Privacy

Controller

Laggner Digital Solutions, owner Stefan Laggner Spitalstrasse 64, 9472 Grabs, Switzerland Email: hallo@laggner.li

Principles

We process personal data in accordance with the Swiss Data Protection Act (DSG) and, where applicable, the EU General Data Protection Regulation (GDPR). We collect only data that is necessary for the operation of mimaster, and we do not pass on personal data to third parties unless this is necessary for the provision of the service (processors below) or required by law.

What data we process and for what purpose

Data category Examples Purpose Legal basis
Account data Name, email (via the login service), organisation membership, role Account and contract administration, login Performance of the contract
Usage content Content created in mimaster and uploaded files Core of the service Performance of the contract
Payment data Billing name/address, subscription status; no card data held by us (processing by Stripe) Billing Performance of the contract, legal obligations
Communication data Support requests, system emails Support, contract performance Performance of the contract, legitimate interest
Technical data IP address, timestamp, error/log data Security, operation, error analysis Legitimate interest
Analytics data Pseudonymous usage statistics (only with consent) Improvement of the service Consent (revocable)

Processors / recipients

Service Purpose Registered office / data location Note
Cloudflare, Inc. CDN, DNS, protection against attacks USA/EU (global network) Data transfer to the USA possible; safeguarded via standard contractual clauses
Own hosting (EU) Operation of the application and database EU
Stripe Payments Europe Ltd. Payment processing, subscription management Ireland/USA Card data held exclusively by Stripe; Stripe's own privacy policy applies in addition
Amazon Web Services (SES) Sending of system emails Frankfurt (eu-central-1)
Zitadel (self-operated) Login and authentication via the provider's central sign-in service: the customer account (name, email address, linked login providers such as Google) is stored across products for all of the provider's services; sign-in takes place separately per product EU Product and usage data remain separated with the respective product
Sentry (self-operated) Error analysis EU technical error data; personal content is filtered out
Google Ireland Ltd. (Analytics 4) Reach measurement — only with consent Ireland/USA Consent Mode v2; data transfer to the USA possible; withdrawal at any time via "Cookie settings"
DigitalOcean LLC (Spaces) File storage Frankfurt

Cookies and consent

Technically necessary cookies (in particular session cookies) do not require consent. We set analytics cookies (Google Analytics) only after your explicit consent via the cookie banner; before consent, no such services are loaded. You can change your choice at any time via the "Cookie settings" link in the footer; if you decline or withdraw, tracking cookies that have been set are deleted.

Retention and deletion

We process account data and usage content for the duration of the contractual relationship. After deletion of the account or organisation, personal data is deleted or anonymised within 30 days, unless statutory retention obligations (in particular accounting-related, 10 years) apply. Backup copies rotate automatically; deleted data also disappears from the backups with the rotation cycle.

Data security

Transmission exclusively encrypted (TLS); access to production data only for authorised persons; infrastructure reachable exclusively via secured access; regular, encrypted backups.

Your rights

Within the framework of the DSG and the GDPR, you have the right to information, correction, deletion, restriction of processing, release or portability of your data, and to object to certain processing. You may withdraw consent granted at any time with effect for the future. Requests to: hallo@laggner.li. We may require proof of identity in order to process a request.

Supervisory authority

Switzerland: Federal Data Protection and Information Commissioner (FDPIC). Data subjects in the EU may also contact their national data protection supervisory authority.

Changes to this policy

We may amend this policy, in particular in the event of changes to the service or the legal situation. The version published on mimaster.com at the relevant time applies; in the event of material changes, we will inform active users in an appropriate manner.

Last updated: 24 July 2026


Data processing agreement (DPA)

Data Processing Agreement pursuant to Art. 28 GDPR

Version 1.0 — applies in addition to the General Terms and Conditions of mimaster (mimaster.com).

1. Parties

Controller: the customer (the business that uses mimaster and concludes the agreement in the application — company and account are logged upon conclusion).

Processor: Laggner Digital Solutions, owner Stefan Laggner, Spitalstrasse 64, 9472 Grabs, Switzerland, email: hallo@laggner.li (hereinafter the "Provider").

2. Subject matter and duration

The Provider operates the software mimaster (software-as-a-service at mimaster.com) for the customer and processes personal data on behalf of the customer in doing so. The agreement applies for the duration of the usage contract and ends upon its termination; Section 9 (Deletion and return) remains reserved.

3. Nature, purpose and scope of processing

Storage, display, organisation and transmission of the data entered by the customer into mimaster for the purpose of providing the contractual functions (in particular recording and managing briefings, products, change requests and incident reports, as well as subscription and revenue-share billing incl. notifications and exports). No processing for the Provider's own purposes takes place.

4. Types of data and categories of data subjects

  • Types of data: account and master data of the customer's organisation and its members (name, company, address, email, contact details), the content of submitted briefings, product and change-request details incl. attachments, incident reports and support requests, billing and payout metadata.
  • Data subjects: members and contacts of the customer's organisation, as well as third parties recorded by the organisation in briefings, attachments or change requests.

5. Instructions

The Provider processes the data only on the documented instructions of the customer; use of the application functions is deemed to be an instruction. If the Provider considers an instruction to be unlawful, it will inform the customer without delay and may suspend execution.

6. Confidentiality and technical and organisational measures

The Provider obliges all persons involved in the processing to maintain confidentiality. It takes appropriate technical and organisational measures pursuant to Art. 32 GDPR, in particular: encryption of transmission (TLS), access control with role-based permissions and central sign-in, strict tenant separation at the data level, regular backups with restore tests, logging of security-relevant events, and hardening and updating of the systems used.

7. Sub-processors

The customer approves the use of the following sub-processors. The Provider will inform the customer in advance in the application or by email of intended changes; the customer may object for good cause. The list corresponds to the processor table of the privacy policy at mimaster.com:

Sub-processor Purpose Place of processing / safeguards
Cloudflare, Inc. Hosting, delivery, storage (database/files) EU/USA — EU standard contractual clauses
Amazon Web Services EMEA SARL (SES) Sending of transactional emails EU (region eu-central-1)
Stripe Payments Europe Ltd. Payment processing of subscriptions EU/USA — EU standard contractual clauses; for payment data partly a separate controller
Provider's own server infrastructure Sign-in service (login) and operating services EU/Switzerland

8. Support and notification obligations

The Provider supports the customer with appropriate means in responding to data-subject requests (information, correction, deletion, portability — the application's export and deletion functions are available for this) and with the obligations under Art. 32–36 GDPR. The Provider reports breaches of the protection of personal data to the customer without undue delay, with the information available pursuant to Art. 33(3) GDPR.

9. Deletion and return

After termination of the usage contract, the customer may export its data in a common format for 30 days; thereafter the Provider deletes the data, unless statutory retention obligations apply. Backups are overwritten on a rotating basis.

10. Evidence

Upon request, the Provider provides the customer with the information required to demonstrate the obligations under Art. 28 GDPR (in particular a description of the measures under Section 6). Further audits take place after prior notice, during business hours and at the customer's expense.

11. Final provisions

The law pursuant to the General Terms and Conditions of mimaster applies. In the event of contradictions between this agreement and the General Terms and Conditions, this agreement takes precedence with regard to data processing. Conclusion takes place electronically in the application; time, account and version are logged.