Privacy Policy

Last updated: August 2026

This privacy policy explains which personal data we process when you visit our website, contact us, use our interactive tools or apply for a job with us — and which rights you have in that respect.

We have deliberately written this policy to describe what actually happens. Every service we use is named individually, together with its provider, location, purpose, legal basis and retention period.

This is a translation of the German original. In the event of any discrepancy, the German version prevails.

Contents

  • 1. Controller and scope

  • 2. Your rights at a glance

  • 3. Right to object under Art. 21 GDPR

  • 4. Legal bases, retention periods and international transfers

  • 5. When you visit our website

  • 6. Cookies and local storage

  • 7. Audience measurement with Fathom Analytics

  • 8. Appointment booking via Calendly

  • 9. Advertising campaign measurement

  • 10. Contacting us and forms

  • 11. Project cost calculator

  • 12. Deckname demo (AI-assisted text anonymisation)

  • 13. Customer and contract data

  • 14. Communication and conferencing tools

  • 15. Job applications

  • 16. Our social media profiles

  • 17. Data security

  • 18. Changes to this privacy policy

1. Controller and scope

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

InnoGE GmbH
Ederstr. 5
36043 Fulda
Germany

Phone: +49 661 90034410
E-mail: [email protected]

Commercial Register: HRB 8448, Amtsgericht Fulda
Represented by: Tim Geisendörfer

Data protection officer

We are not legally required to appoint a data protection officer and have not appointed one. For any questions regarding data protection and to exercise your rights, please contact us directly using the details above.

Scope

This privacy policy applies to the website innoge.de, including all subpages and landing pages, and to our recruitment process, including where it is handled via karriere.innoge.de.

It does not apply to third-party websites we link to. The respective providers are solely responsible for their content and data processing.

2. Your rights at a glance

You have the following rights in relation to us. Exercising them is free of charge; an informal message to [email protected] is sufficient.

  • Access (Art. 15 GDPR) — you may request confirmation of whether and which personal data we process about you, for which purposes, to which recipients we disclose it and how long we store it.

  • Rectification (Art. 16 GDPR) — you may request correction of inaccurate data and completion of incomplete data.

  • Erasure (Art. 17 GDPR) — you may request deletion of your data unless a statutory retention obligation applies.

  • Restriction of processing (Art. 18 GDPR) — you may request that we only store your data without using it further, for example while we verify data whose accuracy you contest.

  • Data portability (Art. 20 GDPR) — we will provide data you have given us on the basis of consent or for the performance of a contract in a common, machine-readable format.

  • Withdrawal of consent (Art. 7 (3) GDPR) — you may withdraw consent at any time with effect for the future. The lawfulness of processing carried out until then remains unaffected.

  • Objection (Art. 21 GDPR) — see the separately highlighted section 3.

Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.

The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
Phone: +49 611 1408-0
E-mail: [email protected]
Web: https://datenschutz.hessen.de

No automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. No automated assessment of individuals takes place that produces legal effects concerning you or similarly significantly affects you.

Provision of your data

Providing your personal data is neither required by law nor by contract. You are under no obligation to provide us with data.

However, if you do not provide the information marked as mandatory in our forms, we will not be able to process your enquiry or enter into a contract with you. No other disadvantages arise for you.

3. Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (f) GDPR (legitimate interests). This also applies to profiling based on that provision.

If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where we process your personal data for direct marketing purposes, you have the right to object at any time and without giving reasons. Following such an objection, we will no longer use your data for direct marketing purposes.

An informal message to [email protected] is sufficient to object. The sections below state explicitly which of our processing activities are based on legitimate interests.

4. Legal bases, retention periods and international transfers

Legal bases

We base every processing activity on one of the following legal bases. The section describing each activity states which one applies.

  • Art. 6 (1) (a) GDPR — consent, where applicable in conjunction with Section 25 (1) TDDDG, insofar as information is stored on or read from your device.

  • Art. 6 (1) (b) GDPR — performance of a contract and pre-contractual measures, for example for enquiries, quotations and project delivery.

  • Art. 6 (1) (c) GDPR — legal obligation, for example commercial and tax retention obligations under Section 257 HGB and Section 147 AO.

