Privacy Policy2019-04-03T11:37:21+00:00

Our Commitment to Privacy and Data Protection

Privacy Policy

Scope and version

This Privacy Policy informs you of how we collect and process information as part of the service that is offered on and its subdomains.

This version of the Privacy Policy is valid starting on November 05, 2018. We may adjust this statement in the future from time to time in order, for example, to take account of changed processes or new developments.

Further provisions may apply to the usage of the SaaS application Meisterplan, which are defined in the Software as a Service Terms and Conditions.

Service Authority and Data Protection Officer

The service that is described herein is provided by:

itdesign GmbH
Friedrichstr. 12
72072 Tübingen

Our external data protection officer is:
Dr. iur. Christian Borchers
Datenschutz Süd GmbH
Wörthstrasse 15
97082 Würzburg

Legal basis for the processing of personal data

This Privacy Policy is based on Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR). The legal basis for the processing of your personal data is: your consent to data processing (Art. 6, Para. 1(a) of the GDPR); fulfillment of a contract or precontractual measures (Art. 6, Para. 1(b) of the GDPR); a legitimate interest on our part (or by third parties), provided your interests, fundamental rights, and fundamental freedoms are not superseded (Art. 6, Para. 1(f) of the GDPR).


We use cookies on our site. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our site. The cookie stores information about the specific end user device that was used to access the site.  However, the information that is stored in the cookie does not allow us to determine your exact identity.

On the one hand, the use of cookies makes it easier for you to use our service. For example, we use so-called session cookies to recognize when you have already visited individual pages on our website. These are automatically deleted after you leave our website.

In addition, we also use temporary cookies that are stored on your device for a specified period of time to improve usability. If you visit our site again to take advantage of our services, the site will use the cookie to automatically recognize that you have already visited us before. It will also remember text and settings that you previously entered so that you do not have to re-enter them. Cookies help to make the website more user-friendly (for example, they can be used to store login data), or they can be used to control advertisements or recognize users that have been referred to us from certain partners. In addition, cookies are used to collect statistical data on website usage and analyze it to optimize the website.

You have control over how cookies are used on your device. Most browsers have an option that will allow you to restrict or completely prevent the storage of cookies. However, we would like to point out that the functionality and especially the usability of the website are limited when cookies are disabled.

Server logs

All server requests are stored in logs. These logs must be kept to maintain our service, to troubleshoot problems, and to prevent attacks.

These logs contain the following information among other data points:

URL of the accessed website or file, date and time of the query, amount of data transferred, note about whether data was successfully retrieved, browser type and version, user operating system, referrer URL, IP address, and the requesting provider.

Traffic Analysis Provided by Google Analytics

We use Google Analytics, a web analytics service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter “Google”), for the purpose of designing and continually optimizing our web pages as needed. In this context, pseudonymized usage profiles are created and cookies are used. Google Analytics collects the following information among other data points:

browser type and browser version, browser language, used operating system, geographic origin, page views, timestamps, previously visited pages, interactions with such page elements as forms, search queries, service providers, and data transmitted by search engines or advertising platforms.

This information is generally transmitted to a Google server in the US and stored there.

In addition, you may prevent the collection of data that is generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on (

For more information about privacy related to Google Analytics, see the Google Analytics Help Center (

You can also prevent the installation of cookies by configuring the browser software accordingly. However, we would like to point out that not all features of this website will be fully usable in this case.

Google Analytics is integrated using the Google Tag Manager service. IP addresses are anonymized through settings defined there. The data that we receive through Google Analytics can be merged with other data, e.g., the information that you voluntarily share with us through the website.

We use the data to maintain and improve our website, evaluate the user’s interactions with the website, and evaluate our marketing strategies.

Analysis by Visual Website Optimizer

We use Visual Website Optimizer, a web analysis service from Wingify (Wingify, Inc., Delhi, India), hereinafter referred to as “VWO”. VWO is designed to test and optimize the usability of our website. VWO anonymously collects statistics on user behavior. We have no way of assigning these anonymous metrics, for example, by assigning an IP address to a person. In order to obtain meaningful test results, cookies are used. VWO stores user activities, device and browser information as well as a unique user ID (_vwo_uuid) in a cookie, but anonymizes both the IP address and personal content. You can delete cookies in your browser at any time. In addition, you have the option to opt-out of participation in the tests altogether via the following link:

For more information on privacy at VWO, see the VWO Privacy Policy (


This site uses Google Remarketing technology for targeted advertising. The basis for showing ads on the Google Display Network is the user’s previous visits to this website. This feature stores cookies that are used by Google and third parties to target the ads that they display. The purpose of this measure is to better attract customers.

