Skip to main content

Data protection

Privacy policy

This privacy policy explains the nature, scope, and purpose of processing personal data (referred to as "data" below) within our online services, associated websites, features, content, and external online presences, such as our social media profiles (collectively referred to as "online services"). Regarding the terms used, such as "processing" or "controller," we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Controller

Machbar GmbH

Obere Königsstraße 39

34117 Kassel

Telephone: +49 561 4759560

Fax: +49 561 47595629

Email: hello@machbar.eu

Website: www.machbar.com

Types of data processed:

– Inventory data (e.g., names, addresses).
– Contact data (e.g., email, telephone numbers).
– Content data (e.g., text input, photographs, videos).
– Usage data (e.g., visited websites, interest in content, access times).
– Meta/communication data (e.g., device information, IP addresses).

Categories of data subjects

Visitors and users of the online offering (hereinafter, these individuals are collectively referred to as 'users').

Purpose of processing

– Provision of the online offering, its functions, and content.
– Responding to contact enquiries and communicating with users.
– Security measures.
– Audience measurement/marketing.

Key definitions

'Personal data' means any information relating to an identified or identifiable natural person (hereinafter 'data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

'Processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.

'Pseudonymisation' means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

'Profiling' means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

'Controller' means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

'Processor' means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Relevant legal bases

In accordance with Article 13 of the GDPR, we inform you of the legal bases for our data processing. Unless otherwise stated in this privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfil our services, perform contractual measures, and respond to enquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfil our legal obligations is Article 6(1)(c) of the GDPR; and the legal basis for processing to protect our legitimate interests is Article 6(1)(f) of the GDPR. Should vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.

Security measures

In accordance with Article 32 of the GDPR, and taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access, input, disclosure, ensuring availability, and their separation. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the deletion of data, and responses to data breaches. We also consider the protection of personal data during the development and selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default (Article 25 of the GDPR).

Collaboration with processors and third parties

If, in the course of our processing, we disclose data to other individuals and companies (processors or third parties), transmit it to them, or otherwise grant them access to the data, this is only done on the basis of a legal permission (e.g., if the transmission of data to third parties, such as payment service providers, is necessary for contract fulfilment in accordance with Article 6(1)(b) of the GDPR), if you have consented, if a legal obligation requires it, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).

If we commission third parties to process data on the basis of a 'data processing agreement', this is done in accordance with Article 28 of the GDPR.

Transfers to third countries

We only transfer personal data to recipients in countries outside the European Union (EU) or European Economic Area (EEA), or use service providers with access from such countries, if the specific requirements of Art. 44 et seq. GDPR are met.

Data transfer to certain third countries may be permissible, particularly if an adequacy decision by the European Commission exists for the respective third country. For data transfers to certified companies in the USA, this may occur specifically on the basis of the EU-U.S. Data Privacy Framework. The European Commission issued a corresponding adequacy decision on 10 July 2023.

If no adequacy decision exists for a recipient country, or if the respective recipient does not fall under such a decision, we base the transfer of personal data on appropriate safeguards, particularly on the standard contractual clauses approved by the European Commission.

Please note that for data transfers to third countries, a level of data protection fully comparable to that in the EU cannot always be guaranteed, despite contractual and technical protective measures.

If we use services from providers based in third countries on our website, we will inform you about the details of the respective data transfer, the relevant legal basis, and the safeguards used in the respective sections of this privacy policy.

Rights of data subjects

You have the right to request confirmation as to whether data concerning you is being processed, and to access information about this data, as well as further information and a copy of the data, in accordance with Art. 15 GDPR.

In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.

In accordance with Art. 17 GDPR, you have the right to request that data concerning you be deleted without undue delay, or alternatively, in accordance with Art. 18 GDPR, to request a restriction of the processing of the data.

You have the right to request to receive the data concerning you, which you have provided to us, in accordance with Art. 20 GDPR, and to request its transmission to other controllers.

Furthermore, in accordance with Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.

Right to withdraw consent

You have the right to withdraw consent given in accordance with Art. 7 para. 3 GDPR with effect for the future.

