Privacy policy
1. Controller
IFATEC Privat-Institut für angewandte Technologie GmbHBrixener Str. 13, 94036 Passau, Germany
Managing Director: Robert Maier
Contact details: see Legal notice.
2. Principles
We process personal data only to the extent required to operate this website, handle contact initiated by you or – with your consent – conduct our own reach and interaction analytics. We do not use external advertising or social-media trackers and do not use Matomo.
3. Hosting and server data
The site is hosted by INWX GmbH, Prinzessinnenstr. 30, 10969 Berlin, Germany. Web servers and hosting infrastructure may technically process IP address, date/time, requested resource, transferred volume, referrer and browser/system information. The purposes are secure and stable operation, attack prevention and fault analysis. The legal basis is Art. 6(1)(f) GDPR. Where we control retention, technical logs not otherwise required are generally deleted no later than 30 days, unless longer retention is necessary for security incidents or legal claims.
4. Required settings: privacy and language
Your choice “Required only” or “Allow analytics” is stored for up to 180 days using the first-party setting wmgg_consent and/or local browser storage. When you actively select a language, wmgg_lang (German/English) is stored for up to twelve months so that your language selection can be retained across pages and future visits. These settings provide functionality expressly requested by you.
5. Optional first-party analytics
Only after you choose “Allow analytics” do we store a random pseudonymous visitor identifier (wmgg_vid) for up to twelve months. We can then evaluate page views and selected interactions, including A/B/C/D information variants, WhatsApp and order/information clicks, PDF downloads, language changes and aggregated engagement time and scroll depth.
Analytics fields may include timestamp, pseudonymous visitor ID, page path, event, campaign, referrer domain, voluntarily supplied UTM parameters, device class, browser family, operating-system family, coarse screen-size class, browser/site language, browser time zone and whether the visit is new or returning. Country or region is stored only if our hosting infrastructure already supplies such a coarse server-side assignment. We do not use an external Geo-IP service.
Our own analytics do not store a full IP address or full user-agent string. Names, email addresses, telephone numbers, genetic data, laboratory values or other health data are not inferred from browsing behaviour and are not part of this analytics system.
The purpose is reach measurement, technical/content optimisation, evaluation of information variants and coarse technical/regional usage analysis. The legal basis is your consent under Art. 6(1)(a) GDPR; storage/access on your device is based on Section 25(1) TDDDG. Raw analytics data are deleted no later than 24 months.
6. External links
External services are not automatically embedded. A connection to an external provider is created only when you actively open an external link or redirect. From that point onward, the external provider’s privacy terms apply. Our NovoDaily redirect is configured to minimise referrer transmission.
7. WhatsApp and email
WhatsApp opens only after your active action. If you use WhatsApp or email, we process the data you voluntarily provide to handle your request under Art. 6(1)(b) GDPR for contractual/pre-contractual matters or Art. 6(1)(f) GDPR for other enquiries. Please do not send genetic, laboratory or other particularly sensitive health data via WhatsApp.
8. Recipients and transfers
The hosting provider may be involved as processor or recipient for technical operation. Our analytics run on our own hosting space and are not transmitted to an external analytics provider. Connections to WhatsApp or NovoDaily arise only after your active action.
9. Voluntary nature of analytics
Analytics consent is voluntary. The website and its information remain usable if you decline analytics.
10. Your rights
Subject to the statutory conditions, you have rights including access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent for the future (Art. 7(3)).
11. Complaint
You may lodge a complaint with a supervisory authority under Art. 77 GDPR. For a non-public company based in Bavaria, the competent authority is generally the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
12. No automated decision-making
This website does not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
13. Updates
This policy may be updated when functions, technical processes or legal requirements change.