Data Policy
Effective Date: 10.12.2024
At www.cibermedia.de, we are committed to protecting your privacy and ensuring that your data is handled in compliance with the General Data Protection Regulation (GDPR/DSGVO). This policy explains how we collect, process, and protect your personal data, covering both the platform and the website.
1. Responsible Person for Data Protection
Ciberdime GmbH
Tieskamp 4
25693 St. Michaelisdonn
Germany
Email: info@ciberdime.com
Phone: +49 4853 9953008
If you have questions about this Data Policy, your rights, or concerns about your personal data, you may contact our Data Protection Officer at the above email address.
2. Data Collected Through the Platform
2.1 Account Data
When you connect Instagram or Twitch accounts, we collect and process data such as account details, linked Facebook pages, and permissions granted during setup. For Instagram integration, this requires logging in via Facebook Business and ensuring the Instagram account is linked to a Facebook page.
2.2 Insights and Analytics
We process Instagram insights (e.g., story reach, reel impressions, post engagement) and Twitch metrics (e.g., viewer statistics, stream duration) to provide you with detailed analytics. This data may include individual-level metrics as defined in Art. 4 Nr. 1 DS-GVO but is processed exclusively for your use in analyzing and managing your connected accounts.
2.3 Public Data
If you use public accounts, we may process publicly available data, such as usernames, post captions, and public engagement metrics. This processing is performed within the bounds of GDPR.
2.4 Usage Data
We collect data about your activity on our platform, such as login times, features used, and account connections. This is done to ensure the platform operates securely and effectively.
3. Data Collected Through Website Hosting
3.1 Hosting Provider: Vercel
Our website is hosted by Vercel, a cloud platform operated by:
Vercel Inc.
340 S Lemon Ave #4133
Walnut, CA 91789, USA
When you visit our website, Vercel processes certain data as part of its hosting services. This includes:
- Your IP address
- Requested pages or files
- Browser type and version
- Operating system
- Referrer URL
- Timestamps
Vercel stores this data temporarily in server logs to ensure secure and reliable hosting. Vercel complies with GDPR and operates servers within the EU/EEA. In cases where data is transferred outside the EU/EEA, such transfers are governed by Standard Contractual Clauses (SCCs).
3.2 Data Automatically Collected
We collect the following data automatically during your visit:
- Your IP address
- Browser type and version
- Date and time of access
- Operating system
- Referrer URL
This data is processed to ensure proper functionality and security of the website under Art. 6 Abs. 1 S. 1 lit. f DS-GVO (legitimate interest).
3.3 Cookies and Tracking
Our website uses cookies to enhance your experience. These include:
- Essential Cookies: Necessary for website functionality.
- Analytics Cookies: Help us understand how users interact with the site. Data is anonymized when possible.
- Preference Cookies: Save your settings, such as language preferences.
You can manage or block cookies via your browser settings or through the cookie banner on our website.
4. Creator Control Over Data Sharing
As a creator, you maintain full control over your data. You can decide which organizations have access to your insights and revoke that access at any time. The platform does not automatically share data with third parties or external service providers.
When you revoke access, the respective organization will lose access immediately and must delete any data already received.
5. Facebook Login and Single Sign-On (SSO)
We allow users to log in to our platform, cibermedia.de, using their Facebook accounts. For this, we use Facebook Login, a Single Sign-On (SSO) process. SSO enables users to log in to our platform using existing credentials from other online services without cibermedia.de gaining access to these credentials. Through this SSO process, certain personal data may be exchanged between Facebook and cibermedia.de. This includes information such as the IP address, browser used, channel name, and other technical data, but no private information such as non-public real names or home addresses.
On our platform, the SSO process is used to allow users to access detailed, statistically prepared insights and analytics about their connected Instagram accounts. These insights form the foundation of our data services. Users are verified through the SSO process, and their analytics are enhanced using data obtained after authorization. All data is handled with the utmost care and in strict compliance with the GDPR (DSGVO).
cibermedia.de offers Instagram insights only to users whose Instagram accounts are connected to a Facebook account and are linked to an Instagram Business Account. Portions of the collected data may be used or stored by cibermedia.de to optimize internal calculations and reporting. By using the Facebook Login feature on the cibermedia.de platform, users explicitly agree to this usage. The authorization for API requests is initiated solely when users actively choose to share this data through the Facebook Login process. Prior to this, users are informed of all necessary information about data processing and must confirm their understanding and consent.
The legal basis for this data processing is the user’s consent according to Art. 6 Abs. 1 S. 1 lit. a DSGVO. Users may revoke their consent at any time with future effect, as outlined in Art. 7 Abs. 3 DSGVO. Revocation can be carried out either through Facebook or by contacting us via post. Once consent is revoked, users will no longer be able to view their detailed insights, and the permissions granted to cibermedia.de will be terminated.
6. Legal Basis for Data Processing
We process your data based on the following legal grounds:
- Art. 6 Abs. 1 S. 1 lit. b DS-GVO: Processing is necessary for the performance of a contract (e.g., providing analytics for your accounts).
- Art. 6 Abs. 1 S. 1 lit. f DS-GVO: Processing is necessary for legitimate interests, such as ensuring platform functionality and security.
- Art. 6 Abs. 1 S. 1 lit. a DS-GVO: In cases where we request your explicit consent (e.g., for analytics or cookies), you can withdraw consent at any time.
7. Data Retention
We retain your data only as long as necessary to fulfill the purposes described. If you delete your account, all associated data will be permanently removed within 30 days unless legal obligations require otherwise. For organizations, any revoked access results in immediate termination of their ability to process your data.
8. Your Rights Under GDPR (DS-GVO)
As a data subject, you have the following rights:
- Right to Access (Art. 15 DS-GVO): Request a copy of the data we hold about you.
- Right to Rectification (Art. 16 DS-GVO): Correct inaccurate or incomplete data.
- Right to Erasure (Art. 17 DS-GVO): Request deletion of your data under certain conditions.
- Right to Restrict Processing (Art. 18 DS-GVO): Request restriction of data processing under specific circumstances.
- Right to Data Portability (Art. 20 DS-GVO): Obtain your data in a structured format.
- Right to Object (Art. 21 DS-GVO): Object to data processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7 Abs. 3 DS-GVO): Withdraw consent at any time.
- Right to Lodge a Complaint (Art. 77 DS-GVO): File a complaint with your local supervisory authority.
9. Protection of Personal Data and Security Measures
The protection of your personal data is a top priority for us. To ensure the highest level of security, cibermedia.de implements a range of technical and organizational measures, including:
- SSL/TLS Encryption
- Secure Authentication
- Access Controls
- Data Minimization
- Regular Security Audits
- Server Security
- Data Backup and Recovery
10. Cross-Border Data Transfers
For data transfers outside the EU/EEA (e.g., through Vercel’s infrastructure), we use GDPR-compliant mechanisms such as Standard Contractual Clauses (SCCs).
11. Updates to this Policy
This policy may be updated periodically to reflect changes in services or legal requirements. Any significant updates will be communicated to you via email or the platform. Continued use of our services after updates indicates acceptance of the revised policy.