Privacy Policy

At RIVA Engineering, we take the protection of your personal data very seriously. That is why we openly inform you about how we handle your personal data – whether you visit our website, meet us at a trade fair, enter into a project with us, or apply for a job with us.  

Your personal data is processed in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection regulations. In most cases, we collect this data directly from you – for example, when you fill out a form, send us an email, or leave your contact details at one of our trade fair stands.  

We proceed according to the following principles: 

  •  Transparency: We tell you what data we collect and why. 
  • Purpose limitation: We only use your data for the purposes for which it was collected. 
  • Care: Your data is treated confidentially and protected both technically and organizationally.  

1. Responsible party within the meaning of Art. 4 (7) GDPR

RIVA GmbH Engineering  
Manfred-von-Ardenne-Allee 33  
71522 Backnang 
Germany 

Phone: +49 7191 904 38-0  
Email: info@rivagmbh.de  
Website: https://www.rivagmbh.de/ 

Authorized representative: Marcus Püttmer, Managing Director  
Legal notice: https://www.rivagmbh.de/en/imprint/  

We have outsourced essential commercial processes to Mpire GmbH, Manfred-von-Ardenne-Allee 33, 71522 Backnang, Germany. These include, in particular, marketing, purchasing, IT, accounting & controlling, and human resources (HR). Mpire acts as a processor in accordance with Art. 28 GDPR. 

2. Data Protection Officer

disiviva  
Daniel Voigtländer  
Zeisigweg 11  
71397 Leutenbach-Nellmersbach  
Phone: +49 7195 9772959  
Emaildaniel.voigtlaender@disiviva.de 

3. General information on data processing

We process personal data in compliance with the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and the Telecommunications and Telemedia Data Protection Act (TDDDG). Processing only takes place if there is legal permission, a contractual requirement, or your consent.  

As part of our business activities, personal data is also processed by external service providers on our behalf. This includes, in particular, Mpire GmbH, which handles various commercial processes for us. Processing is carried out on the basis of a data processing agreement in accordance with Art. 28 GDPR. 

 

Types of data processed:
  • Master data – e.g., name, address 
  • Applicant data – e.g., personal details, postal and contact details, application documents (cover letter, resume, references), and voluntary information on qualifications or personal details  
  • Payment data – e.g., bank details, invoices, payment history 
  • Contact details – e.g., email address, telephone number  
  • Content data – e.g., entries in online forms 
  • Contract data – e.g., subject matter of the contract, term, customer category 
  • Usage data – e.g., websites visited, interest in content, access times 
  • Meta/communication data – e.g., device information, IP addresses 

 

Categories of data subjects:
  • Prospective customers 
  • Job applicants 
  • Communication partners 
  • Users of our services 
  • Business and contractual partners 

 

Purposes of processing: 

We process data in order to: 

  • Provide contractual services and ensure our customer service 
  • Respond to inquiries and communicate with you 
  • Carry out application procedures (including possible justification, implementation, or termination of an employment relationship) 
  • Conduct direct marketing 
  • Measure reach  
  • Control office and organizational processes 
  • Implement security measures 
  • Perform remarketing and conversion measurements 
  • Collect feedback 
  • Plan marketing measures 
  • Create profiles with user-related information 
  • Define target groups 
  • Provide our online offering and make it user-friendly 

 

Legal basis for processing:  

We process personal data on the basis of the GDPR. Depending on the purpose of the processing, different legal bases may apply. In addition to the GDPR, national data protection laws (e.g., the BDSG in Germany, TDDDG) may also be relevant.   

The GDPR asserts the following legal bases:  

  • Consent (Art. 6 (1) (a) GDPR) – if you expressly consent to us processing your personal data for one or more specific purposes.  
  • Performance of a contract / pre-contractual measures (Art. 6 (1) (b) GDPR) – if processing is necessary to fulfill a contract or to take action at your request prior to entering into a contract.
  • Legal obligation (Art. 6 (1) (c) GDPR) – if we are legally obliged to process certain data.  
  • Legitimate interests (Art. 6 (1) (f) GDPR) – if we have a legitimate interest in processing and your interests or fundamental rights do not override this.  
  • Application process (Art. 9(2)(b), (c), (h) GDPR) – if we need to process special categories of personal data (e.g., health data, information on severe disability, or ethnic origin)  in the application process in order to fulfill obligations under labor law, social security law, or health law.  
  • Voluntary consent for special categories of data (Art. 9 (2) (a) GDPR) – if you provide us with such data without any obligation to do so. 

In addition, the Telecommunications Digital Services Data Protection Act (TDDDG) applies in Germany. This law primarily regulates the protection of your privacy when using online offers, apps, and digital services. This includes, in particular: 

  • the storage of information (e.g., cookies) on your device 
  • access to already stored information  
  • obtaining your consent for this – unless the storage or access is absolutely necessary for technical reasons 

In other words, the TDDDG ensures that we need your consent before we store or read data on your device, e.g. in the case of cookies or similar technologies – unless this data is technically necessary for our website to function at all. 

4. Security measures

We protect personal data in accordance with legal requirements, taking into account the current state of technology, implementation costs, the scope and purpose of processing, and the likelihood and severity of possible risks to the rights and freedoms of data subjects.  

