Privacy Policy

Information on the processing of personal data

The protection of privacy in the context of the processing of personal data is of paramount importance. Upon visiting the website, the web server automatically logs the Internet Service Provider (ISP) IP address, the referring website, the visited pages, and the date and duration of the visit. This information is indispensable for the technical transmission of web pages and the secure operation of the server. This data is not analyzed on a personal basis.

If data is submitted via the contact form, it will be stored on the servers as part of the data backup process. The processing of personal data is carried out exclusively for the purposes delineated in this Privacy Notice and in accordance with prevailing data protection legislation.

Data Controller:

AKW A+V Protec Rail GmbH
Dienhof 26
92242 Hirschau
T: +49 9622 7039 0
F: +49 9622 7039 390
info@protec-bioreactor.com

Personal Data

Personal data is defined as information about an individual. This includes the client's name, address, and email address. Visitors to the website are not required to submit any personal data. In certain instances, we may require additional information, including your name and address, to facilitate the delivery of the requested service. 

This same policy is applicable in instances where informational materials are furnished upon request or in responses to inquiries. In such instances, the relevant parties will be duly informed. Additionally, the data stored is limited exclusively to information voluntarily or automatically provided by the user.

If a service is utilized, data is generally collected solely to the extent necessary for the provision of the service or the processing of the request. We may request that you provide additional information, the provision of which is voluntary. The processing of personal data is undertaken exclusively for the provision of services, the facilitation of communication, or the execution of business processes.

Contacting Us

If an individual elects to initiate communication with the company, whether by means of the designated contact form, electronic mail, telephone, or social media platform, the information furnished by the inquiring party is processed solely to the extent necessary to address the specific inquiry or request.

In accordance with the parameters of contractual or pre-contractual relationships, the organization is committed to addressing contact inquiries with the objective of providing services and overseeing the management of contractual relationships.

  • Types of data processed: Master data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact inquiries and communication.
  • Legal basis: Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

When you use our contact form, we process the information you provide—in particular, company name, title, first and last name, contact information, address, and the content of your message—to handle your inquiry. Required fields are marked as such; additional information is provided voluntarily.

Automatically Stored Data 

Server log files 

The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:

  • Date and time of the request
  • Name of the requested file
  • Page from which the file was requested
  • Access status (file transferred, file not found, etc.)
  • Web browser and operating system used
  • Full IP address of the requesting computer
  • Amount of data transferred

This data is not combined with other data sources. Processing is carried out in accordance with Article 6(1)(f) of the GDPR based on our legitimate interest in improving the stability and functionality of our website.   

For technical security reasons, to defend against attempted attacks on our web server, we store this data temporarily. It is not possible for us to identify individual persons based on this data. After no later than seven days, the data is anonymized by truncating the IP address at the domain level, so that it is no longer possible to establish a connection to the individual user. In anonymized form, the data is also processed for statistical purposes; no comparison with other data sets or disclosure to third parties, even in excerpts, takes place. 

Cloudflare

We use the “Cloudflare” service. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”). 

Cloudflare offers a globally distributed content delivery network with DNS. Technically, this means that data is routed between your browser and our website via Cloudflare’s network. This enables Cloudflare to analyze the data traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the internet. In doing so, Cloudflare may also use cookies or other technologies to recognize internet users, but these are used solely for the purpose described here.

The use of Cloudflare is based on our legitimate interest in providing our website as error-free and secure as possible (Art. 6(1)(f) GDPR).

Data transfers to the U.S. are based on the EU Commission’s Standard Contractual Clauses. Details can be found here:

https://www.cloudflare.com/privacypolicy/.

Further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.

We have entered into a data processing agreement (DPA) pursuant to Art. 28 GDPR with the provider. This is a contract required by data protection law that ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

jsDelivr CDN

This website uses a so-called “Content Delivery Network” (CDN) from jsDelivr.

A CDN is a service that enables the content of our online offering—particularly large media files such as graphics or scripts—to be delivered more quickly via regionally distributed servers connected via the Internet. User data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of the CDN.

For this purpose, the browser you are using must establish a connection to the CDN’s servers. As a result, the CDN becomes aware that our website has been accessed via your IP address.

This use is based on our legitimate interests, namely the interest in the secure and efficient provision, analysis, and optimization of our online offering pursuant to Art. 6(1)(f) of the GDPR.

For more information, please refer to jsDelivr’s privacy policy: www.jsdelivr.com/privacy-policy-jsdelivr-net/

Cookies

When you visit our website, we may store information on your computer in the form of cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a string of characters that allows websites and servers to associate the specific web browser in which the cookie was stored. This enables the visited websites and servers to distinguish the individual browser of the data subject from other web browsers that contain different cookies. A specific web browser can be recognized and identified via the unique cookie ID. 

