Privacy Policy

The protection of your personal data is very important to mindberry Consulting GmbH, Renngasse 4/5/4, 1010 Vienna ("mindberry", "we", "us"). Therefore, we process your data exclusively on the basis of the legal provisions, in particular on the basis of the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act (TKG 2003). In this privacy statement, we will inform you about the key aspects of data processing through our website www.mindberry.com ("website") and the use of our related services.

1. What data do we collect from you, for what purposes and on what legal basis?

Contacting us

If you contact us by means of a form on the website or by email, the personal data provided by you (name, email address, company and message content) will be collected and processed. These data are processed, stored and used exclusively for the purpose of answering your request or for establishing contact with you and the associated technical processing or administration. This data processing is therefore necessary to fulfill our (pre-) contractual interests.

Sign up for our newsletter - use of your data for direct mail

You have the opportunity to subscribe to our newsletter via our website.
When you sign up for our email newsletter, we will periodically send you updates and marketing information, such as case studies, tips and user insights related to Conversion Rate Optimization and user research.
On the basis of your consent, we therefore process your personal data voluntarily provided during the newsletter registration (your email address, if applicable your name). The data collected by us when registering for the newsletter will be used exclusively for promotional purposes by way of the newsletter for the above mentioned purposes.
To register for our newsletter, we use a so-called double opt-in procedure. This means that we will only send you an email newsletter if you have explicitly confirmed to us that you agree to the sending of the newsletter. We will then send you a confirmation email asking you to confirm by clicking on a link that you wish to receive newsletters in the future.
The newsletters contain a so-called "web beacon", a pixel-sized file that is retrieved from the MailChimp server when the newsletter is opened. In the context of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and time of retrieval is collected. This information is used to improve the technical performance of services based on the technical data or the reading behavior of the newsletter audience based on their locations (which can be determined using the IP address) or access times.
You may change your mind at any time and revoke your consent to receive the newsletter with effect for the future. For example, you may unsubscribe from the newsletter by clicking on the unsubscribe link found in the footer of any email you receive from us, or by contacting us at contact@mindberry.com. After the cancellation, we will immediately delete your data in connection with the newsletter dispatch.

We use MailChimp, a marketing automation platform from The Rocket Science Group LLC as our service provider (processor) to manage our newsletter, including the subscription process to it.
We have concluded an appropriate contract data processing contract as well as EU standard data protection clauses with MailChimp (Customer EU Data Processing Addendum).
There are cases where newsletter recipients are directed to the MailChimp website. For example, the newsletters contain a link that allows recipients to retrieve newsletters online. Furthermore, newsletter subscribers can update their data, e.g. correct their email address at a later point. The Privacy Policy of MailChimp is only available on their page. In this context, we point out that on the websites of MailChimp cookies are used and thus possibly personal data processed by MailChimp, their partners and service providers used (for example, Google Analytics). We have no influence on this data collection.
The email addresses of our newsletter recipients, as well as other data of newsletter recipients described in the context of this Privacy Policy, are stored on the servers of MailChimp in the USA. MailChimp uses this information to send and analyze the newsletters on our behalf. Furthermore, MailChimp may, according to its own information, use this data to optimize or improve its own services, e.g. for the technical optimization of the dispatch and the presentation of the newsletters or for economic purposes, in order to determine which countries the recipients come from. However, MailChimp does not use the data of our newsletter recipients to send them newsletters in their name or to pass them on to third parties.
For more information on how Mailchimp handles user data, please see the Privacy Policy of MailChimp: mailchimp.com/legal/privacy.

Comments function on our blog

In addition to your comment, information on the time of writing your comment and the name you have provided for commenting will be saved and published on the website as part of the comments function on the blog of this website. Furthermore, your email address will be logged and saved. The email address will not be published on the website. We need your email address in order to contact you if a third party objects to your published content as unlawful. The processing of personal data is thus based on our legitimate interests in the provision of a (secure) commentary on our blog.
We reserve the right to delete comments if they are objected to by third parties as unlawful.

Server log files

When you use our website, we only collect such data that your browser reports to our server (so-called "server log files"). When you visit our website, we collect the following server log files, which are technically necessary for us to display the website: our visited website, date and time at the time of access, amount of data sent in bytes, source / reference, from which you came to the page, browser used, operating system used, IP address used (possibly in anonymous form).
This processing of server log files is based on our legitimate interest in providing the website, improving the stability and functionality of our website.

Usage data

We also collect information about your use of our website. These usage data are collected via cookies (see in detail in section 2). We use this usage data for (i) web analytics, (ii) improvements to our services and our website, (iii) usability enhancements. This data processing is based on your consent to the use of cookies on our website. You can revoke this consent at any time (for example, via your browser settings for cookies) with effect for the future and free of charge.

