Legal

Privacy Policy

How we process and protect your personal data.

Introduction

With the following privacy policy we would like to explain to you which types of your personal data (hereinafter also referred to in short as “data”) we process, for which purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as the “online offering”).

The terms used are not gender-specific.

Last updated: 29 August 2026

Table of contents

Controller

Minoka GbR
Bergstraße 5
45731 Waltrop, Germany

Email address:

dse@minoka.de

Legal notice

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of data processed

  • Inventory data.
  • Payment data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta and communication data.

Categories of data subjects

  • Prospective customers.
  • Communication partners.
  • Users.
  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and customer support.
  • Contact enquiries and communication.
  • Reach measurement.
  • Office and organisational procedures.
  • Managing and responding to enquiries.
  • Profiles with user-related information.
  • Provision of our online offering and user-friendliness.

Relevant legal bases

Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in an individual case, we will inform you of these in this privacy policy.

  • Consent (Article 6(1)(a) GDPR) – The data subject has given consent to the processing of personal data relating to them for one specific purpose or several specific purposes.
  • Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Article 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Article 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.

In addition to the data protection provisions of the General Data Protection Regulation, national data protection rules apply in Germany. These include in particular the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act, Bundesdatenschutzgesetz, BDSG). The BDSG contains special provisions in particular on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transfer as well as automated decision-making in individual cases including profiling. It also governs data processing for the purposes of the employment relationship (Section 26 BDSG), in particular with regard to the establishment, performance, or termination of employment relationships and to the consent of employees. Furthermore, the data protection acts of the individual federal states may apply.

Security measures

In accordance with the legal requirements and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of the processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, availability, and separation relating to it. Furthermore, we have established procedures that ensure the exercise of data subject rights, the erasure of data, and responses to threats to the data. We also take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.

Shortening of the IP address: Where IP addresses are processed by us or by the service providers and technologies we use, and the processing of a complete IP address is not necessary, the IP address is shortened (also referred to as “IP masking”). In this process the last two digits, or the last part of the IP address after a full stop, are removed or replaced with placeholders. The purpose of shortening the IP address is to prevent, or substantially impede, the identification of a person by means of their IP address.

SSL encryption (https): In order to protect the data you transmit via our online offering, we use SSL encryption. You can recognise such encrypted connections by the prefix https:// in the address bar of your browser.

Transfer of personal data

In the course of our processing of personal data, it may happen that the data is transferred to, or disclosed to, other bodies, companies, legally independent organisational units, or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content that are integrated into a website. In such cases we observe the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.

Data processing in third countries

Where we process data in a third country (that is, outside the European Union (EU) or the European Economic Area (EEA)), or where processing takes place in the context of using third-party services or the disclosure or transfer of data to other persons, bodies, or companies, this only takes place in accordance with the legal requirements.

Subject to express consent or a transfer required by contract or by law, we only process the data, or have it processed, in third countries with a recognised level of data protection, on the basis of a contractual obligation through what are known as standard contractual clauses of the EU Commission, where certifications exist, or where binding corporate rules apply (Articles 44 to 49 GDPR, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en).

Erasure of data

The data processed by us is erased in accordance with the legal requirements as soon as the consents permitting its processing are withdrawn or other permissions cease to apply (for example, where the purpose of processing this data no longer applies or the data is not necessary for that purpose).

Where data is not erased because it is required for other legally permissible purposes, its processing is restricted to those purposes. That is, the data is blocked and not processed for other purposes. This applies, for example, to data that has to be retained for commercial or tax law reasons, or whose storage is necessary for the establishment, exercise, or defence of legal claims, or for the protection of the rights of another natural or legal person.

Our data protection notices may also contain further information on the retention and erasure of data that takes precedence for the respective processing operations.

