Privacy

Privacy

As of August 2026

As of August 2026

Protecting your personal data is a top priority for us. That is why we process all personal data in strict accordance with applicable European and national data protection laws.


You can, of course, withdraw your consent at any time with effect for the future. To do so, please contact the responsible controller.

The following privacy policy provides an overview of the types of data we collect, how this information is used and shared, the security measures we take to protect your data, and how you can access the information you have provided to us.

Protecting your personal data is a top priority for us. That is why we process all personal data in strict accordance with applicable European and national data protection laws.


You can, of course, withdraw your consent at any time with effect for the future. To do so, please contact the responsible controller.

The following privacy policy provides an overview of the types of data we collect, how this information is used and shared, the security measures we take to protect your data, and how you can access the information you have provided to us.

Legal basis for processing personal data

Legal basis for processing personal data

When we obtain your consent to process your personal data, we do so in accordance with Article 6(1)(a) of the EU General Data Protection Regulation (GDPR). If we need to process your data to fulfill a contract with you—or to take necessary steps before entering into a contract—this is covered by Article 6(1)(b) GDPR. When processing is required to comply with a legal obligation we are subject to, we rely on Article 6(1)(c) GDPR. Finally, if processing is necessary to protect our legitimate business interests or those of a third party, we do so under Article 6(1)(f) GDPR, provided your rights, freedoms, and interests do not override those business needs.

When we obtain your consent to process your personal data, we do so in accordance with Article 6(1)(a) of the EU General Data Protection Regulation (GDPR). If we need to process your data to fulfill a contract with you—or to take necessary steps before entering into a contract—this is covered by Article 6(1)(b) GDPR. When processing is required to comply with a legal obligation we are subject to, we rely on Article 6(1)(c) GDPR. Finally, if processing is necessary to protect our legitimate business interests or those of a third party, we do so under Article 6(1)(f) GDPR, provided your rights, freedoms, and interests do not override those business needs.

Data deletion and retention period

Data deletion and retention period

We delete or restrict the processing of your personal data as soon as the original purpose for storing it no longer applies. We may retain your data for longer if required by European or national regulations, laws, or other legal provisions that apply to us. Your data will also be restricted or deleted once these mandatory storage periods expire, unless further storage is necessary to conclude or fulfill a contract with you.

We delete or restrict the processing of your personal data as soon as the original purpose for storing it no longer applies. We may retain your data for longer if required by European or national regulations, laws, or other legal provisions that apply to us. Your data will also be restricted or deleted once these mandatory storage periods expire, unless further storage is necessary to conclude or fulfill a contract with you.

Hosting Solutions

Hosting Solutions

External Hosting

External Hosting

This website is hosted by an external service provider (host). Any personal data collected on this website is stored on our host's servers. This primarily includes IP addresses, contact requests, meta and communication data, contract details, contact information, names, website access logs, and any other data generated through a website.

 

We use this hosting service to fulfill our contractual obligations to potential and existing customers (Art. 6 para. 1 lit. b GDPR) and to ensure our online services are provided securely, quickly, and efficiently by a professional provider (Art. 6 para. 1 lit. f GDPR).

 

Our host will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.

This website is hosted by an external service provider (host). Any personal data collected on this website is stored on our host's servers. This primarily includes IP addresses, contact requests, meta and communication data, contract details, contact information, names, website access logs, and any other data generated through a website.

 

We use this hosting service to fulfill our contractual obligations to potential and existing customers (Art. 6 para. 1 lit. b GDPR) and to ensure our online services are provided securely, quickly, and efficiently by a professional provider (Art. 6 para. 1 lit. f GDPR).

 

Our host will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.

Our website is proudly hosted by Framer:

Our website is proudly hosted by Framer:

Framer BV, Rozengracht 207B, 1016 LZ Amsterdam, Netherlands.

Framer stores essential technical data (such as IP addresses in log files) to ensure the website runs securely and smoothly. We have a data processing agreement in place with Framer. For more details, please visit:
https://www.framer.com/legal/privacy-statement/

Framer BV, Rozengracht 207B, 1016 LZ Amsterdam, Netherlands.

Framer stores essential technical data (such as IP addresses in log files) to ensure the website runs securely and smoothly. We have a data processing agreement in place with Framer. For more details, please visit:
https://www.framer.com/legal/privacy-statement/

Data Controller & Data Protection Officer

Data Controller & Data Protection Officer

Name and address of the responsible party

Name and address of the responsible party

The controller responsible under the General Data Protection Regulation (GDPR) and other national data protection laws of the member states, as well as other data protection regulations, is:

The controller responsible under the General Data Protection Regulation (GDPR) and other national data protection laws of the member states, as well as other data protection regulations, is:

design for human nature GmbH

Lippeltstraße 1

20097 Hamburg
Germany

design for human nature GmbH

Lippeltstraße 1

20097 Hamburg
Germany

Phone: +49 (0) 40 51 00 00

Email: mail@designforhumannature.de

Phone: +49 (0) 40 51 00 00

Email: mail@designforhumannature.de

Name and contact details of our Data Protection Officer

Name and contact details of our Data Protection Officer

The contact details for our Data Protection Officer are:

