MIXCONIX.COM
  • Coming to the SAP StoreBusiness Partner ValidatorDRC compliance for business partner master dataBusiness Partner ScoringCredit intelligence and portfolio analyticsZebra Scanner BridgeBarcode capture and smart glassesSAP Basis MonitoringHealth checks and predictive alerting
    Further productsNote CompanionSAP Notes governance
    DeliveryS/4HANA Cloud ConversionECC to S/4HANA, end to endSAP Field Service ManagementScheduling and mobile techniciansAll apps and solutions →
  • Services
  • Downloads
  • Company
  • Career
Book a Demo
  • Apps on BTP
  • Business Partner Validator
  • Business Partner Scoring
  • Zebra Scanner Bridge
  • SAP Basis Monitoring
  • Services
  • Downloads
  • Company
  • Career
  • Book a Demo
Home / Compliance / Privacy Policy
Mixconix SAP Store Applications

Privacy Policy

Last updated: 14 August 2025

Contents

  • 1. Controller & Contact
  • 2. Overview
  • 3. Purposes & Legal Bases
  • 4. Categories of Data
  • 5. Hosting & CDN
  • 6. Cookies & Consent
  • 7. Server Logs
  • 8. Third-Party Tools
  • 9. Website Registration
  • 10. Newsletter & Marketing
  • 11. Online Conferencing
  • 12. Job Applications
  • 13. Social Media
  • 14. Recipients
  • 15. International Transfers
  • 16. Retention Periods
  • 17. Security Measures
  • 18. Your Rights
  • 19. Exercising Rights
  • 20. Non-EEA Transfers
  • 21. Changes
  • Appendix A — Processors
  • Appendix B — Retention
  • Appendix C — DSR Workflow
  • Appendix D — Security Controls

1. Controller and Contact Details

Organization: MIXCONIX.COM SRL
CUI: RO 31654250
Address: Str. Brândușelor 74, Green Centre, Brașov, Romania
Privacy Contact: office@mixconix.com

2. Overview of Data Protection

Personal data encompasses "any information relating to an identified or identifiable natural person."

Data Collection Methods

  • Direct provision via forms, email, phone, or contracts
  • Automatic collection from websites and services
  • Third-party sources including partners and social media platforms

Processing Purposes

  • Website security and service provision
  • Inquiry response and contract administration
  • Analytics and user experience optimization
  • Marketing and advertising activities
  • Legal compliance and claim defense

Key Rights

Access, rectification, erasure, restriction, objection, portability, consent withdrawal, and supervisory complaint filing.

3. Purposes and Legal Bases of Processing

  • A1 · Website Security: Legitimate interests (Art. 6(1)(f)) for system resilience.
  • A2 · Pre-contractual/Contractual: Contract performance (Art. 6(1)(b)); legal obligations (Art. 6(1)(c)).
  • A3 · Newsletters: Consent (Art. 6(1)(a)).
  • A4 · Marketing/Surveys: Consent (Art. 6(1)(a)).
  • A5 · Third-party Disclosure: Consent (Art. 6(1)(a)).
  • A6 · Legal Compliance: Legal obligation (Art. 6(1)(c)).
  • A7 · Legal Claims: Legitimate interests (Art. 6(1)(f)).

4. Categories and Sources of Personal Data

Data Categories

  • Identification and professional information
  • Contact details
  • Commercial and contract information
  • Technical and usage data
  • Marketing preferences and consent records

Sources: Data subjects, website systems, partners, processors, and public sources where legally permitted.

5. Hosting and Content Delivery Networks (CDN)

External hosting providers process personal data under Data Processing Agreements. CDNs such as Amazon CloudFront route information and filter malicious traffic using cookies strictly per policy purposes.

Legal Basis: Legitimate interests (Art. 6(1)(f)) and contract performance (Art. 6(1)(b)); international transfers protected by Standard Contractual Clauses.

6. Cookies and Consent Management

Cookies that are not strictly necessary are only set with your consent. Consent Management Platforms collect and manage non-essential cookie preferences. Browser management is available; disabled cookies may limit functionality.

