Data Privacy

Privacy Policy

(Last updated: 2026-04-01)

 

This privacy policy explains how personal data is processed on the website www.usemodus.io (hereinafter "Website") by SureIn GmbH. "Personal data" means any information relating to an identified or identifiable natural person (data subject), such as name, address, telephone number, date of birth, email address, or IP address. Information that cannot be assigned to a specific person, for example due to anonymization, is not considered personal data.

  1. Controller 

The controller for the processing of personal data on the website within the meaning of the General Data Protection Regulation (GDPR) is: 

SureIn GmbH

Urbanstraße 71

10967 Berlin

info@surein.de

For data protection inquiries or to exercise your data subject rights, please contact dsb@kertos.io

  1. Data Protection Officer

The appointed Data Protection Officer is:

Kertos GmbH

Brienner Straße 41

80333 Munich

Germany

Email: dsb(at)kertos.io  

  1. Data Processing on Our Website

3.1 Provision of the Website 

Purpose of processing:  

We process your data to

  • ensure the reliable operation of the website

  • allow user-friendly access to our website

  • and maintain IT security

Recipient: Framer B.V., Planciusstraat 75, 1013 MR Amsterdam, Netherlands

Processed data: 

  • IP address of the requesting device

  • Method (e.g. GET, POST), date, and time of the request

  • Address of the accessed website and path of the requested file

  • if applicable, previously accessed or requesting website/file (HTTP Referrer)

  • Details about the browser and operating system used

  • Version of the HTTP protocol, HTTP status code, size of the delivered file

  • Request information such as language, content-type, content-encoding, character encodings

Legal basis:   Art. 6 para. 1 lit. f GDPR. The processing of the aforementioned data is necessary to provide the website as well as to ensure a secure and user-friendly operation.

Storage duration: The collected data will be deleted as soon as they are no longer required for the operation of the website, but at the latest after 30 days, unless there is a statutory retention obligation. 

Further information: https://aws.amazon.com/de/privacy/

3.2 Book Demo/Appointment

Purpose: Collection of contact information for planning and conducting product demonstrations or meetings

Recipient: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.

Processed data:

  • Contact information (e.g. name, email address)

  • Company data (e.g. company name, position)

  • Appointment preferences (e.g. preferred date, time)

  • Technical data (e.g. IP address, browser type)

Legal basis: Performance of a contract or pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR for the data processing required for the demo booking, legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR for the processing of additional data to optimize our services and for customer support.

Storage duration: The data will be stored for the duration of the business relationship and beyond in accordance with statutory retention periods.

Third-country transfer: It cannot be ruled out that the data will be forwarded to a HubSpot server in the US and stored there. Google has submitted to the EU-US Data Privacy Framework and is certified accordingly. Therefore, such data transfers are based on the legal basis of Art. 45 GDPR.

Further information: https://legal.hubspot.com/de/privacy-policy

  1. Contact via Email

Purpose: Processing and answering your inquiry. 

Processed data: 

  • Name

  • Email address

  • Content of your message

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in communicating with you). If your inquiry is aimed at the conclusion or execution of a contract, the processing is based on Art. 6 para. 1 lit. b GDPR. 

Storage duration: Your data will only be stored for as long as necessary for the final processing of your inquiry. 

  1. International Data Transfers

Personal data is processed primarily within the EU/EEA. Transfers to so-called "third countries" take place exclusively in compliance with the provisions of the GDPR and if appropriate safeguards are in place. Before a transfer to a service provider in a third country, the level of data protection is verified. A transfer only takes place if sufficient protection mechanisms exist. All service providers must conclude a data processing agreement. For providers outside the EEA, additional measures are required. Pursuant to Art. 44 et seq. GDPR, a transfer is permissible if at least one of the following conditions is met:

  • The European Commission has determined an adequate level of data protection.

  • Standard contractual clauses have been agreed with the recipient.

  • Other appropriate guarantees pursuant to Art. 46 GDPR exist.

  • In certain exceptional cases in accordance with Art. 49 GDPR.

  1. CRM, Sales, and Lead Management

Purpose: Management and maintenance of relations with customers, prospects, and other contractual or business partners (B2B), including lead management, qualification and prioritization of leads, documentation of communication and contract histories, planning and control of sales activities, as well as enrichment of contact and company data from public sources and specialized B2B data providers.

Recipient: HubSpot, Inc., 25 First Street, Cambridge, MA 02141, USA.

