Convenience translation. The German version is authoritative. Hosting provider, commercial-register details and VAT identification number will be finalised before public release.
1. Controller
OHMIRIS UG (haftungsbeschränkt)
Prenzlauer Allee 7
10405 Berlin
Germany
Represented by its Managing Director:
Sadig Guliyev
Commercial-register details and the VAT identification number will be added once the company formation has been completed.
Email: info@ohmiris.com
2. General information
The protection of personal data is of particular importance to us. We process personal data only within the scope of applicable law, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
Personal data means all information relating to an identified or identifiable natural person.
3. Legal bases
Depending on the processing operation, we rely in particular on:
- Article 6(1)(a) GDPR where consent has been given;
- Article 6(1)(b) GDPR for the performance of a contract or pre-contractual measures;
- Article 6(1)(c) GDPR to comply with legal obligations;
- Article 6(1)(f) GDPR to safeguard our legitimate interests, provided that the interests or fundamental rights of the data subject do not prevail.
Where information is stored on, or read from, a user’s terminal device, this is carried out in accordance with Section 25 TDDDG.
4. Hosting and server log files
When our website is accessed, the hosting provider may process, in particular:
- IP address;
- date and time of access;
- requested URL;
- volume of data transferred;
- referrer URL;
- browser type and version;
- operating system;
- HTTP status code;
- hostname of the accessing device.
Processing is carried out to provide the website securely from a technical perspective, to analyse errors and to detect and prevent abusive or security-relevant access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and technically functional operation of our website.
Server log files are generally retained only as long as necessary for those purposes, unless longer retention is required to investigate specific security incidents or to meet legal obligations. Where required, we enter into data-processing agreements with hosting or infrastructure providers pursuant to Article 28 GDPR.
5. Contacting us
If you contact us by email, contact form, telephone or another communication channel, we process the information you provide. This may include your name, company, role, email address, telephone number, enquiry content, transmitted files and technical or commercial project information.
Processing is carried out to handle your enquiry. Where it relates to entering into or performing a contract, Article 6(1)(b) GDPR applies. In other cases, processing is based on our legitimate interest in efficient business communication under Article 6(1)(f) GDPR.
Data is deleted once it is no longer required for the relevant purpose and no statutory retention obligation or other legitimate reason for continued storage applies.
6. Business customers, prospects, suppliers and project partners
In the course of our business activities, we process personal data of contacts at customers, prospective customers, suppliers, development partners, research institutions, authorities and other organisations.
This may include names and contact details, employer or organisation, role and area of responsibility, business correspondence, contract and project data, quotation and invoice data, technical contacts, and documentation and communication history.
Processing takes place in particular for contract initiation and performance, project coordination, procurement, supplier management and the maintenance of business relationships. The legal bases are in particular Article 6(1)(b) and (f) GDPR.
7. Applications
Where applications are submitted through our website or by email, we process the personal data transmitted for the purpose of conducting the application process. This may include name, contact details, CV, references, qualifications, work samples, professional experience and other voluntarily provided information.
Processing is carried out in particular on the basis of Section 26 BDSG. If an application is unsuccessful, application data is generally deleted after expiry of the period required to defend against possible legal claims, unless consent has been given for longer storage.
8. Cookies and comparable technologies
Our website may use cookies or technically comparable technologies. Strictly necessary cookies or storage/access operations may be used without consent where the requirements of Section 25(2) TDDDG are met.
For non-essential technologies, in particular certain analytics, tracking or marketing purposes, we obtain consent before activation where legally required. Consent may be withdrawn at any time with future effect.
At present, this website does not use non-essential analytics, tracking or marketing technologies.
9. LinkedIn, Instagram and other social networks
Our website may link to company profiles on LinkedIn, Instagram or other social networks. A normal external link does not itself load any content from those platforms through our website. Their privacy policies apply only after you follow the link.
If plugins, embedded posts, tracking pixels or comparable technologies are introduced, this policy will be updated and any required consent obtained before activation.
10. Recipients of personal data
Where required, personal data may be transferred to the following categories of recipients:
- hosting and IT service providers;
- communications providers;
- tax advisers and auditors;
- legal advisers;
- banks and payment service providers;
- project or development partners where required for a project;
- public bodies where there is a legal obligation.
Data is transferred only where a legal basis exists.
11. Transfers to third countries
Where personal data is transferred to recipients outside the European Economic Area, the transfer is carried out only in compliance with Articles 44 et seq. GDPR. This may include an adequacy decision of the European Commission, appropriate safeguards such as standard contractual clauses or another statutory transfer basis.
Once specific services involving third-country transfers are used, they will be named individually in this policy.
12. Retention periods
We generally retain personal data only for as long as necessary for the respective processing purpose. Data may also be retained due to statutory commercial, tax or other retention obligations. Once the purpose no longer applies and relevant retention periods have expired, data is deleted or anonymised unless another legal basis permits continued storage.
13. Data security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or unauthorised disclosure. These may include access restrictions, authorisation concepts, encrypted transmission, secure authentication procedures, backup and recovery measures, logging of security-relevant events and regular updates of the systems used.
14. Rights of data subjects
Subject to the legal requirements, data subjects have in particular the right to:
- access under Article 15 GDPR;
- rectification under Article 16 GDPR;
- erasure under Article 17 GDPR;
- restriction of processing under Article 18 GDPR;
- data portability under Article 20 GDPR;
- object under Article 21 GDPR;
- withdraw consent with future effect.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
15. Objection to processing based on legitimate interests
Where processing is based on Article 6(1)(f) GDPR, you have the right, subject to Article 21 GDPR, to object on grounds relating to your particular situation.
16. No solely automated decisions
Unless expressly stated otherwise, we do not make decisions in connection with the operation of this website that are based solely on automated processing within the meaning of Article 22 GDPR and that produce legal effects concerning a person or similarly significantly affect them.
17. Changes to this privacy policy
We reserve the right to amend this privacy policy if our website, technologies used, processing activities or legal framework change. The version currently published on our website applies.