  • Art. 6 (1) (f) GDPR — legitimate interests. We state the specific interest for each processing activity.

  • Section 26 BDSG in conjunction with Art. 6 (1) (b) GDPR for the recruitment process.

Retention periods

We store personal data only for as long as necessary for the respective purpose. The specific period is stated for each processing activity. Where a fixed period cannot be given, the following criteria apply:

  • Data from ongoing correspondence is deleted once the matter is concluded and no further queries are to be expected.

  • Data from a business relationship is deleted after it ends, once the statutory retention periods have expired — generally six years for commercial correspondence (Section 257 (4) HGB) and ten years for accounting records (Section 147 (3) AO), each calculated from the end of the calendar year.

  • Data processed on the basis of your consent is deleted after withdrawal.

  • Data to whose processing you have effectively objected is deleted unless compelling legitimate grounds prevent this.

Transfers to third countries

We deliberately favour providers that process data within the European Union. Our hosting, e-mail delivery and audience measurement all take place in the EU.

Where we nevertheless use service providers based outside the EU or EEA, we say so explicitly in the relevant section and base the transfer on one of the following safeguards:

  • an adequacy decision of the European Commission under Art. 45 GDPR — for example for Canada (commercial organisations) or for recipients in the USA certified under the EU-US Data Privacy Framework, and

  • in addition or in the alternative, the Standard Contractual Clauses of the European Commission under Art. 46 (2) (c) GDPR (Implementing Decision (EU) 2021/914).

Please note that third countries — in particular the USA — cannot be guaranteed to offer a level of data protection fully comparable to that of the EU. In particular, authorities there may under certain conditions access data without you having the same level of legal protection available as within the EU. We will provide a copy of the safeguards agreed in each case on request.

5. When you visit our website

Server log files

When you access our website, our web server automatically collects and stores information transmitted by your browser:

  • IP address of the requesting device

  • date and time of access

  • name and URL of the file retrieved

  • volume of data transferred and notification of successful retrieval

  • referrer URL, i.e. the previously visited page

  • browser used, its version and the operating system

Purpose: delivery of the website, ensuring system security and stability, detecting and preventing attacks, and error analysis.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technically faultless and secure operation of our website.

Retention period: log files are deleted automatically after no more than 14 days. This data is not combined with other data sources. Longer storage occurs only where a specific security incident has to be documented; the data concerned is then retained until the matter is finally resolved.

Abuse prevention and rate limiting

For individual interactive features — in particular the Deckname demo described in section 12 — we limit the number of requests per unit of time. Your IP address is used briefly in the server's memory or cache as a counting key for this purpose. It is not stored permanently or logged.

Legal basis: Art. 6 (1) (f) GDPR, legitimate interest in preventing abuse and maintaining the availability of our services.

Hosting by Hetzner

Our website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

Hetzner processes all data arising from the operation of the website on our behalf, in particular the access data set out above. The servers are located in Germany. No transfer to a third country takes place.

Legal basis: Art. 6 (1) (f) GDPR, legitimate interest in the reliable and secure provision of our online offering.

Data processing agreement: a data processing agreement under Art. 28 GDPR is in place with Hetzner.

Hetzner privacy policy: https://www.hetzner.com/legal/privacy-policy

Content delivery network and security filter: Cloudflare

We use the "Cloudflare" service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. For users in the EEA, Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany, is the contracting party.

Cloudflare operates a globally distributed content delivery network with DNS. Traffic between your browser and our server is routed through Cloudflare's network. This enables Cloudflare to analyse traffic and act as a filter between our servers and potentially malicious requests. The data processed includes your IP address, information about the browser used and the address requested. Cloudflare may set cookies or comparable technologies for this purpose, used solely for security and delivery.

Purpose: accelerated delivery of content and protection against overload and abuse attacks.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in the security and uninterrupted availability of our website.

International transfer: a transfer to the USA cannot be ruled out. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework; the transfer is therefore based on the European Commission's adequacy decision of 10 July 2023 and, in addition, on the European Commission's Standard Contractual Clauses.

