Privacy Policy
1. Introduction
Protecting your personal data is our top priority. This privacy policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as "data") in connection with our online offering. This includes the associated website, its functions and content, as well as external online presences such as social media profiles (hereinafter collectively referred to as the "online offering"). Your personal data is treated confidentially and processed strictly in accordance with statutory data protection regulations and the provisions of this privacy policy.
General Information
This privacy policy provides you with a comprehensive overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to identify you personally. For detailed information on data protection, please refer to this complete privacy policy.
Controller
Data processing on this website is carried out by the website operator. The contact details of the controller can be found in the "Controller" section of this privacy policy.
Collection of Your Data
Personal data is collected, on the one hand, when you actively provide it, for example by filling out a contact form. Other data is collected automatically, or after your consent, when you visit the website through the controller's IT systems. This primarily concerns technical data (e.g., internet browser, operating system, or time of page access). This data collection occurs automatically as soon as you enter the website.
Use of Your Data
Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior in order to optimize the offering and tailor it to your needs.
Data Transfer to External Parties
In the course of the controller's business activities, it may be necessary to transfer personal data to external parties. This transfer takes place exclusively under certain conditions: when the disclosure is necessary for the fulfillment of a contract, when there is a legal obligation, for example to tax authorities, when a legitimate interest exists in accordance with Art. 6(1)(f) GDPR, or when another legal basis permits the data transfer. When external service providers are used for data processing, personal data is disclosed exclusively on the basis of a valid data processing agreement in accordance with Art. 28 GDPR. If data is processed jointly with other parties, a joint controllership agreement is concluded in accordance with Art. 26 GDPR.
Withdrawal of Consent to Data Processing
Certain data processing operations can only take place with your express consent. This consent can be withdrawn at any time. The lawfulness of the data processing carried out up to the time of withdrawal remains unaffected by the withdrawal.
Right to Object to Specific Data Processing and Advertising Measures (Art. 21 GDPR)
If the processing of your personal data is based on Art. 6(1)(e) or (f) GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions. The specific legal basis for the data processing can be found in this privacy policy. In the event of an objection, the controller will no longer process your personal data unless compelling legitimate grounds can be demonstrated that outweigh your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims (objection pursuant to Art. 21(1) GDPR).
If your personal data is used for direct marketing purposes, you have the right to object to this processing at any time. This also applies to profiling insofar as it is related to direct marketing. Following your objection, the controller will no longer use your personal data for these advertising purposes (objection pursuant to Art. 21(2) GDPR).
Rights under the General Data Protection Regulation
You have the right to lodge a complaint with a competent supervisory authority in the event of violations of the GDPR. This right may in particular be exercised in the member state of your habitual residence, place of work, or the place of the alleged violation. This is without prejudice to any other administrative or judicial remedy.
Personal data that is processed automatically on the basis of consent or for the fulfillment of a contract may be requested in a structured, commonly used, and machine-readable format. Upon request, this data may also be transmitted directly to another controller, insofar as this is technically feasible.
Every data subject has the right to obtain, free of charge, information about their stored personal data, its origin, recipients, and the purpose of the data processing. Furthermore, there is a right to rectification or erasure of this data, insofar as legal provisions permit. For further questions or concerns regarding personal data, you may contact the controller at any time.
You have the right to request the restriction of the processing of personal data if the accuracy of the data is disputed and verification is pending. Restriction of processing may also be requested instead of erasure in the case of unlawful processing. Furthermore, restriction may be requested if the data is no longer needed but is required for the assertion, exercise, or defense of legal claims. In the event of an objection to processing pursuant to Art. 21(1) GDPR, the right to restriction also applies until it has been clarified whose interests prevail.
If the processing of personal data has been restricted, such data may, apart from being stored, only be processed with the consent of the data subject, or for the assertion, exercise, or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the EU or a member state.
2. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Ampmotion Advisory
Owner: Fabian Krohn Address: Majakowskiring 73, 13156 Berlin Website: www.ampmotion.de Email: info@ampmotion.de
3. Processors
We work with various processors who process data on our behalf. These service providers are contractually obligated to treat the data confidentially and to use it exclusively within the scope of the respective service. In addition, there are cases in which responsibility for data processing is shared jointly with other parties. In such cases, responsibilities are transparently defined and documented to ensure compliance with data protection requirements.
