Last updated: 18 August 2026 — Effective immediately upon publication. Changes are not applied retroactively to data already collected (§ 12.4).
This Privacy Policy (hereinafter “Policy”) explains how Morphica Technologies, operating under the trade name “ThesisDraft” (hereinafter “Controller”, “we”, “us”, or “our”) collects, processes, stores, and protects personal data in connection with the operation of the website thesisdraft.com and the provision of our services. This Policy is issued in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, “GDPR”), the German Federal Data Protection Act (Bundesdatenschutzgesetz, “BDSG”), and the German Telecommunications-Telemedia Data Protection Act (Telekommunikation-Telemedien-Datenschutz-Gesetz, “TTDSG”).
§ 1 — Identity and Contact Details of the Controller
1.1. The Controller within the meaning of Article 4(7) GDPR is:
Morphica Technologies
(operating as ThesisDraft)
Email: contact@morphica.de
Website: thesisdraft.com
1.2. The Controller has not appointed a Data Protection Officer pursuant to Article 37 GDPR, as the conditions set forth in Article 37(1)(b) and (c) GDPR and § 38 BDSG are not met. For all data protection inquiries, the Controller may be contacted directly at the email address stated above.
§ 2 — Categories of Personal Data Processed
2.1. In the course of providing our services and operating the Platform, we collect and process the following categories of personal data:
2.1.1. Data Provided Directly by the Data Subject
- Email address — provided by the Client for the purpose of order communication and delivery of the Deliverable, and collected by Stripe at checkout for the purpose of issuing a payment receipt. We do not require, and do not ask for, a real name or an institutional email address. A pseudonymous address, a disposable address, or a private relay address of the kind offered by Apple, Mozilla, or a mail provider is accepted without restriction and without any reduction in service. The address used for delivery may differ from the address used for payment. We note for completeness that an email address remains personal data even where it is a relay address, and it is processed as such.
- Order details — thesis topic, academic level (Bachelor/Master), specific requirements, and any additional instructions provided by the Client in connection with an Order.
- Email address submitted to the launch notification list — where the Data Subject asks to be told when a product currently in development becomes available. This is a separate purpose with a separate legal basis and is not the same processing as the order-communication address above. It is collected only through an explicit, unticked opt-in, the wording of which is stored alongside the address together with the date, so that the consent given can be evidenced against the text actually displayed. No name, institution, or any other field is requested, and the address is not combined with any other data we hold — in particular, it is never linked to a submission to the analysis tools or to an Order. It is used for one purpose only: a single message announcing availability. It is not used for any other marketing, is not shared with any third party for marketing purposes, and is not enriched or profiled. Consent may be withdrawn at any time, with effect for the future, by emailing the Controller, and withdrawal results in deletion of the address.
2.1.2. Data Collected Automatically
- Server log data — IP address (anonymized), browser type and version, operating system, referrer URL, date and time of access, pages visited, and data volume transferred. This data is collected automatically by our web hosting infrastructure for the purposes of ensuring system security and stability.
- Cookie data — as described in detail in § 8 of this Policy.
2.1.3. Data Processed by Third-Party Processors
- Payment data — payment card number, expiration date, CVC, billing address, and transaction metadata are collected and processed exclusively by Stripe, Inc. (hereinafter “Stripe”) as an independent payment processor. The Controller does not receive, access, process, or store payment card data at any time. Stripe acts as a joint controller or independent controller (as applicable) for such data processing activities.
- Analytics data — anonymized usage data collected through Google Analytics (operated by Google Ireland Limited), including pages visited, session duration, bounce rate, and approximate geographic location (country/city level), processed only upon the Data Subject's prior consent.
2.1.4. Text Submitted to the Free Analysis Tools
Where a Data Subject submits text to the AI-detection tool, the similarity tool, or the watermark and hidden-character tool, whether by pasting text or by uploading a document, that text is transmitted to our servers and is retained as described below. This applies to use of the free tools and does not require an account.
In the case of the watermark and hidden-character tool, the analysis itself is performed locally in the Data Subject's browser; the analysed text and the result are transmitted to our servers afterwards, for the purposes stated below. That tool applies no word limit, and accordingly the text retained is the whole of the document submitted.
