Owner and Data Controller
Cortado Mobile Solutions GmbH
Alt-Moabit 91a
10559 Berlin
Germany
Email address of the data protection officer: dataprotection@cortado.com
Owner contact email: info@cortado.com
Types of Data collected
Among the types of Personal Data that cortado.com, mycortado.com collects, by itself or through third parties, there are:
Usage Data; Cookies; email address; first name; last name; Email; Data communicated while using the service; name; device information; geographic position; calendar information; phone number; billing address; shipping address; payment info; purchase history; various types of Data; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example); answers to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position; touch events; gender; VAT Number; company name; profession; country; state; county; ZIP/Postal code; city; field of activity; website; language; username; workplace; Universally unique identifier (UUID); Precise location permission (non-continuous).
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using cortado.com, mycortado.com.
Unless specified otherwise, all Data requested by cortado.com, mycortado.com is mandatory and failure to provide this Data may make it impossible for cortado.com, mycortado.com to provide its services. In cases where cortado.com, mycortado.com specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Any use of Cookies – or of other tracking tools — by cortado.com, mycortado.com or by the owners of third-party services used by cortado.com, mycortado.com serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.
Users are responsible for any third-party Personal Data obtained, published or shared through cortado.com, mycortado.com.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of cortado.com, mycortado.com (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Place
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Retention time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users’ consent.
The purposes of processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:
Hosting and backend infrastructure, Managing support and contact requests, User database management, Registration and authentication, Tag Management, Remarketing and behavioral targeting, Displaying content from external platforms, Managing contacts and sending messages, Contacting the User, Interaction with live chat platforms, Managing data collection and online surveys, Handling activities related to productivity, Advertising, Platform services and hosting, Handling payments, Traffic optimization and distribution, Analytics, SPAM protection, Collection of privacy-related preferences, Connecting Data, Location-based interactions, Data transfer outside the EU, Interaction with external social networks and platforms, Content commenting and Device permissions for Personal Data access.
For specific information about the Personal Data used for each purpose, the User may refer to the section “Detailed information on the processing of Personal Data”.
Device permissions for Personal Data access
Depending on the User's specific device, cortado.com, mycortado.com may request certain permissions that allow it to access the User's device Data as described below.
By default, these permissions must be granted by the User before the respective information can be accessed. Once the permission has been given, it can be revoked by the User at any time. In order to revoke these permissions, Users may refer to the device settings or contact the Owner for support at the contact details provided in the present document.
The exact procedure for controlling app permissions may be dependent on the User's device and software.
Please note that the revoking of such permissions might impact the proper functioning of cortado.com, mycortado.com.
If User grants any of the permissions listed below, the respective Personal Data may be processed (i.e accessed to, modified or removed) by cortado.com, mycortado.com.
Precise location permission (non-continuous)
Used for accessing the User's precise device location. Cortado.com, mycortado.com may collect, use, and share User location Data in order to provide location-based services.
The geographic location of the User is determined in a manner that isn't continuous. This means that it is impossible for cortado.com, mycortado.com to derive the exact position of the User on a continuous basis.
Detailed information on the processing of Personal Data
Personal Data is collected for the following purposes and using the following services:
-
Advertising
This type of service allows User Data to be utilized for advertising communication purposes. These communications are displayed in the form of banners and other advertisements on cortado.com, mycortado.com, possibly based on User interests.
This does not mean that all Personal Data are used for this purpose. Information and conditions of use are shown below.
Some of the services listed below may use Trackers for identifying Users, behavioral retargeting i.e. displaying ads tailored to the User’s interests and behavior, or to measure ads performance. For more information, please check the privacy policies of the relevant services.
Services of this kind usually offer the possibility to opt out of such tracking. In addition to any opt-out feature offered by any of the services below, Users may learn more on how to generally opt out of interest-based advertising within the dedicated section "How to opt-out of interest-based advertising" in this document.
Google Ads conversion tracking (Google Ireland Limited)
Google Ads conversion tracking is an analytics service provided by Google Ireland Limited that connects data from the Google Ads advertising network with actions performed on cortado.com, mycortado.com.
Personal Data processed: Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy.
Meta ads conversion tracking (Meta pixel)
Meta ads conversion tracking (Meta pixel) is an analytics service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing, that connects data from the Meta Audience Network with actions performed on cortado.com, mycortado.com. The Meta pixel tracks conversions that can be attributed to ads on Facebook, Instagram and Meta Audience Network.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy – Opt out; Ireland – Privacy Policy – Opt out.
Facebook Lookalike Audience
Facebook Lookalike Audience is an advertising and behavioral targeting service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing, that uses Data collected through Facebook Custom Audience in order to display ads to Users with similar behavior to Users who are already in a Custom Audience list on the base of their past use of cortado.com, mycortado.com or engagement with relevant content across the Facebook apps and services.
