Data Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, the purposes for which we process them, and the extent of such processing. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as “online offering”).
The terms used are not gender-specific.
Last updated: August 11, 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing
- Legal Bases
- Security Measures
- Transfer of Personal Data
- International Data Transfers
- Data Retention and Deletion
- Rights of Data Subjects
- Data Protection Officer
- Provision of Online Services and Web Hosting
- Use of Cookies
- Contact and Inquiry Management
- Marketing Communication
- Social Media Presence
- Changes and Updates
Controller
Dr. Guido Schroer / Dr. Tobias Riedl / Mr. Yannik Kohlhaas / Dr. Harald Rubner
Power2Polymers GmbH
Dennewartstrasse 25
52068 Aachen, Germany
Handelsregisternummer: HRB 28251, Amtsgericht Aachen
Umsatzsteuer-Identifikationsnummer (VAT ID): DE450454157
Email: founder@power2polymers.com
Imprint: https://www.power2polymers.com/
Overview of Processing
Types of Data Processed
- Master data
- Contact data
- Content data
- Usage data
- Metadata, communication, and procedural data
- Log data
Categories of Data Subjects
- Communication partners
- Users
Purposes of Processing
- Communication
- Security measures
- Direct marketing
- Organizational and administrative processes
- Feedback
- Marketing
- Provision and improvement of our online services
- IT infrastructure
- Public relations
- Sales promotion
Legal Bases
Relevant Legal Bases under GDPR
- Consent (Art. 6(1)(a) GDPR)
- Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
National Regulations (Germany)
In addition to the GDPR, German data protection laws apply, particularly the Federal Data Protection Act (BDSG).
Note on Swiss Data Protection Law
Power2Polymers GmbH also processes personal data of customers based in Switzerland. This policy therefore also serves to provide the information required under the Swiss Federal Act on Data Protection (FADP/DSG). For consistency, the GDPR terminology used throughout this policy is applied to fulfil the equivalent Swiss DSG requirements as well.
Security Measures
We implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk, considering:
- State of the art
- Implementation costs
- Nature, scope, and purpose of processing
- Risks to individuals
Measures include safeguarding:
- Confidentiality
- Integrity
- Availability of data
Transfer of Personal Data
Personal data may be shared with third parties such as:
- IT service providers
- Embedded service providers
We ensure appropriate safeguards through contracts and agreements.
International Data Transfers
Data transfers outside the EU/EEA occur only:
- Based on adequacy decisions (Art. 45 GDPR), or
- With safeguards such as standard contractual clauses (Art. 46 GDPR), or
- With explicit consent
More information:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en
Data Retention and Deletion
Personal data is deleted when:
- Consent is withdrawn, or
- Legal basis no longer applies
Retention Periods (Germany)
- 10 years: accounting records, financial statements
- 6 years: business correspondence
- 3 years: legal claims
Rights of Data Subjects
You have the following rights:
- Right to object
- Right to withdraw consent
- Right of access
- Right to rectification
- Right to erasure and restriction
- Right to data portability
- Right to lodge a complaint with a supervisory authority
Data Protection Officer
We have not appointed a Data Protection Officer. If you have questions about our processing of personal data or wish to exercise your rights, please contact us directly using the details provided under “Controller” above.
Provision of Online Services and Web Hosting
We process user data to provide online services, including:
- IP address
- Usage data
- Log files
Legal Basis
Legitimate interests (Art. 6(1)(f) GDPR)
Hosting Provider
IONOS SE, Germany
Use of Cookies
Cookies store and retrieve information on user devices.
Types
- Session cookies
- Persistent cookies (up to 2 years)
Legal Basis
- Consent (Art. 6(1)(a) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
- Consent under Section 25 TTDSG (German Telecommunications-Telemedia Data Protection Act) for the storage of, and access to, information on end devices
Users can withdraw consent at any time.
Contact and Inquiry Management
When contacting us, we process:
- Name
- Contact details
- Message content
Purpose
- Communication
- Handling inquiries
Legal Basis
- Contract performance
- Legitimate interests
Marketing Communication
We process personal data for marketing via:
- Phone
Users can withdraw consent at any time.
Data may be retained up to 3 years for legal purposes.
Social Media Presence
We maintain profiles on social networks to:
- Communicate with users
- Share information
Data may be processed outside the EU.
Example: LinkedIn
Data is processed jointly with LinkedIn Ireland for analytics (“Page Insights”). A summary of this joint controllership arrangement, including the allocation of responsibilities under Art. 26 GDPR, is published by LinkedIn and available at linkedin.com/legal/l/pages-joint-controller-addendum.
Changes and Updates
We regularly update this privacy policy.
Users are advised to review it periodically.
