Optimaite Logo
GDPR-compliant

Privacy Policy

Information about how we handle your personal data in accordance with the General Data Protection Regulation (GDPR)

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to our privacy policy below.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Information about the Responsible Party" in this privacy policy.

How do we collect your data?

Your data is collected in part by you providing it to us. This may include data you enter in a contact form, for example.

Other data is collected automatically or with your consent when you visit the website through our IT systems. This is primarily technical data (e.g., internet browser, operating system, or time of page visit). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated through the website, the transmitted data will also be processed for contract offers, orders, or other inquiries.

What rights do you have regarding your data?

You have the right to obtain free information about the origin, recipient, and purpose of your stored personal data at any time. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of processing of your personal data under certain circumstances. Furthermore, you have the right to file a complaint with the competent supervisory authority.

You can contact us at any time regarding these and other questions about data protection.

Analytics Tools and Third-Party Tools

When you visit this website, your browsing behavior may be statistically evaluated. This is done primarily with so-called analytics programs.

We use both consent-free, privacy-friendly analytics tools (Pirsch Analytics, Vercel Web Analytics) as well as consent-required services (Google Analytics 4, Microsoft Clarity). Consent-required services are only activated after you give your explicit consent via our cookie consent banner.

Detailed information about all analytics programs used can be found in Section 5 of this privacy policy.

2. Hosting

External Hosting

This website is externally hosted. The personal data collected on this website is stored on the servers of the hosting provider(s). This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access, and other data generated through a website.

External hosting is carried out for the purpose of contract fulfillment with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). If consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

Our hosting provider(s) will only process your data to the extent necessary to fulfill their performance obligations and will follow our instructions regarding this data.

We use the following hosting provider(s):

Vercel Inc. 440 N Barranca Ave #4133 Covina, CA 91723, USA

The website is provided via Vercel. Vercel uses a global edge network, with static content also being served from European locations (including Frankfurt).

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the personal data of our website visitors is processed only according to our instructions and in compliance with the GDPR.

3. General Information and Mandatory Disclosures

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We point out that data transmission over the Internet (e.g., when communicating by email) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Information about the Responsible Party

The responsible party for data processing on this website is:

Jamil Mounzer / Optimaite UG Obermeiersfeld 9 33104 Paderborn, Germany Phone: +49 176 37613924 Email: jamil.mounzer@optimaite.eu

The responsible party is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent for data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will take place after these reasons cease to apply.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent that has already been given at any time. The legality of data processing carried out before the revocation remains unaffected by the revocation.

SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address bar of the browser changes from "http://" to "https://" and by the lock symbol in your browser bar.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

4. Data Collection on This Website

Cookies

Our websites use so-called "cookies." Cookies are small data packets and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.

Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).

You can set your browser to notify you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.

Contact Form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and for follow-up questions. We do not share this data without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be revoked at any time.

5. Analytics Tools and Plugins

Cookie Consent Banner and Consent Management

We use a custom-built cookie consent banner on this website to manage your consent for the processing of personal data and the use of cookies and similar technologies. The consent banner is displayed on your first visit to our website and allows you to set your consent preferences for various categories of data processing.

Our consent banner implements Google Consent Mode v2 and manages the following consent categories:

  • Necessary – Technically required functions (always active)
  • Analytics – Controls whether analytics cookies (e.g., Google Analytics) may be set
  • Marketing – Controls whether advertising cookies and personalized advertising may be activated

All consent-required services (Google Analytics 4, Microsoft Clarity, and Google Tag Manager) are only activated after you have given your explicit consent. Without your consent, no cookies from these services are set and no data is transmitted to them.

Your consent status is stored in a first-party cookie ("optimaite_consent") in your browser to restore your decision on subsequent visits. Storage duration: 1 year or until revocation.

The legal basis for storing the consent cookie is § 25(2) No. 2 TDDDG, as the storage is strictly necessary for providing the service you have explicitly requested (consent management). The processing of consent data is also based on our legal obligation to document given consents pursuant to Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.

You can change or revoke your consent settings at any time by clicking the "Cookie Settings" link in the footer of our website. Revoking consent does not affect the legality of data processing carried out before the revocation.

Pirsch Analytics

We use the web analytics service Pirsch Analytics on this website, a service of Emvi Software GmbH, Nickelstraße 1b, 33378 Rheda-Wiedenbrück, Germany.

Pirsch Analytics is a privacy-friendly, cookie-free web analytics software developed according to the Privacy by Design principle and hosted exclusively on servers in Germany. Pirsch Analytics does not use cookies and does not employ fingerprinting. With each page view, an anonymous visitor ID is generated using a hashing algorithm from your IP address, your user agent, the current date, and a random, website-specific salt. Your IP address is neither fully nor partially stored and is completely and irreversibly anonymized through the hash. The visitor ID is discarded after a maximum of 24 hours.

The following data is collected in anonymized, aggregated form: page views and time on page, referrer and UTM campaign parameters, country of origin, city, and language, operating system, browser, and screen resolution, as well as custom events.

