Privacy policy
1. Controller
IESOFT UG (haftungsbeschränkt) Marktplatz 7 75203 Königsbach-Stein Germany Phone: +49 (0) 7232 3239032 Email: info[@]iesoft.de
Below, we explain how we process personal data when you visit this website and use our services.
2. Hosting and server logs
This website is hosted by a web hosting and email service provider based in Germany. The provider processes data on our behalf under a data processing agreement in accordance with Article 28 GDPR.
When you access the website, the hosting provider processes technically necessary access data. According to the provider, this includes, in particular, the requested page or file, referrer URL, browser type and version, operating system, device type, time of access and an IP address that is immediately anonymised for geolocation purposes. The provider evaluates this anonymised access data for statistical analysis and to improve the security, stability and quality of the service.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is in operating this website securely, reliably and in line with users' needs. According to the provider, it stores the data mentioned above for up to eight weeks and does not transfer it to third parties or third countries.
3. Cookies and similar technologies
We use analytics cookies only with your consent. We store your cookie choice in your browser for six months. We then ask you again. You can change your choice at any time under “Cookie settings”.
Cal.com's external appointment booking is activated only when you click the “Load appointment booking” button. From that point, Cal.com may store information on or read information from your device. See “Appointment booking with Cal.com” below for details.
4. Website analytics with Matomo
We use Matomo to statistically analyse how our website is used. Tracking is activated only after you consent. In particular, we process the pages visited, the time of the visit, the referring page, browser and device information, and a shortened IP address. We do not combine this data with the information you provide in the contact form. Processing is based on your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG.
The analytics cookies associate page views with a visit (30 minutes), recognise returning visitors (13 months), and record the source of a visit (six months).
Detailed visit data are deleted after six months. We retain aggregated reports for five years; purely non-personal summary figures may be retained longer for long-term comparisons. You can withdraw your consent at any time under “Cookie settings”, with effect for the future.
5. Contacting us and the contact form
If you contact us by email, phone or contact form, we process the information you provide to handle and respond to your enquiry. On the contact form, your name, email address and message are required; providing a company name is optional. The form data is transmitted in encrypted form to our web server and then delivered to us by email.
If your enquiry relates to a contract or pre-contractual measures, processing is based on Article 6(1)(b) GDPR. In all other cases, it is based on Article 6(1)(f) GDPR. Our legitimate interest is in appropriately handling your enquiry.
We delete your enquiry once it has been fully processed and no statutory retention obligations or legitimate interests, in particular the assertion, exercise or defence of legal claims, require us to retain it.
To protect against automated and abusive enquiries, the form uses a hidden check field, a minimum completion time and a request limit. For this limit, a hash derived from the IP address is processed server-side together with timestamps in a temporary file. Timestamps outside the 15-minute checking period are discarded during the next check.
6. Spam protection with CleanTalk
We use CleanTalk, provided by CleanTalk Inc., 711 S Carson Street, Suite 4, Carson City, NV 89701, USA, to protect the contact form against spam and misuse. The check is carried out server-side when the form is submitted.
The IP address, email address, name provided, message text, completion time and technical information about the form are transmitted to CleanTalk. CleanTalk assesses this information to detect automated or abusive enquiries. Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is in protecting our contact form and IT systems against spam and misuse.
Entries in CleanTalk's anti-spam log are stored for up to seven days. As CleanTalk is a US company, data may also be processed in the USA. For international data transfers, CleanTalk identifies, in particular, the EU–US Data Privacy Framework and the European Commission's Standard Contractual Clauses as safeguards.
Further information: https://cleantalk.org
7. Appointment booking with Cal.com
For optional online appointment booking, we use Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. Cal.com content is loaded only when you click “Load appointment booking”. In particular, your IP address, browser and device information, the page visited, and the date and time may then be transmitted to Cal.com.
If you then book an appointment, Cal.com processes the information you enter, in particular your name, email address, appointment details and any other information you provide voluntarily. Loading the external appointment booking form is based on your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Your booking information is processed to take pre-contractual measures or perform a contract under Article 6(1)(b) GDPR. Alternatively, you can contact us by email or phone.
Cal.com stores booking data while our Cal.com account is active. After the account is closed, the data is deleted according to Cal.com's deletion schedule, unless statutory retention obligations apply.
Cal.com processes data in the USA. According to Cal.com, transfers from the EU are covered by the EU–US Data Privacy Framework and, where applicable, the European Commission's Standard Contractual Clauses.
Further information: https://cal.com
8. External links
This website contains links to external services, such as LinkedIn. Merely displaying a link does not transmit data to the respective provider. The destination provider's privacy policy applies only when you follow the link.
9. Retention periods
Unless a specific retention period is stated in this privacy policy, we store personal data only for as long as necessary for the relevant purpose. We then delete the data unless statutory retention obligations or legitimate reasons for continued storage apply.
10. Your rights
Subject to the statutory requirements, you have, in particular, the following rights:
- Access your personal data (Article 15 GDPR).
- Have inaccurate data rectified (Article 16 GDPR).
- Have your data erased (Article 17 GDPR).
- Restrict processing (Article 18 GDPR).
- Data portability (Article 20 GDPR).
- Object to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR).
You may withdraw any consent you have given at any time with effect for the future (Article 7(3) GDPR). This does not affect the lawfulness of processing carried out before withdrawal. To exercise your rights, contact us using the contact details above.
11. Right to lodge a complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is, in particular, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Heilbronner Straße 35, 70191 Stuttgart, Germany; telephone: +49 (0) 711 615541-0; email: poststelle[@]lfdi.bwl.de.
Further information and contact options: https://www.baden-wuerttemberg.datenschutz.de
12. Data security
We use an encrypted HTTPS connection and appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. Complete protection during data transmission over the internet cannot, however, be guaranteed.
