Data Protection Information

Below you will find detailed information on how data protection is ensured on our website “https://www.hyceon.com/”.

Mandatory information according to External: Article 13 of the General Data Protection Regulation (GDPR).

The protection of your private data is a top priority for us. We therefore use targeted measures to ensure that both our team and service providers commissioned by us strictly follow the statutory provisions for handling personal data.

hyceon is a registered trademark of TTSP HWP GmbH.

1. Responsible Body and Data Protection Officer

The responsible body for data processing on this website within the meaning of External: Article 4 No. 7 of the General Data Protection Regulation is:

TTSP HWP GmbH
Hanauer Landstraße 181-185
60314 Frankfurt am Main
Email contact: info@ttsp-hwp.de
Telephone: +49 69 96 12 23-0

All details regarding the persons legally responsible for this internet offering can be found in the Imprint.

You can reach our company data protection officer at:

Data Protection Officer of TTSP HWP GmbH
Protektis GmbH
Benzstraße 2a
63741 Aschaffenburg
Email: datenschutz@ttsp-hwp.de

Please note: The data protection officer handles questions regarding data protection in our company. For other questions regarding data protection in which hyceon is not involved, you are welcome to contact the competent supervisory authority:

The Hessian Commissioner for Data Protection and Freedom of Information
Wilhelmstraße 7
65185 Wiesbaden

2. General Information on Data Processing and Legal Bases

The following list explains how hyceon protects your privacy and which categories of information we process for which purposes and to what extent. We also inform you about your individual data subject rights.

This privacy policy remains valid for all online offers from hyceon, regardless of the end devices used (e.g., smartphone or PC), systems, or domains.

Technical terms such as “processing” or “personal data” are used here in accordance with the definitions in External: Article 4 of the General Data Protection Regulation.

We reserve the right to update this statement to adapt it to new legal framework conditions or changed processes in our data processing. Technical innovations may also make a revision necessary. We therefore advise you to check this page regularly. If changes affect regulations of your contractual relationship or if consent is required, we will only make these adjustments with your prior consent.

In addition, for certain functions, such as cookies or social media links, the provisions of the Telecommunications-Digital-Services-Data-Protection-Act (TDDDG) are a decisive legal basis.

3. Data Processing Processes on this Website

Within the scope of our web presence, we process data for the following purposes:

  • Provision and retrieval of website content,
  • Processing of inquiries via contact form,
  • Conducting statistical analyses.

The processed categories of personal data include master data (such as names and email addresses), usage data (e.g., visited websites, access times), and content data (such as your text entries in forms).

The collection is based on External: Article 6 paragraph 1 point (f) GDPR, to safeguard our legitimate interest in providing this online service.

We process your data strictly according to applicable law. This means that processing only takes place if it is necessary for the fulfillment of a contract or the implementation of pre-contractual measures External: Article 6 paragraph 1 point (b) GDPR, is required to fulfill a legal obligation External: Article 6 paragraph 1 point (c) GDPR, serves to safeguard our legitimate interests External: Article 6 paragraph 1 point (f) GDPR or you have given us your explicit consent for this External: Article 6 paragraph 1 point (a) GDPR.

Server Logfiles (Log Data)

For technical reasons, a data transfer takes place between your browser and our host system with every page call. The following logfile information is automatically recorded by hyceon:

  • Browser type including version number,
  • the operating system used,
  • the specifically selected subpage,
  • the origin page (referrer URL),
  • time of the server request.

The evaluation of these logs takes place exclusively in anonymized form (after shortening the IP address) for statistical analyses of reach and system performance. It is not possible for us to identify individual persons; furthermore, these data sets are not linked with other sources.

Important Note: While the statistical evaluation is anonymized, the collection and temporary processing of the user’s IP address is technically necessary to enable the delivery of the website to your computer and to ensure the security of our information technology systems against attacks. For this reason, IP addresses are recorded as part of security and hosting operations by our service providers IONOS and Sucuri.

IP addresses are automatically anonymized or deleted after seven days. The legal basis for this temporary storage of data and logfiles is our legitimate interest according to External: Article 6 paragraph 1 point (f) GDPR.

We only pass on log data if there is a legal obligation or a court order, or if attacks on our systems require criminal prosecution. No other transmission to third parties takes place.

