Privacy policy mioparere

Protecting your personal data is important to us. We therefore want to explain transparently what personal data we process when you use our website, why we process it, and what rights you have.

Who is responsible for processing your data?

The controller responsible for processing your personal data is

Untiedt Research GmbH
Denkmalstrasse 2
45529 Hattingen
Germany

You can find further information and contact options in our Legal notice.

What data do we process – and why?

Personal data means any information relating to you that can identify you directly or indirectly. This includes, for example, your name, your email address, or an online identifier. For simplicity, we generally refer to this below as "your data"; this always means your personal data.

We only process personal data if there is a legal basis for doing so. This is particularly the case

  • if you have given us your consent (Article 6(1), first subparagraph, point (a) GDPR and, where required, Article 9(2)(a) GDPR),
  • if the processing is necessary for you to use our website or our services (Article 6(1), first subparagraph, point (b) GDPR),
  • if we have a legitimate interest in improving our website, ensuring its security, or providing our services (Article 6(1), first subparagraph, point (f) GDPR),
  • if we process your enquiry or carry out pre-contractual measures (Article 6(1), first subparagraph, point (a) and/or point (b) GDPR),
  • if we are entering into or fulfilling a contract with you (Article 6(1), first subparagraph, point (b) GDPR),
  • or if we are legally obliged to process or retain certain data, for example to comply with tax or data protection requirements (Article 6(1), first subparagraph, point (c) GDPR).

Below, we explain step by step which data we process in each situation.

What data is automatically collected when you visit our website?

When you visit our website, your browser automatically sends certain technical information to our hosting provider, IPHH Internet Port Hamburg GmbH, Wendenstrasse 408, 20537 Hamburg, Germany. This information is stored in what are known as server log files.

You can find further information on data protection at our hosting provider here.

This may involve processing the following data, among other things:

  • the website you came from (referrer)
  • the page or file accessed
  • your browser type and the browser version used
  • your operating system
  • the amount of data transferred
  • the type of device used
  • date and time of access
  • your IP address in anonymized form (for example, by shortening the last digits so that it can no longer be linked to you)

We need this data so that our website can be delivered correctly to your device and can operate securely. It also helps us keep our website operational, detect errors, and prevent misuse.

This data is not combined with other data sources.

The server log files are used exclusively to ensure the technical operation of the website, analyze website traffic, and protect our systems. They are automatically deleted after 30 days.

Legal basis: Article 6(1), first subparagraph, point (f) GDPR (legitimate interest in the secure and reliable operation of our website).

How do we use cookies?

Our website uses cookies so that it works reliably and you can use all its features.

Cookies are small text files that are stored on your device. They help, for example, provide basic website functions or save the settings you have selected.

We do not use other storage technologies such as Local Storage or comparable methods, unless we expressly inform you otherwise where relevant.

Which cookies do we use?

Technically necessary cookies

Some cookies are necessary for our website to function at all. For example, they ensure that content is displayed correctly or that basic functions are available.

We use these cookies on the basis of Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) as well as Article 6(1), first subparagraph, point (f) GDPR.

Optional cookies and services

Where we use optional cookies or comparable services, we ask for your consent beforehand. Processing then takes place on the basis of Section 25(1) TDDDG as well as Article 6(1), first subparagraph, point (a) GDPR.

Using our consent management tool, you can at any time

  • see which cookies and services are being used,
  • change your consent, or
  • withdraw consent you have already given with effect for the future.

Please note that certain functions of our website may not work as intended if you reject or disable certain cookies.

How can you manage cookies?

You can also restrict or delete cookies directly via your browser settings. Most browsers offer appropriate options for this.

You can find instructions for the most common browsers here:

What happens when you contact us or register with mioparere?

When you contact us

If you contact us by email, via our contact form, or by any other means, we process the information you provide to us. This includes, for example, your name, your email address, and the content of your message.

We use this data to process your request and, if necessary, to respond to any follow-up questions.

Legal basis: Article 6(1), first subparagraph, point (b) GDPR. If you have given us your consent, the processing takes place on the basis of Article 6(1), first subparagraph, point (a) GDPR.

What happens when you register?

When you register with mioparere, we need certain personal data to create and manage your user account.

This includes in particular:

  • your name
  • your email address
  • your year of birth

You can also voluntarily provide further information, for example about your marital status or your gender. This information helps us manage your user account and send you suitable survey invitations.