Feedback and Surveys

If you leave us feedback on our services or participate in surveys on our website, we will process the personal information that you provide voluntarily (the email address and the content of your feedback or answers as part of the survey). These data are processed solely for the purpose of processing your feedback or for contacting you if desired, and for improving our services. This data processing is therefore required to fulfill our (pre-) contractual obligations and to safeguard our legitimate interests in the ongoing development of our services and website.

2. Cookies

Our website uses so-called cookies. These are small text files that are stored on your device by the browser. They do no harm.
On our cookie policy page you will find a detailed list of cookies we use on our website. Our website is scanned with our cookie scanning tool regularly to maintain a list as accurate as possible. You can opt-out of each cookie category (except strictly necessary cookies) by clicking on the "cookie settings" button below:


Cookie settings


As indicated in the following detailed information, when cookies are set on the basis of your voluntary consent, your personal data is sometimes transmitted to recipients in third countries outside the EU. If there is no adequacy decision by the EU Commission in accordance with Art 45 GDPR for the third country concerned, the transfer takes place in individual cases subject to suitable guarantees in accordance with Art 46 GDPR or, if necessary, by consent for certain purposes.
If you have given your consent, we use tracking, marketing and web analytics cookies to make our offerings user-friendly based on your usage data.
If you do not want this, you can set up your browser so that it informs you about the setting of cookies and you can then allow this only in individual cases. In this case, only the absolutely necessary cookies are set (Necessary Cookies) and we also record only anonymous data about your visit to our website, for example, to be able to determine the total number of visitors.
Disabling cookies may limit the functionality of our website. Here is a link to our cookie policy page, which shows you which cookies we use and gives you the option to change your cookie settings.

Google Analytics

If you have given consent to cookies, our website uses Google Analytics, a web analytics service provided by Google LLC. ("Google"), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA and its representative in the Union Google Ireland Ltd., Gordon House, Barrow Street, D04 E5W5, Dublin, Ireland.
Google Analytics uses so-called "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of our website (including the shortened IP address) is usually transmitted to and stored by Google on servers in the United States.
Our website uses Google Analytics exclusively with the extension "_anonymizeIp ()", which ensures anonymization by truncating the IP address and thereby preventing a direct personal reference.
By activating IP-anonymisation your IP address will be truncated within the area of Member States of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases the whole IP address will be first transferred to a Google server in the USA and truncated there.
Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing them with other services relating to website activity and internet usage. The IP-address, that your Browser conveys within the scope of Google Analytics, will not be associated with any other data held by Google.
You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to make full use of all the functions on this website. You can also opt-out from your data concerning the use of the website (incl. your IP address) being tracked with the use of cookies and processed by Google Analytics with effect for the future by downloading and installing the Google Analytics Optout Browser Addon for your current web browser: tools.google.com/dlpage/gaoptout.
For more information on the handling of user data by Google Analytics, please visit the Google Privacy Policy: support.google.com/analytics/answer/6004245.

Hotjar

If you have given your consent to cookies, we use Hotjar in order to better understand our users' needs and to optimize our service and users' experience. This is provided by Hotjar Ltd, Level 2, St Julians Business Center, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe.
Hotjar is a technology service that helps us better understand our users' experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don't like, etc.) and this enables us to build and maintain our service by means of user feedback. Hotjar uses cookies and other technologies to collect data on our users' behavior and their devices (in particular the IP address of the device (captured and stored only in anonymized form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), preferred language used to display our website). Hotjar stores this information in a pseudonymized user profile. Neither Hotjar nor we will ever use this information to identify individual users or to match it with further data on an individual user. For further details, please see Hotjar's Privacy Policy.
If you do not want to be recorded by Hotjar, you can disable it by setting the DoNotTrack header in your browser. For more information and more about Hotjar's data processing, please visit: www.hotjar.com/legal/compliance/opt-out.

3. Social Media Sharing

We offer the possibility to share blog articles of our website on social media like Facebook, Twitter, LinkedIn and Google+.
In order to increase the protection of your data when visiting our website, these buttons are only embedded in the page by means of an HTML link and not fully integrated. This ensures that when you visit a page on our site that contains such buttons, it will not automatically connect to the Facebook, Twitter, LinkedIn, or Google+ servers. If you click the button, a new browser window will open and call up the Facebook, Twitter, LinkedIn or Google+ page, where you can interact with the plugins there (if necessary after entering your login data).

Further information on these plugins, which open in a new browser window, can be found here:

Facebook-Plugin

Our website links to a browser window that uses so-called social plugins ("plugins") of the social network Facebook operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook").
For more information on the purpose and scope of the data collection and the further processing and use of the data by Facebook as well as your related rights and settings options for the protection of your privacy, please refer to the Privacy Policy of Facebook: www.facebook.com/policy.php.