SSL/TLS encryption:  

We use SSL or TLS encryption to protect the data you transmit to us online. You can recognize an encrypted connection by the string https:// and the lock symbol in the address bar of your browser. 

5. Transfer of personal data

Disclosure to third parties  

We only disclose your personal data to external parties if this is permitted by law, if you have given your consent, or if it is necessary for the fulfillment of a contract. 

Possible recipients include, for example: 

  • IT service providers 
  • Hosting and cloud providers 
  • Providers of external content or functions that we integrate into our website 
  • Mpire GmbH: Carrying out commercial processes on our behalf, in particular marketing, purchasing, IT, accounting & controlling, human resources (HR), and application management.  

We do not pass on your data to third parties for direct marketing purposes.  

Order processing  

We use order processors for some technical information and communication services. These may be companies or other entities that process personal data on our behalf. We conclude contracts with all order processors in accordance with Art. 28 (3) GDPR.  

Legal disclosure obligations  

In certain cases, we are legally obliged to disclose personal data – for example, in response to requests from authorities, on the basis of a court order, or in the context of legal retention and documentation obligations. In such cases, we carefully check whether the request is justified and only disclose the necessary data. 

Internal disclosure 

Within our organization, personal data is only disclosed to those departments that need it to perform their tasks. This is done on the basis of legal regulations, contractual obligations, or legitimate interests. 

6. Data processing in third countries

Personal data will only be transferred to or processed in countries outside the EU/EEA (so-called third countries) if: 

  • an adequate level of data protection is recognized by the EU,  
  • EU standard contractual clauses (SCC) have been agreed,  
  • appropriate certifications or binding corporate rules (BCR) are in place, or  
  • you have expressly consented.  

Legal basis: Articles 44–49 GDPR. Further information on the currently recognized third countries and the EU standard contractual clauses can be found at the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de 

7. Storage period

We only store personal data for as long as is legally permitted or until you revoke your consent to processing. If the purpose for which we collected the data no longer applies or if there is no longer a legal basis for storing it, we will delete it.  

If certain data must be retained for other reasons—for example, because legal obligations require it or because it is needed to enforce, exercise, or defend legal claims—we will restrict processing to this purpose. In this case, the data will be blocked and not used for other purposes. 

8. Contact and inquiry management

When you contact us, for example via our contact form, by email, phone, or social media, we process your information in order to respond to your request and take all necessary steps. Depending on the nature of your inquiry, it may be processed by Mpire GmbH, which handles marketing, service, and administrative processes on our behalf.  

Depending on the situation, we process your data: 
  • to fulfill a contract or in the case of pre-contractual inquiries (e.g., offers, advice, appointments) 
  • on the basis of our legitimate interests, so that we can help you quickly and in a targeted manner 
  • to fulfill legal obligations, e.g., to archive important messages 
What data we process in this context:  
  • Inventory data (e.g., name, address) 
  • Contact details (e.g., email address, phone number) 
  • Content data (e.g., your message or information in the form) 
What we use your data for: 
  • To respond to your inquiry 
  • To serve you as a customer or prospective customer 
  • To maintain our business relationship  
Legal basis: 
  • Art. 6 (1) (b) GDPR (contract/pre-contractual measures) 
  • Art. 6 (1) (f) GDPR (legitimate interests) 
  • Art. 6 (1) (c) GDPR (legal obligation) 

 

Contact form 

If you use our contact form, we will process the data you enter solely for the purpose of processing your request. Mandatory fields are marked as such so that we can contact you specifically.  

Your information will be transmitted in encrypted form (SSL/TLS). If we use additional tools for the form, e.g., reCAPTCHA for spam protection, this will only be done with your consent in accordance with Art. 6 (1) lit. a GDPR in conjunction with § 25 (1) TDDDG. 

9. Visitors to our premises

If you visit us at our premises—for example, as a customer, partner, applicant, supplier, tradesman, or for any other business reason—please first report to our reception desk or gatekeeper. 

We usually collect the following personal data: Name Company or organization, if applicable Name of your contact person at our company Date and time of your visit 

Purpose of processing  

We process this data exclusively for the purpose of controlling access to our premises, ensuring security measures, and escorting you to your contact person.  

Video surveillance on company premises  

We use video surveillance in certain areas of our company premises and at the entrances. The recordings are used exclusively to ensure the protection of our employees, visitors, and our property, and to enable clarification in the event of security-related incidents.  

Legal basis  

The processing is based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR in maintaining the security of our company location, protecting our property, and preventing and investigating criminal offenses. 

Recipients of the data  

Only authorized internal departments have access to recordings. Data will only be passed to third parties if this is necessary to enforce legal claims or to investigate criminal offenses (e.g., to law enforcement authorities).  

Storage period  

Video recordings are generally deleted after 72 hours at the latest, unless they need to be evaluated in connection with a specific incident. Visitor data is only stored for as long as is necessary for the stated purpose and is then deleted, unless there are legal storage obligations. 

10. Advertising communications (email, post, telephone, etc.)

If you have given us your consent or if we are permitted to contact you within the scope of the legal possibilities, we will also use your contact details for advertising information, for example by email, telephone, post, or in rare cases by fax.  