Right to object

You have the right to object to the future processing of your data at any time, in accordance with Article 21 of the GDPR. This objection can be made, in particular, against processing for direct marketing purposes.

Cookies and right to object to direct marketing

Cookies are small files stored on users' computers, containing various information. Their primary purpose is to store user data (or data about the device where the cookie is stored) during or after a visit to an online service. Temporary cookies, also known as 'session cookies' or 'transient cookies', are deleted once a user leaves an online service and closes their browser. These might store, for example, the contents of a shopping cart or a login status. 'Permanent' or 'persistent' cookies remain stored even after the browser is closed. This allows, for instance, the login status to be retained if users revisit the site after several days. Such cookies can also store user interests for audience measurement or marketing purposes. 'Third-party cookies' are offered by providers other than the controller operating the online service (otherwise, if they are only the controller's cookies, they are referred to as 'first-party cookies').

We may use temporary and permanent cookies, and we provide further details in our privacy policy. If users do not wish cookies to be stored on their computer, they are asked to deactivate the corresponding option in their browser's system settings. Stored cookies can be deleted in the browser's system settings. Disabling cookies may lead to functional limitations of this online service.

A general objection to the use of cookies for online marketing purposes, especially for tracking, can be declared via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, cookies can be prevented from being stored by disabling them in the browser settings. Please note that in this case, not all functions of this online service may be available.

Deletion of data

Data processed by us will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless explicitly stated otherwise in this privacy policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and no legal retention obligations prevent its deletion. If data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

According to legal requirements in Germany, retention periods are notably 10 years pursuant to §§ 147 para. 1 AO, 257 para. 1 no. 1 and 4, para. 4 HGB (books, records, management reports, booking vouchers, commercial books, tax-relevant documents, etc.) and 6 years pursuant to § 257 para. 1 no. 2 and 3, para. 4 HGB (commercial letters).

According to legal requirements in Austria, retention periods are notably 7 years pursuant to § 132 para. 1 BAO (accounting records, receipts/invoices, accounts, vouchers, business papers, statements of income and expenditure, etc.), 22 years in connection with real estate, and 10 years for documents related to electronically supplied services, telecommunications, broadcasting, and television services provided to non-entrepreneurs in EU member states for which the Mini One Stop Shop (MOSS) is used.

Business-related processing

Additionally, we process contract data (e.g., contract subject, term, customer category) and payment data (e.g., bank details, payment history) from our customers, prospective clients, and business partners. This is for the provision of contractual services, customer care, marketing, advertising, and market research.

Hosting and email delivery

The hosting services we use provide infrastructure and platform services, computing capacity, storage and database services, email delivery, security, and technical maintenance. These are all essential for operating this online offering. We, or our hosting provider, process inventory data, contact data, content data, contract data, usage data, meta-data, and communication data from customers, prospective clients, and visitors to this online offering. This processing is based on our legitimate interests in the efficient and secure provision of this online offering, in accordance with Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement). We operate this website on our own infrastructure with a hosting provider in the European Union (Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland). When you visit the website, technically necessary server log files are processed (see below). A data processing agreement is in place with the provider.

Collection of access data and log files

We, or our hosting provider, collect data on every access to the server hosting this service (known as server log files). This is based on our legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR. The access data includes the name of the accessed webpage, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address, and the requesting provider. Log file information is stored for a maximum of 7 days for security reasons (e.g., to investigate abuse or fraudulent activities) and then deleted. Data requiring longer retention for evidentiary purposes is exempt from deletion until the final resolution of the incident.