On the base of these Data, personalized ads will be shown to Users suggested by Facebook Lookalike Audience.
Users can opt out of Facebook's use of Trackers for ads personalization by visiting this opt-out page.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out; Ireland – Privacy Policy – Opt Out.
Google Ad Manager (Google Ireland Limited)
Google Ad Manager is an advertising service provided by Google Ireland Limited that allows the Owner to run advertising campaigns in conjunction with external advertising networks that the Owner, unless otherwise specified in this document, has no direct relationship with.
In order to understand Google's use of Data, consult Google's partner policy.
This service uses the “DoubleClick” Cookie, which tracks use of cortado.com, mycortado.com and User behavior concerning ads, products and services offered.
Users may decide to disable all the DoubleClick Cookies by going to: Google Ad Settings.
Personal Data processed: Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy.
Google Ads Similar audiences (Google Ireland Limited)
Similar audiences is an advertising and behavioral targeting service provided by Google Ireland Limited that uses Data from Google Ads Remarketing in order to display ads to Users with similar behavior to Users who are already on the remarketing list due to their past use of cortado.com, mycortado.com.
On the basis of this Data, personalized ads will be shown to Users suggested by Google Ads Similar audiences.
Users who don't want to be included in Similar audiences can opt out and disable the use of advertising Trackers by going to: Google Ad Settings.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out.
LinkedIn Ads
LinkedIn Ads is an advertising service provided by LinkedIn Ireland Unlimited Company or by LinkedIn Corporation, depending on how the Owner manages the Data processing.
Personal Data processed: Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt out; United States – Privacy Policy – Opt out.
LinkedIn conversion tracking (LinkedIn Insight Tag) (LinkedIn Corporation)
LinkedIn conversion tracking (LinkedIn Insight Tag) is an analytics and behavioral targeting service provided by LinkedIn Corporation that connects data from the LinkedIn advertising network with actions performed on cortado.com, mycortado.com. The LinkedIn Insight Tag tracks conversions that can be attributed to LinkedIn ads and enables to target groups of Users on the base of their past use of cortado.com, mycortado.com.
Users may opt out of behavioral targeting features through their device settings, their LinkedIn account settings or by visiting the AdChoices opt-out page.
Personal Data processed: device information; Trackers; Usage Data.
Place of processing: United States – Privacy Policy.
Microsoft Advertising (Microsoft Corporation)
Microsoft Advertising is an advertising service provided by Microsoft Corporation.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out.
X Ads conversion tracking (X Corp.)
X Ads conversion tracking is an analytics service provided by X Corp. that connects data from the X advertising network with actions performed on cortado.com, mycortado.com.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy.
LiveRamp (LiveRamp, Inc.)
LiveRamp is an advertising service provided by LiveRamp, Inc.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy – Opt out.
-
Analytics
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics (Universal Analytics) with anonymized IP (Google Ireland Limited)
Google Analytics (Universal Analytics) is a web analysis service provided by Google Ireland Limited (“Google”). Google utilizes the Data collected to track and examine the use of cortado.com, mycortado.com, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
This integration of Google Analytics anonymizes your IP address. It works by shortening Users' IP addresses within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the complete IP address be sent to a Google server and shortened within the US.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out.
Google Analytics Demographics and Interests reports (Google Ireland Limited)
Google Analytics Demographics and Interests reports is a Google Advertising Reporting feature that makes available demographic and interests Data inside Google Analytics for cortado.com, mycortado.com (demographics means age and gender Data).
Users can opt out of Google's use of cookies by visiting Google's Ads Settings.
Personal Data processed: Trackers; unique device identifiers for advertising (Google Advertiser ID or IDFA, for example).
Place of processing: Ireland – Privacy Policy – Opt Out.
Google Analytics 4 (Google Ireland Limited)
Google Analytics 4 is a web analysis service provided by Google Ireland Limited (“Google”). Google utilizes the Data collected to track and examine the use of cortado.com, mycortado.com, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
In Google Analytics 4, IP addresses are used at collection time and then discarded before Data is logged in any data center or server. Users can learn more by consulting Google’s official documentation.
In order to understand Google's use of Data, consult Google's partner policy.
Personal Data processed: Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out.
Salesviewer
This website uses SalesViewer® technology from SalesViewer® GmbH on the basis of the website operator’s legitimate interests (Section 6 paragraph 1 lit.f GDPR) in order to collect and save data on marketing, market research and optimisation purposes.
