Privacy Policy
Last updated: July 2026
1. Controller
Controller responsible for data processing on this website:
Convios GmbH
Bischof-Riegg-Str. 19a
86899 Landsberg am Lech, Germany
Phone: +49 (0) 160 924 512 00
Email: info@convios.com
No data protection officer has been appointed, as the statutory requirements under Art. 37 GDPR are not met.
2. Overview
This website is a statically generated site with no advertising networks, no cookie banner and no tracking services that require consent. Our own scripts do not set cookies. Web analytics is provided by a cookieless service that does not store device data and does not create personal profiles (Plausible, see below). External connections only occur in clearly defined cases: when the website itself is retrieved (hosting by Cloudflare), when article images are loaded (Sanity CDN), for web analytics (Plausible), and only through your active action when you submit a form or follow an appointment link to Calendly. The individual processing operations are described below.
3. Hosting and Content Delivery Network: Cloudflare
This website is delivered via Cloudflare Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare acts as hosting platform and content delivery network (CDN) and protects the website against attacks (DDoS protection).
When the website is accessed, Cloudflare automatically records technical connection data in server log files: IP address, date and time of access, URL called up, HTTP status code, volume of data transferred, referrer URL, as well as browser type and operating system. Cloudflare may set technically necessary cookies (e.g. __cf_bm for bot detection).
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and performant provision of the website. For technically necessary cookies, Section 25(2) no. 2 TDDDG applies.
Third-country transfer: Cloudflare Inc. is certified under the EU-U.S. Data Privacy Framework (DPF). The transfer takes place on the basis of the European Commission's adequacy decision (Art. 45 GDPR) and additionally on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. A Data Processing Addendum (DPA) pursuant to Art. 28 GDPR is in place with Cloudflare.
Cloudflare privacy information: https://www.cloudflare.com/privacypolicy/
4. Web Analytics: Plausible Analytics
This website uses Plausible Analytics, provided by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. The analytics script is only loaded on the production domain convios.com.
Plausible works without cookies, without local storage and without fingerprinting. Only aggregated statistics are recorded: pages visited, country of origin (from a truncated IP address), referrer URL, device category and browser type. The IP address is not stored; it is only used to calculate a daily-rotating, anonymised hash that can no longer be reconstructed after 24 hours. No personal profiles are created.
Data is processed exclusively on servers located in Germany (Hetzner, Falkenstein). No transfer to third countries takes place.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the analysis of website usage to improve our offering. Since Plausible does not access end devices and does not store any information on them, Section 25 TDDDG does not apply.
A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Plausible Insights OÜ.
Objection: As Plausible only collects anonymised, aggregated data, an individual technical opt-out is not possible. Anyone who also wishes to prevent this aggregated collection can use the browser extension "Plausible Analytics Opt Out".
Plausible privacy information: https://plausible.io/data-policy
5. Appointment Scheduling: Calendly
To arrange meetings, appointment links on this website (e.g. home page, footer, service and author pages) point directly to calendly.com, operated by Calendly LLC, 3423 Piedmont Road NE, Atlanta, GA 30305, USA. When a page is merely accessed, no Calendly resources are loaded, no connections to Calendly servers are established, and no cookies are set; no Calendly widget is embedded on this website.
Only when you click an appointment link does the external Calendly platform open in a new tab. As soon as you follow this link, you leave this website; further processing of your booking data (name, email address, requested time and any messages you enter) is subject to Calendly's privacy policy. This website only receives a notification of the booked appointment.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) for processing booking data after an appointment has been made.
Third-country transfer: Calendly LLC is certified under the EU-U.S. Data Privacy Framework (DPF). Additionally, Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR apply. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Calendly LLC.
Calendly privacy information: https://calendly.com/legal/privacy-notice
6. Content Management: Sanity
The editorial content of this website is managed via Sanity AS, Tordenskjolds gate 2, 0160 Oslo, Norway, and retrieved server-side when the website is generated (build process). No Sanity content is retrieved when you visit the website itself. One exception: article images are delivered via the Sanity CDN (cdn.sanity.io); your IP address is transmitted to the CDN when the image file is retrieved.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the efficient provision of website content.
Sanity AS is based in Norway (EEA); no third-country transfer takes place with European CDN delivery. For the U.S. infrastructure (Google Cloud), DPF certification and SCCs pursuant to Art. 46 GDPR apply. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Sanity.
Sanity privacy information: https://www.sanity.io/legal/privacy
7. Self-Check Result Delivery (Lead Forms)
On individual service pages you can voluntarily enter your email address after completing a self-check (e.g. AI readiness, compliance, delivery costs) to receive your result as a PDF. Only when you submit the form are the following data transmitted to a serverless function we use at Supabase (Supabase Inc., 970 Toa Payoh North, Singapore, with infrastructure hosted on AWS): email address, check type, language and your check result.
