Privacy Notice and Data Protection Documentation
Newsmind Stories
Software-as-a-Service (SaaS) Solution by Convit GmbH
Software-as-a-Service (SaaS) Solution by Convit GmbH
This Privacy Notice and Data Protection Documentation describes the processing of personal data in connection with the use of Newsmind Stories, the Software-as-a-Service (SaaS) solution provided by Convit GmbH.
This document serves both as the product-specific privacy notice for the editorial platform and as documentation of the implemented data protection measures for use in proposals, contractual documentation, and compliance reviews.
Its scope includes the provision, operation, administration, maintenance, and support of Newsmind Stories, including the associated technical components, interfaces, logging mechanisms, backup and deletion processes, as well as authentication and authorization functions.
This document does not cover customer-operated systems, end-user devices, customer-managed networks, or third-party systems that are independently connected to Newsmind Stories by the customer and are not operated or controlled by Convit GmbH.
The controller responsible for this Privacy Notice is:
Convit GmbH
Schanzenstraße 39 | E2
51063 Cologne
Germany
datenschutz@convit.de
+49 221 29294899
Where Newsmind Stories is operated on behalf of a customer and processes personal data of users or customer-specific editorial content, Convit generally acts as a data processor within the meaning of Article 28 of the General Data Protection Regulation (GDPR). In such cases, the respective customer is the data controller responsible for the processing of personal data.
Convit GmbH has appointed a Data Protection Officer. Contact details are as follows:
Stephanie Linke
datenschutz@convit.de
Schanzenstraße 39 | E2
51063 Cologne
Germany
Where Convit acts as a data processor, the processing of personal data in connection with the operation of Newsmind Stories is carried out on the basis of a Data Processing Agreement (DPA) in accordance with Article 28 GDPR.
The DPA defines, among other things, the subject matter and duration of the processing, the nature and purpose of the processing, the categories of personal data, the categories of data subjects, the technical and organizational measures (TOMs), as well as the rights and obligations of the contracting parties.
Convit processes personal data exclusively on the documented instructions of the customer. Personal data processed under the Data Processing Agreement is not used by Convit for its own purposes.
Newsmind Stories is a Software-as-a-Service (SaaS) solution for planning, creating, reviewing, managing, and publishing editorial content. The platform supports editorial workflows, topic and campaign planning, task management, approval workflows, integrations with third-party systems, and optional AI-powered assistance features.
Personal data is processed primarily in connection with user management, authentication, logging, authorization management, and the general use of the application. Editorial content and other business-related information are created and maintained by users or imported from connected systems. The customer determines the content and purpose of such data.
All data processing takes place within a controlled operating environment. Newsmind Stories is operated as a multi-tenant platform, with each customer’s data logically isolated through dedicated databases for each tenant.
Depending on the specific use of the platform, the following categories of personal data may be processed:
Under the intended operating model, Convit neither requires nor prescribes the processing of special categories of personal data as defined in Article 9 GDPR. If the customer processes such data within editorial content, responsibility for that processing remains solely with the customer.
Where Convit acts as a data processor, personal data is processed solely on behalf of and under the documented instructions of the customer in accordance with Article 28 of the General Data Protection Regulation (GDPR). The legal basis for the processing of personal data with respect to data subjects is determined by the respective customer acting as the data controller.
Where Convit processes its own personal data in connection with contract performance, business communications, or technical and organizational security measures, the applicable legal basis may include, depending on the specific processing activity, Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(c) GDPR (compliance with a legal obligation), or Article 6(1)(f) GDPR (legitimate interests).
Newsmind Stories is hosted in a cloud-based infrastructure located within the European Union. All personal data is stored and processed exclusively in data centers located within the EU. Personal data is not transferred to countries outside the European Economic Area (EEA) unless such a transfer has been explicitly agreed upon contractually or initiated by the customer.
The platform is operated by Convit GmbH and, where applicable, by contractually engaged infrastructure and hosting providers acting as authorized subprocessors under appropriate data protection agreements in accordance with the GDPR.
