and posts on their Facebook pages into their SocialHub account if they enter the corresponding account information in their SocialHub. In this case, we access the following information via the Facebook API as our customers' processor: Title of the page on which the respective post or comment is located, the commented post if applicable, the name and profile picture of the user who made the respective post or comment, and the associated timestamp. Customers can also add their own posts or comments within their SocialHub account or reply to imported posts or comments. Their comments or replies to comments are then sent to Facebook via the API and displayed under the corresponding post or comment.

9.X

We may also use the API of Twitter International Unlimited Company (X Corp.), an Irish company with its registered office at One Cumberland Place, Fenian Street Dublin 2, D02 AX07 Ireland, for the SocialHub software. Via the X-API, our customers can integrate comments and postings on their X channels into their SocialHub account if they enter the corresponding account information in their SocialHub. In this case, we access the following information as our customers' processor via the X-API Name of the account on which the respective post or comment is located, the commented post if applicable, name and profile picture of the user who made the respective post or comment, and the associated timestamp. Customers can also add their own posts or comments within their SocialHub account or reply to imported posts or comments. Their comments or replies to comments are then sent to X via the API and displayed under the corresponding post or comment. 

10.Instagram

We can also use the Instagram API of Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland for the SocialHub software. Via the Instagram API, our customers can integrate comments and posts on their Instagram pages into their SocialHub account if they enter the corresponding account information in their SocialHub. In this case, we access the following information via the Instagram API as our customers' processor Title of the page on which the respective post or comment is located, the commented post if applicable, the name and profile picture of the user who made the respective post or comment, and the associated timestamp. Customers can also add their own posts or comments within their SocialHub account or reply to imported posts or comments. Their comments or replies to comments are then sent to Facebook via the API and displayed under the corresponding post or comment.

11.LinkedIn

We can also use the LinkedIn API of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland for the SocialHub software. Via the LinkedIn API, our customers can integrate comments and postings on their LinkedIn pages into their SocialHub account if they enter the corresponding account information in their SocialHub. In this case, we access the following information via the LinkedIn API as our customers' processor: Title of the page on which the respective post or comment is located, the commented post if applicable, name, ID and profile picture of the user who made the respective post or comment, as well as the associated timestamp. Customers can also add their own posts or comments within their SocialHub account or reply to imported posts or comments. Their comments or replies to comments are then sent to LinkedIn via the API and displayed under the corresponding post or comment.

12.Information on the transfer of data to a third country

We do not transfer any personal data processed by us as the controller within our software to a third country outside the EU/EEA.

13.Is there an automated decision-making process?

We do not use automated decision-making processes in accordance with Art. 22 GDPR to initiate decisions on the establishment or implementation of the business relationship that would have legal consequences for the data subject or similar significant negative effects on the data subject.

14.List of sub-processors

In order to provide the functions of SocialHub, it may be necessary to disclose personal data to third parties. The list of the relevant service providers, including the purpose and place of processing, can be viewed in this document.

C)Special data protection information for the SocialHub website (socialhub.io), the SocialHub blog (blog.socialhub.io) and the SocialHub Social Media Channels

 

Note: This data protection notice fulfills our legal obligation pursuant to Art. 13 GDPR with regard to your use of the SocialHub website (socialhub.io), the SocialHub blog (blog.socialhub.io) and the SocialHub Social Media Channels.

 

1.Which data is processed and from which sources does it originate?

We process personal data (Art. 4 No. 1 GDPR) that we collect on our website or receive. The personal data processed by us includes the following personal data Name, address, email addresses and communication content

2.For what purpose is the data processed and on what legal basis is the processing based?