4. Definitions
To ensure the transparency of this privacy policy and make it understandable for everyone, this policy primarily uses terms that are also defined in the General Data Protection Regulation (GDPR). The complete legal definitions can be found in Art. 4 GDPR. The most important terms relevant to this privacy policy are explained below:
Personal data: This includes all information relating to an identified or identifiable natural person (hereinafter "data subject"). A person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
Processing: This term encompasses any operation or set of operations performed on personal data, whether or not by automated means. This may include the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of data.
Controller: This is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor: A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Consent: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Website: The website refers to the entire online offering made available by the controller under a specific URL. This includes all content, information, functions, and services published by the controller that are made accessible to users via this URL. The website serves as a digital platform for providing information, services, and interaction between the controller and users.
Device: A device is an electronic device capable of accessing the internet and loading web pages. This includes, among others, computers, laptops, tablets, and smartphones.
These definitions help you better understand this privacy policy and the meaning of the terms used.
5. Hosting
This website is hosted on the servers of an external service provider to ensure reliable and secure use of this online offering.
Data processing by the hosting provider is carried out in accordance with Art. 6(1)(f) GDPR, as the controller has a legitimate interest in providing a stable and secure website. Should it be necessary to obtain the user's consent (for example, for the use of certain cookies or tracking technologies), the data processing is based on the user's consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TTDSG). You may withdraw your consent at any time with effect for the future.
The hosting provider is:
Squarespace House Ship Street Great Dublin 8 Ireland D08 N12C
Details on data processing and data protection can be found in the hosting provider's privacy policy, available here: https://de.squarespace.com/datenschutz
6. Legal Bases for Data Processing
The processing of your personal data is based on the General Data Protection Regulation (GDPR) as well as other relevant statutory provisions. Depending on the purpose of the data processing, different legal bases apply.
If you have consented to the processing of your personal data, this processing is based on your consent pursuant to Art. 6(1)(a) GDPR. This applies in particular to the processing of special categories of personal data pursuant to Art. 9(2)(a) GDPR, as well as to the transfer of personal data to third countries pursuant to Art. 49(1)(a) GDPR. Your consent may be withdrawn at any time.
The processing of your data may be necessary for the performance of a contract or the implementation of pre-contractual measures, in which case it is based on Art. 6(1)(b) GDPR. In addition, processing may be required to comply with legal obligations, in which case it is carried out in accordance with Art. 6(1)(c) GDPR.
In certain cases, processing takes place to safeguard the legitimate interests of the controller or a third party, provided that your interests or fundamental rights and freedoms do not override those interests. This processing is based on Art. 6(1)(f) GDPR.
For certain processing operations, national regulations may also apply, such as Section 25 TTDSG regarding the storage of cookies or access to information on your device. The applicable legal bases are explained in detail in the specific sections of this privacy policy.
7. Data Transfer to Unsafe Third Countries and Non-DPF-Certified US Companies
If tools from companies based in third countries with an inadequate level of data protection are used on this website, or if US tools are used whose providers are not certified under the EU-US Data Privacy Framework (DPF), your personal data may be transferred to and processed in these countries. Please note that an inadequate level of data protection cannot guarantee a level of protection comparable to that of the EU. In principle, no level of data protection comparable to that of the EU is guaranteed for the US as an unsafe third country. A transfer of data to the US is therefore only permissible if the recipient either holds a certification under the "EU-US Data Privacy Framework" (DPF) or has appropriate additional safeguards in place. Detailed information on possible transfers to third countries, including data recipients, can be found in this privacy policy.
8. Retention Period
Unless a more specific retention period is stated in this privacy policy, personal data remains with the controller until the purpose for the data processing no longer applies. If a legitimate request for erasure is made or consent to data processing is withdrawn, the relevant data will be deleted, provided there are no other legally permissible reasons for retaining the personal data (e.g., statutory retention periods under tax or commercial law). In such cases, deletion takes place once these reasons cease to apply.
The controller stores personal data only for as long as necessary to fulfill the respective purposes for which the data was collected. This includes, in particular, the fulfillment of contractual obligations, compliance with statutory retention periods, and the safeguarding of the controller's legitimate interests, such as IT security and protection against misuse. If the processing of personal data is based on consent, storage continues until the data subject withdraws that consent. Such withdrawal is possible at any time with effect for the future. The data will then be deleted without delay, unless statutory retention obligations or other overriding legal grounds require further storage.
