Data protection
Privacy policy
This privacy policy explains the nature, scope, and purpose of processing personal data (referred to as "data" below) within our online services, associated websites, features, content, and external online presences, such as our social media profiles (collectively referred to as "online services"). Regarding the terms used, such as "processing" or "controller," we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Controller
Machbar GmbH
Obere Königsstraße 39
34117 Kassel
Telephone: +49 561 4759560
Fax: +49 561 47595629
Email: hello@machbar.eu
Website: www.machbar.com
Types of data processed:
– Inventory data (e.g., names, addresses).
– Contact data (e.g., email, telephone numbers).
– Content data (e.g., text input, photographs, videos).
– Usage data (e.g., visited websites, interest in content, access times).
– Meta/communication data (e.g., device information, IP addresses).
Categories of data subjects
Visitors and users of the online offering (hereinafter, these individuals are collectively referred to as 'users').
Purpose of processing
– Provision of the online offering, its functions, and content.
– Responding to contact enquiries and communicating with users.
– Security measures.
– Audience measurement/marketing.
Key definitions
'Personal data' means any information relating to an identified or identifiable natural person (hereinafter 'data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
'Processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.
'Pseudonymisation' means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
'Profiling' means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
'Controller' means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
'Processor' means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Relevant legal bases
In accordance with Article 13 of the GDPR, we inform you of the legal bases for our data processing. Unless otherwise stated in this privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfil our services, perform contractual measures, and respond to enquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfil our legal obligations is Article 6(1)(c) of the GDPR; and the legal basis for processing to protect our legitimate interests is Article 6(1)(f) of the GDPR. Should vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.
Security measures
In accordance with Article 32 of the GDPR, and taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access, input, disclosure, ensuring availability, and their separation. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the deletion of data, and responses to data breaches. We also consider the protection of personal data during the development and selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default (Article 25 of the GDPR).
Collaboration with processors and third parties
If, in the course of our processing, we disclose data to other individuals and companies (processors or third parties), transmit it to them, or otherwise grant them access to the data, this is only done on the basis of a legal permission (e.g., if the transmission of data to third parties, such as payment service providers, is necessary for contract fulfilment in accordance with Article 6(1)(b) of the GDPR), if you have consented, if a legal obligation requires it, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).
If we commission third parties to process data on the basis of a 'data processing agreement', this is done in accordance with Article 28 of the GDPR.
Transfers to third countries
We only transfer personal data to recipients in countries outside the European Union (EU) or European Economic Area (EEA), or use service providers with access from such countries, if the specific requirements of Art. 44 et seq. GDPR are met.
Data transfer to certain third countries may be permissible, particularly if an adequacy decision by the European Commission exists for the respective third country. For data transfers to certified companies in the USA, this may occur specifically on the basis of the EU-U.S. Data Privacy Framework. The European Commission issued a corresponding adequacy decision on 10 July 2023.
If no adequacy decision exists for a recipient country, or if the respective recipient does not fall under such a decision, we base the transfer of personal data on appropriate safeguards, particularly on the standard contractual clauses approved by the European Commission.
Please note that for data transfers to third countries, a level of data protection fully comparable to that in the EU cannot always be guaranteed, despite contractual and technical protective measures.
If we use services from providers based in third countries on our website, we will inform you about the details of the respective data transfer, the relevant legal basis, and the safeguards used in the respective sections of this privacy policy.
Rights of data subjects
You have the right to request confirmation as to whether data concerning you is being processed, and to access information about this data, as well as further information and a copy of the data, in accordance with Art. 15 GDPR.
In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
In accordance with Art. 17 GDPR, you have the right to request that data concerning you be deleted without undue delay, or alternatively, in accordance with Art. 18 GDPR, to request a restriction of the processing of the data.
You have the right to request to receive the data concerning you, which you have provided to us, in accordance with Art. 20 GDPR, and to request its transmission to other controllers.
Furthermore, in accordance with Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.
Right to withdraw consent
You have the right to withdraw consent given in accordance with Art. 7 para. 3 GDPR with effect for the future.
Right to object
You have the right to object to the future processing of your data at any time, in accordance with Article 21 of the GDPR. This objection can be made, in particular, against processing for direct marketing purposes.