The contact details for our Data Protection Officer are:

Dieter Grohmann
Data Protection & Privacy

Welserstr. 3
87463 Dietmannsried
Germany

Dieter Grohmann
Data Protection & Privacy

Welserstr. 3
87463 Dietmannsried
Germany

Phone: +49 (0) 8374 5865 263

Email: info@datenschutzprivacy.de

Website: www.datenschutzprivacy.de

Phone: +49 (0) 8374 5865 263

Email: info@datenschutzprivacy.de

Website: www.datenschutzprivacy.de

Definitions

Definitions

This privacy policy is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (hereinafter referred to as "GDPR"). We want our privacy policy to be clear and easy to understand. To ensure this, we have outlined and explained the key terms below:

 

a)    Personal data refers to any information relating to an identified or identifiable natural person (hereinafter "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

b)    Data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.

c)    Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

d)    Profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.

e)    Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

f)     Controller or controller responsible for the processing is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

g)    Processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

h)    Recipient is a natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

i)     Third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Consent is any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

This privacy policy is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (hereinafter referred to as "GDPR"). We want our privacy policy to be clear and easy to understand. To ensure this, we have outlined and explained the key terms below:

 

a)    Personal data refers to any information relating to an identified or identifiable natural person (hereinafter "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

b)    Data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.

c)    Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

d)    Profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.

e)    Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

f)     Controller or controller responsible for the processing is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

g)    Processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

h)    Recipient is a natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

i)     Third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Consent is any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Website hosting and log file management

Website hosting and log file management

If you use our website purely for informational purposes—meaning you do not register or otherwise share information with us—we automatically collect the following data and information from your computer system each time you visit:

 

a)    Your IP address

b)    Information about your browser type and version

c)     Your operating system

d)    Your internet service provider

e)    Date and time of your visit

f)     Websites that your system accesses via our website

g)    Content of your requests (specific pages visited)

h)    Amount of data transferred in each case

i)      Language and version of your browser software

 

This data is also stored in our system's log files. We do not store this data alongside any of your other personal information.

 

The legal basis for temporarily storing log files is Art. 6 (1) (f) GDPR.

 

Temporarily storing your IP address is necessary for our system to:

a)    Deliver the website to your computer. To do this, your IP address must remain stored for the duration of your session.

b)    Optimize our website content and related promotions.

c)     Ensure the continued functionality and security of our IT systems and website technology.

d)    Provide law enforcement authorities with the information required for prosecution in the event of a cyberattack.

 

Storing this data in log files helps us keep the website running smoothly, optimize its performance, and secure our IT systems. We do not analyze this data for marketing purposes.

 

These purposes represent our legitimate interest in processing the data under Art. 6 (1) (f) GDPR.

 

The data is deleted as soon as it is no longer needed to achieve the purpose of its collection—which, in this case, is when your website session ends.

For data stored in log files, this deletion happens after seven days at the latest. We may store data beyond this period, but if we do, IP addresses are deleted or anonymized so they can no longer be linked to you or your device.

 

Collecting this data to deliver the website and storing it in log files is essential for running the website. Therefore, there is no option to opt out of this processing.

If you use our website purely for informational purposes—meaning you do not register or otherwise share information with us—we automatically collect the following data and information from your computer system each time you visit:

 

a)    Your IP address

b)    Information about your browser type and version

c)     Your operating system

d)    Your internet service provider

e)    Date and time of your visit

f)     Websites that your system accesses via our website

g)    Content of your requests (specific pages visited)

h)    Amount of data transferred in each case

i)      Language and version of your browser software

 

This data is also stored in our system's log files. We do not store this data alongside any of your other personal information.

 

The legal basis for temporarily storing log files is Art. 6 (1) (f) GDPR.

 

Temporarily storing your IP address is necessary for our system to:

a)    Deliver the website to your computer. To do this, your IP address must remain stored for the duration of your session.

b)    Optimize our website content and related promotions.

c)     Ensure the continued functionality and security of our IT systems and website technology.

d)    Provide law enforcement authorities with the information required for prosecution in the event of a cyberattack.

 

Storing this data in log files helps us keep the website running smoothly, optimize its performance, and secure our IT systems. We do not analyze this data for marketing purposes.

 

These purposes represent our legitimate interest in processing the data under Art. 6 (1) (f) GDPR.

 

The data is deleted as soon as it is no longer needed to achieve the purpose of its collection—which, in this case, is when your website session ends.

For data stored in log files, this deletion happens after seven days at the latest. We may store data beyond this period, but if we do, IP addresses are deleted or anonymized so they can no longer be linked to you or your device.

 

Collecting this data to deliver the website and storing it in log files is essential for running the website. Therefore, there is no option to opt out of this processing.

How we use cookies

How we use cookies

This website uses cookies.

