Privacy notice
Last revised: 30 September 2026.
1. Who is responsible?
Mindtro GmbH, Knesebeckstraße 62/63, 10719 Berlin, Germany, is responsible for personal data it processes for this website, its own enquiries and business administration. Contact legal@mindtro.com or +49 30 166381616 for privacy requests. This is our privacy contact; no separate data protection officer is represented as appointed by this notice.
MİNDTRO TEKNOLOJİ ANONİM ŞİRKETİ is the Turkish company listed in the legal notice. Its involvement and role depend on the relevant contract and actual processing. A company listing does not authorise access to customer data. Where Mindtro processes workspace content on a customer’s instructions, the customer determines the purpose and the agreed DPA applies. Requests concerning that content should normally go to the customer; we assist them as required.
2. Data, purposes and legal bases
| Processing | Data involved | Purpose and GDPR basis |
|---|---|---|
| Delivering and protecting the website | IP address and connection, browser, request and error information | Operate the site and investigate abuse; legitimate interests under Article 6(1)(f), subject to a balancing assessment |
| Responding to enquiries | Name, work email, organisation, product interest and message you provide | Take requested pre-contract steps under Article 6(1)(b), or handle business correspondence under Article 6(1)(f) |
| Administering a customer relationship | Contact, account, contract, invoice and payment-status information | Perform a contract under Article 6(1)(b), manage organisational contacts under Article 6(1)(f), and meet applicable obligations under Article 6(1)(c) |
| Optional external maps | Connection and device information disclosed when you choose to load a map | Your consent under Article 6(1)(a); addresses and external directions links remain available without loading it |
| Optional website performance reporting | Page category, language, performance values and selected error events | Improve the website with your consent under Article 6(1)(a); off before your choice, and disabled by browser privacy signals |
| Optional marketing | Contact details and the recorded choice to receive messages | Consent where required; each message must provide a way to stop it |
Providing enquiry details is voluntary, but we need a reply address and enough context to answer. Avoid unnecessary sensitive information. We do not make decisions with legal or similarly significant effects about website visitors solely through automated processing. Separate customer workflows require their own assessment and notices.
3. Forms, storage and external content
The contact form states whether it prepares an email draft or submits a message to our server. In draft mode, this website does not receive the message through the form; your email application sends it only when you choose to send. In server-submission mode, the displayed acceptance result is distinct from final email delivery.
The site remembers a language preference, a theme preference and your privacy choices. Cookie preferences in the footer let you accept, reject or change optional categories; choices last 180 days on this browser. The cookie notice identifies these stores and how to remove them. Optional maps load only after your choice; Google Maps or the OpenStreetMap tile service receives the network information needed to display its content. You can stop the map and reload without it. External links connect you to their destination when followed.
If enabled by Mindtro and permitted through Cookie preferences, first-party performance measurements contain metric values, page category and language rather than account identifiers or raw page URLs. Hosting infrastructure may separately receive connection data. We do not describe this as proof that no personal data is processed anywhere in the delivery chain.
4. Recipients and international access
Hostinger provides hosting for this public website. Mindtro also uses AWS and Google services. The provider overview explains the known provider families and how to obtain the service-specific processing schedule. We share data only for the relevant service or a lawful obligation, with appropriate contractual arrangements. Professional advisers, payment providers and authorities receive information only where their role requires it; this is not unrestricted permission to share customer content.
Provider regions, support locations and enabled integrations depend on the service configuration. We do not promise that all data stays in Germany or the EEA. Before making personal data available outside the EEA, including relevant access from Türkiye, we must establish the applicable transfer basis and safeguards. Where needed, this includes the EU Standard Contractual Clauses, a transfer assessment and supplementary measures. A provider’s adequacy or certification status must apply to the actual recipient and processing; the Turkish company’s ISO certification is not an international-transfer mechanism. Ask legal@mindtro.com for the relevant safeguards and a copy, with necessary confidential details protected.
5. Retention
Data is retained only for its purpose and applicable obligations. For a sales enquiry that does not become a contract, our policy is to remove the correspondence within six months of the last substantive exchange unless a longer period is needed for an identified dispute or legal duty. Necessary business and accounting records are retained for their applicable statutory period, classified by record type; there is no universal ten-year period for everything.
For hosted customer content, the default contractual schedule provides a 30-day post-termination export/deletion window and expiry of restricted backup copies within a further 35 days. An agreed service-specific schedule may differ and must be disclosed before processing. Deletion duties, lawful holds and technically necessary backup isolation are documented in the DPA.
Operational log retention is set for the service’s security purpose and configuration, recorded in its processing schedule and reviewed for necessity. Request the schedule for your deployment from our privacy contact. Unneeded data is deleted or irreversibly anonymised; a legal hold does not permit unrelated reuse.
6. Your rights
Subject to the relevant conditions, you may request access, correction, deletion, restriction or portability. You may object to processing based on legitimate interests and to direct marketing. Consent can be withdrawn as easily as given, without changing the lawfulness of earlier processing. Contact legal@mindtro.com; we request only proportionate identification where needed and respond within the applicable GDPR period, normally one month, explaining any permitted extension.
You may complain to a competent supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information, or the authority where you live or work. Contacting us first is not a condition for a complaint.
7. Security, children and changes
The security policy describes the required controls and the limits of certification claims. No system can promise absolute security. This website is aimed at organisations and professional contacts, not children; contact us if you believe a child has supplied personal data that should be removed.
We date revisions and provide additional notice where a material change requires it. A changed notice is not consent to a new purpose. Existing customer processing remains governed by the applicable agreement and law.
Questions, notices and requests: legal@mindtro.com. General enquiries: info@mindtro.com, +49 30 166381616.