In order to do this, a javascript based code, which serves to capture company-related data and according website usage. The data captured using this technology are encrypted in a non-retrievable one-way function (so-called hashing). The data is immediately pseudonymised and is not used to identify website visitors personally
The data stored by Salesviewer will be deleted as soon as they are no longer required for their intended purpose and there are no legal obligations to retain them.
The data recording and storage can be repealed at any time with immediate effect for the future, by clicking on https://www.salesviewer.com/opt-out in order to prevent SalesViewer® from recording your data. In this case, an opt-out cookie for this website is saved on your device. If you delete the cookies in the browser, you will need to click on this link again.
Freshsales tracking
The Freshsales tracking code allows us in our Freshsales customer database to display for existing contacts which pages you have visited, whereby the code is linked to the Cookie Banner and is only loaded if you have agreed to the Analytics/Measurement section.
Recipient of the data: Freshworks Inc, 2950 S. Delaware Street, Suite 201, San Mateo, California 94403, USA.
Leadinfo
We use the lead generation service provided by Leadinfo B.V., Rotterdam, The Netherlands, which recognizes visits of companies to our website based on IP addresses and shows us related publicly available information, such as company names or addresses.
For additional information, please visit www.leadinfo.com. On this page: www.leadinfo.com/en/opt-out you have an opt-out option. In the event of an opt-out, your data will no longer be used by Leadinfo”.
-
Collection of privacy-related preferences
This type of service allows cortado.com, mycortado.com to collect and store Users’ preferences related to the collection, use, and processing of their personal information, as requested by the applicable privacy legislation.
iubenda Cookie Solution (iubenda srl)
The iubenda Cookie Solution allows the Owner to collect and store Users’ preferences related to the processing of personal information, and in particular to the use of Cookies and other Trackers on cortado.com, mycortado.com.
Personal Data processed: Trackers.
Place of processing: Italy – Privacy Policy.
-
Connecting Data
This type of service allows the Owner to connect Data with third-party services disclosed within this privacy policy.
This results in Data flowing through these services, potentially causing the retention of this Data.
Zapier (Zapier, Inc.)
Zapier is a workflow automation service provided by Zapier, Inc. that automates the movement of Data between (third-party) services.
Personal Data processed: city; company name; country; Data communicated while using the service; device information; email address; first name; gender; geographic position; language; last name; phone number; profession; Usage Data; username; VAT Number; workplace; ZIP/Postal code.
Place of processing: United States – Privacy Policy.
-
Contacting the User
Web forms
You can use our web forms to request information, gifts or services, enter raffles or register for our events. Depending on the purpose of the form in question, the following data may be requested: last name, first name, company name, email address, business address and/or home address.
Under certain circumstances, your consent may also be obtained for pictures and videos of the participants to be taken as part of an event for which you register and to be used for publication on the website or on social media channels and also to be stored for this purpose. The photos and videos are used exclusively for public relations purposes by Cortado Holding AG and its subsidiaries.
Contact form (cortado.com, mycortado.com)
By filling in the contact form with their Data, the User authorizes cortado.com, mycortado.com to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.
Personal Data processed: city; company name; country; county; email address; field of activity; first name; gender; last name; phone number; profession; state; VAT Number; website; ZIP/Postal code.
-
Content commenting
Content commenting services allow Users to make and publish their comments on the contents of cortado.com, mycortado.com.
Depending on the settings chosen by the Owner, Users may also leave anonymous comments. If there is an email address among the Personal Data provided by the User, it may be used to send notifications of comments on the same content. Users are responsible for the content of their own comments.
If a content commenting service provided by third parties is installed, it may still collect web traffic data for the pages where the comment service is installed, even when Users do not use the content commenting service.
Boxzilla
Boxzilla is a plugin that uses an information box to point out additional product information. It sets a cookie (boxzilla_box_xxxx), but it does not collect any personal data, which is why it is listed in the category of technically essential cookies.
-
Device permissions for Personal Data access
Cortado.com, mycortado.com requests certain permissions from Users that allow it to access the User's device Data as described below.
Device permissions for Personal Data access (cortado.com, mycortado.com)
Cortado.com, mycortado.com requests certain permissions from Users that allow it to access the User's device Data as summarized here and described within this document.
Personal Data processed: Precise location permission (non-continuous).
-
Displaying content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of cortado.com, mycortado.com and interact with them.
This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
Font Awesome (Fonticons, Inc. )
Font Awesome is a typeface visualization service provided by Fonticons, Inc. that allows cortado.com, mycortado.com to incorporate content of this kind on its pages.
Personal Data processed: Usage Data.
Place of processing: United States – Privacy Policy.
YouTube video widget (Google Ireland Limited)
YouTube is a video content visualization service provided by Google Ireland Limited that allows cortado.com, mycortado.com to incorporate content of this kind on its pages.