4. Website Provision and Security

Web Hosting by IONOS

Our website is hosted on the servers of the provider IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Each time our website is accessed, the system automatically collects data and information from the computer system of the accessing computer (server logfiles). The hosting provider processes this data exclusively on servers within the European Union, which guarantees European data protection standards. The temporary storage of the IP address and the logfiles is technically necessary to enable delivery of the website and to ensure IT security. The legal basis for this data processing is our legitimate interest according to External: Article 6 paragraph 1 point (f) GDPR.

Security Services and Web Application Firewall (Sucuri)

To protect our website from unauthorized access, cyber attacks, malware, and harmful bots, we use the security solution and firewall from Sucuri (Provider: GoDaddy Media Temple, Inc., USA). All data traffic of our website is routed via Sucuri’s servers (Web Application Firewall) and analyzed there for threats. Logfiles including the IP addresses of website visitors are recorded and processed by Sucuri.

The use of this service serves to maintain the security, stability, and integrity of our online systems. Processing takes place on the basis of our legitimate interest in the secure provision of our online offer according to External: Article 6 paragraph 1 point (f) GDPR.

Transfer to Third Countries (USA): Sucuri is a service of the GoDaddy group based in the USA. Since Sucuri filters all incoming web traffic, an inspection of personal data (such as IP addresses) by the US parent company cannot be completely ruled out. This data transfer is primarily secured via the adequacy decision of the European Commission of July 10, 2023, according to Art. 45 GDPR, as the parent company GoDaddy.com, LLC is certified under the EU-U.S. Data Privacy Framework (DPF). Additionally, we have concluded Standard Contractual Clauses (SCCs) according to Art. 46 Para. 2 lit. c GDPR with the provider to ensure the protection of your data even in the event of a change in DPF status.

Storage Period: Security logfiles at Sucuri are generally kept for a maximum of 30 days and then deleted, unless they are needed longer for investigation purposes in the event of security incidents.

5. Contacting Us, Forms, and Customer Relationship Management (CRM)

Submission of Voluntary Data

At various points on our website, you can actively provide us with data, for example, in contact forms, by email, or through telephone inquiries. We use this information strictly for the purpose of your respective request. Without an explicit notice, we do not pass this data on to outsiders.

Contact Forms (Gravity Forms)

We offer various forms on our website (e.g., for general contact inquiries, callback requests, or the download of whitepapers), which are provided via the WordPress plugin “Gravity Forms”. When you use these forms, the data entered in the input mask (such as first and last name, email address, phone number, and your message) is transmitted to us and stored.

The data is used exclusively for processing your respective request, contacting you, or providing the requested documents.

This data is processed on the basis of External: Article 6 paragraph 1 point (b) GDPR, provided that your request is related to the performance of a contract or is necessary to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (External: Article 6 paragraph 1 point (f) GDPR) or on your consent (External: Article 6 paragraph 1 point (a) GDPR), provided this was explicitly requested.

Storage Period: We store the data collected via our contact forms for as long as is necessary to process your request or the resulting transaction, or until you request deletion or withdraw your consent. Mandatory legal storage periods remain unaffected (e.g., 6 to 10 years for business correspondence under the Commercial Code [HGB] or the Tax Code [AO]).

Customer Management and Email Dispatch (HubSpot & WP Mail SMTP)

The data collected via our forms is automatically transferred via an interface (add-on) to our CRM system “HubSpot” and stored there for the central management of your contact inquiries, customer relationships, and potential marketing measures (where legally permissible).

The provider for the European area is HubSpot Ireland Limited, 1 Sir John Rogerson’s Quay, Dublin 2, Ireland. The parent company is HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA.

For the secure and reliable dispatch of system and notification emails (e.g., confirmation emails after filling out a form), we also use the service “WP Mail SMTP”.

The use of the CRM system and the SMTP service is based on our legitimate interest in fast, efficient, data-protection-compliant, and secure management of user inquiries and customer relationships according to External: Article 6 paragraph 1 point (f) GDPR.

Transfer to Third Countries (USA): As part of the use of HubSpot, a data transfer to the USA may take place. This transfer is primarily based on the adequacy decision of the European Commission of July 10, 2023, according to Art. 45 GDPR for the EU-U.S. Data Privacy Framework (DPF), under which HubSpot, Inc. is actively certified. As an additional legal safeguard, we have concluded Standard Contractual Clauses (SCCs) with HubSpot according to Art. 46 Para. 2 lit. c GDPR, which guarantee data-protection-compliant transfer even in the event of a change in the legal situation.

