Privacy Policy

Last updated: May 2026

We appreciate your interest in Techanics and our website. The protection of personal data is important to us. In this Privacy Policy, we explain which personal data is processed when you visit our website, contact us, subscribe to our newsletter, apply by email or through general contact channels, or use embedded content.

This Privacy Policy applies to the website of Techanics GmbH under the domain techanics.de and to the contact, information, application and newsletter functions provided there.


1. Controller

The controller responsible for the processing of personal data on this website is:

Techanics GmbH
Am Hoffeld 2
83703 Gmund am Tegernsee
Germany

Email: info [at] techanics.de

Commercial Register: HRB 289565
Register Court: Munich
VAT ID: DE365855756


2. Privacy requests

We have not appointed a data protection officer at this time.

Privacy-related requests may be sent at any time to the contact details stated above.


3. Key terms and legal bases

a) What personal data means

Personal data means any information relating to an identified or identifiable natural person. A person is identifiable if they can be identified directly or indirectly, for example by reference to a name, an identification number, location data, an online identifier or specific characteristics of their identity.

For the use of our website, this means that not only information actively entered into a form can be personal data. Technical data such as an IP address, access times or certain browser information may also be personal data if it can be linked to a person or if such a link cannot be ruled out.

b) Principle of processing

We process personal data only where this is necessary for a specific purpose and where a legal basis exists. Processing is carried out in particular in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

c) The main legal bases

Depending on the processing activity, we rely in particular on the following legal bases:

  • Article 6(1)(a) GDPR – Consent: This legal basis applies where you voluntarily consent to a specific processing activity, for example when subscribing to the newsletter or loading certain external content, where consent is obtained for this purpose.
  • Article 6(1)(b) GDPR – Contract or pre-contractual steps: This legal basis applies where processing is necessary for the performance of a contract or to take pre-contractual steps at your request, for example when you make an enquiry about our services or when a cooperation is being initiated.
  • Article 6(1)(c) GDPR – Legal obligation: This legal basis applies where we are required to process data in order to comply with legal obligations, for example commercial, tax or retention obligations.
  • Article 6(1)(f) GDPR – Legitimate interests: This legal basis applies where we have a legitimate interest in the processing and your interests or fundamental rights do not override that interest. This applies in particular to the secure and stable operation of our website, the handling of general enquiries, the internal organisation of our communication and the prevention of misuse.

d) Cookies, local storage and similar technologies

Where we store information on your device or access information stored on your device, for example by using cookies, local storage or similar technologies, we also comply with Section 25 TDDDG.

Technically necessary storage does not require consent where it is strictly necessary to provide a digital service expressly requested by you. Non-essential storage or access generally takes place only with consent.


4. Hosting, website operation and server log files

a) Hosting provider

Our website is operated using external server and hosting infrastructure. The hosting and server provider is in particular:

IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany

b) Access data processed

When our website is accessed, technically required data is processed so that the website can be displayed, operated securely and protected against misuse.

This may include in particular:

  • the page or file accessed
  • date and time of access
  • volume of data transferred
  • browser type and browser version
  • operating system used
  • referrer URL, where transmitted
  • IP address, where technically required
  • requesting provider
  • technical status and error messages

c) Purpose, legal basis and retention period

Processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and error-free operation of the website and the technical protection of our systems.

According to the current configuration, server-side access data is stored for seven days and anonymised. Longer storage takes place only where this is necessary in an individual case to investigate security-related incidents.


5. Technically necessary cookies and similar technologies

a) Technically necessary functions

According to the current status, our website uses only technically necessary cookies or similar technical storage technologies. These are used to provide basic website functions, process forms securely, enable technical settings or operate the website in a stable and secure manner.

b) No first-party analytics, advertising or tracking cookies

According to the current status, we do not use our own cookies for analytics, advertising or profiling purposes. In particular, we currently do not use Google Analytics, Google Ads conversion tracking, Meta Pixel or social media tracking plugins on our website.

c) Distinction from external content

Independently of this, the embedding of external content, in particular YouTube videos, may involve data processing by third-party providers. This is described separately in this Privacy Policy.


