Privacy Policy
Table of Contents
- Controller
- Overview of Processing Activities
- Applicable Legal Bases
- Security Measures
- Disclosure of Personal Data
- General Information on Data Retention and Deletion
- Rights of Data Subjects
- Provision of Online Services and Web Hosting
- Use of Cookies
- Contact and Inquiry Management
- Presence in Social Networks (Social Media)
- Plug-ins and Embedded Content
Controller
Miglena Doncheva
Mühlenstrаße 8a
14167 Berlin
E-Mail-Adresse: info@miglena.eu
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.
Types of Data Processed
- Inventory data
- Contact data
- Content data
- Usage data
- Meta, communication, and procedural data
- Log data
Categories of Data Subjects
- Communication partners
- Users
Purposes of Processing
- Communication
- Security measures
- Reach measurement
- Tracking
- Audience building
- Organizational and administrative procedures
- Feedback
- Marketing
- Provision of our online offer and user-friendliness
- IT infrastructure
- Public relations
Applicable Legal Bases
Legal Bases According to the GDPR:
Below is an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the GDPR, national data protection regulations may apply in your or our country of residence. If more specific legal bases are relevant in individual cases, they are specified in the privacy policy.
- Consent (Art. 6 para. 1 sentence 1 lit. a GDPR): The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Contractual performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR): Processing is necessary for the performance of a contract or for carrying out pre-contractual measures.
- Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR): Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, unless overridden by the interests or fundamental rights and freedoms of the data subject.
National Data Protection Laws in Germany:
In addition to the GDPR, national regulations such as the Federal Data Protection Act (BDSG) apply. This includes specific provisions regarding the right to access, erasure, objection, the processing of special categories of personal data, data processing for other purposes, and data transfer, including automated decision-making and profiling. Federal state data protection laws may also apply.
Notice Regarding the Swiss Data Protection Act (DSG):
This privacy notice is intended to inform you under both the Swiss DSG and the GDPR. Therefore, for clarity, we use GDPR terminology throughout. For example, “processing of personal data,” “legitimate interest,” and “special categories of data” are used instead of the Swiss terms. However, the legal interpretation under Swiss law remains unchanged where applicable.
Security Measures
We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, nature, scope, circumstances, and purposes of processing, and the varying likelihood and severity of the risk to individuals’ rights and freedoms.
These measures include:
- Ensuring the confidentiality, integrity, and availability of data through physical and electronic access controls
- Controls for input, disclosure, availability, and separation of data
- Procedures to enforce data subject rights, data deletion, and responses to data risks
- Data protection is embedded by design and by default, including the careful selection of hardware, software, and processes.
Securing online connections using TLS/SSL encryption technology (HTTPS):
To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information exchanged between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Transfer of Personal Data:
In the course of processing personal data, it may happen that such data is transmitted to other entities, companies, legally independent organizational units, or individuals, or disclosed to them. Recipients of this data may include, for example, service providers tasked with IT responsibilities or providers of services and content integrated into a website. In such cases, we comply with the legal requirements and in particular, conclude appropriate contracts or agreements with the recipients of your data to ensure their protection.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with legal requirements as soon as the underlying consents are revoked or there are no further legal grounds for processing. This applies to cases where the original purpose of processing no longer exists or the data is no longer required. Exceptions to this rule apply if legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax reasons or whose storage is necessary for legal prosecution or the protection of the rights of other natural or legal persons must be archived accordingly.
Our data protection notices contain additional information on the retention and deletion of data that apply specifically to certain processing procedures.
If there are multiple statements on retention periods or deletion deadlines for certain data, the longest period always applies.
If a deadline does not expressly begin on a specific date and is at least one year, it automatically begins at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the date the contract is terminated or otherwise ends.
Data that is no longer needed for the originally intended purpose, but is retained due to legal requirements or other reasons, will be processed exclusively for the purposes justifying their retention.
Further Notes on Processing Operations, Procedures, and Services:
- Retention and Deletion of Data: The following general deadlines apply for retention and archiving under German law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the work instructions and other organizational documents required for their understanding (§ 147 para. 1 no. 1 in conjunction with para. 3 AO, § 14b para. 1 UStG, § 257 para. 1 no. 1 in conjunction with para. 4 HGB).
- 8 years – Accounting documents such as invoices and cost receipts (§ 147 para. 1 no. 4 and 4a in conjunction with para. 3 sentence 1 AO and § 257 para. 1 no. 4 in conjunction with para. 4 HGB).