We process mandatory information on the basis of Article 6(1), first subparagraph, point (b) GDPR. We only process voluntary information if you have given us your consent to do so (Article 6(1), first subparagraph, point (a) GDPR).

How do we use your data for surveys?

Participating in surveys is a core part of our service. When you take part in a survey, we process your data in order to

  • conduct and evaluate surveys,
  • manage your panel account,
  • credit points to your account,
  • pay out rewards,
  • and handle support and billing processes.

Which data is processed depends on the specific survey.

Participating in a survey is, of course, voluntary. You decide for yourself whether you want to take part and what information you want to provide.

Legal basis: Article 6(1), first subparagraph, points (a) and (b) GDPR.

What rules apply to particularly sensitive data?

Some surveys may involve so-called special categories of personal data. These include, for example, information about

  • your health,
  • political opinions,
  • religious or philosophical beliefs,
  • or your sexual orientation.

We only process such data if you have expressly given us your consent to do so for the relevant surveys.

Legal basis: Article 9(2)(a) GDPR.

You can withdraw your consent at any time with effect for the future. You will not suffer any disadvantage as a result.

Do we work with other market research institutes?

Yes. We conduct most surveys together with cooperation partners or other market research institutes.

In doing so, the following applies:

  • We only transmit pseudonymized data.
  • Our clients do not receive any personal data from you.
  • Results are evaluated exclusively in aggregated and anonymized form.

Legal basis: Article 6(1), first subparagraph, points (a) and (b) GDPR.

What external services do we use?

We use various technical services from external providers on our website. They help us operate our website securely, provide its functions, or continuously improve it.

Depending on the service, it may be necessary for technical information – such as your IP address – to be processed. This is necessary so that the relevant content or functions can be delivered to your device.

We make sure that we use only services that we need to operate our website or to further develop it. Where a service requires your consent, we obtain it beforehand via our consent management tool. There you can view, change, or withdraw your consent at any time.

The individual services are described below.

How do we manage your cookie settings?

To manage your consent, we use Klaro, a consent management tool provided by KIProtect GmbH, Bismarckstraße 10-12, 10625 Berlin.

With Klaro, you can see at any time

  • which services you have consented to,
  • change your selection, or
  • withdraw consent you have already given with effect for the future.

So that we can document your decision and comply with statutory documentation obligations, the following information, among other things, is processed:

  • time of your consent
  • IP address
  • browser and device information (user agent)
  • language
  • website visited
  • time zone

Legal basis:

  • Article 6(1), first subparagraph, point (f) GDPR (legitimate interest in legally compliant management of your consent)
  • Article 6(1), first subparagraph, point (a) GDPR (when you give your consent)
  • Article 6(1), first subparagraph, point (c) GDPR (legal obligation),

If you would like to learn more about how Klaro processes your data, you can find further information in the Klaro privacy notice.

Which technical libraries do we use?

So that our website works reliably across different browsers and all functions are provided as intended, we use various JavaScript libraries. These are loaded exclusively from our own servers and are used to ensure the technical functionality, compatibility, and user-friendliness of our website. No additional personal data is processed for analysis or advertising purposes in this context.

Legal basis: Article 6(1), first subparagraph, point (f) GDPR (legitimate interest in a secure, functional, and user-friendly website).

How do we analyze the use of our website?

To continuously improve our website, we use various analytics and statistics services. These help us understand which areas are used particularly often and how we can further optimize our website.

These services are only used if you have given your prior consent.

Google Tag Manager

We use the Google Tag Manager to integrate and manage various analytics and tracking services. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager itself does not create usage profiles. It merely ensures that other services – for example Google Analytics – can be loaded after you have given your consent. Your IP address may be processed in order to deliver the required scripts. Where personal data is transferred to the USA in this context, this takes place exclusively on the basis of the EU-US Data Privacy Framework.

Legal basis: Section 25(1) TDDDG as well as Article 6(1), first subparagraph, point (a) GDPR.

You can find further information in Google's privacy notice.

Google Analytics

We use Google Analytics 4 to better understand how our website is used. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

This may involve processing the following information, among other things:

  • pages accessed
  • time spent on the site
  • click paths
  • browser and device information
  • operating system
  • approximate location (city level)
  • anonymized IP address

The IP address is shortened before further processing (IP anonymization). The data collected is stored for a maximum of 14 months and then automatically deleted. Any transfer to the USA takes place exclusively on the basis of the EU-US Data Privacy Framework.