Cookies are small text files that are sent to your browser by a web server when you visit a website. They are stored locally on your device (PC, laptop, tablet, smartphone, etc.) to help us provide you with a better, more secure user experience. Cookies allow us to analyze how our site is used—such as how often pages are visited and how users interact with them—so we can continually improve our service. They do not harm your computer and do not contain viruses. Each cookie contains a unique identifier (a cookie ID) that allows our system to recognize your browser when you return to our website.

Cookies can remain stored even after you close your browser, making your next visit smoother. Because cookies are saved directly on your device, you have complete control over how they are used. If you prefer not to have cookies active, you can adjust your browser settings to notify you when cookies are set, to block them entirely, or to delete them individually. Please note, however, that disabling cookies may limit some of the features and functionality of our website. Any session cookies we use are automatically deleted as soon as you leave the site.

This website uses cookies.

Cookies are small text files that are sent to your browser by a web server when you visit a website. They are stored locally on your device (PC, laptop, tablet, smartphone, etc.) to help us provide you with a better, more secure user experience. Cookies allow us to analyze how our site is used—such as how often pages are visited and how users interact with them—so we can continually improve our service. They do not harm your computer and do not contain viruses. Each cookie contains a unique identifier (a cookie ID) that allows our system to recognize your browser when you return to our website.

Cookies can remain stored even after you close your browser, making your next visit smoother. Because cookies are saved directly on your device, you have complete control over how they are used. If you prefer not to have cookies active, you can adjust your browser settings to notify you when cookies are set, to block them entirely, or to delete them individually. Please note, however, that disabling cookies may limit some of the features and functionality of our website. Any session cookies we use are automatically deleted as soon as you leave the site.

SHARING YOUR PERSONAL DATA

SHARING YOUR PERSONAL DATA

Information on data transfers to third countries with limited data protection, and to US companies certified under the Data Privacy Framework (DPF)

Information on data transfers to third countries with limited data protection, and to US companies certified under the Data Privacy Framework (DPF)

We use tools from companies based in non-secure third countries, as well as US tools whose providers are certified under the EU-US Data Privacy Framework (DPF).


When these tools are active, your personal data may be transferred to and processed in these countries. Please note that the US, as a secure third country, generally offers a level of data protection comparable to that of the EU. Consequently, data transfers to the US are permitted if the recipient is certified under the "EU-US Data Privacy Framework" (DPF) or has appropriate additional safeguards in place.


Under the European Commission's adequacy decision (Art. 45 para. 3 GDPR), the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list), and standard contractual clauses, the provider of these tools commits to maintaining European data protection standards in accordance with the GDPR when processing your personal data, even when that data is processed in the US.


We use tools from companies based in non-secure third countries, as well as US tools whose providers are certified under the EU-US Data Privacy Framework (DPF).


When these tools are active, your personal data may be transferred to and processed in these countries. Please note that the US, as a secure third country, generally offers a level of data protection comparable to that of the EU. Consequently, data transfers to the US are permitted if the recipient is certified under the "EU-US Data Privacy Framework" (DPF) or has appropriate additional safeguards in place.


Under the European Commission's adequacy decision (Art. 45 para. 3 GDPR), the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list), and standard contractual clauses, the provider of these tools commits to maintaining European data protection standards in accordance with the GDPR when processing your personal data, even when that data is processed in the US.


Privacy Policy for our use of Framer

Privacy Policy for our use of Framer

We use the services of Framer, Inc. (548 Market St PMB 35992, San Francisco, CA 94104, USA) on our website as an all-in-one CMS system. This allows us to deliver, manage, and analyze our content as well as understand how users navigate our site. Framer enables us to create interactive websites without code and places cookies and tracking scripts on your device for these purposes.

 

Data Processor
Framer, Inc.
548 Market St PMB 35992
San Francisco, CA 94104
USA
Email: support@framer.com

 

Privacy Inquiries
https://www.framer.com/legal/privacy-statement

 

Purpose of Data Processing
On our behalf, Framer uses this information to deliver the website, analyze how you use it, and generate reports on website activity. By analyzing this data, we can understand how different parts of our website are used, helping us continuously improve our website and enhance your user experience.

 

Types of Data Collected
When you visit pages on our website, the following data is saved (pseudonymized using IP anonymization):

  • The visited web page

  • Entry and exit pages

  • Time spent on the website and bounce rate

  • How often the website is accessed

  • Country and regional origin, language, browser, operating system, screen resolution

  • Search engines and search terms used

  • Device IDs, events, and user interactions (e.g., clicks, scrolls, animations)
    IP addresses are pseudonymized before storage (IP anonymization: the last octets are deleted or hashed).

 

Data Sharing
The information generated by cookies and scripts about your use of this website is typically transferred to and stored on a Framer server in the USA.

 

Processing Location and Control
The cookies used are stored on your device and transmitted from there to our site. If you do not agree to the collection and evaluation of this usage data, you can prevent it by disabling or restricting cookies in your browser settings. You can also delete stored cookies at any time. Please note, however, that disabling cookies may limit your ability to use all the features of this website. Additionally, you can block the collection of data generated by cookies/scripts relating to your website use (including your IP address) by using browser extensions like uBlock Origin or AdBlock to stop Framer scripts. For detailed cookie control, we recommend using tools like Global Privacy Control (GPC) or consent management platforms.

