Privacy Policy
Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy below.
Data Collection on This Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the legal notice (Impressum) of this website.
How do we collect your data?
Your data is collected when you provide it to us, for example by entering it into a contact form. Other data is collected automatically by our IT systems when you visit the website. This is primarily technical data (e.g. browser, operating system or time of the page request). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour, to the extent this is necessary and you have consented to this processing.
What rights do you have regarding your data?
You have the right to receive information free of charge about the origin, recipients and purpose of your stored personal data at any time. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
General Information and Mandatory Disclosures
Data Protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the internet (e.g. when communicating by e-mail) may have security gaps. Complete protection of data against access by third parties is not possible.
Responsible Party
The party responsible for data processing on this website is:
apollon GmbH+Co. KG
Maximilianstr. 104
75172 Pforzheim
Germany
Phone: +49 7231 941-123
E-mail: info@apollon.de
Website: www.apollon.de
Managing Directors: Norbert Weckerle, Tobias Marks
General Partner: apollon Verwaltungs-GmbH
VAT ID: DE297662610
Commercial Register: Mannheim Local Court, HRA 705979
Data Protection Officer
We have appointed an external data protection officer:
Georg Schütz
DEKRA
E-mail: datenschutz@apollon.de
You can contact our data protection officer directly with any questions about data protection and the exercise of your rights.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected.
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
Competent supervisory authority in Baden-Württemberg:
Landesbeauftragte für Datenschutz und Informationsfreiheit Baden-Württemberg (LfDI)
Postfach 10 29 32
70025 Stuttgart, Germany
Phone: +49 711 615541-0
Fax: +49 711 615541-15
E-mail: poststelle@lfdi.bwl.de
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, such as enquiries you send to us as the site operator, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Information, Correction and Deletion
Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction or deletion of this data. You can contact us at any time regarding this and other questions on the subject of personal data.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
Objection to Advertising E-mails
We hereby object to the use of contact data published within the scope of the legal notice obligation for the purpose of sending unsolicited advertising and information material. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited advertising, such as spam e-mails.
Data Collection on This Website
Cookies and Consent Management (Borlabs Cookie)
This website uses cookies. Cookies are small text files that your browser stores on your device. They allow us to recognise your browser on your next visit.
Some of the cookies we use are required for the website to function technically (so-called necessary cookies). These are stored automatically. All other cookies require your consent. This is managed by the consent management system Borlabs Cookie, which allows us and you to manage cookie consents and refusals.
Legal basis: Art. 6(1)(a) GDPR (consent)
Provider: Borlabs – Daniel Hüfner, Bischofstr. 16, 37293 Herleshausen, Germany
Data: cookie preferences, unique user ID (cookie ID), timestamp of consent
Storage period: The consent cookies (borlabs-cookie, borlabs-cookie-gcs) are stored for 60 days; after that, or when you change your preferences, you will be asked again.
Opt-out: You can change or withdraw your cookie settings at any time via the cookie banner or the cookie settings on this website.
Borlabs Cookie is software installed on our own server; no data is transmitted to the manufacturer. To document your consent (Art. 7(1) GDPR), we log the time, the settings chosen, the version of the cookie dialog and a random identifier in our website database; your IP address is not stored for this purpose.
Note on the TDDDG (German Telecommunications Digital Services Data Protection Act)
Insofar as cookies or comparable technologies that are not technically necessary are used on this website, this is done exclusively on the basis of your consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. You can withdraw your consent at any time via our consent tool. Technically necessary cookies are set on the basis of Section 25(2) TDDDG.
Server Log Files
The provider of the website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address
We do not directly assign this data to a specific person. According to the case law of the CJEU, IP addresses are considered personal data; a personal reference can therefore not be ruled out in principle. This data is not merged with other data sources. We reserve the right to check this data retrospectively if we become aware of specific indications of unlawful use.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technically error-free provision and security of the website)
Storage period: In accordance with current practice, such data is usually deleted after seven to 30 days.