You can revoke your consent at any time or object to receiving advertising at any time. After that, you will no longer receive any advertising from us.  

To be able to prove in the event of a dispute that you did in fact give your consent, we may store the necessary data for up to three years. During this time, it will only be used for this purpose and will be deleted afterwards. If you wish, we will also delete it earlier. In this case, we would need confirmation from you that you had given your consent. 

Legal basis:  
  • Consent (Art. 6 (1) (a) GDPR)  
  • Legitimate interest (Art. 6 (1) (f) GDPR) 

11. Applications

We have outsourced our application management and other commercial processes to Mpire GmbH, Manfred-von-Ardenne-Allee 33, 71522 Backnang, Germany. For applications, this means that your documents will be sent directly to Mpire GmbH, where they will be processed in consultation with us. You can find Mpire GmbH’s privacy policy here. 

Process 
  • Your application will be received directly by Mpire GmbH. 
  • Mpire will review your documents, consult with us, and coordinate communication with you. 
  • Your data will be used exclusively for the specific application process and will only be passed on to persons involved in it. 

Platform
 

Mpire GmbH uses the Personio platform, an external service provider (Personio SE & Co. KG, Seidlstraße 3, 80335 Munich), for applicant management. Personio processes your application data on our behalf in accordance with Art. 28 GDPR and hosts it on servers within the EU. More information: Service provider’s privacy policy. 


Processed data:
 
  • Personal details (name, address, contact details) 
  • Application documents (cover letter, resume, references) 
  • Proof of qualifications 
  • Any additional voluntary information 
  • Technical metadata for online applications 
Storage period:  
  • In case of rejection: deletion no later than 6 months after completion of the application process 
  • If accepted into our applicant pool: only with your consent 
  • If hired: transfer to the personnel management system of Mpire GmbH 
Legal basis: 
  • Art. 6 (1) (b) GDPR, § 26 BDSG (initiation/execution of an employment contract)  
  • Art. 6 (1) (a) GDPR (consent, e.g., applicant pool) 
  • Art. 9 (2) (b) GDPR (special categories of personal data, if necessary) 

12. Business services

As part of our business activities, we process personal data from customers, interested parties, partners, suppliers, service providers, and other business partners. We do this in order to initiate or fulfill contracts, organize cooperation, comply with legal obligations, and protect our legitimate interests – always in accordance with applicable data protection laws. If we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms apply to the relationship between users and providers.  

Our accounting and controlling are carried out by Mpire GmbH on our behalf. In doing so, personal data such as billing addresses, bank details, transaction data, and payment information are processed to the extent necessary to fulfill our legal and contractual obligations.  

Customers, partners, and interested parties 
We process your data in order to: 
  • provide the agreed services  
  • provide updates, warranty, and support in the event of service disruptions 
  • communicate with you before and after concluding a contract (e.g., to respond to inquiries)  
  • perform administrative and organizational tasks Protect our rights and prevent misuse 
Possible recipients: 
  • Telecommunications, transportation, IT, and cloud service providers 
  • Subcontractors 
  • Banks, tax, and legal advisors 
  • Payment service providers or tax authorities 
  • Trading and leasing partners 
  • Service partners 
Typical types of data: 
  • Master data (e.g., name, address) 
  • Contact details (e.g., email, phone number) 
  • Contract data (e.g., contract content, term, customer category) 
  • Payment data (e.g., bank details, invoices, payment history)  
Storage period: 
  • Contract data: generally 4 years after the end of the warranty or comparable obligations 
  • Tax-relevant documents: generally 10 years 
  • Order data: after the end of the order, to the extent permitted by law 
Legal basis:  
  • Contract fulfillment and pre-contractual inquiries (Art. 6 (1) (b) GDPR) 
  • Legal obligations (Art. 6 (1) (c) GDPR) 
  • Legitimate interests (Art. 6 (1) (f) GDPR) 

 

Suppliers, service providers, and other business partners 

If you work with us as a supplier, service provider, or business partner, we process your personal data to fulfill our contractual agreements, organize our collaboration, and comply with legal requirements. The initiation, management, and processing of orders with suppliers and partners is carried out both by us and on our behalf by Mpire GmbH. The personal data necessary for this purpose is processed. 

This includes, for example: 

  • Reviewing and managing offers, contracts, and invoices 
  • Communicating with you (including before the conclusion of a contract)  
  • Coordinating deliveries, services, or projects 
  • Fulfilling legal documentation and retention obligations 
  • Protecting our rights, e.g., claims management or legal disputes 
Possible recipients: 
  • Internal departments 
  • External service providers   
  • Banks, tax and legal advisors 
  • Authorities and public bodies (if required by law) 
Typical types of data: 
  • Master data (e.g., name, company name, address) 
  • Contact details (e.g., email, telephone number) 
  • Contract and service data (e.g., contract content, delivery or service records)  
  • Billing and payment data (e.g., bank details, invoices, payment history) 
Storage period:  
  • Contract and service data: generally 4 years  
  • Tax-related documents: generally 10 years  
  • General communication data: as soon as it is no longer required  
Legal basis:  
  • Contract fulfillment and pre-contractual measures (Art. 6 (1) (b) GDPR)  
  • Legal obligations (Art. 6 (1) (c) GDPR) 
  • Legitimate interests (Art. 6 (1) (f) GDPR) 

 

Other categories 
Economic analyses and market research 

We analyze business transactions, contracts, inquiries, and usage data to identify market trends, improve our services, and evaluate marketing measures. We evaluate data in a pseudonymized or anonymized form wherever possible. Results are not passed on to third parties unless they are anonymous overall analyses. 