Agency services

We process client data as part of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, campaign and process implementation/handling, server administration, data analysis/consulting, and training services. This involves processing inventory data (e.g., client master data such as names or addresses), contact data (e.g., email, phone numbers), content data (e.g., text entries, photographs, videos), contract data (e.g., subject matter, term), payment data (e.g., bank details, payment history), and usage and metadata (e.g., for evaluating and measuring the success of marketing activities). We generally do not process special categories of personal data, unless they are components of a commissioned processing task. Data subjects include our clients, prospective clients, their customers, users, website visitors, employees, and third parties. The purpose of processing is the provision of contractual services, invoicing, and customer service. The legal bases for processing are Art. 6 para. 1 lit. b GDPR (contractual services) and Art. 6 para. 1 lit. f GDPR (analysis, statistics, optimisation, security measures). We process data necessary for the establishment and fulfilment of contractual services and indicate where such provision is required. Disclosure to external parties only occurs if required within the scope of an order. When processing data provided to us within the scope of an order, we act in accordance with the client's instructions and the legal requirements for commissioned processing under Art. 28 GDPR, and we process the data solely for the purposes specified in the order. We delete data after the expiry of statutory warranty and similar obligations. The necessity of data retention is reviewed every three years; in the case of statutory archiving obligations, deletion occurs after their expiry (6 years, pursuant to § 257 para. 1 HGB; 10 years, pursuant to § 147 para. 1 AO). For data disclosed to us by the client within the scope of an order, we delete the data according to the order's specifications, generally after the order's completion.

Provision of contractual services

We process inventory data (e.g., names, addresses, and contact details of users) and contract data (e.g., services utilised, names of contact persons, payment information) to fulfil our contractual obligations and services in accordance with Art. 6 para. 1 lit. b GDPR. Entries marked as mandatory in online forms are required for contract conclusion. When using our online services, we store the IP address and the time of each user action. This storage is based on our legitimate interests, as well as the users' interest in protection against misuse and other unauthorised use. These data are generally not disclosed to third parties, unless it is necessary to pursue our claims or there is a legal obligation to do so under Art. 6 para. 1 lit. c GDPR. We process usage data (e.g., visited pages of our online offering, interest in our products) and content data (e.g., entries in contact forms or user profiles) for advertising purposes within a user profile, for example, to display product information to the user based on their previously utilised services. Data deletion occurs after the expiry of statutory warranty and similar obligations; the necessity of data retention is reviewed every three years. In the case of statutory archiving obligations, deletion occurs after their expiry. Information in any client account remains until its deletion.

Administration, financial accounting, office organisation, contact management

We process data for administrative tasks, operational organisation, financial accounting, and compliance with legal obligations, such as archiving. We process the same data as those processed for the provision of our contractual services. The legal bases for processing are Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR. Clients, prospective clients, business partners, and website visitors are affected by this processing. The purpose and our interest in processing lie in administration, financial accounting, office organisation, and data archiving – tasks that serve to maintain our business operations, fulfil our duties, and provide our services. Data deletion regarding contractual services and contractual communication corresponds to the information provided for those processing activities. We disclose or transmit data to the tax authorities, consultants (e.g., tax advisors or auditors), and other fee collection agencies and payment service providers. Furthermore, based on our business interests, we store information about suppliers, event organisers, and other business partners, for example, for future contact. These predominantly company-related data are generally stored permanently.

Business analysis and market research

To operate our business effectively, identify market trends, and understand customer and user needs, we analyse data related to business transactions, contracts, and enquiries. We process inventory, communication, contract, payment, usage, and metadata in accordance with Art. 6 para. 1 lit. f. GDPR. Affected individuals include customers, prospective clients, business partners, visitors, and users of our online services. These analyses are conducted for business evaluations, marketing, and market research. We may consider the profiles of registered users, including details of their purchasing activities. The analyses help us to improve user-friendliness, optimise our offerings, and enhance business efficiency. These analyses are for our internal use only and are not disclosed externally, unless they are anonymous analyses with aggregated values. If these analyses or profiles contain personal data, they are deleted or anonymised upon user termination, or otherwise two years after contract conclusion. Overall business analyses and general trend determinations are created anonymously wherever possible.

