Privacy
Controller
Laggner Digital Solutions, owner Stefan Laggner Spitalstrasse 64, 9472 Grabs, Switzerland Email: hallo@laggner.li
Principles
We process personal data in accordance with the Swiss Data Protection Act (DSG) and, where applicable, the EU General Data Protection Regulation (GDPR). We collect only data that is necessary for the operation of mimaster, and we do not pass on personal data to third parties unless this is necessary for the provision of the service (processors below) or required by law.
What data we process and for what purpose
| Data category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Name, email (via the login service), organisation membership, role | Account and contract administration, login | Performance of the contract |
| Usage content | Content created in mimaster and uploaded files | Core of the service | Performance of the contract |
| Payment data | Billing name/address, subscription status; no card data held by us (processing by Stripe) | Billing | Performance of the contract, legal obligations |
| Communication data | Support requests, system emails | Support, contract performance | Performance of the contract, legitimate interest |
| Technical data | IP address, timestamp, error/log data | Security, operation, error analysis | Legitimate interest |
| Analytics data | Pseudonymous usage statistics (only with consent) | Improvement of the service | Consent (revocable) |
Processors / recipients
| Service | Purpose | Registered office / data location | Note |
|---|---|---|---|
| Cloudflare, Inc. | CDN, DNS, protection against attacks | USA/EU (global network) | Data transfer to the USA possible; safeguarded via standard contractual clauses |
| Own hosting (EU) | Operation of the application and database | EU | — |
| Stripe Payments Europe Ltd. | Payment processing, subscription management | Ireland/USA | Card data held exclusively by Stripe; Stripe's own privacy policy applies in addition |
| Amazon Web Services (SES) | Sending of system emails | Frankfurt (eu-central-1) | — |
| Zitadel (self-operated) | Login and authentication via the provider's central sign-in service: the customer account (name, email address, linked login providers such as Google) is stored across products for all of the provider's services; sign-in takes place separately per product | EU | Product and usage data remain separated with the respective product |
| Sentry (self-operated) | Error analysis | EU | technical error data; personal content is filtered out |
| Google Ireland Ltd. (Analytics 4) | Reach measurement — only with consent | Ireland/USA | Consent Mode v2; data transfer to the USA possible; withdrawal at any time via "Cookie settings" |
| DigitalOcean LLC (Spaces) | File storage | Frankfurt | — |
Cookies and consent
Technically necessary cookies (in particular session cookies) do not require consent. We set analytics cookies (Google Analytics) only after your explicit consent via the cookie banner; before consent, no such services are loaded. You can change your choice at any time via the "Cookie settings" link in the footer; if you decline or withdraw, tracking cookies that have been set are deleted.
Retention and deletion
We process account data and usage content for the duration of the contractual relationship. After deletion of the account or organisation, personal data is deleted or anonymised within 30 days, unless statutory retention obligations (in particular accounting-related, 10 years) apply. Backup copies rotate automatically; deleted data also disappears from the backups with the rotation cycle.
Data security
Transmission exclusively encrypted (TLS); access to production data only for authorised persons; infrastructure reachable exclusively via secured access; regular, encrypted backups.
Your rights
Within the framework of the DSG and the GDPR, you have the right to information, correction, deletion, restriction of processing, release or portability of your data, and to object to certain processing. You may withdraw consent granted at any time with effect for the future. Requests to: hallo@laggner.li. We may require proof of identity in order to process a request.
Supervisory authority
Switzerland: Federal Data Protection and Information Commissioner (FDPIC). Data subjects in the EU may also contact their national data protection supervisory authority.
Changes to this policy
We may amend this policy, in particular in the event of changes to the service or the legal situation. The version published on mimaster.com at the relevant time applies; in the event of material changes, we will inform active users in an appropriate manner.
Last updated: 24 July 2026
Data processing agreement (DPA)
Data Processing Agreement pursuant to Art. 28 GDPR
Version 1.0 — applies in addition to the General Terms and Conditions of mimaster (mimaster.com).
1. Parties
Controller: the customer (the business that uses mimaster and concludes the agreement in the application — company and account are logged upon conclusion).
Processor: Laggner Digital Solutions, owner Stefan Laggner, Spitalstrasse 64, 9472 Grabs, Switzerland, email: hallo@laggner.li (hereinafter the "Provider").
2. Subject matter and duration
The Provider operates the software mimaster (software-as-a-service at mimaster.com) for the customer and processes personal data on behalf of the customer in doing so. The agreement applies for the duration of the usage contract and ends upon its termination; Section 9 (Deletion and return) remains reserved.
3. Nature, purpose and scope of processing
Storage, display, organisation and transmission of the data entered by the customer into mimaster for the purpose of providing the contractual functions (in particular recording and managing briefings, products, change requests and incident reports, as well as subscription and revenue-share billing incl. notifications and exports). No processing for the Provider's own purposes takes place.
4. Types of data and categories of data subjects
- Types of data: account and master data of the customer's organisation and its members (name, company, address, email, contact details), the content of submitted briefings, product and change-request details incl. attachments, incident reports and support requests, billing and payout metadata.
- Data subjects: members and contacts of the customer's organisation, as well as third parties recorded by the organisation in briefings, attachments or change requests.
5. Instructions
The Provider processes the data only on the documented instructions of the customer; use of the application functions is deemed to be an instruction. If the Provider considers an instruction to be unlawful, it will inform the customer without delay and may suspend execution.
6. Confidentiality and technical and organisational measures
The Provider obliges all persons involved in the processing to maintain confidentiality. It takes appropriate technical and organisational measures pursuant to Art. 32 GDPR, in particular: encryption of transmission (TLS), access control with role-based permissions and central sign-in, strict tenant separation at the data level, regular backups with restore tests, logging of security-relevant events, and hardening and updating of the systems used.
7. Sub-processors
The customer approves the use of the following sub-processors. The Provider will inform the customer in advance in the application or by email of intended changes; the customer may object for good cause. The list corresponds to the processor table of the privacy policy at mimaster.com:
| Sub-processor | Purpose | Place of processing / safeguards |
|---|---|---|
| Cloudflare, Inc. | Hosting, delivery, storage (database/files) | EU/USA — EU standard contractual clauses |
| Amazon Web Services EMEA SARL (SES) | Sending of transactional emails | EU (region eu-central-1) |
| Stripe Payments Europe Ltd. | Payment processing of subscriptions | EU/USA — EU standard contractual clauses; for payment data partly a separate controller |
| Provider's own server infrastructure | Sign-in service (login) and operating services | EU/Switzerland |
8. Support and notification obligations
The Provider supports the customer with appropriate means in responding to data-subject requests (information, correction, deletion, portability — the application's export and deletion functions are available for this) and with the obligations under Art. 32–36 GDPR. The Provider reports breaches of the protection of personal data to the customer without undue delay, with the information available pursuant to Art. 33(3) GDPR.
9. Deletion and return
After termination of the usage contract, the customer may export its data in a common format for 30 days; thereafter the Provider deletes the data, unless statutory retention obligations apply. Backups are overwritten on a rotating basis.
10. Evidence
Upon request, the Provider provides the customer with the information required to demonstrate the obligations under Art. 28 GDPR (in particular a description of the measures under Section 6). Further audits take place after prior notice, during business hours and at the customer's expense.
11. Final provisions
The law pursuant to the General Terms and Conditions of mimaster applies. In the event of contradictions between this agreement and the General Terms and Conditions, this agreement takes precedence with regard to data processing. Conclusion takes place electronically in the application; time, account and version are logged.