Privacy Policy
We are very pleased that you are interested in our services. This Privacy Policy informs you about the nature, scope and purpose of the personal data we process on the website https://cemas.io/ and its respective subdomains (hereafter referred to as the 'Website'), as well as your rights as a data subject.
I. General Information
1. Data Controller
Unless otherwise specified in this Privacy Policy, the controller responsible for data processing pursuant to Art. 4(7) GDPR is
CeMAS - Center für Monitoring, Analyse und Strategie gGmbH
Lietzenburger Straße 107, 10707 Berlin (hereinafter “we” or “us”).
2. Contact Information
If you have any questions or suggestions regarding data protection or the exercise of your rights as a data subject, please contact us at any time using the following contact information:
CeMAS - Center for Monitoring, Analysis, and Strategy gGmbH Lietzenburger Straße 107 10707 Berlin
Email address: info@cemas.io
Loading fingerprint…You can reach our Data Protection Officer by email at:
JBB Data Consult GmbH
Friedrichstraße 95, 10117 Berlin
Email address: datenschutz@cemas.io
3. Hosting and General Use of the Website
Purposes: When you visit our website, we process certain data to enable you to use the website and its features. You can generally use our website without providing any personal data, for example by not registering. However, certain technical data is generated during use that may potentially identify you as an individual. Data processed in connection with use of the website typically includes your IP address, which is necessary to deliver content from our online services to your device. It also includes content data (e.g. entries in online forms, language selection, search functions or similar), usage data (e.g. which webpages you visit, your interest in content and access times) and meta/communication data (e.g. device information).
When you visit our website, we also store certain data in log files.
We use the Contentful service, provided by Contentful GmbH, to display content. When you use our website, Contentful processes the IP address, user agent and browser information in particular.
Recipients: The aforementioned data is processed within the scope of the web hosting and infrastructure services provided by the following providers:
Host Europe GmbH, Friesenplatz 4, 50672 Köln
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723
Transfers to third countries: Data may be transferred to third countries, in particular the United States. Vercel Inc. is certified under the Data Privacy Framework, ensuring an adequate level of protection during processing. Standard contractual clauses have also been concluded.
Privacy Policy: https://vercel.com/legal/privacy-policyFly.io, Inc. 2261 Market St, #4990, San Francisco, CA 94114
Transfers to third countries: Data may be transferred to third countries, in particular the United States. Fly.io, Inc. is certified under the Data Privacy Framework, ensuring an adequate level of protection during processing. Standard contractual clauses have also been concluded.
Privacy Policy: https://fly.io/legal/privacy-policy/Contentful GmbH, Max-Urich-Str. 3, 13355 Berlin
Transfers to third countries: Data may be transferred to third countries, in particular the United States. Standard contractual clauses have been implemented.
Privacy Policy: https://www.contentful.com/legal/privacy-and-data-protection/privacy-notice/
We have data processing agreements in place with all service providers in accordance with Art. 28 GDPR.
Legal basis: The processing of this data is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and efficient provision of our online services.
Retention period: Log files are stored for a limited period (usually a maximum of 90 days) for security reasons and are subsequently deleted.
4. Analysis
Purposes: When you use our website, we process your IP address and user agent to create an identifier and use it to analyze your use of our website. The analysis is conducted exclusively in aggregated and non-personal form. The analysis serves to gain general insights into the use of our site, to optimize and improve it, and, if necessary, to resolve issues. Your use of our site cannot be tracked over multiple days, as a new identifier is assigned to you after each day. It is not possible to link the identifiers.
In addition, we use the social media management and analytics tool Metricool. It enables us to plan, analyze, and manage our digital presence as well as our corporate profiles. User behavior is evaluated and presented in the form of statistical reports and heatmaps. On this basis, we can present our products and services in a targeted manner, particularly on social media platforms, and optimize their presentation.
Recipients: The processing of the aforementioned data is carried out on our instructions by the service Plausible, provided by Plausible Insights OÜ, Västriku tn 2, 50403, Tartu, Estonia. We have entered into a data processing agreement with Plausible Insights OÜ in accordance with Art. 28 GDPR.
To optimize our social media activities, we use the service Metricool, METRICOOL SOFTWARE, SL, located at C / Téllez, No. 12, Entreplanta H, 28007, Madrid, Spain. We have also entered into a data processing agreement with METRICOOL Software in accordance with Art. 28 GDPR. Privacy Policy: Metricool Privacy Policy.
Legal basis: The processing of this data is based on Art. 6(1)(f) GDPR. Our legitimate interest here lies in the purposes mentioned above.
