1. Data Controller
Pursuant to Article 4(7) GDPR, the data controller for this website is:
DerMech Solution GmbH
[PLACEHOLDER STREET ADDRESS]
[PLACEHOLDER CITY], [PLACEHOLDER POSTAL CODE]
Germany
Email
info@dermech-etc.com
2. Personal Data Collected
We collect and process personal data only when necessary for the provision of our services and always in compliance with GDPR. The following categories of personal data may be collected:
- Contact information: name, email address, phone number, company name
- Project-related data: service interests, project descriptions, technical requirements
- Technical data: IP address, browser type, access times, visited pages
- Communication data: content of inquiries, consultation notes, correspondence
3. Contact Form Data
When you submit our contact form, we process the following data for the purpose of handling your inquiry:
- Name and email address are mandatory fields required to respond to your inquiry
- Company, service interest, subject, and message are optional but help us provide tailored responses
- Data is stored securely and shared only with authorized personnel involved in your inquiry
- We retain contact form data for 36 months in compliance with German commercial law requirements
4. Cookies
Our website uses cookies to enhance user experience and analyze site traffic. Cookies are small text files stored on your device. We use:
- Essential cookies: Required for website functionality (language preference, session management)
- Analytics cookies: Help us understand how visitors interact with our website (Google Analytics, anonymized)
- No marketing cookies are used on this website
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect website functionality.
5. Analytics
We use Google Analytics to analyze website usage and improve our services. Google Analytics collects:
- Anonymized IP addresses (IP anonymization is enabled)
- Browser type, language settings, screen resolution
- Pages visited, time on page, referral source
- Interaction data: clicks, scrolls, form interactions
Google Analytics is configured with a 26-month retention period. You can opt out via browser add-on or cookie settings.
6. Server Logs
Our web hosting provider automatically records server log files containing:
- IP address and anonymized IP suffix
- Date and time of access
- Requested URL and HTTP status code
- Referring URL (if applicable)
- Browser and operating system information
Server logs are retained for 30 days for security and debugging purposes, then automatically deleted unless required for ongoing security investigations.
7. User Rights (GDPR Articles 15–22)
Under the General Data Protection Regulation, you have the following rights:
- Right of access (Art. 15): Request confirmation of data processing and obtain a copy of your personal data
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete personal data
- Right to erasure (Art. 17): Request deletion of personal data under certain conditions
- Right to restriction (Art. 18): Request limitation of data processing under certain conditions
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to object (Art. 21): Object to processing of personal data in certain circumstances
To exercise these rights, please contact us at info@dermech-etc.com with the subject line 'GDPR Data Request'. We will respond within 30 days.
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, regulatory, and contractual obligations:
- Contact form inquiries: 36 months (commercial law retention period)
- Client project data: 7 years (tax law requirements)
- Analytics data: 26 months (Google Analytics retention)
- Server logs: 30 days (security and debugging)
- Newsletter subscriptions: Until unsubscribe or 24 months of inactivity
9. International Data Transfers
DerMech Solution operates primarily from Germany and Taiwan. Personal data is processed within the European Economic Area (EEA) and Taiwan. Transfers to third countries occur only when:
- Adequate protection level exists (EU adequacy decision)
- Appropriate safeguards are in place (Standard Contractual Clauses, Binding Corporate Rules)
- Data subject has explicitly consented to the transfer after being informed of risks
- Transfer is necessary for contract performance or legal claims
In particular, Google Analytics data may be transferred to Google LLC in the United States. Google has implemented appropriate safeguards including EU Standard Contractual Clauses and is certified under the EU-US Data Privacy Framework.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for data transmission
- Secure hosting with regular security updates
- Access controls and authentication for authorized personnel only
- Regular security audits and vulnerability assessments
- Employee training on data protection and GDPR compliance