You can withdraw your consent at any time via our consent management tool or disable data collection using Google Analytics' browser add-on.

Legal basis: Section 25(1) TDDDG as well as Article 6(1), first subparagraph, point (a) GDPR.

You can find further information in Google's privacy notice.

Meta Pixel

We use Meta Pixel to measure the success of our advertising activities and further optimize our website.

The service is provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

After you have given your consent, the following data, among other things, may be processed:

  • IP address
  • browser and device information
  • pages accessed
  • referrer information
  • information about your use of our website

We are joint controllers with Meta for the collection and transmission of this data (Article 26 GDPR). Meta subsequently processes the data on its own responsibility. Any transfer of data to the USA takes place exclusively on the basis of the EU-US Data Privacy Framework.

Legal basis: Section 25(1) TDDDG as well as Article 6(1)(a) GDPR.

You can find further information on how Meta processes your data here.

You can find information on the joint controllership between Meta and us in the Controller Addendum pursuant to Article 26 GDPR.

You can find further information in Meta's privacy notice.

How are your rewards paid out?

We work together with various payment providers to pay out your rewards. The data processed depends on the payout method you choose. We only transmit the information required for the respective payout.

Payout via PayPal

If you redeem your collected credits for a payout via PayPal, we transmit the data necessary for the payment to

PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

This includes in particular

  • the email address you have on file with PayPal, or your PayPal ID,
  • the payout amount
  • as well as, where applicable, transaction information required to process the payout.

PayPal itself is responsible for processing your data in connection with the payment process.

We process the information required to initiate, document, and properly process the payout.

We store your data only for as long as necessary for payment processing or as long as statutory retention obligations apply.

Legal basis:

  • Article 6(1), first subparagraph, point (b) GDPR (contract performance)
  • Article 6(1), first subparagraph, points (c) and (f) GDPR (statutory documentation obligations as well as our legitimate interest in secure and reliable payment processing)

You can find further information in PayPal's privacy notice.

Payout by bank transfer, Amazon voucher, or donation

You can also redeem your credits for a bank transfer, an Amazon voucher, or a donation.

We process the data required for the respective option. This includes, for example,

  • your bank details for a transfer,
  • your email address for sending an Amazon voucher
  • or the information required to allocate and process your chosen donation to the relevant organization.

We collect donations and transfer the accumulated amount to the respective organization at regular intervals.

We use this data exclusively to process the reward or donation you have chosen.

We store your data only for as long as necessary for processing or as long as statutory retention obligations apply.

Legal basis: Article 6(1), first subparagraph, point (b) GDPR (contract performance).

Who receives your data?

We treat your personal data confidentially and only pass it on if this is necessary for providing our website or our services, or if we are legally obliged to do so.

Recipients of your data may include, in particular:

  • our employees, insofar as they need the data to perform their duties,
  • service providers who support us in providing and operating our website (processors),
  • and – depending on the features you use – the providers named in this privacy policy, for example for analytics services or payment processing.

Our hosting is provided by IPHH Internet Port Hamburg GmbH, including the subprocessors it engages.

Your personal data is only passed on to other third parties if

  • you have expressly consented,
  • we are legally obliged to do so, or
  • the disclosure is necessary for the performance of a contract with you.

Is your data also processed outside the EU?

In principle, we process your personal data within the European Union (EU) or the European Economic Area (EEA).

However, for certain services, personal data may also be transferred to so-called third countries – i.e., states outside the EU or EEA. This applies in particular to the following providers:

  • Google
  • Meta
  • Microsoft
  • PayPal

Where such data transfers take place, we ensure that the legal requirements of the GDPR are met.

Depending on the provider, the transfer takes place in particular on the basis of

  • the EU-US Data Privacy Framework,
  • the Standard Contractual Clauses approved by the European Commission
  • or other appropriate safeguards under the GDPR.

You can find out which basis applies in a specific case in the description of the relevant service above in this privacy policy.

If you have any questions about the processing of your data or data transfers to third countries, you can contact us at any time.

How long do we store your data?

We store your personal data only for as long as it is necessary for the relevant purpose or as we are legally obliged to do so.

As soon as the purpose of the processing no longer applies and there are no statutory retention obligations or other legitimate reasons for further storage, we delete your data.

Server log files

The server log files automatically collected when you visit our website are automatically deleted by our hosting provider after 30 days.

