Privacy Policy and Mandatory Privacy Information

1. Data Controller

The entity responsible for processing personal data is:

DATAflor AG
August-Spindler-Straße 20
37079 Göttingen

Phone: +49 (551) 50665-0
Fax: +49 (551) 50665-59
Email: info@dataflor.de

Represented by the Executive Board:
Christoph Honig and Matthias Gehrke

With this privacy notice, we inform you, in accordance with Articles 12 through 14 of the GDPR, about how we process personal data and what rights you have.

2. Data Protection Officer

If you have any questions regarding data protection, please contact our Data Protection Officer:

Mr. Thomas Werning
, werning.com GmbH
, Dieselstraße 12
, 32791 Lage

Phone: +49 5232 980-4700
Email: teamdatenschutz@werning.com

3. General Information on Data Processing

Personal data refers to any information that can be used to identify a natural person, either directly or indirectly. This includes, for example, names, contact information, contract and payment details, the content of communications, as well as usage and connection data.

We process personal data in particular on the following legal bases:

  • Article 6(1)(a) of the GDPR in the case of consent,
  • Article 6(1)(b) of the GDPR for the performance of a contract or precontractual measures,
  • Article 6(1)(c) of the GDPR to comply with legal obligations,
  • Article 6(1)(f) of the GDPR to protect legitimate interests.

Our legitimate interests include, in particular, the secure operation of our website, the processing of inquiries, the management of business relationships, direct marketing to the extent permitted by law, and the protection and enforcement of legal claims.

To the extent that information is stored on or retrieved from your device, the provisions of Section 25 of the TDDDG also apply.

4. Source and Recipients of the Data

We generally receive personal data directly from you, for example, when you submit an inquiry, place an order, register, apply for a job, or as part of a business relationship.

To the extent permitted, we may also obtain data from your employer, business partners, affiliated companies, public registries, or other publicly available sources.

Within DATAflor AG, only those departments that need your data to perform their duties have access to it.

In addition, the following recipients, in particular, may receive data:

  • Hosting and IT service providers,
  • providers of software, cloud, and communication services,
  • tax advisors, auditors, and attorneys,
  • banks and payment service providers,
  • Logistics, shipping, and printing service providers,
  • Event and training service providers,
  • government agencies and public authorities where there is a legal obligation to do so.

Data processors are contractually bound in accordance with Article 28 of the GDPR and process data only in accordance with our instructions.

5. Processing Outside the European Economic Area

For certain service providers, processing in countries outside the European Union or the European Economic Area cannot be ruled out.

Data will only be transferred if the requirements of Articles 44 et seq. of the GDPR are met, for example based on:

  • an adequacy decision by the European Commission,
  • a valid certification under the EU-U.S. Data Privacy Framework,
  • standard contractual clauses adopted by the European Commission,
  • other appropriate safeguards.

You may request further information regarding the safeguards in place from our Data Protection Officer.

6. Retention Period

We store personal data only for as long as is necessary for the respective purpose.

In addition, statutory retention periods apply. Depending on the type of document, these periods are typically six, eight, or ten years. Data may also be stored until the expiration of statutory limitation periods if this is necessary to assert, exercise, or defend legal claims.

Once the purpose no longer applies and the relevant periods have expired, the data is deleted or anonymized.

Data Processing on Our Website

7. Hosting and Server Log Files

Our website is hosted by:

Mittwald CM Service GmbH & Co. KG
Königsberger Straße 4–6
32339 Espelkamp

When you visit our website, technically necessary information is processed. This includes, in particular:

  • IP address,
  • date and time of access,
  • page or file accessed,
  • referrer URL,
  • browser and operating system,
  • hostname of the accessing device,
  • HTTP status code.

This processing is necessary to ensure the availability, stability, and security of the website, as well as to detect technical errors and unauthorized access.

The legal basis is Article 6(1)(f) of the GDPR. A contract for data processing has been entered into with Mittwald.

The server log data is deleted after the period required for technical and security reasons has elapsed. In the event of a specific security incident, it may be stored until the matter is fully resolved.

