Privacy policy

1. Scope

This privacy policy applies to the websites
• https://know-me.info and
• https://shop.know-me.info

including all subpages and the services offered through them (user accounts, digital business cards/contacts, NFC linking, contact file downloads, the shop and order processing).

2. Data controller

Kern Medien
Dennis-Michael Kern
Tschaikowskistraße 6
18069 Rostock
Germany

Phone: +49 381 12779523 or +49 157 37529299
Email: service@know-me.info

3. Data protection officer

No data protection officer has been appointed unless this is required by law. Please direct data protection enquiries to service@know-me.info.

4. Definitions and legal bases

We process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection legislation.

The legal bases include:
• Article 6(1)(b) GDPR (contract or pre-contractual measures), for example account creation, providing digital business cards and shop orders.
• Article 6(1)(c) GDPR (legal obligation), for example retention under commercial and tax law.
• Article 6(1)(f) GDPR (legitimate interests), for example safe and stable website operation, prevention of abuse and fraud, and IT security.

5. Data processing when visiting the websites (server logs)

Whenever you access our websites, our server automatically processes data transmitted by your browser (server logs), including:
• IP address,
• date and time of access,
• page or file accessed,
• referring URL,
• browser type/version and operating system,
• status codes and volume of data transferred.

Purpose: delivering the website, ensuring stability and security, troubleshooting, and preventing attacks and abuse.
Legal basis: Article 6(1)(f) GDPR.
Retention: log data is generally stored only as long as necessary for its purpose (typically a few days to weeks), then deleted or anonymised unless security needs require a longer retention period.

6. User accounts, registration and login

User accounts may be offered on both domains (for example through “Create a free account”, “Log in” or “Register”). We typically process:
• username,
• email address,
• password (in hashed form only),
• any additional details you enter in your account,
• login and session data.

Purpose: account creation, authentication and providing the platform’s features.
Legal basis: Article 6(1)(b) GDPR.
Retention: until the account is deleted; statutory retention requirements, for example for orders, remain unaffected.

7. Digital business cards/contacts (profile management)

7.1 Creating and managing contacts
Registered users can create and manage one or more contacts (digital business cards). Depending on what you enter, the following data may be processed:
• name, title and date of birth,
• company and job title,
• email addresses (personal/work, possibly more than one),
• phone numbers (mobile/personal/work, possibly more than one),
• addresses (home/work),
• websites (personal/work),
• biography and free text,
• social media links (for example Instagram, TikTok, Facebook and LinkedIn),
• WhatsApp links and numbers (personal/business),
• images and uploads (profile photo/avatar, logo),
• visibility and sharing settings (for example whether fields appear on the public page or in the contact file).

Purpose: providing and personalising the digital business card, displaying and exporting it as a contact file, and managing it through the user account.
Legal basis: Article 6(1)(b) GDPR.

7.2 Public profiles and publication by the user
The digital business card may be accessible through a public URL, for example when an NFC card is used or a link is shared. Content you add to your profile and make visible can therefore be viewed by third parties.

Important: you decide which data to publish. Please do not publish anyone else’s data without appropriate authorisation.
Legal basis: Article 6(1)(b) GDPR (providing the platform), together with your configuration and publication choices within the platform.

Search engines and caches: public profiles may be indexed by search engines or cached by third parties. Even after changes or deletion, content may remain temporarily available through caches or archive services, over which we have limited control.

7.3 Image uploads (avatar/logo)
When you upload images, they are stored in the system and, depending on your settings, used on your public profile or in your contact file.

Purpose: displaying your profile and optionally including a photo in contact file exports.
Legal basis: Article 6(1)(b) GDPR.
Retention: until you delete the images or your account is deleted, unless legal obligations require longer retention.

8. Contact file downloads

The platform offers a downloadable contact file (vCard), generated from your profile details. Depending on your settings, images such as an avatar or logo may be embedded in the file.

Purpose: providing a standard contact file that can be saved or imported.
Legal basis: Article 6(1)(b) GDPR.

9. NFC cards: linking, redirects and scan counts

9.1 Linking an NFC card to a contact
When you link an NFC card to a contact in your account, a card code/identifier is stored and assigned to that contact.

Purpose: linking and displaying the correct profile when the card is scanned or tapped.
Legal basis: Article 6(1)(b) GDPR.

9.2 Opening an NFC link (redirect)
When an NFC URL is opened, the visitor is directed to the destination you configured, such as your profile, contact file, custom URL, social media link or WhatsApp.

As with any website visit, access data such as the time and requested URL is processed for technical reasons (see server logs).

Legal basis: Article 6(1)(f) GDPR (operation and IT security) and Article 6(1)(b) GDPR (providing the service to the cardholder).

9.3 Scan/usage counter (statistical counting)
A counter records how often a card is opened. Provided that no uniquely identifiable user profiles are created, this serves to show usage and improve the system.

Legal basis: Article 6(1)(f) GDPR (legitimate interests in demonstrating functionality, improvement and detecting abuse).

10. Shop and orders

You can order NFC cards and, where available, digital services from the shop. We generally process:

Order and contract data
• name, billing address and delivery address,
• email address and phone number, if provided,
• products and variants ordered, prices and relevant dates/times,
• order status and order-related communication,
• customer number and internal notes, where applicable.

Purpose: contract performance, delivery, billing and customer service.
Legal basis: Article 6(1)(b) GDPR.

