Privacy Notice for Hypatos Studio | Hypatos

Privacy Notice for Hypatos Studio

Introduction

Thank you for your interest in Hypatos Studio. Hypatos Studio is Hypatos’ Software as a Service offering for document processing. The protection of your personal data is important to us. Below you will find information on how we handle the data that is collected through your use of Hypatos Studio. Your data will be processed in accordance with the legal data protection regulations.

Controller within the meaning of data protection law

Hypatos GmbH, c/o Unicorn Workspaces
Am Neuen Markt 9 E-F
14467 Potsdam
info@hypatos.ai
+49 (0) 302 09 97 00

Data Protection Officer

Proliance GmbH / www.datenschutzexperte.de Datenschutzbeauftragter
Leopoldstr. 21
80802 Munich
datenschutzbeauftragter@datenschutzexperte.de

Definitions

Our privacy policy should be simple and understandable for everyone. For this reason, our privacy policy generally uses the official terms of the General Data Protection Regulation (GDPR). The official definitions are explained in Art. 4 GDPR.

Subject and Duration of Data Processing

Hypatos processes personal data on behalf of and in accordance with the inputs of the customer. The subject of this privacy notice is the use of Hypatos Studio and the processing of documents, for example incoming invoices of the customer.

Categories of data subjects

The categories of persons affected by the handling of personal data within Hypatos Studio include:

Types of personal data we process

(1) The personal data are subject to two categories: personal data of Users (“Personal User Data”) and personal data of persons mentioned in the documents processed by means of the Services (“Personal Document Data”).
(2) The following data types are affected by data processing:

Type and Purpose of data processing

The type and purpose of data processing of personal data are specified in the Order Form. This includes the following activities and purposes:

Cookies

Hypatos Studio uses cookies which are stored on your device by the browser and contain certain settings for the use of the website (e.g. the current session). Cookies are used to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and stored by your browser. Most of the cookies we use are so-called session cookies, which are automatically deleted after the browser is closed. Other cookies remain stored on your terminal device until you delete them, or the storage period expires.

These cookies enable us to recognize your browser on your next visit. In some cases, cookies are used to simplify website processes by saving settings (e.g. settings that have already been made during previous visits). If personal data are also processed by individual cookies implemented by us, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either to fulfill the contract, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the product and a customer-friendly and effective design of the site visit.

In order to accept or refuse all or certain cookies, you can set up your browser to inform you when cookies are set. You can also activate the automatic deletion of cookies when closing the browser. The cookie settings for the respective browsers can be customized under the following links:

You can also individually manage the cookies of many companies and functions that are used for advertising purposes. Details about the user tools are available at https://www.aboutads.info/choices/ or http://www.youronlinechoices.com/uk/your-ad-choices.

Most browsers also offer a "do-not-track" feature. This feature allows you to indicate that you do not want to be "tracked" by websites. When the function is activated, the browser will tell ad networks, websites and applications that you do not want to be tracked for the purpose of behavior-based advertising and such like. For information and instructions on how to use this feature, see the links below:

In addition, you can prevent the loading of scripts by default. NoScript allows you to run JavaScripts, Java and other plug-ins only on trusted domains of your choice. Information and instructions on how to use this function can be obtained from your browser's provider (e.g. for Mozilla Firefox at: https://addons.mozilla.org/en-GB/firefox/addon/noscript/). Please note that deactivating cookies may limit the functionality of this website.

Data Transfer and Recipients

We generally make sure that personal data is only accessible by a limited number of authorized persons who need the data to provide you with the above-mentioned purposes. Within the scope of the described processing activities, your data is not transferred to third parties, unless

Under these conditions, we use external service providers for the processing of our services, whom we have carefully selected and commissioned in writing. They are bound by our instructions and are regularly monitored by us. Required data processing agreements pursuant to Art. 28 GDPR are concluded before the commission. In particular, these contracts concern web hosting services, the processing of documents, external document labeling, user analytics and IT updates and maintenance. Your personal data will not be transferred to third parties by our service providers.

Sub-Processors

  1. Amazon-Web-Services
    Name/Company: Amazon Web Services EMEA SARL
    Function/activity: Hosting Provider
    Headquarters: 38 avenue John F. Kennedy, L-1855 Luxembourg
    Type of data: Personal User Data as well as Personal Document Data
    Location of data processing: European Union
    Measures/guarantees to ensure an adequate level of data protection: https://aws.amazon.com/security/

  2. Microsoft
    Name/Company: Microsoft Ireland Operations Limited
    Function/activity: Hosting Provider
    Headquarters: One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland
    Type of data: Personal User Data as well as Personal Document Data
    Location of data processing: European Union
    Measures/guarantees to ensure an adequate level of data protection: see Annex A: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA

  3. Google Vision AI
    Name/Company: Google Ireland Limited
    Function/Activity: Cloud OCR – optical character recognition of documents processed by Customer
    Headquarters: Gordon House, Barrow Street Dublin 4, Ireland
    Location of data processing: European Union
    Type of data: Personal User Data as well as Personal Document Data
    Measures/guarantees to ensure an adequate level of data protection: https://cloud.google.com/terms/data-processing-terms

  4. Atlas MongoDB
    Name/Company: MongoDB, Inc.
    Function/Activity: Cloud MongoDB deployment
    Headquarters: MongoDB Limited, Building Two, Number One Ballsbridge, Ballsbridge, Dublin 4, Ireland
    Location of data processing: European Union
    Type of data: Personal User Data
    Measures/guarantees to ensure an adequate level of data protection: https://www.mongodb.com/technical-and-organizational-security-measures

  5. Jira Service Management
    Name/Company: Atlassian. Pty Ltd
    Function/Activity: Service Desk for Customer support
    Headquarters: Level 6, 341 George Street, Sydney, NSW, 2000 Australia
    Location of data processing: EU, USA, Australia
    Type of data: Personal User Data
    Measures/guarantees to ensure an adequate level of data protection: Standard Contractual Clauses (SCCs) for processors as approved by the European Commission

  6. Mailjet
    Name/Company: Mailjet SAS
    Function/Activity: e-mail notification dispatch service
    Headquarters: 13-13 bis, rue de l’Aubrac, 75012 Paris, France
    Location of data processing: European Union
    Type of data: Personal User Data, Personal Document Data
    Measures/guarantees to ensure an adequate level of data protection: https://documentation.mailjet.com/hc/en-us/sections/360007328433-Security-Privacy

  7. LabelYourData
    Name/Company: SupportYourApp, Inc. DBA Label Your Data
    Function/Activity: Data Labelling Service Provider
    Headquarters: 1007 North Orange Street, 4th Floor, Suite 122, Wilmington, DE 19801, USA
    Location of data processing: USA
    Type of data: Personal Document Data
    Measures/guarantees to ensure an adequate level of data protection: Standard Contractual Clauses (SCCs) for processors as approved by the European Commission; additional safeguards

  8. CenterDevice
    Name/Company: CenterDevice GmbH
    Function/Activity: Cloud document management system (DMS)
    Headquarters: Rheinwerkallee 3, 53227 Bonn, Germany
    Location of data processing: European Union
    Type of data: Personal User Data as well as Personal Document Data

  9. DeepL
    Name/Company: DeepL SE
    Function/Activity: Translation Service Provider
    Headquarters: Maarweg 165, 50825 Cologne, Germany
    Location of data processing: European Union
    Type of data: Personal User Data, Personal Document Data
    Measures/guarantees to ensure an adequate level of data protection: Data Protection Agreement according to Art. 28 GDPR

  10. Aggranda
    Name/Company: Aggranda
    Function/Activity: Managed Service Provider
    Headquarters: Copaceni Street No 30-34, Ap. D3, Room 2 030395 București, Romania
    Location of data processing: European Union
    Type of data: Personal User Data, Personal Document Data
    Measures/guarantees to ensure an adequate level of data protection: Data Protection Agreement according to Art. 28 GDPR

  11. Wargitsch
    Name/Company: Wargitsch & Comp. AG
    Function/Activity: Managed Service Provider
    Headquarters: Ingolstädter Straße 92, 85276 Pfaffenhofen an der Ilm, Germany
    Location of data processing: European Union
    Type of data: Personal User Data, Personal Document Data
    Measures/guarantees to ensure an adequate level of data protection: Data Protection Agreement according to Art. 28 GDPR

Storage period

The period for which the personal data will be stored is determined by the relevant statutory storage periods (e.g. from commercial law and tax law). The corresponding data is deleted routinely upon expiry of the respective period. If data is required for the fulfillment of a contract or contract initiation, or if we have a legitimate interest in further storage, the data will be deleted if they are no longer required for these purposes or if you make use of your right of withdrawal or objection.

Data security

We take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons. This website uses SSL encryption for security reasons and to protect the transmission of confidential content.

Hypatos is certified under the ISO27001:2017 industry standard.

Your Rights

If you have questions regarding the processing of personal data within Hypatos Studio, please reach out to us using the following e-mail address: privacy@hypatos.ai

In the following, you will find information about your data subject rights, which the current data protection law grants you against the controller concerning the processing of personal data:

  1. The right, pursuant to Art. 15 GDPR, to obtain information about your personal data processed by us.
  2. The right to obtain without undue delay the rectification of inaccurate personal data concerning you, in accordance with Art. 16 GDPR.
  3. The right to request the erasure of your personal data stored by us in accordance with Art. 17 GDPR.
  4. The right, pursuant to Art. 18 GDPR, to demand the restriction of the processing of your personal data.
  5. The right, in accordance with Art. 20 GDPR, to receive the personal data concerning you.
  6. The right to withdraw your given consent pursuant to Art. 7 para. 3 GDPR.
  7. The right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR.
  8. The right to object if your personal data is processed based on legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.

If you wish to exercise your right of withdrawal, objection or any of your other rights, simply send an e-mail to privacy@hypatos.ai.

Subject to change

We reserve the right to adapt or update this privacy policy, if necessary, in compliance with the applicable data protection regulations. In this way, we can adapt it to the current legal requirements and take account of changes to our services, e.g. the introduction of new services. The most current version applies to your visit.

December 2023