1. Privacy at a Glance
The following information gives you a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally.
This website deliberately does without analytics tools, advertising cookies, and social media plugins. Data is only collected when you provide it to us directly (contact form, email, phone), when it is technically necessary for operating the site (server log files, the contact form's session cookie), or when you actively click to load the Google Maps direction finder.
2. Data Controller
minionKIDS – Kindertagespflege
Hasmik Khachatryan & Astghik Ivers
Semperplatz 5
22303 Hamburg
Phone: 0170 5925789
Email:
kontakt@minionkids.de
The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
3. Hosting
This website is hosted by an external service provider. The personal data collected on this website is stored on the host's servers (in particular IP addresses, contact inquiries, and meta and communication data). We use this host in the interest of providing our online offering securely, quickly, and efficiently (Art. 6 Abs. 1 lit. f DSGVO).
We use the following host:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
To ensure GDPR-compliant processing, we have entered into a data processing agreement (Auftragsverarbeitungsvertrag, "AVV") with our host.
4. General Information and Mandatory Disclosures
Data Protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. Please note that data transmitted over the internet (e.g., when communicating by email) may be subject to security gaps. Complete protection of data against access by third parties is not possible.
Retention Period
Unless a more specific retention period is stated in this privacy policy, your personal data will remain with us until the purpose for processing it no longer applies. If you assert a valid request for deletion or withdraw your consent to processing, your data will be deleted, provided no other legally permissible grounds for retention exist (e.g., statutory retention periods under tax law).
Withdrawing Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You may withdraw consent you have already given at any time. Such withdrawal does not affect the lawfulness of any processing carried out before the withdrawal.
Right to Object (Art. 21 DSGVO)
If data processing is based on Art. 6 Abs. 1 lit. e or f DSGVO, you have the right at any time to object to the processing of your personal data for reasons arising from your particular situation. The relevant legal basis for each type of processing is stated in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the DSGVO (GDPR), data subjects have the right to lodge a complaint with a supervisory authority. The competent authority for Hamburg is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, datenschutz-hamburg.de.
Access, Rectification, Erasure, Restriction, Data Portability
Under applicable legal provisions, you have the right at any time to request free information about your stored personal data, its origin and recipients, and the purpose of the processing, as well as the right to have this data corrected or deleted, to restrict its processing, and to have it transferred in a common, machine-readable format. You may contact us at any time regarding these rights or any other questions about data protection.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, such as inquiries sent through the contact form, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the lock icon in your browser bar.
5. Data Collection on This Website
Server Log Files
The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request, and IP address. This data is not combined with data from other sources. This collection is based on Art. 6 Abs. 1 lit. f DSGVO – we have a legitimate interest in the technically error-free presentation and security of our website.
Cookies
This website does not use analytics, marketing, or third-party cookies. Only on the contact page is a technically necessary session cookie set, used solely to protect the contact form from abuse (a security token and a spam-protection math challenge). It contains no data that could be used to identify you personally and is automatically deleted when you close your browser. The legal basis is § 25 Abs. 2 TDDDG in conjunction with Art. 6 Abs. 1 lit. f DSGVO; consent is not required for technically necessary cookies.
Contact Form
If you send us inquiries via the contact form, the information you provide in the form (name, email address, phone number if given, subject, and message) is stored by us in order to process your inquiry and in case we have follow-up questions. We do not share this data without your consent.
Processing is based on Art. 6 Abs. 1 lit. b DSGVO where your inquiry relates to entering into or fulfilling a Betreuungsvertrag (childcare contract). In all other cases, processing is based on our legitimate interest in effectively handling inquiries addressed to us (Art. 6 Abs. 1 lit. f DSGVO). The data remains with us until you ask us to delete it or the purpose for storing it no longer applies.
If your inquiry does not result in a childcare contract, we remove it from the contact form log no later than three months after receipt.
Online Childcare Contract
If we have sent you a personal link to the childcare contract (Betreuungsvertrag), you can fill out the contract on this website. In doing so, we process information about the child, the parents/legal guardians, the agreed care hours and fee, and the persons you designate as authorized for pickup. The legal basis is Art. 6 Abs. 1 lit. b DSGVO – this information is required to enter into and carry out the childcare contract.
We additionally collect health-related information: health insurance provider and insurance number, allergies and medications, and – optionally – the child's pediatrician. We process these special categories of personal data on the basis of your express consent (Art. 9 Abs. 2 lit. a DSGVO), which you give by submitting the contract; without it, we cannot responsibly provide care. Proof of measles immunity (Masernschutz) is required under § 20 Abs. 9 Infektionsschutzgesetz (the German Infection Protection Act) (Art. 6 Abs. 1 lit. c, Art. 9 Abs. 2 lit. i DSGVO).
What We Keep, and for How Long. We retain the contract itself for six years (§ 147 Abs. 1 Nr. 2 und 3, Abs. 3 AO, the German Fiscal Code). Because a childcare contract is a continuing obligation, this period only begins at the end of the calendar year in which the care relationship was fully terminated. Everything that loses its purpose afterward, by contrast, we delete four weeks after the last day of care: health insurance provider and insurance number, allergies and medications, the pediatrician information, and the contact details of the persons authorized for pickup.
Proof of Measles Immunity. We are only permitted to record that proof was presented. An uploaded copy is therefore deleted as soon as the childcare provider (Tagespflegeperson) confirms it has been reviewed. What remains is a note with the date and the name of the person who reviewed the proof; this note, too, is removed when the care relationship ends.
Technical Metadata. To document that the contract was submitted, we store the date and time as well as the IP address. The IP address is already truncated at the time of submission, so that only the network can be identified; we do not store a browser identifier. The contract link expires after submission and cannot be used a second time.
The sole recipient of this data is your childcare provider (Tagespflegeperson). No further disclosure takes place; storage on the server is covered by the data processing agreement mentioned under "Hosting."
Meal Plan Newsletter
If you sign up for the meal plan newsletter, we store your email address as well as – as proof of consent – the date, time, and IP address of your sign-up. Registration is confirmed via double opt-in: you will only actually receive the newsletter once you click the link in the confirmation email. The legal basis is your consent (Art. 6 Abs. 1 lit. a DSGVO).
We retain this data until you unsubscribe. Every meal plan email contains an individual unsubscribe link that lets you opt out at any time, with a single click and without giving a reason – your data is deleted immediately when you do.
Inquiries by Email or Phone
If you contact us by email or phone, your inquiry, including any personal data arising from it, is stored and processed by us for the purpose of handling your request. The same legal bases and retention periods apply as for the contact form.
6. Google Maps (Two-Click Solution)
On our contact page, we offer a directions map provided by the Google Maps service. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
The map is not loaded automatically: a connection to Google's servers is only established once you actively click "Load map." When you do, data (including your IP address) is transmitted to and stored by Google – potentially also on servers in the USA; this transfer relies on the European Commission's Standard Contractual Clauses. Before you click, no data whatsoever is sent to Google. The legal basis is your consent given by clicking (Art. 6 Abs. 1 lit. a DSGVO); it applies to that particular page visit and can be "withdrawn" by reloading the page. More information can be found in Google's Privacy Policy.
7. Link to Instagram
On our website, we link to our Instagram profile. This is a simple link, not an embedded plugin: no data is transmitted to Instagram or Meta when you visit our website. Only when you click the link do you leave our website; from that point on, Instagram's Privacy Policy applies.
The German version of this page is legally binding. View the German version