Hosting: Hostinger, data centre in Germany
Contact and Demo Requests via Forms
When you contact us via a form on this website (e.g. contact request, demo request, download request, partner enquiry), we process the information you enter – usually name, company, e-mail address, telephone number and your message – to handle your request and for follow-up questions. The forms are operated with the software Gravity Forms installed on our server and our own submission function; the data is passed on to our customer relationship management system (see section “Pipedrive (Customer Relationship Management)”).
To prevent automated spam submissions, we check technical characteristics of the submission process (e.g. completion time, hidden check fields) and use the Cloudflare Turnstile service (see the section “Cloudflare Turnstile (Protection against Automated Submissions)”). No personal data beyond the information entered in the form is stored for this purpose.
If you have previously consented to marketing cookies, we record the origin of your visit together with your enquiry – source, medium, campaign, search term and ad (UTM parameters), advertising click identifiers such as “gclid”/“msclkid”, landing page, the page of the form, the referring website and the time of your first visit – and store this information as attributes of the enquiry in our CRM system, together with a note that your consent was given. This allows us to evaluate through which channels enquiries arise and to report the receipt and the subsequent qualification of the enquiry – only with the click identifier and the time, without transmitting your name or contact details – back to Google Ads or Microsoft Advertising (see the sections on Google Ads and Microsoft Advertising). Without consent, we only store the address of the landing page and of the form page without campaign parameters; click identifiers and campaign data are then neither stored nor reported back.
Legal basis: Art. 6(1)(b) GDPR (handling a pre-contractual enquiry), otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries and preventing misuse); for origin and campaign data Art. 6(1)(a) GDPR (consent via the cookie dialog, revocable at any time)
Storage period: We store enquiry data for as long as processing and a possible business initiation are ongoing and delete it as soon as the purpose no longer applies, at the latest after 24 months without further communication. Statutory retention obligations remain unaffected.
Cloudflare Turnstile (Protection against Automated Submissions)
Our forms are protected by Cloudflare Turnstile, a service of Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany (parent company: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA). Turnstile checks in the background whether a form entry originates from a human or from an automated program and thus replaces a classic captcha with image puzzles. The check is only loaded when you interact with a form.
In doing so, Cloudflare processes technical characteristics of your browser and device (e.g. browser version, screen resolution, language, behaviour of script execution) as well as your IP address and issues a short-lived verification token, which we verify server-side with Cloudflare when the form is submitted. Turnstile does not set cookies for recognition and does not create a user profile; we only receive the result of the check, which we note together with the enquiry.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing automated abuse and spam submissions and in the secure operation of the forms); insofar as information is read from your device, Section 25(2) No. 2 TDDDG (strictly necessary for the service you have requested)
Storage period: The verification token is valid for a few minutes; Cloudflare stores the data collected for the check only briefly in accordance with its terms.
Third-country transfer: Cloudflare may transfer data to Cloudflare, Inc. in the USA. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR); in addition, the EU Standard Contractual Clauses apply (Art. 46(2)(c) GDPR).
Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/
Pipedrive (Customer Relationship Management)
To manage enquiries, contacts and business relationships, we use the CRM system Pipedrive from Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia. There we store the information from your enquiries via forms and appointment bookings (name, company, contact details, content of the enquiry, origin of the visit if consent has been given) as well as the history of our communication. Pipedrive processes the data on our behalf on servers in the EU; a data processing agreement pursuant to Art. 28 GDPR is in place.
Legal basis: Art. 6(1)(b) GDPR (initiation and performance of contracts) and Art. 6(1)(f) GDPR (legitimate interest in efficient customer management)
Storage period: see section “Contact and Demo Requests via Forms”; we retain data on customers and contractual partners in accordance with commercial and tax law retention periods.
Pipedrive privacy policy: https://www.pipedrive.com/en/privacy
Enquiries via E-mail or Telephone
If you contact us by e-mail or telephone, your enquiry including all resulting personal data (name, enquiry) will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
Legal basis: Art. 6(1)(b) GDPR insofar as your enquiry relates to the performance of a contract or pre-contractual measures; otherwise Art. 6(1)(f) GDPR (legitimate interest in handling enquiries) or Art. 6(1)(a) GDPR (consent)
Storage period: Enquiry data is deleted as soon as it is no longer required for processing the enquiry. This is usually the case after three to six months, unless statutory retention obligations apply.
