Privacy Policy
We take the protection of your personal data very seriously. This privacy policy informs you about the nature, scope, and purpose of the personal data we collect and process when you use this website.
The processing of personal data, such as name, address, email address, or telephone number, is always carried out in compliance with the General Data Protection Regulation (GDPR) and in accordance with the applicable data protection regulations.
1. Data Controller
opotoc GmbH Friedrich-Ebert-Anlage 27 DE-69117 Heidelberg, Germany
Email: post@opotoc.com
2. Data Collection
When you visit this website, our web server automatically collects general information such as browser type, operating system, referrer URL, access time, and IP address. This data is used solely for ensuring the proper functioning of the website and for security purposes. It is not used to identify individual visitors.
3. Contact Forms
If you contact us via the contact form on this website, the data you provide (name, email address, company, message) will be processed for the purpose of handling your enquiry. This data is transmitted via Formspree (formspree.io) and stored there. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
4. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
Right of access (Art. 15 GDPR), right to rectification (Art. 16 GDPR), right to erasure (Art. 17 GDPR), right to restriction of processing (Art. 18 GDPR), right to data portability (Art. 20 GDPR), and right to object (Art. 21 GDPR).
To exercise any of these rights, please contact us at post@opotoc.com.
5. Data Retention
Personal data is retained only for as long as necessary for the purpose for which it was collected, or as required by law. After the retention period expires, the data is routinely deleted.
6. Use of Cloudflare
This website is delivered via Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) as a content delivery network (CDN) and security service. All requests to our website are routed through the Cloudflare network.
The following data is processed: IP address, requested URL, time of access, referrer URL, user agent (browser type and version), and connection data. This processing is technically necessary for delivering the website, DDoS protection, and ensuring network security.
We also use Cloudflare Web Analytics for anonymous, cookie-free analysis of website usage. No cookies are set and no personal profiles are created. The analysis is based on aggregated data without individual identification.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and performant delivery of the website). Cloudflare is certified under the EU-US Data Privacy Framework and provides a Data Processing Addendum (pursuant to Art. 28 GDPR). Cloudflare holds ISO 27001, ISO 27701, and BSI C5 certifications.
For more information on data protection at Cloudflare, see https://www.cloudflare.com/privacypolicy/.
7. Google Fonts
This website uses Google Fonts for font rendering. Fonts are loaded from servers of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Your IP address may be transmitted to Google in the process. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in an appealing presentation of the website). For more information, see Google's privacy policy at https://policies.google.com/privacy.
8. Contact Form (Formspree)
If you contact us via the contact form on this website, the data you provide (name, email address, company, message) is transmitted via and stored by Formspree (formspree.io). The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Formspree's privacy policy is available at https://formspree.io/legal/privacy-policy/.
The full German version of this privacy policy (Datenschutzerklaerung) is the legally binding version and is available at /de/data-policy/.