Education and training services 

When participating in training or education programs, we process personal data for the purposes of organization, implementation, and, if necessary, performance evaluation. Where necessary, we transfer data to external service providers or authorities, always in compliance with legal requirements.  

Craft, project, and development services as well as technical services 

We process our customers’ personal data as required for quotations, implementation, and billing. If we gain access to third-party data (e.g., employees or end customers) in the process, processing is carried out in accordance with contractual and legal provisions.  

Types of data processed: 
  • Inventory data (e.g., names, addresses) 
  • Payment data (e.g., bank details, invoices, payment history)  
  • Contact data (e.g., email, telephone numbers) 
  • Contract data (e.g., subject matter of the contract, term, customer category) 
  • Usage data (e.g., websites visited, access times) 
  • Meta/communication data (e.g., device information, IP addresses) 
Affected persons:   
  • Prospective customers  
  • Business and contractual partners  
  • Customers  
  • Trainees and trainees  
Purposes of processing:   
  • Provision of contractual services  
  • Customer service  
  • Contact requests  
  • Organization  
  • Security measures  
  • Conversion measurement  
  • Marketing analyses  
  • User profiles 
Legal bases: 
  • Contract fulfillment and pre-contractual inquiries (Art. 6 (1) (b) GDPR) 
  • Legal obligations (Art. 6 (1) (c) GDPR) 
  • Legitimate interests (Art. 6 (1) (f) GDPR) 

13. Hosting and access data

Our IT systems and internal applications are operated and maintained by Mpire GmbH. Access to personal data may occur in the context of maintenance, support, or administration. This occurs exclusively in accordance with data protection regulations.  

Our website is operated on servers belonging to IONOS SE. In order to provide a stable, secure, and user-friendly online service, we use various hosting services. These include computing capacity, storage space, security functions, technical support, email hosting, and the provision of infrastructure and platform services.  

Collection of access data and log files 

Every time our website is accessed, so-called server log files are automatically collected. These include, among other things: IP address and provider Browser type and version Operating system Referrer URL (previously visited page) Date, time, and duration of access Content or files accessed  

The log files are used to ward off attacks (e.g., DDoS), optimize loading times, fix errors, and ensure secure operation. They are usually stored for a maximum of 30 days and then deleted or anonymized—unless they are needed for a specific security or evidence purpose for a longer period. 

Email hosting 

Email is also processed (sending, receiving, and storage) as part of the hosting services. This involves data such as sender and recipient addresses, provider information, and content. Please note: Emails are generally not end-to-end encrypted on the internet. They are usually encrypted during transport, but not necessarily on all servers. 

Content Delivery Network (CDN) 

We use a Content Delivery Network (CDN) to deliver large files (e.g., images, scripts) more quickly. This allows content to be delivered to you more efficiently from regionally distributed servers. 

Types of data processed: 
  • Content data (e.g., entries in online forms)  
  • Usage data (e.g., websites visited, access times, interests) 
  • Meta/communication data (e.g., device information, IP addresses) 
Data subjects: 
  • Users (e.g., website visitors, users of online services) 
Purposes of processing: 
  • Provision and security of our online offering 
  • User-friendliness and optimization of loading times 
  • Provision of contractual services and customer service 
Legal basis: 

Processing is based on our legitimate interests in the secure, efficient, and user-friendly provision of our website (Art. 6 (1) (f) GDPR). 

Services and service providers used: 
  • WordPress.com, hosting platform for websites   
    Service provider: Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA   
    Website: wordpress.com   
    Privacy policy: Automattic Privacy  

14. Video conferences, online meetings, webinars, and screen sharing

We use platforms and applications from other providers (“conference platforms”) to conduct video and audio conferences, webinars, and other online meetings. We comply with legal requirements when selecting these services.  

Types of data processed: 
  • Inventory data (e.g., names, addresses) 
  • Contact details (e.g., email, phone numbers) 
  • Content data (e.g., entries in chats or forms) 
  • Usage data (e.g., participation in meetings, access times)  
  • Meta/communication data (e.g., device information, IP addresses) 
Data subjects: 
  • Communication partners 
  • Users (e.g., participants in webinars, conferences, and online meetings)  
Purposes of processing: 
  • Conducting online meetings, webinars, and conferences 
  • Communication and collaboration 
  • Provision of contractual services and customer service 
  • Office and organizational procedures 
Legal bases: 
  • Consent (Art. 6(1)(a) GDPR)  
  • Contract fulfillment and pre-contractual inquiries (Art. 6 (1) (b) GDPR) 
  • Legitimate interests (Art. 6 (1) (f) GDPR) 
Services and providers used:  
  • Microsoft Teams (service provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA).  