Newsletter (Pipedrive Campaigns)
If you would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and agree to receive the newsletter (double opt-in).
We use Pipedrive Campaigns, a service of Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia, to send the newsletter. Pipedrive processes your e-mail address and, if applicable, your name for the purpose of sending the newsletter.
Data processed: e-mail address, name (optional), opening and click behaviour
Legal basis: Art. 6(1)(a) GDPR (consent)
Storage period: Your data is stored for as long as you subscribe to the newsletter. After unsubscribing, your data is deleted.
Server location: Data is processed on servers in the EU (Estonia). No transfer to third countries takes place.
Opt-out: You can unsubscribe from the newsletter at any time via the unsubscribe link contained in every newsletter.
Pipedrive privacy policy: https://www.pipedrive.com/en/privacy
Analytics Tools and Advertising
Tag Management and Server-Side Tagging (Google Tag Manager on Our Own Server)
To manage the analytics and marketing services used on this website, we use Google Tag Manager from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager itself does not set cookies and does not collect personal data; it merely controls which services are loaded according to your decision in the cookie dialog. The container script is delivered from our own server; no data is transmitted to Google or other third parties before you give your consent.
The measurement data of the services you have approved (Google Analytics, Google Ads) is not sent directly from your browser to Google, but first to a server operated by us (“server-side tagging”, reachable at apollon.de and data.apollon.de, hosted on a server of Hostinger International Ltd. in Germany). There, the data is checked, automated accesses (bots) are filtered out and the data is then forwarded to the respective service. To monitor this server, we store – without personal reference – the time, type of request, page accessed, response status and device type; IP addresses and identifiers are not stored for this purpose.
As part of server-side tagging, cookies are set under our own domain after your consent (so-called first-party cookies): FPID and _ga (recognition of your browser for Google Analytics, up to 2 years), _gcl_au or _gcl_aw (attribution of ad clicks for Google Ads, 90 days), gtm_pageview_count (counting page views within a visit, 30 days) and apln_attr (origin of your visit – campaign, advertising click identifier, landing page, time of first visit – 90 days; only set if you consent to marketing cookies and deleted upon withdrawal).
We use Google Consent Mode: the Google services are only activated after your consent; without consent, no measurement data – not even anonymised signals – is transmitted to Google.
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent) for the controlled services and cookies; for the operation of the server-side tagging server and bot filtering Art. 6(1)(f) GDPR (legitimate interest in data-minimising, secure measurement)
Withdrawal: at any time via the cookie settings of this website
Google Analytics 4
After your consent, this website uses Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables us to statistically evaluate the use of our website (pages accessed, time spent, origin of the visit, device used, interactions such as downloads or submitted forms – without form contents).
The data is transmitted to Google via our own server (see section “Tag Management and Server-Side Tagging”). Google Analytics 4 does not store IP addresses; the IP address is only used for approximate location determination (country/region) and then discarded. The first-party cookies mentioned in the previous section are used to recognise your browser.
Data processed: pseudonymous browser identifier, page views, events (e.g. clicks, downloads, form submissions), approximate location, device and browser information, origin of the visit
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent)
Storage period: User and event data is deleted at Google after 14 months; aggregated reports contain no personal reference.
Third-country transfer: Google Ireland may transfer data to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR); in addition, the EU Standard Contractual Clauses apply (Art. 46(2)(c) GDPR).
Withdrawal: at any time via the cookie settings of this website
Google Ads (Conversion Tracking, Remarketing, Enhanced Conversions)
After your consent, we use Google Ads from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland to place ads in Google Search and measure their success.
Conversion tracking: If you reach our website via a Google ad, the click identifier of the ad (“gclid”) is stored in a first-party cookie (_gcl_aw/_gcl_au, 90 days). If you subsequently submit a form or book an appointment, this is reported to Google via our server as a conversion so that we can see which ads lead to enquiries. Google does not receive any information from the form.
Enhanced conversions: To be able to attribute conversions even if cookies are no longer available, we transmit the e-mail address and telephone number in hashed form (SHA-256) to Google when an enquiry is made. Google uses the hash exclusively for matching with signed-in Google accounts and deletes it afterwards; the plain data can only be inferred for values that are already known.
