elbmind GmbH
Privacy Policy
Information on the processing of personal data pursuant to Art. 13, 14 GDPR.
1. Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations is:
elbmind GmbH
Represented by Dipl.-Ing. Thomas Lindner (Managing Director)
Semperstraße 2b
01069 Dresden
Germany
Phone: +49 177 2774874
Email: mail@elbmind.com
2. Data Protection Officer
Due to our company size, we are not legally required to appoint a data protection officer. For all data protection matters, please contact the controller named above at mail@elbmind.com.
3. General Information on Data Processing
We process personal data of our users only insofar as this is necessary to provide a functional website as well as our content and services. Processing is generally carried out only with the user's consent (Art. 6(1)(a) GDPR), for the performance of a contract (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c) GDPR), or on the basis of legitimate interests (Art. 6(1)(f) GDPR).
4. Rights of the Data Subject
You have the following rights regarding your personal data processed by us:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure ("right to be forgotten", Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for us is:
5. Website Provision and Server Log Files
Each time our website is accessed, our system automatically collects data and information from the computer system of the calling device. The following data is temporarily stored in log files:
- IP address (in shortened/anonymized form)
- Date and time of access
- URL called and HTTP status code
- Browser and operating system used (user agent)
- Referrer URL
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the technical provision, security and stability of our website. Log files are deleted after 30 days at the latest, unless security-relevant incidents require longer storage.
6. Hosting
Our website is operated on a globally distributed edge platform (Cloudflare Workers). The provider processes data on our behalf that is necessary for the technical operation of the website. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the provider. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, performant provision).
7. Cookies
Our website uses only technically necessary cookies or comparable storage technologies (e.g. for the language selection DE/EN). These are strictly required for the operation of the website (§ 25(2)(2) TTDSG, Art. 6(1)(f) GDPR). We do not use tracking or marketing cookies.
8. Contact
If you contact us via the contact form, email or telephone, your information (e.g. name, email address, phone number, message content) will be stored by us for the purpose of processing your request and in the event of follow-up questions. The legal basis is Art. 6(1)(b) GDPR (pre- contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in the effective handling of your request). Your data will be deleted as soon as it is no longer required for the purpose, at the latest after expiry of statutory retention periods (usually 6 or 10 years under HGB/AO).
9. Third-Party Services
Logo.dev
On our references page, company logos are loaded via the Logo.dev service (Silver Bullet Labs, Inc.). When the images are called, your IP address is transmitted to the provider. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in an appealing presentation of publicly known brands).
External Web Fonts
To display fonts consistently, we integrate external web fonts. When a page is called, your browser loads the required fonts from the respective provider. The legal basis is Art. 6(1)(f) GDPR.
10. Data Transfer to Third Countries
If personal data is transferred to recipients outside the EU/ EEA, this only takes place on the basis of appropriate safeguards within the meaning of Art. 44 ff. GDPR (e.g. EU standard contractual clauses, adequacy decisions of the EU Commission).
11. SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the "https://" in the address bar of your browser.
12. Objection to Advertising Emails
The use of contact data published within the framework of the imprint obligation for sending unsolicited advertising and information materials is hereby objected to. The site operators expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as via spam emails.
13. Currency and Amendment of this Privacy Policy
This privacy policy is currently valid. Due to the further development of our website or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version can be accessed at any time on this page.