7. Server Logs and Contact Channels

Server Logs Collect

  • Browser and OS information
  • Referrer URL, hostname, request time, IP address

Legal Basis: Legitimate interests (Art. 6(1)(f)) for technical operation and security.

Contact forms and communications are processed under contract, pre-contractual steps, legitimate interests, or consent.

8. Third-Party Tools and Integrations

  • Google Tag Manager: Tag management system deploying analytics and marketing tags; collects IP addresses.
  • Google Analytics: Analyzes website usage including pages accessed, session duration, device/OS, approximate geolocation using cookies and device identifiers.
  • Google Ads & Remarketing: Interest-based advertising and campaign effectiveness measurement.
  • Meta (Facebook) Pixel: Conversion measurement and audience building for Meta platform advertising; joint controller arrangements may apply.
  • LinkedIn Insight Tag: Conversion measurement, audience insights, and LinkedIn ad retargeting.
  • YouTube (Privacy-Enhanced Mode): Embedded videos may set cookies upon playback using privacy-enhanced settings where available.
  • CRM (HubSpot): Customer relationship and marketing workflow management.
  • Online Forms (Typeform): Form data stored by provider and shared for request processing.
  • Workflow Automation (Zapier): Tool integration and task automation.

Legal Bases: Legitimate interests (Art. 6(1)(f)) and/or consent (Art. 6(1)(a)); contract performance where applicable.

9. Registration on the Website

"Data you provide will be used to enable and administer your account and notify you of important changes." Legal basis: consent and/or contract; retention while account active and as required by law.

10. Newsletter and Direct Marketing

Email subscription requires address ownership confirmation. You may withdraw consent at any time via the "Unsubscribe" link.

Postal advertising uses legitimate interests (Art. 6(1)(f)); objection available without overriding grounds or legal obligations.

11. Online Audio and Video Conferences

Conferencing tools (Microsoft Teams, GoToMeeting/GoToWebinar) process metadata and exchanged content. Legal basis: contract, legitimate interests, and consent for recordings.

12. Job Applications

Application data (contact, communications, documents, interview notes) processed for recruitment decisions. Legal basis: contract and employment law; consent for talent pool inclusion.

Retention: Generally six months post-closure; longer for legal claims or with consent.

13. Social Media Presence

Platform pages (Facebook, LinkedIn, Instagram, YouTube) process data under platform policies. Joint controller arrangements may apply for certain activities like insights.

14. Recipients of Personal Data

Access limited to personnel and contractors requiring it, plus processors providing services (hosting, analytics, marketing, CRM, communications). All processors bound by Art. 28 GDPR contractual obligations.

15. International Data Transfers

Non-EEA transfers safeguarded by European Commission's Standard Contractual Clauses, supplemented by risk assessments and additional measures where required.

16. Retention Periods

  • Contracts/Billing: Contract duration plus 5–10 years statutory retention
  • Support/Communications: Three years from closure unless needed for claims
  • Marketing/Newsletter: Until consent withdrawal or two years inactivity
  • Server Logs: Up to 12 months, shorter where feasible
  • Recruitment: Six months post-closure; longer with consent or for legal claims

17. Security Measures

Technical and organizational measures include encryption in transit, network segmentation, access controls, multi-factor authentication for privileged accounts, vulnerability management, logging and monitoring, regular backups, and vendor due diligence.

18. Your Rights

  • Access (Art. 15): Obtain confirmation and data copy.
  • Rectification (Art. 16): Correct inaccurate/incomplete data.
  • Erasure (Art. 17): Request deletion per GDPR conditions.
  • Restriction (Art. 18): Request limited processing.
  • Portability (Art. 20): Receive data in structured, machine-readable format.
  • Objection (Art. 21): Object to legitimate interests processing and direct marketing.
  • Automated Decision Protection (Art. 22): Not subject to solely automated decisions with legal effects.
  • Consent Withdrawal (Art. 7(3)): Anytime without affecting prior processing.
  • Supervisory Authority Complaint: ANSPDCP — www.dataprotection.ro

19. How to Exercise Your Rights

Submit requests to office@mixconix.com. Response provided within one month, extendable by two months for complex requests. Identity verification conducted where necessary.

20. Information on Transfers to Non-EEA Countries

"Such jurisdictions may have laws permitting authorities to access personal data." Reliance on SCCs with additional risk mitigation measures implemented where possible.

21. Changes to this Policy

The current version will be available on our website and will indicate the date of the latest update.

Appendix A — Processors and Tools (Illustrative)

Provider / ToolPurposeData CategoriesLegal Basis / Safeguards
Hosting/CDN (AWS CloudFront)Hosting, content delivery, securityIP, usage/technical dataArt. 6(1)(f); SCCs
CMP (OneTrust CookiePro)Cookie consent collection/storageConsent preferences, IP, device infoArt. 6(1)(c) & (f)
Google Tag ManagerTag deploymentIP (limited), tag metadataArt. 6(1)(f); consent required
Google AnalyticsWeb analyticsUsage/technical, pseudonymous IDsArt. 6(1)(f) or 6(1)(a); SCCs
Google Ads / RemarketingAdvertising measurementPseudonymous IDs, usage dataArt. 6(1)(f) or 6(1)(a); SCCs
Meta (Facebook) PixelAudience / measurementPseudonymous IDs, usage dataArt. 6(1)(f) or 6(1)(a); joint controller
LinkedIn Insight TagAudience / measurementPseudonymous IDs, usage dataArt. 6(1)(f) or 6(1)(a); SCCs
YouTubeEmbedded videosUsage/technical, cookies on playbackArt. 6(1)(f) or 6(1)(a)
CRM (HubSpot)Lead/customer managementIdentification, contact, interactionsArt. 6(1)(b), (f), (a)
Forms (Typeform)Form submission collectionIdentification, contact, form contentArt. 6(1)(b), (f), (a)
Workflow Automation (Zapier)Integrations/data flowsVaries per workflowArt. 6(1)(f), (a)
Conferencing (Teams, GoTo)Online meetings/webinarsContact, metadata, contentArt. 6(1)(b), (f), (a) for recordings

Note: Providers listed are illustrative; DPA (Art. 28 GDPR) is executed with each processor.

Appendix B — Retention Schedule (Illustrative)

Data CategoryRetention PeriodRationale
Contracts / Invoicing10 yearsStatutory accounting / tax retention
Customer Support Tickets3 years from closureLimitation periods for claims
Marketing / NewsletterUntil withdrawal or 2 years inactivityConsent and best practice
Server LogsUp to 12 monthsSecurity and troubleshooting
Recruitment6 months after closure; longer with consentClaim defense; talent pool consent

Appendix C — Data Subject Request (DSR) Workflow

  1. Receipt, logging, and identity verification
  2. Triage to determine right invoked and data scope; coordinate with processors
  3. Data retrieval and review; apply exemptions (rights of others, legal privilege)
  4. Fulfillment within one month (extendable by two months); secure delivery; record keeping

Appendix D — Security Controls (Summary)

  • Access control and least privilege; role-based access; MFA for administrators
  • Encryption in transit; encryption at rest where supported
  • Patch and vulnerability management; change management
  • Logging, alerting, incident response; regular backups and recovery testing
  • Third-party risk management; DPAs and SCCs; periodic vendor reviews

Privacy questions? Contact office@mixconix.com.

MIXCONIX.COM

SAP BTP Partner. Engineering the Future of SAP.

SAP BuildISO 9001ISO 27001

Apps on BTP

  • Business Partner Validator
  • Scanner Application
  • Business Partner Scoring
  • SAP Basis Monitoring

Company

  • About MIXCONIX
  • Career
  • Downloads
  • Compliance
  • Contact

Contact

  • connect@mixconix.com
  • Brașov, Romania
  • VAT: RO31654250
SAP and the SAP logo are trademarks or registered trademarks of SAP SE in Germany and other countries.
ImpressumDatenschutzDPA