Privacy Policy

Last updated: 30 July 2026

We are delighted that you are interested in our company. Data protection is of particularly high priority for the management of eclareon GmbH. It is generally possible to use the websites of eclareon GmbH without providing any personal data. However, if a data subject wishes to make use of particular services offered by our company via our website, processing of personal data may become necessary. Where the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain the consent of the data subject.

The processing of personal data — such as the name, address, email address or telephone number of a data subject — is always carried out in accordance with the General Data Protection Regulation and in compliance with the country-specific data protection provisions applicable to eclareon GmbH. By means of this privacy policy, our company wishes to inform the public of the nature, scope and purpose of the personal data we collect, use and process. Furthermore, data subjects are informed of the rights to which they are entitled by means of this privacy policy.

As the controller, eclareon GmbH has implemented numerous technical and organisational measures to ensure the most complete protection possible of the personal data processed via this website. Nevertheless, internet-based data transmissions may in principle have security gaps, so that absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.

1. Definitions

The privacy policy of eclareon GmbH is based on the terminology used by the European legislator when adopting the General Data Protection Regulation (GDPR). Our privacy policy is intended to be easy to read and understand for the general public as well as for our customers and business partners. To ensure this, we would like to explain the terminology used in advance.

In this privacy policy, we use the following terms, among others:

a) Personal data

Personal data means any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more special characteristics which express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

b) Data subject

Data subject means any identified or identifiable natural person whose personal data is processed by the controller.

c) Processing

Processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of processing

Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.

e) Profiling

Profiling means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

f) Pseudonymisation

Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.

g) Controller or controller responsible for the processing

The controller, or controller responsible for the processing, is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

h) Processor

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

i) Recipient

Recipient means a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not.

j) Third party

Third party means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and the persons who are authorised to process personal data under the direct authority of the controller or the processor.

k) Consent

Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, by which they signify agreement to the processing of personal data relating to them, in the form of a statement or of another clear affirmative action.

2. Name and address of the controller

The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and other provisions of a data protection nature is:

eclareon GmbH Albrechtstrasse 22 10117 Berlin Germany Tel.: +49 30 88 66 740 -0 Email: info@eclareon.com Website: www.eclareon.com

2a. Contact for data protection enquiries

For questions concerning data protection and for the exercise of your rights as a data subject, please contact: info@eclareon.com

3. Hosting

This website is hosted by an external service provider. The personal data collected on this website is stored on the host’s servers. This may include, in particular, IP addresses, contact enquiries, metadata and communication data, contact details, names and website access data.

Our host is:

domainfactory GmbH Oskar-Messter-Straße 33 85737 Ismaning Germany

The servers are located in Germany. The host is engaged in the interest of the secure, fast and efficient provision of our online offering by a professional provider (Art. 6 (1) (f) GDPR) and for the purpose of performing pre-contractual and contractual measures (Art. 6 (1) (b) GDPR).

4. Cookies

The websites of eclareon GmbH use cookies. Cookies are text files which are stored on a computer system via an internet browser. Many websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a character string by which websites and servers can be assigned to the specific internet browser in which the cookie was stored.

Through the use of cookies, eclareon GmbH can provide the users of this website with more user-friendly services that would not be possible without cookies being set.

Consent and cookie banner

We use cookies and comparable technologies that are not strictly technically necessary solely on the basis of your consent (Sec. 25 (1) TDDDG, Art. 6 (1) (a) GDPR). When you first visit our website, a consent banner informs you of the categories in use and allows you to select individually which of them you consent to. Without your consent, only those cookies are set which are strictly technically necessary for the operation of the website (Sec. 25 (2) TDDDG).

Your consent is given voluntarily and may be withdrawn at any time. You can change your settings at any time via the “Cookie settings” link in the footer of every page, or withdraw your consent entirely. Withdrawal does not affect the lawfulness of processing carried out up to that point.

A complete list of the cookies used, their purposes and their storage periods can be found in our Cookie Policy.

Independently of this, you can also prevent cookies from being set via your internet browser settings, or delete cookies that have already been set. If you disable the setting of cookies, not all functions of our website may be fully usable.

5. Collection of general data and information

Each time the website of eclareon GmbH is accessed by a data subject or an automated system, the website collects a range of general data and information. This general data and information is stored in the server log files. The following may be recorded: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrer), (4) the sub-pages accessed on our website via an accessing system, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system, and (8) other similar data and information which serve to avert danger in the event of attacks on our information technology systems.

When using this general data and information, eclareon GmbH does not draw any conclusions about the data subject. Rather, this information is required in order to (1) deliver the content of our website correctly, (2) optimise the content of our website and the advertising for it, (3) ensure the long-term operability of our information technology systems and the technology of our website, and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack. This anonymously collected data and information is therefore evaluated by eclareon GmbH both statistically and with the aim of increasing data protection and data security within our company, in order ultimately to ensure an optimal level of protection for the personal data we process. The anonymous data in the server log files is stored separately from all personal data provided by a data subject.

The server log files are stored for a limited period for security reasons and are then deleted automatically. The legal basis for the processing is our legitimate interest in the technical security and stability of our website (Art. 6 (1) (f) GDPR).

6. Contact forms, questionnaire and email contact

On our website we provide forms through which you can contact us (the contact form and the questionnaire relating to our events and business trips). If you use one of these forms, we process the data you enter — in particular your name, email address and your message — for the purpose of handling your enquiry.