In summary, personal data is deleted once the purpose has been fulfilled or the legal basis for storage no longer applies, unless there continue to be legal obligations or legitimate interests justifying further storage.
9. Security Measures and Data Minimization
Comprehensive technical and organizational measures are taken to effectively protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. Care is taken to ensure that only the data absolutely necessary for the respective purpose is collected and processed. This data minimization strategy helps to significantly reduce the risk of misuse and unauthorized access. Security measures are continuously adapted to the state of the art to ensure a consistently high level of protection for your data.
10. SSL/TLS Encryption
To protect the security of your data during transmission, state-of-the-art encryption methods (e.g., SSL or TLS) are used via HTTPS. SSL (Secure Socket Layer) and TLS (Transport Layer Security) are protocols for encrypting data transmissions over the internet. This ensures that data exchanged between your browser and the server is protected from unauthorized access. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the lock symbol in your browser's address bar.
11. Storage of User Information in Log Files
Each time this website is accessed, general information is automatically collected that your browser transmits to the server. This information is stored in so-called log files and typically includes:
a) IP address of the requesting computer b) Date and time of access c) Name and URL of the file accessed d) Website from which access occurred (referrer URL) e) Browser used and user agent string f) Operating system g) Name of your access provider h) HTTP status code
This data is stored for security reasons, to ensure a smooth connection to the website, for the convenient use of the website, to evaluate system security and stability, and for other administrative purposes.
The legal basis for this data processing is Art. 6(1)(f) GDPR. The legitimate interest arises from the purposes of data collection stated above. Under no circumstances is the collected data used to draw conclusions about your identity. The stored data is anonymized or deleted unless there are statutory retention obligations.
12. Cookies
This website uses cookies. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit the site. Cookies do not cause any damage to your device and do not contain viruses, trojans, or other malicious software.
Information is stored in the cookie that arises in connection with the specific device used. However, this does not mean that the controller thereby gains direct knowledge of your identity.
The use of cookies serves, on the one hand, to make the use of our offering more pleasant for you. For this reason, the controller uses so-called session cookies to recognize that you have already visited individual pages of the website. These are automatically deleted when you leave the site.
In addition, to further optimize user-friendliness, the controller also uses temporary cookies that are stored on your device for a specific, defined period. If you visit the site again to use its services, it is automatically recognized that you have previously visited and which entries and settings you made, so that you do not have to enter them again.
Furthermore, the controller uses cookies to statistically record the use of the website and to evaluate it for the purpose of optimizing the offering for you. These cookies enable the controller to automatically recognize, upon a repeat visit, that you have previously visited the site. These cookies are automatically deleted after a specified period.
The data processed through cookies is necessary for the stated purposes of safeguarding the legitimate interests of the controller and third parties pursuant to Art. 6(1) sentence 1(f) GDPR.
Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer, or so that a notice always appears before a new cookie is created. Completely disabling cookies may, however, mean that you are unable to use all the functions of this website.
13. Cookie Consent Banner
This website uses a cookie consent banner to manage your consent to the use of cookies. The provider of this service is:
Squarespace Ireland Limited Squarespace House Ship Street Great Dublin 8 Ireland D08 N12C
Function and Purpose The cookie consent banner sets a technically necessary cookie to store your cookie preferences. This cookie does not process any personal data. It only stores the settings you selected upon entering the website, including:
a) Consent to or rejection of certain cookies b) Time of consent c) Duration for which the settings are stored d) Legal basis for the data processing
Data processing by the cookie consent banner is carried out in accordance with Art. 6(1)(f) GDPR. The controller's legitimate interest lies in ensuring lawful consent to the use of cookies. If consent was requested, the processing is based on Art. 6(1)(a) GDPR.
Retention Period and Deletion The stored data remains in place until you delete the cookies in your browser yourself or withdraw your consent. You can change your settings at any time in the cookie settings of this website.
14. Inquiries by Email or Telephone
You have the option of contacting the controller by email or telephone. The personal data transmitted in this process (e.g., name, email address, telephone number, and the inquiry itself) is processed and stored by the controller exclusively for the purpose of handling the inquiry and any follow-up questions.
The legal basis for this data processing is Art. 6(1)(b) GDPR, as the processing is necessary for the performance of a contract or the implementation of pre-contractual measures. If the processing is not related to a contract, it is carried out on the basis of Art. 6(1)(f) GDPR, as the controller has a legitimate interest in processing and responding to inquiries.