10.1 Payment processing
Depending on the payment method selected, we process data to handle payment:
• Bank transfer (payment in advance): we process payment information transmitted with your transfer or booking, such as your name, IBAN, amount, payment reference and date.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR (retention obligations).
• PayPal: if you use PayPal, PayPal handles the payment. Transaction data and, where necessary, identification and contact details are transmitted to or processed by PayPal to complete the payment.
Legal basis: Article 6(1)(b) GDPR.
• Credit card: credit card payments are typically handled by an integrated payment service provider or acquirer. Transaction data and necessary contact details are processed. We generally receive status and transaction information rather than full card details, depending on the integration.
Legal basis: Article 6(1)(b) GDPR.

Transfers to third countries: depending on the payment provider, data may be transferred to third countries such as the USA. Where this occurs, it is based on an adequacy decision or appropriate safeguards, such as EU standard contractual clauses, under Articles 44 et seq. GDPR.

10.2 Shipping and logistics
To deliver physical products, we may share your name and delivery address with shipping providers.

Legal basis: Article 6(1)(b) GDPR.

11. Product reviews and comments

Product pages may offer reviews or comments. When you submit a review, we typically process:
• display name and email address,
• review content,
• website, if the field is offered and completed,
• for technical reasons: IP address and browser identifier (user agent) to prevent abuse and spam, as used by many commenting systems.

Purpose: publishing reviews, quality feedback and preventing abuse and spam.
Legal basis: Article 6(1)(f) GDPR (legitimate interests in feedback and preventing abuse), or Article 6(1)(b) GDPR where reviews are part of an account or contractual feature.
Retention: until the review is deleted, or longer where necessary to provide evidence or defend legal claims.

12. Contacting us (email/phone)

When you contact us, for example by email or phone, we process the information you provide, such as your name, email address, message and phone number where applicable, to handle your enquiry.

Legal basis: Article 6(1)(b) GDPR (pre-contractual or contractual enquiries) or Article 6(1)(f) GDPR (general enquiries).
Retention: for the duration of processing and afterwards where necessary for documentation or legal defence.

13. Cookies and similar technologies

Our websites use cookies and, where applicable, similar technologies that may be necessary for their operation and features, such as login, shopping cart and sessions.

Typical cookie categories:
• Necessary cookies: for example session and login cookies, shopping cart and checkout features, and security features.
Legal basis: Article 6(1)(f) GDPR (necessary for operation) or Article 6(1)(b) GDPR (providing functionality).
• Optional cookies, only if used: for example statistics, marketing or tracking.
Legal basis: consent under Article 6(1)(a) GDPR, where required. You can withdraw consent at any time with effect for the future, for example through cookie settings where available.

Typical examples of functional cookies:
• WooCommerce: cookies for managing the shopping cart and sessions, such as woocommerce_cart_hash, woocommerce_items_in_cart and wp_woocommerce_session_*.
• Comment cookies: storing your name, email and website for convenience when commenting again, if you select the corresponding checkbox.

14. QR code on your profile

Public profiles on know-me.info can display a QR code. It is generated locally by the Know Me plugin. No external QR code service is contacted to create or display it.

Purpose: displaying a QR code to make it easy to open or save contact details.
Legal basis: Article 6(1)(b) GDPR (providing the platform feature) and/or Article 6(1)(f) GDPR (ease of use).

15. External links (social media, WhatsApp, websites)

Your profile may contain links to external services such as Instagram, TikTok, Facebook, LinkedIn, WhatsApp or other websites. Clicking a link connects you to the relevant provider. That provider’s privacy policy applies.

We are not the controller of processing carried out by these third-party providers.

16. Recipients and categories of recipients

We share personal data only where necessary or where a legal basis exists, particularly with:
• hosting and IT providers for operating, maintaining and providing the platform,
• payment providers, such as PayPal and credit card payment providers,
• shipping and logistics providers for delivering physical products,
• authorities and public bodies where legally required,
• legal and tax advisers where necessary for enforcing rights or compliance.

Where service providers act as processors, they do so under a data processing agreement in accordance with Article 28 GDPR.

17. Retention and deletion

We keep personal data only for as long as necessary for its purposes or as required by statutory retention obligations. Typical criteria include:
• Account data and profiles: until deleted by the user or until account deletion.
• Order and invoice data: in accordance with retention requirements under commercial and tax law.
• Communication: as long as necessary for handling enquiries and, where applicable, providing evidence.
• Log data: see the server logs section.

18. Your data protection rights

Subject to the applicable legal requirements, you have the following rights:
• access (Article 15 GDPR),
• rectification (Article 16 GDPR),
• erasure (Article 17 GDPR),
• restriction of processing (Article 18 GDPR),
• data portability (Article 20 GDPR),
• objection to processing based on legitimate interests (Article 21 GDPR),
• withdrawal of consent with effect for the future (Article 7(3) GDPR).

To exercise your rights, send a message to service@know-me.info.

19. Right to complain to a supervisory authority

You have the right to complain to a data protection supervisory authority. The authority responsible for us, based in Rostock, is in particular:

The State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Vorpommern
Schloss Schwerin, Lennéstraße 1, 19053 Schwerin
Email: info@datenschutz-mv.de
Website: https://www.datenschutz-mv.de

20. Obligation to provide data

Certain data is needed to use key features such as accounts, profiles and orders — for example an email address for your account, an address for delivery and payment details for payment. Without this data, we may be unable to provide the relevant service.

21. Automated decision-making and profiling

No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.

22. Data security

We implement appropriate technical and organisational security measures, such as access restrictions, transport encryption/HTTPS and backup systems, to protect data against loss, manipulation and unauthorised access.

23. Changes to this privacy policy

We may update this privacy policy when legislation, services or data processing change. The version published on the website at the time applies.

Scroll to Top