 

Adequacy Decision // Data Privacy Framework // SCC
Under the European Commission's adequacy decision (Art. 45 para. 3 GDPR), the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/?utm_source=pryvet_ai), and Standard Contractual Clauses (SCC), the processing company is committed to maintaining European data protection standards in line with the GDPR, even when data is processed in the USA.

 

Retention Period
We only store your personal data for as long as necessary for the respective purpose or as required by statutory retention periods. Once the processing purpose no longer applies, the data is deleted, unless legal retention obligations prevent this.
The data is deleted as soon as it is no longer required for our records. In our case, this occurs after 14 months (the default configuration for Framer Analytics and Logs).

 

Legal Basis
Art. 6 para. 1 lit. a GDPR (Consent)

 

Your Rights
You have the right to request access to the personal data we store about you. You also have the right to request the correction, deletion, or restriction of the processing of your data, as well as the right to data portability. You can withdraw your consent at any time.

We use the services of Framer, Inc. (548 Market St PMB 35992, San Francisco, CA 94104, USA) on our website as an all-in-one CMS system. This allows us to deliver, manage, and analyze our content as well as understand how users navigate our site. Framer enables us to create interactive websites without code and places cookies and tracking scripts on your device for these purposes.

 

Data Processor
Framer, Inc.
548 Market St PMB 35992
San Francisco, CA 94104
USA
Email: support@framer.com

 

Privacy Inquiries
https://www.framer.com/legal/privacy-statement

 

Purpose of Data Processing
On our behalf, Framer uses this information to deliver the website, analyze how you use it, and generate reports on website activity. By analyzing this data, we can understand how different parts of our website are used, helping us continuously improve our website and enhance your user experience.

 

Types of Data Collected
When you visit pages on our website, the following data is saved (pseudonymized using IP anonymization):

  • The visited web page

  • Entry and exit pages

  • Time spent on the website and bounce rate

  • How often the website is accessed

  • Country and regional origin, language, browser, operating system, screen resolution

  • Search engines and search terms used

  • Device IDs, events, and user interactions (e.g., clicks, scrolls, animations)
    IP addresses are pseudonymized before storage (IP anonymization: the last octets are deleted or hashed).

 

Data Sharing
The information generated by cookies and scripts about your use of this website is typically transferred to and stored on a Framer server in the USA.

 

Processing Location and Control
The cookies used are stored on your device and transmitted from there to our site. If you do not agree to the collection and evaluation of this usage data, you can prevent it by disabling or restricting cookies in your browser settings. You can also delete stored cookies at any time. Please note, however, that disabling cookies may limit your ability to use all the features of this website. Additionally, you can block the collection of data generated by cookies/scripts relating to your website use (including your IP address) by using browser extensions like uBlock Origin or AdBlock to stop Framer scripts. For detailed cookie control, we recommend using tools like Global Privacy Control (GPC) or consent management platforms.

 

Adequacy Decision // Data Privacy Framework // SCC
Under the European Commission's adequacy decision (Art. 45 para. 3 GDPR), the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/?utm_source=pryvet_ai), and Standard Contractual Clauses (SCC), the processing company is committed to maintaining European data protection standards in line with the GDPR, even when data is processed in the USA.

 

Retention Period
We only store your personal data for as long as necessary for the respective purpose or as required by statutory retention periods. Once the processing purpose no longer applies, the data is deleted, unless legal retention obligations prevent this.
The data is deleted as soon as it is no longer required for our records. In our case, this occurs after 14 months (the default configuration for Framer Analytics and Logs).

 

Legal Basis
Art. 6 para. 1 lit. a GDPR (Consent)

 

Your Rights
You have the right to request access to the personal data we store about you. You also have the right to request the correction, deletion, or restriction of the processing of your data, as well as the right to data portability. You can withdraw your consent at any time.

Data transfer upon contract conclusion for services and digital content

Data transfer upon contract conclusion for services and digital content

We only share your personal data with third parties when it is necessary to fulfill your contract—for example, with the financial institution processing your payment.


We do not share your data beyond this unless you have given us your explicit consent. Your data will never be passed on to third parties for marketing or advertising purposes without your clear approval.


The legal basis for processing your data is Art. 6 (1) (b) GDPR, which permits the processing of data to fulfill a contract or to carry out pre-contractual measures.


We only share your personal data with third parties when it is necessary to fulfill your contract—for example, with the financial institution processing your payment.


We do not share your data beyond this unless you have given us your explicit consent. Your data will never be passed on to third parties for marketing or advertising purposes without your clear approval.


The legal basis for processing your data is Art. 6 (1) (b) GDPR, which permits the processing of data to fulfill a contract or to carry out pre-contractual measures.


Links to external websites

Links to external websites

Our website provides various ways to get in touch with us, including email, phone, and our postal address. If you choose to contact us, we will securely store and process any personal details you share with your enquiry (such as your name, email address, phone number, company, and message).

