Privacy policy
Information on the processing of personal data under Arts. 13 and 14 GDPR on this marketing website.
The German version is the legally binding text. This translation is not legal advice.
Scope of this privacy policy
This privacy policy applies only to this marketing website under the domain deveca.de / www.deveca.de. It describes how we process personal data when you visit our public pages.
The deveca GRC application (grc.deveca.app) has its own, separate privacy policy, provided inside the application. This statement does not cover processing inside the platform.
1. Privacy at a glance
General information
The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified.
Who is responsible for data collection?
Processing on this website is carried out by the website operator. You can find the contact details in the section on the controller.
How do we collect your data?
Some data is collected because you provide it to us, for example in a contact form.
Other data is collected automatically, or after your consent, by our IT systems when you visit the website. This is mainly technical data (browser, operating system, time of the request). Collection starts as soon as you enter the website.
What do we use your data for?
Some data is collected to provide the website without errors. Other data may be used to analyse how you use the site. Where contracts can be concluded or prepared via the website, the data you send is also processed for offers, orders, or other requests.
What rights do you have?
You may at any time request free information about the origin, recipients, and purpose of your stored personal data, and you may request rectification or erasure. You may withdraw consent for the future. In certain circumstances you may request restriction of processing. You have the right to lodge a complaint with a supervisory authority.
You can contact us at any time about this and about other privacy questions.
2. Hosting and processors
We host this marketing website with external providers. Personal data collected on this website is stored on the hosters’ servers. This may include IP addresses, contact requests, meta and communication data, website access, and other data generated via a website.
External hosting takes place to perform contracts with prospective and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by professional providers (Art. 6(1)(f) GDPR).
Contracts under Art. 28 GDPR exist with all processors and require that personal data is processed only on our instructions and in compliance with the GDPR.
Vercel (hosting of the marketing website)
This marketing website is hosted on Vercel’s infrastructure. The provider is:
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Privacy notice: vercel.com/legal/privacy-policy
When you call the site, technical connection data (in particular IP address, date and time, URL, HTTP status, referrer, user agent) is processed on Vercel’s servers to deliver the content and protect the infrastructure. The legal basis is Art. 6(1)(f) GDPR.
Delivery preferably uses edge nodes in the European Union (region fra1 / Frankfurt). A transfer to third countries cannot be fully excluded because of the global edge network. A data processing agreement exists with Vercel. Transfers are additionally based on standard contractual clauses. Vercel is certified under the EU-US Data Privacy Framework (DPF).
Further information: Vercel DPA, Sub-Processors.
Cloudflare (DNS and security)
We use Cloudflare as DNS provider and to protect this website against attacks (including DDoS protection and a WAF).
Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. Privacy notice: cloudflare.com/privacypolicy
Cloudflare processes request data (IP addresses, HTTP headers) to provide and secure the infrastructure. The company is certified under the EU-US Data Privacy Framework. Processing is additionally based on standard contractual clauses. The legal basis is Art. 6(1)(f) GDPR.
Further information: Cloudflare DPA, DPF.
3. General information and mandatory notices
Privacy
The operators of these pages take the protection of your personal data seriously. We treat your personal data confidentially and in line with statutory data-protection rules and this privacy policy.
Data transmission on the internet (for example by email) can have security gaps. Complete protection against access by third parties is not possible.
Notice on the controller
The controller for processing on this website is:
Kevin Carter (deveca GRC), c/o MDC#deveca, Welserstraße 3, 87463 Dietmannsried. E-Mail: datenschutz@deveca.org
The controller is the natural or legal person that alone or jointly with others decides on the purposes and means of processing personal data.
Storage period
Unless a more specific storage period is stated in this policy, your personal data remains with us until the purpose of processing ceases. If you make a justified erasure request or withdraw consent, your data is erased unless we have another legally permitted reason to store it (for example tax or commercial retention duties).
General notes on legal bases
Where you have consented, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories are processed. Where you have consented to cookies or to access to information on your device, processing is additionally based on § 25(1) TDDDG. Consent can be withdrawn at any time.
Where your data is required to perform a contract or pre-contractual steps, we process it under Art. 6(1)(b) GDPR. Where it is required to comply with a legal obligation, under Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR.
Recipients of personal data
In the course of our business we work with various external parties. We disclose personal data only where this is required to perform a contract, where we are legally obliged, where we have a legitimate interest under Art. 6(1)(f) GDPR, or where another legal basis permits disclosure.
When we use processors, we disclose our customers’ personal data only on the basis of a valid data-processing agreement.
4. Data collection on this website
Server log files
On every call, our hoster’s infrastructure (Vercel, and Cloudflare where it sits in front) automatically collects data and information from the calling computer system. The following data is processed:
This data is not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation).
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
Cookies and similar technologies
Our website uses technically necessary cookies and similar storage mechanisms on the device (for example LocalStorage). Optional services for audience measurement (section 5) and marketing analysis (section 6) are loaded only after your consent in the cookie banner.
