Privacy
Controller
coepto GmbH
Oskar-Jäger-Str. 173, 50825 Cologne, Germany
Phone: +49 221 291 996-0
Email: connect@coepto.com
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
Data protection officer
We have appointed a data protection officer as required by law:
Easy Datenschutz
Rechtsanwältin Alicja Wilczek
Kolberger Str. 7, 40599 Düsseldorf, Germany
Phone: +49 211 506699-45
Email: info@easydatenschutz.com
What this website does
This website is a static site. It sets no cookies, uses no tracking, no analytics, no advertising networks, no social media plugins and no external fonts, maps or video services. While you read these pages, nothing is loaded from third-party servers, which is why you are not met with a consent banner.
The appointment booking described below is the one exception. It is not loaded with the page: we first show you a notice, and only when you agree to it does your browser contact Cal.com.
Server log files
Our host automatically records data that your browser transmits when you request a page: the requested address, the date and time of the request, the amount of data transferred, the referring page, your browser and operating system, and your IP address.
This processing is based on Art. 6 (1) (f) GDPR — our legitimate interest in delivering the site reliably and in recognising and preventing attacks. The log files are rotated weekly and four generations are kept, so entries are deleted at the latest four weeks after your visit. The data is not merged with other sources and is not used to identify individual visitors.
Hosting
This website is hosted on webspace we rent from Gerst ITS, Daniel Gerst, Im Zinkig 65, 67069 Ludwigshafen am Rhein, Germany. Gerst ITS acts as a processor within the meaning of Art. 28 GDPR and processes data only on our documented instructions. We have concluded a data processing agreement with them to that effect.
The server stands in a data centre in Frankfurt am Main, Germany. All data therefore stays within the European Union; no content is delivered through a network outside it.
SSL and TLS encryption
This site uses TLS encryption for every request. You can recognise an encrypted connection by the address starting with https:// and by the padlock in your browser.
Contacting us
If you write to us by email, we process the data you send in order to answer your enquiry. The legal basis is Art. 6 (1) (b) GDPR where your request relates to a contract, otherwise Art. 6 (1) (f) GDPR. We keep this correspondence for as long as it is needed to handle your matter and as long as statutory retention periods require.
Recipients
We do not pass your data on to third parties, except to our host and, where you book an appointment, to Cal.com, Inc. — both as processors under Art. 28 GDPR — or where we are legally obliged to do so.
Booking appointments via Cal.com
We use the online scheduling tool Cal.com to allow you to book appointments with us. The provider is Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. The booking dialogue is not part of this page: when you click a button labelled “Tell us about your project”, we first show you a notice naming Cal.com and the transfer to the USA. Only when you agree does your browser load the dialogue.
When you book an appointment, we process the information you enter in the booking form, in particular your name, email address, phone number where applicable, the selected date and time, and any further details you provide voluntarily. In addition, Cal.com processes technical data such as your IP address, browser type and time of access in order to provide the service securely. Your data is used exclusively to schedule, carry out and manage the appointment you requested.
The legal basis for this processing is your consent pursuant to Art. 6 (1) (a) GDPR, which you give before the dialogue is loaded. Where terminal equipment access (e.g. cookies) takes place that is not strictly necessary, it is additionally based on your consent pursuant to Section 25 (1) TDDDG. You may withdraw your consent at any time with effect for the future (Art. 7 (3) GDPR), for example by sending an email to privacy@coepto.com. The withdrawal does not affect the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal. Alternatively, you can arrange an appointment with us by telephone or email at any time.
So that you are not asked again on every visit, your decision is kept in the local storage of your browser for six months. It is not a cookie, it is not sent to our server, and it holds nothing but the date on which you agreed.
You can take the decision back here at any time:
No consent for the booking dialogue is stored in this browser.
Cal.com processes the data on our behalf as a processor within the meaning of Art. 28 GDPR. As Cal.com processes data in the United States, a transfer to a third country takes place. Your data will be deleted as soon as it is no longer required for the purpose for which it was collected, generally six months after the appointment has taken place, unless statutory retention obligations apply. Further information can be found in Cal.com’s privacy policy at cal.com/privacy.
We operate a Facebook page to communicate with customers and interested parties and to provide information about our company, products and services. For users in the EU and the EEA, the platform is provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”). When you visit our page, Meta processes personal data such as your IP address, device and browser information, cookie identifiers and your interactions, for example likes, comments, shares and messages. If you are logged in to your Facebook account, Meta can link your visit to your profile and use this information, under its own responsibility, for purposes such as personalised advertising.