Note: Microsoft also processes data in the USA, among other places, where, in the opinion of the European Court of Justice, there is no adequate level of data protection. Microsoft also uses standard contractual clauses in accordance with Art. 46 GDPR.  

More information: Microsoft Privacy Statement 

15. Cookies and consent management

Our website uses cookies. These are small text files or similar storage notes that are stored on your device. They store information and can also read it again—for example, to secure your login status, save contents in your shopping cart, or remember which pages and functions you have used.  

We use cookies for various purposes:  
  • Technically necessary cookies: These ensure that basic functions of our website work, e.g., login, navigation, or security features.  
  • Analysis and marketing cookies: These help us analyze the use of our website and optimize marketing measures. These cookies are only activated with your express consent.  
Legal basis  
  • Technically necessary cookies: Art. 6 (1) lit. f GDPR (legitimate interest)  
  • Analysis and marketing cookies: Art. 6 (1) (a) GDPR (consent)  

Our consent management tool Complianz obtains and logs your consent. You can revoke or adjust your consent at any time for the future via the cookie settings on this website. 

Storage period  

Temporary cookies (session cookies): These are deleted as soon as you leave the website and close your browser.  

Permanent cookies: These remain stored even after you close your device, e.g., to secure login data or display preferred content directly. Without specific information on the storage period, cookies can remain on your device for up to two years. 

Revocation and objection 

You can revoke your consent at any time. You also have the right to object to the processing of cookie data (Art. 21 GDPR). You can declare your objection via the cookie settings or directly in your browser.  

Management of cookie consent  

We store your consent in our cookie consent management system so that you do not have to reconfirm it each time you visit. This involves storing pseudonymous user identifiers, the time of consent, browser, system, and device information, and details on the scope of consent. This information may be stored for up to two years. 

You can find more detailed information on the individual cookies, their function, storage duration, and third-party providers used in the cookie settings of our tool and in the other sections of this privacy policy. 

16. Web analysis, monitoring, and optimization

We want to understand how you use our website so that we can continuously improve it for you. That is why we use web analysis tools (also known as “reach measurement”). This allows us to see, for example, which content is most interesting, how often certain pages are visited, or at what time of day there are particularly many visitors.  

Technical information such as your browser, operating system, the time of your visit, or your (truncated) IP address may also be processed. We do not store or process real names or email addresses, only pseudonymized data.  

If you give us your consent, we may also set cookies or read information from your device to improve your user experience. Without your consent, we limit ourselves to the minimum that is technically and legally permissible.  

In short, we use analytics to provide you with a better, faster, and more relevant online experience. This is implemented by Mpire GmbH. 

Types of data processed: Usage data (e.g., pages visited, clicks, length of stay), technical metadata (e.g., device information, truncated IP address).  

Data subjects: Visitors to our website. 

Purposes of processing: Reach measurement, performance optimization, content improvement. 

Security measures: IP masking (truncation of your IP address). 

Legal basis: 

  • Consent (Art. 6(1)(a) GDPR) 
  • Legitimate interest in a user-friendly and economical online offering (Art. 6(1)(f) GDPR) 

 

Google Analytics 

This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, length of stay, operating systems used, and the origin of the user. This data is summarized in a user ID and assigned to the respective end device of the website visitor. Furthermore, we can use Google Analytics to record your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data sets and uses machine learning technologies in data analysis. Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there. The use of this service is based on your consent in accordance with Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG. Consent can be revoked at any time. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/. 

IP anonymization  

Google Analytics IP anonymization is activated. This means that your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before being transmitted to the US. Only in exceptional cases will the full IP address be transmitted to a Google server in the US and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. 

Browser plugin 

You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. 

For more information on how Google Analytics handles user data, please refer to Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de. 

 

Google Tag Manager 

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is a tool that helps us integrate tracking or statistics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It is used solely for the administration and playback of the tools integrated via it. However, Google Tag Manager collects your IP address, which may also be transferred to Google’s parent company in the United States. The use of Google Tag Manager is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the fast and uncomplicated integration and administration of various tools on its website. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when data is processed in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780. 

17. Online marketing

We use online marketing measures to tailor content and advertisements on our website to the interests of users, to measure their reach, and to optimize our offerings. For this purpose, we may process personal data, in particular usage data (e.g., pages visited, click behavior, access times) and meta/communication data (e.g., device information, IP address).   

Cookies or similar technologies may be used for this purpose to create pseudonymous usage profiles. These profiles do not contain any clear data such as name or email address, so no direct identification takes place. If you agree to their use, this data may also be linked to your profiles with external providers (e.g., Google).  

Google Marketing Platform / Google Ad Manager 

We use the “Google Marketing Platform” (and services such as “Google Ad Manager”) to place ads on the Google advertising network (e.g., in search results, in videos, on websites, etc.). The Google Marketing Platform is characterized by the fact that ads are displayed in real time based on the presumed interests of users. This allows us to display ads for and within our online offering in a more targeted manner, so that users are only presented with ads that potentially match their interests. If, for example, a user is shown ads for products that they have shown interest in on other online offerings, this is referred to as “remarketing”; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Further information: Types of processing and data processed: https://privacy.google.com/businesses/adsservices; Data processing terms for Google advertising products: Information about the services Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms; if Google acts as a processor, data processing terms for Google advertising products and standard contractual clauses for third-country data transfers: https://business.safety.google/adsprocessorterms.   

