Privacy
27.06.2024
Privacy Notice
(Last modified: 01.04.26)
This Privacy Notice explains how personal data is processed on the website www.usemodus.io (hereinafter the „Website“) by SureIn GmbH. „Personal data“ means any information relating to an identified or identifiable natural person (data subject), such as name, address, telephone number, date of birth, email address, or IP address. Information that cannot be attributed to a specific person, for example due to anonymization, is not considered personal data.
Controller
The controller responsible for the processing of personal data on the Website within the meaning of the General Data Protection Regulation (GDPR) is:
SureIn GmbH
Urbanstraße 71
10967 Berlin
info@surein.de
For data protection inquiries or to exercise your data subject rights, please contact dsb@kertos.io
Data Protection Officer
The following has been appointed as Data Protection Officer:
Kertos GmbH
Brienner Straße 41
80333 Munich
Germany
Email: dsb(at)kertos.io
Data Processing on Our Website
3.1 Provision of the Website
Purpose of processing: We process your data in order to
- ensure the reliable operation of the Website
- enable user-friendly access to our Website
- and maintain IT security
Recipient: Framer B.V., Planciusstraat 75, 1013 MR Amsterdam, Netherlands
Processed data:
- IP address of the requesting device
- Method (e.g. GET, POST), date and time of the request
- Address of the website accessed and path of the requested file
- where applicable, the previously accessed or requesting website/file (HTTP referer)
- Information about the browser and operating system used
- HTTP protocol version, HTTP status code, size of the file delivered
- Request information such as language, content type, content encoding, character encodings
Legal basis: Art. 6(1)(f) GDPR. The processing of the aforementioned data is necessary to provide the Website and to ensure secure and user-friendly operation.
Storage period: The collected data is deleted as soon as it is no longer required for the operation of the Website, but no later than after 30 days, unless a statutory retention obligation applies.
Further information: https://aws.amazon.com/de/privacy/
3.2 Book a Demo/Appointment
Purpose: Collection of contact information to schedule and conduct product demonstrations or meetings
Recipient: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
Processed data:
- Contact information (e.g. name, email address)
- Company data (e.g. company name, position)
- Appointment preferences (e.g. desired date, time)
- Technical data (e.g. IP address, browser type)
Legal basis: Performance of a contract or pre-contractual measures pursuant to Art. 6(1)(b) GDPR for the data processing required to book a demo; legitimate interest pursuant to Art. 6(1)(f) GDPR for the processing of additional data to optimize our services and for customer support.
Storage period: The data is stored for the duration of the business relationship and beyond in accordance with the statutory retention periods.
Third-country transfer: It cannot be ruled out that the data will be forwarded to a HubSpot server in the USA and stored there. Google has submitted to the EU-US Data Privacy Framework and is certified accordingly. Such data transfers are therefore based on the legal basis of Art. 45 GDPR.
Further information: https://legal.hubspot.com/de/privacy-policy
Contacting Us by Email
Purpose: Processing and responding to your inquiry.
Processed data:
- Name
- Email address
- Content of your message
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in communicating with you). Insofar as your inquiry is directed at the conclusion or performance of a contract, the processing is carried out on the basis of Art. 6(1)(b) GDPR.
Storage period: Your data is stored only for as long as is necessary to conclusively process your inquiry.
International Data Transfers
Personal data is processed primarily within the EU/EEA. Transfers to so-called „third countries“ take place exclusively in compliance with the requirements of the GDPR and where appropriate safeguards are in place. Before any transfer to a service provider in a third country, the level of data protection is assessed. A transfer only takes place if adequate protection mechanisms exist. All service providers must enter into a data processing agreement. For providers outside the EEA, additional measures are required. Pursuant to Art. 44 et seq. GDPR, a transfer is permissible if at least one of the following conditions is met:
- The European Commission has determined that an adequate level of data protection exists.
- Standard contractual clauses have been agreed with the recipient.
- Other appropriate safeguards pursuant to Art. 46 GDPR exist.
- In certain exceptional cases pursuant to Art. 49 GDPR.
CRM, Sales, and Lead Management
Purpose: Management and maintenance of relationships with customers, prospects, and other contractual or business partners (B2B), including lead management, qualification and prioritization of leads, documentation of communication and contract histories, planning and controlling of sales activities, as well as enrichment of contact and company data from public sources and specialized B2B data providers.
Recipient: HubSpot, Inc., 25 First Street, Cambridge, MA 02141, USA.
Processed data:
- First and last name
- Business contact details (e.g. email address, telephone number, business address)
- Company-related data (e.g. company name, industry, company size, function/position, department)
- Data on contractual matters and inquiries (e.g. quote number, service interests, history of inquiries and matters)
- Communication and interaction data (e.g. appointments, conversation notes, participation in events/webinars, response to emails, retrieval of content)
Legal basis:
Performance of a contract and implementation of pre-contractual measures pursuant to Art. 6(1)(b) GDPR, insofar as we have a (pre-)contractual relationship with you/your employer.