No personal data is stored and no data is shared with third parties. No transfer to third countries takes place.

The legal basis for using Pirsch Analytics is our legitimate interest in the statistical evaluation of user behavior for optimization purposes pursuant to Art. 6(1)(f) GDPR. Since Pirsch Analytics does not set cookies and does not access information on the user's device within the meaning of § 25 TDDDG, consent pursuant to § 25(1) TDDDG is not required.

We have concluded a data processing agreement (DPA) pursuant to Art. 28 GDPR with Emvi Software GmbH. More information: https://pirsch.io/privacy

Google Tag Manager

We use Google Tag Manager, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google Tag Manager is a tool that allows us to manage tracking and analytics tags on our website. Google Tag Manager itself does not create user profiles, does not store cookies, and does not perform any independent analysis. It only serves to manage and deploy the tools integrated through it. However, Google Tag Manager does collect your IP address, which may also be transmitted to a Google server in the USA.

The legal basis for using Google Tag Manager is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Consent can be revoked at any time with effect for the future. The services integrated via Google Tag Manager are only activated after the respective consent has been given.

Google is certified under the EU-US Data Privacy Framework (DPF). More information: https://policies.google.com/privacy

Google Analytics 4

We use Google Analytics 4 on this website, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies that enable analysis of how you use our website. The information collected is generally transmitted to and stored on a Google server in the USA.

Google Analytics 4 collects the following data: pages visited and time spent, interaction with website content (clicks, scroll depth), approximate location (country, city, based on anonymized IP address), technical information about browser, operating system, and device, as well as the source of the visit.

IP Anonymization: In Google Analytics 4, IP address anonymization is enabled by default. Your IP address is truncated by Google within member states of the EU or in other contracting states of the EEA Agreement before being transmitted to a Google server in the USA.

Cookies and Storage Duration: Google Analytics stores cookies in your web browser for up to two years from your last visit. User-related data linked to cookies is automatically deleted after 14 months.

Google Analytics is only activated after you give your explicit consent via our consent banner. Activation is consent-controlled via Google Tag Manager using the consent signal "analytics_storage."

The legal basis for data processing is your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent can be revoked at any time with effect for the future.

Opt-out option: You can also download and install the browser add-on to deactivate Google Analytics: https://tools.google.com/dlpage/gaoptout

Google is certified under the EU-US Data Privacy Framework (DPF). More information: https://support.google.com/analytics/answer/6004245

Microsoft Clarity

We use Microsoft Clarity on this website, a web analytics and heatmap service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The parent company is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Microsoft Clarity collects usage data through session replays and heatmaps to analyze and improve the usability of our website. The following data is processed: cursor and scroll movements, clicks and typing behavior, access times and page views, IP address (anonymized), information about the browser, operating system, and screen resolution used, as well as location data (country/region, derived from the IP address).

Microsoft Clarity sets the following cookies: "_clck" (storage duration: 1 year), "_clsk" (storage duration: 1 day), "CLID", "MUID", "ANONCHK", "MR", and "SM" (third-party cookies). Sensitive input fields (e.g., password, email) are automatically masked in session recordings.

Microsoft Clarity is only activated after you give your explicit consent via our consent banner. Activation is consent-controlled via Google Tag Manager.

The legal basis for data processing is your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent can be revoked at any time with effect for the future via our consent banner.

Microsoft is certified under the EU-US Data Privacy Framework (DPF). More information: https://privacy.microsoft.com/privacystatement

Vercel Web Analytics

We use Vercel Web Analytics on this website, a privacy-friendly web analytics service of Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA, which also serves as the hosting provider for this website.

Vercel Web Analytics is cookie-free and collects only anonymized, aggregated usage data. Visitors are identified via a server-side generated hash that does not allow conclusions about individual persons. The lifetime of a visitor session is a maximum of 24 hours. The following data is collected in anonymized form: page views, referrer URL, geolocation (country, region, city), operating system, browser, device type.

The legal basis for use is our legitimate interest in the statistical evaluation of user behavior pursuant to Art. 6(1)(f) GDPR. Since Vercel Web Analytics does not set cookies and does not access information on the user's device, consent pursuant to § 25(1) TDDDG is not required.

Data transfer to the USA is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR). More information: https://vercel.com/legal/privacy-policy

Overview of Services Used

ServiceConsentLegal BasisCookiesThird Country
Pirsch AnalyticsNoArt. 6(1)(f) GDPRNoneNo (DE)
Google Tag ManagerYesArt. 6(1)(a) GDPRNone of its ownUSA (DPF)
Google Analytics 4YesArt. 6(1)(a) GDPRYes (up to 2 years)USA (DPF)
Microsoft ClarityYesArt. 6(1)(a) GDPRYes (up to 1 year)USA (DPF)
Vercel AnalyticsNoArt. 6(1)(f) GDPRNoneUSA (SCCs)
Consent-BannerNo§ 25(2) No. 2 TDDDG1 (necessary)No

Questions about Data Protection?

If you have questions about data protection or wish to exercise your rights, you can contact us at any time:

Privacy Policy | Optimaite