Data Policy

<h1>Privacy Policy</h1>

<h2>1. An overview of data protection</h2>

<h3>General information</h3>
The following information will provide you with an easy-to-navigate overview of what happens to your personal data when you visit this website. The term “personal data” comprises all data that can be used to personally identify you. For detailed information about data protection, please consult this Privacy Policy.

<h3>Data recording on this website</h3>

<h4>Who is the responsible party for the recording of data on this website (i.e., the “controller”)?</h4>
The data on this website is processed by the operator of the website, whose contact information is available under the section “Information about the responsible party (referred to as the “controller” in the GDPR)” in this Privacy Policy.

<h4>How do we record your data?</h4>
We collect your data when you share it with us, for example when you enter information into a contact form.

Other data are recorded automatically by our IT systems or after you consent to their recording during your visit to the website. This data primarily includes technical information (e.g., web browser, operating system, or time of site access) and is recorded automatically when you access this website.

<h4>What are the purposes we use your data for?</h4>
Some of the information is required to ensure the error-free provision of the website. Other data may be used to analyze user behavior. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other inquiries.

<h4>What rights do you have regarding your information?</h4>
You have the right to receive information about the origin, recipients, and purposes of your stored personal data at any time without charge. You also have the right to request the correction or deletion of your data. If you have consented to data processing, you may revoke this consent at any time with effect for the future. Furthermore, you have the right to request restrictions on the processing of your personal data under certain circumstances and the right to lodge a complaint with the competent supervisory authority.

<h3>Analysis tools and tools provided by third parties</h3>
There is a possibility that your browsing behavior will be statistically analyzed when you visit this website. Such analyses are carried out primarily using analysis programs.

For detailed information on these analysis programs, please refer to the relevant sections of this Privacy Policy.

<h2>2. Hosting</h2>

<h3>Mittwald</h3>
We host the content of our website with the following provider:

Mittwald CM Service GmbH &amp; Co. KG
Königsberger Straße 4–6
32339 Espelkamp
Germany

For details, please refer to Mittwald’s privacy policy:
<a href=”https://www.mittwald.de/datenschutz” target=”_blank” rel=”noopener noreferrer”>https://www.mittwald.de/datenschutz</a>

The use of Mittwald is based on Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring the most reliable presentation of our website possible. If consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, insofar as consent includes the storage of cookies or access to information on the user’s end device. Consent can be revoked at any time.

<h4>Data processing</h4>
We have concluded a data processing agreement (DPA) with the above-mentioned provider. This agreement ensures that personal data of our website visitors are processed only in accordance with our instructions and in compliance with the GDPR.

<h2>3. General information and mandatory information</h2>

<h3>Data protection</h3>
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this Privacy Policy.

<h3>Information about the responsible party (referred to as the “controller” in the GDPR)</h3>
The controller responsible for data processing on this website is:

ZAL GmbH
Hein-Saß-Weg 22
21129 Hamburg
Germany

Phone: +49 40 248 595-0
E-mail:

<h3>Storage duration</h3>
Unless a more specific storage period is stated in this Privacy Policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you request deletion or revoke your consent, your data will be deleted unless statutory retention obligations apply.

<h3>Legal basis for data processing</h3>
If you have given your consent, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR for special categories of data. If processing is required for the performance of a contract or pre-contractual measures, it is based on Art. 6(1)(b) GDPR. Processing to fulfill a legal obligation is based on Art. 6(1)(c) GDPR. In addition, processing may be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.

<h3>Designation of a data protection officer</h3>
We have appointed a data protection officer:

DS EXTERN GmbH
Dipl.-Kfm. Marc Althaus
Frapanweg 22
22589 Hamburg
Germany

<a href=”https://www.dsextern.de/anfragen” target=”_blank” rel=”noopener noreferrer”>https://www.dsextern.de/anfragen</a>

<h3>Recipients of personal data</h3>
Personal data may be transferred to external parties if this is necessary to fulfill a contract, due to a legal obligation, on the basis of legitimate interest, or another legal basis. Where processors are used, processing is carried out on the basis of a valid data processing agreement.