Data processing agreement: a data processing agreement under Art. 28 GDPR is in place with Cloudflare.

Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/

6. Cookies and local storage

We use only a small number of cookies and local storage entries on our website. We do not use advertising cookies, cross-site tracking cookies or cookies from advertising networks. For that reason, we do not show you a consent banner.

The following entries are set:

  • Session cookie — technically necessary in order to associate your session on the server side, for example when submitting a form. Expires when you close your browser or after two hours of inactivity at the latest. Legal basis: Section 25 (2) no. 2 TDDDG, Art. 6 (1) (f) GDPR.

  • XSRF-TOKEN — technically necessary; protects our forms against cross-site request forgery. Same lifetime as the session cookie. Legal basis: Section 25 (2) no. 2 TDDDG, Art. 6 (1) (f) GDPR.

  • innoge_click_id — local storage entry, only on individual landing pages, used to measure advertising campaigns. Details in section 9.

  • innoge_deckname_example_seen — session storage entry; prevents an event from being counted twice within one session. Deleted when you close the browser tab. Legal basis: Art. 6 (1) (f) GDPR.

You can inspect cookies and local storage entries in your browser settings at any time, delete them individually or entirely, and prevent future entries from being set. If you block technically necessary cookies, our forms will no longer work.

7. Audience measurement with Fathom Analytics

We want to know which of our content is read and how visitors find us. For this we use Fathom Analytics, provided by Conva Ventures Inc., 1055 Canada Pl, Vancouver, BC V6C 0C3, Canada.

We chose Fathom deliberately because it is data-minimising:

  • Fathom sets no cookies and uses no other persistent identifiers on your device. No fingerprinting takes place.

  • Fathom creates no cross-device or cross-site user profiles and does not share data for advertising purposes.

  • Processing takes place in Fathom's EU region, i.e. on servers within the European Union.

  • Your IP address is not stored. It is processed only transiently in order to derive a non-reversible attribute for distinguishing visits and a rough geographic classification at country level.

The data processed comprises: page requested, referrer URL, time of access, device type, browser, operating system and country of origin, together with triggered events.

Events: we count individual named events in order to understand which features are used — for example opening a frequently asked question, submitting a form, using our project cost calculator or booking an appointment. These events are likewise recorded only as aggregate figures and are not linked to you as an individual.

Purpose: statistical evaluation of the use of our website in order to design our content according to need and to improve our offering.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in a data-minimising, anonymous evaluation of how our website is used. Since no information is stored on or read from your device, in our assessment consent under Section 25 (1) TDDDG is not required.

Retention period: we retain the aggregated statistical data indefinitely for long-term comparison. It cannot be related back to an individual.

International transfer: processing takes place in the EU. Insofar as the provider in Canada accesses data, this is based on the European Commission's adequacy decision for Canada (commercial organisations) and, in addition, on the Standard Contractual Clauses.

Data processing agreement: a data processing agreement under Art. 28 GDPR is in place with Conva Ventures Inc.

Your right to object: you may object to this processing at any time under Art. 21 (1) GDPR — informally to [email protected]. Independently of this, you can prevent measurement technically by enabling a script blocker or the "Do Not Track" setting in your browser; Fathom respects that setting.

Fathom Analytics privacy policy: https://usefathom.com/privacy

8. Appointment booking via Calendly

On individual pages and in our contact window we offer you the option of booking a meeting directly. For this we use Calendly, provided by Calendly, LLC, 271 17th St NW, 10th Floor, Atlanta, GA 30363, USA.

When data is transferred: the booking window is an embedded Calendly element. As soon as it loads, your browser establishes a direct connection to Calendly's servers. At a minimum, your IP address, information about your browser and operating system and the page requested are transmitted to Calendly; Calendly may set cookies and local storage entries in the process. In our contact window, the element is only loaded once you open the "appointment" tab. On individual landing pages it is loaded as soon as you scroll to the relevant part of the page.

If you book an appointment, we additionally process the data you enter there — generally name, e-mail address, preferred time, time zone and your description of the matter.

Purpose: arranging and managing meetings.