- What is retained — the text submitted for analysis, together with the technical output of the analysis (scores, per-feature values, word and sentence counts, and the language detected). Where the free tier analyses only part of a longer document, only the portion actually analysed is retained. The technical output may itself contain short excerpts of the submitted text, because the analysis identifies the specific sentences on which its result is based.
- Submitted without an identifier — we do not request, receive, generate, or attach a name, email address, account, university, matriculation number, payment reference, or Stripe identifier to a submission, and we do not store the submitting IP address alongside the text. The only reference held with a submission is a randomly generated analysis reference, which is not derived from any characteristic of the Data Subject or their device. We hold no identifier by which a submission could be traced back to the person who made it, and we never attempt to establish one.
- What this does and does not mean — we state this precisely rather than favourably. A submission is unlinked: we cannot connect it to a person using anything we hold. It is not, for that reason alone, anonymous data within the meaning of Recital 26 GDPR, because an academic text can identify its author through its content — its topic, its research question, its data — irrespective of any identifier we attach. We therefore continue to treat every submission as personal data and to apply the full protection of the GDPR to it, rather than relying on a claim of anonymity to place it outside the Regulation's scope.
- How to submit with the least data possible — the amount of personal data in a submission is very largely within the Data Subject's control, and we encourage minimising it. A title page, declaration of authorship (Eigenständigkeitserklärung), acknowledgements section, or a document's embedded author field typically carry a name, a university, and a supervisor; none of these is required for any analysis we perform, and a document submitted without them is analysed identically. Where a document is submitted as a file, we remove the embedded author, creator, last-modified-by, and title fields in the Data Subject's browser before any transmission to us, so those fields never reach our servers. We do retain, and use for measuring how our tools are used, a small number of technical attributes of the file itself: its format, whether it was uploaded or pasted, the software that produced it, and, where the file records them, its editing time, save count, page count and creation and modification dates. The file's name is not transmitted; only its extension is. These attributes describe the document, not the person who wrote it.
- Purpose, and what the Data Subject gets in return — submitted text is used to measure and improve the accuracy, reliability, and fairness of our analysis products: the measurement and publication of false-positive rates, the correction of errors, the development and calibration of detection methods, the reference corpus described in § 2.1.5, and the detection of abuse of the service. This is a reciprocal arrangement and we state it plainly rather than burying it. An AI detector is only as fair as the body of real academic writing it has been measured against, and the error that matters — a student whose own writing is wrongly reported as machine-written — is reduced by exactly one thing: more real academic writing to measure against. Every submission makes the next verdict more accurate, for the person submitting it and for those who come after them. Submitted text is used for no other purpose. It is not used for advertising or profiling, and it is not used for any automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR.
- Legal basis — Article 6(1)(f) GDPR (legitimate interests). Our legitimate interest lies in maintaining and evidencing the accuracy of an analytical tool whose output may affect a Data Subject's academic standing, and in reducing the rate at which such a tool wrongly reports honest work as machine-generated. We consider this interest not to be overridden by the interests or fundamental rights of the Data Subject, having regard to the fact that no identifying data is requested, collected, or attached; that the processing is not used to make any decision about any individual; that it is not combined with payment records or with any other data set; and to the safeguards set out in § 2.1.5. A record of this assessment is maintained and is available to a supervisory authority on request.
- No re-identification — we do not attempt, and will not attempt, to identify any Data Subject from the content of submitted text, and we do not combine submitted text with payment records or with any other data held by us or by any third party.
- Never shown to another user, never sold — submitted text is never displayed, quoted, or reproduced to another user of the service or to any third party, and is never sold or licensed. It is not used to train third-party machine-learning models. It is used to build the reference corpus described in § 2.1.5, which is what allows the analysis to be measured and improved; that corpus returns statistical measures only, and never returns, displays, or identifies another person's document.
- Content-borne data — an uploaded document may itself contain personal data which the Data Subject has chosen to include, such as a name on a title page or the name of a supervisor or interview participant. We do not extract, index, or process such data, and no analysis we perform is directed at it. We ask Data Subjects not to submit documents containing special categories of personal data within the meaning of Article 9 GDPR, and to remove the material described above before submitting.
