Privacy policy
Privacy Notice in accordance with Art. 13 GDPR
Name and Address of the Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection laws is:
gate - Garchinger Technologie- und Gründerzentrum GmbH
Lichtenbergstr. 8
85748 Garching
Phone: +49 89 54840
Email: team@gategarching.com
General Information on Data Processing
Legal Basis for the Processing of Personal Data
In accordance with Art. 13 GDPR, we inform you of the legal basis for our data processing. If you have given consent to the processing of personal data, the legal basis is Art. 6(1)(a) GDPR and, where special categories of data are processed, Art. 9(2)(a) GDPR. If personal data is transferred to third countries based on explicit consent, Art. 49(1)(a) GDPR applies. If you consent to the storage of cookies or access to device information (e.g., via device fingerprinting), the processing is also based on § 25(1) TDDDG. Consent can be withdrawn at any time.
If the processing is necessary for the performance of a contract or pre-contractual measures, Art. 6(1)(b) GDPR applies. If processing is required to fulfill a legal obligation, the legal basis is Art. 6(1)(c) GDPR. Processing may also occur on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Data Deletion and Storage Duration
We adhere to the principles of data minimization (Art. 5(1)(c) GDPR) and storage limitation (Art. 5(1)(e) GDPR). Personal data is stored only as long as necessary to fulfill the purposes stated or as required by statutory retention periods. Once the purpose no longer applies or the retention period expires, the data is deleted promptly.
External Links
Our website may contain links to third-party websites or other websites under our responsibility. If you follow a link to a website outside our responsibility, please note that these websites have their own privacy policies, for which we assume no responsibility or liability. External links are visually distinguishable and can also be detected by cursor hover. Data is only transferred when you click such a link.
Please note that some links may lead to data transfers outside the European Economic Area, potentially exposing your data to foreign government access. If you want to avoid this, do not click such links.
Rights of Data Subjects
You have the following rights under the GDPR:
-
Right of access (Art. 15)
-
Right to rectification (Art. 16)
-
Right to erasure (Art. 17)
-
Right to restriction of processing (Art. 18)
-
Right to data portability (Art. 20)
-
Right to object (Art. 21)
-
Right to lodge a complaint with a supervisory authority
Right to Withdraw Consent:
You may withdraw any consent given at any time. The lawfulness of processing prior to withdrawal remains unaffected.
Right to Object:
If processing is based on Art. 6(1)(e) or (f) GDPR, you may object at any time on grounds relating to your particular situation. This includes profiling. If no overriding legitimate grounds exist, we will cease processing.
If processing is for direct marketing purposes, you may object at any time without stating a reason.
Processing of Applicant Data
If you submit a job application (by post, email, or form), we will process your personal data for the purpose of handling the application process.
The legal basis is Art. 6(1)(b) GDPR or, if consent is given, Art. 6(1)(a) GDPR and § 26 BDSG. If the application leads to an employment relationship, we continue to process the data under Art. 6(1)(b) GDPR. Otherwise, data is stored under Art. 6(1)(f) GDPR to defend against potential legal claims, e.g., discrimination.
With your consent, we may store your application in a talent pool for up to 2 years. You may withdraw this consent at any time.
Website Hosting
Our website is hosted by:
Host Europe GmbH
Hansestrasse 111
51149 Cologne, Germany
Server Location: France
When you visit our site, server log files are automatically collected, including:
-
IP address
-
Device used
-
Hostname
-
Operating system
-
Browser type and version
-
Requested file name and time
-
Data volume transferred
-
Access status
We do not combine this data with other sources.
Processing is based on Art. 6(1)(f) GDPR (legitimate interest in a secure and optimized website) or Art. 6(1)(b) GDPR if the website is used for contract purposes.
Contact via Contact Form, Email or Phone
When contacting us, your provided data is stored and processed for the purpose of handling your inquiry.
Legal bases:
-
Art. 6(1)(b) GDPR (contractual/pre-contractual inquiries)
-
Art. 6(1)(f) GDPR (legitimate interest in communication)
Data will be deleted once your request is fully addressed unless legal retention obligations prevent deletion.
Use of Cookies
Our website uses cookies, including session cookies and persistent cookies, as well as third-party cookies (e.g., for payment or video services).
Cookies enhance site functionality and analytics. Necessary cookies are processed under Art. 6(1)(f) GDPR. All others require your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG).
You can revoke your consent at any time.
Use of External Services
We use third-party services (e.g., for embedding media or analytics). Data may be transferred to these providers.
We obtain your prior consent where required under Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Analytics
To analyze user behavior, we process data to improve our site and marketing activities. This may include profiling, session tracking, heatmaps, etc.
Legal basis: your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). You can withdraw consent at any time.
Google Services
We use various Google services such as:
-
Google Analytics
-
Google APIs
-
Google Tag Manager
-
Google Fonts
-
Google Static
-
Google reCAPTCHA
-
Google Content Security Policy
All are provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to the USA under the EU-U.S. Data Privacy Framework.
More info: https://policies.google.com/privacy
Consent Management Tool
We use a consent management tool (Borlabs Cookie) to store your cookie and external service preferences. The tool is hosted locally.
Legal basis: Art. 6(1)(c) GDPR (legal obligation).
Content Delivery Network (CDN)
We use a CDN (e.g., Cloudflare) to ensure fast and secure website delivery. This involves processing your IP address and visit time.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website performance).
Audio and Video Integration
When you play embedded media (e.g., YouTube), your data (IP address, device info) is transferred to the provider. Only with your prior consent (Art. 6(1)(a) GDPR).
Webfonts
Webfonts are loaded from external providers (e.g., Google Fonts) to ensure uniform font display. Your IP address is transmitted when this happens.
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Web Security Tools
We use tools (e.g., Google reCAPTCHA, security headers) to protect against unauthorized access, spam, and attacks.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in site security).
Data Protection for Customers and Contractual Partners
We process personal data in accordance with Art. 13, 14 and 21 GDPR and the Federal Data Protection Act (BDSG):
Purposes and Legal Bases:
-
Art. 6(1)(b) GDPR: Contract fulfillment and pre-contractual measures
-
Art. 6(1)(c) GDPR: Legal obligations
-
Art. 6(1)(f) GDPR: Legitimate interests, e.g. marketing, legal enforcement
-
Art. 6(1)(a) GDPR: Consent (e.g., newsletter, whitepaper downloads)
Data Categories:
E.g., name, contact data, account info, company data, representative info.
Data Sources:
Directly from you during contact or contract initiation.
Recipients and Processors:
Data may be shared internally or with processors (e.g., CRM, web providers) under Art. 28 GDPR. No third-country transfer unless otherwise noted.
Retention Period:
We retain data only as long as necessary, in accordance with legal retention and limitation periods (2 to 30 years).
Your Rights:
You have the same rights as described earlier under the GDPR, including the right to withdraw consent and object to processing based on Art. 6(1)(f) GDPR.