Legal basis: for the booking itself, Art. 6 (1) (b) GDPR, since it serves to carry out pre-contractual measures at your request. For providing the booking function, Art. 6 (1) (f) GDPR; our legitimate interest lies in simple and quick scheduling without e-mail correspondence.

Retention period: we delete appointment data once the meeting has taken place and the matter is concluded, and at the latest on expiry of statutory retention periods.

International transfer: Calendly, LLC is certified under the EU-US Data Privacy Framework. The transfer to the USA is based on the European Commission's adequacy decision of 10 July 2023 and, in addition, on the European Commission's Standard Contractual Clauses.

Data processing agreement: a data processing agreement under Art. 28 GDPR is in place with Calendly.

How to avoid the transfer: if you do not want your data transferred to Calendly, simply do not open the booking window and contact us instead by e-mail at [email protected] or by phone on +49 661 90034410. You will not be at any disadvantage — we are equally happy to arrange appointments that way. You may also object to the embedding at any time under Art. 21 (1) GDPR.

Calendly privacy policy: https://calendly.com/privacy

9. Advertising campaign measurement

We run advertisements on Google Ads. In order to understand which campaigns actually lead to enquiries, we evaluate an identifier that Google appends to the destination address when an ad is clicked.

What happens specifically: if the address requested contains one of the parameters `gclid`, `wbraid` or `gbraid`, we store that value together with a timestamp in your browser's local storage under the key innoge_click_id. If you subsequently submit one of our forms, that value is transmitted with it so that we can attribute the enquiry to the campaign that triggered it. When you open our booking window, the value is also appended to the booking address as a campaign parameter.

Important: we do not embed any Google scripts on our website. There is no Google Analytics, Google Tag Manager or conversion tracking. The identifier is stored and evaluated by us alone. No transfer to Google takes place on our website.

Purpose: measuring the success of our advertising campaigns.

Legal basis: Art. 6 (1) (f) GDPR, legitimate interest in the commercial evaluation of our advertising spend. Section 25 (1) TDDDG may also be relevant to storing the identifier on your device; we inform you transparently at this point and give you a straightforward right to object.

Retention period: the entry remains in your browser's local storage until you delete it. Identifiers that have been transmitted are stored with the corresponding enquiry and deleted with it.

How to object: delete the local storage for innoge.de in your browser settings, use a private browsing window, or visit our pages without clicking an advertisement. You may of course also object informally to [email protected].

10. Contacting us and forms

Contact form and contact window

You can reach us via a contact form and via a contact window accessible from every page. The data collected is:

  • e-mail address (mandatory)

  • subject (mandatory)

  • message (mandatory)

  • phone number (optional)

In addition, the contact window automatically transmits the title of the page from which you opened it. This helps us put your enquiry in context and saves a follow-up question.

To prevent automated spam entries, our forms contain an additional field that is invisible to you and is not filled in by humans. If it is completed, we discard the submission. We deliberately do not use a captcha service; no data is transmitted to third parties for this purpose.

Purpose: processing your enquiry and answering follow-up questions.

Legal basis: Art. 6 (1) (b) GDPR insofar as your enquiry is aimed at concluding or performing a contract; otherwise Art. 6 (1) (f) GDPR, with our legitimate interest in responding to enquiries.

Recipients: submissions are stored on our own server in Germany and additionally delivered to our mailbox by e-mail. They are not passed on to third parties. We do not use a customer relationship or marketing system.

Retention period: we delete your enquiry once it has been dealt with conclusively and no further queries are to be expected, and at the latest after three years at the end of the year. If your enquiry leads to a contract, commercial and tax retention periods apply. You may request earlier deletion at any time.

Enquiries by e-mail and telephone

If you contact us by e-mail or telephone, we process your details solely in order to deal with your request. Legal basis, recipients and retention period correspond to those stated for the contact form.

Automatic acknowledgement and e-mail delivery

We send an automatic acknowledgement of receipt to the address you provide when you submit a form. For the technical delivery of our e-mails we use Amazon Simple Email Service (Amazon SES) provided by Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, 1855 Luxembourg.