Google Ads / Conversion Tracking 

We use the online marketing method “Google Ads” to place ads in the Google advertising network (e.g., in search results, in videos, on websites, etc.) so that they are displayed to users who are likely to be interested in the ads (so-called “conversion”). We also measure the conversion of the ads. However, we only learn the anonymous total number of users who clicked on our ad and were redirected to a page tagged with a so-called “conversion tracking tag.” However, we ourselves do not receive any information that can be used to identify users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy policy: https://policies.google.com/privacy; Further information: Types of processing and data processed: https://privacy.google.com/businesses/adsservices; Data processing terms for Google advertising products: Information about the services Data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.  

The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. Consent can be revoked at any time. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:  https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780. 

Google Analytics / Remarketing Audiences  

We use Google Analytics to display ads placed within Google’s advertising services and those of its partners only to users who have shown an interest in our online offering or who have certain characteristics (e.g., interests in certain topics or products, which are determined based on the websites visited) that we transmit to Google (so-called “remarketing audiences”). “Google Analytics Audiences”). With the help of remarketing audiences, we also want to ensure that our ads match the potential interests of users; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Legal basis: https://business.safety.google/adsprocessorterms/; Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Further information: Types of processing and data processed: https://privacy.google.com/businesses/adsservices; Data processing terms for Google advertising products and standard contractual clauses for third-country transfers of data: https://business.safety.google/adsprocessorterms.  

18. Presence on social networks (social media)

We maintain an online presence on social networks and process user data in this context in order to communicate with people who are active there or to provide information about us. The maintenance of our social media channels and the evaluation of interactions is carried out on our behalf by Mpire GmbH.  

We would like to point out that user data may also be processed outside the European Union. This may result in risks for users, for example, because it could make it more difficult to enforce their rights.  

Furthermore, user data within social networks is generally processed for market research and advertising purposes. This allows user profiles to be created based on user behavior and resulting interests. These profiles can in turn be used to place advertisements within and outside the networks that are presumed to correspond to the interests of the users. For this purpose, cookies are usually stored on users’ end devices, in which their usage behavior and interests are stored. In addition, data can also be stored across devices in the profiles (especially if users are members of the respective platforms and are logged in to them). 

For a detailed description of the respective forms of processing and the options for objection (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.  

In the case of requests for information and the assertion of data subject rights, we also recommend contacting the providers directly. Only they have access to user data and can take appropriate measures and provide information directly. However, if you still require assistance, you can contact us.  

  • Types of data processed: Contact data (e.g., email, phone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta/communication data (e.g., device information, IP addresses).  
  • Data subjects: Users (e.g., website visitors, users of online services).  
  • Purposes of processing: Contact requests and communication; feedback; marketing.  
  • Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). 

 

Further information on processing operations, procedures, and services
  • Facebook pages: Profiles within the Facebook social network – Together with Meta Platforms Ireland Limited, we are responsible for collecting (but not further processing) data from visitors to our Facebook page (“fan page”). This data includes information about the types of content users view or interact with, or the actions they take (see “Things you and others do and provide” in the Facebook Data Policy), as well as information about the devices used (e.g., IP addresses, operating system, browser type, language settings, cookie data; see “Device Information” in the Facebook Data Policy). Facebook also collects and uses this information to provide analytics services (“Page Insights”). We have entered into a special agreement with Facebook (“Information on Page Insights”) which, among other things, regulates security measures and obliges Facebook to comply with data subject rights. Further information can be found in Facebook’s Terms of Service. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Standard Contractual Clauses: EU Data Transfer Addendum. 
  • Vimeo: Video platform; service provider: Vimeo Europe Limited, 6–8 Merrion Row, Dublin 2, D02 K283, Ireland; privacy policy: https://vimeo.com/privacy   

 

In addition to our presence on social networks, we also use the business and marketing tools offered by the platforms when you contact us via our Facebook, Instagram, or LinkedIn page or interact with our posts. These include in particular: 

  • Lead forms: If you fill out a form within the platform (e.g., to request information or register for an event), we process the data contained therein in order to handle your request. The legal basis for this is—depending on the content of your request—your consent (Art. 6 (1) (a) GDPR) or the implementation of pre-contractual measures (Art. 6 (1) (b) GDPR).  
  • Target group uploads (“Custom Audiences” on Meta / “Matched Audiences” on LinkedIn): If we show you targeted advertising on the networks based on existing customer data, we only do so if you have consented to this or if we are permitted to do so on the basis of our legitimate interests in targeted marketing (Art. 6 (1) (a) or (f) GDPR).  
  • Insights and analyses: We receive statistical data from the platform operators on the use of our pages (e.g., which posts were viewed or clicked on and how often). This data is usually anonymous to us and helps us to improve our content. 
  • Advertisement tracking: When you interact with an advertisement placed by us, the platform may provide us with aggregated information about how successful this campaign was.  