Storage Period: Data in the HubSpot CRM system is stored for as long as is necessary for customer relationship management and to process your concerns. It will be deleted if the purpose of storage no longer applies, you object to processing, or request deletion, provided there are no legal storage periods to the contrary.

Direct Marketing Note: Since we can also use HubSpot for future marketing measures, we explicitly point out your right to object to the processing of your data for the purpose of direct marketing at any time, informally and free of charge, in accordance with External: Article 21 paragraph 2 GDPR (see section 8 “Data Subject Rights”).

Further details on data processing by HubSpot can be found in the official privacy policy of the provider at: https://legal.hubspot.com/privacy-policy.

Geolocation and Multilingualism (WPML)

To be able to offer our website in multiple languages and automatically deliver content suitable for your region, we use the plugin WPML in combination with a geolocation add-on. For this automatic assignment, the tool processes your IP address to determine your rough location (country/region).

This function is technically necessary to present the website in the desired language version and to increase user-friendliness. The legal basis for the temporary processing of the IP address for this purpose is our legitimate interest according to External: Article 6 paragraph 1 point (f) GDPR. The IP address is only processed in transient storage and is not permanently logged for this purpose.

Performance Optimization through Caching (WP Rocket)

To optimize loading times and improve the general performance of our website, we use the caching plugin “WP Rocket” (wp-rocket.me). The plugin stores static copies of our website content and delivers them faster on recurring visits. WP Rocket may set a technically necessary cookie to recognize if you have made certain view settings.

The use of this performance tool and the storage of the associated cookie are based on § 25 Para. 2 No. 2 TDDDG in conjunction with our legitimate interest (External: Article 6 paragraph 1 point (f) GDPR) in technically flawless and fast delivery of our internet appearance.

6. Cookies and Consent Management

Cookies (General Information)

To ensure that the cookie settings you have made are maintained on our site and that you can use our services smoothly, so-called session cookies are used. Cookies are small text files that a provider stores in the memory or on the visitor’s end device. A randomly generated unique identification number, a so-called session ID, is stored in a session cookie. A cookie also contains information about its origin and storage period. These cookies cannot read or damage other data on your computer.

Session cookies are only stored for the duration of the current visit to our website and are deleted when you close your browser. In this respect, too, we only process your personal data to provide the online offer on the basis of § 25 Para. 2 No. 2 TDDDG (technically necessary storage) in conjunction with External: Article 6 paragraph 1 point (f) GDPR.

Use of Cookies and Consent Process

Our website uses cookies. We differentiate here between essential cookies for operating the site and optional technologies for advertising, analysis, or third-party content.

  • Legal Bases for Cookie Use: Essential cookies are based on § 25 Para. 2 No. 2 TDDDG, as they are indispensable for the service you have requested. We only use all other optional cookies after you have given us active consent in accordance with § 25 Para. 1 TDDDG and External: Article 6 paragraph 1 point (a) GDPR.
  • Control via the Cookie Banner: As soon as you access our website for the first time, a notice banner appears, through which you can configure your individual settings regarding the use of cookies and other tracking technologies. If you decide against using optional cookies, this has no negative impact on the usability of our website. You will still have full access to all essential information of our internet presence.
  • Withdrawal and Adjustment: You can withdraw your consent to data processing at any time with effect for the future. If you wish to adjust your decisions subsequently, a special configuration menu is permanently available on our website, which you can conveniently reach via the corresponding link in the footer of our website.
  • Manual Control of Cookies: You can generally regulate the acceptance of cookies in your browser settings. However, you can disable the storage of cookies at any time in the system settings. Please note that general rejection of cookies can lead to functional restrictions.

Cookie Consent Management (Cookiebot)

To comply with legal requirements and to obtain and document your consent for the use of cookies subject to consent and third-party services in a legally secure manner, we use the consent management tool Cookiebot. The provider of this service is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.

When you visit our website, a connection to Cookiebot’s servers is established to query and document your preferences regarding cookie use. Your IP address and information about your browser and end device may be transmitted to Cookiebot.