Retention period: After one day, the identifiers are changed, thereby anonymizing the previously collected data. Otherwise, we store data for as long as necessary for the aforementioned analysis and optimization purposes.
5. Contact via Email
Purposes: When contacting us via email, the information provided by the inquiring individuals is processed to the extent necessary to respond to contact inquiries and any requested actions. During this communication process, we process, in particular, master data (e.g., name, address), contact data (e.g., email), and content data.
We use technologies that allow us to measure interactions (e.g., email opens, click-through rates). We use this data for general statistical analysis as well as to optimize and further develop our content and customer communications. This is done using small graphics embedded in the mails(so-called pixels).
Recipients:
CiviCRM instance hosted by civilisten GmbH, Schwedenstraße 15a, 13357 Berlin
Postmark, ActiveCampaign, LLC, 1 N Dearborn St FL 5, Chicago, IL 60602
Transfers to third countries: Data may be transferred to third countries, in particular the United States. ActiveCampaign is certified under the Data Privacy Framework, ensuring an adequate level of protection during processing. Standard contractual clauses have also been concluded.
Privacy Policy: https://postmarkapp.com/eu-privacy#security-and-privacy
A data processing agreement pursuant to Art. 28 GDPR has been concluded with ActiveCampaign LLC.
Legal basis: The legal basis for this is Art. 6(1)(f) GDPR, whereby our legitimate interest lies in effectively responding to inquiries.
Retention period: We delete the data processed for this purpose 12 months after the end of active communication with you.
6. Formspree Contact Form
Purposes: On our website, you can reach us via the contact form provided by Formspree Inc., 309 E 21st St, Rm 3331, Austin, Texas, 78705, United States (“Formspree”) and contact us regarding various topics. We typically use our contact form to receive general inquiries and requests to participate in events. When you use the contact form, we process your personal data, specifically the following information:
Last name & First name (optional)
Email address
Subject
We also process all information you provide to us via the contact form. We use Formspree to check the entered information for spam, forward it to our email provider, and ultimately receive your message.
Recipients: When you use our contact form, the aforementioned data is transmitted to our email provider via Formspree’s API on our instructions (Art. 28 GDPR). Formspree does not store the data permanently.
Legal basis: The processing of your personal data when responding to your message is carried out exclusively to answer your inquiry. The legal basis for this is Art. 6(1)(f) GDPR. Our legitimate interest lies in the aforementioned purpose.
Retention period: If you contact us via our contact form, we will store your data for a period of 12 months following the end of our active communication and will then delete the data immediately.
7. Newsletter
Purposes: If you are interested in our expertise and offerings, you have the option to subscribe to our newsletters. If you wish to subscribe to a newsletter at , you must enter your email address in a form on our website. If you have subscribed to an email newsletter, we process your data to send you the email newsletter.
In our newsletters, we use technologies that allow us to measure interactions with the newsletters (e.g., email open rates, click-through rates). We use this data for general statistical analysis as well as to optimize and further develop our content and customer communications. This is done using small graphics embedded in the newsletters (so-called pixels).
Recipients:
CiviCRM instance hosted by civilisten GmbH, Schwedenstraße 15a, 13357 Berlin
Postmark, ActiveCampaign, LLC, 1 N Dearborn St FL 5, Chicago, IL 60602
Transfer to third countries: Data may be transferred to third countries, in particular the United States. ActiveCampaign is certified under the Data Privacy Framework, ensuring an adequate level of protection during processing. Standard contractual clauses have also been concluded.
Privacy Policy: https://postmarkapp.com/eu-privacy#security-and-privacy
A data processing agreement pursuant to Art. 28 GDPR has been concluded with ActiveCampaign LLC
Legal basis: The legal basis for this data processing is your consent pursuant to Art. 6(1)(a) GDPR.
Right to Withdraw Consent: You may withdraw your consent at any time, effective immediately, by contacting us at info@cemas.io or by using the unsubscribe link in any of the messages we have sent you.
Retention period: After you revoke your consent, your data will no longer be used for sending messages; however, we will retain the data regarding your opt-in for a period of an additional 3 years after revocation for verification purposes and to defend ourselves against any potential legal claims.
8. Ensuring Security and Integrity
Purposes: Measures are taken to protect the website and its integrity. To this end, we use the features of Friendly Captcha to automatically filter requests submitted via our website forms (contact, newsletter sign-up). With the help of this feature, it is possible to distinguish whether an entry was made by a natural person or abusively through machine and/or automated processing.
Categories of data: Friendly Captcha does not store any personal data of the visitor. Data that could identify the visitor, such as IP addresses, is anonymized through one-way hashing.