Data protection information for applicants

We process applicant data solely for the purpose and within the scope of the application process, in compliance with legal requirements. This processing fulfils our (pre-)contractual obligations under Art. 6 para. 1 lit. b. GDPR and Art. 6 para. 1 lit. f. GDPR, particularly if data processing becomes necessary for legal proceedings (in Germany, § 26 BDSG also applies). The application process requires applicants to provide us with their data. Necessary applicant data, if an online form is provided, will be indicated; otherwise, it can be found in the job descriptions. This generally includes personal details, postal and contact addresses, and application documents such as cover letter, CV, and references. Applicants may also voluntarily provide additional information. By submitting an application, applicants agree to the processing of their data for the purposes of the application process as described in this privacy policy. If special categories of personal data (Art. 9 para. 1 GDPR) are voluntarily provided during the application process, their processing also occurs under Art. 9 para. 2 lit. b GDPR (e.g., health data, such as severe disability status or ethnic origin). If such data is requested from applicants, its processing occurs under Art. 9 para. 2 lit. a GDPR (e.g., health data, if required for professional practice). Applicants may submit applications via an online form on our website, if available. Data is transmitted to us encrypted using state-of-the-art technology. Applicants may also submit applications via email. However, please note that emails are generally not encrypted, and applicants must ensure their own encryption. We cannot assume responsibility for the transmission path of the application between the sender and our server, and therefore recommend using an online form or postal delivery. Applicants can still send their application by post as an alternative to the online form and email. Data provided by successful applicants may be further processed by us for employment purposes. Otherwise, if an application is unsuccessful or withdrawn (which applicants are entitled to do at any time), the applicant's data will be deleted. Deletion occurs, subject to a legitimate withdrawal by the applicant, after six months. This allows us to answer any follow-up questions and fulfil our obligations under the Equal Treatment Act. Invoices for any travel expense reimbursement will be archived in accordance with tax regulations.

Contacting us

When you contact us (e.g., via contact form, email, telephone, or social media), your details are processed to handle your enquiry in accordance with Art. 6 para. 1 lit. b) GDPR. User details may be stored in a Customer Relationship Management (CRM) system or similar enquiry management system. We delete enquiries when they are no longer required, reviewing their necessity every two years. Statutory archiving obligations also apply.

Online presence on social media

We maintain an online presence on social networks and platforms to communicate with customers, interested parties, and users, and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing guidelines of their respective operators apply.

Unless otherwise stated in our privacy policy, we process user data when they communicate with us on social networks and platforms, for example, by posting on our online profiles or sending us messages.

Integration of third-party services and content

Within our online offering we embed third-party content and services — in particular videos.

This requires that the third-party providers receive the user’s IP address, as they cannot deliver the content to the browser without it. Fonts are loaded locally from our own server; we do not use Google Fonts or comparable font CDNs.

Embedded YouTube videos are loaded only after your consent via our cookie consent tool (Cookiebot, “Marketing” category). Until then, placeholders or links to YouTube are shown. Case study and contact videos hosted on our own infrastructure (AWS S3) are first-party content and do not require this consent. Legal basis for third-party embeds: Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent can be withdrawn at any time (see “View and change cookie consent”).

YouTube

We embed videos from the “YouTube” platform, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (potentially involving Google LLC, USA). Where possible, we use the more privacy-friendly host “youtube-nocookie.com”. Privacy policy: https://policies.google.com/privacy. Integration only occurs after your consent via Cookiebot (“Marketing” category).

Google Analytics (Statistics cookies)

If you consent to the “Statistics” category in Cookiebot, we use Google Analytics 4 (Google Ireland Limited / possibly Google LLC, USA), measurement ID G-9TMGCP7RTT, to collect pseudonymous usage statistics (e.g. page views, approximate region). Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG. Consent can be withdrawn at any time.

Leadinfo (Marketing cookies)

If you consent to the “Marketing” category in Cookiebot, we use Leadinfo (Leadinfo B.V., Netherlands, code LI-678682C108723) to recognise companies by IP address and attribute B2B interest. Cookies such as _li_id and _li_ses may be set. Legal basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG. Withdraw consent at any time via Cookiebot.

Cloudflare Turnstile (booking form)

On the machbar.home page we use Cloudflare Turnstile (Cloudflare, Inc.) to protect against spam and automated submissions. Turnstile may transmit technically necessary data (including IP address and browser identifiers) to Cloudflare. This is not gated by Cookiebot; it is part of form protection. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention) or Art. 6(1)(b) when initiating a booking. Privacy policy: https://www.cloudflare.com/privacypolicy/.

View and change cookie consent