Privacy Policy

Preamble

With this privacy policy we inform you which types of your personal data (hereinafter also referred to as "data") we process for which purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, and within external online presences, such as our social media profiles (collectively referred to as the "online offering").

The terms used are gender-neutral.

Last updated: 10 December 2025

Table of Contents

Controller

naion.tech GbR
Forckenbeckstr. 51
52074 Aachen

Authorized representative: Milan Abel

Email: [email protected]

Phone: +492418098095

Imprint: naion.tech/imprint

Overview of Processing

The following overview summarizes the types of data processed, the purposes of their processing, and the categories of data subjects.

Types of Data Processed

Categories of Data Subjects

Purposes of Processing

Relevant Legal Bases

Relevant legal bases under the GDPR: Below is an overview of the legal bases of the GDPR on which we process personal data. Please note that national data protection regulations in your or our country of residence may also apply. If more specific legal bases are relevant in individual cases, we will inform you in the privacy policy.

National data protection rules in Germany: In addition to the GDPR, national data protection regulations apply in Germany, particularly the Federal Data Protection Act (BDSG). The BDSG contains specific provisions on the right to information, deletion, objection, processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making including profiling. State data protection laws may also apply.

Security Measures

We take appropriate technical and organizational measures in accordance with legal requirements, considering the state of the art, implementation costs, the nature, scope, circumstances, and purposes of processing as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

Measures include safeguarding confidentiality, integrity, and availability of data by controlling physical and electronic access to data, as well as access, input, transmission, availability, and separation. We have procedures to ensure data subject rights, deletion of data, and responses to data threats. We also consider the protection of personal data during the development or selection of hardware, software, and procedures according to the principle of data protection by design and by default.

Securing online connections through TLS/SSL encryption (HTTPS): To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption. When a website is secured by an SSL/TLS certificate, HTTPS appears in the URL.

Transfer of Personal Data

In the course of processing personal data, it may be transferred to or disclosed to other entities, companies, legally independent organizations, or persons. Recipients may include IT service providers or providers of services and content that are embedded in a website. In such cases we comply with legal requirements and conclude corresponding contracts or agreements with recipients.

Data transfers within the organization: We may transfer personal data to other departments or units within our organization. If the data transfer is for administrative purposes, it is based on our legitimate business and commercial interests or is necessary to fulfill contractual obligations, provided consent or legal permission exists.

General Information on Data Storage and Deletion

We delete personal data we process in accordance with legal provisions as soon as consent is revoked or there is no other legal basis for processing. This applies when the original purpose no longer exists or the data is no longer needed, unless legal obligations or special interests require longer retention.

Data that must be retained for commercial or tax reasons or that is necessary to assert or defend legal claims will be archived accordingly. Our privacy notices contain additional information on retention and deletion of data for specific processing operations.

Where multiple retention periods are indicated, the longest period applies. Data retained for reasons other than the original purpose is processed only for those reasons.

Retention and deletion periods under German law:

If a period is not explicitly tied to a date and is at least one year, it begins at the end of the calendar year in which the triggering event occurred. For ongoing contracts, the event is the termination or other end of the relationship.

Rights of Data Subjects

Rights under the GDPR: As a data subject you have the following rights under Art. 15-21 GDPR:

Business Services

We process data of our contractual and business partners (e.g., customers and prospects) within contractual or similar legal relationships and related measures, and for communication with the partners (including pre-contractual), such as responding to inquiries.

We use this data to fulfill contractual obligations, including providing agreed services, updates, and remedies for warranty or performance issues. We also use the data to protect our rights and for administrative tasks and business organization. Data may be shared with third parties where necessary for the above purposes or legal obligations. We inform partners of further processing, such as for marketing, in this privacy policy.

We inform partners about required data before or during collection (e.g., in online forms by labels or symbols) or personally. We delete data after statutory warranty or comparable obligations expire, generally after four years, unless stored in a customer account or archived for legal reasons (e.g., tax retention typically ten years). Data disclosed to us in the course of an assignment is deleted as specified and generally after the end of the assignment.

Further notes on processing, procedures, and services:

Provision of the Online Offering and Web Hosting

We process user data to provide our online services. This requires processing the user's IP address to deliver content and functions to their browser or device.

Further notes on processing, procedures, and services:

Use of Cookies

"Cookies" are functions that store and read information on user devices. They can be used for functionality, security, comfort, and analytics. We use cookies according to legal requirements and obtain consent where required; otherwise, we rely on legitimate interests where storage and access are essential to provide expressly requested content and functions.

Legal basis notes: Whether we process personal data using cookies depends on consent. If consent is given, it is the legal basis; otherwise, we rely on legitimate interests as explained.

