Privacy Policy
1 Scope of application
1.1 The following
privacy policy applies to the use of our websites and the services offered via
them. This privacy policy informs you, in accordance with Art. 12 et seq. of
the General Data Protection Regulation (GDPR), about the handling of your
personal data when using our websites. In particular, it explains what data we
collect and for what purposes we use it. It also informs you about how and for
what purpose this takes place.
1.2 When you visit our websites, various personal data are processed depending on the nature and extent of your use. Personal data (hereinafter also referred to as "data") is information relating to an identified or identifiable natural person (hereinafter referred to as the "data subject"); a natural person is considered identifiable if they can be identified directly or indirectly (e.g., by association with an online identifier). This includes information such as name, address, telephone number, and date of birth.
1.3 The processing of your data may encompass any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
2 General Information
2.1 Controller
Unless otherwise stated, IFEX® GmbH is the controller within the meaning of Art. 4 No. 7 GDPR.
Our contact details:
IFEX GmbH
Bäckerstraße 28, 21244 Buchholz i. d. N.,
Germany
Phone: 04181 9458010
Fax: 04181 9458015
E-mail: office@ifextechnologies.com
2.2 Legal bases for processing
We process personal data only where there is a legal basis for doing so under data protection law, a statutory obligation, or your express consent. Specifically, the following legal bases apply: Data processing is carried out on the basis of Art. 6(1)(a) GDPR if we obtain your consent for a specific processing purpose.
In situations where the processing of personal data is necessary to fulfill a contract to which you are a party—such as for the delivery of goods or services—we rely on Art. 6(1)(b) GDPR. This also applies if such processing is required to carry out pre-contractual measures, e.g., in the case of product inquiries.
If we are required to comply with a legal obligation necessitating the processing of personal data—such as for tax purposes—we do so in accordance with Article 6(1)(c) of the GDPR.
In certain exceptional cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. For example, this might be necessary in an emergency situation requiring the disclosure of medical information to physicians. In such cases, Article 6(1)(d) of the GDPR applies.
Finally, processing may also be based on Article 6(1)(f) of the GDPR. This legal basis applies to cases not covered by the preceding provisions where we, or a third party, have a legitimate interest in the data processing, provided that such interest is not overridden by the interests of the data subject upon balancing the respective interests.
2.3 Duration of data storage
Unless otherwise stated, we process and store your personal data initially for the duration required by the specific purpose of processing. This may include the periods involved in initiating a contract (pre-contractual relationship) and executing a contract. On this basis, personal data is routinely deleted once our contractual and/or statutory obligations have been fulfilled, unless continued processing for a limited period is required for the following purposes:
Compliance with statutory retention obligations, such as those arising from the Commercial Code (Sections 238, 257(4) HGB) and the Fiscal Code (Section 147(3), (4) AO). The retention or documentation periods specified therein extend up to ten years.
Preservation of evidence, taking into account applicable statutes of limitation. Under Sections 194 et seq. of the German Civil Code (BGB), these limitation periods can extend up to 30 years, whereas the standard limitation period is three years.
2.4 Disclosure of data to third parties
As a general rule, personal data you have provided to us is not disclosed to third parties. Disclosure occurs only: based on your consent. You are informed of the recipients or categories of recipients at the time the data is collected to external service providers (e.g., hosting providers) as part of data processing on our behalf pursuant to Art. 28 GDPR. These providers have been carefully selected and commissioned by us; they are bound by our instructions and the provisions of the GDPR and are subject to regular monitoring to authorized bodies in order to fulfill legal obligations. If we transfer data to recipients in a so-called third country (located outside the European Economic Area), details regarding this—including information on the recipients and the underlying legal basis pursuant to Art. 46 para. 2 GDPR—can be found in the description of the respective data processing activity within this privacy policy. The European Commission certifies that certain third countries have a data protection standard comparable to that of the European Economic Area via so-called adequacy decisions. Where a comparable data protection standard does not exist in a country, we and our sub-processors ensure that data protection is adequately guaranteed through other measures. This can be achieved, for example, through the European Commission’s Standard Contractual Clauses ("SCCs") for the protection of personal data, certificates, or recognized codes of conduct.
2.5 Your rights
Subject to the statutory requirements, you have the following rights as a data subject:
Right of access
You may request confirmation from us as to whether we are processing your data, in accordance with the conditions set out in Art. 15 GDPR. If this is the case, you have the right to obtain information regarding this data. Right to rectification
If the data we hold about you is incorrect or incomplete, you may request the rectification and, where applicable, the completion of such data (Art. 16 GDPR).
Right to erasure and restriction of processing
Provided the statutory requirements are met, you may request the erasure (Art. 17 GDPR) or "blocking" (Art. 18 GDPR) of your data.