Convit does not disclose users‘ personal data to third parties for its own purposes. In particular, personal data is neither sold nor used for advertising or marketing purposes.
Personal data may be transferred where necessary to provide the contracted services, where the customer has configured or enabled a specific integration or interface, or where disclosure is required by applicable law. In such cases, the processing is carried out in accordance with the contractual agreements and the documented instructions of the customer.
Depending on the agreed scope of services, Newsmind Stories can be integrated with external systems such as content management systems (CMS), production systems, publishing and distribution platforms, identity providers, media asset management (MAM) systems, external data sources, or AI services. The nature and scope of the transferred data depend on the customer’s specific system configuration.
All integrations are authenticated, authorized, and operated over encrypted communication channels. Customer-specific interfaces are implemented in coordination with the customer and according to the agreed technical requirements.
| Interface / System Type | Purpose | Data Types | Direction | Security |
|---|---|---|---|---|
| Identity Provider / Keycloak | User authentication and identity management | User identifiers, roles, groups, token information | Bidirectional / authentication flow | OpenID Connect, OAuth 2.0, TLS |
| CMS / Publishing Systems | Transfer and publication of editorial content | Editorial content, metadata, status information | Outbound or bidirectional | API authentication, TLS |
| MAM / Production Systems | Exchange of media assets and metadata | Media references, metadata, status information | Customer-specific | API authentication, TLS |
| AI Services (where agreed) | AI-assisted features, summarization, and text assistance | Input content and generated output within the respective workflow | Outbound / processing by the contracted service | API authentication, TLS, contractual safeguards |
| Monitoring / Logging | Operations, security, and troubleshooting | Technical log data and operational information | Internal / operational | Access controls, TLS where data is transmitted |
Convit implements appropriate technical and organizational measures (TOMs) to protect personal data and editorial content processed within Newsmind Stories. These measures are designed to ensure transparency, data minimization, integrity, availability, confidentiality, and the ability to intervene in accordance with applicable data protection requirements.
All data transmissions are protected using encrypted communication channels based on current TLS standards, including TLS 1.2 and TLS 1.3. This applies in particular to user access via HTTPS as well as communication with connected services and external interfaces.
Data stored within the platform is protected using appropriate encryption mechanisms at the storage and/or database level. Encryption of data at rest is implemented in accordance with current industry standards, for example by using AES-256 or equivalent technologies provided by the underlying infrastructure.
Comprehensive pseudonymization of all data processed within Newsmind Stories is not part of the standard operating model, as editorial collaboration, responsibilities, approval workflows, and auditability generally require data to remain attributable to individual users.
Where technically feasible and appropriate, technical identifiers, internal IDs, and tenant-specific identifiers are used. Log and operational data are collected only to the extent necessary to ensure system security, operational reliability, troubleshooting, and traceability.
Personal data is processed only to the extent necessary for the operation, use, security, and contractually agreed functionality of the platform. Access to personal data is restricted to authorized individuals and limited to defined business purposes in accordance with the applicable authorization concept.
To ensure system availability and recoverability, backup copies of relevant data, process states, configurations, data structures, and, where required, transaction histories are created. Backups are used exclusively for disaster recovery and business continuity purposes and are not used for day-to-day operational activities.
Newsmind Stories incorporates data protection principles throughout the design, architecture, and ongoing development of the platform. This includes, in particular, tenant-specific data segregation, role-based access control, encrypted communications, logging of relevant events, controlled system integrations, and defined data retention and deletion processes.
The platform supports privacy-friendly default settings. Users are granted only those permissions explicitly assigned to them through roles, groups, or individual access rights. Access to data belonging to other tenants is strictly prevented.
Tracking for advertising, marketing, or profiling purposes is not part of the standard functionality of Newsmind Stories.
Optional features, integrations, and AI-powered capabilities are provided only within the scope agreed upon with the customer and can be configured according to customer-specific requirements.
