Privacy Policy
We are very pleased about your interest in our studio. Data protection
is of particular importance to micemice. This website can generally
be used without providing any personal data. If you wish to use special
services via our website, however, processing of personal data may
become necessary. If processing of personal data is necessary and there
is no legal basis for such processing, we will generally obtain your
consent.
The processing of personal data — such as the name, address, e-mail
address or telephone number of a data subject — is always carried out in
accordance with the General Data Protection Regulation (GDPR) and the
country-specific data protection provisions applicable to micemice.
By means of this privacy policy we wish to inform the public about the
nature, scope and purpose of the personal data we collect, use and
process, and to inform data subjects of the rights to which they are
entitled.
As the controller, micemice has implemented numerous technical and
organisational measures to ensure the most complete protection possible
of the personal data processed via this website. Nevertheless,
internet-based data transmissions can in principle have security gaps,
so absolute protection cannot be guaranteed. For this reason, every data
subject is free to transmit personal data to us by alternative means,
for example by telephone.
1. Definitions
This privacy policy is based on the terms used by the European
legislator in adopting the GDPR. It is intended to be easy to read and
understand for the public as well as for our clients and business
partners. To ensure this, we would like to explain the terms used in
advance. In this privacy policy we use, among others, the following
terms:
- Personal data means any information relating to an
identified or identifiable natural person (“data subject”). An
identifiable natural person is one who can be identified, directly or
indirectly, in particular by reference to an identifier such as a
name, an identification number, location data, an online identifier or
to one or more factors specific to the physical, physiological,
genetic, mental, economic, cultural or social identity of that natural
person.
- Data subject is any identified or identifiable
natural person whose personal data is processed by the controller.
- Processing is any operation or set of operations
performed on personal data, whether or not by automated means, such as
collection, recording, organisation, structuring, storage, adaptation
or alteration, retrieval, consultation, use, disclosure by
transmission, dissemination or otherwise making available, alignment
or combination, restriction, erasure or destruction.
- Restriction of processing is the marking of stored
personal data with the aim of limiting its processing in the future.
- Profiling is any form of automated processing of
personal data consisting of the use of personal data to evaluate
certain personal aspects relating to a natural person, in particular
to analyse or predict aspects concerning that person’s performance at
work, economic situation, health, personal preferences, interests,
reliability, behaviour, location or movements.
- Pseudonymisation is the processing of personal data
in such a manner that the personal data can no longer be attributed to
a specific data subject without the use of additional information,
provided that such additional information is kept separately and is
subject to technical and organisational measures to ensure that the
personal data is not attributed to an identified or identifiable
natural person.
- Controller is the natural or legal person, public
authority, agency or other body which, alone or jointly with others,
determines the purposes and means of the processing of personal data.
Where the purposes and means of such processing are determined by
Union or Member State law, the controller or the specific criteria for
its nomination may be provided for by Union or Member State law.
- Processor is a natural or legal person, public
authority, agency or other body which processes personal data on
behalf of the controller.
- Recipient is a natural or legal person, public
authority, agency or other body to which the personal data is
disclosed, whether a third party or not. Public authorities which may
receive personal data in the framework of a particular inquiry in
accordance with Union or Member State law are, however, not regarded
as recipients.
- Third party is a natural or legal person, public
authority, agency or body other than the data subject, the controller,
the processor and the persons who, under the direct authority of the
controller or processor, are authorised to process personal data.
- Consent of the data subject is any freely given,
specific, informed and unambiguous indication of the data subject’s
wishes by which they, by a statement or by a clear affirmative action,
signify agreement to the processing of personal data relating to them.
2. Name and address of the controller
The controller within the meaning of the GDPR, other data protection
laws applicable in the Member States of the European Union and other
provisions of a data protection nature is:
micemice — Martin Köhler
Weerthstraße 2
12489 Berlin
Germany
Phone: +49 176 71239389
E-mail: kontakt@micemice.de
Website: www.micemice.de
3. Hosting and server log files
This website is hosted by Cloudflare, Inc., 101 Townsend St., San
Francisco, CA 94107, USA (EU establishment: Cloudflare Germany GmbH,
Rosental 7, 80331 Munich, Germany). Each time this website is accessed by
a data subject or an automated system, a series of general data and
information is collected and stored in the server log files. The
following may be recorded: (1) the browser types and versions used, (2)
the operating system used by the accessing system, (3) the website from
which an accessing system reaches our website (referrer), (4) the
sub-pages accessed on our website, (5) the date and time of access, (6)
an internet protocol address (IP address), (7) the internet service
provider of the accessing system and (8) other similar data and
information that serve to avert danger in the event of attacks on our
information technology systems.