Remarketing: Google may also assign your browser to an audience in order to show you ads related to our products on other websites and in Google Search. We do not use ads based on special categories of personal data.
Subsequent reporting from the CRM: When an enquiry resulting from an ad is received by us, when we later classify it as qualified, or when it leads to a concrete proposal phase, we report each of these events – only with the click identifier, the time and a flat value, without name or contact details – back to Google Ads via a Google interface (Data Manager API) in order to align our ads with genuine interest. This only happens if you had consented to marketing cookies at the time of the enquiry.
Data processed: click identifier, time, type of conversion, pseudonymous browser identifier, hashed e-mail address/telephone number (only for enquiries), device and browser information
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent)
Storage period: cookies up to 90 days; conversion data at Google according to its terms, hashed contact data is deleted after matching.
Third-country transfer: Google Ireland may transfer data to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR); in addition, the EU Standard Contractual Clauses apply (Art. 46(2)(c) GDPR).
Withdrawal/opt-out: at any time via the cookie settings of this website; you can additionally deactivate personalised advertising at https://adssettings.google.com.
Microsoft Advertising (Bing Ads, Universal Event Tracking)
After your consent, we use Microsoft Advertising from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, to place ads in Bing Search and the Microsoft advertising network and to measure their success. For this purpose, Microsoft’s Universal Event Tracking (UET) is integrated. If you reach our website via a Microsoft ad, the click identifier (“msclkid”) is stored; page views and certain events (e.g. submitted enquiry, booked appointment) are reported to Microsoft so that we can see which ads lead to enquiries. We report the receipt of an enquiry resulting from an ad, its subsequent classification as qualified and the start of a proposal phase – only with the click identifier, the time and a flat value, without name or contact details – back to Microsoft Advertising via its interface; this only happens if you had consented to marketing cookies at the time of the enquiry. Microsoft may also assign your browser to an audience for remarketing ads.
Cookies: _uetsid (session, 1 day), _uetvid (recognition, 13 months), MUID (Microsoft domain, 13 months)
Data processed: click identifier, pseudonymous browser identifier, page views, events, device and browser information, IP address
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent)
Third-country transfer: Microsoft may transfer data to Microsoft Corporation in the USA; Microsoft is certified under the EU-US Data Privacy Framework (Art. 45 GDPR), and the EU Standard Contractual Clauses additionally apply.
Withdrawal/opt-out: at any time via the cookie settings of this website; you can additionally deactivate personalised advertising from Microsoft at https://account.microsoft.com/privacy/ad-settings.
Microsoft privacy statement: https://privacy.microsoft.com/en-gb/privacystatement
Microsoft Clarity (Heatmaps and Session Recording)
After your consent, this website uses Microsoft Clarity, an analytics service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft Clarity records user interactions such as mouse movements, clicks and scrolling to help us improve the user experience. The data is pseudonymised.
Data processed: user interactions, session replays, heatmaps, device and browser information, truncated IP addresses
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent)
Third-country transfer: The transfer of data to the USA is based on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the provider is certified accordingly, and additionally on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Opt-out: You can deactivate data collection by Microsoft Clarity by adjusting your cookie settings.
LinkedIn Insight Tag
After your consent, this website uses the LinkedIn Insight Tag, a tracking service of LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. The LinkedIn Insight Tag enables us to measure the success of our LinkedIn campaigns and to collect data for advertising purposes. This is done using cookies and similar tracking technologies.
Data processed: cookie IDs, user interactions, device and browser information, IP addresses
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent)
Third-country transfer: LinkedIn Ireland is part of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. The transfer of data to the USA is based on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the provider is certified accordingly, and additionally on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Opt-out: You can deactivate data collection by LinkedIn by adjusting your cookie settings or by managing the ad settings in your LinkedIn profile.
Company-Level Visit Analysis (VisitInfo)
We use a procedure developed by us called “VisitInfo” to evaluate whether visits to our website originate from the network of a company or another organisation. Collection and the essential processing take place on our own server infrastructure; for individual attribution queries we use the service provider named below. In doing so, we process personal data, in particular IP addresses and information on the use of our website. The procedure is not designed to identify individual visitors by name.