Use of cookies

Cookies are small text files, or other forms of storage entry, that store information on end devices and read information from end devices. For example, to store the login status in a user account, the contents of a shopping basket in an online shop, the content accessed, or the functions used within an online offering. Cookies can also be used for various purposes, for example for the functionality, security, and convenience of online offerings as well as for producing analyses of visitor flows.

Notes on consent: We use cookies in accordance with the legal requirements. We therefore obtain prior consent from users, except where this is not required by law. Consent is in particular not necessary where the storage and reading of the information, including cookies, is strictly necessary in order to provide users with a telemedia service (that is, our online offering) that they have expressly requested. The revocable consent is clearly communicated to users and contains the information on the respective use of cookies.

Notes on the legal bases under data protection law: Which legal basis under data protection law we rely on when processing users’ personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the consent given. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (for example, in the commercially efficient operation of our online offering and improving its usability) or, where this takes place in the performance of our contractual obligations, where the use of cookies is necessary in order to fulfil our contractual obligations. We explain the purposes for which we process cookies in the course of this privacy policy or as part of our consent and processing procedures.

Retention period: With regard to the retention period, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are erased at the latest once a user has left an online offering and closed their end device (for example, the browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the end device has been closed. This makes it possible, for example, to store the login status or to display preferred content directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Where we do not provide users with explicit information on the type and retention period of cookies (for example, when obtaining consent), users should assume that cookies are permanent and that the retention period may be up to two years.

General notes on withdrawal and objection (opt-out): Users may withdraw the consents they have given at any time and may also object to processing in accordance with the legal requirements in Article 21 GDPR (further information on objection is provided in the course of this privacy policy). Users may also declare their objection by means of their browser settings.

Further notes on processing operations, procedures, and services:

  • Processing of cookie data on the basis of consent: We use a cookie consent management procedure, within which users’ consents to the use of cookies, or to the processing operations and providers named within the cookie consent management procedure, are obtained and can be managed and withdrawn by users. In this process the declaration of consent is stored so that the request does not have to be repeated and so that consent can be demonstrated in accordance with the legal obligation. Storage may take place on the server side and/or in a cookie (what is known as an opt-in cookie, or by means of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following applies: the consent may be stored for up to two years. A pseudonymous user identifier is created and stored together with the time of consent, information on the scope of the consent (for example, which categories of cookies and/or service providers), and the browser, system, and end device used.
  • BorlabsCookie: Cookie consent management; Service provider: Borlabs; Website: https://borlabs.io/borlabs-cookie/; Further information: An individual user ID, the language, and the types of consent together with the time they were given are stored on the server side and in a cookie on the user’s device.

Commercial services

We process the data of our contractual and business partners, for example customers and prospective customers (collectively referred to as “contractual partners”), in the context of contractual and comparable legal relationships as well as associated measures, and in the context of communication with contractual partners (or prior to entering into a contract), for example in order to answer enquiries.

We process this data in order to fulfil our contractual obligations. These include, in particular, the obligations to provide the agreed services, any obligations to provide updates, and remedies in the event of warranty claims and other performance issues. In addition, we process the data to safeguard our rights and for the purposes of the administrative tasks associated with these obligations as well as the organisation of the business. Furthermore, we process the data on the basis of our legitimate interests in proper and commercially sound management and in security measures to protect our contractual partners and our business operations from misuse and from risks to their data, secrets, information, and rights (for example, when involving telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisers, payment service providers, or tax authorities). Within the framework of applicable law, we pass on the data of contractual partners to third parties only to the extent necessary for the aforementioned purposes or to fulfil legal obligations. Contractual partners are informed about further forms of processing, for example for marketing purposes, within this privacy policy.

We inform contractual partners which data is required for the aforementioned purposes before or in the course of data collection, for example in online forms, by means of special marking (for example, colours) or symbols (for example, asterisks or similar), or in person.