Retention period for server log files: 60 days

8. TYPO3

Our website is based on the TYPO3 content management system.

TYPO3 may use technically necessary cookies or similar technologies, for example, to manage sessions, security features, or page settings.

The use of technically necessary technologies is based on Section 25(2) of the TDDDG. The associated data processing is based on Article 6(1)(f) of the GDPR.

9. Cookies and Consent Management

We use technically necessary cookies, cookies that require consent, and similar technologies.

Technically necessary technologies are used to provide the website and its functions. They are used in accordance with Section 25(2) of the TDDDG.

Analytics and third-party services are only activated if you have given your prior consent. The legal bases are Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR.

Through our consent management system, we specifically store:

  • Your consent decision,
  • the date and time of the decision,
  • a pseudonymous identifier,
  • the version of the displayed settings.

This information is stored to ensure your decision is taken into account and to provide proof of it. You can change or revoke your selection at any time via the cookie settings.

Consent Manager used: Stefan Galinski Internet Services

10. Contact and Inquiry Forms

If you contact us via a form, by email, or by phone, we will process your information to handle your inquiry.

Depending on the form, the following data in particular may be collected:

  • Company,
  • Name,
  • Address,
  • phone number,
  • email address,
  • Industry,
  • Customer number,
  • Selected product or topic,
  • Content of the inquiry.

Required fields are marked accordingly. Without this information, we may not be able to process your inquiry.

For contractual or pre-contractual inquiries, processing is based on Article 6(1)(b) of the GDPR. We process general inquiries based on Article 6(1)(f) of the GDPR.

The data will be deleted once the inquiry is resolved and there are no retention obligations or legitimate interests in further storage.

Information provided via contact forms is not automatically used for newsletter distribution.

12. YouTube and Google Maps

We use YouTube to display videos and Google Maps to display locations and directions.

The respective providers are:

Google Ireland Limited
, Gordon House
, Barrow Street
, Dublin 4
, Ireland

The content is not loaded until you have consented to it or explicitly activated the respective content.

In particular, your IP address, browser and device information, the page you visited, and information about your interaction with the content may be transmitted to Google. If you are signed in to a Google account, Google may associate your use of the content with your account.

Processing is based on Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Processing in the United States cannot be ruled out. The safeguards described in the section on Google Analytics apply.

You can revoke your consent at any time via the cookie settings.

13. Encrypted Transmission

Our website uses an encrypted HTTPS connection. This protects data from unauthorized access by third parties during transmission.

Further Processing

14th Newsletter

Through our newsletter, we keep you informed about Dataflor, our products and services, events, training sessions, and technical topics.

We use the following service to send our newsletter:

CleverReach GmbH & Co. KG
Schafjückenweg 2
26180 Rastede
Germany

Subscription is handled via a double opt-in process. After you subscribe, you’ll receive an email asking you to confirm your subscription.

To verify your registration, we specifically store:

  • your email address,
  • the time of registration and confirmation,
  • the IP address used,
  • the content and version of the consent.

The legal basis for sending this information is your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2) of the German Unfair Competition Act (UWG). Provided that the requirements of Section 7(3) of the UWG are met, we may inform existing customers about our own similar products and services.

The registration is logged on the basis of Article 6(1)(f) of the GDPR. Our legitimate interest lies in verifying consent and protecting against the misuse of third-party email addresses.

We have a contract with CleverReach for data processing.

Performance Tracking

Our newsletters may contain technologies that track opens and clicks on links.

Personalized performance tracking is conducted only with your separate consent. The legal bases are Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

Consent to performance measurement is voluntary and not a prerequisite for receiving the newsletter. Without this consent, you will receive the newsletter without personalized tracking of opens and clicks.

You can revoke your consent at any time via the unsubscribe link in the newsletter. After you unsubscribe, we may store your email address in a block list to prevent further mailings and to be able to verify your prior consent.

15. Customers, Prospects, Suppliers, and Service Providers

We process data from customers and prospective customers, in particular for the following purposes:

  • Processing inquiries,
  • preparing quotes,
  • fulfilling contracts,
  • providing our products and services,
  • billing and payment processing,
  • Customer service and support,
  • Organizing events and training sessions,
  • direct marketing permitted by law.

