Privacy Policy
1. Data Protection at a Glance
General Information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on data protection can be found in our Privacy Policy below this text.
Data Collection on This Website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find the contact details of the website operator in the section “Note on the Responsible Party” in this privacy policy.
How do we collect your data?
Some of your data is collected when you provide it to us — for example when you send us an email or call us. This website contains no contact form and no other input fields; you cannot transmit any data to us through the site itself.
Other data is collected automatically by our server when you visit the website. This is technical data (e.g., Internet browser, operating system, or time of page access). It is collected as soon as you access this website; the collection is technically necessary and is not made dependent on your consent. The section “Server Log Files” describes exactly which data this is.
What do we use your data for?
We use the automatically collected technical data solely to provide the website free of errors and to protect our server against attacks. Your user behaviour is not analysed. Data you send us by email or tell us by phone is used solely to handle your enquiry. No contracts can be concluded and no orders can be placed via this website.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of this data. If you have consented to data processing, you can withdraw this consent at any time with effect for the future. Furthermore, you have the right to request the restriction of the processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority.
For further questions regarding data protection, you can contact us at any time.
Analysis Tools and Third-Party Tools
This website does not use any analysis, tracking or statistics programs. Your browsing behaviour is not evaluated.
2. Hosting and Server Operation
External Hosting
This website is hosted by an external service provider (host). The provider is
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
The server on which this website runs is located in the Falkenstein data centre in Germany. No personal data is transferred to a third country outside the European Union.
The data our host processes on our behalf is limited to the technical access data required to deliver the website — in particular IP addresses. The section “Server Log Files” describes exactly which data this is and how long it is stored. This website contains no forms, so no data entered by you is processed.
We use this host in the interest of a secure, fast and reliable delivery of our online offering by a professional provider. The legal basis is Art. 6 para. 1 lit. f GDPR.
Our host processes your data only to the extent necessary to fulfil its performance obligations, and follows our instructions in doing so.
Further information can be found in Hetzner’s privacy policy: https://www.hetzner.com/legal/privacy-policy/
Data Processing Agreement
We have concluded a data processing agreement (DPA) with the provider named above. This is a contract required by data protection law, ensuring that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Detection and Prevention of Attacks
Like any publicly reachable server, ours is subject to automated attack attempts such as vulnerability scans or login attempts with guessed credentials. To protect against these we use the CrowdSec software. It evaluates the server log files and blocks IP addresses from which attacks demonstrably originate.
When an IP address is identified as a source of attacks, we transmit it to the provider
CrowdSec SAS
20 rue Maurice Arnoux
92120 Montrouge
France
and receive in return block lists compiled from the reports of all participants.
What is transmitted: the IP address the attack originates from, the network identification derived from it (AS number and country), the detected attack pattern including its version, the start and end of the observation and the number of observed events, the measure we took in response and its duration, an identifier of our server instance, and technical identifiers of the report itself.
What is not transmitted: log files, pages requested, browser identifiers (user agent), or data belonging to regular visitors of this website.
The legal basis is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in protecting our server and the availability of this website against attacks. The provider is established in the European Union; no transfer to a third country takes place.
Further information: https://www.crowdsec.net/privacy-policy
3. General Notes and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations as well as this privacy policy.
When you use this website, various personal data will be collected. Personal data is data with which you can be personally identified. This privacy policy explains which data we collect and how we use it. It also explains how and for what purpose this is done.
We point out that data transmission over the Internet (e.g., when communicating via email) may have security vulnerabilities. Complete protection of data from access by third parties is not possible.
Note on the Responsible Party
The responsible party for data processing on this website is:
Inmati GmbH
Grotzstr. 23
87448 Waltenhofen
Phone: +49 162 6045721
Email: info@inmati.com
The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Storage Duration
Unless a more specific storage period is mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you make a legitimate request for deletion or revoke consent for data processing, your data will be deleted unless we have other legally permissible reasons to store your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will occur after these reasons no longer apply.
General Notes on the Legal Grounds for Data Processing on This Website
If you have given consent to data processing, we process your personal data based on Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, if special categories of data are processed according to Art. 9 para. 1 GDPR. In case of explicit consent for the transfer of personal data to third countries, data processing is also based on Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing is additionally based on § 25 para. 1 TDDG. The consent can be withdrawn at any time. If your data is required for contract fulfillment or for the execution of pre-contractual measures, we process your data based on Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if necessary to fulfill a legal obligation based on Art. 6 para. 1 lit. c GDPR. Data processing may also be based on our legitimate interest under Art. 6 para. 1 lit. f GDPR. The relevant legal grounds for processing are explained in the following sections of this privacy policy.