Personal Data processed: Cookies; Usage Data.
Place of processing: Ireland – Privacy Policy.
URL shortening using Bitly
Bitly's URL or link shortener converts long URLs into shorter, more readable links. When a user clicks on the shortened version of a link, he/she is automatically redirected to the target URL. Only the IP addresses of the users who click on a link are collected as personal data.
Place of processing: USA, in particular Amazon Web Services and Google Cloud for hosting (aws.amazon.com, cloud.google.com), Auto Pilot, Mailgun and Marketo for email communication (autopilotapp.com, mailgun.com, marketo.com)
Calendly widget (Calendly, LLC)
Calendly widget is a calendar content visualization service provided by Calendly, LLC that allows cortado.com, mycortado.com to incorporate content of this kind on its pages.
Personal Data processed: calendar information; device information; email address; geographic position; name.
Place of processing: United States – Privacy Policy.
YouTube video widget (Privacy Enhanced Mode) (Google Ireland Limited)
YouTube is a video content visualization service provided by Google Ireland Limited that allows cortado.com, mycortado.com to incorporate content of this kind on its pages.
This widget is set up in a way that ensures that YouTube won't store information and cookies about Users on cortado.com, mycortado.com unless they play the video.
Personal Data processed: Trackers; Universally unique identifier (UUID); Usage Data.
Place of processing: Ireland – Privacy Policy.
Google Fonts
Google Fonts is a typeface visualization service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing, that allows cortado.com, mycortado.com to incorporate content of this kind on its pages.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Synthesia video generator (Synthesia Limited)
Synthesia is a service provided by Synthesia Limited (Kent House, 14-17 Market Place, London, W1W 8AJ, United Kingdom) for AI-powered video generation and visualization of video content that allows cortado.com, mycortado.com to incorporate content of this kind on its pages.
Personal Data processed: cookies, usage data.
Place of processing: USA (Amazon Web Services) – Privacy Policy:
https://www.synthesia.io/legal/privacy-policy
-
Handling activities related to productivity
This type of service helps the Owner to manage tasks, collaboration and, in general, activities related to productivity. In using this type of service, Data of Users will be processed and may be retained, depending on the purpose of the activity in question.
These services may be integrated with a wide range of third-party services disclosed within this privacy policy to enable the Owner to import or export Data needed for the relative activity.
Calendly (Calendly, LLC)
Calendly is a service provided by Calendly, LLC, that facilitates online scheduling of appointments.
Personal Data processed: device information; email address; geographic position; name.
Place of processing: United States – Privacy Policy.
-
Handling payments
Unless otherwise specified, cortado.com, mycortado.com processes any payments by credit card, bank transfer or other means via external payment service providers. In general and unless where otherwise stated, Users are requested to provide their payment details and personal information directly to such payment service providers. Cortado.com, mycortado.com isn't involved in the collection and processing of such information: instead, it will only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.
ChargeBee (ChargeBee Inc.)
ChargeBee is a payment service provided by ChargeBee Inc.
Personal Data processed: billing address; email address; first name; last name; payment info; phone number; purchase history; shipping address; Trackers; Usage Data; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Stripe
Stripe is a payment service provided by Stripe Inc, Stripe Technology Europe Ltd or by Stripe Payments Ltd, depending on how the Owner manages the Data processing.
Personal Data processed: billing address; email address; first name; last name; payment info; purchase history; Trackers; Usage Data; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy; United Kingdom – Privacy Policy.
-
Hosting and backend infrastructure
This type of service has the purpose of hosting Data and files that enable cortado.com, mycortado.com to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of cortado.com, mycortado.com.
Some services among those listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Amazon Web Services (AWS) (Amazon Web Services, Inc.)
Amazon Web Services (AWS) is a hosting and backend service provided by Amazon Web Services, Inc.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Germany – Privacy Policy.
Microsoft Azure (Microsoft Corporation)
Microsoft Azure is a hosting service provided by Microsoft Corporation.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy; Germany – Privacy Policy.
WP Engine
The websites of Cortado including the online shop are hosted by WP Engine Inc. WP Engine only provides the web server platform. The management of the data, including encryption, however, is the exclusive responsibility of Cortado.
Place of processing: United States - (https://wpengine.com/legal/privacy/)
-
Interaction with external social networks and platforms
This type of service allows interaction with social networks or other external platforms directly from the pages of cortado.com, mycortado.com.
The interaction and information obtained through cortado.com, mycortado.com are always subject to the User’s privacy settings for each social network.
This type of service might still collect traffic data for the pages where the service is installed, even when Users do not use it.
