Privacy Policy
Trust begins with transparency. Here you'll find everything you need to know about how PSI Technics processes and protects personal data — and how we uphold your rights as a user.
Privacy Policy
1. Data Protection at a Glance
The protection of your personal data is important to us. This Privacy Policy provides you with comprehensive information on the nature, scope, and purpose of the processing of personal data in connection with the use of our website, as well as on your rights as a data subject.
Personal data means any data that can be used to identify you personally. Our website can generally be used without providing personal data. Insofar as personal data (such as name, address, or email address) is collected on our pages, this is always done on a voluntary basis or within the scope of the purposes described below.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection provisions is:
PSI Technics GmbH
An der Steinkaul 6a, 56333 Winningen, Germany
Email: info@psi-technics.com
Phone: +49 2630 91590 0
Authorized to represent the company: Managing Shareholder Karl-Heinz Förderer
Data Protection Contact
Responsibility for data protection is exercised by the management. If you have any questions about data protection or wish to exercise your rights as a data subject, please contact:
Karl-Heinz Förderer
Phone: +49 2630 91590 0
Email: datenschutz@psi-technics.com
3. General Information on Data Processing
3.1 Legal Bases
We only process personal data where a legal basis exists. Depending on the specific processing situation, we rely on:
- Art. 6(1)(a) GDPR – consent
- Art. 6(1)(b) GDPR – performance of a contract and pre-contractual measures
- Art. 6(1)(c) GDPR – compliance with a legal obligation
- Art. 6(1)(f) GDPR – legitimate interests
3.2 Retention Period
Unless a specific retention period is stated in this Policy, we process personal data only for as long as necessary to achieve the respective purpose, or as required by statutory retention obligations (in particular under commercial and tax law pursuant to Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO) – generally 6 to 10 years).
3.3 Recipients of Data
Your data is transferred to third parties only where legally permitted, where you have given your consent, or where this is necessary for the performance of a contract. Where we engage processors, this is done on the basis of agreements pursuant to Art. 28 GDPR.
4. Hosting & Server Log Files
Our website is hosted by an external service provider (host). When you access our website, the browser automatically transmits information to the server, which is temporarily stored in what are known as server log files:
- IP address of the requesting device
- Date and time of access
- Name and URL of the page accessed
- Browser type and version
- Operating system used
- Referrer URL (the previously visited page)
- Volume of data transferred and access status
This data serves the technical security, stability, and functionality of our website, as well as the defense against attacks. This data is not combined with other data sources.
We use the webEdition content management system to create and manage the content of our website. The CMS runs on the hosting infrastructure we use (see below); use of the CMS itself does not involve any transfer of personal data to third parties.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and stable provision of our website
We have entered into a data processing agreement (DPA) with our host pursuant to Art. 28 GDPR.
Host: IONOS SE Elgendorfer Str. 57, 56410 Montabaur, Germany
The personal data collected through our website is stored on IONOS's servers. This may in particular include IP addresses, contact inquiries, meta and communication data, contract data, contact details, names, website visits, and other data generated through the website.
IONOS is used for the purpose of performing contracts with our prospective and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) of the German Telecommunications-Digital-Services Data Protection Act (TDDDG), insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
IONOS will process your data only to the extent necessary to fulfil its contractual obligations and will follow our instructions with respect to this data. The DPA concluded with IONOS ensures that the personal data of our website visitors is processed only in accordance with our instructions and in compliance with the GDPR.
Microsoft 365 / Exchange Online (Email Communication)
For our email communication and related Office applications, we use Microsoft 365 (Exchange Online) provided by Microsoft Ireland Operations Ltd. (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). This involves the processing and storage of the content, connection, and metadata of email communication conducted through us (e.g., sender, recipient, subject, content, timestamp).
Mailboxes are hosted in Microsoft data centers within the European Union. However, the processing of personal data in third countries, in particular the USA (e.g., in connection with support, telemetry, or by the parent company Microsoft Corporation), cannot be completely ruled out in individual cases.
The purpose of the processing is to conduct and manage our business email communication.
Legal basis: Art. 6(1)(b) GDPR (initiation and performance of contracts) as well as Art. 6(1)(f) GDPR (legitimate interest in a professional, secure, and efficient email infrastructure).
We have entered into a data processing agreement with Microsoft pursuant to Art. 28 GDPR (Microsoft Data Protection Addendum). To the extent personal data is exceptionally transferred to the USA, the level of protection is safeguarded through Microsoft's certification under the EU-US Data Privacy Framework (DPF) as well as, additionally, through the EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
Retention period: We store emails for as long as necessary for the respective communication; business-relevant emails are additionally subject to the statutory retention periods (Sections 257 HGB, 147 AO – generally 6 to 10 years).