Delivery takes place via the Europe (Frankfurt) region, so processing occurs within the European Union. The data processed comprises the recipient address, sender address, subject and content of the message together with technical delivery information. Open and click rates are not measured.

Legal basis: Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR, with our legitimate interest in reliable e-mail delivery.

Data processing agreement: a data processing agreement under Art. 28 GDPR is in place with Amazon Web Services.

AWS privacy notice: https://aws.amazon.com/privacy/

11. Project cost calculator

We provide a project cost calculator that gives you a non-binding initial estimate for a software project. You make your selections anonymously at first; we only ask for your name and e-mail address in order to send you the result.

The data then transmitted and processed comprises your name, your e-mail address and the selections you have made about the project.

Purpose: sending you the initial estimate and internal awareness so that we can advise you competently if you wish.

Legal basis: Art. 6 (1) (b) GDPR, since the calculation is carried out at your request as a pre-contractual measure.

Retention period: the entries are not stored in a database. They are processed solely in order to send the two e-mails — one to you and one to us. What remains is the e-mail in our mailbox, which we treat like any other enquiry and delete in accordance with the periods stated above.

12. Deckname demo (AI-assisted text anonymisation)

On our pages about the "Deckname" product you can paste a text of your choice and see which personal details our process detects and replaces in it.

Notice pursuant to Art. 50 of Regulation (EU) 2024/1689 (AI Act)

This demo processes your input using an AI system. It is a machine learning model for detecting personal details in text. The output is generated automatically and may be incorrect or incomplete. The demo is for illustration only and does not replace a professional review.

Please do not enter real personal data

Please do not paste real data about yourself or about other people into the demo — in particular no health data, application documents, contract documents or customer data. Please use fictitious sample text. If you nevertheless enter third-party data, you are responsible for ensuring that you are entitled to do so.

How your input is processed

  • Your input is limited to 2,000 characters.

  • It is transmitted to our own server and passed from there to a service running locally on that same server which performs the detection. That service is reachable only via the server's local interface and not from the internet.

  • No transfer to an external AI provider takes place. We do not use services from OpenAI, Anthropic, Google, Microsoft or comparable providers for this feature. The text does not leave our infrastructure.

  • Your input is neither stored nor logged. It is not written to a database, not written to log files and not used to train or improve models. Once the result has been returned to your browser, it is discarded from memory.

  • To prevent abuse we limit the number of requests; your IP address is used briefly as a counting key for this purpose (see section 5).

Purpose: illustrating how our product works.

Legal basis: Art. 6 (1) (b) GDPR insofar as using the demo serves to initiate a contract; otherwise Art. 6 (1) (f) GDPR, with our legitimate interest in presenting our services.

Retention period: no storage.

13. Customer and contract data

Where a business relationship is established, we process the data required to establish, structure, perform and invoice it — in particular contact persons, contact details, invoicing and project data.

Legal basis: Art. 6 (1) (b) GDPR for performance of the contract and Art. 6 (1) (c) GDPR for compliance with commercial and tax obligations.

Retention period: after completion of the assignment and termination of the business relationship, we delete the data once the statutory retention periods have expired — generally six or ten years at the end of the year.

We do not operate an online shop, do not process payments via this website and do not carry out credit checks. No data is transferred to credit agencies.

14. Communication and conferencing tools

We use the following tools for working with clients and partners. They only come into play in the context of actual collaboration and are irrelevant to a mere visit to our website.

Microsoft Teams

Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

Used for video and telephone conferences and the accompanying exchange of messages. The data processed includes basic data such as name and e-mail address, metadata such as the time and duration of the conference, and — during transmission — video, audio and text content. We only make recordings where all participants have been informed in advance and have agreed.

Slack

Provider: Salesforce, Inc., Salesforce Tower, 415 Mission Street, San Francisco, CA 94105, USA; for customers in the EEA Salesforce Ireland Limited, 5 Hanover Quay, Dublin 2, Ireland.

Used for ongoing exchange of messages in shared project channels. The data processed includes name, e-mail address, message content, shared files and usage metadata.

Common information

Purpose: simple and quick coordination in the course of our collaboration.