 

For technical and security reasons, the following information is also automatically saved when you reach out:

  • User's IP address (recorded in email server logs)

  • Date and time of your enquiry

 

We treat your information with complete confidentiality. It will never be shared with third parties and is used solely to assist you and answer your enquiry.

 

Purpose of data processing
We process this information simply to handle your enquiry and ensure clear communication. If you share contact details like your email address or phone number, we will use them to get back to you through those channels.

 

Legal basis
We process your data based on:

  • Art. 6 (1) (b) GDPR, if your enquiry relates to preparing or fulfilling a contract with you.

  • Art. 6 (1) (f) GDPR (our legitimate interest in managing and responding to enquiries efficiently).

  • Art. 6 (1) (a) GDPR (consent), where explicitly requested and provided.

The technical data (such as IP addresses and timestamps) is processed to keep our systems secure and prevent misuse (our legitimate interest in line with Art. 6 (1) (f) GDPR).

 

Retention period
We only keep your data for as long as needed to fulfill the purpose of your enquiry. This means we delete your information once our conversation with you is complete and the matter has been fully resolved. Technical logs (such as IP addresses) are deleted after 7 days at the latest. Any statutory storage requirements (such as commercial or tax law retention periods) remain unaffected.

 

Your rights
You have the right to request access to the personal data we hold about you. You can also request that we correct, delete, or restrict the processing of your data, or ask for a copy of your data in a portable format. You can withdraw your consent or object to the storage of your data at any time by emailing us or our Data Protection Officer. Please note that if you object, we will not be able to continue our conversation, and all stored data will be deleted. To exercise your rights, please contact us by email or post.

Our website provides various ways to get in touch with us, including email, phone, and our postal address. If you choose to contact us, we will securely store and process any personal details you share with your enquiry (such as your name, email address, phone number, company, and message).

 

For technical and security reasons, the following information is also automatically saved when you reach out:

  • User's IP address (recorded in email server logs)

  • Date and time of your enquiry

 

We treat your information with complete confidentiality. It will never be shared with third parties and is used solely to assist you and answer your enquiry.

 

Purpose of data processing
We process this information simply to handle your enquiry and ensure clear communication. If you share contact details like your email address or phone number, we will use them to get back to you through those channels.

 

Legal basis
We process your data based on:

  • Art. 6 (1) (b) GDPR, if your enquiry relates to preparing or fulfilling a contract with you.

  • Art. 6 (1) (f) GDPR (our legitimate interest in managing and responding to enquiries efficiently).

  • Art. 6 (1) (a) GDPR (consent), where explicitly requested and provided.

The technical data (such as IP addresses and timestamps) is processed to keep our systems secure and prevent misuse (our legitimate interest in line with Art. 6 (1) (f) GDPR).

 

Retention period
We only keep your data for as long as needed to fulfill the purpose of your enquiry. This means we delete your information once our conversation with you is complete and the matter has been fully resolved. Technical logs (such as IP addresses) are deleted after 7 days at the latest. Any statutory storage requirements (such as commercial or tax law retention periods) remain unaffected.

 

Your rights
You have the right to request access to the personal data we hold about you. You can also request that we correct, delete, or restrict the processing of your data, or ask for a copy of your data in a portable format. You can withdraw your consent or object to the storage of your data at any time by emailing us or our Data Protection Officer. Please note that if you object, we will not be able to continue our conversation, and all stored data will be deleted. To exercise your rights, please contact us by email or post.

Apply by email or phone

Apply by email or phone

On our website, under the "Jobs" tab, you will find contact details for applications via email and phone. If you choose to contact us using one of these options, the personal data you share with your application (e.g., name, email address, phone number, company, cover letter, CV, certificates, qualifications, interview notes) will be sent to us, stored, and processed.

 

We assure you that we collect, process, and use your data in full compliance with applicable data protection laws and all other legal regulations, and treat your information as strictly confidential. Your data will not be shared with third parties. Within our company, your data will only be shared with individuals who are directly involved in processing your application.

 

Purpose of data processing
The processing of this data serves solely to evaluate your application for employment and, if successful, to manage and carry out the employment relationship.

 

Legal basis

  • Section 26 BDSG in conjunction with Art. 88 GDPR (initiation and performance of an employment relationship).

  • Art. 6 (1) (b) GDPR (contract initiation and performance).

  • Art. 6 (1) (a) GDPR (consent), where this has been given.

 

You may withdraw your consent at any time.

 

Retention period

  • For successful applications: Based on Section 26 BDSG and Art. 6 (1) (b) GDPR, your data will be stored in our systems for the duration of your employment as necessary. This does not affect mandatory legal retention periods (e.g., under labor or tax law).

  • For unsuccessful applications, withdrawals, or rejected offers: Your data will be stored for a maximum of 6 months after the recruitment process is completed (retention period) so that we can reconstruct the application process in the event of any queries or disputes (Art. 6 (1) (f) GDPR).

 

YOU HAVE THE RIGHT TO OBJECT TO THIS STORAGE IF YOU HAVE LEGITIMATE INTERESTS THAT OUTWEIGH OUR OWN.