Meta and LinkedIn also process the data independently for their own purposes. We have no influence on this processing. You can find more information in the respective privacy policies: 

19. Plugins and embedded content

On our website, we sometimes use functions and content from other providers (“third-party providers”). These can be, for example, videos, maps, fonts, or social media feeds that we integrate so that you can use additional information and services directly on our site.  

In order for this content to be displayed in your browser, it is technically necessary for your device to contact the server of the respective provider. This usually also involves the processing of your IP address. Some third-party providers also use so-called pixel tags or cookies, for example, to evaluate the use of the content or to improve marketing measures. This data can be linked to information from other sources in pseudonymized form.  

We take care to only integrate services that process your data in accordance with the GDPR and TDDDG. If a service uses cookies or similar technologies, we will ask for your consent in advance via our cookie banner. Such content will not be loaded without your consent.  

Types of data processed: Usage data (e.g., pages visited, access times), meta/communication data (e.g., IP address, device information), inventory data (e.g., name, address), contact data (e.g., email), content data (e.g., entries in online forms).  

Data subjects: Visitors to our website. 

Purposes of processing: Presentation of content, user-friendliness, marketing, and statistical evaluations.  

Legal basis: Consent (Art. 6 (1) (a) GDPR, § 25 TDDDG), fulfillment of contract (Art. 6 (1) (b) GDPR), legitimate interest (Art. 6 (1) (f) GDPR). 

 

Services used   
Google Fonts 

This site uses Google Fonts, which are provided by Google, to ensure uniform font display. When you visit a page, your browser loads the required fonts into your browser cache to display text and fonts correctly. To do this, the browser you are using must connect to Google’s servers. This allows Google to know that this website has been accessed via your IP address. The use of Google Fonts is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the uniform presentation of the typeface on its website. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time. If your browser does not support Google Fonts, a standard font from your computer will be used. Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=de. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the US that aims to ensure compliance with European data protection standards when data is processed in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780. 

Google Maps 

This site uses the Google Maps map service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to integrate map material into our website. To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer. If Google Maps is activated, Google may use Google Fonts for the purpose of uniform font display. When you access Google Maps, your browser loads the required web fonts into your browser cache to display texts and fonts correctly. Google Maps is used in the interest of an appealing presentation of our online offerings and to make it easy to find the locations we have indicated on the website. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time. Data transfer to the USA is based on the standard contractual clauses. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/. For more information on how user data is handled, please refer to Google’s privacy policy: https://policies.google.com/privacy?hl=de 

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the US that aims to ensure compliance with European data protection standards when processing data in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780. 

YouTube with enhanced data protection 

This website embeds videos from the YouTube website. The website is operated by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. When you visit one of these websites that incorporates YouTube, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to associate your surfing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account. We use YouTube in extended data protection mode. According to YouTube, videos played in extended data protection mode are not used to personalize browsing on YouTube. Ads played in extended data protection mode are also not personalized. No cookies are set in extended data protection mode. Instead, however, so-called local storage elements are stored in the user’s browser, which, similar to cookies, contain personal data and can be used for recognition. Details on enhanced privacy mode can be found here: https://support.google.com/youtube/answer/171780. After a YouTube video has been activated, further data processing operations may be triggered over which we have no control. YouTube is used in the interest of an appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time. Further information on data protection at YouTube can be found in their privacy policy at: https://policies.google.com/privacy?hl=de. 

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the US that aims to ensure compliance with European data protection standards when processing data in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780 

Vimeo Without Tracking (Do-Not-Track) 

This website uses plugins of the Vimeo video portal. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA. Whenever you visit one of our pages featuring Vimeo videos, a connection with the servers of Vimeo is established. In conjunction with this, the Vimeo server receives information about which of our sites you have visited. Vimeo also receives your IP address. However, we have set up Vimeo in such a way that Vimeo cannot track your user activities and does not place any cookies. We use Vimeo to make our online presentation attractive for you. This is a legitimate interest on our part pursuant to Art. 6(1)(f) GDPR. If a respective declaration of consent was requested (e.g. concerning the storage of cookies), processing shall occur exclusively on the basis of Art. 6(1)(a) GDPR; the given consent may be revoked at any time. Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission and, according to Vimeo, on “legitimate business interests”. Details can be found here: https://vimeo.com/privacy. For more information on the handling of user data, please consult Vimeo’s data privacy policy at: https://vimeo.com/privacy 

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5711. 

20. Links to other websites

If we provide links to websites of other organizations, the privacy policies and statements of those websites apply.

21. Trade fairs, events, product training, and training courses

As part of our marketing and sales activities, we participate in trade fairs, specialist events, and other events, and conduct our own product training and training courses. In doing so, we process personal data that we receive directly from you—for example, when you give us your business card, register for an event, participate in a product demonstration, or provide your contact details during a training session.  