In addition, the tool stores a technically necessary cookie in your browser (CookieConsent), to be able to permanently assign the consents given or their withdrawal to future page calls.

The legal basis for the associated data processing is External: Article 6 paragraph 1 point (c) GDPR, fulfillment of the legal obligation to obtain and document legally compliant consents. The storage of the technically necessary cookie for documenting your decision on your end device is based on § 25 Para. 2 No. 2 TDDDG.

Storage Period: The consent cookie is stored in your browser for a period of 12 months, unless you delete the cookie yourself beforehand from your browser history or withdraw your consent.

Further information on data protection at Cookiebot can be found in the provider’s privacy policy at: https://www.cookiebot.com/en/privacy-policy/.

Detailed Cookie Overview

We do not list static lists of the cookies used in this statement, as these change dynamically through updates and technical adjustments. A detailed and always up-to-date overview of all cookies used, including their specific functions, purposes, periods of validity, and classification by category (e.g., essential, statistical, marketing), is automatically generated by Cookiebot and is stored in our separate Cookie Policy.

There you also have the opportunity at any time to check, adjust, or withdraw your consent made in the cookie banner.

7. Web Tracking and Analysis (Google Services)

Web Tracking with Google Analytics 4 (GA4)

If you have given your explicit consent via our cookie banner, we use the web analysis service Google Analytics 4 (GA4) for statistical evaluation and analysis of visitor access. The provider of this service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

For the demand-oriented design and continuous improvement of our internet offer, pseudonymous usage profiles are created and evaluated based on the collected data. For this function, cookies are stored on your end device. The information generated by the cookies about your use of this internet offer is usually transmitted to servers of Google LLC in the USA and stored there.

When using GA4, IP anonymization is activated by default. This means that your IP address is shortened by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before storage, to rule out a direct identification of the individual visitor. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

The legal basis for this processing and the storage of cookies on your end device is your consent according to External: Article 6 paragraph 1 point (a) GDPR in conjunction with § 25 Para. 1 TDDDG.

Transfer to Third Countries (USA): The transfer of your data to Google LLC in the USA is primarily based on the adequacy decision of the European Commission of July 10, 2023, according to Art. 45 GDPR for the EU-U.S. Data Privacy Framework (DPF), under which Google LLC is actively certified. As an additional safeguard, we have agreed Standard Contractual Clauses (SCCs) with Google according to External: Article 46 paragraph 2 GDPR, which ensure an adequate level of data protection even if the legal situation changes.

Storage Period: The data transmitted by us to Google at the event level (Event-Data) is automatically and irrevocably deleted after a storage period of 14 months.

Further information on which data is processed by Google and for what purposes it is used can be found in Google’s privacy policy at: https://policies.google.com/privacy.

Google Ads Conversion Tracking and Google Tag Manager

If you have given your explicit consent via our cookie banner, we use the Google Tag Manager as well as Google Ads Conversion Tracking on our website. The provider of these services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The Google Tag Manager is an auxiliary service with which we can centrally manage and integrate website tags (such as tracking codes or analysis tools) via a uniform interface. The Tag Manager itself usually does not set its own cookies and does not directly evaluate personal data, but merely ensures the controlled triggering of other tags. To provide this service technically, however, the Google Tag Manager establishes a connection to Google’s servers, whereby Google gains knowledge of your IP address.

Furthermore, we use Google Ads Conversion Tracking to measure the effectiveness of our advertising measures and to make our offer more target-oriented. If you reach our website via a Google advertisement, a cookie for conversion tracking is stored on your end device. Based on this cookie, both we and Google can recognize that you clicked on the advertisement and were redirected to our page to follow certain actions (conversions, e.g., submitting a contact form). These cookies do not serve the personal identification of users.

The legal basis for the use of these services and the storage of the associated cookies on your end device is your prior consent according to External: Article 6 paragraph 1 point (a) GDPR in conjunction with § 25 Para. 1 TDDDG.

Transfer to Third Countries (USA): The data transfer to the USA is primarily secured via the DPF certification of Google LLC (External: Article 45 GDPR) and secondarily via Standard Contractual Clauses (SCCs) according to External: Article 46 paragraph 2 point (c) GDPR.

8. Information on our Presence on Social Platforms

We maintain an online presence on the platform LinkedIn to communicate with our customers, interested parties, and partners and to provide information about our service portfolio.