- Deletion at any time, on request — the Data Subject may at any time, without giving reasons and free of charge, require the deletion of a submission by contacting the Controller at contact@morphica.de. This applies in addition to, and independently of, the right to object under Article 21(1) GDPR and the right to erasure under Article 17 GDPR. Because a submission carries no identifier of the person who made it, it can only be located by its analysis reference. That reference is printed in the footer of the analysis report available for download with the result and, for the watermark and hidden-character tool, which produces no downloadable report, it is displayed with the result on screen. Where that reference is provided, the submission, all files associated with it, and every entry it has contributed to the reference corpus are deleted without undue delay and in any event within thirty (30) days, and the deletion is confirmed by reply. Where it is not available, we will assist as far as is technically possible, but we are not able to identify a submission from a name or an email address, because we hold neither in connection with it.
2.1.5. The Reference Corpus
An AI-detection tool can only state how often it is wrong if it is measured against a large body of real academic writing. Submissions to our analysis tools form that body, and this paragraph explains what is built from them, the limits we place on it, and how a Data Subject can prevent their submission contributing.
Why we ask this of the people we serve. The damaging error in this field is not a missed detection; it is a student whose own writing is reported as machine-written. That error is reduced by one thing above all others — a larger and more representative body of genuine academic writing to measure against — and there is no source of that writing other than the people who use the tool. A submission therefore improves the verdict the submitter receives, and every verdict issued afterwards. We consider that a fair exchange, and we would rather set it out here than leave it implied.
Which submissions this paragraph applies to. The reference corpus went live on 17 August 2026. Following a legal review completed on 18 August 2026, building and maintaining the reference corpus is treated as part of the analytical purpose stated in § 2.1.4 at the time of collection — the measurement of accuracy and the development and calibration of detection methods — and this paragraph therefore applies to every submission retained under § 2.1.4, whenever it was made. Every right set out below, including objection and deletion, applies equally to all of them.
- What the corpus contains — the submitted text as retained under § 2.1.4 (the most recent complete version of a document, where several were submitted), held in a separate storage location that is not served to any browser, together with irreversible mathematical fingerprints of its passages and technical attributes such as its language, its approximate length, the type of section a passage came from, and which field of study the submission belongs to. A fingerprint is a one-way numerical summary from which the original wording cannot be reconstructed. The text is held so that the aggregate measures described below can be recomputed as the methods improve; it is not used for anything other than computing them.
- What it is used for — to establish how common a given formulation, or a given passage, is across academic writing generally, and within the field of study a submission belongs to. This is what allows us to distinguish writing which is unusual from writing which is highly formulaic, and it is a substantially more reliable and less discriminatory signal than the stylistic measures on which AI detectors have conventionally relied. Detection methods based on writing style are documented to produce markedly higher error rates for authors writing in a second language; this method does not share that characteristic.
- What it never does — the corpus never returns, identifies, references, or makes accessible any individual submission or its author. A result derived from it is expressed only as a statistical measure of how common a formulation is across many documents. No user of the service is ever shown another user's work, any part of it, or any indication that a particular other document exists, and no result ever names or points to a counterparty. The corpus is not made available to any third party.
- Status of the corpus entries — we do not claim that the text or the fingerprints in the corpus are anonymous data outside the scope of the GDPR. They are retained as pseudonymous personal data and treated accordingly, including for the purposes of the rights set out in § 7.
- Legal basis — Article 6(1)(f) GDPR (legitimate interests), on the assessment recorded in § 2.1.4 and having particular regard to the irreversibility of the fingerprints, the impossibility of any user obtaining access to another's submission through the corpus, and the availability of the objection right below. A record of that assessment is maintained and is available to a supervisory authority on request.
- Right to object, and how to prevent this — the Data Subject may object at any time under Article 21(1) GDPR, without giving reasons and free of charge, by contacting the Controller at contact@morphica.de quoting the analysis reference. On objection, every entry derived from that submission is removed from the corpus without undue delay and in any event within thirty (30) days.
- Deletion — corpus entries derived from a submission are deleted when that submission is deleted: on request under § 2.1.4, on objection under Article 21(1) GDPR, or on a request for erasure under Article 17 GDPR. Retention is otherwise indefinite, as set out in § 6.