We process data from suppliers and service providers in particular to initiate, conduct, and manage the respective business relationship.

The legal bases are, in particular, Article 6(1)(b), (c), and (f) of the GDPR.

Direct mail advertising and the maintenance of existing business contacts may be carried out on the basis of Article 6(1)(f) of the GDPR. Advertising via email is generally permitted only with consent or under the conditions set forth in Section 7(3) of the German Unfair Competition Act (UWG).

You may object to the processing of your data for direct marketing at any time:

Email: info@dataflor.de
Phone: +49 (551) 50665-0

16. Applications

When you submit an application, we process the following information in particular:

  • contact information,
  • cover letter and resume,
  • qualifications and professional history,
  • Certificates and supporting documents,
  • other information provided voluntarily.

Data processing is carried out for the purpose of conducting the application and selection process based on Section 26(1) of the Federal Data Protection Act (BDSG) in conjunction with Article 6(1)(b) of the General Data Protection Regulation (GDPR).

Access is granted only to persons involved in the selection process. Data will not be disclosed to other companies without your consent or unless there is another legal basis for doing so.

Following a rejection, the data is generally deleted six months after the conclusion of the application process, unless longer retention is necessary to defend against legal claims.

We will obtain separate consent for inclusion in a candidate pool.

Please send unsolicited applications to:

bewerbung@dataflor.de

Separate privacy notices apply to employees.

17. Shareholders and the Annual Shareholders' Meeting

We process personal data of shareholders and shareholder representatives in order to prepare for and conduct the Annual General Meeting and to enable shareholders to exercise their rights.

The legal basis is Article 6(1)(c) of the GDPR in conjunction with the provisions of stock corporation law.

To the extent provided for by law, data in the list of participants may be made available to other shareholders and shareholder representatives.

The data is stored in accordance with the statutory retention periods and subsequently deleted.

18. Social Networks

We maintain company profiles on Instagram, Facebook, and LinkedIn.

These profiles are used to communicate with customers, prospective customers, job applicants, and other users, as well as to provide information about Dataflor, our products, events, and job openings.

When you visit one of these pages, the respective platform provider processes personal data. The providers may create usage profiles and use data for analysis, market research, and advertising purposes. In doing so, processing may take place outside the European Union or the European Economic Area.

If you communicate with us via one of these platforms, we process your message—depending on its content—based on Article 6(1)(b) or (f) of the GDPR.

For more information on data processing and your options for managing your settings and exercising your right to object, please refer to the privacy policies of the respective platform providers.

The social media references on our website are embedded as external links. A connection to the respective provider is established only when you click on the link.

Your Rights

19. Rights of Data Subjects

Provided that the legal requirements are met, you have the right to:

  • Access to information pursuant to Art. 15 of the GDPR,
  • Rectification pursuant to Article 16 of the GDPR,
  • Erasure pursuant to Art. 17 of the GDPR,
  • Restriction of processing pursuant to Article 18 of the GDPR,
  • Data portability pursuant to Article 20 of the GDPR,
  • Objection pursuant to Article 21 of the GDPR,
  • Withdrawal of consent with future effect.

To exercise your rights, please contact:

info@dataflor.de

To the extent that we process data based on legitimate interests, you may object for reasons arising from your particular situation.

You may object to processing for direct marketing purposes at any time without providing a reason.

20. Right to File a Complaint

You have the right to file a complaint with a data protection supervisory authority.

The authority responsible for us is:

The State Data Protection Commissioner of Lower Saxony

You may also contact the data protection supervisory authority in your place of residence, your place of work, or the location of the alleged violation.

21. Duty to Provide Information and Automated Decisions

The provision of personal data may be required by law or by contract, or may be necessary for the conclusion or performance of a contract.

Without the required information, we may not be able to process a request, prepare a quote, or fulfill a contract.

As a general rule, we do not engage in fully automated decision-making, including profiling, as defined in Article 22 of the GDPR.

22. Update

We update this Privacy Policy when our data processing practices, the services we use, or legal requirements change.

As of July 30, 2026