Last Updated: 25th of January 2025
Hummel Media GmbH (“we,” “us,” or “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit and interact with our main website (https://replystone.com, the “Main Website”) and our sub-site (https://onboarding.replystone.com, the “Onboarding Site”).
By using the Main Website and/or the Onboarding Site (collectively, the “Sites”), you acknowledge that you have read and understand this Privacy Policy. If you do not agree with its terms, please do not use the Sites.
1. Who We Are
- Data Controller: Hummel Media GmbH
- Registered Address: Flurgasse 2c, 7202 Bad Sauerbrunn, Austria
- Contact Email: [email protected]
For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, Hummel Media GmbH is the controller of your personal data collected through the Sites.
2. Scope
This Privacy Policy applies to information collected through:
- The Main Website (https://replystone.com), which is built on WordPress and protected by Cloudflare.
- The Onboarding Site (https://onboarding.replystone.com), which is hosted on Firebase.
Please note that when you complete the signup process on the Onboarding Site, you will be required to review and accept a separate privacy policy, terms of service, and service-level agreements that specifically govern the services you will use.
3. Information We Collect
3.1. Information You Provide Voluntarily
- Contact Form Information (Main Website): If you choose to contact us via our contact form, we collect your name, email address, the company you work for, and any other information you provide in your message. This information is used solely to respond to your inquiry and provide the services or information you have requested.
- Onboarding Information (Onboarding Site): While going through the onboarding process on https://onboarding.replystone.com, you may be asked to provide contact details (such as name, email address, company name, and any other details necessary to set up your account). We track your progress to assist you in completing the onboarding steps. This data is stored on Firebase and shared internally to facilitate your onboarding.
3.2. Information Collected Automatically
- Usage Data: We use Google Analytics on our Sites to collect information about how you interact with the site, including the pages you visit, how long you stay on each page, your IP address, device identifiers, browser information, and operating system. This helps us understand user behavior and improve our services.
- Cookies & Similar Technologies: We (and our service providers, such as Cloudflare and WordPress) may use cookies, web beacons, and similar tracking technologies to collect information about your interaction with the Sites. For more details, please see our “Cookies & Tracking” section below.
- Firebase Analytics (Onboarding Site): The Onboarding Site may use Firebase Analytics or other Firebase services that automatically collect usage data. You can learn more about how Firebase handles data by visiting Firebase’s Privacy and Security documentation.
3.3. Information From Other Sources
We may receive additional information about you from third parties, such as analytics providers, Cloudflare (for security and performance data), or public databases, to protect our Sites and improve user experience.
4. How We Use Your Information
We use your personal data for the following purposes:
- To Provide and Maintain Our Services:
- Responding to inquiries submitted via our contact forms.
- Facilitating and tracking onboarding progress on the Onboarding Site.
- Analytics and Site Improvement:
- Understanding how users interact with our Sites.
- Monitoring and analyzing usage trends to improve performance, functionality, and user experience.
- Security and Fraud Prevention:
- Protecting against misuse or unauthorized use of our Sites (e.g., via Cloudflare).
- Internal Business Purposes:
- Sharing data internally among team members who require it to perform their roles.
- Maintaining business records for administrative and legal purposes.
- Compliance with Legal Obligations:
- Complying with applicable laws, regulations, and requests from competent authorities.
5. Legal Basis for Processing
We process your personal data under the following legal bases, as permitted by the GDPR:
- Consent: When you voluntarily submit your data through a contact form or agree to the use of certain cookies.
- Contractual Necessity: When data processing is necessary to provide you with the requested services (e.g., onboarding).
- Legitimate Interests: For analytics, site improvement, and the security of our Sites.
- Legal Obligations: When necessary to comply with legal or regulatory requirements.
6. Data Sharing and Transfers
- Internal Sharing: We may share your data internally among our teams to respond to your requests and provide our services.
- Service Providers: We use third-party services and tools (e.g., Google Analytics, Firebase, Cloudflare, and WordPress plugins) that process personal data on our behalf for analytics, hosting, security, and site functionality.
- Third-Country Data Transfers: Some of our service providers (e.g., Google) may store or process data in countries outside the European Union/European Economic Area. Where such transfers occur, we ensure appropriate safeguards (e.g., Standard Contractual Clauses) are in place to protect your personal data.
- Legal Compliance and Protection: We may disclose your information if required to do so by law or to protect and defend our rights, property, or personal safety (and that of our users).
7. Retention of Your Data
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specifically:
- Contact Form Data: Retained until your inquiry is resolved or as needed for legal or administrative requirements.
- Onboarding Data: Retained for as long as necessary to complete the onboarding process and provide the related services, or until you request deletion (subject to any overriding legal obligations).
- Analytics Data: Retained as per Google Analytics’ standard retention settings, unless you request its deletion.
8. Cookies & Tracking Technologies
We use cookies and similar technologies to optimize the functionality of our Sites. Cookies are small text files placed on your device to store data. You can configure your browser settings to refuse cookies or alert you when cookies are being sent. However, some parts of the Sites may not function properly if you disable cookies.
Types of Cookies Used:
- Essential Cookies: Necessary for the operation of the Sites (e.g., security, load balancing through Cloudflare).
- Analytics Cookies: Help us understand how users interact with the Sites (e.g., Google Analytics, Firebase Analytics).
For more information about how Google Analytics uses your data, visit Google’s Privacy & Terms.
9. Your Rights (GDPR)
Under applicable data protection laws, particularly the GDPR, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of any inaccurate or incomplete personal data.
- Erasure (“Right to be Forgotten”): Request deletion of your personal data under certain circumstances.
- Restriction of Processing: Request that we limit how we use your personal data.
- Data Portability: Obtain a copy of your personal data in a structured, commonly used, and machine-readable format.
- Objection: Object to certain processing activities based on our legitimate interests.
- Withdraw Consent: Where we rely on consent, you can withdraw it at any time.
To exercise these rights, please contact us at [email protected]. We will respond to your request in compliance with applicable data protection laws.
If you believe we are unlawfully processing your personal data, you also have the right to complain to the relevant supervisory authority. In Austria, this is the Austrian Data Protection Authority.
10. Security Measures
We implement industry-standard technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, but are not limited to:
- Cloudflare protection for enhanced security and performance on the Main Website.
- Firebase secure hosting for the Onboarding Site.
- Encryption of data in transit (HTTPS).
- Access Controls limiting internal access to only those who need it to perform their duties.
11. External Links
The Sites may contain links to external websites not operated by us. If you click on a third-party link, you will be directed to that third party’s website. We strongly advise you to review the privacy policies of every website you visit, as we have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
12. Children’s Privacy
Our Sites are not intended for use by individuals under the age of 16, and we do not knowingly collect personal data from anyone under 16. If you believe that a child under 16 has provided personal data to us, please contact us immediately at [email protected].
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, and other factors. When we make changes, we will revise the “Last Updated” date at the top of this page. We encourage you to periodically review this Privacy Policy for the latest information on our data protection practices.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Hummel Media GmbH
Flurgasse 2c, 7202 Bad Sauerbrunn, Austria
Email: [email protected]
Thank you for trusting Hummel Media GmbH with your personal data. We are committed to ensuring your privacy and are here to help with any questions you may have about this Privacy Policy or the security of your personal data.