Once the retention period expires, your data will be deleted unless there is a legal obligation to retain it or another legal basis for continued storage (such as pending litigation).

 

Your rights
You have the right to request information about the personal data we store about you. You also have the right to correct, delete, or restrict the processing of your data, as well as the right to data portability. You can withdraw your consent or object to the storage of your data at any time (by emailing the controller or data protection officer). If you choose to do so, we will stop processing your application and delete all stored data. Please contact us by email or post to exercise these rights.

On our website, under the "Jobs" tab, you will find contact details for applications via email and phone. If you choose to contact us using one of these options, the personal data you share with your application (e.g., name, email address, phone number, company, cover letter, CV, certificates, qualifications, interview notes) will be sent to us, stored, and processed.

 

We assure you that we collect, process, and use your data in full compliance with applicable data protection laws and all other legal regulations, and treat your information as strictly confidential. Your data will not be shared with third parties. Within our company, your data will only be shared with individuals who are directly involved in processing your application.

 

Purpose of data processing
The processing of this data serves solely to evaluate your application for employment and, if successful, to manage and carry out the employment relationship.

 

Legal basis

  • Section 26 BDSG in conjunction with Art. 88 GDPR (initiation and performance of an employment relationship).

  • Art. 6 (1) (b) GDPR (contract initiation and performance).

  • Art. 6 (1) (a) GDPR (consent), where this has been given.

 

You may withdraw your consent at any time.

 

Retention period

  • For successful applications: Based on Section 26 BDSG and Art. 6 (1) (b) GDPR, your data will be stored in our systems for the duration of your employment as necessary. This does not affect mandatory legal retention periods (e.g., under labor or tax law).

  • For unsuccessful applications, withdrawals, or rejected offers: Your data will be stored for a maximum of 6 months after the recruitment process is completed (retention period) so that we can reconstruct the application process in the event of any queries or disputes (Art. 6 (1) (f) GDPR).

 

YOU HAVE THE RIGHT TO OBJECT TO THIS STORAGE IF YOU HAVE LEGITIMATE INTERESTS THAT OUTWEIGH OUR OWN.

Once the retention period expires, your data will be deleted unless there is a legal obligation to retain it or another legal basis for continued storage (such as pending litigation).

 

Your rights
You have the right to request information about the personal data we store about you. You also have the right to correct, delete, or restrict the processing of your data, as well as the right to data portability. You can withdraw your consent or object to the storage of your data at any time (by emailing the controller or data protection officer). If you choose to do so, we will stop processing your application and delete all stored data. Please contact us by email or post to exercise these rights.

Secure SSL encryption

Secure SSL encryption

For your security and to protect your confidential information—such as inquiries you send to us—this website uses SSL encryption. You can easily verify that your connection is secure: the address bar in your browser will change from "http://" to "https://" and a padlock icon will appear. When SSL encryption is active, the data you share with us cannot be read by anyone else.

For your security and to protect your confidential information—such as inquiries you send to us—this website uses SSL encryption. You can easily verify that your connection is secure: the address bar in your browser will change from "http://" to "https://" and a padlock icon will appear. When SSL encryption is active, the data you share with us cannot be read by anyone else.

Your privacy rights

Your privacy rights

If your personal data is being processed, you are considered a data subject under the GDPR. This grants you the following rights in relation to the data controller:

 

Right of Access

You have the right to request confirmation from the controller as to whether we are processing your personal data. If we are, you can request access to this personal data free of charge at any time, along with the following information:

 

a)    the purposes of the processing;

b)    the categories of personal data being processed;

c)     the recipients or categories of recipients to whom your personal data has been or will be disclosed;

d)    the planned storage period for your personal data or, if specific details cannot be provided, the criteria used to determine this period;

e)    your right to request the rectification or erasure of your personal data, your right to restrict its processing by the controller, or your right to object to such processing;

f)     your right to lodge a complaint with a supervisory authority;

g)    any available information regarding the source of the data, if it was not collected directly from you;

h)    the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR, and—at least in these cases—meaningful information about the logic involved, as well as the significance and envisioned consequences of such processing for you.

 

You also have the right to know whether your personal data is transferred to a third country or an international organization. In this case, you can request to be informed of the appropriate safeguards in place under Article 46 of the GDPR regarding the transfer.

 

Right to Rectification

You have the right to have any inaccurate or incomplete personal data concerning you corrected or completed by the controller without delay.

 

Right to Restriction of Processing

You can request that the controller restrict the processing of your personal data under the following conditions:

 

a)    if you contest the accuracy of your personal data, for a period enabling the controller to verify its accuracy;

b)    if the processing is unlawful and you oppose the erasure of the personal data, requesting instead that its use be restricted;

c)     if the controller no longer needs the personal data for processing, but you require it to establish, exercise, or defend legal claims; or

d)    if you have objected to the processing pursuant to Article 21(1) of the GDPR, pending verification of whether the controller’s legitimate grounds override yours.

