Privacy Policy

1. Overview of Data Protection

1.1 General Information

This privacy policy provides an overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to personally identify you. For detailed information about data protection, please refer to our Data Protection Declaration included below.

1.2 Data Recording on This Website

Who is the responsible party for data processing on this website (i.e., the "controller")?
The data on this website is processed by the website operator, whose contact information can be found under the section "Information about the responsible party (referred to as the "controller" in the GDPR)" in this Privacy Policy.

How do we collect your data?

We collect your data through:

  • Data you provide: For example, data entered into our contact form.
  • Automatically collected data: Technical information (e.g., web browser, operating system, or time the site was accessed) recorded automatically upon visiting the website.

What do we use your data for?

  • To ensure error-free provision of the website.
  • To analyze user behavior and patterns for improving our services.

What rights do you have regarding your data?

  • Right to access, rectify, or erase your personal data.
  • Right to revoke your consent to data processing at any time.
  • Right to demand restriction of data processing under certain conditions.
  • Right to lodge a complaint with a supervisory authority.

Please contact us if you have any questions about data protection.

2. Hosting

This website is hosted by an external service provider. The personal data collected on this website is stored on the host's servers, which may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access, and other data generated through a website. The External hosting is carried out to fulfill contracts with potential and existing customers (Art. 6 para. 1 lit. b GDPR) and to provide a secure, fast, and efficient online service (Art. 6 para. 1 lit. f GDPR). If consent has been requested, processing is based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG for storage of cookies or access to device information. Consent can be revoked at any time.

Our host will only process your data as necessary to fulfill their service obligations and according to our instructions.

 

Host:
Nordcraft
Æblehaven 15A
2500 Valby
Denmark

Website:  https://nordcraft.com
You can find Nordcraft's privacy policy here:  https://nordcraft.com/privacy

3. General Information and Mandatory Information

3.1 Data Protection

We take the protection of your personal data seriously and handle it confidentially and in compliance with statutory data protection regulations and this Data Protection Declaration.

Whenever you use this website, a variety of personal information will be collected. Personal data comprises data that can be used to personally identify you. This Data Protection Declaration explains which data we collect as well as the purposes we use this data for. It also explains how, and for which purpose the information is collected.

We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.

3.2 Information about the responsible party (referred to as the "controller" in the GDPR)

The data processing controller on this website is:

ZenoDev GmbH
Hermann-Löns-Str. 2
93049 Regensburg
Email: team@zenodev.com

The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g., names, e-mail addresses, etc.).

3.3 Storage Duration

Unless a specific storage period is stated, your personal data will remain with us until the purpose for which it was collected no longer applies. Data will be deleted if you request it, revoke your consent, or the purpose for data storage lapses, unless we have other legally permissible reasons to store it (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.

3.4 Legal Basis for Data Processing

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9 (2)(a) GDPR, if special categories of data are processed according to Art. 9 (1) DSGVO. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49 (1)(a) GDPR. If you have consented to the storage of cookies or to the access to information in your end device (e.g., via device fingerprinting), the data processing is additionally based on § 25 (1) TTDSG. The consent can be revoked at any time. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, if your data is required for the fulfillment of a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Furthermore, the data processing may be carried out on the basis of our legitimate interest according to Art. 6(1)(f) GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.

3.5 Data Transfer to Non-EU Countries

Among other things, we use tools of companies domiciled in the United States or other from a data protection perspective non-secure non-EU countries. If these tools are active, your personal data may potentially be transferred to these non-EU countries and may be processed there. We must point out that in these countries, a data protection level that is comparable to that in the EU cannot be guaranteed. For instance, U.S. enterprises are under a mandate to release personal data to the security agencies and you as the data subject do not have any litigation options to defend yourself in court. Hence, it cannot be ruled out that U.S. agencies (e.g., the Secret Service) may process, analyze, and permanently archive your personal data for surveillance purposes. We have no control over these processing activities.

3.6 Revocation of Consent

A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.

3.7 Right to object to the collection of data in special cases and to direct advertising (Art. 21 GDPR)

IN THE EVENT THAT DATA ARE PROCESSED ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA BASED ON GROUNDS ARISING FROM YOUR UNIQUE SITUATION. THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. TO DETERMINE THE LEGAL BASIS, ON WHICH ANY PROCESSING OF DATA IS BASED, PLEASE CONSULT THIS DATA PROTECTION DECLARATION. IF YOU LOG AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE ARE IN A POSITION TO PRESENT COMPELLING PROTECTION WORTHY GROUNDS FOR THE PROCESSING OF YOUR DATA, THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR IF THE PURPOSE OF THE PROCESSING IS THE CLAIMING, EXERCISING OR DEFENCE OF LEGAL ENTITLEMENTS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS BEING PROCESSED IN ORDER TO ENGAGE IN DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR AFFECTED PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING AT ANY TIME. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS AFFILIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

3.8 Right to log a complaint with the competent supervisory agency

In the event of violations of the GDPR, data subjects are entitled to log a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred. The right to log a complaint is in effect regardless of any other administrative or court proceedings available as legal recourses.