It is recommended to log out from the respective services in order to make sure that the processed data on cortado.com, mycortado.com isn’t being connected back to the User’s profile.
Facebook Like button and social widgets
The Facebook Like button and social widgets are services allowing interaction with the Facebook social network provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing,
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Twitter Tweet button and social widgets (X Corp.)
The Twitter Tweet button and social widgets are services allowing interaction with the Twitter social network provided by X Corp.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy.
-
Interaction with live chat platforms
This type of service allows Users to interact with third-party live chat platforms directly from the pages of cortado.com, mycortado.com, in order to contact and be contacted by cortado.com, mycortado.com‘s support service.
If one of these services is installed, it may collect browsing and Usage Data in the pages where it is installed, even if the Users do not actively use the service. Moreover, live chat conversations may be logged.
Freshchat Widget (Freshworks, Inc.)
The Freshchat Widget is a service for interacting with the Freshchat live chat platform provided by Freshworks, Inc.
Personal Data processed: Data communicated while using the service; email address; Tracker; Usage Data.
Place of processing: United States – Privacy Policy.
AI chatbot
The AI chatbot is a service for interacting with the live chat platform of Chatbase.co Inc, 4700 Keele Street, 215 Bergeron Centre, Toronto, ON, Canada, M3J 1P3.
Processed personal data: Data communicated when using the service; email address; Tracker; Usage Data.
Place of processing: United States - Privacy Policy: https://www.chatbase.co/legal/privacy
-
Location-based interactions
Geolocation (cortado.com, mycortado.com)
Cortado.com, mycortado.com may collect, use, and share User location Data in order to provide location-based services.
Most browsers and devices provide tools to opt out from this feature by default. If explicit authorization has been provided, the User’s location data may be tracked by cortado.com, mycortado.com.
Personal Data processed: geographic position.
-
Managing contacts and sending messages
This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with the User.
These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.
Mailjet (SAS Mailjet)
Mailjet is an email address management and message sending service provided by SAS Mailjet.
Personal Data processed: email address; first name; last name.
Place of processing: France – Privacy Policy.
Inxmail
Inxmail is a software for personalized newsletters and automated email campaigns. It exchanges data with other systems such as the customer database, the online store and the content management system of the websites.
Place of processing: Berlin/Germany (Cortado Holding AG)
Quickmail
Quickmail is an email program of the company HCG Partners GmbH (Blegistrasse 17a, 6340 Baar, Switzerland), which is used for sending product information and newsletters as well as for customer acquisition via email.
Place of processing: USA, in particular Amazon Web Services (aws.amazon.com), Helpscout (www.helpscout.net), Zopim (www.zopim.com), Google (www.goole.com), Heroku (www.heroku.com), Salesforce (www.salesforce.com)
-
Managing data collection and online surveys
This type of service allows cortado.com, mycortado.com to manage the creation, deployment, administration, distribution and analysis of online forms and surveys in order to collect, save and reuse Data from any responding Users.
The Personal Data collected depend on the information asked and provided by the Users in the corresponding online form.
These services may be integrated with a wide range of third-party services to enable the Owner to take subsequent steps with the Data processed - e.g. managing contacts, sending messages, analytics, advertising and payment processing.
Surveys
thermistat.io is a survey platform that works with only one question per survey and an optional feedback box. Here thermistat.io creates a single Net Promoter Score (NPS).
thermostat.io may process the following personal information from you:
• Contact information, such as name, email address, mailing address, or phone number
• Demographic information, such as age, education, gender, interests and zip code
• Billing information, such as credit card number and billing address
• Unique identifiers, such as username, account number or password
• Geo location based on IP address
• Information about your business, such as company name, company size, business type
• If you send a support request via email thermostat.io will collect your name and email address
• Affiliate or referral IDs if you participate in any affiliate/referral programs
• Software event information such as software crash logs, application IDs, unique device identifiers, system activity, and hardware settings
• Information passed to thermostat.io from integrations with third party services you have authorized to connect with the Services of thermostat.io
Place of processing: USA, in particular Amazon Web Services for hosting (aws.amazon.com) and Rackspace for email delivery (rackspace.com).
-
Managing support and contact requests
This type of service allows cortado.com, mycortado.com to manage support and contact requests received via email or by other means, such as the contact form.
The Personal Data processed depend on the information provided by the User in the messages and the means used for communication (e.g. email address).
Freshdesk (Freshworks, Inc.)
Freshdesk is a support and contact request management service provided by Freshworks, Inc.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
-
Platform services and hosting
These services have the purpose of hosting and running key components of cortado.com, mycortado.com, therefore allowing the provision of cortado.com, mycortado.com from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data.
Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Apple App Store (Apple Inc.)