You can use to disable Google Analytics for display advertising and to adjust the settings for the Google display network.

Conversion tracking

We use conversion tracking tools from various advertisers on our site. When you reach our website through the advertisements of specific providers, the provider will place a cookie on your computer that will collect information on your behavior to compile statistics on the effectiveness of the ads. Conversion tracking can be deactivated via your browser’s cookie settings. The purpose of this measure is to better attract customers.

Currently, this concerns the services Google AdWords (a service of Google) and Capterra (Capterra Inc., 901 North Glebe Road, Suite 1010, Arlington, VA 22203, USA) use conversion tracking.

Google Fonts

On some pages of our website, we include fonts (“Google Fonts”) from the provider Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. You can unsubscribe from the provider’s statistical data collection at

Plugins from other platforms

We install plugins for various other platforms, e.g., for social media platforms, on our website. The purpose of these plugins is to increase the level of awareness of our service or to serve content. The respective provider is responsible for ensuring that it operates its service in accordance with data protection rules.

These plugins are generally used to establish a direct connection between your browser and the servers of the respective provider. Specifically, the plugins are:

Google + plugin

On our pages we use the “+1” button for the Google Plus social network. This is powered by Google.

You will recognize the Google+ button by the “+1” sign. When you visit a web page on our website that contains such a button, the displayed image and content of the “+1” button will be transmitted directly from Google to your Internet browser, incorporated into the presentation of our website, and displayed in your browser. We have no control over the extent and content of the data that Google collects through this button. According to Google, no personal information is collected if the button is not clicked. Only the data of members of Google+ who are logged into Google will be collected, processed, and stored. We are not familiar with what exact data this represents. If you want to prevent such data from being transmitted, you must log out of your Google + account before visiting our website. The purpose, nature, and extent of this data; your own processing  options for protecting your privacy; as well as further information and instructions can be found in the Google Privacy Policy at the following link:

Twitter plugin

The functionality of the Twitter service is integrated into our web pages. These features are provided by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. By using Twitter and the “Re-Tweet” function, the websites you visit are linked to your Twitter account and shared with other users. This data is also transmitted to Twitter. We point out that we as the provider of the pages are not aware of the content of the transmitted data and how it is used by Twitter. For more information, see the Twitter Privacy Policy at

You can change your privacy settings on Twitter by visiting your account settings page at

LinkedIn plugin

You can find plugins from the LinkedIn social network, which is operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, United States (hereafter “LinkedIn”). The LinkedIn plugins can be recognized by the corresponding logo. Please note that when you visit our website, the plugin establishes a connection between your Internet browser and the LinkedIn server. LinkedIn is informed that our website has been visited by someone at your IP address. If you click on LinkedIn’s “Recommend Button” and at the same time you are logged into your LinkedIn account, you have the option of linking content from our website with your profile page on your LinkedIn Profile. By doing so, you allow LinkedIn to link your visit to our website to you or your user account. We point out that we are in no way aware of the content of the transmitted data and how it is used by LinkedIn.

For more information on data collection, your legal options, as well as your setting options, please visit LinkedIn. You can access this information at:

Xing plugin

This website uses the XING “share button”. Therefore, when you connect to this website, your browser will connect to the servers of XING AG, Gänsemarkt 43, 20354, Hamburg, Germany. This service is used to provide share functions (e.g., displaying counter values). According to our information, no personal information about you is stored when you load this website. In particular, XING does not store IP addresses. Nor is your usage behavior analyzed. Current information on data protection regarding the “share button” as well as other relevant information can be found here:

Youtube plugin

We use a YouTube plugin on our website (YouTube, LLC., 901 Cherry Avenue, San Bruno, California, USA) to provide video to our users. This plugin establishes a connection with YouTube’s servers that is used to transfer data to YouTube. Therefore, it can be assumed that YouTube collects the IP addresses of users, for example. The IP address must be known in order to send content to the browser of the respective user. Thus, it is required for the presentation of the content.

Quest hosting

The service is hosted by the service provider: Invision Community (Invision Power Services, Inc., PO Box 2365, Forest, VA 24551, USA). Data that is submitted through (such as the username and contact details) may be processed by this provider outside the EU/EEA. Submitting information to is voluntary.