Processed data:

  • Surname and first name

  • Business contact details (e.g. email address, phone number, business address)

  • Company-related data (e.g. company name, industry, company size, function/position, department)

  • Data on contractual transactions and inquiries (e.g. offer number, performance interests, history of inquiries and transactions)

  • Communication and interaction data (e.g. appointments, meeting notes, participation in events/webinars, response to emails, retrieval of content)

Legal basis:

  • Performance of a contract and implementation of pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR, insofar as we are in a (pre-)contractual relationship with you/your employer.

  • Furthermore, legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the efficient organization of sales and business relations, targeted B2B communication, and the optimization of our products and services. Insofar as we process personal data for direct marketing purposes, you can object to this processing at any time with effect for the future.

Storage duration: For the duration of the business relationship or as long as there is a legitimate interest in further storage (e.g. tracking of inquiries, maintenance of business relationships); subsequent deletion or anonymization, unless legal retention periods prevent this. Contact data of prospective customers/leads with whom there has been no interaction for a longer period of time are regularly deleted or only processed further in anonymized form for statistical purposes.

Third-country transfer: Data transfer to the USA based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR)

Further information: https://legal.hubspot.com/de/privacy-policy

  1. Recipients

As a matter of principle, the personal data collected by us will only be passed on if:

  • You have given us your express consent in accordance with Art. 6 para. 1 lit. a GDPR,

  • the disclosure is necessary for the protection of our legitimate interests or for the establishment, exercise, or defense of legal claims, and there is no reason to assume that your interests or fundamental rights and freedoms requiring the protection of personal data prevail (Art. 6 para. 1 lit. f GDPR),

  • we are legally obliged to pass them on (Art. 6 para. 1 lit. c GDPR), or

  • it is legally permissible and necessary for the performance of a contract with you or for carrying out pre-contractual measures at your request (Art. 6 para. 1 lit. b GDPR).

Possible recipients are: 

  • Processors: Group companies or external service providers (e.g. in the field of technical infrastructure and processing, maintenance, payment processing) who are carefully selected and monitored. Processors may process the data exclusively in accordance with our instructions.

  • Public bodies: Authorities and state institutions (e.g. tax authorities, public prosecutors, courts) to which we must transmit personal data, for example to fulfill legal obligations or to protect legitimate interests.

  1. Data Security and Protection Measures 

We deploy appropriate technical and organizational measures to ensure the security and confidentiality of your personal data. These measures serve to protect against unauthorized access, manipulation, loss, or misuse. Our security precautions are regularly reviewed and adapted to the state of the art and current industry standards.

Please note that despite extensive protective measures, data transmission on the internet can generally have security gaps. Especially with unencrypted communication (e.g. standard email), there is a risk that data can be read by third parties. We have no influence on the behavior of external parties. We therefore recommend using encryption or other protective measures when transmitting sensitive information electronically in order to minimize potential risks.

8.1 Storage Duration and Deletion/Blocking of Data 

Personal data will be deleted or blocked as soon as the purpose of storage no longer applies. Any further storage is only carried out if required by Union or national regulations to which the controller is subject. The data will also be deleted or blocked as soon as a statutory retention period expires, unless further storage is necessary for the performance of a contractual relationship. 

  1. Data Subject Rights

You have the following rights with respect to your personal data: 

  1. Right of access (Art. 15 GDPR, § 34 BDSG): You can request information as to whether and which personal data is processed by us, for what purpose, to which recipients or categories of recipients the data is transmitted, and how long the data is stored.

  2. Right to rectification (Art. 16 GDPR): You can request the immediate correction of inaccurate or the completion of incomplete personal data.

  3. Right to erasure (Art. 17 GDPR): You can request the deletion of your personal data, especially if it is no longer necessary, you withdraw your consent, or the data was processed unlawfully.

  4. Right to restriction of processing (Art. 18 GDPR): You can request the restriction of the processing of your data, e.g. if the accuracy of the data is contested.

  5. Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format or – as far as technically possible – to request transfer to another controller.

  6. Right to withdraw consent (Art. 7 para. 3 GDPR): You can withdraw consent once given at any time with effect for the future. The lawfulness of the processing up to the withdrawal remains unaffected.

Right to object (Art. 21 GDPR): You can object to the processing of your personal data at any time for reasons arising from your particular situation, in particular in connection with direct marketing or associated profiling.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR):  You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection regulations. 

Revision History

Date 

Version

Reason

2026-04-01

1.0 

First version of the revised privacy policy in the new format.