User authentication is provided through a dedicated identity management solution, such as a Keycloak deployment, or through the customer’s external Identity Provider (IdP), where such integration has been configured.
If no external Identity Provider is used, Convit can provide a dedicated Keycloak instance for the customer. This instance enables the management of users, groups, roles, and authentication policies.
Newsmind Stories provides a comprehensive role-based access control (RBAC) model. Permissions are assigned based on roles and can be defined, assigned, modified, and revoked according to customer-specific requirements within each tenant.
The authorization model follows the principle of least privilege. Users are granted access only to the functions and data required to perform their assigned responsibilities.
Newsmind Stories supports structured logging of data protection-relevant and security-related events. Logging is implemented to ensure traceability, facilitate troubleshooting, support security monitoring, and meet applicable regulatory and compliance requirements.
Log data is retained for a defined period. Unless otherwise required by applicable law, a security incident, or a specific contractual agreement, the retention period does not exceed six months.
Upon expiration of the applicable retention period, log data is automatically deleted. Approval records, editorial revision histories, and other business-critical audit information stored within editorial objects may be retained independently of the technical log files where necessary to support traceability, auditing, or editorial documentation.
In the event of a security-related incident, relevant log data that is still available may be preserved using a Quick Freeze procedure and provided to the customer to the extent necessary. Such disclosure is carried out in compliance with applicable legal requirements, contractual obligations, and security policies.
Personal data and editorial content are retained only for as long as necessary to provide the services, fulfill contractual obligations, or comply with applicable legal requirements. Upon termination of the contractual relationship, data is deleted or returned to the customer in accordance with the contractual agreement, unless statutory retention obligations require continued storage.
Deletion procedures take into account, among other things, data classification, retention schedules, deletion periods, and, where applicable, the logging of deletion activities.
Depending on the system configuration and the underlying object model, Newsmind Stories provides functionality for deleting and restoring data. These capabilities may include:
Backups are retained according to defined retention schedules and are automatically deleted once the applicable retention period has expired. Data that has been deleted from the production environment is not used or processed operationally from backup copies.
If restoration from a backup becomes necessary, an assessment is performed to determine whether personal data that had previously been deleted could be reintroduced into the production environment. Where applicable, a post-restoration cleanup process is carried out to ensure that such data is removed again in accordance with the original deletion requirements.
Newsmind Stories is operated as a multi-tenant platform by default. Multiple customers share a common application environment while maintaining strict separation of their respective data.
Tenant isolation is implemented at the database level. Each tenant is assigned its own dedicated database within the database management system, ensuring that data belonging to different customers remains logically and physically separated.
In addition, the application validates and enforces the tenant context for every request. Access to data is restricted exclusively to the tenant to which the authenticated user belongs. Role-based access control (RBAC) provides an additional layer of authorization within each tenant by governing access to application features and data according to assigned permissions.
A dedicated single-tenant deployment can be provided upon request where contractually agreed.
Where Convit acts as a data processor, it supports the customer in fulfilling its obligations under Chapter III of the General Data Protection Regulation (GDPR), insofar as these obligations relate to personal data processed by Convit on the customer’s behalf.
This includes, in particular, providing information regarding the nature, purpose, and scope of the processing activities performed by Convit where such information is necessary to comply with the transparency obligations under Articles 13 and 14 GDPR or to respond to requests from data subjec
Requests from data subjects must generally be directed to the respective data controller, i.e., the customer, where Convit acts as a data processor.
By default, Newsmind Stories does not use cookies during normal operation.
Information required for authentication, session management, and user sign-in is processed server-side or by the configured identity management component. Where technically necessary, security-related or session-related information may be processed as part of the authentication process without requiring the use of cookies by Newsmind Stories in its standard configuration.
Newsmind Stories does not perform user tracking for advertising, marketing, or profiling purposes. The platform does not set analytics or marketing cookies, nor does it employ tracking technologies to create user profiles.