<h3>Revocation of consent</h3>
You may revoke any consent you have given at any time. The lawfulness of data processing carried out before the revocation remains unaffected.

<h3>Right to object pursuant to Art. 21 GDPR</h3>
If data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation.

<h3>Right to lodge a complaint with a supervisory authority</h3>
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority.

<h3>SSL/TLS encryption</h3>
This website uses SSL/TLS encryption for security reasons. An encrypted connection can be recognized by the “https://” prefix in the browser address bar and the lock symbol.

<h2>4. Recording of data on this website</h2>

<h3>Cookies</h3>
Cookies are small data packages stored on your device either temporarily (session cookies) or permanently (persistent cookies). Cookies may be technically necessary or used for analysis and functionality purposes.

The storage of cookies is based on Art. 6(1)(f) GDPR unless consent is required. Where consent is required, processing is based on Art. 6(1)(a) GDPR and § 25 (1) TDDDG. Consent can be revoked at any time.

Information on the cookies used on this website, including their purpose and storage duration, can be found in the consent management tool, which can be accessed at any time via the blue button in the lower left corner of the screen.

<h3>CCM19</h3>
We use the consent management tool CCM19 provided by Papoo Software &amp; Media GmbH, Bonn, Germany, to obtain and document consent. The legal basis is Art. 6(1)(f) GDPR.

<h3>Server log files</h3>
The provider of this website automatically collects and stores information in server log files. This includes browser type, operating system, referrer URL, hostname, time of request, and IP address. Processing is based on Art. 6(1)(f) GDPR.

<h3>Contact form</h3>
Data submitted via the contact form is stored for the purpose of processing your inquiry. Processing is based on Art. 6(1)(b) or (f) GDPR.

<h3>Requests by e-mail, telephone, or fax</h3>
If you contact us by e-mail, telephone, or fax, your inquiry including personal data will be stored and processed to handle your request.

<h2>5. Analysis tools</h2>

<h3>WP Statistics</h3>
This website uses WP Statistics by Veronalabs, Tallinn, Estonia, to analyze visitor behavior. The data collected is stored exclusively on our own server. IP addresses are anonymized. The legal basis is Art. 6(1)(f) GDPR or consent, where required.

<h2>6. Newsletter</h2>

<h3>Newsletter data</h3>
If you subscribe to our newsletter, we collect your e-mail address and information required to verify your subscription. The newsletter is sent via Mailchimp (Rocket Science Group LLC, USA). Data transfers are based on Standard Contractual Clauses and the EU–US Data Privacy Framework.

<h2>7. Plug-ins and tools</h2>

<h3>YouTube</h3>
This website embeds videos from YouTube (Google Ireland Limited). Data processing is based on Art. 6(1)(f) GDPR or consent. Google is certified under the EU–US Data Privacy Framework.

<h3>Google Maps</h3>
This website uses Google Maps. Use of the service requires the processing of IP addresses. Google is certified under the EU–US Data Privacy Framework.

<h2>8. Social media</h2>

<h3>Social media profiles</h3>
We maintain publicly accessible profiles on various social networks. When you visit these profiles, personal data may be processed by the respective providers.

<h3>Legal basis</h3>
Our social media presence is based on Art. 6(1)(f) GDPR.

<h2>9. Video surveillance</h2>
We use video surveillance at our premises for the protection of property and access control. Processing is based on Art. 6(1)(f) GDPR. Recordings are generally deleted after 72 hours unless required for legal purposes.

<em>Privacy Policy, January 2026</em>

Ups...! Your Browser needs an update

Did you know that you browser is outdated? To get the best experience of our website we recommend that you upgrade to a newer version or a different web browser. A list of the most popular browsers can be found below. Just click on the icons to get to the download page. Please note that the latest and final version of Internet Explorer (IE 11) is no longer fully supported.

If you can‘t or don‘t want to update your browser, ignore this message and keep browsing.