We process personal data in order to provide our services and to be able to receive and process your inquiries.

a) Processing in accordance with Art. 6 para. 1 a) GDPR with your consent

We process personal data in accordance with Art. 6 para. 1 a) in order to be able to draw your attention to our offers.

b) Processing in accordance with Art. 6 para. 1 c) GDPR for the fulfillment of legal obligations

If our company is subject to a legal obligation which requires the processing of personal data, such as for the fulfillment of tax obligations, the processing is based on Art. 6 para. 1 lit. c GDPR.

c) Processing in accordance with Art. 6 para. 1 d) GDPR

In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were injured in our company and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other third party. The processing would then be based on Art. 6 para. 1 lit. d GDPR.

d) Processing pursuant to Art. 6 para. 1 f) due to overriding legitimate interests 

Ultimately, processing operations could be based on Art. 6 para. 1 lit. f GDPR. Processing operations that are not covered by any of the aforementioned legal bases are based on this legal basis.

3.Legitimate interests in the processing pursued by the controller or a third party

If the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the performance of our business activities and the associated communication with you (Recital 47 GDPR).

4.SSL encryption

Our website uses SSL encryption for security reasons and to protect the transmission of confidential content, such as the requests you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. If SSL encryption is activated, the data you send to us cannot be read by third parties.

5.Server Logfiles

We collect and store information about your visit to our website in so-called server log files, which your browser automatically transmits to us, on the basis of Art. 6 para. 1 lit. f GDPR. These are:

  • Abbreviated IP address
  • Browser type/version
  • Operating system used
  • Referrer URL (the previously visited page)
  • Date and time of the server request
  • Amount of data transferred
  • the requesting provider

This data is collected exclusively for statistical purposes. This data is not merged with other data sources.

6.Use of Cookies

Our website uses so-called “cookies”. A “cookie” is a file that stores certain device-related information on the user's access device (PC, tablet, smartphone, etc.). If our website is accessed by the user's device, the server of our website receives information back from cookies. The server can analyze the information stored in the cookie in various ways. We set technically necessary cookies that are required for the operation of the software on the basis of our legitimate interest in accordance with Art. 6 para. 1 f) GDPR. We only set other cookies, e.g. for GoogleAdWords Conversion Tracking or Google Analytics, with your express consent in accordance with Art. 6 para. 1 a) GDPR. These cookies can be used, for example, to adapt advertisements to the user behavior recorded with the cookie and to collect statistical data on website usage. You can allow or deactivate cookies via the settings in your browser. However, not all functions of our website may then be available.

7.Duration of storage

We process and store personal data only for the period necessary to achieve the purpose of processing or if this is provided for in laws or regulations to which the controller is subject. If the storage purpose no longer applies or if a legally prescribed storage period expires, the personal data is routinely blocked or deleted in accordance with the statutory provisions.

8.GoogleAdWords Conversion Tracking

This website uses the “Google AdWords Conversion Tracking” function of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”) in accordance with Art. 6 para. 1 f) GDPR. Google AdWords Conversion Tracking uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site when they click on a Google ad. The cookies are valid for a maximum of 180 days. Personal data is not stored. As long as the cookie is valid, Google and we as the website operator can recognize that you have clicked on an ad and have reached a specific target page (e.g. order confirmation page, newsletter registration). These cookies cannot be tracked across multiple websites by different AdWords participants. The cookie is used to create conversion statistics in “Google AdWords”. These statistics record the number of users who have clicked on one of our ads. It also counts how many users have reached a target page that has been provided with a “conversion tag”. However, the statistics do not contain any data that can be used to identify you. You can find more information about how Google uses conversion data and Google's privacy policy at: https://support.google.com/adwords/answer/93148?ctx=tltp, https://www.google.de/policies/privacy/

9.Google Analytics

This website uses functions of the web analysis service Google Analytics on the basis of Art. 6 para. 1 lit. f GDPR. The provider is Google Inc. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Google Analytics uses so-called “cookies”. These are text files that are stored on your computer and enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there.

10.IP anonymization

We have activated the IP anonymization function on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de

You can find more information on how Google Analytics handles user data in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de

Objection to data collection

You can prevent the collection of your data by cookies by clicking on the button with “Cookie settings” at the top of this page. The respective cookies can be deactivated in the subsequent menu.