The transfer of data to third countries (such as the USA) within the scope of our social media activities is primarily based on the adequacy decision of the European Commission of July 10, 2023, according to External: Article 45 GDPR for the EU-U.S. Data Privacy Framework (DPF). The platforms we use or their parent companies are certified under this framework.

To increase transparency and clarity, we have summarized the corresponding certifications in the following table.

Overview of Transatlantic Data Transfers

(As of: August 2026)

PlatformOperator in the EUUS Parent Company (Data Recipient)Certification after EU-U.S. DPFLink to DPF Entry
LinkedInLinkedIn Ireland Unlimited CompanyMicrosoft CorporationActivehttps://www.dataprivacyframework.gov/participant/6474
HubspotHubSpot, Inc.HubSpot, Inc.Activehttps://www.dataprivacyframework.gov/participant/5812
Google (GA4/Ads)Google Ireland LimitedGoogle LLCActivehttps://www.dataprivacyframework.gov/participant/5780
SucuriGoDaddy Media Temple, Inc.GoDaddy Media Temple, Inc.Activehttps://www.dataprivacyframework.gov/participant/4957

Note: To provide coverage in the event of the DPF being invalidated, Standard Contractual Clauses (SCCs) have also been agreed upon with all the aforementioned providers.

Mere Linking to LinkedIn

We do not use active social media plugins on our website. We refer to our LinkedIn company page and the personal profiles of our management team exclusively via mere links (hyperlinks).

This means that when you merely navigate on our website, no personal data is transmitted to LinkedIn. A data transfer only takes place when you actively click on the corresponding LinkedIn symbol or the text link and are thereby redirected to the LinkedIn platform. By following this link, you leave our website. The LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, is responsible for the subsequent data processing of persons outside the USA, and LinkedIn’s data protection provisions apply.

Joint Controllership for LinkedIn Page Insights

LinkedIn provides us with so-called Page Insights for our LinkedIn company page. These are summarized, non-personal statistics (e.g., demographic data on visitors, click rates, interactions) that help us evaluate the attractiveness of our presence and optimize it according to needs.

Regarding the collection and processing of this insights data, there is a joint controllership in accordance with External: Article 26 paragraph 1 GDPR between TTSP HWP GmbH and LinkedIn Ireland Unlimited Company. For this purpose, we have concluded a corresponding agreement with LinkedIn (LinkedIn Page Insights Joint Controller Addendum).

This agreement states that:

  • LinkedIn bears the primary responsibility for the processing of insights data and fulfills all obligations under the GDPR (including information obligations under Art. 13, 14 GDPR, guaranteeing data subject rights).
  • The Irish Data Protection Commission is the lead supervisory authority for joint processing.
  • We have no way of viewing the specific raw data of individual users, but exclusively receive aggregated reports.

We recommend that you assert your data subject rights (such as access or erasure) regarding the insights data directly against LinkedIn, as only LinkedIn has full access to the user data and can implement the corresponding measures immediately.

Detailed information on data processing by the network, on the relevant legal bases, and on your specific rights against LinkedIn can be found in LinkedIn’s official privacy policy at: https://de.linkedin.com/legal/privacy-policy.

9. Contact, Applications, and Events

Contact with hyceon

You have many options to communicate with us (by post, email, contact form, telephone, or fax). We store and use the data voluntarily provided to us exclusively for the purpose for which it was given (e.g., answering your inquiry).

Should the support of a third party (e.g., a specialist planner or partner office) be required to process your concern, we will only pass on your data for that specific purpose.

Conducting Events and Site Access

Where there is a connection to our business premises, grounds, or projects – for example, as part of specialist events, tours, or meetings – we process personal data of organizers, visitors, and participants.

It may be necessary here to pass on participant lists to third parties (in particular to the external security service / porter commissioned as part of our security concept, as well as to co-organizers of events).

The legal basis for this data processing and any transfers is the fulfillment of the event certificate or contract implementation (External: Article 6 paragraph 1 point (b) GDPR) and our legitimate interest in safeguarding domestic authority, guaranteeing building security, and the orderly conduct of the event (External: Article 6 paragraph 1 point (f) GDPR).