Basic analysis (legitimate interest): When you access our website, a script embedded by us sends a message to our server. This contains the IP address, the time, the address of the page accessed (cleaned, see below), information on the referring page and a random identifier valid only for this single page view. Cookies, local storage or browser fingerprinting are not used for this; no permanent visitor identifiers are created and no visitors are tracked across multiple websites. From the IP address, we determine whether the address range can be assigned to a company or organisation. Private, mobile and connections that cannot be reliably assigned are not included in the analysis and are deleted at an early stage. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in evaluating company-level interest in our content, identifying potentially interested business customers and preparing company-related sales outreach. We have documented the underlying balancing of interests.
Extended measurement (only with consent): We measure time spent, scroll depth and interaction events (file downloads, clicks on contact links, submission of expressly approved general contact forms – without form contents) exclusively if you have consented to the service “VisitInfo” (category Marketing) via our cookie dialog (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Application, complaint, whistleblower and other forms whose use could reveal particularly sensitive information are excluded from measurement. Consent is voluntary and can be withdrawn at any time with effect for the future via the cookie settings. The normal server log files required for delivery and security (see section “Server Log Files”) remain unaffected.
Data minimisation: URL parameters and URL fragments are removed before storage; only defined campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) are retained via a whitelist. Advertising click IDs and comparable unique identifiers are not stored; we only record which advertising network a visit came from. For external referring pages we store only the source domain, for internal referrals additionally a cleaned page path.
Company attribution and service provider: The assignment of the IP address to a company is first carried out using public network registry data stored locally on our servers as well as network and reverse DNS queries. If an assignment is not possible in this way, we transmit the IP address to Elaunira SARL, Antibes, France, operator of the “Ipregistry” service, which acts for us on the basis of the Data Processing Addendum integrated into its terms of use, including EU Standard Contractual Clauses. Queries are made via the European API endpoint. According to the provider’s published information, transmitted IP addresses may be logged for monitoring, alerting and internal reporting purposes for up to twelve months. The provider uses service providers, including providers based in the USA; the provider bases third-country transfers on EU Standard Contractual Clauses (overview: ipregistry.co/service-providers). You can request a copy of or further information on the safeguards used from us at the contact details given above.
Transfer to our sales CRM: Identified companies can be transferred by our employees to our customer relationship management system (Pipedrive, see the information on Pipedrive in this privacy policy): company name, company domain, publicly available business address and a summary of the company-level visit profile (topics visited, interest rating). We do not transfer names, e-mail addresses or other direct identifiers of individual visitors; an indirect personal reference cannot be completely ruled out for sole traders or very small organisations. The legal basis is Art. 6(1)(f) GDPR (documented balancing of interests). Advertising contact is only made if the additional legal requirements applicable to the respective communication channel are met. If we later research contact persons from public sources, this is a separate processing operation; the data subjects are informed in accordance with Art. 14 GDPR.
Storage period: In the event of a successful assignment, the full IP address is truncated immediately after completion of the assignment check (IPv4 to the /24 network, IPv6 to the /48 prefix); we also treat the truncated data as pseudonymised data. If a visit cannot be reliably assigned immediately, the full IP address is stored exclusively for necessary repeated assignment attempts and is completely deleted after completion of the check, at the latest after seven days. Detailed company-level visit data is stored for a maximum of six months; it is then deleted or aggregated into condensed company statistics without reference to individual visits. The temporary page view identifier is deleted at the latest together with the associated visit record.
Objection, opt-out and withdrawal: You may object at any time to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation; insofar as the processing serves direct marketing, at any time without giving reasons. The easiest way is to use our opt-out page at apollon.de/?visitinfo-optout: it deactivates VisitInfo completely for the browser currently in use (opt-out cookie, 400 days, used exclusively to store your decision). Companies and other organisations can additionally request a separate block of their network range via the contact details given above (only the truncated network range is stored). Consent given for the extended measurement can be withdrawn at any time via the cookie settings.
Plugins and External Services
YouTube
This website contains videos from YouTube, a video portal operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube videos are embedded on this website in privacy-enhanced mode. This means that YouTube does not store any information about visitors unless they actively play the video.
