Controller and data protection officer

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

dg technologies GmbH Ober der Mühle 39 42699 Solingen Germany

Operational site:
Bodenseeallee 20, 78333 Stockach, Germany
Represented by the Managing Director Dr. Peter Möller
E-mail: info@dg-technologies.de
Website: www.dg-technologies.de

You can reach our data protection officer at:

Mr Frank Adelsbach Data Elements GmbH & Co. KG Klever Str. 27-29 40477 Düsseldorf Germany

General information on data processing

Scope. As a rule we process personal data of our users only to the extent necessary to provide a functional website and our content and services, or where you have given your consent.

Legal bases. Where we obtain consent, Art. 6 (1) (a) GDPR is the legal basis. Where processing is necessary for the performance of a contract or for pre-contractual measures, it is based on Art. 6 (1) (b) GDPR. Where it is necessary to comply with a legal obligation, it is based on Art. 6 (1) (c) GDPR. Where it is necessary to safeguard legitimate interests, it is based on Art. 6 (1) (f) GDPR. Where information is stored on or read from your terminal equipment, Section 25 of the German Digital Services Data Protection Act (TDDDG) applies in addition.

Retention. We delete personal data as soon as the purpose of processing ceases to apply and no statutory retention obligations conflict with deletion. Retention periods for individual processing activities are stated in the sections below.

Recipients and processors. We use external service providers who process personal data on our behalf, in particular for hosting, web analytics and consent management. We have concluded data processing agreements with these providers pursuant to Art. 28 GDPR. The specific providers are named with the respective processing activity.

Transfers to third countries. For some of the services listed below, processing in the United States cannot be ruled out. The basis is the European Commission’s adequacy decision on the EU-US Data Privacy Framework of 10.07.2023, provided the respective provider is certified under it, supplemented by the standard contractual clauses pursuant to Art. 46 (2) (c) GDPR. We point out that US authorities may access such data under certain conditions and that a level of protection fully equivalent to European standards cannot be guaranteed in every case. [PRÜFEN] For each provider used, check before publication whether the DPF certification is currently listed.

Hosting and server log files

This website is hosted by STRATO GmbH, Otto-Ostrowski-Strasse 7, 10249 Berlin, Germany. The provider processes the data arising when the website is accessed on our behalf, on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Each time the site is accessed, the system automatically records the following data: the IP address or host name of the requesting device, the date and time of access, the file or page requested, the volume of data transferred, the HTTP status code, the browser and system information transmitted in the user agent header, and the previously visited page transmitted in the referrer header.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technical delivery of the website, in ensuring its operation and in defending against attacks. No evaluation for marketing purposes takes place.

Access logs are available to us for a period of six weeks and are deleted by the hosting provider thereafter. Error logs cover the last five days. In addition, the hosting provider states that it stores access data for a maximum of seven days for its own security purposes, in order to detect and defend against attacks.

Consent management with Cookiebot

We use the consent management service Cookiebot provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.

Cookiebot displays a consent banner on your first visit, blocks services requiring consent until you have made your choice, and documents that choice. In doing so it processes your IP address in truncated form, the time and content of your consent, information about your browser and device, and a randomly generated identifier, and stores this in a cookie on your device.

The legal basis is Art. 6 (1) (c) GDPR in conjunction with our obligation to demonstrate consent under Art. 7 (1) GDPR, as well as Art. 6 (1) (f) GDPR. Storing the consent cookie is strictly necessary within the meaning of Section 25 (2) no. 2 TDDDG and therefore does not itself require consent.

Your consent is stored for 12 months.

Cookies and cookie declaration

Cookies are small text files stored on your device. We distinguish between strictly necessary cookies that enable the operation of the website, such as storing your language setting and managing your session, and cookies requiring consent that serve reach measurement and analysis of usage behaviour.

We use strictly necessary cookies on the basis of Art. 6 (1) (f) GDPR and Section 25 (2) no. 2 TDDDG. All other cookies are only used with your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG.

You can delete cookies or restrict their storage in your browser settings. If cookies are disabled, individual functions of the website may be limited.

Google Tag Manager and Google Analytics 4

We use Google Tag Manager and Google Analytics 4 provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool for managing website tags. It does not set cookies itself and does not collect personal data, but it enables other tags to be triggered which in turn collect data.

