Skip to content
Privacy

Privacy policy

Information under Art. 13 and Art. 14 GDPR.

Information pursuant to Art. 13 and 14 GDPR on the processing of personal data on the websites etmita.com and etmita.de and in the course of our business.

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Company
Etmita UG (haftungsbeschränkt)
Address
Nieder Straße 10, 65795 Hattersheim am Main, Germany
Managing director
Mohammad Ghadery
Register
Amtsgericht Frankfurt am Main, HRB 143789
VAT ID
DE455715354

Data protection officer

The legal requirements for appointing a data protection officer (Art. 37 GDPR, § 38 BDSG) are currently not met. For data protection questions please contact [email protected].

Principles and legal bases

We process personal data only as far as necessary to operate this website, answer your enquiries and provide our services. The legal bases are in particular:

  • Art. 6 (1) (a) GDPR – consent;
  • Art. 6 (1) (b) GDPR – contract or pre-contractual steps taken at your request;
  • Art. 6 (1) (c) GDPR – legal obligation (e.g. commercial and tax retention duties);
  • Art. 6 (1) (f) GDPR – legitimate interests, unless your interests override them.

Data is deleted once the purpose no longer applies, unless statutory retention periods (in particular § 257 HGB, § 147 AO; up to ten years) require otherwise.

Hosting and server log files

The website runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in data centres in Germany. Hetzner processes the data on our behalf (Art. 28 GDPR).

With each request, technically necessary data is processed and stored in server log files:

  • IP address of the requesting device;
  • date and time of access;
  • requested page or file and amount of data transferred;
  • referrer URL (the previously visited page), if sent by the browser;
  • browser type and operating system (user agent).

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is the secure and stable operation of the website and the defence against attacks. These web server access logs are kept for at most 14 days and then deleted automatically. They are not combined with other data.

Content delivery network and attack protection (Cloudflare)

Our website is delivered through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare provides TLS encryption, delivers content and protects the website against overload and other attacks. Cloudflare processes technical connection data, in particular your IP address, and provides us with the country derived from the IP address, which we use only to preselect the language (German/English).

Legal basis: Art. 6 (1) (f) GDPR (secure, fast delivery of the website). Cloudflare is certified under the EU-U.S. Data Privacy Framework (adequacy decision under Art. 45 GDPR); the EU Standard Contractual Clauses apply in addition (Art. 46 (2) (c) GDPR).

Cookies and local storage

We use no analytics, advertising or tracking cookies and no comparable technologies (e.g. pixels, fingerprinting). We only store information that is strictly necessary for the functions you use (§ 25 (2) no. 2 TDDDG):

  • NEXT_LOCALE – stores the language you chose with the language switcher; set only after that choice, kept for 12 months;
  • theme – stores the selected light or dark theme, only if you switch it, kept for 12 months;
  • etmita_session – only when signing in to the non-public administration area; this cookie is never set for website visitors.

No consent is required for this. Further processing is based on Art. 6 (1) (f) GDPR. You can delete cookies in your browser at any time; the website will then use its default settings.

Fonts are loaded from our own server; no connection to Google or other font providers is made.

Contact form, email and phone

If you contact us by contact form, email or phone, we process your details (name, email address, company if given, and message) to handle your enquiry.

The contact form is transmitted to our mailbox via the EmailJS service of EmailJS Pte. Ltd., Singapore. EmailJS servers are located in the USA. EmailJS processes your form details and your IP address. Storage of the message history at EmailJS is switched off. For transfers to third countries without an adequacy decision (Singapore, USA) we have concluded the EU Standard Contractual Clauses with EmailJS (Art. 46 (2) (c) GDPR); EmailJS processes the data on our behalf.

Our mailbox is operated by Hetzner Online GmbH in Germany.

Legal basis: Art. 6 (1) (b) GDPR if your enquiry is aimed at concluding a contract; otherwise Art. 6 (1) (f) GDPR (answering enquiries). We delete the enquiry once it has been fully handled, unless retention duties apply.

Job applications

If you apply through the form on our careers page (etmita.com/careers), we process the details you send us: name, email address, optionally your phone number, place of residence, links to professional profiles, work experience, earliest start date, your cover letter and optionally your CV (PDF).

Purpose and legal basis: We process these data to decide on establishing an employment relationship (Art. 6 (1) (b) GDPR – steps prior to an employment relationship, taken at your request). After our decision we keep them so that we can defend ourselves against claims under the General Equal Treatment Act (AGG) (Art. 6 (1) (f) GDPR; legitimate interest: legal defence).

