Data-minimised website
This website uses no analytics or marketing trackers, no embedded third-party fonts and no non-essential cookies. The request window does not collect audit files.
Controller
Vereinstraße 19
30175 Hannover
Germany
Telephone: +49 176 32370190
Email: [email protected]
Hosting, delivery and server logs
The website and customer portal run on a server provided by DeinServerHost.de. The provider identifies Frankfurt am Main as the server location. Structured portal and project data is processed in a PostgreSQL database on that server. Uploaded audit files are stored in the protected file system of the same server; no separate external file or cloud storage is connected.
Technically necessary log data may be processed when the service is accessed, including IP address, time, requested resource, referrer, browser type, operating system and status code.
Processing serves secure, stable and efficient delivery. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is technical reliability, error analysis and abuse prevention.
Where Network Error Logging (NEL) is active at Cloudflare's edge, the browser may retain the reporting policy for up to seven days and send technical error reports to Cloudflare. These reports are used solely to detect delivery errors.
DeinServerHost provides a data processing agreement under which the contracted processing takes place exclusively in the EU or EEA. Information about Cloudflare is available in its relevant privacy documentation. DeinServerHost AV-Vertrag · Cloudflare DPA
Contact and audit requests
Without a connected secure form endpoint, the request window sends nothing automatically. You may deliberately open the structured details in your email app. When you contact us, we typically process your name, email address, company and message.
For pre-contractual or contractual enquiries, processing is based on Article 6(1)(b) GDPR. In other cases Article 6(1)(f) GDPR applies; our legitimate interest is appropriate communication with prospects and business partners.
We use Zoho Mail for business email. In addition to message content, the Zoho group processes technically necessary email metadata. Messages that are no longer required are deleted unless statutory or contractual retention duties apply. Under the provider's deletion and backup policies, deleted data may remain temporarily in recovery systems. Zoho Datenschutz
Data used in a Parcel Audit
Audit data is not accepted through this website. Before any transfer, scope, secure transfer method, roles and deletion period are agreed separately. Initial reviews are intended to use pseudonymised shipment IDs; unnecessary customer names should not be transferred.
Where MarginMine processes personal data on a customer's behalf, a data processing agreement will be concluded before processing begins where required by Article 28 GDPR.
Portal sign-in and Cloudflare Turnstile
An email address and password are required to sign in. On successful sign-in MarginMine also processes the IP address and user agent for session and abuse security. Access is not possible without providing the credentials.
Cloudflare Turnstile is loaded only when you start a sign-in attempt. Cloudflare processes in particular the IP address and browser and device information to detect automated or abusive access. The legal basis is Article 6(1)(f) GDPR; the integration protects the customer portal. MarginMine does not permanently store the Turnstile token or verification response.
If the security check rejects you incorrectly or is technically unavailable, you can request an alternative resolution using the email address above. Cloudflare Privacy Policy
Cookies, analytics and external fonts
The public website uses no analytics or marketing services and stores no non-essential cookies. Fonts are served locally. After successful sign-in, a technically necessary HttpOnly-protected session cookie is required for portal access.
Retention
Hashes of failed and successful sign-in attempts are deleted after 30 days. Portal sessions remain valid for no more than 14 days; signing out invalidates the related session token and expired records are cleared. The most recent IP and user-agent entry stored after a successful sign-in is overwritten at the next successful sign-in and removed no later than deletion of the user account.
Email enquiries are deleted once conclusively handled unless statutory or contractual duties apply. Contract and audit records follow individually agreed deletion periods and statutory retention duties.
Requirement to provide data
Sign-in data is required for access to the customer portal. Access cannot be provided without it. Details in an audit request are voluntary, but we cannot respond without sufficient contact information. Audit data required by contract is defined before the project begins.
Your rights
Subject to statutory requirements, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection to processing based on legitimate interests (Article 21). You may withdraw consent at any time with future effect.
To exercise these rights, send a message to the email address stated above.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The relevant authority in Lower Saxony is:
Der Landesbeauftragte für den Datenschutz NiedersachsenPrinzenstraße 5
30159 Hannover
www.lfd.niedersachsen.de
Security and updates
The website is delivered over HTTPS. We update this notice when functions, providers or legal requirements change. The version published here is authoritative.