Twitter-Plugin

Our website links to a browser window that uses Twitter microblogging plug-ins operated by Twitter Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA ("Twitter"). The plugins are marked with a Twitter logo, for example in the shape of a blue "Twitter bird". An overview of the Twitter plugins and their appearance can be found here: dev.twitter.com/web/tweet-button.
For more information on the purpose and scope of the data collection and the further processing and use of the data by Twitter as well as your related rights and settings options for the protection of your privacy, please refer to the Privacy Policy of Twitter: twitter.com/privacy.

LinkedIn-Plugin

Our website links to a browser window that uses LinkedIn plugins provided by the LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (hereinafter referred to as "LinkedIn"). You can recognize the plugins of LinkedIn by the corresponding logo or the "Recommend-Button".
For details on the collection of data and your legal as well as settings options, visit LinkedIn at: www.linkedin.com/static?key=privacy_policy.

4. Embedded services and third party content

We use third-party services and content within our online offering based on our legitimate interests in the provision, optimization and economic operation of our online offerings to integrate their content and services. This usually requires that the respective third-party providers of this content receive the IP address of the users, as they would not be able to send the requested content to their correct browser without the IP address. The IP address is therefore required for the presentation of this content and the use of the incorporated services.

5. Disclosure of personal data to third parties

We share your personal information to the extent necessary withthe following external service providers (processors) who assist us in the provision of our services:

  • IT service providers and / or providers of data hosting solutions or similar services;
  • other service providers, suppliers of tools and software solutions who also support us in the provision of our services and act on our behalf (including providers of marketing tools

All our processors process your data only on our behalf and on the basis of our instructions, so that we can make our online offer available to you.
In addition, we will transmit your personal data to the extent necessary to the following recipients (responsible persons):

  • any third parties involved in the provision of services to you to fulfill our contractual obligations;
  • external third parties to the extent necessary on the basis of our legitimate interests (for example, auditors and tax consultants, insurances in the event of a claim, legal representatives if required);
  • authorities and other public bodies to the extent required by law (such as tax authorities).

If we process your data in a third country outside the European Union (EU) or the European Economic Area (EEA) or in the context of the use of third party services, this will only be done if it is necessary to fulfill our (pre)contractual obligations based on your consent, due to a legal obligation or based on our legitimate interests. If you set cookies on the basis of your voluntary consent, your personal data will be transmitted to recipients in ("unsafe") third countries outside the EU, such as the USA. Your consent also includes such transfers in accordance with Article 49 (1) (a) GDPR.
In all other cases we have implemented suitable and appropriate safeguards to ensure that your data is transferred to the relevant third country in compliance with data protection laws (for example, through the conclusion of so-called "standard data protection clauses"). Upon your request, we will send you a copy of these appropriate warranties, as long as your data is processed by us or by third countries.

6. Storage duration

We only store your personal information for as long as it is necessary for the purposes for which it is processed. In addition, we might be obliged to keep your data for a longer period of time due to applicable statutory retention periods.
Specifically, we store your data in connection with contacting us on the basis of corresponding statutory retention requirements for a period of generally seven years, insofar as they are no longer of use to us. Access data and log files are stored for a maximum of 14 days and then deleted.
As a rule, we store data on your user behavior for a period of three years, or at the latest until you revoke your consent.
Personal data provided by you as part of feedback and surveys will remain stored until deleted by you or us.
If you have only registered for our newsletter and are not a customer of ours, we store your data until you revoke your consent and apart from that up to a maximum of three years.
In addition, we store your personal data beyond the specified periods if necessary, as long as legal claims can be asserted from the relationship between you and us or until the final clarification of a specific incident or legal dispute. This longer retention is essential for the protection of our legitimate interests in the assertion, investigation and defense of legal claims.

7. Data security

We take appropriate technical and organizational security measures within the meaning of Art. 32 GDPR in order to ensure a level of data protection commensurate with the risk, in particular to protect your personal data against unintentional or unlawful deletion, rectification or loss, and against unauthorized disclosure or access.

8. Your rights

You therefore have the right to information about the personal data we process of you. In addition, you have the right to rectification of incorrect data and deletion of your data ("right to be forgotten"). You may also revoke your consent to the processing of personal data with effect for the future if processing is based on your consent. You may also be entitled to restrict the processing of your data, to object to it, and to the right to receive the data you provided in a structured, common and machine-readable format ("data portability").
You also have the option to file a complaint with a data protection supervisory authority. The data protection supervisory authority responsible for us is:
Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna.
Before submitting a complaint to the DPA, or in the course of your or other questions, please contact us:

mindberry Consulting GmbH
Renngasse 4/5/4
1010 Vienna, Austria

contact@mindberry.com

+43 660 22 42 001 or +43 660 22 42 002

In order for us to process your request for your above mentioned rights and to ensure that personal information is not disclosed to unauthorized third parties, please direct the request with a clear identification of your person and a brief description of the extent to which you exercise your above listed rights of individuals affected.

9. Changes to the Privacy Policy

Changes will be announced on our website. Therefore, you should visit this Privacy Policy regularly to keep up to date with the latest developments.

As of September 2022