Privacy policy
This privacy policy explains which personal data is processed when you visit the website devacon.eu and when you contact us, on which legal basis this happens and which rights you have. We use cookies and third-party services only with your consent: Google Analytics for audience measurement (section 5) and the directions map from OpenStreetMap on the contact page (section 6). Audience measurement with Umami (section 5) works without cookies and runs on our own servers.
1. Controller
The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is DEVACON GmbH, Lessingstraße 16, 16356 Ahrensfelde, Germany, with an office at Uhlandstraße 28, 10719 Berlin. Phone +49 30 81453320, email [email protected]. Represented by the managing director Eduard Meiler.
2. Contact for data protection matters
For questions about data protection, the exercise of your rights or this policy, you can reach us by email at [email protected] or by post at DEVACON GmbH, Datenschutz, Lessingstraße 16, 16356 Ahrensfelde, Germany.
3. Hosting and delivery of the website
The website is operated on a virtual server of IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The server is located in a data centre in Germany. IONOS processes the data generated when the site is accessed on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR.
The website is delivered through the content delivery network of Cloudflare (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA; for users in the European Economic Area: Cloudflare Germany GmbH, Rosental 7, 80331 Munich). Cloudflare serves the website via globally distributed servers, fends off attacks on the website and encrypts the connection. In doing so, technical connection data, in particular your IP address, is processed by Cloudflare. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, standard contractual clauses of the EU Commission have been agreed. A data processing agreement is in place with Cloudflare.
The legal basis for using IONOS and Cloudflare is our legitimate interest in a secure, stable and fast delivery of the website (Art. 6 (1) (f) GDPR).
4. Server log files
Each time the website is accessed, the web server automatically stores technical data in log files: the IP address of the requesting device, date and time of access, the page or file requested, the amount of data transferred, the HTTP status code, the previously visited page (referrer), browser type and operating system. This data is not merged with other data sources and is not evaluated to identify individual persons.
The purpose of the processing is the technical provision of the website, the security of our systems and the investigation of faults and attacks. The legal basis is Art. 6 (1) (f) GDPR. The log files are rotated daily and deleted automatically after eight days at the latest; individual entries are retained longer only if a specific security incident has to be investigated.
5. Audience measurement: Umami (no cookies) and Google Analytics (only after consent)
To analyse the use of our website we use the open-source software Umami. Umami runs exclusively on our own infrastructure at analytics.devacon.eu, a virtual server operated by us at IONOS in a data centre in Germany (section 3). The data stays with us; it is neither passed on to third parties nor transferred to countries outside the European Economic Area.
Umami does not set cookies and does not store identifiers in your browser. It records the page visited, the referring page, browser type, operating system, device type, screen resolution, language and the approximate location (country, region, city), which Umami derives from the IP address. The IP address itself is not stored. To group the page views of one visit, Umami forms a hash from the IP address, the browser identifier and a secret value that changes daily; the IP address cannot be recovered from it, and we do not link it with other data. There is no tracking across other websites, and no user profiles are created. The evaluation is carried out in aggregated form (page views, visits, origin, devices).
The legal basis is our legitimate interest in audience measurement that shows us which content is used, helps us find errors and improve the website (Art. 6 (1) (f) GDPR). The processing is limited to what is necessary: no cookies, no storage of the IP address, no disclosure to third parties and no combination with other data; in our assessment your interests therefore do not prevail. As Umami neither stores information on your device nor reads information stored there, no consent under Section 25 (1) of the German TDDDG is required.
You may object to the processing at any time (Art. 21 GDPR, section 14). The simplest technical way is to enable the "Do Not Track" setting in your browser; our Umami script respects this signal and then records no page views. Alternatively, you can email us at [email protected].
With your consent we use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics is only loaded once you choose "Accept all" in the notice at the bottom of the page or enable the "Statistics" category under "Adjust settings". No connection to Google is established before that.
Google Analytics uses cookies and similar identifiers (including "_ga" and "_ga_" followed by our measurement ID, stored for up to two years) to evaluate your use of the website: pages viewed, time spent, approximate location based on the truncated IP address, device type, browser and the page you came from. Google Analytics 4 does not store full IP addresses. The reports help us understand which content is used and improve the website. Google signals and advertising features are not enabled; the retention period for user-level data at Google is set to two months in our Analytics settings, after which the data is deleted automatically.