6. Contact by email or contact form

a) Data processed

If you contact us by email, contact form or a comparable contact option, we process the data you provide in order to handle your enquiry.

This may include in particular:

  • name
  • email address
  • telephone number, if provided
  • company, if provided
  • content of your message
  • time of the enquiry
  • technical transmission data

b) Purpose and legal basis

Depending on the content of the enquiry, processing is carried out on the basis of Article 6(1)(b) GDPR where the enquiry concerns a specific service request, an offer, cooperation or pre-contractual steps.

In all other cases, processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in reliably responding to enquiries and processing business communication in a traceable manner.

c) Technical processing in the form system

Contact enquiries are processed through the form system of our website. Depending on the technical configuration, form content may additionally be stored or logged in the backend of our website so that enquiries can be processed in a traceable manner and no message is lost.

d) Bot protection in the contact form with Cloudflare Turnstile

To protect our contact form at techanics.de/kontakt/ against automated entries, spam and misuse, we use Cloudflare Turnstile.

Provider:

Cloudflare, Inc.
101 Townsend St
San Francisco, CA 94107
USA

Cloudflare Turnstile performs an automatic background check when the contact form is accessed in order to determine whether the request is likely to come from a human or an automated system. No classic CAPTCHA is displayed.

For this purpose, the following data in particular may be processed and transmitted to Cloudflare:

  • IP address
  • browser information, in particular user agent, browser type and browser version
  • behavioural and interaction data in connection with the check
  • timestamp
  • verification token

Processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our contact form against spam, automated use and abusive enquiries and in ensuring the security of our website.

Where Cloudflare Turnstile is technically necessary to securely provide the contact form accessed by you, any access to information on your device is also based on Section 25(2) TDDDG.

According to Cloudflare, Turnstile does not set cookies. Personal data may also be processed in the USA. According to Cloudflare, transfers of data are based in particular on the EU Commission’s Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.

Further information can be found in Cloudflare’s privacy policy:

cloudflare.com/de-de/privacypolicy/

e) Forwarding of contact form emails through Brevo

Messages from the contact form are technically transmitted to us through Brevo. Brevo is used as an email delivery or transactional service in order to reliably forward form messages to the recipient addresses stored with us.

The data entered in the form as well as technical delivery and log data may be transmitted to Brevo and processed there on our behalf. This may include in particular:

  • name and contact details from the form
  • content of the form message
  • time of transmission
  • technical delivery information
  • where applicable, status information regarding successful or failed email delivery

The legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR, depending on the content of the enquiry. Our legitimate interest lies in the reliable technical delivery and handling of contact enquiries.

Brevo processes this data as a processor under Article 28 GDPR on the basis of corresponding data protection and data processing agreements.

Transmission through Brevo in connection with the contact form does not automatically result in a subscription to our newsletter. Newsletter subscription takes place only if you expressly consent to it.

f) Processing in Microsoft 365

Contact enquiries may be processed and stored internally in our Microsoft 365 environment. The data mentioned above may be processed in Microsoft services such as Outlook, Exchange, Teams, SharePoint or OneDrive where this is necessary to handle your enquiry.

g) Retention period

We store contact enquiries for as long as this is necessary to process them. If a business relationship results from the enquiry or if statutory retention obligations apply, we store the relevant data in accordance with the applicable statutory periods.


7. Microsoft 365

a) Provider

We use Microsoft 365 for internal communication, email processing, appointment coordination, file storage and collaboration.

Provider:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland

b) Data processed

If you communicate with us, your personal data may be processed in Microsoft 365. This applies in particular to:

  • emails
  • contact details
  • communication content
  • documents and attachments
  • calendar data
  • project-related information

c) Purpose and legal basis

Depending on the context, processing is carried out on the basis of Article 6(1)(b) GDPR, Article 6(1)(c) GDPR or Article 6(1)(f) GDPR. Our legitimate interest lies in secure, efficient and traceable business communication.

d) Contractual basis and data processing

We use Microsoft 365 on the basis of the applicable Microsoft contractual terms, including the relevant data protection and data processing terms.

