Privacy Policy
Information on the processing of personal data pursuant to Art. 13 and 14 GDPR for the website insightfox.de, the protected customer area and participant recruiting. Last updated: September 2026.
1. Controller
WMM GmbH
Hamburger Straße 11
22083 Hamburg
Germany
Email: info@insightfox.de
"Insight Fox" is a brand of WMM GmbH. The controller within the meaning of the GDPR is WMM GmbH.
2. Data Protection Officer
Our Data Protection Officer is Lulu Petrina.
Privacy contact:
Lulu Petrina
Email: datenschutz@insightfox.de
3. Visiting the website
3.1 Server log data
When you access the website, our hosting provider processes technically necessary connection data: IP address, date and time of access, page requested, data volume transferred, browser type and version, and operating system. This processing is necessary to deliver the website and ensure its security (Art. 6(1)(f) GDPR). The website is provided via the platform of the provider Lovable.
3.2 Cookies, local storage and tracking
We use no analytics, tracking or marketing cookies and no web analytics services. The website itself sets no cookies. Only technically necessary values are stored in your browser's local storage:
- Your chosen language (German/English), so that the setting is retained on your next visit.
- After signing in to the protected area, the session token that keeps you logged in (see section 5).
This storage is strictly necessary to provide the service you have explicitly requested (§ 25(2) no. 2 TDDDG). No consent is required; therefore no cookie banner is displayed.
3.3 Fonts
The typeface used on this website ("Manrope", Open Font License) is part of the website and is delivered together with it through our hosting infrastructure (section 7). No connection to Google Fonts or any other external font provider is made for font delivery.
4. Contact, contact form and project assessment
4.1 Contact form
When you submit the contact form on this website, we process the details you enter: name, company (if provided), email address, phone number (if provided) and your message. The submission is stored in our database (table "contact_requests"), which is operated by our backend service provider (section 7). Technical connection data is also generated (section 3.1).
The purpose of the processing is to handle and answer your enquiry and to prepare a possible engagement. The legal basis is Art. 6(1)(b) GDPR (pre-contractual steps taken at your request); for general enquiries without a contractual context we rely on our legitimate interest in communicating with prospective clients (Art. 6(1)(f) GDPR).
We keep the enquiry for as long as is necessary to handle it and any follow-up communication, and delete it afterwards unless statutory retention obligations apply (see section 9). The details are not used for advertising and are not passed on to third parties for advertising or sales purposes; apart from the Insight Fox team, only the contractually bound processors named in section 7 have access.
Providing your name, email address and message is necessary for us to handle your enquiry; company and phone number are optional.
4.2 Project assessment
The "Project assessment" is computed entirely in your browser; no input is transmitted to us or stored by us.
4.3 Contact by email
If you contact us by email, we process your details (name, company, email address, content of your request) to handle your enquiry and to prepare a possible engagement (Art. 6(1)(b) GDPR; for general enquiries Art. 6(1)(f) GDPR).
5. Protected area: sign-in, customer dashboard and Operations Center
5.1 User accounts and sign-in
Access to the protected area is created exclusively by us; self-registration is not possible. For an account we process the email address, a securely hashed password, display name, assigned role (customer or Insight Fox team), company assignment where applicable, and sign-in timestamps. After signing in, a session token is stored in your browser's local storage. In the "forgot password" flow, a reset link is sent to the registered email address; this email is sent by our authentication service (section 7). The legal basis is the performance of the contract or usage agreement with you or your company (Art. 6(1)(b) GDPR) and our legitimate interest in secure access control (Art. 6(1)(f) GDPR).
5.2 Customer dashboard
In the dashboard, customers see only project-related information about their own projects: project number, status, recruiting progress as figures (target/confirmed participants), released quotas, milestones and project updates. Personal data of participants is not displayed in the customer dashboard. Dashboard content is released manually by the Insight Fox team; access is technically restricted to the respective company.
5.3 Operations Center (internal tool)
The Insight Fox team manages projects, customer contacts and participants in the Operations Center. All access is role-restricted; security- and project-relevant actions are recorded in an internal audit log with timestamp and acting person.
6. Data of study participants
6.1 Data processed
In the course of recruiting for qualitative studies we process the following data of participants and candidates: name, contact details (phone, email, location), demographic and study-related profile attributes, answers to screener questionnaires, notes from the personal phone check, availability, session and backup assignments, participation status (attended, cancelled, no-show), incentive status, internal ratings and post-study feedback, warning flags, the recruiting source, and the results of a duplicate check so that the same person is not created twice or invited too frequently.
6.2 Purposes and legal bases
- Selecting, screening and inviting suitable participants and handling participation and incentives: performance of the participation agreement with the data subject (Art. 6(1)(b) GDPR).
- Maintaining a participant history for quality assurance, avoiding duplicate records and excessive study frequency: legitimate interest (Art. 6(1)(f) GDPR).
- Where special categories of personal data (e.g. health data) are collected for individual studies, this is done only on the basis of separate, explicit consent (Art. 9(2)(a) GDPR).
6.3 Source of the data
We generally collect participant data directly from the data subject (screener, phone check). Where contact details reach us via recruiting channels or referrals, we inform the data subject at the latest upon first contact (Art. 14 GDPR).
6.4 Disclosure to customers
Customers do not receive personal participant data via the customer dashboard. Individual participant data is disclosed to a customer (e.g. first name and session assignment for conducting an interview) only where necessary to carry out the study and where participants have been informed accordingly.
7. Recipients and processors
We use the following service providers that process data on our behalf (Art. 28 GDPR):
- Lovable (provisioning and hosting platform for the website and the protected area).
- Supabase (database, authentication and dispatch of sign-in/password emails). The database is operated in a data centre in the EU (region eu-west-1, Ireland).
Data is disclosed to other third parties only where we are legally obliged to do so or you have consented.
8. Transfers to third countries
Data of the protected area is stored within the EU. For individual service providers headquartered or with a parent company in the USA (in particular Supabase Inc.), access from a third country cannot be ruled out. In these cases we base the transfer on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) or on EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
9. Retention periods
- Server log data is retained by the hosting provider only briefly for security purposes.
- Enquiries via the contact form and by email are deleted once the enquiry has been fully handled and no contractual relationship arises, unless statutory retention obligations apply.
- User accounts exist for the duration of the business relationship and are deactivated and deleted after it ends.
- Project and participant data is reviewed for continued necessity after completion of the respective project. Participant data in the participant history is retained only as long as necessary for quality assurance and to avoid excessive study frequency; at the data subject's request we delete it earlier unless legal obligations prevent this.
- Records relevant under commercial and tax law (offers, invoices, incentive receipts, business correspondence) are retained pursuant to § 257 HGB and § 147 AO: commercial and business letters 6 years, accounting vouchers 8 years, books and annual accounts 10 years.
10. Your rights
You have the following rights with regard to your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, an email to datenschutz@insightfox.de is sufficient.
11. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Straße 22, 7th floor
20459 Hamburg, Germany
Email: mailbox@datenschutz.hamburg.de
Web: datenschutz-hamburg.de
You may also contact the supervisory authority of your habitual residence or place of work.
12. Obligation to provide data, automated decision-making
Providing data is neither legally nor contractually required; without the data mentioned, however, we cannot handle an enquiry, provide access or arrange participation in a study. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place; in particular, no screener disqualifies automatically – every answer is reviewed by a person.
13. Changes to this privacy policy
We update this policy when our processing or the legal situation changes. The version published on this page applies.