When using this general data and information, micemice does not
draw any conclusions about the data subject. This information is needed
in order to (1) deliver the content of our website correctly, (2)
optimise the content of our website, (3) ensure the long-term
functionality of our information technology systems and the technology
of our website, and (4) provide law enforcement authorities with the
information necessary for prosecution in the event of a cyber attack.
This anonymously collected data and information is therefore evaluated
statistically and with the aim of increasing data protection and data
security, so as ultimately to ensure an optimal level of protection for
the personal data we process. The anonymous data of the server log files
is stored separately from any personal data provided by a data subject.
The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in the
secure and reliable delivery of this website. Cloudflare processes this
data on our behalf under a data processing agreement pursuant to
Art. 28 GDPR. Cloudflare, Inc. is certified under the EU-U.S. Data
Privacy Framework; transfers to the USA are additionally safeguarded by
the EU standard contractual clauses. Further information:
cloudflare.com/privacypolicy.
4. Video streaming (bunny.net)
The videos on this website are delivered by the video platform of
BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia
(“bunny.net”). When a page containing a video is loaded, your browser
establishes a direct connection to bunny.net’s content delivery network
in order to load the video and its preview images; in doing so, your IP
address and the technical data described in section 3 are transmitted
to bunny.net. bunny.net uses this data solely to deliver the videos and
for aggregated, non-personal delivery statistics. No cookies are set for
this purpose.
The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in
presenting our work in high quality without operating our own video
infrastructure. bunny.net is established in the European Union and
processes the data on our behalf under a data processing agreement
pursuant to Art. 28 GDPR. Further information:
bunny.net/privacy.
5. Local storage — no cookies, no tracking
This website does not use cookies, and no tracking or analytics tools
are in use. To remember your display preferences (for example a video
quality you selected), individual values are stored in your browser’s
local storage. These values remain on your device, are not transmitted
to us or to third parties, and can be deleted at any time via your
browser settings. The legal basis is Section 25 (2) No. 2 TDDDG (German
Telecommunications Digital Services Data Protection Act): the storage is
strictly necessary to provide a function you explicitly requested.
6. Contact form and e-mail
If you contact us via the contact form or by e-mail, the data you
provide (your e-mail address, your name if given, and the content of
your message) will be stored for the purpose of handling your enquiry
and any follow-up questions. This data is not passed on to third
parties without your consent. The legal basis is Art. 6 (1) (b) GDPR
where your enquiry relates to a contract or to pre-contractual
measures, and otherwise Art. 6 (1) (f) GDPR — our legitimate interest
in answering enquiries addressed to us. We delete the data once your
enquiry has been fully dealt with, unless statutory retention periods
require longer storage.
Messages sent via the contact form are delivered to our mailbox by the
e-mail service of Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris,
France), which processes the message content and your e-mail address on
our behalf under a data processing agreement pursuant to Art. 28 GDPR
and stores them temporarily for delivery and logging purposes. To
protect the form against automated abuse, your IP address is processed
on our server for a short period (rate limiting, at most one minute);
it is neither stored nor included in the message we receive. The legal
basis for this is Art. 6 (1) (f) GDPR — our legitimate interest in a
secure contact channel. Further information:
brevo.com/legal/privacypolicy.
7. Routine erasure and blocking of personal data
The controller processes and stores personal data of the data subject
only for the period necessary to achieve the purpose of storage, or
where provided for by the European legislator or another legislator in
laws or regulations to which the controller is subject. If the purpose
of storage ceases to apply, or if a storage period prescribed by the
European legislator or another competent legislator expires, the
personal data is routinely blocked or erased in accordance with
statutory provisions.
8. Rights of the data subject
You may exercise any of the following rights at any time by contacting
us using the details given in section 2.
- Right to confirmation. Every data subject has the
right, granted by the European legislator, to obtain from the
controller confirmation as to whether or not personal data concerning
them is being processed.
