Thank you for your interest in our AI training platform snipKI.de. Protecting your personal data is important to us. Below, we provide detailed information about the collection, processing and use of your data when you use our website.
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
snipKI GmbH
Fehrbelliner Straße 48
10119 Berlin
Germany
Represented by the managing directors:
Moritz Heininger, Jens Lehnen
Phone: +49 160 2390573
Email: moritz@snipki.de
Responsible for content pursuant to section 18(2) of the German Interstate Media Treaty (MStV):
Jens Lehnen
Josef-Bayer-Str. 8
50733 Köln
Germany
Email: jens.lehnen@snipki.de
2. Hosting
We use the cloud infrastructure of Amazon Web Services (AWS) to operate our website and learning platform. Our web application, database and central media storage are operated in the AWS Frankfurt am Main region (eu-central-1).
AWS provides computing resources, database storage and file storage. We also use Amazon CloudFront, a content delivery network, to deliver our website and media. This involves processing the connection data required to retrieve content, in particular your IP address and information about the requested resource.
CloudFront uses a distributed network of server locations. Having Frankfurt as our primary region therefore does not mean that all processing takes place exclusively in Germany.
Hosting serves the purpose of performing contracts with our prospective and existing customers pursuant to Article 6(1)(b) GDPR and our interest in providing our online services securely, quickly and efficiently pursuant to Article 6(1)(f) GDPR.
Information about AWS privacy terms and the AWS Data Processing Addendum is available in the AWS GDPR Center.
3. General information on data processing
Scope of personal data processing
We process your personal data only to the extent necessary to provide a functioning website and our content and services.
Legal bases for processing
-
Consent: Article 6(1)(a) GDPR, e.g. when subscribing to a newsletter
-
Performance of a contract: Article 6(1)(b) GDPR, e.g. when using paid services
-
Legal obligation: Article 6(1)(c) GDPR, e.g. tax retention requirements
-
Legitimate interest: Article 6(1)(f) GDPR, e.g. security when using the website
4. Data collection on our website
a) Server log files
When you visit our website, our hosting provider automatically collects and stores information in server log files that your browser automatically transmits to us. This includes:
-
IP address of the requesting computer
-
Date and time of the server request
-
Browser type and version
-
Operating system used
-
Referrer URL
-
Hostname of the accessing computer
This data cannot be attributed to specific individuals. It is not combined with other data sources. Processing takes place pursuant to Article 6(1)(f) GDPR.
b) Contact form and communication
If you send us enquiries using the contact form, we store your details, including the contact details you provide, to process your enquiry. We do not share this data without your consent.
c) Registration on the website
We use Supabase Auth as a hosted service for registration and login. Our Supabase project is operated in the Frankfurt am Main region (eu-central-1). Supabase processes the data required for your account and login, in particular your email address, user identifier, and authentication and session data.
This processing serves to provide and secure your user account and enable use of the learning platform. The legal bases are Article 6(1)(b) GDPR for providing the requested service and Article 6(1)(f) GDPR for login security.
Further information is available in the Supabase Privacy Policy and the Data Processing Addendum linked there. The Frankfurt project region does not constitute a guarantee that all supplementary processing by the provider takes place exclusively in Germany.
d) Comments and posts
When users leave comments or other posts, their IP addresses are stored on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR. This is for our security in case unlawful content is published in comments or posts.
5. Cookies and similar technologies
We use necessary cookies to operate our website and, with your consent, cookies to analyse website usage. We manage your choices through our own cookie banner.
The snipki_cookie_consent cookie stores your choice, the accepted and rejected categories, and the time of your decision in your browser for 180 days. This allows us to respect your settings on subsequent visits. Analytics services are loaded only after you have given your consent.
Legal basis:
-
Necessary cookies: Article 6(1)(f) GDPR
-
Non-essential cookies: Article 6(1)(a) GDPR
You can change your choices at any time via “Cookie settings” in the footer of our website and withdraw your consent with effect for the future.
6. Email communication and newsletters
We use a double opt-in procedure for newsletter subscriptions. After subscribing, you receive an email with a confirmation link. You will receive our newsletter only after you have opened this link and confirmed your subscription.
System emails via Resend
We use Resend for system emails, such as login and security messages relating to your account. This involves processing the email address, message content and delivery information required to send these messages.
Transactional messages serve to provide and secure the requested service. Depending on the purpose, processing is based on Article 6(1)(b) or (f) GDPR. These messages are distinct from voluntarily subscribed newsletters.
Further information is available in the privacy policies of Resend and HubSpot.