Registration for Events

Should you be invited to a hyceon event and register for it via a form on our website, we collect your registration data (usually first and last name, email address, and organization; for security-sensitive events, depending on access requirements, possibly also date of birth, address, or ID card number).

We use this data exclusively for the purpose of conducting the event, for participant coordination, and for admission control.

The legal basis is the event participation contract External: Article 6 paragraph 1 point (b) GDPR) or your consent (External: Article 6 paragraph 1 point (a) GDPR). All registration data is deleted after the end and follow-up of the event, provided there are no legal storage obligations to the contrary.

Data Protection for Job Applications

We process the data you send to us in connection with your application to check your suitability for the advertised position (or possibly other open positions in our company) and to conduct the application process. This includes your cover letters, resumes, certificates, and information provided in the interview.

The provision of the data is necessary to conduct the application process. There is no legal obligation; however, without this data, we cannot consider your application in the selection process.

  • Legal Basis: The primary legal basis for the processing of your applicant data is § 26 paragraph 1 of the Federal Data Protection Act (BDSG) in conjunction with External: Article 6 paragraph 1 point (b) GDPR (initiation of an employment relationship).
  • Sensitive Data: If you voluntarily provide us with special categories of personal data within the meaning of Art. 9 Para. 1 GDPR in your application documents (e.g., information on severely disabled status, religious affiliation, or health data), the processing is additionally based on External: Article 9 paragraph 2 point (b) GDPRin conjunction with § 26 paragraph 3 BDSG, to fulfill our legal obligations under labor law and social security law.
  • Recipients: Your data is reviewed after receipt in our human resources department. Suitable applications are forwarded internally to the respective department heads and, in the further selection process, to the management. At hyceon, basically only those persons have access to your data who strictly need it for the proper course of the application process.
  • Storage Period: In the event of a rejection, your applicant data is automatically deleted after four months (calculated from the time of rejection) to defend us against any lawsuits under the General Equal Treatment Act (AGG). In the event of recruitment, we transfer your application documents to our personnel information system and your personnel file.

10. Data Subject Rights

As a person affected by data processing, you are entitled to extensive rights under the GDPR, which you can assert against us at any time informally (e.g., by email to info@ttsp-hwp.de):

  • Right of Access (Art. 15 GDPR): You have the right to request information about the data stored about you at any time, informally and without stating reasons. This also includes information about their origin, recipients, and the purpose of storage.
  • Right to Rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate or the completion of incomplete personal data concerning you immediately.
  • Right to Erasure / “Right to be Forgotten” (Art. 17 GDPR): You can request the erasure of your personal data stored by us, provided that processing is not mandatory for exercising the right to freedom of expression, fulfilling a legal obligation, or asserting legal claims.
  • Right to Restriction of Processing (Art. 18 GDPR): You have the right to request the restriction of processing of your data if you dispute the accuracy of the data, the processing is unlawful, we no longer need the data but you need it to assert legal claims, or you have lodged an objection according to Art. 21 GDPR.
  • Right to Data Portability (Art. 20 GDPR): You have the right to have data that we process automatically based on your consent or a contract transferred to you or another controller in a common, machine-readable format.
  • Right to Withdraw Consent (Art. 7 Para. 3 GDPR): If you have given us consent to data processing (e.g., in the cookie banner or for event registrations), you can withdraw it at any time with effect for the future. The legality of the processing carried out until withdrawal remains unaffected.
  • Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR): Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence or at the headquarters of our company (The Hessian Commissioner for Data Protection and Freedom of Information, Wiesbaden), if you believe that the processing of your data violates the GDPR.

Right to Object (Art. 21 GDPR)

Case-Specific Right to Object

Insofar as we process your personal data to safeguard legitimate interests according to External: Article 6 paragraph 1 point (f) GDPR, you have the right, for reasons arising from your particular situation, to object to the processing of personal data concerning you at any time. We will then no longer process your data unless we can prove compelling legitimate reasons for the processing that outweigh your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.

Objection to Direct Marketing (Art. 21 Para. 2 GDPR)

If your personal data is processed to conduct direct marketing (e.g., via HubSpot), you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing. If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes.

11. No Automated Decision-Making

We point out that we do not use automated decision-making, including profiling, on our website according to External: Article 13 paragraph 2 point (f) GDPR.

Status of the Privacy Policy: 10th of August 2026