Privacy Policy

1. Scope

This privacy policy applies to the websites
https://know-me.info as well as
https://shop.know-me.info

including all subpages and the services offered through them (user account, digital business cards/contacts, NFC linking, vCard download, shop/order processing).

2. Controller

Kern Medien
Dennis-Michael Kern
Tschaikowskistraße 6
18069 Rostock
Germany

Phone: 0381/12779523 or 0157/37529299
E-Mail: service@know-me.info

3. Data Protection Officer

A data protection officer has not been appointed insofar as there is no legal obligation to do so. Please direct data protection inquiries to: service@know-me.info.

4. Terms and Legal Bases

We process personal data in compliance with the General Data Protection Regulation (GDPR) and the applicable national data protection laws.

Legal bases include in particular:
• Art. 6(1)(b) GDPR (contract/contractual measures) – e.g. account creation, provision of the digital business card, orders in the shop.
• Art. 6(1)(c) GDPR (legal obligation) – e.g. commercial and tax retention requirements.
• Art. 6(1)(f) GDPR (legitimate interests) – e.g. secure and stable provision of the websites, abuse and fraud prevention, IT security.

5. Data Processing When Visiting the Websites (Server Log Files)

Each time our websites are accessed, data automatically processed by our server and transmitted by your browser (“server log files”) are collected, in particular:
• IP address,
• date and time of the request,
• requested page/file,
• referrer URL,
• browser type/version, operating system,
• status codes, amount of data transferred.

Purpose: delivery of the website, ensuring stability and security, error analysis, defense against attacks/abuse.
Legal basis: Art. 6(1)(f) GDPR.
Storage period: Log data is generally only retained for as long as necessary for the purpose (typically a few days to weeks), and is then deleted or anonymized, unless there is a security-related need for longer retention.

6. User account, registration and login

Both domains may offer user accounts (e.g. “Create account for free”, “Sign in”, “Register”). In doing so we typically process:
• Username,
• Email address,
• Password (only in hashed form),
• any additional account data you store in the account,
• Login/session data.

Purpose: Account creation, authentication, provision of platform functions.
Legal basis: Art. 6(1)(b) GDPR.
Storage period: Until the account is deleted; statutory retention obligations (e.g. for orders) remain unaffected.

7. Digital business cards/contacts (profile management)

7.1 Creating and managing contacts
Registered users can create and manage one or more contacts (“digital business cards”). Depending on the input, the following data in particular may be processed:
• Name, title, date of birth,
• Company, position,
• Email addresses (private/business, possibly multiple),
• Phone numbers (mobile/private/business, possibly multiple),
• Addresses (private/business),
• Websites (personal/business),
• Biography/free text,
• Social media links (e.g., Instagram, TikTok, Facebook, LinkedIn),
• WhatsApp links/numbers (personal/business),
• Images/uploads (profile picture/avatar, logo),
• Visibility/release settings (e.g., whether fields are shown on the public page or in the vCard).

Purpose: Provision and personalization of the digital business card, display and export (vCard), management via the user account.
Legal basis: Art. 6(1)(b) GDPR.

7.2 Public profile pages and publication by the user
The digital business card may be accessible via a public URL (e.g., when an NFC card is used or a link is shared). Content you add to your profile and choose to display can thus be viewed by third parties.

Important: You decide which data you publish. Please do not publish third-party data without the appropriate authorization.
Legal basis: Art. 6(1)(b) GDPR (provision of the platform) in conjunction with your configuration/publication within the platform.

Note on search engines/caches: Public profile pages may be indexed by search engines or cached by third parties. Even after changes/deletion, content may remain temporarily accessible via caches/archive services, over which we have limited influence.

7.3 Uploads of images (avatar/logo)
If you upload images, they are stored in the system and, depending on settings, used on the public profile page or in the vCard.

Purpose: Representation of your profile, optional vCard photo export.
Legal basis: Art. 6(1)(b) GDPR.
Storage period: Until you delete it or until the account is deleted (unless a longer retention is required by statutory obligations).