The legal basis is your consent (Art. 6 (1) (a) GDPR, Section 25 (1) of the German TDDDG). Google processes the data on our behalf (Art. 28 GDPR) and may transfer it to servers of Google LLC in the USA. The transfer is safeguarded by the certification of Google LLC under the EU-US Data Privacy Framework and, in addition, by the standard contractual clauses of the EU Commission.
You may withdraw your consent at any time with effect for the future by deselecting the "Statistics" category or choosing "Essential only" via "Cookie settings" in the footer (section 7). Google Analytics is then no longer loaded and the cookies that were set are removed. Further information on data protection at Google: https://policies.google.com/privacy and https://support.google.com/analytics/answer/6004245.
6. Directions map from OpenStreetMap (only after consent)
On the contact page we offer an interactive directions map from the OpenStreetMap service. The provider is the OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom. The maps (one per location) are only loaded once you choose "Accept all" in the notice at the bottom of the page, enable the "External content" category there under "Adjust settings" or click "Load maps (OpenStreetMap)" on the contact page. Before that, no connection to OpenStreetMap is established; instead you see a stylised location overview with addresses and a link for route planning.
When the map is loaded, your browser retrieves map tiles from the servers of the OpenStreetMap Foundation. In doing so, your IP address, the date and time of the request, the requested map section as well as browser type and operating system are transmitted to the OpenStreetMap Foundation. We have no influence on the further processing there. Information on this is provided in the privacy policy of the OpenStreetMap Foundation at https://wiki.osmfoundation.org/wiki/Privacy_Policy.
The legal basis is your consent (Art. 6 (1) (a) GDPR). The transfer to the United Kingdom is safeguarded by the adequacy decision of the European Commission under Art. 45 GDPR. You may withdraw your consent at any time with effect for the future by choosing "Essential only" via "Cookie settings" in the footer of the website or by deselecting the "External content" category (section 7); loaded maps are then removed immediately and not loaded again.
7. Storage of your consent (cookie settings)
On your first visit we show a notice with three categories: "Necessary" (always active, covers only the storage of your choice and the basic functions of the website), "Statistics" (audience measurement with Google Analytics, section 5) and "External content" (the directions maps by OpenStreetMap, section 6). You can accept all categories, allow only the necessary ones or select them individually under "Adjust settings".
We store your decision exclusively in your browser in the so-called local storage under the key "dv-consent" (content: your choice per category, the time and the version of the notice). No cookie is set; the information is transmitted neither to us nor to third parties. The storage is technically necessary so that the notice does not reappear on every page view and your choice is respected (Section 25 (2) no. 2 of the German TDDDG, Art. 6 (1) (f) GDPR).
The entry expires after twelve months. You can delete it at any time via the website data of your browser or change your choice via the "Cookie settings" link in the footer of every page. Without JavaScript enabled, no notice appears, no map is loaded and no optional service runs.
8. Contact by email and phone
If you contact us by email or phone, we process the data you provide (name, contact details, content of the enquiry) in order to handle and answer your enquiry. The legal basis is Art. 6 (1) (b) GDPR where the enquiry is aimed at a contract, otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries). We use Microsoft 365 for our email (section 13). The data is deleted as soon as the enquiry has been fully dealt with and no statutory retention obligations apply.
9. Contact form and request for the IT security infrastructure check
We provide forms on the contact page and on the cybersecurity page. Mandatory fields are, for the contact form, your name, business email address and your request and, for the IT security infrastructure check request, company, contact person, email address and the details of your IT environment (workplaces, servers, sites, operating model); all other details are voluntary.
Your details are transmitted encrypted to our web server and from there transferred to our customer relationship management system (CRM), in which we handle enquiries and prepare proposals. At the same time we receive a notification with your details by email to [email protected]; for this we use Microsoft 365 (section 13). If the CRM or the email dispatch is temporarily unavailable, our web server stores the enquiry until we have taken it over.
To protect against automated submissions, the form contains a check field invisible to humans, and we limit the number of requests per IP address; for this purpose our web server keeps your IP address in memory for ten minutes when the form is submitted. We do not use third-party services such as captcha providers for this.
The legal basis is the implementation of pre-contractual measures at your request (Art. 6 (1) (b) GDPR) and your consent, which you give when submitting the form (Art. 6 (1) (a) GDPR); the protection against automated submissions is based on our legitimate interest in preventing abusive use (Art. 6 (1) (f) GDPR). You may withdraw your consent at any time with effect for the future, for example by email to [email protected]. The data is deleted as soon as your enquiry has been fully dealt with; if a contract is concluded, we retain it within the statutory periods.
