Privacy notice

This privacy notice explains how techtropy (“we”, “us”, or “our”) processes personal data when you use the Service. We process personal data only as described in this notice and only on a legal basis under Article 6 of the EU General Data Protection Regulation (GDPR).

This is an unofficial English translation provided for convenience only. The is legally binding.

Controller

The controller responsible for processing personal data in connection with the Service is Jan-Philipp Kiel, Gollwitzerstraße 7, 86157 Augsburg, Germany, as interim operator until the incorporation of techtropy. Contact details are listed in the legal notice.

Information we collect

We process the following categories of personal data:

Personal information: You provide personal data such as your email address and name when you create an account, when you submit content to the Service, or when you contact us via forms or email. This data we collect only when you choose to provide it.

Data from public sources: For our market research we process publicly available publications, such as news articles and company websites. In doing so we also process personal data of people who do not use the Service, in particular the name of an article's author and names occurring in the text itself. We use an author's name to attribute a publication and to tell repeated coverage of one story apart. We do not rate or profile individual writers. The legal basis is our legitimate interest in verifiable market research (Article 6(1)(f) GDPR).

Usage data: When you use the Service, our servers automatically process limited technical data in server log files, including your IP address, browser type, pages visited, and the time and date of the request. We use this data solely to deliver the Service reliably, to secure it, and to prevent abuse (Article 6 (1) (f) GDPR).

Cookies: We use only strictly necessary cookies and preference settings you actively choose. We do not use tracking or advertising cookies. For more information, please see our cookie notice.

Data not obtained from you

Where we have not obtained personal data from you but from a publicly available source, we inform you here as required by Article 14 GDPR: the controller is the entity named in the legal notice; the purpose of processing is market research; the legal basis is Article 6(1)(f) GDPR; the categories are the name and the context in which it was published; the source is the publication named in each case. You have the rights set out below, in particular the right of access, to rectification, to erasure, and to object to the processing. Notifying every individual separately would involve disproportionate effort (Article 14(5)(b) GDPR), which is why we provide this information here.

How we use your information

We use your data to provide the Service and your account (Article 6(1)(b) GDPR), to communicate with you, to improve functionality and content, and to detect and prevent abuse and technical problems (Article 6(1)(f) GDPR). Where processing is based on your consent (Article 6(1)(a) GDPR), you may withdraw it at any time with effect for the future. We do not sell your personal data. We make no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR), and we do not rate individual people. The posts people hold at companies, read from those companies' own public pages, are recorded and never rated or scored.

Data retention

We retain personal data only as long as necessary to provide the Service, to comply with legal obligations, and to resolve disputes. When you delete your account, the personal data associated with it is deleted unless a statutory retention obligation requires us to keep it. Personal data not tied to any account, such as the name of an author of an article we have processed, is deleted on request and otherwise once it is no longer needed for its purpose; stored page text is deleted after a set period unless an entry in the evidence record cites it. You may request deletion of your data at any time.

Data transfer

Your data is processed on servers located in Germany, and our service providers are based in the European Union. We do not transfer your personal data to countries outside the EU or the European Economic Area. Should such a transfer ever become necessary, it will take place only under the safeguards of Chapter V of the GDPR, such as an adequacy decision or standard contractual clauses.

Sharing of data

We share personal data only with service providers that process it on our behalf under data processing agreements pursuant to Article 28 GDPR, such as hosting and transactional email delivery, and beyond that only where we are required to by law or to protect our legal rights. We do not share your data for advertising or analytics purposes.

Transactional emails

We use AhaSend B.V. (“AhaSend”), Amsterdam, Netherlands, to deliver transactional emails such as sign-in verification codes and organization invitations. AhaSend processes your email address on our behalf under a data processing agreement pursuant to Article 28 GDPR, solely to deliver these messages. For details, see the AhaSend data processing agreement.

Your rights

Under the GDPR, you have the right to access your personal data (Article 15), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20), and to object to processing based on legitimate interests (Article 21). Where processing is based on consent, you can withdraw it at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). To exercise your rights, contact us at: privacy@techtropy.com.

Security

We take reasonable measures to protect your data, but no method of transmission over the internet is 100% secure.

Our servers are hosted in Frankfurt, Germany, in data centers operated by our partner dataforest GmbH (“dataforest”), Kriftel, Germany, which processes data on our behalf under a data processing agreement pursuant to Article 28 GDPR. These facilities hold industry-standard security and operational audits, including SOC 2 Type II, SOC 1 ISAE 3402 Type II, TÜV Certified Data Center Level 3, ISO 9001:2015, as well as EMAS and ISO 50001 (energy management) certifications. For details on how dataforest processes personal data, see the dataforest privacy policy.

Our Service may contain links to other websites. We are not responsible for their privacy practices.

Children’s privacy

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this privacy notice from time to time. Changes take effect when posted on this page.

Contact

If you have any questions about this privacy notice, contact us at: privacy@techtropy.com.