Privacy policy
1. Controller
The controller responsible for data processing on this website is:
Miro Sozialdienste GmbH Königsberger Platz 30 51371 Leverkusen Germany
Represented by the managing director:
Farhat Miro Phone: +49 157 32490591 Email: info@miro-sozialdienste.de
2. General information
Protecting your personal data is particularly important to us.
We process personal data exclusively in accordance with the GDPR, the German Federal Data Protection Act (BDSG) and the specific rules on social data protection.
This policy explains which data we process when you visit this website and when you contact us. If we process data as part of an actual support service, you will receive separate information about it.
3. Hosting and delivery of this website
This website is hosted by Netlify. The provider is Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA, together with its European entity. Netlify operates the servers from which your browser retrieves our pages, images, fonts and stylesheets.
When you open a page, your browser transmits technically necessary data to these servers, in particular your IP address. Without this transmission the website cannot be delivered.
The pages of this website are generated in advance and delivered as finished files. There is no database or other permanent storage in which visitor data would be kept.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and efficient provision of our website.
A data processing agreement pursuant to Article 28 GDPR is in place with Netlify. For the log data this generates and how long it is kept, see section 4.
As the provider is based in the USA, a transfer of personal data to a third country outside the EU/EEA cannot be ruled out. Such transfers take place on the basis of the provider’s certification under the EU-US Data Privacy Framework; in addition, the standard contractual clauses pursuant to Commission Decision (EU) 2021/914 agreed in the data processing agreement apply.
Further information on data protection at Netlify: https://www.netlify.com/privacy/
4. Server log files
When you visit this website, log data (server and function logs) may be recorded automatically by the hosting provider. This data may include:
the IP address of the requesting device, the date and time of access, the name and URL of the file retrieved, the volume of data transferred and the status message, browser type and operating system, and the previously visited page (referrer), if your browser transmits it.
This data is used solely for technical operation, security and troubleshooting. We do not use it to identify individuals and do not combine it with other data sources. No analysis of user behaviour takes place.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the security and operability of our website.
Retention: depending on the plan, the hosting provider keeps these logs for between 24 hours and 7 days and then deletes them automatically.
5. No cookies, no trackers, no external services
This website does not set any cookies and does not store information on your device.
We do not use analytics or statistics services, tracking, advertising networks, social media plugins, embedded maps, videos or chat windows, and no external fonts. Every file your browser loads comes from our own web server; the fonts we use are hosted locally.
This is also why you will not see a consent banner on this website: there is no processing you would need to consent to. Most of our pages are delivered without any application JavaScript at all.
Data is only transmitted to us if you complete and submit the contact form. The next section explains what happens in that case.
6. Contact form
You can send us a message using the form on our contact page. We process the details you enter yourself:
first name and surname (optional), email address (required), phone number (required), and your message (optional).
Purpose: we process this information solely in order to handle your enquiry and reply to you.
Legal basis: Article 6(1)(b) GDPR where your enquiry serves the initiation or performance of a contractual or support relationship. For general enquiries the legal basis is Article 6(1)(f) GDPR; our legitimate interest is responding to enquiries addressed to us. Providing your name and a message is optional; without an email address and a phone number we cannot process your enquiry.
Please do not use this form to send health data or other special categories of personal data within the meaning of Article 9 GDPR. For confidential matters, please call us or arrange a personal meeting.
How the data travels: your entries are transmitted over an encrypted connection (TLS) to an endpoint of our own website and sent from there by SMTP via the mail server of our provider 1&1 IONOS SE as an email to our mailbox kontakt@miro-sozialdienste.de.
No storage at the host: we do not operate a database or any permanent storage for this form. Your details remain in the memory of the server function only for the duration of processing and are not retained afterwards. The only place your message is stored is our email mailbox.
Recipients: only the managing director has access to the kontakt@miro-sozialdienste.de mailbox. Messages are not forwarded to other mailboxes and not passed on to third parties unless we are legally obliged to do so. Netlify (provision of the endpoint) and 1&1 IONOS SE (email dispatch and mailbox) act as processors in the technical transmission.
Retention and erasure: no fixed period is set. We delete your enquiry once it has been dealt with conclusively and no statutory retention obligation applies. If your enquiry leads to a support or contractual relationship, the longer statutory retention periods apply.
7. Contacting us by email or phone
If you contact us by email or by phone, we process the information you provide in order to handle your enquiry.