Cookies

Session cookies are automatically deleted as soon as you close your browser.

Cookies with a longer storage period remain on your device until they expire. You can delete them or prevent their storage at any time via your browser settings. You can find further information on this in the section “How do we use cookies?”

Contact requests

When you contact us, we store your information until your request has been fully processed.

We then delete the data, unless statutory retention obligations apply. In individual cases, commercial, tax, or data protection laws may require longer storage.

In addition, we may store certain data until the statutory limitation periods expire, if this is necessary to assert, exercise, or defend legal claims.

User account

We store your user account data for as long as your account is active.

If you delete your user account, your personal data will be deleted within 30 days, unless statutory retention obligations prevent deletion.

Statutory retention obligations

Certain data is subject to statutory retention periods, for example under the German Commercial Code (HGB) or the Fiscal Code (AO).

In these cases, we may or must retain the relevant data for the legally prescribed period. Depending on the type of data, this period is generally six or ten years.

Regular review

We regularly review whether personal data is still needed.

As soon as the respective processing purpose no longer applies, no statutory retention obligations remain, and no legitimate interests preclude deletion, the data is deleted.

Legal bases

Depending on the purpose of the processing, storage is based in particular on

  • Article 6(1), first subparagraph, point (a) GDPR (consent),
  • Article 6(1), first subparagraph, point (c) GDPR (legal obligation),
  • Article 6(1), first subparagraph, point (f) GDPR (legitimate interests, in particular for asserting, exercising, or defending legal claims).

What rights do you have?

You retain control over your personal data. That's why you have various rights under the General Data Protection Regulation (GDPR). If you would like to exercise one of these rights or have questions about the processing of your data, you can contact us at any time.

In principle, you are not obliged to provide us with personal data. However, certain functions of our website or use of our services may require specific information. Without this data, we may not be able to provide you with certain services.

How do we use your profile data?

So that we can offer you suitable surveys, we use the information from your user profile to check which surveys may be suitable for you.

This process is referred to as profiling (Article 4(4) GDPR). We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you.

If an automated filter detects possible misuse, your account is not blocked automatically. Each case is reviewed by a person before a decision is made.

Legal basis: Article 6(1), first subparagraph, points (a) and (b) GDPR.

What rights do you have specifically?

Where the statutory requirements are met, you have, in particular, the following rights:

Right to access

You can request information at any time about which personal data we have stored about you and how we process it (Article 15 GDPR).

Right to rectification

If your data is incomplete or incorrect, you can request its rectification (Article 16 GDPR).

Right to erasure

Where the statutory requirements are met, you can request that we delete your personal data (Article 17 GDPR).

Right to restriction of processing

In certain cases, you can request that the processing of your data be restricted (Article 18 GDPR).

Right to data portability

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or – where technically feasible – to have it transferred to another provider (Article 20 GDPR).

Right to withdraw your consent

If you have given us consent to process your personal data, you can withdraw your consent at any time with effect for the future (Article 7 GDPR).

The withdrawal does not affect the lawfulness of the processing carried out before the withdrawal.

Right to object

You also have the right to object to the processing of your personal data under certain circumstances (Article 21 GDPR).

You can find further information on this in the section “When can you object to the processing of your data?”

How can you exercise your rights?

If you would like to exercise one of your rights or have questions about data protection, you can contact us at any time. You can find the relevant contact details in the section “Who is responsible for processing your data?”

Would you like to file a complaint?

If you believe that we are not processing your personal data in accordance with data protection law, you have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).

The following supervisory authority is responsible for our company:

North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information
Kavalleriestraße 2–4, 40213 Düsseldorf.

You can find further information on the website of the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.

When can you object to the processing of your data?

In certain cases, you have the right to object to the processing of your personal data.

Objection based on legitimate interests

Insofar as we process your personal data on the basis of our legitimate interests (Article 6(1), first subparagraph, point (f) GDPR), you can object to this processing on grounds relating to your particular situation.

If you object, we will no longer process your personal data, unless

  • we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights, and freedoms,
  • or the processing serves to assert, exercise, or defend legal claims.

How can you object?

You can send us your objection at any time and without any specific formal requirements. You can find the contact details in the section “Who is responsible for processing your data?”

If you have any questions about data protection or the processing of your data, please feel free to contact us at any time. We are happy to help.

Last updated: August 10, 2026