Data Policy

Preamble

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, the purposes for which we process them, and the extent of such processing. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as “online offering”).

The terms used are not gender-specific.

Last updated: August 11, 2026

Table of Contents

  • Preamble
  • Controller
  • Overview of Processing
  • Legal Bases
  • Security Measures
  • Transfer of Personal Data
  • International Data Transfers
  • Data Retention and Deletion
  • Rights of Data Subjects
  • Data Protection Officer
  • Provision of Online Services and Web Hosting
  • Use of Cookies
  • Contact and Inquiry Management
  • Marketing Communication
  • Social Media Presence
  • Changes and Updates

Controller

Dr. Guido Schroer / Dr. Tobias Riedl / Mr. Yannik Kohlhaas / Dr. Harald Rubner
Power2Polymers GmbH
Dennewartstrasse 25
52068 Aachen, Germany
Handelsregisternummer: HRB 28251, Amtsgericht Aachen
Umsatzsteuer-Identifikationsnummer (VAT ID): DE450454157

Email: founder@power2polymers.com

Imprint: https://www.power2polymers.com/

Overview of Processing

Types of Data Processed

  • Master data
  • Contact data
  • Content data
  • Usage data
  • Metadata, communication, and procedural data
  • Log data

Categories of Data Subjects

  • Communication partners
  • Users

Purposes of Processing

  • Communication
  • Security measures
  • Direct marketing
  • Organizational and administrative processes
  • Feedback
  • Marketing
  • Provision and improvement of our online services
  • IT infrastructure
  • Public relations
  • Sales promotion

Legal Bases

Relevant Legal Bases under GDPR

  • Consent (Art. 6(1)(a) GDPR)
  • Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)

National Regulations (Germany)

In addition to the GDPR, German data protection laws apply, particularly the Federal Data Protection Act (BDSG).

Note on Swiss Data Protection Law

Power2Polymers GmbH also processes personal data of customers based in Switzerland. This policy therefore also serves to provide the information required under the Swiss Federal Act on Data Protection (FADP/DSG). For consistency, the GDPR terminology used throughout this policy is applied to fulfil the equivalent Swiss DSG requirements as well.

Security Measures

We implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk, considering:

  • State of the art
  • Implementation costs
  • Nature, scope, and purpose of processing
  • Risks to individuals

Measures include safeguarding:

  • Confidentiality
  • Integrity
  • Availability of data

Transfer of Personal Data

Personal data may be shared with third parties such as:

  • IT service providers
  • Embedded service providers

We ensure appropriate safeguards through contracts and agreements.

International Data Transfers

Data transfers outside the EU/EEA occur only:

  • Based on adequacy decisions (Art. 45 GDPR), or
  • With safeguards such as standard contractual clauses (Art. 46 GDPR), or
  • With explicit consent

More information:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en

Data Retention and Deletion

Personal data is deleted when:

  • Consent is withdrawn, or
  • Legal basis no longer applies

Retention Periods (Germany)

  • 10 years: accounting records, financial statements
  • 6 years: business correspondence
  • 3 years: legal claims

Rights of Data Subjects

You have the following rights:

  • Right to object
  • Right to withdraw consent
  • Right of access
  • Right to rectification
  • Right to erasure and restriction
  • Right to data portability
  • Right to lodge a complaint with a supervisory authority

Data Protection Officer

We have not appointed a Data Protection Officer. If you have questions about our processing of personal data or wish to exercise your rights, please contact us directly using the details provided under “Controller” above.

Provision of Online Services and Web Hosting

We process user data to provide online services, including:

  • IP address
  • Usage data
  • Log files

Legal Basis

Legitimate interests (Art. 6(1)(f) GDPR)

Hosting Provider

IONOS SE, Germany

Use of Cookies

Cookies store and retrieve information on user devices.

Types

  • Session cookies
  • Persistent cookies (up to 2 years)

Legal Basis

  • Consent (Art. 6(1)(a) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)
  • Consent under Section 25 TTDSG (German Telecommunications-Telemedia Data Protection Act) for the storage of, and access to, information on end devices

Users can withdraw consent at any time.

Contact and Inquiry Management

When contacting us, we process:

  • Name
  • Contact details
  • Message content

Purpose

  • Communication
  • Handling inquiries

Legal Basis

  • Contract performance
  • Legitimate interests

Marketing Communication

We process personal data for marketing via:

  • Email
  • Phone
  • Mail

Users can withdraw consent at any time.

Data may be retained up to 3 years for legal purposes.

Social Media Presence

We maintain profiles on social networks to:

  • Communicate with users
  • Share information

Data may be processed outside the EU.

Example: LinkedIn

Data is processed jointly with LinkedIn Ireland for analytics (“Page Insights”). A summary of this joint controllership arrangement, including the allocation of responsibilities under Art. 26 GDPR, is published by LinkedIn and available at linkedin.com/legal/l/pages-joint-controller-addendum.

Changes and Updates

We regularly update this privacy policy.
Users are advised to review it periodically.