10. Job applications
We accept applications by email. We process the data you submit (cover letter, CV, certificates, contact details) exclusively to carry out the application process. The legal basis is Art. 6 (1) (b) GDPR in conjunction with Section 26 of the German Federal Data Protection Act (BDSG). We process special categories of personal data, such as information on health or a severe disability, only if you provide it voluntarily (Art. 9 (2) (b) GDPR).
If you are hired, the data is transferred to your personnel file. Otherwise we delete the application documents after the end of the process, as soon as no evidence obligations, for example under the German General Equal Treatment Act (AGG), stand in the way.
11. Customers, prospects and business partners
In the context of proposals, contracts, maintenance contracts and support we process the data of our contacts at customers, prospects and suppliers (name, role, business contact details, communication, contract and billing data). The legal basis is Art. 6 (1) (b) GDPR where the data subject is the contracting party, otherwise Art. 6 (1) (f) GDPR (legitimate interest in handling the business relationship) and Art. 6 (1) (c) GDPR for retention obligations under commercial and tax law. The data is deleted after the end of the business relationship and expiry of the statutory retention periods.
12. Fonts and external links
The fonts of the website are delivered from our own server. No connection to external font providers is established when you visit the website.
The website contains links to external offerings, such as our online shop, app stores and social networks. When you click such a link you leave our website; the privacy policy of the respective provider then applies. With the exception of the OpenStreetMap map on the contact page (section 6), third-party content is not embedded on devacon.eu.
13. Recipients and transfers to third countries
Within DEVACON GmbH only those departments that need your data to fulfil the purposes described have access to it. We use IONOS (hosting), Cloudflare (delivery and protection of the website) and Microsoft (Microsoft 365 for email; Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) as processors. Transfers to third countries outside the European Economic Area only take place in the course of delivery via Cloudflare (safeguarded by the certification of Cloudflare, Inc. under the EU-US Data Privacy Framework and standard contractual clauses), in individual cases at Microsoft 365, for example for support (safeguarded by the certification of Microsoft Corporation under the EU-US Data Privacy Framework and standard contractual clauses), and, after your consent, when Google Analytics is used, to Google (USA, safeguarded by the certification of Google LLC under the EU-US Data Privacy Framework and standard contractual clauses, section 5) and when the OpenStreetMap map is loaded, to the OpenStreetMap Foundation in the United Kingdom (safeguarded by the adequacy decision of the European Commission, section 6). Data is passed on to other third parties only if we are legally obliged to do so or if you have consented.
14. Your rights
You have the following rights vis-à-vis DEVACON GmbH with regard to the personal data concerning you:
Access (Art. 15 GDPR)
You may request information on whether and which personal data we process about you, for which purposes, who the recipients are and how long the data is stored.
Rectification (Art. 16 GDPR)
You may request the rectification of inaccurate data and the completion of incomplete data.
Erasure (Art. 17 GDPR)
You may request the erasure of your data unless statutory retention obligations or other legal grounds prevent this.
Restriction of processing (Art. 18 GDPR)
Under the statutory conditions you may request that the processing of your data be restricted.
Data portability (Art. 20 GDPR)
You may receive data you have provided to us on the basis of consent or a contract in a structured, commonly used and machine-readable format.
Objection (Art. 21 GDPR)
Where we process your data on the basis of a legitimate interest (Art. 6 (1) (f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Withdrawal of consent (Art. 7 (3) GDPR)
You may withdraw any consent you have given at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Complaint to a supervisory authority (Art. 77 GDPR)
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The supervisory authority responsible for our registered office is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (State Commissioner for Data Protection of Brandenburg), Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany, phone +49 33203 356-0, email [email protected]. For our Berlin office, the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59 to 61, 10555 Berlin, Germany, phone +49 30 13889-0, email [email protected], can be contacted.
15. Automated decision-making and profiling
We do not make decisions based solely on automated processing and do not carry out profiling.
16. Data security
The website is delivered exclusively encrypted via HTTPS. We use technical and organisational measures to protect your data against loss, misuse and unauthorised access.
17. Changes to this privacy policy
We adapt this privacy policy when the legal situation, our website or the services used change. The version published on this page applies in each case.
Last updated: 6 October 2026