We erase the data after the expiry of statutory warranty and comparable obligations, that is, as a rule after four years, unless the data is stored in a customer account, for example for as long as it has to be retained for legal archiving reasons (for example, for tax purposes, as a rule ten years). Data disclosed to us by the contractual partner in the course of an engagement is erased in accordance with the requirements of that engagement, as a rule at the end of the engagement.

Where we use third-party providers or platforms to provide our services, the terms and conditions and privacy notices of the respective third-party providers or platforms apply in the relationship between users and those providers.

Agency services We process our customers’ data in the context of our contractual services, which may include, for example, conceptual and strategic consulting, campaign planning, software and design development, consulting, or maintenance, implementation of campaigns and processes, handling, server administration, data analysis and consulting services, and training services.

  • Types of data processed: Inventory data (for example, names, addresses); payment data (for example, bank details, invoices, payment history); contact data (for example, email addresses, telephone numbers); contract data (for example, subject matter of the contract, term, customer category).
  • Data subjects: Prospective customers; business and contractual partners.
  • Purposes of processing: Provision of contractual services and customer support; contact enquiries and communication; office and organisational procedures; managing and responding to enquiries.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legal obligation (Article 6(1)(c) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Provision of the online offering and web hosting

In order to provide our online offering securely and efficiently, we use the services of one or more web hosting providers, from whose servers (or servers managed by them) the online offering can be accessed. For these purposes we may use infrastructure and platform services, computing capacity, storage space, and database services as well as security services and technical maintenance services.

The data processed in the course of providing the hosting service may include all information relating to the users of our online offering that arises in the course of use and communication. This regularly includes the IP address, which is necessary in order to deliver the content of online offerings to browsers, and all entries made within our online offering or on websites.

  • Types of data processed: Content data (for example, entries in online forms); usage data (for example, websites visited, interest in content, access times); meta and communication data (for example, device information, IP addresses).
  • Data subjects: Users (for example, website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and user-friendliness.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Further notes on processing operations, procedures, and services:

  • Collection of access data and log files: We ourselves (or our web hosting provider) collect data on every access to the server (what are known as server log files). The server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), and as a rule IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, for example to avoid overloading the servers (in particular in the case of abusive attacks, known as DDoS attacks), and on the other hand to ensure the utilisation and stability of the servers; Erasure of data: Log file information is stored for a maximum period of 30 days and then erased or anonymised. Data whose further retention is necessary for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.
  • ALL-INKL: Services in the field of providing information technology infrastructure and related services (for example, storage space and/or computing capacity); Service provider: ALL-INKL.COM – Neue Medien Münnich, proprietor: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany; Website: https://all-inkl.com/; Privacy policy: https://all-inkl.com/datenschutzinformationen/; Data processing agreement: concluded with the provider.

Contact and enquiry management

When you contact us (for example, via a contact form, email, telephone, or social media) as well as in the context of existing user and business relationships, the information provided by the enquiring persons is processed to the extent necessary to respond to the contact enquiries and any measures requested.

Responding to contact enquiries and managing contact and enquiry data in the context of contractual or pre-contractual relationships takes place in order to fulfil our contractual obligations or to respond to (pre-)contractual enquiries, and otherwise on the basis of our legitimate interests in responding to enquiries and maintaining user and business relationships.

  • Types of data processed: Inventory data (for example, names, addresses); contact data (for example, email addresses, telephone numbers); content data (for example, entries in online forms).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact enquiries and communication; provision of contractual services and customer support.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR); legal obligation (Article 6(1)(c) GDPR).

Further notes on processing operations, procedures, and services:

  • Contact form: When users contact us via our contact form, by email, or through other means of communication, we process the data communicated to us in this context in order to deal with the matter raised. For this purpose we process personal data in the context of pre-contractual and contractual business relationships to the extent necessary for their performance, and otherwise on the basis of our legitimate interests as well as the interests of the communication partners in having their matters answered, and of our statutory retention obligations.