Data processed: IP address, video viewing data (only when the video is played), cookie IDs
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Section 25(1) TDDDG
Third-country transfer: The transfer of data to the USA is based on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the provider is certified accordingly, and additionally on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Opt-out: You can prevent data collection by YouTube by adjusting your cookie settings or by deactivating YouTube tracking in your Google account.
Google Maps
This website uses the Google Maps API to display interactive maps. Google Maps is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When using Google Maps, data is transmitted to Google, including your IP address and possibly your location.
Data processed: IP address, location data (if permitted), zoom and pan actions, cookie IDs
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Section 25(1) TDDDG
Third-country transfer: The transfer of data to the USA is based on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the provider is certified accordingly, and additionally on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Google privacy policy: https://policies.google.com/privacy
Calendly (Appointment Booking)
On some pages you can book a meeting with us directly via Calendly, a service of Calendly LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA. The booking form is only loaded when you actively open it or have approved it via the cookie dialog. When you make a booking, Calendly processes the data you enter (name, e-mail address, company and telephone number if applicable, selected appointment, time zone) and transmits it to us; we transfer it to our CRM (see “Pipedrive (Customer Relationship Management)”) and our calendar. If you have consented to marketing cookies, the booking is also reported as a conversion to Google Ads or Microsoft Advertising (without your contact details).
Legal basis: Art. 6(1)(b) GDPR (appointment arrangement at your request); for embedding the service and the conversion report Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent)
Third-country transfer: Calendly LLC is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); in addition, the EU Standard Contractual Clauses apply. A data processing agreement pursuant to Art. 28 GDPR is in place.
Calendly privacy notice: https://calendly.com/legal/privacy-notice
Google Web Fonts (Locally Hosted)
This website uses the font Open Sans for the uniform display of fonts. The fonts are installed locally on our server. No connection to Google servers takes place and no data is transmitted to Google.
Chatbase (AI Chatbot)
This website uses Chatbase, an AI-powered chatbot service of Chatbase.co Inc., 4700 Keele Street, Toronto, ON, Canada. The Chatbase chatbot is used to support users with automated answers to their questions. The chat history and user data are collected and processed for the purpose of improving the chatbot service.
Data processed: chat messages, user ID, timestamp, IP address, browser and device information, possibly personal information you enter in the chat
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Section 25(1) TDDDG
Storage period: Chat data is stored in accordance with the Chatbase privacy policy, typically for a limited period.
Third-country transfer: The transfer of data to Canada is based on the adequacy decision of the European Commission for Canada (Art. 45 GDPR) and, in addition, on the EU Standard Contractual Clauses.
Note: Please do not enter sensitive personal data (e.g. health data, financial information) into the chatbot. Entries are transmitted to the provider’s servers.
Chatbase privacy policy: https://www.chatbase.co/privacy
Opt-out: You can decline to use the chatbot by not interacting with it. For more detailed opt-out options, please consult the Chatbase privacy policy.
Wordfence (Website Security)
This website uses Wordfence, a website security service of Wordfence, Inc., 329 Oak Creek Drive, Ann Arbor, MI 48103, USA. Wordfence protects this website against security threats such as malware, brute-force attacks and other cyber threats. For this purpose, data about your access to the website is collected, processed and analysed.
Data processed: IP address, HTTP request data, user agent, cookies, access patterns
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website security)
Storage period: Wordfence typically stores access data for 30 days.
Third-country transfer: The transfer of data to the USA is based on the EU-US Data Privacy Framework (Art. 45 GDPR), provided the provider is certified accordingly, and additionally on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Wordfence privacy policy: https://www.wordfence.com/privacy/
Hosting
Hostinger
This website is hosted by Hostinger, a web hosting provider. The web space is provided on servers in Germany. Hostinger has access to all data stored on the servers, in particular all data collected through this website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable hosting) and Art. 28 GDPR (processing on behalf)
Hostinger privacy policy: https://www.hostinger.com/privacy
Server location: Germany
Data processing agreement: A data processing agreement pursuant to Art. 28 GDPR has been concluded with Hostinger.
This English version is provided for convenience. In case of doubt, the German version of this privacy policy (Datenschutzerklärung) shall prevail.