Cortado.com, mycortado.com is distributed on Apple's App Store, a platform for the distribution of mobile apps, provided by Apple Inc.
By virtue of being distributed via this app store, Apple collects basic analytics and provides reporting features that enables the Owner to view usage analytics data and measure the performance of cortado.com, mycortado.com. Much of this information is processed on an opt-in basis.
Users may opt-out of this analytics feature directly through their device settings. More information on how to manage analysis settings can be found on this page.
Personal Data processed: Usage Data.
Place of processing: United States – Privacy Policy.
Google Play Store (Google Ireland Limited)
Cortado.com, mycortado.com is distributed on the Google Play Store, a platform for the distribution of mobile apps, provided by Google Ireland Limited.
By virtue of being distributed via this app store, Google collects usage and diagnostics data and share aggregate information with the Owner. Much of this information is processed on an opt-in basis.
Users may opt-out of this analytics feature directly through their device settings. More information on how to manage analysis settings can be found on this page.
Personal Data processed: Usage Data.
Place of processing: Ireland – Privacy Policy.
Wix (Wix.com, Ltd.)
Wix is a platform provided by Wix.com, Ltd. that allows the Owner to build, run and host cortado.com, mycortado.com.
Wix is highly customizable and can host websites from simple blogs to complex e-commerce platforms.
Personal Data processed: billing address; device information; email address; first name; last name; payment info; phone number; shipping address; Trackers; Usage Data.
Place of processing: Israel – Privacy Policy.
Mobile Device Management
Cortado passes data on to Apple or Google during device registration and app configuration.
1. Apple Push Notification service (APNs)
This is used to tell the Apple iOS or iPadOS device to connect to the Cortado MDM backend and retrieve their MDM commands.
2. Automated Device Enrollment (ADE)
Cortado backend sends data to the ADE server, to Assign an Apple iOS or iPadOS device to an ADE Profile, that specifies how the enrollment process is configured.
3. Volume Purchase Program (VPP)
Cortado backend sends data to the Apple App and Book Management API. This is used to assign apps and books to a Apple iOS or iPadOS device.
4. Enterprise Mobility Management (EMM)
Cortado backend sends data to the Google Play EMM API.
For details see: https://support.cortado.com/en/support/solutions/articles/43000708075-data-security-and-sharing
-
Registration and authentication
By registering or authenticating, Users allow cortado.com, mycortado.com to identify them and give them access to dedicated services.
Depending on what is described below, third parties may provide registration and authentication services. In this case, cortado.com, mycortado.com will be able to access some Data, stored by these third-party services, for registration or identification purposes.
Some of the services listed below may also collect Personal Data for targeting and profiling purposes; to find out more, please refer to the description of each service.
Google OAuth (Google Ireland Limited)
Google OAuth is a registration and authentication service provided by Google Ireland Limited and is connected to the Google network.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
ID Server
For downloads and the use of certain services, you must first log on to our Identity (ID) Server and provide personal information. The data to be provided include: first and last name, company name, phone number, email address and country. Cortado does not store passwords in plain text, but only a hash value of them.
Linkedin OAuth (LinkedIn Corporation)
Linkedin Oauth is a registration and authentication service provided by Linkedin Corporation and is connected to the Linkedin social network.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
OneDrive OAuth (Microsoft Corporation)
OneDrive OAuth is a registration and authentication service provided by Microsoft Corporation and is connected to the OneDrive network.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Facebook Authentication
Facebook Authentication is a registration and authentication service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing, and is connected to the Facebook social network.
Personal Data processed: Trackers; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
Facebook Oauth
Facebook Oauth is a registration and authentication service provided by Meta Platforms, Inc. or by Meta Platforms Ireland Limited, depending on how the Owner manages the Data processing, and is connected to the Facebook social network.
Personal Data processed: Trackers; various types of Data.
Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.
-
Remarketing and behavioral targeting
This type of service allows cortado.com, mycortado.com and its partners to inform, optimize and serve advertising based on past use of cortado.com, mycortado.com by the User.
This activity is facilitated by tracking Usage Data and by using Trackers to collect information which is then transferred to the partners that manage the remarketing and behavioral targeting activity.
Some services offer a remarketing option based on email address lists.
In addition to any opt-out feature provided by any of the services below, Users may opt out by visiting the Network Advertising Initiative opt-out page.
Users may also opt-out of certain advertising features through applicable device settings, such as the device advertising settings for mobile phones or ads settings in general.
LinkedIn Website Retargeting (LinkedIn Corporation)
LinkedIn Website Retargeting is a remarketing and behavioral targeting service provided by LinkedIn Corporation that connects the activity of cortado.com, mycortado.com with the LinkedIn advertising network.