 

Where processing has been restricted, such data—apart from storage—may only be processed with your consent, to establish, exercise, or defend legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the EU or a Member State. If processing has been restricted under these conditions, the controller will inform you before the restriction is lifted.

 

Right to Erasure

You can request the controller to delete your personal data without delay if one of the following reasons applies:

 

a)    Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed.

b)    You withdraw the consent on which the processing was based under Article 6(1)(a) or Article 9(2)(a) of the GDPR, and there is no other legal basis for the processing.

c)     You object to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing for direct marketing purposes pursuant to Article 21(2) of the GDPR.

d)    Your personal data has been processed unlawfully.

e)    Your personal data must be erased to comply with a legal obligation under Union or Member State law to which the controller is subject.

f)     Your personal data was collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR.

 

If the controller has made your personal data public and is required to erase it under Article 17(1) of the GDPR, they will take reasonable steps—including technical measures, considering available technology and implementation costs—to inform other controllers processing the data that you have requested the deletion of any links to, or copies or replications of, that personal data.

 

The right to erasure does not apply if the processing is necessary:

 

a)    for exercising the right of freedom of expression and information;

b)    for compliance with a legal obligation under Union or Member State law to which the controller is subject, or for performing a task carried out in the public interest or in the exercise of official authority vested in the controller;

c)     for reasons of public interest in the area of public health in accordance with Article 9(2)(h) and (i) and Article 9(3) of the GDPR;

d)    for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1) of the GDPR, insofar as the right referred to in section (a) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

e)    for the establishment, exercise, or defense of legal claims.

 

Right to Notification

If you have exercised your right to rectification, erasure, or restriction of processing, the controller is required to communicate this to each recipient to whom your personal data has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right to be informed about who these recipients are.

 

Right to Data Portability

You have the right to receive the personal data you provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the data was originally provided, provided that:

 

a)    the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, or on a contract pursuant to Article 6(1)(b) of the GDPR; and

b)    the processing is carried out by automated means.

 

In exercising this right, you can also request that your personal data be transmitted directly from one controller to another, where technically feasible. This must not adversely affect the rights and freedoms of others.

 

The right to data portability does not apply to processing that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

 

To exercise your right to data portability, you can contact the data controller at any time.

 

Right to Object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on these provisions.

 

The controller will stop processing your personal data unless they can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or if the processing is necessary to establish, exercise, or defend legal claims.

 

If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your data for such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes.

 

In the context of the use of information society services—and notwithstanding Directive 2002/58/EC—you may exercise your right to object by automated means using technical specifications.

 

To exercise your right to object, you can contact the data controller directly.

 

Right to Withdraw Consent

You have the right to withdraw your consent to data processing at any time. Withdrawing your consent does not affect the lawfulness of any processing carried out before the withdrawal. You can contact the controller to exercise this right.

 

Automated Individual Decision-Making, Including Profiling

You have the right not to be subject to a decision based solely on automated processing—including profiling—which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision:

 

a)    is necessary for entering into, or performing, a contract between you and the controller;

b)    is authorized by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights, freedoms, and legitimate interests; or

c)     is based on your explicit consent.

 

However, these decisions must not be based on special categories of personal data referred to in Article 9(1) of the GDPR, unless Article 9(2)(a) or (g) applies and suitable measures to safeguard your rights, freedoms, and legitimate interests are in place.

 

In the cases referred to in points (1) and (3), the controller will implement suitable measures to safeguard your rights, freedoms, and legitimate interests, which include at least the right to obtain human intervention on the part of the controller, to express your point of view, and to contest the decision.

 

If you wish to exercise your rights regarding automated decision-making, you can contact the data controller at any time.

 

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR. The supervisory authority with which the complaint has been lodged will keep you updated on the progress and outcome of your complaint, including the possibility of a judicial remedy pursuant to Article 78 of the GDPR.

If your personal data is being processed, you are considered a data subject under the GDPR. This grants you the following rights in relation to the data controller:

 

Right of Access

You have the right to request confirmation from the controller as to whether we are processing your personal data. If we are, you can request access to this personal data free of charge at any time, along with the following information:

 

a)    the purposes of the processing;

b)    the categories of personal data being processed;

c)     the recipients or categories of recipients to whom your personal data has been or will be disclosed;

d)    the planned storage period for your personal data or, if specific details cannot be provided, the criteria used to determine this period;

e)    your right to request the rectification or erasure of your personal data, your right to restrict its processing by the controller, or your right to object to such processing;

f)     your right to lodge a complaint with a supervisory authority;

g)    any available information regarding the source of the data, if it was not collected directly from you;

h)    the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR, and—at least in these cases—meaningful information about the logic involved, as well as the significance and envisioned consequences of such processing for you.

 

You also have the right to know whether your personal data is transferred to a third country or an international organization. In this case, you can request to be informed of the appropriate safeguards in place under Article 46 of the GDPR regarding the transfer.

 

Right to Rectification

You have the right to have any inaccurate or incomplete personal data concerning you corrected or completed by the controller without delay.