Sending to Existing Customers Without Consent
Newsletters are also sent to existing customers without their express consent under certain conditions. This is permissible pursuant to Art. 6(1)(f) GDPR if the following conditions are met:
a) Existing customer status: The customer provided their email address in connection with the sale of goods or services. b) Direct advertising for similar own products or services: The newsletter contains advertising only for similar products or services of the controller's own. c) Notice of right to object: The customer was clearly informed, both at the time the email address was collected and in every newsletter, that they may object to the use of their email address at any time, free of charge other than at the basic transmission rates. d) No objection from the customer: The customer has not objected to the use of their email address.
This method of sending newsletters is based on the controller's legitimate interest in informing existing customers about similar products or services and maintaining the business relationship. Data processing is carried out in accordance with Art. 6(1)(f) GDPR. Customers may of course object to the use of their email address for this purpose at any time. An informal notification by email to the controller, or use of the "unsubscribe" link in the respective newsletter, is sufficient for this purpose.
15. Social Media Plugins
This section informs you about the integration and use of social media on this website. This includes details on data processing and your rights in connection with the use of social media plugins and their functions.
This website uses features of the LinkedIn social network, operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. These plugins allow you to share and disseminate content from this website on your LinkedIn profile. LinkedIn plugins can be recognized by the LinkedIn logo or the "Share" button integrated into this website.
When you visit a page on this website that contains a LinkedIn plugin, your browser establishes a direct connection to LinkedIn's servers. The content of the plugin is transmitted directly by LinkedIn to your browser and integrated into the website. Through this integration, LinkedIn receives the information that your browser has accessed the corresponding page of this website, even if you do not have a LinkedIn account or are not currently logged into LinkedIn. This information (including your IP address) is transmitted directly by your browser to a LinkedIn server in the US and stored there.
If you are logged into LinkedIn, LinkedIn can directly link your visit to this website to your LinkedIn account. If you interact with the plugins, for example by clicking the "Share" button or leaving a comment, the corresponding information is likewise transmitted directly to a LinkedIn server and stored there. The information is also published on your LinkedIn profile and displayed to your LinkedIn contacts.
The use of LinkedIn plugins is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TTDSG, as consent is required for the use of cookies and other tracking technologies. Consent may be withdrawn at any time with effect for the future. To prevent LinkedIn from associating data collected via this website with your LinkedIn account, you must log out of LinkedIn before visiting this website.
The transfer of personal data to the US is based on the European Commission's Standard Contractual Clauses. Further information is available at: https://www.linkedin.com/legal/l/eu-sccs.
LinkedIn Ireland Unlimited Company is certified under the EU-US Data Privacy Framework (DPF), which ensures an adequate level of protection for the transfer of personal data from the EU to the US. Any company certified under the DPF commits to complying with these strict data protection standards. Further information on the EU-US DPF is available at: https://www.dataprivacyframework.gov/.
Further information on data processing and data use by LinkedIn, as well as on your related rights and settings options to protect your privacy, can be found in LinkedIn's privacy policy at: https://www.linkedin.com/legal/privacy-policy.
16. Conclusion of Contracts for Services or Digital Content
When contracts for services or digital content are concluded, the controller collects and processes your personal data in order to fulfill its contractual obligations. This data includes, in particular, your contact information such as name, address, and email address, as well as relevant information regarding the use of the services or digital content.
Your data is processed on various legal bases: pursuant to Art. 6(1)(b) GDPR, the controller processes your data to perform the contract and to carry out pre-contractual measures, such as the provision and use of the services. Processing is also carried out pursuant to Art. 6(1)(c) GDPR to fulfill legal obligations, including compliance with statutory retention requirements. In addition, processing takes place pursuant to Art. 6(1)(f) GDPR to safeguard legitimate interests, such as improving the services and ensuring IT security.
The data collected is used exclusively for the performance and fulfillment of contracts and is deleted after the end of the contractual relationship and the expiry of any statutory retention periods. Your data may be disclosed, in the context of contract performance, to third parties involved in providing the service, such as IT service providers. These third parties are contractually obligated to treat your data confidentially and to use it exclusively for the purpose of providing the service.
The controller ensures that your data is disclosed only to the extent necessary for the performance of the contract. No further transfer of data takes place unless you have expressly consented to such transfer. Your data will not be disclosed to third parties without your express consent, for example, for advertising purposes.