Further information: https://privacy.microsoft.com/en-us/privacystatement
5. Cookies
Our website uses cookies and similar technologies. Cookies are small text files that are stored on your device.
5.1 Technically Necessary Cookies
These cookies are required to ensure the basic functions of the website, in particular:
- Navigation and page changes
- Security functions
- Form and input functions
- Storage of your cookie consent
Legal basis: Section 25(2) No. 2 TDDDG (strictly necessary storage) in conjunction with Art. 6(1)(f) GDPR. Consent is not required for this.
5.2 Cookies and Services Requiring Consent
Our website integrates external services that are not strictly necessary for its operation and which, upon being accessed, establish connections to third-party servers and may store or retrieve information on your device. This applies in particular to Google Web Fonts and embedded YouTube videos (see Section 11). These services are only loaded after you have given your consent via the consent banner.
Legal basis: Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Your consent may be withdrawn at any time with effect for the future (see Section 6).
6. Consent Management (Consent Banner)
When you first visit our website, you are asked via a consent banner to give your consent to the use of non-essential cookies and/or services. Your selection is stored.
You may withdraw or adjust your consent at any time with effect for the future by accessing the cookie settings via the banner or the corresponding link. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
7. White Paper, Contact Form & Communication
If you request a white paper via the corresponding request form, or contact us via the contact form, by email, or by telephone, we process the data you provide to us, in particular:
- Name / company
- Email address
- Telephone number (if provided)
- Content of your message
Purpose: Processing and responding to your inquiry, as well as the initiation of possible business relationships.
Legal bases:
- Art. 6(1)(b) GDPR, insofar as your inquiry is directed at the conclusion or performance of a contract
- Art. 6(1)(f) GDPR in all other respects (legitimate interest in processing inquiries)
Retention period: We delete the data as soon as processing of your inquiry has been completed and no statutory retention obligations preclude deletion.
8. Customer and Supplier Data
In connection with the initiation, conclusion, and performance of contracts, we process personal data of our customers, prospective customers, and suppliers, or of the contact persons acting on their behalf, in particular contact, contract, and billing data.
Purpose: Performance of the contractual relationship, communication, invoicing, and compliance with statutory obligations.
Legal bases:
- Art. 6(1)(b) GDPR (performance of a contract)
- Art. 6(1)(c) GDPR (compliance with legal obligations, in particular under commercial and tax law)
- Art. 6(1)(f) GDPR (legitimate interest in the proper conduct of business)
Retention period: The data is stored for the duration of the business relationship and beyond that in accordance with the statutory retention periods (Sections 257 HGB, 147 AO – generally 6 to 10 years), after which it is deleted.
9. CRM System
We use a customer relationship management (CRM) system to manage relationships with customers and prospective customers. In it, we process contact and communication data (e.g., name, company, email address, telephone number, correspondence history) in order to process inquiries, maintain business relationships, and document sales processes.
As our CRM/ERP system, we use APplus by Asseco Solutions AG (Amalienbadstraße 41C, 76227 Karlsruhe, Germany). The system is operated on our own IT infrastructure (on-premises); the personal data is processed and stored exclusively on our own servers in Germany. The data is not transferred to the software manufacturer or to third parties in the course of regular operations. Where, in individual cases, the manufacturer or a service provider requires access to personal data in connection with maintenance or support, this is carried out on the basis of a data processing agreement (DPA) pursuant to Art. 28 GDPR.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures) as well as Art. 6(1)(f) GDPR (legitimate interest in efficient customer management).
10. Applications
If you apply to work with us, we process the application data you submit (e.g., cover letter, CV, references, contact details) exclusively for the purpose of conducting the application process.
Legal bases:
- Section 26(1) of the German Federal Data Protection Act (BDSG) (data processing for purposes of the employment relationship)
- Art. 6(1)(b) GDPR (initiation of an employment relationship)
Where your application contains special categories of personal data (e.g., information on a severe disability or health data), we process this data on the basis of Art. 9(2)(b) GDPR in conjunction with Section 26(3) BDSG in order to exercise rights and comply with obligations under employment law.
Retention period: In the event of a rejection, your application data is generally retained for up to 6 months after conclusion of the application process (among other things, to defend against potential claims under the German General Equal Treatment Act (AGG)) and is then deleted, unless you have expressly consented to longer storage (e.g., for a talent pool).
11. Third-Party Providers & Tools
The following external services are integrated into our website. Insofar as these are not strictly necessary, they are only loaded after you have given your consent via the consent banner (see Section 6).