Legal basis: Article 6(1)(b) GDPR for enquiries relating to a contract or support relationship, and otherwise Article 6(1)(f) GDPR.
Our domain and our email mailbox are operated by 1&1 IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany. The servers are located in Germany. A data processing agreement pursuant to Article 28 GDPR is in place with Ionos.
Please note that the content of an email is generally not end-to-end encrypted in transit. Please do not send particularly sensitive information by email.
Only the managing director has access to the mailbox. Your information is not passed on to third parties unless we are legally obliged to do so. We delete your enquiry once it has been dealt with conclusively and no statutory retention obligation applies.
8. Job applications
Applications reach us by email at our mailbox info@miro-sozialdienste.de. We process the details and documents you send us solely in order to carry out the application procedure.
Legal basis: section 26(1) BDSG in conjunction with Article 6(1)(b) GDPR for the decision on entering into an employment relationship. Where you provide further information voluntarily, that processing is based on your consent under Article 6(1)(a) GDPR, which you may withdraw at any time with effect for the future.
Only the managing director has access to application documents. They are not passed on to third parties.
Erasure: we delete application documents after the application procedure has been completed, once the periods for asserting claims under the German General Equal Treatment Act (AGG) have expired and no statutory retention obligation applies. We keep documents for future vacancies only with your explicit consent. If you are hired, the documents are transferred to your personnel file.
9. Protection against misuse of the form
To protect our contact form against automated submissions and bulk enquiries we use two simple technical measures that work without cookies and without external services:
An additional field that is invisible to you (a "honeypot") and is only filled in by automated programs. If it is filled in, we discard the submission without forwarding it.
A limit on the number of submissions: we accept a maximum of five form submissions per IP address within 15 minutes. For this purpose your IP address is held solely in the memory of the server function for the duration of that time window and is then discarded automatically. There is no permanent storage and no profiling.
In addition, we check that the submission originates from our own website and we limit the length of the input fields.
Legal basis: Article 6(1)(f) GDPR in conjunction with Article 32 GDPR. Our legitimate interest is preventing misuse, keeping our website available and securing the processing.
10. Processing personal data in connection with social services
When providing educational support, school assistance and inclusion support, we process personal data only on the basis of legal obligations (Social Code Books VIII and IX), within assistance planning procedures (section 36 SGB VIII) and in close coordination with the responsible youth welfare office.
Legal basis: Article 6(1)(c) and (e) GDPR in conjunction with the provisions of Social Code Books VIII and IX. Where special categories of personal data are processed, the processing is based on Article 9(2)(b) and (h) GDPR and on section 22 BDSG.
Such data is additionally subject to social data protection under sections 61 et seq. SGB VIII and section 35 SGB I, as well as to the professional duty of confidentiality of our staff.
Data is processed only for its intended purpose and treated confidentially. We provide separate, plain-language information about the processing in each individual case.
11. Retention period
Personal data is stored only for as long as necessary to fulfil the relevant purpose or statutory retention requirements.
For the individual processing operations this means: log data is deleted automatically by the hosting provider after 24 hours to 7 days. Contact enquiries are deleted once they have been dealt with conclusively. Section 8 applies to application documents. Statutory retention periods apply to records arising from services under Social Code Books VIII and IX and to documents relevant under tax and commercial law.
12. Your rights
You have the right at any time to obtain information about the data we process about you (Article 15 GDPR), to have inaccurate data rectified (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR), to data portability (Article 20 GDPR) and to object to processing based on a legitimate interest (Article 21 GDPR).
Where processing is based on consent, you may withdraw that consent at any time with effect for the future (Article 7(3) GDPR).
To exercise your rights, simply send a message to the contact details given in section 1.
13. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Article 77 GDPR).
The supervisory authority responsible for us: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW) Kavalleriestrasse 2-4 40213 Duesseldorf, Germany Phone: +49 211 38424-0 Email: poststelle@ldi.nrw.de
Specialist supervisory authority (child and youth welfare): Youth Welfare Office of the City of Leverkusen
14. Encrypted transmission
This website is delivered exclusively over an encrypted connection (TLS, indicated by "https://" in the address bar). This prevents third parties from reading the data transmitted between your browser and our server.
We also apply technical protection measures in the browser, including a Content Security Policy that prevents third-party content from being loaded.
15. Status of this policy
We update this privacy policy when our processing activities or the legal requirements change.
Last updated: August 2026