8. vCard download

The platform offers a vCard download (electronic business card) generated from the profile data you maintain. Depending on your settings, images (avatar/logo) may also be embedded in the vCard.

Purpose: Providing a standardized contact file for saving/importing.
Legal basis: Art. 6(1)(b) GDPR.

9. NFC cards: linking, redirection, click counter

9.1 Linking an NFC card to a contact
When you link an NFC card in the account to a contact, a card code/identifier is stored and associated with your contact.

Purpose: Technical assignment and delivery of the correct profile when the card is scanned/tapped.
Legal basis: Art. 6(1)(b) GDPR.

9.2 Access via NFC link (redirection)
When an NFC URL is accessed, the visitor is redirected to the destination you configured (e.g., profile page, vCard, custom URL, social link, WhatsApp).

As with any website access, access data (including time and requested URL) is processed for technical reasons (see server log files).

Legal basis: Art. 6(1)(f) GDPR (provision, IT security) as well as Art. 6(1)(b) GDPR (performance of services for the cardholder).

9.3 Click/usage counter (statistical counting)
A click counter is used to display card usage (number of times a card is accessed). As long as no unique user profiles are created in the process, this serves to show functionality and to improve the system.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in proving functionality/improvement and detecting abuse).

10. Shop/Orders

Through the shop you can order NFC cards (and, if applicable, digital services). In doing so we regularly process:

Order and contract data
• Name, billing and delivery address,
• Email address, telephone number (if provided),
• ordered products/variants, prices, timestamps,
• order status, communication regarding the order,
• if applicable, customer number, internal notes.

Purpose: contract processing, delivery, billing, customer service.
Legal basis: Art. 6(1)(b) GDPR.

10.1 Payment processing
Depending on the chosen payment method, we process data for payment handling:
• Bank transfer (prepayment): We process payment information that is transmitted to us via your transfer/transaction (e.g., name, IBAN, amount, reference, date).
Legal basis: Art. 6(1)(b) GDPR; additionally Art. 6(1)(c) GDPR (retention obligations).
• PayPal: If you use PayPal, the payment is processed via PayPal. Transaction data and, if applicable, identification/contact data are transmitted to or processed by PayPal to carry out the payment.
Legal basis: Art. 6(1)(b) GDPR.
• Credit card: Credit card payments are typically processed via an integrated payment service provider (Payment Service Provider / acquirer). Transaction data and necessary contact details are processed. We usually do not receive full card details, but status/transaction information (depending on the integration).
Legal basis: Art. 6(1)(b) GDPR.

Note on transfers to third countries: Depending on the payment service provider, data may be transferred to third countries (e.g., the USA). If this is the case, it will be based on an adequacy decision or appropriate safeguards (e.g., EU standard contractual clauses) in accordance with Art. 44 et seq. GDPR.

10.2 Shipping/Logistics
For the delivery of physical products, we may transmit your name and delivery address to shipping providers.

Legal basis: Art. 6(1)(b) GDPR.

11. Product reviews/comments

A review/comment function may be available on product pages. If you leave a review, we typically process:
• name (display), email address,
• Review content,
• Website, if provided/filled in,
• For technical reasons: IP address and browser identifier (User-Agent) for abuse/spam prevention (system-related in many comment systems).

Purpose: Publication of the review, quality feedback, abuse/spam prevention.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in feedback and abuse prevention) or Art. 6(1)(b) GDPR (if the review is part of a user account/contract feature).
Storage period: Until the review is deleted or as long as longer retention is necessary to provide evidence/defend against legal claims.

12. Contact (email/phone)

If you contact us (e.g. by email or phone), we process the data transmitted in the process (e.g. name, email address, content of the inquiry, possibly telephone number) to handle your request.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) or Art. 6(1)(f) GDPR (general inquiries).
Storage period: For the duration of processing and thereafter as far as necessary for documentation or legal defense.

13. Cookies and similar technologies

Our websites use cookies and, where applicable, similar technologies that may be required for operation and functions (e.g. login, shopping cart, session).

Typical cookie categories:
• Necessary cookies: e.g. session/login cookies, shopping cart/checkout functions, security features.
Legal basis: Art. 6(1)(f) GDPR (operational necessity) or Art. 6(1)(b) GDPR (provision of functionality).
• Optional cookies (only if used): e.g. analytics/marketing/tracking.
Legal basis: Consent (Art. 6(1)(a) GDPR), if required. Given consent can be revoked at any time with effect for the future (e.g. via cookie settings, if available).

Examples of functional cookies (typically):
• WooCommerce: Cookies for cart/session management (e.g. woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*).
• WordPress comments: Storage of name/email/website for convenience on subsequent comments (if checkbox used).

14. External service for QR code generation (QR code on profile page)

On public profile pages a QR code can be displayed that is technically generated via an external QR code service. Your browser loads a QR code image from a third-party server. This transmits, in particular,
• IP address,
• technical browser/device information,
• and the information about which QR code resource was retrieved (including the target URL contained in the QR code)

to the third party.

Purpose: Displaying a QR code for easy transfer (e.g. vCard link).
Legal basis: Art. 6(1)(b) GDPR (provision of the platform feature) and/or Art. 6(1)(f) GDPR (convenient use).
Recipients: QR code service (e.g. api.qrserver.com).

15. External links (social media, WhatsApp, websites)

Your profile page may contain links to external services (e.g. Instagram, TikTok, Facebook, LinkedIn, WhatsApp, external websites). Clicking them establishes a connection to the respective provider. The privacy policies of the respective provider then apply.

We are not the controller for processing by these third-party providers.

16. Recipients / categories of recipients

We only transmit personal data when necessary or when there is a legal basis, in particular to:
• Hosting/IT service providers (operation/maintenance/provision of the platform),
• Payment service providers (e.g. PayPal; credit card payment providers),
• Shipping/logistics service providers (for delivery of physical products),
• Service providers for QR code generation (when using the QR code function),
• Authorities/public bodies, to the extent we are legally obliged to do so,
• Legal/tax advisors, to the extent necessary for legal enforcement/compliance.

If service providers act as processors, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

17. Retention Period and Deletion

We retain personal data only as long as is necessary for the respective purposes, or as long as statutory retention obligations exist. Typical criteria:
• Account data/profiles: until deletion by the user or account deletion.
• Order/invoice data: in accordance with commercial and tax retention obligations.
• Communication: as long as necessary for processing and, if applicable, for providing evidence.
• Log data: see section Server Log Files.

18. Data Subject Rights

You have the following rights, provided the legal requirements are met:
• Access (Art. 15 GDPR),
• Rectification (Art. 16 GDPR),
• Erasure (Art. 17 GDPR),
• Restriction of processing (Art. 18 GDPR),
• Data portability (Art. 20 GDPR),
• Objection to processing based on legitimate interests (Art. 21 GDPR),
• Withdrawal of consent with effect for the future (Art. 7(3) GDPR).

To exercise your rights, a message to service@know-me.info.

19. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us (registered office in Rostock) is in particular:

The State Commissioner for Data Protection and Freedom of Information Mecklenburg-Western Pomerania
Schwerin Castle, Lennéstraße 1, 19053 Schwerin
E-Mail: info@datenschutz-mv.de
Website: https://www.datenschutz-mv.de

20. Obligation to provide data

Providing certain data is required to use core functions (account, profile, order) (e.g. e-mail for the account; address for shipping; payment data for payment). Without these data we may not be able to provide the respective service.

21. Automated decision-making / profiling

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

22. Data security

We implement appropriate technical and organizational security measures (e.g. access restrictions, transport encryption/HTTPS, backup systems) to protect data against loss, manipulation or unauthorized access.

23. Changes to this privacy policy

We may adapt this privacy policy if the legal situation, services or data processing change. The version published on the website at any given time applies.

Scroll to top