Cookies and right to object to direct marketing
Cookies are small files stored on users' computers, containing various information. Their primary purpose is to store user data (or data about the device where the cookie is stored) during or after a visit to an online service. Temporary cookies, also known as 'session cookies' or 'transient cookies', are deleted once a user leaves an online service and closes their browser. These might store, for example, the contents of a shopping cart or a login status. 'Permanent' or 'persistent' cookies remain stored even after the browser is closed. This allows, for instance, the login status to be retained if users revisit the site after several days. Such cookies can also store user interests for audience measurement or marketing purposes. 'Third-party cookies' are offered by providers other than the controller operating the online service (otherwise, if they are only the controller's cookies, they are referred to as 'first-party cookies').
We may use temporary and permanent cookies, and we provide further details in our privacy policy. If users do not wish cookies to be stored on their computer, they are asked to deactivate the corresponding option in their browser's system settings. Stored cookies can be deleted in the browser's system settings. Disabling cookies may lead to functional limitations of this online service.
A general objection to the use of cookies for online marketing purposes, especially for tracking, can be declared via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, cookies can be prevented from being stored by disabling them in the browser settings. Please note that in this case, not all functions of this online service may be available.
Deletion of data
Data processed by us will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless explicitly stated otherwise in this privacy policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and no legal retention obligations prevent its deletion. If data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
According to legal requirements in Germany, retention periods are notably 10 years pursuant to §§ 147 para. 1 AO, 257 para. 1 no. 1 and 4, para. 4 HGB (books, records, management reports, booking vouchers, commercial books, tax-relevant documents, etc.) and 6 years pursuant to § 257 para. 1 no. 2 and 3, para. 4 HGB (commercial letters).
According to legal requirements in Austria, retention periods are notably 7 years pursuant to § 132 para. 1 BAO (accounting records, receipts/invoices, accounts, vouchers, business papers, statements of income and expenditure, etc.), 22 years in connection with real estate, and 10 years for documents related to electronically supplied services, telecommunications, broadcasting, and television services provided to non-entrepreneurs in EU member states for which the Mini One Stop Shop (MOSS) is used.
Business-related processing
Hosting and email delivery
Collection of access data and log files
Agency services
Provision of contractual services
Administration, financial accounting, office organisation, contact management
Business analysis and market research
Data protection information for applicants
Contacting us
Online presence on social media
We maintain an online presence on social networks and platforms to communicate with customers, interested parties, and users, and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing guidelines of their respective operators apply.
Unless otherwise stated in our privacy policy, we process user data when they communicate with us on social networks and platforms, for example, by posting on our online profiles or sending us messages.
Integration of third-party services and content
Within our online offering we embed third-party content and services — in particular videos.
This requires that the third-party providers receive the user’s IP address, as they cannot deliver the content to the browser without it. Fonts are loaded locally from our own server; we do not use Google Fonts or comparable font CDNs.
Embedded YouTube videos are loaded only after your consent via our cookie consent tool (Cookiebot, “Marketing” category). Until then, placeholders or links to YouTube are shown. Case study and contact videos hosted on our own infrastructure (AWS S3) are first-party content and do not require this consent. Legal basis for third-party embeds: Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent can be withdrawn at any time (see “View and change cookie consent”).
YouTube
We embed videos from the “YouTube” platform, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (potentially involving Google LLC, USA). Where possible, we use the more privacy-friendly host “youtube-nocookie.com”. Privacy policy: https://policies.google.com/privacy. Integration only occurs after your consent via Cookiebot (“Marketing” category).
Google Analytics (Statistics cookies)
If you consent to the “Statistics” category in Cookiebot, we use Google Analytics 4 (Google Ireland Limited / possibly Google LLC, USA), measurement ID G-9TMGCP7RTT, to collect pseudonymous usage statistics (e.g. page views, approximate region). Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG. Consent can be withdrawn at any time.
Leadinfo (Marketing cookies)
If you consent to the “Marketing” category in Cookiebot, we use Leadinfo (Leadinfo B.V., Netherlands, code LI-678682C108723) to recognise companies by IP address and attribute B2B interest. Cookies such as _li_id and _li_ses may be set. Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG. Withdraw consent at any time via Cookiebot.
Cloudflare Turnstile (booking form)
On the machbar.home page we use Cloudflare Turnstile (Cloudflare, Inc.) to protect against spam and automated submissions. Turnstile may transmit technically necessary data (including IP address and browser identifiers) to Cloudflare. This is not gated by Cookiebot; it is part of form protection. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention) or Art. 6(1)(b) when initiating a booking. Privacy policy: https://www.cloudflare.com/privacypolicy/.
View and change cookie consent
Office
Machbar GmbH
Königs-Galerie
Obere Königsstraße 39
34117 Kassel
© 2026 Machbar GmbH