Storage and recipients: The application is stored exclusively on our own server in Germany and is not passed on to third parties. Only the people at our company who decide on the position have access. Technical service providers acting as processors: Hetzner Online GmbH (hosting) and Cloudflare, Inc. (transmission, see section 5).

Retention: We delete the application, including the CV, automatically six months after our decision (rejection or hiring); while no decision has been made, six months after receipt. The period follows from § 15 (4) AGG and § 61b (1) ArbGG. CVs are not included in our backups; the other details remain in our backups for at most 30 days after deletion, until these are overwritten or deleted. If we hire you, we transfer the necessary details to the personnel file.

Withdrawal: You can withdraw your application at any time. An email to [email protected] is enough; we then delete it immediately. Your name and email address are required so that we can process your application; all other details are voluntary.

Business relationship and data processing on behalf of clients

In our business relationships we process master, contact, contract, billing and payment data of our clients, suppliers and service providers and of their contact persons (Art. 6 (1) (b) and (c) GDPR; for contact persons Art. 6 (1) (f) GDPR) for the duration of the business relationship and the statutory retention periods. We keep accounting vouchers for eight years, books and financial statements for ten years and business letters for six years (§ 147 AO, § 257 HGB).

Incoming invoices and receipts: We read invoices and receipts we receive with AI-assisted text recognition in order to record the invoice details and check the mandatory details for input VAT deduction. The result is a suggestion; a person decides on booking and payment. The legal basis is Art. 6 (1) (c) GDPR in conjunction with the tax and commercial record-keeping and retention obligations, and Art. 6 (1) (f) GDPR (our interest in accurate and timely bookkeeping). The service provider does not use the documents to train AI models and usually deletes them within 30 days. You may object to processing based on Art. 6 (1) (f) GDPR on grounds relating to your particular situation (Art. 21 GDPR); an email to [email protected] is sufficient.

Where we process personal data on behalf of our clients, in particular for SaaS services such as MITA Base and Passfest, we act as a processor and conclude a data processing agreement under Art. 28 GDPR before processing starts. The client is the controller in these cases.

Recipients and transfers to third countries

We only pass on personal data as described in this policy, where a legal obligation exists, or where you have consented. Recipients are our processors:

  • Hetzner Online GmbH, Germany – hosting and email;
  • Cloudflare, Inc., USA – delivery and protection of the website (EU-U.S. Data Privacy Framework, Standard Contractual Clauses in addition);
  • EmailJS Pte. Ltd., Singapore, servers in the USA – transmission of the contact form (Standard Contractual Clauses);
  • Anthropic Ireland, Limited, Ireland, with processing by Anthropic, PBC in the USA – AI-assisted recognition of incoming invoices and receipts (Standard Contractual Clauses).

A copy of the safeguards for third-country transfers is available on request at [email protected].

Links to other services

Our website contains links to LinkedIn, GitHub and the websites of our products (mitabase.com, passfest.de). These are plain links, not embedded content: data is only transferred when you click a link. The respective provider is responsible for processing on those sites.

Your rights

You have the following rights regarding your personal data:

  • access (Art. 15 GDPR);
  • rectification (Art. 16 GDPR);
  • erasure (Art. 17 GDPR);
  • restriction of processing (Art. 18 GDPR);
  • data portability (Art. 20 GDPR);
  • withdrawal of consent with effect for the future (Art. 7 (3) GDPR).

Right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6 (1) (f) GDPR. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

To exercise your rights, a message to [email protected] is sufficient.

Right to lodge a complaint (Art. 77 GDPR)

You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Authority
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Address
Postfach 3163, 65021 Wiesbaden

Data security

We take technical and organisational measures under Art. 32 GDPR, in particular:

  • TLS encryption of all connections;
  • access to the administration area only for authorised persons and only with a second factor (TOTP);
  • passwords stored only as a salted hash (bcrypt), recovery codes only as hashes;
  • session cookie with the HttpOnly, Secure and SameSite=Strict attributes;
  • data stored on our own server in Germany;
  • regular backups; downloaded backups are encrypted (AES-256-GCM);
  • regular security updates.

Automated decisions

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Where we read incoming invoices and receipts automatically (section 9), this only prepares the work of a person.

Changes to this privacy policy

We update this privacy policy when our website, our services or the law change. The current version is always available at https://etmita.com/privacy.

As of: 5 October 2026ETM-2026-0002