According to Resend, account data, including email metadata, logs and API data, is stored in the USA regardless of the selected sending region. Choosing a European sending region therefore does not mean that data processing takes place exclusively in Europe. Further information: Resend — Sending regions and data storage.
Contact management and newsletters via HubSpot
We use HubSpot for customer and contact management (CRM) and to send our newsletters. Our HubSpot portal is hosted in the European Union. We process the contact information you provide, the communication history required to support you, and your newsletter subscription status.
Contact management serves to process your enquiries and maintain our customer relationships. Depending on the circumstances, processing takes place to take steps prior to entering into a contract or to perform a contract pursuant to Article 6(1)(b) GDPR, or on the basis of our legitimate interest in handling other enquiries pursuant to Article 6(1)(f) GDPR.
No open or click tracking: Open and click tracking is disabled in our newsletters and system emails. We do not analyse whether you open a message or click links it contains. Technical delivery information is separate from this.
Legal basis for newsletters:
Article 6(1)(a) GDPR (consent). You can unsubscribe from the newsletter at any time using the unsubscribe link in the newsletter.
7. Payment processing via Stripe
We use Stripe for payment processing. Your payment data is transmitted to Stripe for this purpose.
Transfers of data to third countries:
Stripe may transfer data to the USA. Stripe’s privacy policy is available here: https://stripe.com/de/privacy
Legal basis:
Article 6(1)(b) GDPR (performance of a contract), Article 49(1)(b) GDPR.
8. Use of Google Analytics and Google Tag Manager
Our website uses features of Google Analytics and Google Tag Manager, provided by Google Ireland Limited. Google Analytics uses cookies that enable analysis of website usage.
IP anonymisation:
We have enabled IP anonymisation. This means that Google truncates your IP address within the EU.
Objection to data collection:
You can prevent cookies from being stored by adjusting your browser settings.
Legal basis:
Article 6(1)(a) GDPR (consent).
9. Affiliate programme with FirstPromoter
We use FirstPromoter for our affiliate programme. FirstPromoter processes the data provided by partners as part of their participation. Further information is available in the FirstPromoter Privacy Policy.
10. External service providers and recipients
Deals via JoinSecret
We use JoinSecret (Tech-Lab) to provide our deals. When you access the deals page with the relevant access entitlement, we transmit your email address to JoinSecret to obtain an access token for the embedded member offers. This serves to provide the deals as part of your membership on the basis of Article 6(1)(b) GDPR.
The deals and their previews are embedded directly from JoinSecret into our page. When this content loads, the connection data required to retrieve it, in particular your IP address and browser information, is transmitted to JoinSecret.
Further information is available in the JoinSecret Privacy Policy.
Overview of recipients
We work with the following external service providers:
-
Hosting, database, media storage and delivery: Amazon Web Services (AWS), including Amazon CloudFront
-
User account and login: Supabase as a hosted service, Frankfurt am Main project region (
eu-central-1) -
System emails: Resend
-
Customer and contact management (CRM), newsletters: HubSpot, portal hosting in the European Union
-
Payment processing: Stripe
-
Affiliate programme: FirstPromoter
-
Tracking and analytics: Google Analytics, Google Tag Manager
-
Deals and access to member offers: JoinSecret (Tech-Lab)
Where required, we have entered into data processing agreements with all service providers pursuant to Article 28 GDPR.
11. Your rights
You have the right to:
-
Obtain access to the data we store about you (Article 15 GDPR)
-
Request rectification of inaccurate data (Article 16 GDPR)
-
Request erasure of your data (Article 17 GDPR)
-
Request restriction of the processing of your data (Article 18 GDPR)
-
Receive data portability (Article 20 GDPR)
-
Object to processing (Article 21 GDPR)
-
Lodge a complaint with a supervisory authority (Article 77 GDPR)
12. Data security
We use SSL or TLS encryption to secure data transmission. We continuously improve our security measures in line with technological developments.
13. Currency and amendments to this privacy policy
This privacy policy is dated 18 October 2024. Further development of our website or changes in legal requirements may make it necessary to amend this privacy policy.
14. Contact
If you have questions about data protection, please contact:
snipKI GmbH (haftungsbeschränkt)
Email: datenschutz@snipki.de
15. Final provisions
We reserve the right to amend this privacy policy at any time with effect for the future.
16. Consent and withdrawal
If you have given us consent to process your personal data, you may withdraw it at any time with effect for the future.
17. Retention period
Personal data is stored only for as long as necessary for the purposes for which it is processed or as required by statutory retention periods.