In addition, legitimate interest pursuant to Art. 6(1)(f) GDPR in the efficient organization of sales and business relationships, targeted B2B communication, and the optimization of our products and services. Insofar as we process personal data for direct marketing purposes, you may object to this processing at any time with effect for the future.
Storage period: For the duration of the business relationship or as long as a legitimate interest in continued storage exists (e.g. follow-up of inquiries, maintenance of business relationships); subsequent deletion or anonymization, unless statutory retention periods preclude this. Contact data of prospects/leads with whom no interaction has taken place over an extended period is regularly deleted or further processed only in anonymized form for statistical purposes.
Third-country transfer: Data transfer to the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR)
Further information: https://legal.hubspot.com/de/privacy-policy
Recipients
The personal data we collect is generally disclosed only if:
- you have given us your explicit consent to do so pursuant to Art. 6(1)(a) GDPR,
- disclosure is necessary to safeguard our legitimate interests or to assert, exercise, or defend legal claims, and there is no reason to assume that your overriding legitimate interests or fundamental rights and freedoms requiring the protection of personal data prevail (Art. 6(1)(f) GDPR),
- we are legally obligated to disclose (Art. 6(1)(c) GDPR), or
- this is legally permissible and necessary for the performance of a contract with you or for the implementation of pre-contractual measures at your request (Art. 6(1)(b) GDPR).
Possible recipients are:
- Processors: group companies or external service providers (e.g. in the areas of technical infrastructure and processing, maintenance, payment processing) that are carefully selected and monitored. Processors may process the data exclusively in accordance with our instructions.
- Public bodies: authorities and government institutions (e.g. tax authorities, public prosecutors, courts) to which we are required to transmit personal data, for example to fulfill legal obligations or to protect legitimate interests.
Data Security and Protective Measures
We employ appropriate technical and organizational measures to ensure the security and confidentiality of your personal data. These measures serve to protect against unauthorized access, manipulation, loss, or misuse. Our security precautions are regularly reviewed and adapted to the state of the art as well as current industry standards.
Please note that despite extensive protective measures, data transmission over the internet may generally have security vulnerabilities. In particular, with unencrypted communication (e.g. standard email), there is a risk that data may be read by third parties. We have no influence over the conduct of external parties. We therefore recommend using encryption or other protective measures when electronically transmitting sensitive information in order to minimize potential risks.
8.1 Storage Period and Deletion/Blocking of Data
Personal data is deleted or blocked as soon as the purpose of storage no longer applies. Storage beyond this period only takes place if it is required by Union or national law to which the controller is subject. The data is also deleted or blocked as soon as a statutory retention period expires, unless further storage is necessary for the performance of a contractual relationship.
Data Subject Rights
With regard to your personal data, you have the following rights:
- Right of access (Art. 15 GDPR, § 34 BDSG): You can request information as to whether and which personal data is processed by us, for what purpose, to which recipients or categories of recipients the data is disclosed, and how long the data is stored.
- Right to rectification (Art. 16 GDPR): You can request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.
- Right to erasure (Art. 17 GDPR): You can request the erasure of your personal data, in particular if it is no longer required, you withdraw your consent, or the data has been processed unlawfully.
- Right to restriction of processing (Art. 18 GDPR): You can request the restriction of the processing of your data, e.g. if the accuracy of the data is contested.
- Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, or – where technically feasible – to request its transmission to another controller.
- Right to withdraw consent (Art. 7(3) GDPR): You can withdraw consent that has been given at any time with effect for the future. The lawfulness of the processing up to the withdrawal remains unaffected.
- Right to object (Art. 21 GDPR): You can object at any time to the processing of your personal data on grounds relating to your particular situation, in particular in connection with direct marketing or associated profiling.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection provisions.
Change History
Hotjar
We use Hotjar (Hotjar Ltd., Level 2, St Julian's Business Centre, 3, Elia Zammit Street, St Julian's STJ 1000, Malta) to analyse how our website is used. Hotjar creates, among other things, heatmaps and pseudonymised session recordings (e.g. mouse movements, clicks and scrolling) to help us improve the website. Processing is based solely on your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the cookie settings in the footer. The data is processed by Hotjar as our processor within the EU. Keystrokes and content marked as sensitive are suppressed by Hotjar by default and are not recorded.
For more information, see Hotjar's privacy policy at https://www.hotjar.com/legal/policies/privacy/. You can also opt out of recording at https://www.hotjar.com/policies/do-not-track/.
| Date | Version | Reason |
|---|---|---|
| 01.04.26 | 1.0 | First version of the revised privacy notice in the new format. |