Meta provides us with anonymised statistics about the use of our page (“Page Insights”). For this processing, we and Meta are joint controllers pursuant to Art. 26 GDPR. The essential content of the joint controller agreement is available at facebook.com/legal/controller_addendum. Under this agreement, Meta assumes primary responsibility for informing you about the processing and for fulfilling your data subject rights. You may, however, also contact us; we will forward your request to Meta where necessary.
The legal basis for operating our page is our legitimate interest in communicating with users and presenting our company on social media (Art. 6 (1) (f) GDPR). Where Meta obtains your consent, for example to cookies, the processing is based on Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG; you can withdraw this consent at any time in your Facebook settings. Data may be transferred to Meta Platforms, Inc. in the USA. Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework, so the transfer is based on the European Commission’s adequacy decision (Art. 45 GDPR); Meta additionally relies on Standard Contractual Clauses. Further information is available in Meta’s privacy policy at facebook.com/privacy/policy. You can manage your ad settings at facebook.com/adpreferences.
We operate an Instagram account to communicate with customers and interested parties and to provide information about our company, products and services. For users in the EU and the EEA, Instagram is provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”). When you visit our profile, Meta processes personal data such as your IP address, device and browser information, cookie identifiers and your interactions. If you are logged in to your Instagram account, Meta can link your visit to your profile and use this information, under its own responsibility, for purposes such as personalised advertising.
Meta provides us with anonymised statistics about the use of our account (“Insights”). For this processing, we and Meta are joint controllers pursuant to Art. 26 GDPR. The essential content of the joint controller agreement is available at facebook.com/legal/controller_addendum. Meta assumes primary responsibility for informing you and for fulfilling your data subject rights; you may also contact us, and we will forward your request where necessary.
The legal basis is our legitimate interest in communicating with users and presenting our company on social media (Art. 6 (1) (f) GDPR). Where Meta obtains your consent, for example to cookies, the processing is based on Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG; you can withdraw this consent at any time in your Instagram settings. Data may be transferred to Meta Platforms, Inc. in the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR), supplemented by Standard Contractual Clauses. Further information is available at privacycenter.instagram.com/policy.
We operate a LinkedIn company page to communicate with customers, interested parties and potential applicants and to provide information about our company. For users in the EU and the EEA, LinkedIn is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). When you visit our page, LinkedIn processes personal data such as your IP address, device and browser information, cookie identifiers and your interactions. If you are logged in to your LinkedIn account, LinkedIn can link your visit to your profile.
LinkedIn provides us with anonymised statistics about the use of our page (“Page Analytics”). For this processing, we and LinkedIn are joint controllers pursuant to Art. 26 GDPR. The joint controller agreement is available at legal.linkedin.com/pages-joint-controller-addendum. LinkedIn assumes primary responsibility for informing you and for fulfilling your data subject rights; you may also contact us, and we will forward your request where necessary.
The legal basis is our legitimate interest in communicating with users and presenting our company on social media (Art. 6 (1) (f) GDPR). Where LinkedIn obtains your consent, for example to cookies, the processing is based on Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG; you can withdraw this consent at any time in your LinkedIn settings. Data may be transferred to LinkedIn Corporation in the USA on the basis of the EU-U.S. Data Privacy Framework (Art. 45 GDPR), supplemented by Standard Contractual Clauses. Further information is available at linkedin.com/legal/privacy-policy. You can manage your ad settings at linkedin.com/psettings/advertising.
Transfers outside the EU
Reading this website transfers no data outside the European Union. The site loads no external fonts, maps, videos, scripts or tracking services — every file is delivered from the webspace this site runs on.
Data leaves the European Union only if you agree to the appointment booking described above. In that case it is transferred to Cal.com, Inc. in the USA. If you do not want this transfer, write to us by email instead; the address is in the imprint.
The footer links to our LinkedIn page. That link only becomes active when you click it; you then leave this website and the privacy notice of LinkedIn applies. We embed no content from these networks, so they learn nothing about your visit unless you follow a link.
Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have your data erased (Art. 17)
- restrict processing (Art. 18)
- receive your data in a portable format (Art. 20)
- object to processing based on legitimate interest (Art. 21)
- withdraw consent at any time with effect for the future
To exercise these rights, write to privacy@coepto.com. You can also contact our data protection officer directly.
You also have the right to lodge a complaint with a supervisory authority. For our registered office this is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Postfach 20 04 44, 40102 Düsseldorf, Phone: 0211 38424-0, Fax: 0211 38424-10, Email: poststelle@ldi.nrw.de.
Changes to this notice
We update this notice when the site or the law changes.