- 6 years – Other business documents: received commercial or business letters, copies of sent commercial or business letters, other documents relevant for taxation, e.g., time sheets, operating cost sheets, costing documents, price tags, as well as payroll documents, insofar as they are not already accounting documents, and cash register receipts (§ 147 para. 1 no. 2, 3, 5 in conjunction with para. 3 AO, § 257 para. 1 no. 2 and 3 in conjunction with para. 4 HGB).
- 3 years – Data required to consider potential warranty and compensation claims or similar contractual claims and rights, as well as to handle related inquiries, will be stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, particularly arising from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, for reasons arising from your particular situation, to the processing of your personal data that is based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your data for such marketing; this also applies to profiling to the extent it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent given at any time.
- Right of access: You have the right to obtain confirmation as to whether or not your personal data is being processed, and if so, access to the data and additional information and a copy of the data in accordance with legal requirements.
- Right to rectification: You have the right to request the completion or correction of your personal data in accordance with legal requirements.
- Right to erasure and restriction of processing: You have the right to request the immediate erasure of your personal data or alternatively, to request restriction of processing in accordance with legal requirements.
- Right to data portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format and to transmit those data to another controller, in accordance with legal requirements.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR.
Provision of Online Services and Web Hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device.
• Types of data processed: Usage data (e.g., page views and duration of visits, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); metadata, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons); log data (e.g., log files relating to logins or data access or access times); content data (e.g., textual or visual messages and contributions, including related information such as authorship and creation time).
• Data subjects: Users (e.g., website visitors, users of online services).
• Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.); security measures.
• Storage and deletion: Deletion according to the information in the section “General Information on Data Storage and Deletion.”
• Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
• Collection of access data and log files: Access to our online services is logged in the form of so-called “server log files.” These may include the address and name of the accessed web pages and files, date and time of access, data volumes transferred, messages regarding successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), and typically IP addresses and the requesting provider. These log files are used for security purposes (e.g., to prevent server overload, especially in the case of abuse attacks such as DDoS attacks) and to ensure server load and stability.
• Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
• Data deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data required for evidential purposes is excluded from deletion until the respective incident is fully clarified.
- Email transmission and hosting: Our web hosting services also include sending, receiving, and storing emails. For this purpose, the addresses of recipients and senders, and other email transmission details (e.g., involved providers), as well as the content of the respective emails, are processed. The above data may also be processed for SPAM detection. Please note that emails on the Internet are generally not encrypted. While emails are usually encrypted during transmission, they are not encrypted on the servers from which they are sent and received (unless end-to-end encryption is used). We cannot take responsibility for the transmission path of emails between the sender and our server.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
Use of Cookies
“Cookies” refer to functions that store and retrieve information on users’ end devices. Cookies can serve various purposes, including functionality, security, convenience of online services, and analysis of visitor flows. We use cookies in accordance with legal requirements. Where necessary, we obtain user consent in advance. If consent is not required, we rely on our legitimate interests. This applies when storing and retrieving information is essential for providing requested content and functions—such as storing settings or ensuring functionality and security of our online services. Consent can be withdrawn at any time. We clearly inform users about the scope and use of cookies.
Legal basis for data processing with cookies: Whether we process personal data via cookies depends on user consent. If consent is given, it serves as the legal basis. Without consent, we rely on our legitimate interests, as described in this section and in the context of each service or process.
Retention period: We distinguish between the following types of cookies:
• Temporary cookies (also: session cookies): These are deleted at the latest when a user leaves the online service and closes their device (e.g., browser or mobile application).
• Permanent cookies: These remain stored even after the device is closed. For example, login status and preferred content may be retained for future visits. Data collected via cookies may also be used for reach measurement. If we do not explicitly state the type and retention period of cookies (e.g., in the context of consent collection), users should assume that they are permanent and retained for up to two years.
General notes on withdrawal and objection (opt-out): Users may withdraw their consent at any time and object to processing in accordance with legal requirements, including through their browser privacy settings.
• Types of data processed: Metadata, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
• Data subjects: Users (e.g., website visitors, users of online services).
• Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); consent (Art. 6(1)(a) GDPR).
Further notes on processing operations, procedures and services:
• Processing of cookie data based on consent: We use a consent management solution to obtain user consent for the use of cookies or services listed within the consent platform. This procedure manages obtaining, logging, managing, and revoking consents, especially regarding the use of cookies and similar technologies. User consents are stored to avoid repeated requests and to comply with legal requirements. Storage is server-side and/or in a cookie (so-called opt-in cookie) or via similar technologies, enabling user or device identification. Unless otherwise specified, consents are stored for up to two years. A pseudonymous user identifier is created and stored along with the consent timestamp, scope (e.g., cookie categories and/or providers), and device/browser/system information.
