Privacy Policy
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
1. Information about the controller
The controller responsible for data processing on this website is:
NOTISE Media
Christopher Orndorff
Mozartstraße 13A
92637 Weiden in der Oberpfalz
Germany
Phone: 015120479642
Email: mail@notise.me
2. General notes and mandatory information
General information on the legal basis of data processing
If you have consented to data processing, we process your personal data on the basis of Art. 6 Para. 1 lit. a GDPR or Art. 9 Para. 2 lit. a GDPR, provided that special categories of data according to Art. 9 Para. 1 GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also based on Art. 49 Para. 1 lit. a GDPR. If you have consented to the storage of cookies or to access information in your terminal device (e.g. via device fingerprinting), data processing is additionally based on § 25 Para. 1 TDDDG. Consent can be revoked at any time. If your data is required for the fulfillment of a contract or for the performance of pre-contractual measures, we process your data on the basis of Art. 6 Para. 1 lit. b GDPR. Furthermore, we process your data if it is necessary for the fulfillment of a legal obligation on the basis of Art. 6 Para. 1 lit. c GDPR. Data processing may also be carried out on the basis of our legitimate interest according to Art. 6 Para. 1 lit. f GDPR. Information about the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.
Recipients of personal data
As part of our business activities, we work with various external bodies. In some cases, it is also necessary to transfer personal data to these external bodies. We only pass on personal data to external bodies if this is necessary as part of the fulfillment of a contract, if we are legally obliged to do so (e.g. passing on data to tax authorities), if we have a legitimate interest according to Art. 6 Para. 1 lit. f GDPR in passing it on, or if another legal basis allows the data transfer. When using processors, we only pass on our customers' personal data on the basis of a valid contract for order processing. In the case of joint processing, a contract for joint processing is concluded.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The legality of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
3. Overview & Security Measures
Encryption
For security reasons, this site uses SSL or TLS encryption (TLS 1.3). Confidential data (such as uploads or payment data) cannot be read by third parties.
We store passwords and API keys exclusively as cryptographic hash values (Bcrypt/MD5). It is technically impossible for us to trace the original.
Hosting (Strato)
We host the content of our website with the following provider: Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. When you visit our website, Strato collects various log files including your IP addresses. Strato is used on the basis of Art. 6 Para. 1 lit. f GDPR. We have a legitimate interest in the most reliable presentation of our website possible.
Order Processing: We have concluded a contract for order processing (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that they process the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
4. Data collection on our website
Cookies (Technically necessary only)
We do not use tracking cookies, advertising cookies, or analysis tools (such as Google Analytics). We only use technically necessary session cookies (e.g. PHPSESSID) to store your login status during your visit. These are automatically deleted after closing the browser.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address (anonymized)
The basis for data processing is Art. 6 Para. 1 lit. f GDPR (legitimate interest in the technical stability and security of the systems).
Contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 Para. 1 lit. b GDPR, provided your inquiry is related to the fulfillment of a contract or is necessary for the performance of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6 Para. 1 lit. f GDPR) or on your consent (Art. 6 Para. 1 lit. a GDPR) if this was requested; consent can be revoked at any time.
The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after your inquiry has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.
Inquiry by email, phone, or fax
If you contact us by email, phone, or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 Para. 1 lit. b GDPR, provided your inquiry is related to the fulfillment of a contract or is necessary for the performance of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6 Para. 1 lit. f GDPR) or on your consent (Art. 6 Para. 1 lit. a GDPR) if this was requested; consent can be revoked at any time.
The data you send to us via contact inquiries will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
5. Social Media
Social media elements with Shariff
Social media elements are used on this website (e.g. Facebook, X, Instagram, Pinterest, XING, LinkedIn, Tumblr).
You can usually recognize the social media elements by the respective social media logos. To ensure data protection on this website, we only use these elements together with the so-called "Shariff" solution. This application prevents the social media elements integrated into this website from transferring your personal data to the respective provider the first time you enter the site.
Only when you activate the respective social media element by clicking the associated button is a direct connection to the provider's server established (consent). As soon as you activate the social media element, the respective provider receives the information that you have visited this website with your IP address. If you are logged into your respective social media account (e.g. Facebook) at the same time, the respective provider can assign the visit to this website to your user account.
Activating the plugin represents consent within the meaning of Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. You can revoke this consent at any time with effect for the future. The service is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6 Para. 1 lit. c GDPR.
Elements of the social network Facebook are integrated on this website. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.
An overview of the Facebook social media elements can be found here: https://developers.facebook.com/docs/plugins/?locale=en_US.
When the social media element is active, a direct connection is established between your terminal device and the Facebook server. Facebook receives the information that you have visited this website with your IP address. If you click the Facebook "Like" button while you are logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to assign the visit to this website to your user account. We point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Facebook. Further information on this can be found in Facebook's privacy policy at: https://www.facebook.com/privacy/explanation.