Right to data portability
You may exercise the right to data portability (Art. 20 GDPR) regarding data processed by automated means that we have received from you based on your consent or a contract. We will then provide your data to you in a machine-readable format. If you so request and it is technically feasible, we will transmit this data to a third party. In certain cases, the aforementioned rights may be restricted or excluded by law.
2.6 Revocation of consent
Where you have granted us consent to process personal data for specific purposes, the processing is lawful based on that consent. Consent may be revoked at any time. Please note that your revocation applies only to the future; processing that took place prior to the revocation remains unaffected.
2.7 Objection to processing based on legitimate interests
We also collect and process your personal data to safeguard our legitimate interests or the legitimate interests of third parties, provided that such data processing is necessary to protect those interests. In such cases, you have the right to object to the processing with future effect.
2.8 Right to lodge a complaint with a supervisory authority
Subject to the conditions set out in Art. 77 GDPR, you have the right to lodge a complaint with a competent supervisory authority. In particular, you may submit a complaint to the supervisory authority responsible for us or to any other competent supervisory authority.
2.9 Other matters
Our Data Protection Officer is available to answer any further questions or address concerns regarding data protection. Where possible, such inquiries and the exercise of the aforementioned rights should be submitted in writing to the address provided above or via email.
3 Security
We work with carefully selected service providers to ensure the protection of your data. Naturally, these service providers are contractually obligated to comply with regulatory requirements, particularly data protection laws.
4 Data processing via the website
4.1 Log files
As with any website, our server automatically and temporarily collects data in server log files transmitted by your browser, unless you have disabled this function. This data is technically necessary to display our website to you and to ensure its stability and security.
Specifically, the following server log file data is collected on our website:
Browser type and version
Operating system used
Referrer URL
Time of the server request
IP address
This data collection includes the storage of your IP address, which is necessary for technical reasons; while it could theoretically allow for identification of your person, it is not linked to specific individuals at any time.
In addition to ensuring website functionality and system security, the collected data is used for aggregated statistical analysis to tailor and optimize our online services in accordance with Art. 6 (1) (f) GDPR. No analysis involving personal identification takes place, and this data is not combined with other data sources.
Your log data is stored on our web server for a maximum of 7 days for IT security purposes.
4.2 Cookies and other web analytics technologies
4.2.1 Cookies
This website uses cookies and other technologies. Cookies are small text files containing an identification number (ID) that are stored on your computer, tablet, or smartphone (hereinafter referred to as "device") when you visit our website. If you visit our website again, your device can be recognized using this identification number. You have the option to configure settings for cookies and similar technologies via the consent banner and to obtain further information regarding the specific data being processed.
4.2.2 Categories of cookies and other technologies
Depending on the function and purpose of the data processing involved, we classify the technologies used on our website into the following three categories:
Necessary cookies
These technologies are necessary to provide you with website functions and to fulfill our legal obligations. The legal basis for processing your personal data is our legitimate interest (Art. 6(1)(f) GDPR) in making our website securely usable for you and in fulfilling our legal obligations (Art. 6(1)(c) GDPR). With regard to access to your device, the legal basis is Section 25(2) sentence 2 of the TDDDG.
Cookies for reach measurement
We use these technologies for statistical analysis purposes to track usage of our website statistically. Statistics cookies help us improve our website and provide you with content that is particularly relevant to you. The legal basis for processing your personal data is the consent you provide via the cookie banner pursuant to Art. 6(1)(a) GDPR; with regard to access to your device, the legal basis is Section 25(1) of the TDDDG. Your consent is always voluntary and is not required for the use of the website itself. Marketing cookies ("Marketing")
We use these technologies for marketing purposes—for example, to provide you with personalized advertising. The legal basis for the processing of your personal data is the consent you have provided via the cookie banner in accordance with Art. 6(1)(a) GDPR; regarding access to your device, the legal basis is Section 25(1) TDDDG. Your consent is always voluntary and is not required for the use of the website itself.
4.2.3 Storage Duration
Session cookies are deleted after the browser is closed. We also use permanent cookies. Details regarding the storage duration can be found in the sections below.
4.3 Integrated Services
The services we use are listed and described in more detail below.
4.3.1 Required Technologies
4.3.1.1 Consent Banner
Our website uses a consent banner to obtain your informed consent or refusal regarding the storage of certain cookies and other technologies on your device and to document this in a manner compliant with data protection regulations.
When you visit our website, a connection is established to the provider's servers to obtain your consent or refusal regarding the use of cookies and comparable technologies. Subsequently, the provider places a cookie on your device to associate the consents you have granted with you. The data collected in this way is stored until you request its deletion, delete the cookie yourself, or the purpose for data storage ceases to apply. Mandatory statutory retention obligations remain unaffected. The legal basis for this data processing is Art. 6(1)(c) GDPR.