Recipient: Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee, Germany. For more information, please see: Privacy Policy for End Users - Friendly Captcha.
Legal basis: Legitimate interest in the secure operation of our website (Art. 6(1)(f) GDPR).
Retention period: No data is stored in the browser’s permanent memory.
9. Twingle Donation Form
Purposes: On our website, you can donate to us using the form provided by twingle GmbH, Prinzenallee 74, 13357 Berlin (twingle). To donate to us, you must enter some information into the form:
Donation amount
Frequency
Personal or gift donation
Payment method
IBAN (optional)
Last name - First name (optional)
Email address (optional)
Phone number (optional)
We then use this data to process the donation and, if desired, to issue a donation receipt.
Recipients: The processing of the data is carried out on our behalf by twingle. We have entered into a data processing agreement with twingle in accordance with Art. 28 GDPR. We remain responsible for the processing of your personal data as described.
Legal basis: Your data is processed in order to receive and process your donation. The legal basis is Art. 6(1)(b) of the GDPR.
Retention period: Your transaction data from the entries in the donation form will be processed in accordance with statutory retention periods and subsequently deleted.
10. Job Applications
Purposes: You may apply to us for open positions or on your own initiative. We then process the information provided in your application to evaluate your application and decide whether we can offer you a position with us.
Recipients: Your application will be reviewed and evaluated by the relevant personnel internally. We do not share your application documents with external parties.
Legal basis: The legal basis for processing is Section 26(1) of the Federal Data Protection Act (BDSG).
Retention period: We process your data for the stated purposes until a decision regarding your employment is made. We then retain your data for a period of 6 months to defend against any potential legal claims.
11. Legal Retention Obligations
Purposes: We are subject to statutory retention obligations for certain documents, which we must comply with. These documents may also contain personal data, e.g., if they are contracts, invoices, donation receipts, or business letters. The retention obligations arise from Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO). Documents subject to retention are:
Books and records, inventories, annual financial statements, individual financial statements pursuant to Section 325(2a) HGB, consolidated financial statements, management reports, consolidated management reports, the opening balance sheet, as well as the operating instructions and other organizational documents necessary for their understanding, Accounting documents, documents pursuant to Art. 15(1) and Art. 163 of the Union Customs Code.
Received commercial or business correspondence, copies of sent commercial or business correspondence, and other documents, insofar as they are relevant for tax purposes.
Recipients: We may disclose this information to auditors, consultants, or other persons or authorities entrusted with the audit of our accounting records.
Legal basis: The legal basis for this processing is Art. 6(1)(c) GDPR in conjunction with the law requiring us to retain the documents.
Retention period: Specifically, we are required to retain the following documents for the specified periods:
For 10 years: Books and records, inventories, annual financial statements, individual financial statements pursuant to Section 325(2a) HGB, consolidated financial statements, management reports, consolidated management reports, the opening balance sheet, as well as the operating instructions and other organizational documents necessary for their understanding, accounting documents, and documents pursuant to Art. 15(1) and Art. 163 of the Union Customs Code.
For 6 years: Received commercial or business letters, copies of sent commercial or business letters, and other documents, insofar as they are relevant for taxation purposes.
The applicable retention period begins at the end of the calendar year in which the last entry was made in the books of account, the inventory, the opening balance sheet, the annual financial statements, or the management report; or in which the last commercial or business letter was received or sent; or in which the last accounting entry, record, or other document was created.
12. Visiting Our Social Media Profiles
We have profiles on social networks. Our social media accounts complement our website and offer you the opportunity to interact with us. As soon as you access our social media profiles on social networks, the terms and conditions and data processing policies of the respective platforms apply. The data collected about you when using these services is processed by the networks and may also be transferred to countries outside the European Union where there is no adequate level of protection for the processing of personal data.
We generally have no influence over data processing on social networks, as we are users of the network. Information on this, as well as on what data is processed by the social networks and for what purposes the data is used, can be found in the privacy policy of the respective network listed below. We use the following social networks:
a) Twitter
Our page is available at: https://twitter.com/cemas_io
The network operator is: Twitter International Unlimited Company, One Cumberland Place, Fenian Street AX07 IRLAND Dublin 2, D02
Network privacy policy: https://twitter.com/de/privacy
b) Instagram
Our page is available at: https://www.instagram.com/cemas_io/
The network operator is: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
Network Privacy Policy: https://privacycenter.instagram.com/
c) Bluesky
Our page is available at: https://bsky.app/profile/cemas.io
The network operator is: Bluesky Social, PBC, 113 Cherry St, #24821 Seattle, WA 98104, USA.