Personal Data processed: Cookies; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out.
Facebook Remarketing
Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc. or by Facebook Ireland Ltd, depending on how the Owner manages the Data processing, that connects the activity of cortado.com, mycortado.com with the Facebook advertising network.
Personal Data processed: Tracker; Usage Data.
Place of processing: United States – Privacy Policy – Opt Out; Ireland – Privacy Policy – Opt Out.
Google Ads Remarketing (Google Ireland Limited)
Google Ads Remarketing is a remarketing and behavioral targeting service provided by Google Ireland Limited that connects the activity of cortado.com, mycortado.com with the Google Ads advertising network and the DoubleClick Cookie.
In order to understand Google's use of Data, consult Google's partner policy.
Users can opt out of Google's use of Trackers for ads personalization by visiting Google's Ads Settings.
Personal Data processed: Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy – Opt Out.
Twitter Remarketing (X Corp.)
Twitter Remarketing is a remarketing and behavioral targeting service provided by X Corp. that connects the activity of cortado.com, mycortado.com with the Twitter advertising network.
Personal Data processed: Trackers; Usage Data.
Place of processing: United States – Privacy Policy.
-
SPAM protection
This type of service analyzes the traffic of cortado.com, mycortado.com, potentially containing Users' Personal Data, with the purpose of filtering it from parts of traffic, messages and content that are recognized as SPAM.
Google reCAPTCHA (Google Ireland Limited)
Personal Data processed: answers to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position; touch events; Trackers; Usage Data.
Place of processing: Ireland – Privacy Policy.
-
Tag Management
This type of service helps the Owner to manage the tags or scripts needed on cortado.com, mycortado.com in a centralized fashion.
This results in the Users' Data flowing through these services, potentially resulting in the retention of this Data.
Google Tag Manager (Google Ireland Limited)
Google Tag Manager is a tag management service provided by Google Ireland Limited.
Personal Data processed: Usage Data.
Place of processing: Ireland – Privacy Policy.
-
Traffic optimization and distribution
This type of service allows cortado.com, mycortado.com to distribute their content using servers located across different countries and to optimize their performance.
Which Personal Data are processed depends on the characteristics and the way these services are implemented. Their function is to filter communications between cortado.com, mycortado.com and the User's browser.
Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information of the User are transferred.
Cloudflare (Cloudflare Inc.)
Cloudflare is a traffic optimization and distribution service provided by Cloudflare Inc.
The way Cloudflare is integrated means that it filters all the traffic through cortado.com, mycortado.com, i.e., communication between cortado.com, mycortado.com and the User's browser, while also allowing analytical data from cortado.com, mycortado.com to be collected.
Personal Data processed: Trackers; various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
-
User database management
This type of service allows the Owner to build user profiles by starting from an email address, a personal name, or other information that the User provides to cortado.com, mycortado.com, as well as to track User activities through analytics features. This Personal Data may also be matched with publicly available information about the User (such as social networks' profiles) and used to build private profiles that the Owner can display and use for improving cortado.com, mycortado.com.
Some of these services may also enable the sending of timed messages to the User, such as emails based on specific actions performed on cortado.com, mycortado.com.
Freshsales (Freshworks, Inc.)
Freshsales is a User database management service provided by Freshworks, Inc.
Personal Data processed: various types of Data as specified in the privacy policy of the service.
Place of processing: United States – Privacy Policy.
Drip (Drip Global, Inc.)
Drip is a User database management service provided by Drip Global, Inc. Drip leverages the User’s email address, which it can combine with Data that is gathered from cortado.com, mycortado.com and other sources (if any, indicated within this privacy policy), to enable cortado.com, mycortado.com to set up automations and communicate with Users in a personalized context and timing.
Personal Data processed: Email; Tracker; Usage Data.
Place of processing: United States – Privacy Policy.
Information on opting out of interest-based advertising
In addition to any opt-out feature provided by
any of the services listed in this document, Users may learn more on
how to generally opt out of interest-based advertising within the
dedicated section of the Cookie Policy.
Further information about the processing of Personal Data
-
External connections from mycortado.com
1. Cookies
When you visit mycortado.com, cookies are stored in your Internet browser; these are small files that contain a specific character string. Some cookies are used to log in to the Cortado cloud service, others are used to protect against SPAM or attacks by third parties. Other cookies are used to temporarily store your login data and usage preferences. The cookies can be identified in your browser settings by the string mycortado.com in the name of the relevant cookie container. Only the SPAM protection cookie _GRECAPTCHA uses the container google.com.
All cookies are essential, meaning that they are technically necessary for the provision of the Cortado cloud service. The only exception: Those cookies that are used to determine the Net Promoter Score are used for statistical purposes (a corresponding question is asked after login).