- Right of access. Every data subject has the right to
obtain from the controller, free of charge and at any time,
information about the personal data stored about them and a copy of
this information. In addition, the European legislator has granted the
data subject access to the following information: the purposes of the
processing; the categories of personal data concerned; the recipients
or categories of recipients to whom the personal data has been or will
be disclosed, in particular recipients in third countries or
international organisations; where possible, the envisaged period for
which the personal data will be stored or, if not possible, the
criteria used to determine that period; the existence of the right to
request rectification or erasure of personal data, restriction of
processing or to object to such processing; the existence of the right
to lodge a complaint with a supervisory authority; where the personal
data is not collected from the data subject, any available information
as to its source; and the existence of automated decision-making,
including profiling, referred to in Art. 22 (1) and (4) GDPR and, at
least in those cases, meaningful information about the logic involved
as well as the significance and the envisaged consequences of such
processing for the data subject. The data subject also has the right
to be informed whether personal data is transferred to a third country
or to an international organisation and, if so, about the appropriate
safeguards relating to the transfer.
- Right to rectification. Every data subject has the
right to obtain from the controller without undue delay the
rectification of inaccurate personal data concerning them. Taking into
account the purposes of the processing, the data subject also has the
right to have incomplete personal data completed, including by means
of providing a supplementary statement.
- Right to erasure (right to be forgotten). Every data
subject has the right to obtain from the controller the erasure of
personal data concerning them without undue delay where one of the
following grounds applies and the processing is not necessary: the
personal data is no longer necessary in relation to the purposes for
which it was collected or otherwise processed; the data subject
withdraws the consent on which the processing is based according to
Art. 6 (1) (a) or Art. 9 (2) (a) GDPR and there is no other legal
ground for the processing; the data subject objects to the processing
pursuant to Art. 21 (1) GDPR and there are no overriding legitimate
grounds for the processing, or the data subject objects pursuant to
Art. 21 (2) GDPR; the personal data has been unlawfully processed; the
personal data must be erased for compliance with a legal obligation in
Union or Member State law to which the controller is subject; or the
personal data was collected in relation to the offer of information
society services referred to in Art. 8 (1) GDPR. Where micemice has
made the personal data public and is obliged pursuant to Art. 17 (1)
GDPR to erase it, micemice will, taking account of available
technology and the cost of implementation, take reasonable steps,
including technical measures, to inform other controllers processing
the published personal data that the data subject has requested the
erasure of any links to, or copies or replications of, that personal
data, insofar as the processing is not necessary.
- Right to restriction of processing. Every data
subject has the right to obtain from the controller restriction of
processing where one of the following applies: the accuracy of the
personal data is contested by the data subject, for a period enabling
the controller to verify its accuracy; the processing is unlawful and
the data subject opposes the erasure of the personal data and requests
the restriction of its use instead; the controller no longer needs the
personal data for the purposes of the processing, but it is required
by the data subject for the establishment, exercise or defence of
legal claims; or the data subject has objected to processing pursuant
to Art. 21 (1) GDPR pending the verification whether the legitimate
grounds of the controller override those of the data subject.
- Right to data portability. Every data subject has the
right to receive the personal data concerning them, which they have
provided to a controller, in a structured, commonly used and
machine-readable format, and to transmit that data to another
controller without hindrance from the controller to which the personal
data was provided, as long as the processing is based on consent
pursuant to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR or on a contract
pursuant to Art. 6 (1) (b) GDPR, and the processing is carried out by
automated means, unless the processing is necessary for the
performance of a task carried out in the public interest or in the
exercise of official authority vested in the controller. In exercising
this right, the data subject also has the right to have the personal
data transmitted directly from one controller to another, where
technically feasible and where this does not adversely affect the
rights and freedoms of others.
- Right to object. Every data subject has the right to
object, on grounds relating to their particular situation, at any time
to the processing of personal data concerning them which is based on
Art. 6 (1) (e) or (f) GDPR. This also applies to profiling based on
those provisions. In the event of an objection, micemice will no
longer process the personal data unless we can demonstrate compelling
legitimate grounds for the processing which override the interests,
rights and freedoms of the data subject, or the processing serves the
establishment, exercise or defence of legal claims. Where
micemice processes personal data for direct marketing purposes,
the data subject has the right to object at any time to the
processing of personal data for such marketing, including profiling to
the extent that it is related to such direct marketing; we will then
no longer process the personal data for these purposes. In addition,
the data subject has the right, on grounds relating to their
particular situation, to object to the processing of personal data
concerning them by micemice for scientific or historical research
purposes or statistical purposes pursuant to Art. 89 (1) GDPR, unless
the processing is necessary for the performance of a task carried out
for reasons of public interest. In the context of the use of
information society services, and notwithstanding Directive
2002/58/EC, the data subject may exercise the right to object by
automated means using technical specifications.