The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website and forwarded to Facebook with the help of the tool described here, we and Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing by Facebook that takes place after forwarding is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook tool and for the legally secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g. requests for information) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://www.facebook.com/help/566994660333381 and
https://www.facebook.com/policy.php.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
X (formerly Twitter)
Functions of the service X (formerly Twitter) are integrated on this website. These functions are offered by the parent company X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. For persons living outside the USA, the data processing is the responsibility of Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.
When the social media element is active, a direct connection is established between your terminal device and the X server. X (formerly Twitter) receives information about your visit to this website. By using X (formerly Twitter) and the "Re-Tweet" or "Repost" function, the websites you visit are linked to your X (formerly Twitter) account and made known to other users. We point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by X (formerly Twitter). Further information on this can be found in the privacy policy of X (formerly Twitter) at: https://x.com/en/privacy.
The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. Consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://gdpr.x.com/en/controller-to-controller-transfers.html.
You can change your privacy settings at X (formerly Twitter) in the account settings at https://x.com/settings/account.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/2710.
Functions of the service Instagram are integrated on this website. These functions are offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your terminal device and the Instagram server. Instagram receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to assign the visit to this website to your user account. We point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Instagram.
The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website and forwarded to Facebook or Instagram with the help of the tool described here, we and Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook or Instagram. The processing by Facebook or Instagram that takes place after forwarding is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook or Instagram tool and for the legally secure implementation of the tool on our website. Facebook is responsible for the data security of Facebook or Instagram products. Data subject rights (e.g. requests for information) regarding the data processed by Facebook or Instagram can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://privacycenter.instagram.com/policy/ and
https://www.facebook.com/help/566994660333381.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
On this website, we use elements of the social network Pinterest, which is operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
When you access a page that contains such an element, your browser establishes a direct connection to Pinterest's servers. This social media element transmits log data to Pinterest's server in the USA. This log data may contain your IP address, the address of the visited websites that also contain Pinterest functions, type and settings of the browser, date and time of the request, your way of using Pinterest, and cookies.
The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG. Consent can be revoked at any time.
Further information on the purpose, scope, and further processing and use of data by Pinterest, as well as your related rights and options for protecting your privacy, can be found in Pinterest's privacy policy: https://policy.pinterest.com/en/privacy-policy.
The company is certified according to the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/4203.
6. Registration, Verification & Uploads
Customer account & master data
When you register, we store the data you enter (company name, address, email, phone number, registration data). This data serves the fulfillment of the contract and the provision of our verification service (Art. 6 Para. 1 lit. b GDPR).
Upload of proof (Audit documents)
To verify your identity, you upload documents (e.g. business registrations, ID copies, invoices). These files are:
- Transmitted encrypted.
- Stored in a protected directory on German servers.
- Viewed exclusively by our audit team for verification.
- Not passed on to unauthorized third parties.
After successful verification or upon deletion of the account, this data is archived or deleted in accordance with statutory retention periods.
Two-Factor Authentication (2FA / TOTP)
To increase security, we offer 2FA via an authenticator app. The generation of the QR code and the validation of the code take place entirely locally on our server. No data is transferred to external service providers.
Community feed and file uploads (NOTISE Partner Portal)
As a partner, you can upload text and media in the community feed. This content is visible to all other verified partners. You can have your content deleted by us at any time.
7. Payment processing (Stripe)
On our website, we offer payment via Stripe. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
When you make a payment, your payment data (e.g. credit card number) is not stored on our servers, but transmitted directly to Stripe. NOTISE only receives a transaction ID and the status of the payment.
Data processing is based on Art. 6 Para. 1 lit. b GDPR (contract processing). Further information can be found in the Stripe Privacy Policy.
8. Integration of YouTube videos (NOTISE Community)
This website embeds videos from the YouTube website. The operator of the website is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in enhanced data protection mode. According to YouTube, videos played in this mode are not used to personalize browsing. No cookies are set; instead, local storage elements are stored in the browser. YouTube is used in the interest of an appealing presentation of our online offers (Art. 6 Para. 1 lit. f GDPR).
9. Live calls and external links
In the "Live Calls" section, we provide links to external video conferencing providers (e.g. Zoom). When you click on "Join Link", you leave our protected portal. From this point on, the privacy policy of the respective provider applies.
10. Deletion & Rights
Account deletion
You can request the deletion of your account in your dashboard at any time. After checking open contractual obligations, your personal data will be removed from our live system. Statutory retention obligations (e.g. for invoices) remain unaffected.
Your other rights
You have the right at any time to receive information free of charge about the origin, recipient, and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this at any time for the future.
For this purpose, as well as for further questions on the subject of data protection, you can contact us at any time using the contact details provided above.