Microsoft describes a so-called EU Data Boundary for its enterprise cloud services. According to Microsoft, customer data and personal data for Microsoft enterprise services such as Microsoft 365 are generally to be stored and processed within the EU or the EFTA. At the same time, Microsoft points out that certain limited transfers outside this EU Data Boundary may still be possible, for example for technical, security or support reasons.


8. Newsletter with Brevo

a) Provider

You can subscribe to our newsletter on our website. We use Brevo for sending, managing and measuring the success of our newsletter.

Provider:

Sendinblue SAS, trading as Brevo
9-17 rue Salneuve
75017 Paris
France

Brevo is a service for email marketing, newsletter delivery, contact management, campaign management and transactional email communication.

b) Data processed when subscribing to the newsletter

When you subscribe to our newsletter, we process in particular:

  • email address
  • name, if provided
  • company, if provided
  • time of subscription
  • IP address at the time of subscription, where technically recorded
  • confirmation in the double opt-in process
  • subscription channel used
  • consent text
  • newsletter subscription status
  • unsubscribe data

c) Double opt-in and consent

Subscription generally takes place through a double opt-in process. This means that after subscribing, you receive an email asking you to confirm your subscription. You will only be added to the newsletter mailing list after this confirmation. This allows us to document that the subscription actually came from the relevant email address.

The legal basis for sending the newsletter is your consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future, for example via the unsubscribe link in each newsletter or by sending us a message.

d) Processing by Brevo

Newsletter data is transmitted to Brevo and processed there on our behalf. Brevo processes personal data as a processor under Article 28 GDPR. We use Brevo on the basis of the corresponding data protection and data processing agreements.

According to Brevo, its databases are processed and stored on servers within the European Union.

e) Retention period

The data remains stored for as long as you are subscribed to the newsletter. After you unsubscribe, we store certain proof data where necessary in order to document a previously given consent and its withdrawal.

This storage is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in the legally secure documentation of consents and unsubscribes.


9. Newsletter performance measurement

a) Scope of performance measurement

Our newsletters contain performance measurement functions. This allows us to determine whether a newsletter has been opened and which links have been clicked. This may be done using so-called tracking pixels, personalised links or comparable technical procedures.

b) Data processed

In particular, the following data may be processed:

  • opening of a newsletter
  • time of opening
  • links clicked
  • time of click
  • technical information about the device or email program used
  • IP address, where technically recorded
  • assignment to the relevant newsletter campaign

c) Purpose and legal basis

We use this information to understand which content is relevant to our readers and to improve our newsletter technically and in terms of content.

The legal basis is your consent under Article 6(1)(a) GDPR. Where information is stored on or accessed from your device in this context, this also takes place on the basis of your consent under Section 25(1) TDDDG.

d) Withdrawal

You may withdraw this consent at any time with effect for the future by unsubscribing from the newsletter. The unsubscribe link can be found in each newsletter.

If you do not want performance measurement, you can unsubscribe from the newsletter. Depending on your email program, you may also be able to disable the automatic loading of external images; this may limit the measurement of openings.


10. Newsletter subscription via contact forms

a) Active subscription required

If, in the context of a contact form, you expressly select that you would also like to receive our newsletter, the data required for this purpose will be transmitted to Brevo and processed there in our newsletter mailing list.

Transmission to Brevo for the purpose of newsletter subscription takes place only if you actively select newsletter subscription or otherwise clearly consent to receiving the newsletter. A mere contact enquiry does not automatically result in a newsletter subscription.

b) Relationship to the contact enquiry

The legal basis for newsletter subscription is Article 6(1)(a) GDPR. The processing of the actual contact enquiry takes place independently of this on the basis of Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.

Contact enquiries and the related communication may also be processed and stored in our Microsoft 365 environment where this is necessary to handle your enquiry.


11. Embedded YouTube videos

a) Provider

Videos from YouTube may be embedded on our website.