Google Analytics 4 produces statistics on the use of our website. Among other things it processes a randomly assigned user identifier, the truncated IP address, the pages viewed, time spent on the site, approximate location at regional level, the device and browser used, and the source of the visit. Google processes this data on our behalf. Transfer to Google LLC in the United States cannot be ruled out, the notes in Section II apply.

The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. We use Google Consent Mode. Without your consent no analytics cookies are set, and storage for advertising purposes is disabled by default.

The retention period for usage data in Google Analytics is currently unknown.

Microsoft Clarity

We use Microsoft Clarity provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

Clarity records your interaction with our website in order to improve usability. It captures, among other things, mouse movements, clicks, scrolling behaviour, page views and screen resolution. From this data Clarity produces session recordings and heatmaps. Entries in form fields are technically masked. Transfer to Microsoft Corporation in the United States cannot be ruled out, the notes in Section II apply.

The legal basis is exclusively your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. No recording takes place without consent.

Recordings are deleted after a certain currently unknown period.

You can withdraw your consent at any time via the cookie settings in the footer.

Internal note, do not publish: session recording constitutes systematic monitoring of usage behaviour. Before continuing to use it, document that a threshold assessment for a data protection impact assessment under Art. 35 GDPR comes to a negative result. In addition, verify that form field masking actually works on all forms, in particular on the contact form.

Google reCAPTCHA

To protect our forms against automated entries we use reCAPTCHA provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In doing so, your IP address, the time spent on the page, mouse and keyboard movements and information about your browser and device are transmitted to Google and evaluated there.

The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in protection against misuse and spam.

Contact by form and e-mail

You can send us a message using the contact form. We process the data you enter, currently first name, surname, company, e-mail address, message, as well as your IP address and the time of transmission at the moment you submit the form.

You can also contact us by e-mail. In that case we process the data you provide in your message.

The legal basis is Art. 6 (1) (b) GDPR where your enquiry is directed at concluding a contract, otherwise Art. 6 (1) (f) GDPR. Our legitimate interest lies in handling your enquiry.

We delete the data as soon as your enquiry has been dealt with conclusively and no statutory retention obligations conflict with deletion. Business correspondence is subject to the commercial and tax retention periods of six and ten years respectively.

Requests for material, events and marketing

If you request material such as sample kits or product documentation, register for an event or take part in a survey, we process the data you provide in order to fulfil your request. The legal basis is Art. 6 (1) (b) GDPR.

We send you information about our products and services on the basis of your consent pursuant to Art. 6 (1) (a) GDPR. We may send existing customers advertising for our own similar products on the basis of Art. 6 (1) (f) GDPR in conjunction with Section 7 (3) of the German Act Against Unfair Competition (UWG). Every advertising message points out how you can object.

We delete the data as soon as the purpose ceases to apply, in the case of marketing data at the latest three years after the last contact, unless a retention obligation conflicts with deletion.

LinkedIn company page

We operate a company page on LinkedIn. Our website only contains a link to that page, and no data is transmitted to LinkedIn unless you click the link. If you follow the link, the privacy provisions of LinkedIn Ireland Unlimited Company apply. For the processing of visitor statistics for our company page we are joint controllers together with LinkedIn. 

Your rights

You have the right of access to the data stored about you under Art. 15 GDPR, to rectification under Art. 16, to erasure under Art. 17, to restriction of processing under Art. 18 and to data portability under Art. 20 GDPR.

If you have consented to a processing activity, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

To exercise your rights, a message to info@dg-technologies.de or to our data protection officer is sufficient. We handle your request free of charge within one month. Only where there are reasonable doubts about your identity will we request additional information for identification, limited to what is necessary for that purpose.

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where we process your data for direct marketing, you have the right to object at any time and without giving reasons. Following such an objection we will no longer process your data for that purpose.

An objection can be submitted informally to info@dg-technologies.de.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.

The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestrasse 2-4 40213 Düsseldorf Germany

No automated decision-making

Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.

Data security

We take appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, destruction, unauthorised access and unauthorised alteration. The website is delivered over a TLS-encrypted connection, which you can recognise by the padlock symbol in the address bar of your browser. No system can offer complete protection against every conceivable attack.

Changes to this policy

We will adapt this privacy policy if the legal situation, our processing activities or the services we use change. The version published on this page with the stated version date applies.

Menu