11.Microsoft Clarity

We work with Microsoft Clarity and Microsoft Advertising to use behavioral metrics, heat maps and session replay to understand how you use and interact with our website in order to improve and market our products/services. Website usage data is collected using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. We also use this information for website optimization, fraud/security purposes and advertising. For more information about how Microsoft collects and uses your data, please see Microsoft's privacy policy: https://privacy.microsoft.com/de-DE/privacystatement

12.Contact Forms

We provide a contact form on our website to give you the opportunity to contact us electronically. If you use our contact form, we store and process the data entered in the form. This is the following data: Name, e-mail address, telephone number, subject line, your company name and your message. Alternatively, you can contact us by email. In this case, we store and process the data transmitted by email. We do not pass on any personal data to third parties. Data will only be used to respond to your request. The storage and processing of your personal data in this context is based on Art. 6 para. 1 lit. f GDPR.

13.Facebook

a) Facebook-Plugins

Plugins of the social network Facebook, provider Facebook Inc, 1 Hacker Way, Menlo Park, California 94025, USA, are integrated on our pages. If you are accessing from within the European Union, Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland is the responsible provider.  The processing is based on Art. 6 para. 1 f) GDPR. You can recognize the Facebook plugins by the Facebook logo or the “Like button” (“Like”) on our site. You can find an overview of the Facebook plugins here: https://developers.facebook.com/docs/plugins/. When you visit our pages, a direct connection is established between your browser and the Facebook server via the plugin. Facebook receives the information that you have visited our site with your IP address. If you click on the Facebook “Like” button while you are logged into your Facebook account, you can link the content of our pages to your Facebook profile. This allows Facebook to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Facebook. Further information on this can be found in Facebook's privacy policy at https://de-de.facebook.com/policy.php.

If you do not want Facebook to be able to associate your visit to our pages with your Facebook user account, please log out of your Facebook user account.

 b) Facebook-Pages and Facebook-Insights

In connection with the operation of our Facebook page at https://www.facebook.com/pg/socialhub.io/, we also use the Facebook Insights function of the provider Facebook Inc, 1 Hacker Way, Menlo Park, California 94025, USA. If you access from within the European Union, Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland is the responsible provider.  As part of the operation of our Facebook page, we can communicate with you via the functions provided by Facebook. As long as you have only clicked on “Like” and do not interact with our page beyond this, we do not gain access to your name or IP address or other personal data. Since we receive access to the analysis functions of Facebook Insights, we are nevertheless to be qualified as “jointly responsible for data processing” with Facebook pursuant to Art. 26 GDPR according to the case law of the ECJ. Facebook has set out the conditions for joint data processing in the contract annex here https://www.facebook.com/legal/terms/page_controller_addendum. Through Facebook Insights, we only receive access to statistical evaluations, e.g. about the number of page views, the number of new “likes” and other interactions with our page. However, Facebook may collect the information in connection with your profile and may also gain access to your IP address. Therefore, based on the contractual agreement stipulated by Facebook, Facebook (and not us) is also primarily responsible for this data processing. Insofar as our secondary responsibility is affected, the data processing is based on our legitimate interest in accordance with Art. 6 (1) f GDPR. You can generally address requests based on your rights as a data subject regarding the aforementioned data processing to us or to Facebook. As Facebook is primarily responsible, a direct request to Facebook is preferable. You can do this here:https://www.facebook.com/privacy/explanation. If you address your request to us, we are contractually obliged to forward it to Facebook.”

