Privacy Policy
This is a translation for information purposes. In case of discrepancies, the German version at https://www.attek.eu/datenschutz/ prevails.
Who is responsible for the processing?
The controller within the meaning of Article 4(7) GDPR for the processing of personal data on this website is Attek Solutions GmbH, Berlin. For questions about data protection and to exercise your rights you can reach us using the contact details below.
- Controller
- Attek Solutions GmbH
- Address
- Schulstr. 19, 13347 Berlin
- Represented by
- Managing Director Jan Klädtke
- info@attek.eu
- Telephone
- +49 1525 9120406
A data protection officer has not been appointed, because the statutory conditions of § 38 BDSG (German Federal Data Protection Act) are not met. Please address data protection enquiries to the email address given above.
What happens when you simply visit this website?
On every visit your browser transmits technically necessary data to our hosting provider, which stores them briefly in server log files. These include the IP address, the date and time, the address requested, the HTTP status code, the volume of data transferred as well as browser and operating system details. Without this transmission the page could not be delivered.
The website is operated on our behalf by Vercel Inc., Covina, California, USA; delivery takes place via servers in the European Union. A data processing agreement pursuant to Article 28 GDPR is in place with Vercel, and the transfer to the USA is safeguarded by standard contractual clauses pursuant to Article 46(2)(c) GDPR.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in technically faultless operation, in the security of the website and in defending against attacks. The log files are deleted after 30 days at the latest, unless a specific security incident makes longer retention necessary to preserve evidence.
We embed fonts from our own server. When you visit this website, no connection is therefore established to Google Fonts or any other font service.
What data do we process when you book an intro call?
When you arrange an appointment via the “Book an intro call” funnel, we process your contact details and your answers from the questionnaire in order to confirm the appointment and to prepare for the call. Mandatory details are your name, company and email address; telephone number and the free description of your situation are voluntary.
The data collected are: name, company, email address, optionally telephone number, your details on your current situation, number of users, time frame and budget range, your free description as well as time zone and the appointment chosen. In addition, we transmit the origin of your visit (page visited, referring page, campaign parameters such as utm_source or gclid) in order to be able to evaluate which measure led to an enquiry.
We handle the appointment booking via Cal.com, Inc., San Francisco, USA, which acts as a processor on our behalf. Your details are transmitted to Cal.com and stored there. The transfer to the USA is safeguarded by standard contractual clauses pursuant to Article 46(2)(c) GDPR.
The legal basis is Article 6(1)(b) GDPR, because the processing serves the performance of pre-contractual measures at your request; in addition we rely on the consent you gave in the form pursuant to Article 6(1)(a) GDPR. We delete the data as soon as the call has been concluded and no contract comes about, at the latest after six months. If a contract comes about, the retention periods under commercial and tax law of six and ten years respectively apply.
Please do not enter any personal data of third parties and no special categories of personal data pursuant to Article 9 GDPR in the free text field.
What happens when you contact us by email or telephone?
When you write to us or call us, we process the data you provide — at least your name and your contact details as well as the content of your enquiry — exclusively to handle that enquiry and in case of follow-up questions.
The legal basis is Article 6(1)(b) GDPR where your enquiry is aimed at the conclusion or performance of a contract, otherwise Article 6(1)(f) GDPR with our legitimate interest in answering enquiries.
We delete the enquiry as soon as it has been conclusively handled and no retention obligation stands in the way. Business emails are subject, as commercial letters, to the six-year retention period pursuant to § 257 HGB (German Commercial Code).
How do we manage your consent?
Using a consent banner at the bottom of the page you decide whether analytics and marketing services may be loaded. Before you consent, no such service is executed and no associated cookie is set. We store your decision so that we do not have to ask you again on every visit and so that we can demonstrate it.
The banner is provided on our behalf by Usercentrics A/S (Cookiebot), Copenhagen, Denmark. In this process your IP address in shortened form, browser and device data as well as the time and content of your decision are processed and stored under a random key.
The legal basis for storing the consent decision itself is § 25 (2) no. 2 TDDDG — without this storage your wish could not be implemented — as well as Article 6(1)(c) GDPR, because we are required to demonstrate consent pursuant to Article 7(1) GDPR. The entry is deleted or renewed after twelve months.
You can change or withdraw your decision at any time: via the “Cookie settings” link in the footer of every page. The withdrawal takes effect for the future; the lawfulness of the processing carried out until then remains unaffected.
Which analytics and marketing services do we use?
Only after you have consented do we load the Google Tag Manager and the measurement and advertising tags from Google and Meta embedded through it. They measure which advertisement or which page led to an appointment booking. Without consent none of these services is loaded, and no cookie from these providers is set.
The data processed are your IP address, information about your browser and device, the pages you visited, the referrer of the page you came from, as well as identifiers from cookies such as `_ga`, `_gcl_au`, `_fbp` or `_fbc`. The providers are Google Ireland Limited, Dublin, and Meta Platforms Ireland Limited, Dublin; both pass data on to their US parent companies.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and § 25 (1) TDDDG. We base a transfer to the USA on the adequacy decision of the EU Commission on the EU-US Data Privacy Framework and, in addition, on standard contractual clauses pursuant to Article 46(2)(c) GDPR. Despite these safeguards, access by US authorities cannot be entirely ruled out.
The storage period depends on the respective cookie and is at most 24 months. Further information from the providers is available at policies.google.com/privacy and de-de.facebook.com/privacy/policy.
To whom do we pass on data?
We pass on personal data only to service providers that are necessary for the operation of this website and for arranging appointments, and only on the basis of a data processing agreement pursuant to Article 28 GDPR. We do not sell data and do not pass them on to third parties for advertising purposes.
The service providers used are: Vercel Inc. (hosting), Cal.com, Inc. (appointment booking), Usercentrics A/S (consent management), Google Ireland Limited and Meta Platforms Ireland Limited (measurement and advertising, only after consent) as well as our email and office provider.
Beyond that, we pass on data where we are legally obliged to do so or where it is necessary to enforce our rights — for example towards tax advisors, legal advisors or public authorities.
What rights do you have?
You can request information about the data stored about you at any time, demand their rectification or erasure, have the processing restricted, receive your data in a structured format and object to processing. An informal email to info@attek.eu is sufficient; exercising these rights is free of charge for you.
In detail: access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection to processing that we base on a legitimate interest (Article 21).
If you have consented to a processing operation, you can withdraw that consent at any time with effect for the future (Article 7(3) GDPR). The lawfulness of the processing carried out up to the withdrawal remains unaffected.
Irrespective of this, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59–61, 10555 Berlin.
Are you obliged to provide data?
No. You can read this website in full without providing any details. Data are required only where you initiate something yourself: to book an intro call we need your name, company and email address — without these details we cannot confirm the appointment.
Automated decision-making including profiling pursuant to Article 22 GDPR does not take place. Decisions about working together are made by people, not by an algorithm.
How current is this policy?
This privacy policy is dated 6 September 2026. We adapt it as soon as the processing operations described change — for example because a service is added or discontinued. The version available here applies to your visit.