The legal basis for technically necessary storage is § 25(2) no. 2 TDDDG. You can set your browser to inform you about cookies. If you disable them, individual functions of this website may be limited.
| Name | Purpose | Type / storage | Retention |
|---|---|---|---|
deveca:consent:v3 | Stores your current choice per category in the cookie banner | LocalStorage | 12 months |
deveca:consent:log:v1 | Logs consent changes (time, choice, banner version) | LocalStorage | 12 months |
5. Audience and performance measurement (Vercel Analytics)
After your express consent in the cookie banner we measure anonymous page views and web-performance metrics via Vercel Web Analytics and Vercel Speed Insights. Both services work without cookies and without a persistent identifier; no personal user profiles are created.
Provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. vercel.com/legal/privacy-policy
Vercel Web Analytics
Vercel Web Analytics collects aggregated, anonymous usage data (including pages viewed, referrer, approximate region, device type, browser). For recognition within a day a daily rotating hashed identifier is formed from IP address and user agent; it cannot be reversed and is not stored in a cookie. The IP address itself is not stored persistently.
Vercel Speed Insights
Vercel Speed Insights collects anonymised web vitals (including Largest Contentful Paint, Interaction to Next Paint, Cumulative Layout Shift). No personal user profiles are created and no cookies are set.
Legal basis, third-country transfer, withdrawal
The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Processing takes place primarily in the European Union; a transfer to the USA cannot be fully excluded technically and is based on standard contractual clauses and Vercel’s DPF certification.
You can withdraw consent for the future at any time by changing your choice via the footer link “Cookie settings”.
6. Marketing and visitor analysis (Apollo.io)
After your express consent to the Marketing category we use the website tracker of Apollo.io. The service analyses website visits and identifies potential B2B contacts for our sales team.
Provider: ZenLeads Inc. (Apollo.io), 440 N Barranca Ave #4750, Covina, CA 91723, USA. apollo.io/privacy
Apollo may process, among other things, IP address, pages viewed, referrer, time of the visit, browser and device information, and — where technically available — company attribution. Cookies and similar technologies may be stored.
The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Processing may include a transfer to the USA and is based on appropriate safeguards (including standard contractual clauses) where offered by the provider.
You can withdraw consent for the future at any time by disabling the Marketing category in “Cookie settings”.
7. Contact
If you contact us by form, email, or telephone, your request including the resulting personal data (name, email address, request) is stored and processed in order to handle it. We do not pass this data on without your consent.
Processing is based on Art. 6(1)(b) GDPR where your request relates to a contract or pre-contractual steps. In all other cases it is based on our legitimate interest in handling enquiries effectively (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR).
The data remains with us until you ask us to erase it, you withdraw consent, or the purpose ceases. Mandatory statutory retention periods remain unaffected.
Spam and abuse protection
To protect against automated requests we use technical measures (including honeypot fields, signed form tokens, timing checks, rate limiting, and content filters). The IP address is processed briefly to detect abuse. The legal basis is Art. 6(1)(f) GDPR.
Where Cloudflare Turnstile is enabled, the data required for it is transmitted to Cloudflare (USA). Further information: cloudflare.com/privacypolicy
8. Your rights as a data subject
You have the following rights at any time regarding personal data concerning you:
You can contact us at any time about this and about other questions.
Withdrawal of consent
Many processing operations are possible only with your express consent. You may withdraw consent already given at any time. The lawfulness of processing until withdrawal is unaffected.
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
Right to object (Art. 21 GDPR)
Where processing is based on Art. 6(1)(e) or (f) GDPR, you have the right at any time to object on grounds relating to your particular situation; this also applies to profiling based on those provisions. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
Where personal data is processed for direct marketing, you have the right to object at any time; this also applies to profiling to the extent that it is related to such direct marketing.
Right to lodge a complaint
In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work, or the place of the alleged infringement. The right exists without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or for the performance of a contract, in a common machine-readable format, for yourself or a third party. Direct transmission to another controller takes place only where it is technically feasible.
9. Data security
SSL or TLS encryption
This site uses SSL or TLS encryption to protect the transmission of confidential content. You can recognise an encrypted connection because the address bar changes from “http://” to “https://” and by the lock icon. When encryption is active, the data you send to us cannot be read by third parties.
10. Objection to advertising emails
We object to the use of contact details published under the legal-notice duty for sending advertising and information material that has not been expressly requested. The operators reserve the right to take legal action in the event of unsolicited advertising, for example spam emails.
11. Currency of this privacy policy
This privacy policy applies to the marketing website under deveca.de and is currently valid. Changes in law or official guidance may require an update. The privacy policy that applies inside the deveca GRC application is independent of this statement.
*Status: July 2026 — template based on e-recht24.de (adapted). The German version is binding.*