Recipients of Personal Data
In the course of our business activities, we cooperate with various external entities. In some cases, it is necessary to transfer personal data to these external parties. We only disclose personal data to external parties if this is necessary for the fulfillment of a contract, if we are legally obligated to do so (e.g., transfer of data to tax authorities), if we have a legitimate interest in the disclosure under Art. 6 para. 1 lit. f GDPR, or if another legal basis permits the disclosure of the data. When using processors, we only transfer personal data of our customers based on a valid order processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can withdraw any consent you have given at any time. The legality of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RELEVANT LEGAL BASIS ON WHICH THE PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING, TO THE EXTENT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION UNDER ART. 21 PARA. 2 GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
If there are violations of the GDPR, affected individuals have the right to lodge a complaint with a supervisory authority, especially in the member state of their usual residence, place of work, or the place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract in a structured, commonly used, and machine-readable format. If you request the direct transfer of data to another controller, this will only be done to the extent technically feasible.
Access, Correction, and Deletion
You have the right to obtain free information about your stored personal data, its origin, recipients, and the purpose of the data processing at any time, as well as the right to correct or delete this data if applicable. You can contact us at any time for these and other questions regarding personal data.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this. The right to restrict processing applies in the following cases:
-
If you dispute the accuracy of your personal data stored with us, we generally need time to verify this. During the verification period, you have the right to request the restriction of processing your personal data.
-
If the processing of your personal data was unlawful, you may request the restriction of data processing instead of deletion.
-
If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of processing your personal data instead of deletion.
-
If you have objected under Art. 21 para. 1 GDPR, a balancing must be made between your interests and ours. As long as it is not clear whose interests prevail, you have the right to request the restriction of processing your personal data.
If you have restricted the processing of your personal data, such data – apart from storage – may only be processed with your consent or to establish, exercise, or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.
SSL or TLS Encryption
This site uses SSL or TLS encryption for security reasons. It protects your retrieval of this website: third parties cannot see which pages you access while the data is in transit, and cannot alter the content. You can recognize an encrypted connection by the fact that the address line of your browser changes from “http://” to “https://” and by the lock symbol in your browser bar.
Because this website contains no input fields, you do not send us any data through the site itself. For an enquiry by email, the note in the section “Data Protection” applies: the transmission of emails is not protected by this encryption.
Objection to Advertising Emails
The use of contact data published as part of the legal notice to send unsolicited advertising and information materials is hereby objected to. The operators of the site expressly reserve the right to take legal action in case of unsolicited sending of advertising information, such as spam emails.
4. Data Collection on This Website
Cookies
This website sets no cookies and uses no comparable recognition technologies such as local storage, session storage or device fingerprinting. Consent under Section 25 (1) TDDDG is therefore not required, and no consent banner is needed.
Server Log Files
The provider of the pages collects and stores information automatically in so-called server log files, which your browser automatically transmits to us. These include:
-
Browser type and browser version
-
Used operating system
-
Referrer URL
-
Hostname of the accessing computer
-
Time of the server request
-
amount of data transferred
-
IP address
These data are not merged with other data sources.
Retention. We distinguish by the purpose of the processing:
-
To detect and prevent attacks we process the full IP address (see “Detection and Prevention of Attacks”). All data stored for this purpose is deleted after 48 hours at the latest.
-
For technical operation and troubleshooting we process the access data with a truncated IP address. For IPv4 the last block of digits is removed, for IPv6 correspondingly, so that attribution to an individual connection is generally no longer possible. This data is deleted after 14 days at the latest.
This data is not included in any backup, so the periods stated above are the actual retention periods.
The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free display, the security and the optimization of its website – for this purpose, the server log files must be collected.
Inquiries by Email, Phone, or Fax
If you contact us by email, phone, or fax, your inquiry, including all personal data arising from it (name, inquiry), will be stored and processed for the purpose of handling your request. We will not pass on this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is necessary for the performance of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if it has been requested; consent can be withdrawn at any time.
The data you send us via contact inquiries will remain with us until you request deletion, revoke your consent for storage, or the purpose for data storage no longer applies (e.g., after your request has been fully processed). Mandatory legal provisions – especially legal retention periods – remain unaffected.
5. Plugins and Tools
This website embeds no third-party content, fonts, scripts, maps or media. All files are served exclusively from our own server. Visiting this website therefore establishes no connection to third-party servers, and no data is transmitted to third parties.
Source: https://www.e-recht24.de