3.9 Right to Data Portability

You have the right to demand that we hand over any data we automatically process on the basis of your consent or in order to fulfil a contract be handed over to you or a third party in a commonly used, machine readable format. If you should demand the direct transfer of the data to another controller, this will be done only if it is technically feasible.

3.10 Information about Rectification and Eradication of Data

Within the scope of the applicable statutory provisions, you have the right to at any time demand information about your archived personal data, their source and recipients as well as the purpose of the processing of your data. You may also have a right to have your data rectified or eradicated. If you have questions about this subject matter or any other questions about personal data, please do not hesitate to contact us at any time.

3.11 Right to Restrict Processing

You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. To do so, you may contact us at any time. The right to demand restriction of processing applies in the following cases:

  • In the event that you should dispute the correctness of your data archived by us, we will usually need some time to verify this claim. During the time that this investigation is ongoing, you have the right to demand that we restrict the processing of your personal data.
  • If the processing of your personal data was/is conducted in an unlawful manner, you have the option to demand the restriction of the processing of your data in lieu of demanding the eradication of this data.
  • If we do not need your personal data any longer and you need it to exercise, defend or claim legal entitlements, you have the right to demand the restriction of the processing of your personal data instead of its eradication.
  • If you have raised an objection pursuant to Art. 21(1) GDPR, your rights and our rights will have to be weighed against each other. As long as it has not been determined whose interests prevail, you have the right to demand a restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data with the exception of their archiving may be processed only subject to your consent or to claim, exercise or defend legal entitlements or to protect the rights of other natural persons or legal entities or for important public interest reasons cited by the European Union or a member state of the EU.

3.12 SSL and TLS Encryption

For security and to protect the transmission of confidential content, our website uses SSL or TLS encryption. An encrypted connection can be recognized by the browser's address line switching from "http://" to "https://" and the lock icon in the browser line.

4. Third-Party Services

Google Workspace for Appointment Booking

On our website, we offer you the opportunity to book appointments using Google Workspace services (Google Calendar). Google Workspace is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

When you book an appointment with us, your meeting data (such as your name, email address, and meeting details) will be processed through Google's infrastructure. This data processing is necessary to facilitate the scheduling and conduct of our meetings. Please note that your personal data may be transferred to and processed in the USA.

Google processes this data as our data processor in accordance with our Data Processing Agreement with Google. Google has implemented appropriate technical and organizational measures to protect your data and has committed to comply with GDPR requirements for data transfers to third countries through Standard Contractual Clauses (SCCs) and additional safeguards.

You can find Google's privacy policy here:  https://policies.google.com/privacy and information about Google Workspace privacy at: https://workspace.google.com/terms/user_features.html

By using our appointment booking service, you consent to the processing of your data through Google Workspace. This includes the sharing of necessary personal information such as your name and email address to facilitate the scheduling process. The legal basis for this processing is your consent (Art. 6(1)(a) GDPR) and our legitimate interest in providing efficient appointment scheduling services (Art. 6(1)(f) GDPR). If you have any questions about this service or data processing, please feel free to contact us.

Plausible Analytics

Our website uses Plausible Analytics ( https://plausible.io) for website analytics. Plausible is a privacy-focused analytics solution that helps us understand how our website is used, while fully respecting your privacy and complying with GDPR regulations.

Plausible collects basic usage data such as page views, visit duration, and referral sources. Important to note: We have configured Plausible to collect this data in a completely anonymous way. We do not collect or store any personal data such as IP addresses, and no cookies are used for tracking purposes. All data collected is aggregated and cannot be traced back to individual users.

The analytics data is processed by Plausible in accordance with their privacy policy and is used exclusively for our internal statistical analysis to improve our website and services. This data is not shared with third parties for marketing or advertising purposes.

Due to the privacy-first approach of Plausible and our specific configuration, no cookie consent banner is required according to GDPR regulations, as no personal data is processed and no cookies are set for tracking purposes. You can find more information about Plausible at https://plausible.io and their privacy policy at https://plausible.io/privacy.

5. Changes to the Privacy Policy

As we continue to evolve, we may occasionally update this GDPR privacy policy. We encourage our users to review this policy regularly to stay informed about our privacy practices. In this way, we avoid cluttering your inbox with emails that might go unread.

Contact Us

If you have any questions or concerns regarding our GDPR privacy policy or our data privacy practices, please reach out to us at team@zenodev.com.