2.2. We expressly do not collect the following categories of data: full legal names, postal addresses (unless required for invoicing), telephone numbers, dates of birth, university or institutional affiliations, student identification numbers, government-issued identification numbers, or any special categories of personal data within the meaning of Article 9 GDPR. This applies to data we request; it does not extend to information a Data Subject voluntarily includes within the body of a document submitted to the analysis tools, which is addressed in § 2.1.4.
§ 3 — Purposes of Processing and Legal Bases
3.1. We process personal data exclusively for the purposes set forth below, each linked to the applicable legal basis under Article 6(1) GDPR:
| Purpose | Legal Basis |
|---|
| Performance of the contract (order processing, delivery of Deliverables, communication) | Art. 6(1)(b) GDPR — necessity for the performance of a contract |
| Payment processing via Stripe | Art. 6(1)(b) GDPR — necessity for the performance of a contract |
| Compliance with legal retention obligations (tax law, commercial law) | Art. 6(1)(c) GDPR — compliance with a legal obligation (§§ 147 AO, 257 HGB) |
| Website analytics and improvement (Google Analytics) | Art. 6(1)(a) GDPR — consent of the Data Subject |
| Measuring and improving the accuracy of our analysis products, on the basis of submissions collected without an identifier (§ 2.1.4) | Art. 6(1)(f) GDPR — legitimate interests of the Controller |
| Maintaining a reference corpus of submitted text and irreversible fingerprints, to measure how common a formulation or a passage of academic writing is, and thereby to reduce the rate at which honest work is wrongly reported as machine-written (§ 2.1.5) | Art. 6(1)(f) GDPR — legitimate interests of the Controller, subject to the right to object under Art. 21(1) |
| Sending a single notification when a product currently in development becomes available, to addresses submitted to the launch notification list (§ 2.1.1) | Art. 6(1)(a) GDPR — consent of the Data Subject, given by explicit unticked opt-in and withdrawable at any time |
| Ensuring system security, fraud prevention, and abuse detection | Art. 6(1)(f) GDPR — legitimate interests of the Controller |
| Defense of legal claims and assertion of rights | Art. 6(1)(f) GDPR — legitimate interests of the Controller |
3.2. Where processing is based on the legitimate interests of the Controller pursuant to Article 6(1)(f) GDPR, the Controller has conducted a balancing test and has determined that its legitimate interests are not overridden by the interests, fundamental rights, or fundamental freedoms of the Data Subject.
§ 4 — Recipients and Third-Party Data Sharing
4.1. Personal data is shared with the following categories of recipients, solely to the extent necessary for the purposes specified in § 3:
- Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA) — for payment processing. Stripe is certified under the EU-US Data Privacy Framework. Stripe's privacy policy is available at stripe.com/privacy. Data transfers to the United States are safeguarded pursuant to Article 45 GDPR (adequacy decision) and, as a fallback, Article 46(2)(c) GDPR (Standard Contractual Clauses).
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) — for website analytics via Google Analytics 4. IP anonymization is enabled by default. Data may be transferred to Google LLC in the United States, safeguarded by the EU-US Data Privacy Framework and Standard Contractual Clauses. Google's privacy policy is available at policies.google.com/privacy.
- Hosting provider — our web hosting provider processes server log data as a data processor within the meaning of Article 28 GDPR. A Data Processing Agreement (Auftragsverarbeitungsvertrag, “AVV”) has been concluded with the hosting provider in accordance with Article 28(3) GDPR.
4.2. Beyond the recipients listed above, personal data is not disclosed, sold, rented, or otherwise made available to any third parties, unless: (a) the Data Subject has given explicit consent; (b) disclosure is required by applicable law, regulation, or order of a competent court or governmental authority; or (c) disclosure is necessary for the establishment, exercise, or defense of legal claims.
§ 5 — International Data Transfers
5.1. Where personal data is transferred to recipients in countries outside the European Economic Area (“EEA”) that have not been recognized by the European Commission as providing an adequate level of data protection pursuant to Article 45 GDPR, such transfers are safeguarded by appropriate safeguards within the meaning of Article 46 GDPR, including:
- Standard Contractual Clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914);
- Certification under the EU-US Data Privacy Framework pursuant to Commission Implementing Decision C(2023) 4745 of 10 July 2023;
- Binding Corporate Rules pursuant to Article 47 GDPR, where applicable.