Help page

The service is hosted by the provider: Zendesk (Zendesk, Inc., San Francisco, California, USA). In addition to the above-mentioned data analysis provided by Google Analytics, Zendesk has an additional feature that allows visitor behavior to be analyzed anonymously. This data may be processed outside the EU/EEA. We use the data to maintain and improve our content and to evaluate how users interact with the help site.

Interaction with the registration form and contact form

We collect data that you voluntarily provide to us, e.g., by submitting a contact request or when requesting and activating a trial version of our software. By entering your contact details, you give us your consent to process them in the manner described.

If you contact us in this way, we believe that you are interested in receiving more information about our product and possibly becoming our customer. Therefore, we may contact you for informational and consultation purposes.

When activating a trial version, the following data is also collected:

Time that you interacted with the forms, ID of the Google Analytics cookie, and name and internal ID of the generated test instance.

This helps us to maintain the operation of our trial process, provide sales support, and evaluate our marketing strategies.

Interaction with Drift Chatbot and Live Chat

We use Drift software (Drift, Inc., Boston, Massachusetts, USA), hereinafter referred to as “Drift.” Drift is a chat service designed to give our customers and prospects as much information as possible about our product and our services. Additionally, visitors can arrange for web site sessions with our sales representatives through Drift. Drift uses cookies that are stored on the visitor’s computer that enable a conversation in the form of a chat on the website between the customer and the Meisterplan chatbot and the Meisterplan Team. The information generated by the cookie about the use of our website including the IP address of the customer are transmitted to Drift and stored there. The text messages in the live chat and also any personal data that you may enter yourself will be transmitted to Drift and stored on servers by Drift in the USA. Drift is certified under the EU-US Privacy Shield, so that the legal requirements for the adequacy of the data protection level according to Art. 45 DS-GVO are met.

If you do not want to submit any data to Drift, you can refrain from using the chatbot and the live chat. If you have problems or questions, you can contact Meisterplan through other methods (see “Interaction with Registration and Contact Form”).

For more information on privacy at Drift, please refer to the Drift Privacy Policy (

Sending of e-mails

The Mailgun service (Mailgun Technologies, Inc., 535 Mission St., San Francisco, CA 94105, USA) may be used to automatically send e-mails, e.g., to activate a requested trial version of the software or to send information from the online store. This data may be processed outside the EU/EEA.


You are able to sign up for our newsletter on our website. You thereby give us your consent to send our newsletter to you on a regular basis. Each newsletter contains a link that allows you to unsubscribe at any time and thus revoke your consent.

Transfer of data

In order to optimally support our prospective and existing customers, we work closely with regional partner companies or subsidiaries that are distributed around the world. These may also be located in countries outside the EU/EEA, such as, for example, Meisterplan USA Inc. If you sign up for a trial version of our software or submit a contact request, you agree to the disclosure of the data that you have shared with a local affiliate.

Rights with regard to our data processing

You have the following rights with regard to how we process your personal data:

  • Revocation of consent: You may revoke your consent to the collection and processing of data once at any time with future effect.
  • Right to object: You have the right to object to the processing of your personal data.
  • Right of access: You have the right to request information about your personal data.
  • Correction: You have the right to correct erroneous data and to provide supplementary information to rectify incomplete data when such data is processed.
  • Deletion: You have the right to delete your personal data or to limit the extent to which it is processed if the deletion of the data is not legally possible.
  • Data portability: You have the right to receive a copy of your personal information in a commonly used machine-readable format.
  • Right of appeal: You have the right to file a complaint with a regulator.

If you have any questions, please contact our data protection officer, who is mentioned above.

Additional Deletion Periods

Deletion periods for the data collected in connection with the use of the SaaS application and listed in Clause 9 (Part 1) of the Terms of Service.

Data Category Purpose of Processing Deletion Period
Personal Data of the Customer‘s Contact Persons Performance of the contract, in particular within the scope of the billing The deletion periods are based on the legal requirements for deletion and storage.
Server Protocols Search for and rectify errors, avert threats to security, and maintain the technical operation of the application The data will be automatically deleted after 365 days.
Statistical data for the use of the Application Continued provision of the service, adaptation to the developing needs of the users, improvement of the user experience in the application, and optimization of the internal processes of the Supplier The data will be deleted or aggregated after 3 years.