14.X

Functions of the X service (formerly Twitter) are integrated on our pages. In addition, we also operate our company's own account on X. The processing is based on Art. 6 para. 1 f) GDPR.  These functions are offered by Twitter International Company, One Cumberland Place, Fenian Street Dublin 2, D02 AX07 Ireland. By using X and the “Share” function, the websites you visit are linked to your X account and made known to other users. Data is also transferred to X in the process. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by X. Further information on this can be found in X's privacy policy at https://privacy.x.com/

15.LinkedIn

Our website uses functions of the LinkedIn network. In addition, we also operate our own company page on LinkedIn. The processing is based on Art. 6 para. 1 f) GDPR.  The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Each time one of our pages containing LinkedIn functions is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited our website with your IP address. If you click on the LinkedIn “Recommend” button and are logged into your LinkedIn account, LinkedIn is able to associate your visit to our website with you and your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by LinkedIn.

16.Xing 

Our website uses functions of the XING network. In addition, we also operate our own company page on Xing. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. The processing is based on Art. 6 para. 1 f) GDPR.  Each time one of our pages containing XING functions is accessed, a connection to XING servers is established. To the best of our knowledge, no personal data is stored in the process. In particular, no IP addresses are stored or usage behavior evaluated.

Further information on data protection and the XING share button can be found in XING's privacy policy at: https://www.xing.com/app/share?op=dataprotection

17.YouTube

We use YouTube to communicate with potential customers and make content available there for retrieval. YouTube is operated by Google Ireland Limited Gordon House, Barrow Street, Dublin 4, Ireland. The processing is based on Art. 6 para. 1 f) GDPR.   You can find more information on data protection on YouTube here: https://policies.google.com/privacy?hl=de&gl=de   

18.Pinterest

On our website, we use social plugins from the social network Pinterest, which is operated by Pinterest Inc., 808 Brannan Street San Francisco, CA 94103-490, USA (“Pinterest”). The processing is based on Art. 6 para. 1 f) GDPR.  When you visit a page that contains such a plugin, your browser establishes a direct connection to the Pinterest servers. The plugin transmits log data to the Pinterest server in the USA. This log data may contain your IP address, the address of the websites visited that also contain Pinterest functions, the type and settings of the browser, the date and time of the request, your use of Pinterest and cookies. Further information on the purpose, scope and further processing and use of the data by Pinterest as well as your rights and options for protecting your privacy can be found in Pinterest's privacy policy: https://about.pinterest.com/de/privacy-policy

19.Whatsapp

We use social plugins from Whatsapp. WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The processing is based on Art. 6 para. 1 f) GDPR.  When you visit a page that contains such a plugin, your browser establishes a direct connection to the Whatsapp servers. The plugin transmits log data to the Whatsapp server. This log data may contain your IP address, the address of the websites visited that also contain Pinterest functions, the type and settings of the browser, the date and time of the request, your use of Whatsapp and cookies. Further information on the purpose, scope and further processing and use of the data by Whatsapp as well as your rights and options for protecting your privacy in this regard can be found in Whatsapp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy-contact-information.

20.Information on the transfer of data to a third country

For our website, but not as part of our software, we use cloud services, including from providers based in the USA or other countries outside the EU/EEA, which also process personal data (e.g. names, email addresses and possibly other data) on our behalf. We only transfer personal data to a provider in the USA if this transfer is permitted in accordance with the so-called EU-US privacy framework (https://www.dataprivacyframework.gov/EU-US-Framework) and/or the transfer is legitimized under data protection law by standard data protection clauses (standard contractual clauses). 

21.Is there an automated decision-making process?

We do not use automated decision-making processes in accordance with Art. 22 GDPR to initiate decisions on the establishment or implementation of the business relationship that would have legal consequences for the data subject or similar significant negative effects on the data subject.

22.Documentation of consents given

If you have given us your consent to contact you by email via our website in accordance with Art. 7 GDPR, § 7 UWG, your consent is as follows:

X Simply fill out the form below and we will arrange an appointment with you shortly for a free 30-minute demo. You can of course revoke your consent to the use of your data at any time free of charge (e.g. by email)!”

You can revoke your consent at any time free of charge. A revocation can be made e.g. by email or by post or by using the unsubscribe function in the respective email.