Provider:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

YouTube is a service of the Google group.

b) Type of embedding

Where possible, we embed YouTube videos in a privacy-friendly manner. Where technically enabled, we use the enhanced privacy mode or no-cookie embedding through the domain youtube-nocookie.com. This mode is intended to reduce data processing by YouTube compared to a normal YouTube embed. However, it does not mean that no data is transmitted to YouTube or Google when a video is loaded or played.

YouTube videos on our website do not play automatically. According to our current technical configuration, however, a connection to YouTube or Google may already be established when a subpage with an embedded YouTube video is accessed. Data is transmitted to YouTube or Google at the latest when the video is activated or played.

c) Possible transfer of data to Google

Personal data may be transmitted to Google in this context. This may include in particular:

  • IP address
  • technical device and browser information
  • browser and language settings
  • subpage accessed
  • time of access
  • referrer information, where transmitted
  • information about interaction with the video
  • where applicable, information from your Google or YouTube account if you are logged in there

Technical requests may also be made to youtube-nocookie.com, youtube.com, googlevideo.com, ytimg.com or other Google services where this is necessary to provide the embedded video.

d) Legal basis and third-country reference

The processing of personal data in connection with the embedding of YouTube takes place for the clear presentation of video content and the user-friendly presentation of our website on the basis of Article 6(1)(f) GDPR.

Our legitimate interest lies in providing video content directly on our website and in presenting our services in an understandable manner.

Where YouTube stores information on your device or accesses information on your device, for example through cookies, local storage or similar technologies, consent under Section 25(1) TDDDG is generally required, unless the access is technically strictly necessary.

Google may also process data in countries outside the European Union or the European Economic Area. According to Google, suitable data protection safeguards are used for transfers to third countries.

e) Options for reducing data processing

You can reduce further data processing by YouTube by not actively playing embedded videos.

If you are logged into YouTube or Google, Google may associate your use of our website with your account. You can prevent this by logging out of your Google or YouTube account before visiting our website or before playing an embedded video.


12. External links to social media and third-party websites

a) Normal external links

Our website may contain links to external websites, for example to social media profiles, partner websites, Atlassian, YouTube or other third-party providers.

As long as these are only normal links, no personal data is transmitted to these providers by a social media plugin merely by visiting our website. Only when you click an external link do you leave our website. The respective provider is responsible for any subsequent data processing.

b) No social media plugins

According to the current status, we do not use social media plugins that automatically transmit data to social media providers when our website is loaded.


13. Applications by email or through general contact channels

a) No application portal on the website

We may publish information about vacancies, entry opportunities or applications on our website.

b) Processing when actively applying

If you apply to us by email or through a general contact channel, we process the application data transmitted by you in order to carry out the application process.

This may include in particular:

  • name and contact details
  • CV
  • certificates
  • cover letter
  • qualifications
  • communication content
  • other documents voluntarily submitted by you

c) Legal basis and retention period

The legal basis is Article 6(1)(b) GDPR in conjunction with Section 26 BDSG, insofar as the data is required for the decision on establishing an employment relationship.

Where you voluntarily provide us with additional information, processing may also be based on Article 6(1)(a) GDPR.

If no employment relationship is established, we generally delete application documents no later than six months after the conclusion of the application process, unless longer storage is required, for example to defend against legal claims. Longer storage in an applicant pool takes place only with your consent.


14. Cooperation with customers, prospects and business partners

a) Data processed

If you are in contact with us as a customer, prospect, service provider, partner or contact person of a company, we process personal data insofar as this is necessary for the initiation, performance or administration of the business relationship.

This may include:

  • name
  • business contact details
  • company and function
  • communication content
  • contract and project data
  • billing data
  • documentation data
  • support and service information

b) Purpose and legal basis

The legal basis is Article 6(1)(b) GDPR where processing is necessary for the performance of a contract or pre-contractual measures.

Where processing is necessary to comply with legal obligations, for example tax or commercial retention obligations, it is carried out on the basis of Article 6(1)(c) GDPR.