Network privacy policy: https://bsky.social/about/support/privacy-policy
d) Mastodon
Our page is available at: https://mastodon.social/@cemas_io
The operator of the instance is: Mastodon gGmbH, Mühlenstraße 8a, 14167 Berlin, Germany
Privacy policy of the instance: https://mastodon.social/privacy-policy
e) LinkedIn
Our page is available at: https://de.linkedin.com/company/center-f%C3%BCr-monitoring-analyse-und-strategie
The operator of the instance is: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Privacy policy of the platform: LinkedIn Privacy Policy
f) Joint controllership
We process personal data as the data controller when you send us inquiries via our social media profiles. We process this data to respond to your inquiries, which also constitutes our legitimate interest (Art. 6(1)(f) GDPR).
In addition, we are jointly responsible with the following networks for the following processing activities (Art. 26 GDPR).
When you visit our profile on the LinkedIn network, the network collects aggregated statistics (“Insights data”) generated from certain events logged by its servers when you interact with our profiles and the associated content. We receive these aggregated and anonymous statistics from the network regarding the use of our profile. We are generally unable to link the data to specific users. To a certain extent, we can specify the criteria according to which the network generates these statistics for us. We use these statistics to make our profiles more interesting and informative for you. This also constitutes our legitimate interest (Art. 6(1)(f) GDPR) in the data collection carried out by the respective social network to provide us with statistics.
For more information about this data processing, please refer to the Joint Controller Agreement at: https://legal.linkedin.com/pages-joint-controller-addendum
In all other respects, the network is solely responsible for the processing of your data.
II. Storage and/or Retrieval of Information from a Device
When you use our site, information may be stored on your device or information already stored on it may be retrieved if this is absolutely necessary for our service and we would otherwise be unable to provide the service (Section 25(2) TTDSG). Otherwise, we will only store information on your device or access information already stored on it if you have previously given us your informed consent.
III. Categories of Recipients
Unless explicitly stated otherwise in this privacy notice, only individuals within our company will have access to your personal data. Furthermore, these individuals must be responsible for handling the matters in question and have appropriate access to the IT system. In addition to the departments explicitly mentioned, we only engage external service providers to the extent that we cannot perform the services ourselves or it would not be practical to do so. Data will only be transferred to third countries to the extent that we inform you in this privacy policy about the transfer of your data.
IV. Data Subject Rights
The General Data Protection Regulation guarantees you certain rights that you may exercise against us—provided the legal requirements are met.
Art. 15 GDPR – Right of access by the data subject:
You have the right to request confirmation from us as to whether personal data concerning you is being processed, and if so, what data is being processed and the specific circumstances of the data processing.
Art. 16 GDPR – Right to rectification:
You have the right to request that we rectify any inaccurate personal data concerning you without undue delay. In doing so, you also have the right to request the completion of incomplete personal data—including by means of a supplementary statement—taking into account the purposes of the processing.
Art. 17 GDPR – Right to erasure:
You have the right to request that we erase personal data concerning you without undue delay.
Art. 18 GDPR – Right to restriction of processing:
You have the right to request that we restrict the processing of your personal data.
Art. 20 GDPR – Right to data portability:
You have the right, in cases where processing is based on consent or for the performance of a contract, to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and to transmit this data to another controller without hindrance from us, or to have the data transmitted directly to the other controller, provided this is technically feasible.
Art. 21 GDPR – Right to object:
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is necessary for the purposes of our legitimate interests or for the performance of a task carried out in the public interest, or that is carried out in the exercise of official authority.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
To the extent that we process your personal data for direct marketing purposes, you have the right to object to such processing at any time. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.
Art. 77 GDPR in conjunction with § 19 BDSG – Right to lodge a complaint with a supervisory authority:
You have the right to lodge a complaint with a supervisory authority at any time, in particular in the Member State of your habitual residence, your workplace, or the place of the alleged infringement, if you believe that the processing of your personal data violates applicable law. To the extent that you have given us your consent, you have the right to withdraw this consent at any time. This can be done by email to info@cemas.io. The lawfulness of any processing carried out prior to withdrawal remains unaffected.
V. Obligation to Provide Data
You have no contractual or legal obligation to provide us with personal data. However, without the data you provide, we may not be able to offer you all of our services.
VI. Use of Automated Decision-Making (Including Profiling)
When visiting our website, you will at no time be subject to automated decision-making in connection with the processing of personal data that would have legal effects on you or could otherwise adversely affect you.
VII. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time. We will notify you of any changes by posting them here or by other appropriate means.
Berlin, June 2026