Storage duration:

General notes on withdrawal and objection (opt-out): Users can withdraw consent at any time and object to processing using browser privacy settings.

Further notes on processing, procedures, and services:

Contact and Inquiry Management

When contacting us (e.g., by post, contact form, email, phone, or social media) and within existing user and business relationships, we process the information provided by the inquiring persons as necessary to respond to inquiries and any requested measures.

Further notes on processing, procedures, and services:

Marketing Communication via Email, Post, Fax or Phone

We process personal data for marketing communication through channels such as email, phone, post, or fax in accordance with legal requirements. Recipients may withdraw consent or object at any time via the contact options above.

After withdrawal or objection, we retain the data necessary to prove prior authorization for up to three years after the end of the year of withdrawal/objection based on legitimate interests. We also store minimal data to avoid future contact where necessary.

Presence in Social Networks (Social Media)

We maintain online presences in social networks to communicate with users or provide information about us. User data may be processed outside the EU, potentially making enforcement of user rights more difficult.

User data is typically processed for market research and advertising. Usage profiles can be created based on user behavior and interests to serve ads likely matching user interests. Cookies may be stored on user devices to store usage behavior and interests. Usage profiles can also store data across devices (especially if users are logged in).

For detailed information on processing and opt-out options, see the privacy policies of the respective networks. For access or rights requests, please contact the network provider directly. If you need assistance, you may also contact us.

Further notes on processing, procedures, and services:

Plugins and Embedded Functions and Content

We integrate functional and content elements from third-party providers (e.g., graphics, videos, maps). This requires processing users' IP addresses to deliver the content. Third parties may also use pixel tags for statistics or marketing. Information may be stored in cookies on user devices and combined with data from other sources.

Legal basis notes: If we request user consent, that is the legal basis; otherwise, processing is based on our legitimate interests in efficient, economical, and user-friendly services. Please also see our notes on cookies.

Further notes on processing, procedures, and services:

Privacy Information for Whistleblowers

This section explains how we handle data from whistleblowers and affected parties in our whistleblowing process. Our goal is to provide a straightforward and secure way to report possible misconduct by us, our employees, or service providers.

Legal basis (Germany): Where we process data to fulfill statutory obligations under the German Whistleblower Protection Act (HinSchG), the legal basis is Art. 6(1)(c) GDPR (and for special categories Art. 9(2)(g) GDPR, Section 22 BDSG) in connection with Section 10 HinSchG. This covers the duty to operate an internal reporting office and related investigations or employment actions following confirmed violations.

Where we process data (especially when misconduct is found) for or in preparation of legal defense, processing is based on our legitimate interests in lawful and ethical conduct (Art. 6(1)(f) GDPR).

If you provide consent for certain purposes, processing is based on Art. 6(1)(a) GDPR; for special categories of data, Art. 9 may also apply.

Data types processed:

In receiving and handling reports and subsequent procedures, we may collect:

For fact-finding and follow-up, we may also process:

Special categories of personal data:

If provided, we may process health data, data on racial or ethnic origin, religious or philosophical beliefs, or sexual orientation. Such data is processed only as permitted by law (e.g., Art. 9 GDPR).

Use of online forms: Anonymous reports are possible. For additional privacy you may use your browser's incognito mode. When visiting our site normally, your browser sends technical details (e.g., IP address) that are temporarily logged and deleted after 30 days. Logging helps ensure security, stability, and confidentiality of the reporting form.

Providing your name: You may report anonymously. Where permitted by law, we recommend providing your name and contact details to help us follow up and communicate. Your identity is treated confidentially unless legal obligations require disclosure to protect rights or as mandated.

Disclosure to third parties: Data related to reports is shared only with your express consent or where legally required (e.g., public authorities, regulators, tax authorities). We may engage legal counsel or carefully selected processors (e.g., operators of web-based reporting systems) under data processing agreements to investigate and act on reports.

Retention and deletion: Personal data is processed only as long as necessary for the purposes described. If no longer needed, it is deleted unless longer retention is required to meet legal obligations and is proportionate.

Technical and organizational measures: We implement contractual, technical, and organizational measures to protect all processed data. Reports are handled by authorized personnel. Employees are trained and bound to confidentiality.

Changes and Updates

Please review this privacy policy regularly. We will adapt it when changes in our data processing make this necessary. We will inform you if changes require your cooperation (e.g., consent) or other individual notification.

If we provide addresses and contact details of companies and organizations, note that they may change over time; please verify before contacting.

Definitions

This section provides an overview of terms used in this privacy policy. Where terms are legally defined, those definitions apply; the explanations below support understanding.