In other cases, processing is carried out on the basis of Article 6(1)(f) GDPR.

Our legitimate interest lies in the organisation, documentation and performance of our business activities.


15. Recipients of personal data

a) Disclosure only where required

We disclose personal data only where this is necessary for the relevant processing activity, where a legal obligation exists, where you have consented or where another legal basis permits disclosure.

b) Categories of recipients

Recipients may include in particular:

  • hosting and server providers, in particular IONOS
  • IT service providers and technical maintenance providers
  • Microsoft as provider of our communication and collaboration environment
  • Brevo as service provider for newsletters, transactional email communication and form forwarding
  • Cloudflare as provider of bot protection in the contact form
  • service providers for website operation, maintenance and technical support
  • tax advisors, legal advisors or authorities, where required
  • payment or billing service providers, where relevant in an individual case
  • Google or YouTube, where embedded YouTube videos are loaded

c) Processing on behalf

We enter into data processing agreements under Article 28 GDPR with service providers who process personal data on our behalf, where this is legally required.


16. Transfers to third countries

Personal data is transferred to countries outside the European Union or the European Economic Area only where a legal basis exists and suitable data protection safeguards are in place.

For individual service providers, in particular Google/YouTube, Microsoft or Cloudflare, processing outside the EU or EEA cannot be completely ruled out. In such cases, transfers are based in particular on adequacy decisions of the European Commission, Standard Contractual Clauses, additional safeguards or your consent, where required.

According to Cloudflare, transfers to the USA are based in particular on the EU Commission’s Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.


17. Retention period

a) Principle

We store personal data only for as long as it is necessary for the relevant purpose or statutory retention obligations apply.

b) Individual retention periods

In particular, the following applies:

  • Server log data: seven days, anonymised according to the current configuration.
  • Contact enquiries: for the duration of processing and thereafter as required.
  • Form and delivery data: to the extent necessary for technical delivery, traceability and handling of the enquiry.
  • Cloudflare Turnstile verification data: to the extent necessary for checking and preventing automated or abusive form access.
  • Business communication: in accordance with commercial and tax retention obligations, where relevant.
  • Newsletter data: until unsubscribed.
  • Proof data relating to newsletter consents: beyond that, to the extent necessary for legally secure documentation.
  • Application data: generally up to six months after completion of the application process, unless longer storage is required or agreed.

c) Deletion or anonymisation

When storage is no longer required, the data is deleted or anonymised.


18. Your rights

a) Rights under the GDPR

You have the following rights under the GDPR:

  • right of access under Article 15 GDPR
  • right to rectification under Article 16 GDPR
  • right to erasure under Article 17 GDPR
  • right to restriction of processing under Article 18 GDPR
  • right to data portability under Article 20 GDPR
  • right to object under Article 21 GDPR
  • right to withdraw consent under Article 7(3) GDPR
  • right to lodge a complaint with a supervisory authority under Article 77 GDPR

b) Withdrawal of consent

If you withdraw consent, the lawfulness of processing based on consent before its withdrawal remains unaffected.


19. Right to object under Article 21 GDPR

a) Objection where processing is based on legitimate interests

Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object to such processing at any time on grounds relating to your particular situation.

We will then no longer process the relevant data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.

b) Objection to direct marketing

Where personal data is processed for direct marketing purposes, you may object to such processing at any time. In this case, the data will no longer be used for direct marketing.


20. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection law.

For private-sector organisations in Bavaria, the competent authority is generally:

Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach
Germany

You may also contact any other competent data protection supervisory authority.


21. Security

We implement technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure. These measures include in particular access restrictions, encrypted transmission, role and permission concepts and organisational safeguards.

Our website uses TLS/SSL encryption. You can generally recognise an encrypted connection by “https” in the browser’s address bar.


22. No automated decision-making

We do not make decisions that are based solely on automated processing, including profiling, and that produce legal effects concerning you or similarly significantly affect you.


23. Changes to this Privacy Policy

We may update this Privacy Policy if our website, technical systems, services used or legal requirements change. The version published on this website at the relevant time applies.