Web analytics, monitoring, and optimisation

Web analytics (also referred to as “reach measurement”) serves to evaluate the visitor flows of our online offering and may include behaviour, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis we can, for example, identify at which times our online offering or its functions or content are used most frequently, or invite repeat use. We can likewise establish which areas require optimisation.

In addition to web analytics, we may also use testing procedures, for example in order to test and optimise different versions of our online offering or its components.

Unless stated otherwise below, profiles may be created for these purposes, that is, data combined into a single usage process, and information may be stored in a browser or an end device and read from it. The information collected includes in particular the web pages visited and the elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times. Where users have declared their consent to the collection of their location data to us or to the providers of the services we use, location data may also be processed.

The IP addresses of users are also stored. However, we use an IP masking procedure (that is, pseudonymisation by shortening the IP address) to protect users. In general, no plain data of users (such as email addresses or names) is stored in the context of web analytics, A/B testing, and optimisation; pseudonyms are stored instead. That is, neither we nor the providers of the software used know the actual identity of users, but only the information stored in their profiles for the purposes of the respective procedures.

Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for processing data is that consent. Otherwise, users’ data is processed on the basis of our legitimate interests (that is, an interest in efficient, economical, and recipient-friendly services). In this context we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (for example, websites visited, interest in content, access times); meta and communication data (for example, device information, IP addresses).
  • Data subjects: Users (for example, website visitors, users of online services).
  • Purposes of processing: Reach measurement (for example, access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Article 6(1)(a) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Further notes on processing operations, procedures, and services:

  • Matomo (without cookies): Matomo is privacy-friendly web analytics software that is used without cookies and in which returning users are recognised by means of what is known as a “digital fingerprint”, which is stored anonymously and changed every 24 hours. With the “digital fingerprint”, user movements within our online offering are recorded using pseudonymised IP addresses in combination with the user’s browser settings in such a way that conclusions about the identity of individual users are not possible. The data collected through the use of Matomo is processed on our own server. IP addresses are truncated and no user ID is collected. To evaluate the statistics, we retrieve aggregated reports, such as page views per address, via Claude Code, a service of Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, United States. Individual visits and IP addresses are not transmitted. The use of this data for training AI models is disabled in our account. Data is not passed on to third parties for their own purposes, in particular not for advertising purposes; Website: https://matomo.org/.

Amendment and updating of this privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of participation on your part (for example, consent) or other individual notification.

Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time, and we ask you to check the details before making contact.

Rights of data subjects

As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is connected with such direct marketing.
  • Right to withdraw consent: You have the right to withdraw consent you have given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to that data as well as further information and a copy of the data in accordance with the legal requirements.
  • Right to rectification: In accordance with the legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
  • Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without undue delay, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
  • Right to data portability: You have the right to receive data concerning you which you have provided to us, in accordance with the legal requirements, in a structured, commonly used, and machine-readable format, or to request its transmission to another controller.
  • Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the requirements of the GDPR.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and are defined above all in Article 4 GDPR. The statutory definitions are binding. The following explanations, by contrast, are intended primarily to aid understanding. The terms are sorted alphabetically.

  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (for example, a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
  • Profiles with user-related information: The processing of “profiles with user-related information”, or “profiles” for short, covers any form of automated processing of personal data consisting of the use of such personal data to analyse, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information concerning demographics, behaviour, and interests, such as interaction with websites and their content), for example interest in particular content or products, click behaviour on a website, or location. Cookies and web beacons are frequently used for profiling purposes.
  • Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and may cover the behaviour or interests of visitors in certain information, such as the content of web pages. With the help of reach analysis, website owners can, for example, identify at which times visitors come to their website and which content they are interested in. This allows them, for example, to adapt the content of the website more closely to the needs of their visitors. Pseudonymous cookies and web beacons are frequently used for reach analysis purposes in order to recognise returning visitors and thus obtain more precise analyses of the use of an online offering.
  • Controller: “Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: “Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, evaluation, storage, transfer, or erasure.