Legal basis: Art. 6 (1) (b) GDPR insofar as use serves the initiation or performance of a contract; otherwise Art. 6 (1) (f) GDPR, with our legitimate interest in efficient communication.

Retention period: we delete content once it is no longer required for the purpose, and at the latest after the end of the collaboration and expiry of statutory retention periods.

International transfer: both providers may transfer data to affiliated companies in the USA. Microsoft Corporation and Salesforce, Inc. are certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission's adequacy decision of 10 July 2023 and, in addition, on the Standard Contractual Clauses.

Data processing agreements: data processing agreements under Art. 28 GDPR are in place with both providers.

15. Job applications

We welcome applications — via our careers site at karriere.innoge.de, by e-mail to [email protected] or by post. This privacy policy applies to all of these routes.

Which data we process

We process the data you send us as part of your application — generally name, contact details, covering letter, CV, references and evidence of qualifications, together with details of your preferred start date and salary expectations.

Please do not send us special categories of personal data under Art. 9 GDPR that are not required for the application — in particular no information about health, religious affiliation or trade union membership. A photograph is expressly optional; its absence has no adverse effect. We process information about a disability only where this is necessary for exercising rights and fulfilling obligations under employment law (Art. 9 (2) (b) GDPR).

Purpose and legal basis

Purpose: conducting the recruitment process, i.e. reviewing your documents, communicating with you, holding interviews and deciding on an appointment.

Legal basis: Section 26 (1) sentence 1 BDSG in conjunction with Art. 6 (1) (b) GDPR — the processing is necessary for the decision on establishing an employment relationship. Insofar as we process data to defend against potential claims, we rely on Art. 6 (1) (f) GDPR. Inclusion in our talent pool is based on your consent under Art. 6 (1) (a) GDPR.

Recipients

Your documents are seen only by those involved in the appointment decision — the management and, where applicable, the relevant department. They are not passed on to third parties. There is no automated pre-selection and no AI-assisted assessment of applications; every application is read and assessed by people.

Retention period

If you are appointed, we transfer your data to your personnel file. Otherwise we delete your documents no later than six months after the conclusion of the process. This period reflects potential claims under the German General Equal Treatment Act.

With your express consent we will additionally include you in our talent pool and store your documents for twelve months so that we can approach you about suitable positions. You may withdraw this consent informally at any time.

Speculative applications

The same principles apply to speculative applications. We store your documents for six months and will contact you as soon as a suitable position becomes available.

16. Our social media profiles

We maintain profiles on LinkedIn, Instagram, X and GitHub. On our website we merely link to these profiles with an ordinary link.

Simply visiting our website therefore transmits no data to these networks. We do not embed any buttons, tracking pixels or other active content from the networks. Data is only transmitted once you click one of these links and access the network's site.

If you visit our profile there, the respective provider processes your data in accordance with its own terms. We are jointly responsible with the respective provider for the processing of data generated for statistical purposes about our company page (Art. 26 GDPR). We have only limited influence over the extent and nature of that processing. You may assert your rights both against us and against the respective provider; for information about the data stored there, please contact the provider directly, as only they have full access to it.

17. Data security

Our website is delivered exclusively over an encrypted TLS connection. You can recognise this by the address beginning with "https://" and by the padlock symbol in your browser's address bar. The data you transmit to us is therefore protected in transit against being read by third parties.

We also take technical and organisational measures under Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. We adapt these measures continuously in line with technical developments.

Please note that the transmission of data over the internet — for example unencrypted e-mail — may have security gaps. Complete protection against access by third parties is not possible. For particularly confidential information we are happy to offer you an encrypted transmission channel.

18. Changes to this privacy policy

We update this privacy policy whenever our processing activities or the legal framework change. The version available on this page applies. The date given above indicates when the current version was prepared.

Objection to promotional e-mails

We hereby object to the use of contact details published under our imprint obligation for the purpose of sending advertising and information material that has not been expressly requested. We expressly reserve the right to take legal action in the event of unsolicited promotional information being sent.

Let's talk about your project

Book a free appointment directly or send us a message. We'll get back to you within one business day.

Calendar not loading? Open in a new tab

Optional
Max. 500 characters