Browser-based local storage mechanisms are not used for tracking purposes in the standard deployment of Newsmind Stories. Where local storage is used in specific cases, it is solely intended to support application functionality or improve the user experience and is not used to analyze user behavior.
| Technology | Purpose | Requirement | Retention |
|---|---|---|---|
| Cookies used by Newsmind Stories | Not part of the standard platform operation | Not used | Not applicable |
| Session and Authentication Information | User authentication, session management, and security | Technically required | According to the configured authentication policies |
| Local Settings (where used) | Storage of functional application preferences | Functionally required or configuration-dependent | Depends on application settings and browser configuration |
| Analytics or Marketing Tracking | Not part of the standard operation of the editorial platform | Not used | Not applicable |
The retention period for personal data depends on the purpose of the processing, the applicable contractual agreements, statutory retention requirements, and the documented instructions of the customer.
| Data Category | Retention / Deletion |
|---|---|
| User Master Data | Retained for the duration of the user’s authorization or until deleted by the customer, in accordance with contractual requirements |
| Role and Authorization Data | Retained for the duration of the assigned permissions or until modified or removed |
| Log Data | Retained for a defined period of up to six months, after which it is automatically deleted unless an exception applies |
| Editorial Content | Retained in accordance with system usage, configuration, contractual agreements, and the customer’s documented instructions |
| Backups | Retained according to the defined backup retention policy and automatically deleted upon expiration |
| Support Data | Retained for the duration of support activities and in accordance with applicable contractual and legal retention requirements |
The technical and organizational measures implemented in Newsmind Stories are designed to support the data protection objectives established under applicable data protection laws. The following overview maps key security measures to these core data protection objectives.
| Data Protection Objective | Implemented Measures |
|---|---|
| Transparency | Documentation of processing activities, system interfaces, logging, subprocessors, and data deletion procedures |
| Data Minimization | Processing limited to the user, role, operational, and usage data required for the intended purposes |
| Integrity | Data validation, version control, audit logging of changes, and controlled deployment processes |
| Availability | Monitoring, backups, disaster recovery procedures, and a scalable operating environment |
| Confidentiality | TLS encryption, encryption of data at rest, access controls, and tenant isolation |
| Ability to Intervene | Data deletion capabilities, role management, support for data subject rights, and data recovery mechanisms |
This Privacy Notice may be updated to reflect changes in legal, technical, or organizational requirements. The most current version will be made available to the customer upon request or published on the Convit GmbH website.
| Requirement | Implementation in Newsmind Stories |
|---|---|
| GDPR Core Requirements | Data processing under Article 28 GDPR, processing based on documented customer instructions, technical and organizational measures (TOMs), and hosting within the European Union |
| Subprocessors | Documented in the subprocessor register and contractually integrated in accordance with GDPR requirements |
| Encryption | TLS 1.2 / 1.3 for data in transit and encryption of data at rest at the storage and database layers |
| Pseudonymization | No general pseudonymization; use of technical identifiers and data minimization where appropriate |
| Roles and Permissions | Role-Based Access Control (RBAC), principle of least privilege (need-to-know), and flexible assignment and revocation of permissions |
| Privacy by Design / Privacy by Default | Tenant isolation, access restrictions, no advertising or marketing tracking by default, and configurable privacy-related features |
| Authentication | Keycloak or an external identity provider using OpenID Connect (OIDC) / OAuth 2.0, with optional multi-factor authentication (MFA) |
| Logging | Structured audit logs with timestamps, retained for a maximum of six months |
| Interfaces | Authenticated and encrypted APIs with support for customer-specific integrations |
| Data Deletion | Deletion functions, defined backup retention policies, and post-restore cleanup procedures |
| Tenant Isolation | Dedicated database per tenant and strict enforcement of tenant context throughout the application |
| Third-Party Ecosystem | Third-party services are used only within the agreed scope and on an appropriate contractual and legal basis |