- Automated individual decision-making, including
profiling. Every data subject has the right not to be subject
to a decision based solely on automated processing, including
profiling, which produces legal effects concerning them or similarly
significantly affects them, unless the decision (1) is necessary for
entering into, or the performance of, a contract between the data
subject and the controller, (2) is authorised by Union or Member State
law to which the controller is subject and which lays down suitable
measures to safeguard the data subject’s rights, freedoms and
legitimate interests, or (3) is based on the data subject’s explicit
consent. If the decision is necessary for a contract or is based on
explicit consent, micemice will implement suitable measures to
safeguard the data subject’s rights, freedoms and legitimate
interests, at least the right to obtain human intervention on the part
of the controller, to express their point of view and to contest the
decision.
- Right to withdraw consent. Every data subject has
the right to withdraw their consent to the processing of personal data
at any time. Withdrawal does not affect the lawfulness of processing
carried out on the basis of consent before its withdrawal.
- Right to lodge a complaint with a supervisory authority.
Without prejudice to any other administrative or judicial remedy,
every data subject has the right to lodge a complaint with a
supervisory authority pursuant to Art. 77 GDPR. The supervisory
authority responsible for us is the Berlin Commissioner for Data
Protection and Freedom of Information (Berliner Beauftragte für
Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin,
Germany, datenschutz-berlin.de.
9. Legal basis for processing
Art. 6 (1) (a) GDPR serves as the legal basis for processing operations
for which we obtain consent for a specific processing purpose. If the
processing of personal data is necessary for the performance of a
contract to which the data subject is party — as is the case, for
example, when processing operations are necessary for the delivery of a
commissioned work or the provision of any other service or
consideration — the processing is based on Art. 6 (1) (b) GDPR. The
same applies to processing operations that are necessary for carrying
out pre-contractual measures, for example in the case of enquiries about
our services. If we are subject to a legal obligation which requires the
processing of personal data, for example to fulfil tax obligations, the
processing is based on Art. 6 (1) (c) GDPR. In rare cases, the
processing of personal data may be necessary to protect the vital
interests of the data subject or of another natural person; the
processing would then be based on Art. 6 (1) (d) GDPR. Finally,
processing operations may be based on Art. 6 (1) (f) GDPR. This legal
basis applies to processing operations not covered by any of the above,
where processing is necessary for the purposes of a legitimate interest
pursued by us or by a third party, provided that the interests,
fundamental rights and freedoms of the data subject are not overriding.
Such processing operations are permitted in particular because they have
been specifically mentioned by the European legislator, which considered
that a legitimate interest could be assumed if the data subject is a
client of the controller (Recital 47, sentence 2, GDPR).
10. Legitimate interests pursued by the controller or a third party
Where the processing of personal data is based on Art. 6 (1) (f) GDPR,
our legitimate interest is the conduct of our business — in particular
the presentation of our work on this website, its secure and reliable
operation, and communication with clients and interested parties.
11. Period for which personal data is stored
The criterion for the duration of storage of personal data is the
respective statutory retention period. After expiry of that period, the
corresponding data is routinely deleted, provided it is no longer
required for the performance or initiation of a contract.
12. Statutory or contractual requirements to provide personal data;
necessity for the conclusion of a contract; consequences of failure to
provide data
We would like to point out that the provision of personal data is in
part required by law (e.g. tax regulations) or may also result from
contractual arrangements (e.g. information on the contracting party). In
some cases it may be necessary for the conclusion of a contract that a
data subject provides us with personal data which must subsequently be
processed by us. The data subject is, for example, obliged to provide us
with personal data when we conclude a contract with them; failure to
provide the personal data would mean that the contract could not be
concluded. Before providing personal data, the data subject may contact
us; we will then clarify, on a case-by-case basis, whether the provision
of the personal data is required by law or contract or is necessary for
the conclusion of the contract, whether there is an obligation to
provide the personal data, and what the consequences of not providing it
would be.
13. Existence of automated decision-making
As a responsible business, we do not use automated decision-making or
profiling.
Last updated: September 2026