4.3.2 Other Technologies
4.3.2.1 Instagram Link (Social Media Presence)
We maintain an online profile on the Instagram platform to showcase our company and services and to communicate with customers and interested parties.
Links to our Instagram profile are embedded on our website. Unlike so-called social media plugins, a simple link does not transmit data to Instagram when you visit our website. Data is only transmitted to Instagram if you actively click the corresponding button, thereby leaving our website.
If you click the link while logged into your Instagram account, Instagram may associate your visit to our website with your user account. If you do not wish for this to happen, please log out of your Instagram account before clicking the link.
Data Controller: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Legal Basis: Linking to and operating our Instagram presence is based on our legitimate interest in modern public relations and communication (Art. 6(1)(f) GDPR).
Data Transfer to Third Countries: When using Instagram, it cannot be ruled out that data may be transferred to the parent company, Meta Platforms Inc., in the USA. Such data transfers are safeguarded by the EU-US Data Privacy Framework and the EU Commission’s Standard Contractual Clauses
4.3.2.2 LinkedIn Link (Social Media Presence)
We maintain an online profile on the LinkedIn platform to present ourselves as an employer, provide information about our services, and communicate with customers, interested parties, and potential applicants.
Links to our LinkedIn profile are embedded on our website. With these simple links, no data is transmitted to LinkedIn when you visit our website. Data transmission to LinkedIn only occurs if you actively click the corresponding LinkedIn button and thereby leave our website. If you click the link while logged into your LinkedIn account, LinkedIn may associate your visit to our website with your user account. If you do not wish for this to happen, please log out of your LinkedIn account before clicking the link. Data controller for Europe: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
Legal basis: The linking to and operation of our LinkedIn presence are based on our legitimate interest in modern and professional public relations, networking, and communication (Art. 6(1)(f) GDPR).
Data transfer to third countries: When using LinkedIn, data is transferred to the parent company, LinkedIn Corporation, in the USA. LinkedIn bases this data transfer on the EU-US Data Privacy Framework and on Standard Contractual Clauses issued by the EU Commission
4.3.2.3 Facebook-Link (Social-Media-Präsenz)
Wir unterhalten ein Online-Profil auf der Plattform Facebook, um dort unser Unternehmen, unsere Angebote und Neuigkeiten zu präsentieren und mit Kunden sowie Interessenten in Kontakt zu treten.
Auf unserer Website sind Links zu unserer Facebook-Seite eingebunden. Bei diesen einfachen Links werden keine Daten an Facebook übertragen, wenn du unsere Website aufrufst. Eine Datenübertragung an Facebook findet erst dann statt, wenn du den entsprechenden Facebook-Button aktiv anklickst und damit unsere Website verlässt.
Wenn du den Link anklickst und gleichzeitig in deinem Facebook-Account eingeloggt bist, kann Facebook den Besuch unserer Website deinem Benutzerkonto zuordnen. Wenn du das nicht möchtest, logge dich bitte vor dem Klick auf den Link aus deinem Facebook-Account aus.
Verantwortlicher für die Datenverarbeitung: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland.
Rechtsgrundlage: Die Verlinkung und der Betrieb unserer Facebook-Präsenz erfolgen auf Grundlage unseres berechtigten Interesses an einer zeitgemäßen Öffentlichkeitsarbeit und Kundenkommunikation (Art. 6 Abs. 1 lit. f DSGVO).
Datenübertragung in Drittstaaten: Bei der Nutzung von Facebook kann nicht ausgeschlossen werden, dass Daten an die Muttergesellschaft Meta Platforms Inc. in die USA übertragen werden. Die Datenübertragung wird durch das EU-US Data Privacy Framework sowie Standardvertragsklauseln der EU-Kommission abgesichert.
Weitere Informationen zur Datenverarbeitung, zu deinen Rechten und zu den Einstellungsmöglichkeiten zum Schutz deiner Privatsphäre findest du in der Datenschutzerklärung von Facebook unter: https://www.facebook.com/about/privacy/.
4.3.2.4 Contact form
If you send us inquiries via the contact form, the information provided in the form—including the contact details you entered—will be stored by us solely for the purpose of processing the inquiry and handling any follow-up questions. We do not pass this data on to third parties without your consent.
The processing of the data entered into the contact form is therefore based on Art. 6(1)(b) GDPR. The data you enter in the contact form remains with us until you request its deletion, revoke your consent for storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been fully processed). Mandatory legal provisions—particularly retention periods—remain unaffected.
5 Currency of the statement
We regularly review our privacy policy and update it as necessary to ensure that the information contained therein is current and accurate. This privacy policy is currently valid and is dated June 2026.