 

Right to Restriction of Processing

You can request that the controller restrict the processing of your personal data under the following conditions:

 

a)    if you contest the accuracy of your personal data, for a period enabling the controller to verify its accuracy;

b)    if the processing is unlawful and you oppose the erasure of the personal data, requesting instead that its use be restricted;

c)     if the controller no longer needs the personal data for processing, but you require it to establish, exercise, or defend legal claims; or

d)    if you have objected to the processing pursuant to Article 21(1) of the GDPR, pending verification of whether the controller’s legitimate grounds override yours.

 

Where processing has been restricted, such data—apart from storage—may only be processed with your consent, to establish, exercise, or defend legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the EU or a Member State. If processing has been restricted under these conditions, the controller will inform you before the restriction is lifted.

 

Right to Erasure

You can request the controller to delete your personal data without delay if one of the following reasons applies:

 

a)    Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed.

b)    You withdraw the consent on which the processing was based under Article 6(1)(a) or Article 9(2)(a) of the GDPR, and there is no other legal basis for the processing.

c)     You object to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing for direct marketing purposes pursuant to Article 21(2) of the GDPR.

d)    Your personal data has been processed unlawfully.

e)    Your personal data must be erased to comply with a legal obligation under Union or Member State law to which the controller is subject.

f)     Your personal data was collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR.

 

If the controller has made your personal data public and is required to erase it under Article 17(1) of the GDPR, they will take reasonable steps—including technical measures, considering available technology and implementation costs—to inform other controllers processing the data that you have requested the deletion of any links to, or copies or replications of, that personal data.

 

The right to erasure does not apply if the processing is necessary:

 

a)    for exercising the right of freedom of expression and information;

b)    for compliance with a legal obligation under Union or Member State law to which the controller is subject, or for performing a task carried out in the public interest or in the exercise of official authority vested in the controller;

c)     for reasons of public interest in the area of public health in accordance with Article 9(2)(h) and (i) and Article 9(3) of the GDPR;

d)    for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1) of the GDPR, insofar as the right referred to in section (a) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

e)    for the establishment, exercise, or defense of legal claims.

 

Right to Notification

If you have exercised your right to rectification, erasure, or restriction of processing, the controller is required to communicate this to each recipient to whom your personal data has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right to be informed about who these recipients are.

 

Right to Data Portability

You have the right to receive the personal data you provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the data was originally provided, provided that:

 

a)    the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, or on a contract pursuant to Article 6(1)(b) of the GDPR; and

b)    the processing is carried out by automated means.

 

In exercising this right, you can also request that your personal data be transmitted directly from one controller to another, where technically feasible. This must not adversely affect the rights and freedoms of others.

 

The right to data portability does not apply to processing that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

 

To exercise your right to data portability, you can contact the data controller at any time.

 

Right to Object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on these provisions.

 

The controller will stop processing your personal data unless they can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or if the processing is necessary to establish, exercise, or defend legal claims.

 

If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your data for such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes.

 

In the context of the use of information society services—and notwithstanding Directive 2002/58/EC—you may exercise your right to object by automated means using technical specifications.

 

To exercise your right to object, you can contact the data controller directly.

 

Right to Withdraw Consent

You have the right to withdraw your consent to data processing at any time. Withdrawing your consent does not affect the lawfulness of any processing carried out before the withdrawal. You can contact the controller to exercise this right.

 

Automated Individual Decision-Making, Including Profiling

You have the right not to be subject to a decision based solely on automated processing—including profiling—which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision:

 

a)    is necessary for entering into, or performing, a contract between you and the controller;

b)    is authorized by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights, freedoms, and legitimate interests; or

c)     is based on your explicit consent.

 

However, these decisions must not be based on special categories of personal data referred to in Article 9(1) of the GDPR, unless Article 9(2)(a) or (g) applies and suitable measures to safeguard your rights, freedoms, and legitimate interests are in place.

 

In the cases referred to in points (1) and (3), the controller will implement suitable measures to safeguard your rights, freedoms, and legitimate interests, which include at least the right to obtain human intervention on the part of the controller, to express your point of view, and to contest the decision.

 

If you wish to exercise your rights regarding automated decision-making, you can contact the data controller at any time.

 

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR. The supervisory authority with which the complaint has been lodged will keep you updated on the progress and outcome of your complaint, including the possibility of a judicial remedy pursuant to Article 78 of the GDPR.

Privacy Policy Updates

Privacy Policy Updates

We may update our privacy practices and this policy from time to time to keep up with changing laws or to better serve your needs. Any updates will be posted directly on this page, so please check back periodically to review the latest version date.

We may update our privacy practices and this policy from time to time to keep up with changing laws or to better serve your needs. Any updates will be posted directly on this page, so please check back periodically to review the latest version date.

DfHN

Design for Human Nature

Studio

Lippeltstraße 1

20097 Hamburg

Ponton

Entenwerder 1

20539 Hamburg

DfHN

Design for Human Nature

Studio

Lippeltstraße 1

20097 Hamburg

Ponton

Entenwerder 1

20539 Hamburg