Cookies with external connections:
• SPAM protection: _GRECAPTCHA (google.com)
• Determining the Net Promoter Score: thermostatio_hide, thermostatio_pl (thermostat.io)
2. Other external connections
In addition to data transmission using the above-mentioned cookies, when using the Cortado cloud service, data is transmitted to the following destinations or connections are established for the purpose of retrieving data (but not for the transmission of personal data):
• Proxy server as cloud service for protec-tion against hacker attacks: cloudflare.com
• Infrastructure monitoring: betteruptime.com, betterstack.com
• Tools, e.g. for a uniform appearance (such as fonts and themes): google.com, gstatic.com, withgoogle.com
• Downloading website content (content delivery network): datatables.net
For more detailed information, you can request a privacy policy for the Cortado cloud service from dataprotection@cortado.com.
-
User identification via a universally unique identifier (UUID)
Cortado.com, mycortado.com may track Users by storing a so-called universally unique identifier (or short UUID) for analytics purposes or for storing Users' preferences. This identifier is generated upon installation of this Application, it persists between Application launches and updates, but it is lost when the User deletes the Application. A reinstall generates a new UUID.
Cookie Policy
Cortado.com, mycortado.com uses Trackers. To learn more, Users may consult the Cookie Policy.
This section applies to all Users in the European Union, according to the General Data Protection Regulation (the “GDPR”), and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy. Further details regarding the categories of Data processed, the purposes of processing, the categories of recipients of the Personal Data, if any, and further information about Personal Data can be found in the section titled “Detailed information on the processing of Personal Data” within this document.
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes.
- provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
- processing is necessary for compliance with a legal obligation to which the Owner is subject;
- processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
- processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Further information about retention time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users’ consent.
Therefore:
- Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
- Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to fulfil a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
The rights of Users based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights regarding their Data processed by the Owner.
In particular, Users have the right to do the following, to the extent permitted by law:
- Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
- Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
- Access their Data. Users have the right to learn if Data is being processed by the Owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
- Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
- Restrict the processing of their Data. Users have the right to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
- Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their Data from the Owner.
- Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
- Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
Users are also entitled to learn about the legal basis for Data transfers abroad including to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
Details about the right to object to processing
Where Personal Data is processed for a public interest, in the exercise of an official authority vested in the Owner or for the purposes of the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the User objects to processing for direct marketing purposes, the Personal Data will no longer be processed for such purposes. To learn whether the Owner is processing Personal Data for direct marketing purposes, Users may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users’ request, the Owner will inform them about those recipients.
Transfer of Personal Data outside of the European Union
Data transfer abroad based on standard contractual clauses
If this is the legal basis, the transfer of Personal Data from the EU to third countries is carried out by the Owner according to “standard contractual clauses” provided by the European Commission.
This means that Data recipients have committed to process Personal Data in compliance with the data protection standards set forth by EU data protection legislation. For further information, Users are requested to contact the Owner through the contact details provided in the present document.
Data transfer to countries that guarantee European standards
If this is the legal basis, the transfer of Personal Data from the EU to third countries is carried out according to an adequacy decision of the European Commission.
The European Commission adopts adequacy decisions for specific countries whenever it considers that country to possess and provide Personal Data protection standards comparable to those set forth by EU data protection legislation. Users can find an updated list of all adequacy decisions issued on the European Commission's website.
Additional information about Data collection and processing
Legal action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of cortado.com, mycortado.com or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
Additional information about User's Personal Data
In addition to the information contained in this privacy policy, cortado.com, mycortado.com may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, cortado.com, mycortado.com and any third-party services may collect files that record interaction with cortado.com, mycortado.com (System logs) or use other Personal Data (such as the IP Address) for this purpose.
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within cortado.com, mycortado.com and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Usage Data
Information collected automatically through cortado.com, mycortado.com (or third-party services employed in cortado.com, mycortado.com), which can include: the IP addresses or domain names of the computers utilized by the Users who use cortado.com, mycortado.com, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
User
The individual using cortado.com, mycortado.com who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of cortado.com, mycortado.com. The Data Controller, unless otherwise specified, is the Owner of cortado.com, mycortado.com.
cortado.com, mycortado.com (or this Application)
The means by which the Personal Data of the User is collected and processed.
Service
The service provided by cortado.com, mycortado.com as described in the relative terms (if available) and on this site/application.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User's browser.
Tracker
Tracker indicates any technology - e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that enables the tracking of Users, for example by accessing or storing information on the User’s device.
Email
Provides access to the User's primary email address.
Legal information
This privacy policy relates solely to cortado.com, mycortado.com, if not stated otherwise within this document.