Effective Date: August 5, 2026
Last Updated: August 5, 2026
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application (registry.minimise.today) as an account holder or otherwise interact with our registry services.
Under the EU General Data Protection Regulation (GDPR), the role we play depends on the type of data we are handling:
Registered accounts on our platform are linked to an Organization. Your account may be created directly by us, or it may be created and provisioned on your behalf by an administrator within your Organization. While your Organization controls who is granted access and manages active permissions, Minimise acts as a Controller for the essential technical credentials and session authentication logs required to keep your account secure and operational.
The controller responsible for the personal data for which Minimise acts as Controller is:
Minimise GmbH
Meyerbeerstr. 35
13088 Berlin, Germany
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
Email: hello@minimise.today
In accordance with Art. 13(2)(d) and Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The authority competent for Minimise is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), Alt-Moabit 59–61, 10555 Berlin, Germany.
We collect different types of personal data depending on how you interact with our platform.
When you visit or use our web application, we automatically capture technical logs to keep our platform secure and operational.
When you sign up for an account to use Minimise, or contact us for help, we collect information required to deliver our services and assist you.
Your organization uploads and processes operational logistics through our platform, and Minimise processes it strictly under your instruction:
Minimise takes a deliberately minimal approach to tracking. We do not use non-essential marketing, tracking, or profiling cookies, and we do not run session replays. Consequently, no cookie consent banner is legally required.
We only use the following consent-exempt cookies and tracking mechanisms:
| Cookie / Technology Name | Provider | Purpose | Type / Classification |
|---|---|---|---|
preferredLanguage | Minimise | Remembers your language preference for the user interface. | Functional (Consent-Exempt) |
sb-<project-ref>-auth-token | Supabase | Secure token that keeps you logged in (may be split across numbered chunks, e.g. .0/.1). | Strictly Necessary (Consent-Exempt) |
| Error Telemetry SDK | GlitchTip | Captures real-time system crashes and application bugs. Note: IP and email addresses are not attached to these events. | Strictly Necessary Telemetry |
Beyond cookies, we use the following consent-exempt on-device storage strictly to make the application function:
These storage technologies hold no marketing, advertising, or tracking data.
To deliver our platform features, we share data with selected third-party service providers (our sub-processors). The table below is our authoritative sub-processor list: every party Minimise engages appears here, and our internal records reference this list rather than restating it. Where a provider is located outside the European Economic Area (EEA), we ensure appropriate safeguards, such as Standard Contractual Clauses (SCCs), are in place to legally protect your data.
| Sub-processor | Purpose | Data Residency | Transfer Mechanism / Safeguards |
|---|---|---|---|
| Supabase Pte. Ltd (Singapore), with Supabase, Inc. (United States) as its sub-processor | Database, User Authentication, and Cloud Storage | Data stored in the EU Region (AWS eu-central-1, Frankfurt) | The Data Processing Addendum is incorporated into the Supabase Terms of Service and accepted electronically, together with Standard Contractual Clauses (SCCs) governing administration access by the US entity. |
| Cloudflare, Inc. | Content delivery through a global network | Global (edge locations worldwide) | Standard Contractual Clauses (SCCs). Content is served through a global network, so cached copies can rest outside the selected region while a user outside that region accesses them. |
| Vercel, Inc. | Application hosting and edge delivery for the registry app (processes request metadata and IP addresses) | Global edge, function region in Frankfurt | Standard Contractual Clauses (SCCs). Requests terminate at the globally nearest edge location before routing to the function region in Frankfurt. |
| Brevo | Transactional and Operational Emails | European Union | Signed Data Processing Agreement (DPA). |
| GlitchTip (Burke Software) | Error and application telemetry tracking | European Union (Germany, Frankfurt) | Signed Data Processing Agreement (DPA). |
| GitHub, Inc. | Run backup job | United States | Standard Contractual Clauses (SCCs). |
| Google (Google Drive) | Store backup | United States | Standard Contractual Clauses (SCCs). |
| OpenRouter (routing to DeepInfra) | AI categorization of user-uploaded photos of materials | United States | Standard Contractual Clauses (SCCs). OpenRouter is configured so that providers neither store the images nor use them for training; the images are processed transiently and not retained. See DeepInfra: https://deepinfra.com/privacy |
Google Maps Platform (Geocoding) is not a sub-processor: for the address strings it receives it acts as an independent data controller under its own controller-to-controller terms. Transfers to Google (US) are covered by Standard Contractual Clauses (Art. 46 GDPR); we share only the address string — no account identifiers.
Your data is stored and primarily processed in the selected EU region. Administration, support, operational telemetry and content delivery may, however, occur outside that region. Standard Contractual Clauses (SCCs) are the safeguard for those transfers.
When requesting support from our platform vendors, Minimise does not share customer records, personal data or live database contents with them. Should a support case ever require it, we will ask the affected customer first.
Supabase personnel outside the EEA may access platform data for administration, support and incident response under least-privilege, need-to-know controls, and such access is logged.
We only retain personal data for as long as necessary to fulfill the purposes for which we collected it, including satisfying legal, accounting, or reporting mandates.
hello@minimise.today are deleted after 2 years from the resolution of the ticket.Under the GDPR, you have specific, enforceable legal rights regarding your personal data.
To exercise any of these rights, please email us at hello@minimise.today. We will respond directly to all Controller requests within one month.
Important note for third-party contacts: If your personal information was uploaded to Minimise by one of our customer organisations (a PRO or Supplier) or a user acting on its behalf, Minimise acts strictly as a Processor. We cannot fulfill your request directly. Please route your data request to the specific user or company controlling your data, and we will assist them in executing it.
We implement comprehensive technical and organizational safeguards to secure your information. This includes application-layer role-based access control (RBAC) that scopes data to your organization, database access via a privileged service account, and encryption of data both at rest and in transit. Uploaded documents are held in a private storage bucket and are never publicly reachable; each view is served through a short-lived signed link generated only after we have checked that the requester is entitled to that organization's data.
In the event of a security incident affecting your personal data, we follow strict statutory notification procedures: