EGM500 privacy notice — draft
V0.02 DRAFT — NOT LEGALLY APPROVED. This notice describes the EGM500 prototype. Before real pilot data is processed, the open operational details and legal bases must be completed and reviewed.
1. Controller and contact
The controller is WISTRA – Gesellschaft für Wissens- und Informationstransfer mbH, Wildensteinstraße 25
72461 Albstadt
Deutschland / Germany, represented by Gerd H. Schick. Privacy enquiries: info@wistra.de; telephone: +49 7432 18924-100.
[OPEN: Establish whether a data protection officer has been or must be appointed; where applicable, add the officer's separate contact details.]
2. Portal access and sessions
When the portal is accessed, the server environment processes connection data needed for transmission. Additional web server and infrastructure logs depend on the installation: [OPEN: Identify the provider, data categories including IP address, requested path and time, purposes and specific server-log deletion periods.]
The application uses the EGM500SID session cookie. It associates browser requests with a session and enables sign-in, form protection and the selected DE/EN language. It is configured as a session cookie; browsers may restore sessions. The application ends signed-in use after one hour of inactivity. Server-side session files may remain until technical cleanup; a separate retention period must be set. The supplied application serves its scripts, styles and images locally and contains no embedded advertising or audience analytics. Additional hosting services or later extensions require separate assessment. The exception under section 25(2) TDDDG is intended for strictly necessary session storage; it does not authorise additional tracking in general.
3. Accounts and security
Stored information includes account ID, username, display name, language, roles, status and timestamps, and, where provided, email address and verification status. Passwords are stored as hashes. Existing multi-factor and recovery data is retained when switching to prototype mode but is not enforced as a sign-in requirement in that mode. Account actions may generate time-limited proofs and security notifications. To limit sign-in attempts, the application uses keyed identifiers derived from the sign-in identifier and connection address, with attempt counters. Changes and approvals are logged with account, time, action and object reference. Shared test accounts identify the account, not reliably the person acting.
A prototype account requires a username, password and information needed for administration; email is optional. Protected functions are unavailable without an account. Acknowledging a privacy notice is not blanket consent to all processing.
4. Company profiles and sources
Representation applications contain company details, capacity, authorisation information and review decisions. Authorised accounts and editors handle drafts, sources, documents, submissions and corrections. Profile fields may include managers' names and professional roles. Information comes from submissions and the identified sources, such as company publications or registers. Only content approved for publication and information permitted by source rights is published. Published personal information is accessible to portal visitors and may be copied beyond our control. Internal review notes, confidential evidence and protected original files do not automatically become public. Do not upload identity-document copies, special categories of personal data or unnecessary private contact details. A source being publicly accessible does not by itself establish that further processing is lawful.
5. Watchlists, contact requests and service
A watchlist records the connection between an account and followed companies and the optional email-alert setting. An investor's contact request contains account/contact details, the relevant company profile, reason, short message and handling status. It is available to the authorised operator team; the application does not automatically send it to the company. Any separate disclosure is agreed with the requester first. Service requests contain contact name, email, optional organisation, category, subject, message, replies and assignment. Keep free text limited to necessary information. The completeness display checks whether profile information is present; it does not create an individual creditworthiness or investor profile.
6. Events and messages
Event registration records the account, event, registration status, timestamps and, where applicable, attendance status. Authorised event managers can view and export participant lists including contact details. Technical export capability alone does not authorise disclosure to an external organiser; arrangements must be transparently defined for the specific event. Portal and outgoing email messages concern account, company, service or event activity. When SMTP sending is enabled, the configured email provider processes recipient addresses and message content. The application records queue and sending status; acceptance is not proof of delivery. Password or verification links may contain sensitive access tokens. Demo operation and local tests do not amount to sending messages to real recipients.
7. Purposes and legal bases — subject to confirmation
Account administration and requested portal, service and event functions should rely on Article 6(1)(b) GDPR where they are necessary for a contract with the individual or requested pre-contractual steps. That basis is not automatically suitable for an organisation's contact person. System security, accountable access management and proportionate operational records require assessment of legitimate interests under Article 6(1)(f) and documented balancing. For published information about individuals, purpose, source, necessity and information duties require separate review. Optional company-change emails are intended only following the corresponding selection; consent and evidence arrangements must be confirmed. No solely automated decision producing legal or similarly significant effects is intended.
[OPEN: Establish the actual legal basis for each processing operation, the specific interests and balancing for legitimate interests, and documented mechanisms where consent is used; separately fulfil duties concerning indirectly collected data.]
8. Recipients and processing countries
Relevant authorised personnel and administrative support have access as required. Public profile information reaches portal visitors. Hosting, backups and enabled email sending may involve external service providers.
[OPEN: Identify hosting, email, support and backup providers, their subprocessors, tasks and processing locations; conclude necessary data processing agreements.]
[OPEN: Assess and disclose transfers outside the EEA, if any; where applicable, describe recipient countries, transfer basis and access to appropriate safeguards. Processing exclusively in Germany or Europe is not claimed here.]
9. Retention and erasure
Accounts, enquiries, registrations, version histories, rights decisions, messages, logs and backups serve different purposes. The application provides no general automatic erasure of all these categories. Account suspension is not erasure. This does not justify indefinite retention.
[OPEN: Establish and implement verifiable periods or criteria, starting points, responsibilities and erasure procedures for each category, including queues, tokens, sessions, logs, private files, exports and backup rotation. Consider statutory retention or legal claims only to the extent necessary.]
10. Your rights
Subject to the statutory conditions, you may request access, rectification, erasure, restriction and data portability. You may object to processing based on legitimate interests for reasons relating to your situation; an objection to direct marketing needs no such justification. Consent may be withdrawn for the future. You may complain to a data protection supervisory authority, particularly where you live, work or believe an infringement occurred. Contact info@wistra.de to exercise your rights. Proportionate identity verification may be needed. The account export provides selected account and activity data; it does not replace a complete response to an access request. Optional watchlist emails can be disabled in the portal.
[OPEN: Add the competent supervisory authority and verified contact channel; assign internal responsibility and timely handling of data-subject requests.]