By using session cookies, the controller can provide users of this website with a user-friendly service that would not be possible without setting cookies. Without consent, we use only technically necessary cookies on the legal basis of legitimate interest pursuant to Art. 6(1)(f) GDPR.

We use non-technically necessary cookies and comparable technologies for analysis, statistics, or the integration of external services exclusively with your consent. On your first visit, you can voluntarily consent to tracking or analysis via the cookie banner that appears. If applicable, your data may be shared with partners or third-party providers. These cookies are only stored if you explicitly consent to ; the legal basis is then your consent pursuant to Art. 6(1)(a) GDPR. 

You can change your cookie settings at any time here: Cookie Settings

Google Maps

This site uses the Google Maps mapping service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

To use the features of Google Maps, it is necessary to store your IP address. This

information is generally transmitted to a Google server in the U.S. and stored there. The provider of this site has no influence over this data transmission. When Google Maps is activated, Google may use Google Web Fonts to ensure consistent font display. When you access Google Maps, your browser loads the required web fonts into its cache to display text and fonts correctly.

Processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be revoked at any time.

Data transfers to the U.S. are based on the EU Commission’s Standard Contractual Clauses.

Details can be found here:

privacy.google.com/businesses/gdprcontrollerterms/ and

https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

In addition, Google is certified under the Data Privacy Framework Program and thus meets the requirements for secure data transfer in accordance with the EU Commission’s Adequacy Decision for the United States.

For more information on how user data is handled, please refer to Google’s Privacy Policy: https://policies.google.com/privacy?hl=de.

Google Analytics

This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. 

Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the site, operating systems used, and the user’s origin. This data is aggregated into a user ID and assigned to the website visitor’s respective device.

Furthermore, we can use Google Analytics to track your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data sets and employs machine learning technologies in data analysis. 

Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google regarding the use of this website is generally transmitted to a Google server in the United States and stored there. The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent may be revoked at any time. 

Data transfer to the United States is based on the EU Commission’s Standard Contractual Clauses. Details can be found here: privacy.google.com/businesses/controllerterms/mccs/.

Google Fonts

This website uses Google Web Fonts to ensure consistent display of certain fonts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google).

When you visit this website, your browser loads the required fonts directly from Google’s servers to display them correctly on your device. In doing so, your browser establishes a connection to Google’s servers. As a result, Google becomes aware that this website has been accessed via your IP address. According to Google, no cookies are stored when the fonts are provided.

If consent has been requested, processing is carried out exclusively based on Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting). Consent may be revoked at any time.

Data may be transferred to third countries, to the United States. Google uses the EU Commission’s Standard Contractual Clauses for this purpose. Details can be found here: policies.google.com/privacy/frameworks

Further information on Google Fonts can be found at: developers.google.com/fonts/faq Google’s privacy policy can be found at: policies.google.com/privacy

Security

We have implemented technical and administrative security measures to protect your personal data against loss, destruction, manipulation, and unauthorized access. All our employees and service providers working on our behalf are bound by applicable data protection laws.

Whenever we collect and process personal data, it is encrypted before being transmitted. This means that your data cannot be misused by third parties. Our security measures are subject to a continuous improvement process, and our privacy policies are regularly updated. Please ensure that you have the most recent version.

What data is processed, and from what sources does this data originate?

We process personal data that we receive from you when you contact us, use our website, initiate or execute a contract, or based on your consent.

Personal data includes:

  • For prospects, customers, suppliers, and other business partners

e.g., first and last name, company name, job title, address, contact information (email address, phone number), contract and communication data, and, if applicable, bank details.

  • For contacts at companies or institutions

e.g., name, position, company, business contact information, and information required for the collaboration.

  • For job applicants

e.g., first and last name, address, contact information (email address, phone number), application documents, resume, references, and other information provided during the application process.

  • For visitors to our website

e.g., IP address, date and time of access, pages/files accessed, browser type and operating system used, as well as technical log data.

In addition, we process—to the extent necessary in individual cases—further personal data, in particular:

  • Information regarding the nature and content of inquiries, offers, orders, or business relationships,
  • correspondence data and other details you provide to us in the course of communication,
  • technical data from electronic interactions with our website or IT systems,
  • Information regarding the documentation of consent granted.

The data generally comes from you or is collected automatically by our IT systems or technical service providers when you visit our website, to the extent that this is technically necessary.

3. For what purposes and on what legal basis is the data processed?

We process your personal data in accordance with the provisions of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).