Google Web Fonts
This website uses what are known as web fonts provided by Google for the uniform display of typefaces. When a page is accessed, your browser loads the required web fonts into its browser cache in order to display text and fonts correctly. For this purpose, the browser you use must connect to Google's servers. As a result, Google becomes aware that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our online offerings (Art. 6(1)(f) GDPR; where prior consent has been given, Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG). If your browser does not support web fonts, a standard font installed on your computer is used instead. Further information: https://developers.google.com/fonts/faq and https://policies.google.com/privacy?hl=en.
YouTube
We have integrated YouTube components into this website. YouTube is an internet video portal on which video content can be published and viewed, rated, and commented on by other users. This integration constitutes a legitimate interest in presenting videos on our website within the meaning of Art. 6(1)(f) GDPR (where prior consent has been given, Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG). YouTube is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube is a subsidiary of Google. YouTube's privacy policy can be found at: https://policies.google.com/privacy?hl=en. Through integrated YouTube components, YouTube and Google receive information about your visit to our website if you are logged into your YouTube account while visiting our website, regardless of whether you click on a YouTube video. To prevent this, you can log out of your YouTube account before visiting our website. Where applicable, the transfer of data to the USA is safeguarded through the EU-US Data Privacy Framework (DPF) as well as, additionally, through the EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
12. Social Media
We maintain profiles on social networks in order to communicate with prospective customers, customers, and applicants, and to provide information about our company:
- LinkedIn – LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
- Facebook / Instagram – Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland
If you visit or interact with one of our profiles, the respective provider processes your personal data (e.g., IP address, device information, interactions) under its own responsibility and in accordance with its own privacy policy. We have no influence over this processing; the respective provider's terms take precedence:
- LinkedIn: https://www.linkedin.com/legal/privacy-policy?_l=de_DE
- Facebook: https://www.facebook.com/policy.php
- Instagram: https://help.instagram.com/519522125107875
Joint Controllership (Art. 26 GDPR): For the processing of statistical data provided to us by the providers as part of what are known as page insights, we are jointly responsible together with the respective provider. In this context, we receive only anonymized or aggregated statistics on the use of our profiles (e.g., reach, interactions, audience composition) and have no access to the underlying individual personal data. We have entered into the “Page Insights – Controller Addendum” with Meta, and the corresponding “Page Insights Joint Controller” agreement with LinkedIn; the respective providers make the essential content of these agreements available via the links given above.
The legal basis for operating our profiles and evaluating the insights is our legitimate interest in effective external representation and communication (Art. 6(1)(f) GDPR).
Transfer to third countries: The providers also process your data in the USA. Where applicable, the transfer is safeguarded through the EU-US Data Privacy Framework (DPF) as well as, additionally, through the EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
Exercising your rights: Since our access to the data processed by the providers is limited, you can most effectively exercise your rights as a data subject (see Section 15) directly against the respective provider, which has the necessary means of access.
13. Obligation to Provide Data
Die Bereitstellung personenbezogener Daten ist – soweit nicht anders angegeben – weder gesetzlich noch vertraglich vorgeschrieben. Sie sind nicht verpflichtet, uns Unless stated otherwise, the provision of personal data is neither legally nor contractually required. You are not obliged to provide us with your data. However, if you do not provide certain data as part of an inquiry, order, or contract, we may not be able to process your inquiry or conclude or perform a contract. Which data is required is generally indicated in the respective input forms (mandatory fields).
14. No Automated Decision-Making
No automated decision-making in individual cases, including profiling within the meaning of Art. 22 GDPR, takes place. We do not use your personal data for automated decisions that produce legal effects concerning you or similarly significantly affect you.
15. Your Rights as a Data Subject
Subject to the applicable statutory requirements, you have the following rights at any time:
- Right to information about the data processed about you (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure of your data (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent given, with effect for the future (Art. 7(3) GDPR)
Right to object (Art. 21 GDPR): Insofar as we process data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds arising from your particular situation, to such processing.
Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority. The competent authority includes, among others: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate), Hintere Bleiche 34, 55116 Mainz, Germany
An informal notice to the contact details given in Section 2 is sufficient to exercise your rights.
16. Data Security
We take appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR to protect your data against loss, manipulation, and unauthorized access, including:
- SSL/TLS encryption of data transmission
- Access controls and authorization concepts
- Regular security and software updates
- Protection against data loss through back-up procedures
17. Links
For your optimal information, our pages contain links to third-party websites. Where such links are not clearly identifiable as such, we point out that this is an external link. PSI Technics has no influence whatsoever over the content and design of these third-party websites. The content of this Privacy Policy therefore does not apply to them.
18. Currency and Amendments
This Privacy Policy is current as of June 2026. As we further develop our website and our offerings, or due to changed statutory or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version can be accessed on our website at any time.
PSI Technics GmbH, Status: June 2026