To protect against automated abuse, Cloudflare Turnstile (Cloudflare Inc., USA) is loaded when you submit the form. Turnstile is only loaded through your active use of the form, works without storage access requiring consent, and checks technical signals from your browser for bot detection; your IP address is transmitted to Cloudflare in the process.
Your data is used exclusively to send you the result, not for newsletters or advertising.
Legal basis: Art. 6(1)(b) GDPR (delivery of the requested result) and Art. 6(1)(f) GDPR for abuse prevention (Turnstile). For Turnstile as a technically required protective measure, Section 25(2) no. 2 TDDDG applies.
Third-country transfer: Transfers to Supabase and Cloudflare are based on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR; Cloudflare is additionally DPF-certified. Data processing agreements pursuant to Art. 28 GDPR are in place with both providers.
Retention period: The data is deleted as soon as it is no longer required for delivery and traceability of the request.
8. Study Form (Internet Communication Study)
On the study page you can voluntarily enter your email address to receive study materials. Only when you submit the form are your email address, source (study page) and language transmitted to the same serverless function we use at Supabase as for the self-checks (see Section 7). To protect against automated abuse, Cloudflare Turnstile is also loaded; the description in Section 7 applies accordingly.
Legal basis: Art. 6(1)(b) GDPR (delivery of the requested materials) and Art. 6(1)(f) GDPR for abuse prevention (Turnstile).
Third-country transfer: The information on Supabase and Cloudflare in Section 7 applies.
Retention period: The data is deleted as soon as it is no longer required for delivery and traceability of the request.
9. Article Feedback
We offer a simple feedback function on article pages (thumbs up/down). Your rating decision is stored exclusively locally in your browser (localStorage) to prevent multiple ratings of the same article. No data is transmitted to us or to third parties.
Legal basis: For this purely local storage, which solely serves the function you triggered, Section 25(2) no. 2 TDDDG applies.
10. Social Media Sharing Functions
On our article pages, we offer buttons for sharing content via LinkedIn, X (Twitter), WhatsApp and email. When a page is accessed, these buttons do not load any external scripts and do not transmit any data to third parties. Only when you actively click on a button does the respective platform open in a new browser window. The privacy provisions of the respective provider then apply.
The "Copy link" function only saves the article URL to your local clipboard, without sending any data to external servers. The "Share" function uses your browser's Web Share API and transmits data only to the app of your choice on your device.
Legal basis: Since no data is transmitted to third parties when the page is accessed, data processing only takes place through your active action on the respective platform and is subject to its privacy provisions.
11. Contact by Email
If you contact us by email, the data transmitted (email address, content of the message and, where provided, name and telephone number) will be stored to process your request. No transfer to third parties takes place without your consent.
Legal basis: Art. 6(1)(f) GDPR for general enquiries; Art. 6(1)(b) GDPR for enquiries aimed at initiating a contract.
Retention period: The data will be deleted as soon as it is no longer required for processing, at the latest upon expiry of statutory retention periods.
12. Your Rights as a Data Subject
You have the following rights vis-à-vis the controller:
Access (Art. 15 GDPR): You may request information as to whether and which personal data is processed, for what purposes, from which sources and to whom it is disclosed.
Rectification (Art. 16 GDPR): You may request the correction of inaccurate data and the completion of incomplete data.
Erasure (Art. 17 GDPR): You may request the erasure of your data if it is no longer required for the purpose of processing, if you have withdrawn your consent, or if processing is unlawful. Exceptions apply to statutory retention obligations.
Restriction (Art. 18 GDPR): You may request that your data only be stored and no longer further processed.
Data portability (Art. 20 GDPR): If processing is based on consent or contract and takes place in an automated manner, you have the right to receive your data in a machine-readable format or to have it transferred to another controller.
Withdrawal of consent (Art. 7(3) GDPR): Insofar as processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out until then remains unaffected.
Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de.
Automated decisions (Art. 22 GDPR): No automated decision-making, including profiling, takes place that produces legal effects concerning you or similarly significantly affects you.
To exercise your rights, please contact: info@convios.com
13. Right to Object (Art. 21 GDPR)
Insofar as personal data on this website is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object to this processing at any time on grounds relating to your particular situation. This concerns the processing by Cloudflare (hosting, CDN, server log files, Turnstile), Plausible Analytics (web analytics) and image delivery via the Sanity CDN. Please direct your objection to: info@convios.com. Processing of the data concerned will then cease, unless there are compelling legitimate grounds for the processing that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
14. Data Security
This website only transmits data in encrypted form (TLS/HTTPS). The controller takes technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access.
15. Currency and Changes
This privacy policy was last fully revised in July 2026 and adapted to the website's current technical architecture. In the event of material changes to the services used or to data processing procedures, the policy will be updated accordingly. The currently valid version can be accessed at https://www.convios.com/en/privacy-policy.