  • To fulfill contractual or pre-contractual obligations (Art. 6(1)(b) GDPR)
    Processing is carried out to handle inquiries, prepare offers, implement pre-contractual measures, and manage existing contractual and business relationships.
  • To fulfill legal obligations (Art. 6(1)(c) GDPR)
    Personal data is also processed to the extent necessary to fulfill legal obligations, particularly those arising from tax, commercial, or other statutory retention and documentation requirements.
  • To protect legitimate interests (Art. 6(1)(f) GDPR)
    Where necessary, we process personal data to protect our legitimate interests or the interests of third parties. 
    This applies to:
  • the secure and reliable provision of our website,
  • IT security and technical administration,
  • communication with prospective customers, customers, suppliers, and business partners,
  • internal organization and business administration,
  • the assertion, exercise, or defense of legal claims.
  • Based on your consent (Art. 6(1)(a) GDPR)
    To the extent that you have given us your consent, we process your personal data exclusively for the purposes specified in each case, e.g., for optional website features, the integration of certain third-party services, or other processing operations requiring consent.

You may revoke your consent at any time with future effect.

Who receives my data?

If we engage a service provider for data processing, we remain responsible for the protection of your data. All data processors are contractually obligated to treat your data confidentially and to process it only within the scope of providing the service. The data processors we engage receive your data to the extent that they need it to fulfill their respective services. These include, for example, IT service providers, hosting providers, technical support providers and other processors engaged for the operation and security of our systems.

In the event of a legal obligation or in the context of legal proceedings, government agencies, courts, and external auditors may be recipients of your data.

In addition, insurance companies, banks, credit bureaus, and service providers may be recipients of your data for the purpose of contract initiation and fulfillment.

How long will my data be stored?

We process your data until the business relationship ends or until the applicable statutory retention periods expire (such as those under the German Commercial Code, the German Fiscal Code, or the Working Hours Act); furthermore, until the resolution of any legal disputes in which the data is required as evidence.

Is personal data transferred to a third country?

To the extent that individual services transfer personal data to third countries, particularly the United States, we provide separate information on this in the respective sections of this Privacy Policy.

The transfer takes place exclusively based on appropriate safeguards pursuant to Art. 44 et seq. of the GDPR, in particular based on adequacy decisions or standard contractual clauses of the European Commission.

What data protection rights do I have?

You have the right at any time to access, correct, delete, or restrict the processing of your stored data, the right to object to processing, as well as the right to data portability and the right to lodge a complaint in accordance with the requirements of data protection law.

Right of access:

You may request information from us regarding whether and to what extent we process your data.

Right to rectification:

If we process your data that is incomplete or inaccurate, you may request that we correct or complete it at any time.

Right to erasure:

You may request that we erase your data if we are processing it unlawfully or if the processing disproportionately interferes with your legitimate interests. Please note that there may be reasons preventing immediate erasure, e.g., in the case of legally mandated retention obligations.

Regardless of whether you exercise your right to erasure, we will erase your data immediately and completely, provided that no contractual or legal retention obligations prevent this.

Right to restriction of processing:

You may request that we restrict the processing of your data if

- you contest the accuracy of the data, for a period that allows us to verify the accuracy of the data.

- the processing of the data is unlawful, but you oppose erasure and instead request a restriction on the use of the data,

- we no longer need the data for the intended purpose, but you still need it to assert or defend legal claims, or

- you have objected to the processing of the data.

Right to data portability:

You may request that we provide you with the data you have provided to us in a structured, commonly used, and machine-readable format, and that you may transmit this data to another controller without hindrance from us, provided that

- we process this data based on your revocable consent or to fulfill a contract between us, and

- his processing is carried out using automated means.

If technically feasible, you may request that we transfer your data directly to another controller.

Right to object:

If we process your data based on a legitimate interest, you may object to this data processing at any time; this would also apply to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims. You may object to the processing of your data for direct marketing purposes at any time without providing a reason. 

Right to lodge a complaint:

If you believe that we are violating German or European data protection law in the processing of your data, we ask that you contact us so that we can clarify any questions. You also have the right, of course, to contact the supervisory authority responsible for you, the respective State Office for Data Protection Supervision.

If you wish to exercise any of the rights with us, please contact our Data Protection Officer. In case of doubt, we may request additional information to verify your identity.

Am I required to provide data?

The processing of your data is necessary for the conclusion or fulfillment of the contract you have entered with us. If you do not provide us with this data, we will generally have to refuse to conclude the contract or will no longer be able to perform an existing contract and will consequently have to terminate it. However, you are not obligated to grant consent to data processing about data that is not relevant to the fulfillment of the contract or not required by law.

Changes to this Privacy Policy

We reserve the right to amend our privacy policy, if necessary, due to new technologies. Please ensure that you have the most recent version. If fundamental changes are made to this privacy policy, we will announce them on our website.

All interested parties and visitors to our website can contact us regarding data protection issues at:

Projekt 29 GmbH & Co. KG
Ostengasse 14
93047 Regensburg

Tel.: 0941 2986930
Fax: 0941 29869316
Email: anfrage@projekt29.de
Website: www.projekt29.de