5.2. The Data Subject may obtain a copy of the applicable safeguards by contacting the Controller at contact@morphica.de.
§ 6 — Data Retention Periods
6.1. Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable legal retention obligations. The following retention periods apply:
- Order and transaction data: Ten (10) years from the end of the calendar year in which the transaction occurred, in compliance with §§ 147(1) No. 1 and 4 of the German Fiscal Code (Abgabenordnung, “AO”) and § 257(1) Nos. 1 and 4 of the German Commercial Code (Handelsgesetzbuch, “HGB”).
- Email addresses used solely for order delivery: Retained for the duration of the contractual relationship plus the applicable statutory retention period. Deletion upon request is possible for email addresses not linked to retained transaction data.
- Email addresses on the launch notification list: Retained until the announcement they were given for has been sent, or until consent is withdrawn, whichever is earlier, and deleted thereafter. Where the product is not released, the addresses are deleted without any message being sent. Deletion here is performed by an operator rather than by an automatic expiry rule, and is carried out on withdrawal or on request without undue delay and in any event within thirty (30) days. The stored record of the consent wording and date is retained under the consent-record period below.
- Server log data: Automatically deleted after fourteen (14) calendar days, unless longer retention is required for the investigation of security incidents.
- Analytics data (Google Analytics): Retained in accordance with Google's data retention settings, currently configured to twenty-six (26) months.
- Consent records: Retained for the duration of the consent plus three (3) years following withdrawal or expiration, in order to demonstrate compliance with Article 7(1) GDPR.
- Text submitted to the free analysis tools (§ 2.1.4): Retained for as long as it is required for the purpose stated in § 2.1.4 — measuring and improving the accuracy of our analysis products — which is an ongoing purpose without a fixed end date, because the accuracy of a detector can only be measured against how writing changes over time. Retention beyond the period necessary for the original purpose is permitted by Article 5(1)(e) GDPR where processing is for statistical or scientific research purposes, subject to the safeguards in Article 89(1) GDPR, which we apply: no identifying data is requested or attached, the data is not used to make any decision about any individual, and it is not combined with any other data set. This does not limit the Data Subject's rights. Deletion occurs at any time on request pursuant to § 2.1.4, quoting the analysis reference, and without undue delay and in any event within thirty (30) days; and on objection under Article 21(1) GDPR or a request for erasure under Article 17 GDPR. Aggregate statistical results derived from such text — for example measured false-positive rates — do not permit the reconstruction of any submission and are retained indefinitely.
- Reference corpus entries (§ 2.1.5): Retained for as long as the submission from which they were derived is retained, and deleted together with it on a deletion request under § 2.1.4, on objection under Article 21(1) GDPR, or on a request for erasure under Article 17 GDPR.
- Pass and payment-verification records: Retained for the duration of the pass validity period plus the statutory retention obligations applicable to the underlying transaction under §§ 147 AO and 257 HGB, after which they are deleted.
6.2. Upon expiration of the applicable retention period, personal data is securely deleted or irreversibly anonymized in accordance with Article 17 GDPR and applicable technical standards.
§ 7 — Rights of the Data Subject
7.1. The Data Subject has the following rights under the GDPR, which may be exercised at any time by contacting the Controller at contact@morphica.de:
- Right of Access (Article 15 GDPR): The Data Subject has the right to obtain confirmation as to whether personal data concerning them is being processed and, where that is the case, to access the personal data and receive information about the purposes of processing, the categories of data concerned, the recipients, the retention period, and the existence of the rights described herein.
- Right to Rectification (Article 16 GDPR): The Data Subject has the right to obtain the rectification of inaccurate personal data and the completion of incomplete personal data.
- Right to Erasure (Article 17 GDPR): The Data Subject has the right to obtain the erasure of personal data without undue delay where one of the grounds set forth in Article 17(1) GDPR applies, unless processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.
- Right to Restriction of Processing (Article 18 GDPR): The Data Subject has the right to obtain restriction of processing where: the accuracy of the data is contested; the processing is unlawful; the Controller no longer needs the data; or the Data Subject has objected to processing pursuant to Article 21(1) GDPR.
- Right to Data Portability (Article 20 GDPR): The Data Subject has the right to receive their personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV) and to transmit that data to another controller without hindrance, where processing is based on consent or contract and is carried out by automated means.