Purposes of processing:  
  • Planning, organizing, and conducting the event 
  • Contacting you to arrange appointments and send relevant event information 
  • Sending accompanying materials, product information, or further offers 
  • Lead generation: Collecting and maintaining data on interested parties that is provided at trade fairs and events or collected electronically in order to provide the requested information and deepen contact 
  • Documenting and following up on the event (e.g., participant lists, feedback evaluations) 
Categories of data processed: 
  • Master data (name, title, company, position, address)  
  • Contact details (phone number, email address) 
  • Information on interests and inquiries (e.g., desired product information, requested services, project status) 
  • Event-related information (e.g., on participation, travel) 
  • Photo or video recordings, if applicable (only with prior consent) 
Legal basis:  
  • Art. 6 (1) (b) GDPR (performance of a contract, e.g., in the case of a binding registration for a training course)  
  • Art. 6 (1) (f) GDPR (legitimate interest in efficient event organization, customer care, and follow-up sales activities) 
  • Art. 6 (1) (a) GDPR (consent, e.g., for photo/video recordings, electronic lead capture, or subsequent newsletter dispatch)  
Recipient: 

The planning, organization, implementation, and follow-up of our trade fair appearances, events, product training, and training courses—including lead capture and processing—is carried out on our behalf by Mpire GmbH, Manfred-von-Ardenne-Allee 33, 71522 Backnang, Germany. Mpire is therefore also the recipient of the personal data collected in the course of these activities and processes it in accordance with data protection regulations. 

Storage period: 

Your data will be deleted as soon as it is no longer required for the aforementioned purposes, unless legal retention obligations prevent deletion or you have expressly consented to longer storage. 

22. Management, organization, and support tools

We use services, platforms, and software from other providers such as IT and cloud service providers, shipping and payment service providers (hereinafter referred to as “third-party providers”) for the purposes of organization, administration, planning, and provision of our services. We comply with legal requirements when selecting these third-party providers and their services.   

In this context, personal data may be processed and stored on the servers of third-party providers. This may include, in particular, master data and contact details, data on transactions, contracts, other processes, and their contents.  

If users are referred to third-party providers or their platforms in the course of communication or business relations with us, these third-party providers may process usage data and metadata for security purposes, service optimization, or marketing purposes. We therefore ask you to observe the data protection information of the respective third-party providers. 

Information on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis is consent. Furthermore, the use may be part of our (pre)contractual services, provided that it has been agreed within this framework. Otherwise, processing is based on our legitimate interests (Art. 6 (1) (f) GDPR) in efficient, economical, and recipient-friendly services. 

Types of data processed: Content data, usage data, meta/communication data, inventory data, contact data.  

Data subjects: Communication partners, users (e.g., website visitors, users of online services)  

Purposes of processing: Contact requests and communication, office and organizational procedures.  

Legal basis: Consent (Art. 6(1)(a) GDPR), performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).  

Further information on processing procedures, processes, and services 

 

23. Changes and updates to this privacy policy

Please check the content of this privacy policy regularly. We will amend it as soon as there are any changes to the data processing we carry out. If this requires your cooperation (e.g., new consent) or individual notification, we will inform you accordingly.  

If we mention addresses or contact information for companies and organizations in this privacy policy, please note that these may change over time. It is therefore best to check the information before contacting us. 

Last update: March 13, 2026 

24. Rights of data subjects

According to Articles 15 to 21 GDPR, you have various rights with regard to your personal data. These include in particular: 

  • Right to object: If we process your personal data on the basis of Article 6(1)(e) or (f) GDPR, you have the right to object to this at any time for reasons arising from your particular situation. This also applies to profiling based on these legal grounds.  After your objection, we will no longer process your data unless we can demonstrate compelling legitimate grounds that outweigh your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.  
  • Objection to direct marketing: If we use your personal data for direct marketing, you can object to this at any time – including any associated profiling.  After you object, we will no longer use your data for this purpose.  
  • Withdrawal of consent: If you have given us your consent to process your data, you can withdraw it at any time with effect for the future. 
  • Information: You have the right to know whether we process your personal data. If so, you will receive information about this on request, as well as a copy of this data and other information required by law. 
  • Correction: You may have incorrect or incomplete personal data corrected or completed in accordance with legal requirements.  
  • Deletion and restriction: You may request that we delete your personal data or, alternatively, request a restriction on processing, in each case within the framework of legal requirements.  
  • Data portability: You have the right to receive the data you have provided in a structured, commonly used, and machine-readable format or to have it transferred to another controller, insofar as this is technically feasible.  
  • Right to lodge a complaint: If you believe that the processing of your personal data violates the GDPR, you can lodge a complaint with a supervisory authority – in particular in the Member State of your residence, your place of work, or the place of the alleged violation. 

25. Supervisory authority

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg  
Heilbronner Str. 35  
70191 Stuttgart  
Germany 

Phone: +49 711 6155410  
Email: poststelle@lfdi.bwl.de 

Contacts

Controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member states of the European Union and other provisions related to data protection is:

RIVA GmbH Engineering

Manfred-von-Ardenne-Allee 33

D - 71522 Backnang

Tel.: +49 7191 904 38-0

Fax: +49 7191 904 38-25

Data protection officer:

disiviva

Daniel Voigtländer  
Zeisigweg 11  
71397 Leutenbach-Nellmersbach  
+49 7195 9772959  
daniel.voigtlaender@disiviva.de 

Any data subject can contact our data protection officer at any time with any questions or suggestions regarding data protection.