• Legal basis: Consent (Art. 6(1)(a) GDPR).
Contact and Inquiry Management
When contacting us (e.g., by mail, contact form, email, telephone, or via social media), or within the context of existing user and business relationships, we process the data of the inquiring persons as necessary to respond to the contact inquiries and any requested actions.
• Types of data processed: Inventory data (e.g., full name, address, contact info, customer number); contact data (e.g., mailing and email addresses or phone numbers); content data (e.g., messages and contributions including metadata like authorship and timestamp); usage data; metadata.
• Data subjects: Communication partners.
• Purposes of processing: Communication; organizational and administrative processes; feedback (e.g., collecting feedback via online form); provision of our online offering and user-friendliness.
• Storage and deletion: Deletion according to the section “General Information on Data Storage and Deletion.”
• Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); contract fulfillment and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Further notes:
• Contact form: When contacting us via the form, email, or other channels, we process the provided personal data solely for handling the request. This generally includes name, contact information, and any further data necessary to respond appropriately. The data is used only for communication purposes.
• Legal basis: Contract fulfillment and pre-contractual inquiries (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Social Media Presence
We maintain online presences within social networks to communicate with active users and share information about us.
Please note: user data may be processed outside the European Union, which may pose risks, such as difficulties in enforcing user rights.
User data is also typically processed for market research and advertising purposes. For instance, usage profiles may be created based on user behavior and interests, which can then be used to display interest-based advertisements both within and outside the platform. Cookies storing this behavior and interest data are usually placed on users’ devices. These profiles may also contain cross-device data if users are logged into the respective platforms.
We refer to the privacy policies of each platform for detailed information about data processing and opt-out options. For data access requests and the exercise of user rights, users are advised to contact the providers directly, as they have access to the user data. We are happy to support if needed.
Types of data processed: Contact data, content data, usage data.
Data subjects: Users (e.g., website visitors, users of online services).
Purposes of processing: Communication; feedback; public relations.
Storage and deletion: Deletion according to “General Information on Data Storage and Deletion.”
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on services used: Instagram: Social network for sharing photos and videos, messaging, and following profiles.
Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR)
Website: https://www.instagram.com
Privacy policy: https://privacycenter.instagram.com/policy/
Data transfer framework: Data Privacy Framework (DPF)
YouTube: Social network and video platform
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR)
Privacy policy: https://policies.google.com/privacy
Data transfer framework: Data Privacy Framework (DPF)
Opt-out: https://myadcenter.google.com/personalizationoff
Plugins and Embedded Content
We integrate functional and content elements into our online services from third-party providers (“third parties”), such as graphics, videos, or maps. Integration requires these third parties to process users’ IP addresses, as content cannot be delivered without it.
Third parties may also use pixel tags (invisible graphics, “web beacons”) for statistical or marketing purposes. These tags may track visitor traffic and store pseudonymized information in cookies on users’ devices, including browser, system, referral sites, visit times, and usage behavior, possibly linked with other data.
Legal basis: If user consent is requested, this serves as the legal basis. Otherwise, data is processed based on our legitimate interests in efficient, user-friendly, and economically reasonable services. See also the section on cookies in this privacy notice.
Types of data processed: Usage data; metadata
Data subjects: Users
Purposes of processing: Service provision; user-friendliness; reach measurement; tracking; audience segmentation; marketing
Storage and deletion: Deletion according to “General Information on Data Storage and Deletion”; cookies may be stored for up to two years
Legal basis: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR)
Further notes on services used:
YouTube Videos: Video content
Provider: Google Ireland Limited
Legal basis: Consent (Art. 6(1)(a) GDPR)Website: https://www.youtube.com
Privacy policy: https://policies.google.com/privacy
Data transfer framework: Data Privacy Framework (DPF)
Opt-out: https://tools.google.com/dlpage/gaoptout?hl=de and https://myadcenter.google.com/personalizationoff
Google Analytics: Web analytics service
Provider: Google Ireland Limited
Legal basis: Consent (Art. 6(1)(a) GDPR)
Data types: Usage data, metadata
Data subjects: Users
Purpose: Reach measurement, web analytics, service optimization
Notes: Data is transferred to Google in the U.S., usually with truncated IP. We use Google Analytics only with user consent. Consent may be revoked at any time. Opt-out: https://tools.google.com/dlpage/gaoptout?hl=de
Privacy policy: https://policies.google.com/privacy
Data transfer framework: Data Privacy Framework (DPF)