The legal basis is your consent (Art. 6 (1) (a) GDPR) and, insofar as your enquiry is directed at the conclusion or performance of a contract, Art. 6 (1) (b) GDPR. You may withdraw your consent at any time; the lawfulness of processing carried out prior to withdrawal remains unaffected.

Delivery of form notifications (Brevo)

For the technical delivery of the notification emails generated by our forms, we use the service Brevo. The provider is

Brevo GmbH Köpenicker Straße 126 10179 Berlin Germany

a subsidiary of Sendinblue SAS, 9–17 rue Salneuve, 75017 Paris, France.

The data you submit via the form is transmitted to Brevo for the purpose of sending the email and processed there. Brevo processes this data exclusively on our behalf and in accordance with our instructions. The basis for this is a data processing agreement pursuant to Art. 28 GDPR, which forms part of Brevo’s terms of use.

Brevo processes data primarily on servers within the European Union. Transfers to sub-processors in third countries cannot be excluded. For such transfers, Brevo ensures an adequate level of protection in accordance with Art. 44 et seq. GDPR. Further information can be found in Brevo’s privacy policy.

Disclosure to third parties

Beyond the processing on our behalf described above, we do not disclose your data to third parties.

Storage period

We store the data submitted via the forms until the purpose for storage no longer applies — in the case of enquiries, therefore, until your matter has been fully dealt with — but for no longer than one year. Statutory retention obligations, in particular commercial and tax law retention periods, remain unaffected.

7. Routine erasure and blocking of personal data

The controller processes and stores the personal data of the data subject only for the period necessary to achieve the purpose of storage, or where this is provided for by the European legislator or another legislator in laws or regulations to which the controller is subject.

If the purpose of storage no longer applies, or if a prescribed storage period expires, the personal data is routinely blocked or erased in accordance with statutory provisions.

8. Rights of the data subject

a) Right of confirmation

Every data subject has the right to obtain confirmation from the controller as to whether personal data concerning them is being processed.

b) Right of access

Every data subject affected by the processing of personal data has the right to obtain from the controller, free of charge and at any time, information about the personal data stored concerning them, together with a copy of that information.

c) Right to rectification

Every data subject has the right to obtain without undue delay the rectification of inaccurate personal data concerning them.

d) Right to erasure (right to be forgotten)

Every data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay, provided that the statutory conditions for this are met.

e) Right to restriction of processing

Every data subject has the right to obtain from the controller the restriction of processing, provided that the statutory conditions for this are met.

f) Right to data portability

Every data subject has the right to receive the personal data concerning them in a structured, commonly used and machine-readable format.

g) Right to object

Every data subject has the right, on grounds relating to their particular situation, to object at any time to the processing of personal data concerning them.

h) Automated individual decision-making, including profiling

Every data subject has the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them.

i) Right to withdraw consent under data protection law

Every data subject has the right to withdraw consent to the processing of personal data at any time.

j) Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The supervisory authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59-61 10555 Berlin Germany Telephone: +49 30 13889-0 Email: mailbox@datenschutz-berlin.de

If a data subject wishes to exercise any of the above rights, they may contact us at any time at info@eclareon.com.

9. Web analytics

We do not currently use any analytics or tracking tool such as Google Analytics on this website. Should this change, we will update this privacy policy before any such tool is actively used.

10. Links to LinkedIn

On our website, you will find links to the professional network LinkedIn on individual profiles of our staff. These are simple hyperlinks, not embedded content or plug-ins. Accordingly, no data is transmitted to LinkedIn when you access our website.

A transfer of data to LinkedIn only takes place once you actively click such a link and thereby access the LinkedIn website. From that point onwards, LinkedIn’s privacy policy applies. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn’s privacy policy is available at linkedin.com/legal/privacy-policy.

11. Legal basis for the processing

Art. 6 (1) (a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. Where the processing of personal data is necessary for the performance of a contract, the processing is based on Art. 6 (1) (b) GDPR. Where our company is subject to a legal obligation requiring the processing of personal data, the processing is based on Art. 6 (1) (c) GDPR. Finally, processing operations may be based on Art. 6 (1) (f) GDPR where processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, provided that the interests, fundamental rights and freedoms of the data subject do not override those interests.

12. Legitimate interests pursued by the controller or by a third party

Where the processing of personal data is based on Art. 6 (1) (f) GDPR, our legitimate interest is the conduct of our business activities for the benefit of the well-being of all our employees and our shareholders.

13. Period for which the personal data is stored

The criterion for the duration of the storage of personal data is the respective statutory retention period. Once that period has expired, the corresponding data is routinely erased, provided it is no longer required for the performance or initiation of a contract.

14. Statutory or contractual requirements to provide personal data

We would like to inform you that the provision of personal data is in part required by law, or may also arise from contractual provisions. Failure to provide the personal data may mean that a contract with the data subject cannot be concluded.

15. Existence of automated decision-making

As a responsible company, we do not use automated decision-making or profiling.

16. Encrypted data transmission

For security reasons, this website uses TLS encryption. You can recognise an encrypted connection by the fact that your browser’s address bar displays “https://” and a padlock symbol is shown.

17. Use of fonts

The fonts used on this website are served locally from our own server. No connection to Google servers is established when the fonts are loaded.