- Right to Object (Article 21 GDPR): The Data Subject has the right to object, on grounds relating to their particular situation, to the processing of personal data based on Article 6(1)(f) GDPR. Upon receipt of such objection, the Controller shall cease processing unless it demonstrates compelling legitimate grounds that override the interests, rights, and freedoms of the Data Subject.
- Right to Withdraw Consent (Article 7(3) GDPR): Where processing is based on consent, the Data Subject has the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right Not to Be Subject to Automated Decision-Making (Article 22 GDPR): The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them. The Controller does not currently engage in automated individual decision-making or profiling as defined in Article 22 GDPR.
7.2. The Controller shall respond to requests exercising the above rights without undue delay and in any event within one (1) month of receipt of the request, pursuant to Article 12(3) GDPR. This period may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests.
7.3. The Controller may request information necessary to confirm the identity of the Data Subject prior to processing the request, in accordance with Article 12(6) GDPR.
§ 8 — Cookies and Tracking Technologies
8.1. The Platform uses cookies and similar tracking technologies (collectively “Cookies”) in accordance with the TTDSG and the ePrivacy Directive (Directive 2002/58/EC as amended by Directive 2009/136/EC).
8.2. Cookies are classified as follows:
- Strictly Necessary Cookies (§ 25(2) No. 2 TTDSG): These Cookies are essential for the provision of the Platform's core functionality and do not require the Data Subject's consent. They include session cookies, CSRF protection tokens, and load balancing identifiers.
- Analytics Cookies: These Cookies are used for statistical analysis of website usage through Google Analytics 4. They are set only upon the Data Subject's prior, informed, and freely given consent pursuant to § 25(1) TTDSG and Article 6(1)(a) GDPR. Consent is obtained through a consent management mechanism presented upon the Data Subject's first visit to the Platform.
8.3. The Data Subject may manage Cookie preferences at any time through their browser settings or through the consent management mechanism on the Platform. The withdrawal of consent does not affect the lawfulness of Cookie-based processing carried out prior to the withdrawal.
§ 9 — Data Security
9.1. The Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, in accordance with Article 32 GDPR. Such measures include, without limitation:
- Encryption of data in transit using TLS 1.2 or higher (HTTPS);
- Encryption of data at rest using industry-standard encryption algorithms;
- Access control mechanisms limiting access to personal data to authorized personnel only;
- Regular security assessments and vulnerability testing;
- Pseudonymization and data minimization in accordance with Article 25 GDPR (data protection by design and by default);
- Incident detection and response procedures.
§ 10 — Data Breach Notification
10.1. In the event of a personal data breach within the meaning of Article 4(12) GDPR, the Controller shall notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
10.2. Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall communicate the breach to the affected Data Subjects without undue delay, in accordance with Article 34 GDPR, unless one of the conditions set forth in Article 34(3) GDPR applies.
§ 11 — Right to Lodge a Complaint
11.1. Without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if the Data Subject considers that the processing of personal data relating to them infringes the GDPR, pursuant to Article 77 GDPR.
11.2. The competent supervisory authority for the Controller is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44, 40102 Düsseldorf
Website: ldi.nrw.de
§ 12 — Changes to This Policy
12.1. The Controller reserves the right to amend this Policy at any time to reflect changes in legal requirements, technological developments, or business practices. The amended Policy shall be published on the Platform with an updated effective date.
12.2. Where material changes affect the processing of personal data in a manner that requires renewed consent, the Controller shall obtain such consent before implementing the changes.
12.3. Data Subjects are encouraged to review this Policy periodically to remain informed about the Controller's data protection practices.
12.4. Changes to this Policy are not applied retroactively to personal data already collected. Where a version of this Policy in force at the time of collection stated a limitation on the use of data, or gave an undertaking as to how data would not be used, that limitation and that undertaking continue to govern the data collected under it for the whole of its retention period, notwithstanding any later amendment. Where an amendment introduces a new purpose, that purpose applies only to data collected on or after the effective date of the amendment. This is a standing commitment and not a statement about any particular amendment.
12.5. A record of previous versions of this Policy, and of the dates on which each was in force, is retained and is available on request at contact@morphica.de.