Privacy Policy

Privacy Notice

for the use of this website

 

I. Controller and Contact Details

 

The controller within the meaning of Art. 4 No. 7 GDPR is:
QEST Quantenelektronische Systeme GmbH
(hereinafter referred to as the "Controller")
Max-Eyth-Straße 38
71088 Holzgerlingen
Germany

The Data Protection Officer of the Controller can be contacted at:
Data Protection Officer
QEST Quantenelektronische Systeme GmbH
Max-Eyth-Straße 38
71088 Holzgerlingen
Germany
privacy@draexlmaier.com

 

II. Collection and Processing of Personal Data

 

Accessing the Website

When accessing our website, our web server automatically collects the following data:

  • Name of your Internet Service Provider
  • Website from which you visit us
  • Pages you visit on our website
  • Amount of data transferred and file size of the accessed page
  • Protocol and Internet Protocol address (IP address)
  • Date, time and duration of the visit
  • Browser language
  • Status code
  • Device type, device manufacturer, device model and screen resolution
  • Operating system, browser and browser plug-ins
  • Internal search terms
  • Outbound referrals
  • Downloads
  • Search engines

The collection, storage and evaluation of this data are carried out for statistical purposes and to ensure system security. This data is collected anonymously and stored separately from all personal data. No merging of data takes place. The legal basis for this processing is Art. 6(1)(f) GDPR. The aforementioned purposes also constitute our legitimate interests. The IP address collected in this context is deleted immediately after anonymization unless statutory or other legal reasons allow or require longer retention.

When using the internal search function on the website, the entered search terms, the time of the search request and the user's IP address are stored for 90 days. The legal basis for this processing is Art. 6(1)(f) GDPR. The processing serves to handle your search request and therefore constitutes our legitimate interest.

 

Contact via E-mail / Use of Our Contact Form

You are welcome to contact us by e-mail or via our contact form. Providing a valid e-mail address is required so that we can respond to your inquiry. You may voluntarily provide additional information. The processing of personal data for the purpose of contacting us is based on your consent in accordance with Art. 6(1)(a) GDPR, which you grant voluntarily by submitting your data.  The purpose of the processing is to handle your inquiry. Personal data collected through the contact form will be automatically deleted after your request has been processed unless statutory or other legal reasons justify longer retention.

 

Provision of E-Papers and Topic-Specific Documents

For selected topics, we provide e-papers and other documents. You may request these documents by registering on our website and providing your first name, last name and a valid e-mail address. Your data will be processed in order to send you the requested e-papers and documents and to conclude a usage agreement regarding these materials. The legal basis for this processing is Art. 6(1)(b) GDPR.

 

IV. Purpose and Legal Basis of Data Processing

 

We process the personal data described in this privacy notice in accordance with the provisions of the GDPR, other applicable data protection laws and only to the extent necessary. Where processing is based on Art. 6(1)(f) GDPR, the purposes stated in this privacy notice also constitute our legitimate interests.

 

V. Disclosure of Personal Data to Third Parties

 

The following categories of recipients may receive access to your personal data, usually as processors acting on our behalf:

  • Service providers for operating our website and processing data stored or transmitted through our systems (e.g. website maintenance and support, data center services, IT security). The legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR where recipients are not acting as processors.
  • Public authorities and government bodies, where disclosure is required by law. The legal basis is Art. 6(1)(c) GDPR.
  • Persons and organizations involved in the conduct of our business operations (e.g. agencies, auditors, banks, insurance providers, legal advisors, supervisory authorities and parties involved in company acquisitions or joint ventures). The legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.

Furthermore, we will only disclose your personal data to third parties if you have expressly consented to such disclosure pursuant to Art. 6(1)(a) GDPR.

 

VI. Conditions for the Transfer of Personal Data to Third Countries

 

Within the scope of our business relationships, your personal data may be transferred or disclosed to affiliated companies. These companies may also be located outside the European Economic Area (EEA), i.e. in third countries. Such processing is carried out exclusively for the fulfillment of contractual and business obligations and for maintaining our business relationship with you.

For certain third countries, the European Commission has issued adequacy decisions confirming a level of data protection comparable to that within the EEA. A list of these countries and copies of the adequacy decisions are available at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en In other third countries, an adequate level of data protection may not be ensured due to the absence of corresponding legal provisions. In such cases, we ensure adequate safeguards, for example through Binding Corporate Rules (BCRs), Standard Contractual Clauses approved by the European Commission, Certifications, Recognized codes of conduct.

 

VII. Security

 

We implement technical and organizational security measures to protect the data you provide against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security measures are continuously improved in line with technological developments.

 

SSL / TLS Encryption

For security reasons and to protect the transmission of confidential information, such as inquiries submitted to us via this website, we use SSL or TLS encryption.

You can recognize an encrypted connection when the URL changes from "http://" to "https://" and a padlock icon appears in your browser's address bar. When SSL or TLS encryption is activated, data transmitted to us cannot be read by third parties.

 

VIII. Use of Cookies

 

No cookies are used on our website.

 

IX. Your Rights

 

You may exercise your rights as a data subject at any time using the contact details provided above. You have the right:

  • Under Art. 15 GDPR, to obtain information about your personal data processed by us.
  • Under Art. 16 GDPR, to request the correction of inaccurate data or completion of incomplete data.
  • Under Art. 17 GDPR, to request the deletion of your personal data, provided no statutory obligations or overriding legitimate interests prevent deletion.
  • Under Art. 18 GDPR, to request restriction of processing.
  • Under Art. 20 GDPR, to receive your data in a structured, commonly used and machine-readable format or request its transfer to another controller ("data portability").
  • Under Art. 21 GDPR, to object to processing based on Art. 6(1)(e) or Art. 6(1)(f) GDPR.
  • Under Art. 7(3) GDPR, to withdraw your consent at any time with future effect.
  • Under Art. 77 GDPR, to lodge a complaint with a supervisory authority regarding our processing of your personal data.

 

X. No Automated Decision-Making (Including Profiling)

 

We do not intend to use your personal data for automated decision-making processes, including profiling.

 

XI. Social Media Plugins

 

We do not use social media plugins on our website. Where our website displays icons of social media providers (e.g. Facebook, Instagram, Kununu, LinkedIn or Xing), these are used solely as passive links to the respective providers' websites.

 

XII. Use of the Sentry Error Monitoring Tool

 

On our website, we use the open-source error monitoring and analysis tool Sentry. The software is operated on our behalf by our web agency as a self-hosted solution on servers located in Germany.

The purpose of this tool is to ensure the technical stability and proper functioning of our website by logging system errors and software bugs within the source code. For this purpose, Sentry collects only technical metadata at the time an error occurs, such as the operating system used, browser type, accessed URL, and the technical cause of the error.

Sentry does not store any cookies on your device and does not use any tracking technologies. Neither we nor our web agency are able to associate the error logs with a specific individual.

The legal basis for this processing is Article 6(1), first subparagraph, point (f) GDPR. Our legitimate interest lies in ensuring IT security, maintaining the technical functionality of our website, and continuously improving our online services.

Further information about the self-hosted version of Sentry is available at: develop.sentry.dev/self-hosted/.

Further information about Sentry’s privacy practices can be found at: sentry.io/privacy/.

 

 

XIII. Validity and Amendments to this Privacy Notice

 

This Privacy Notice is currently valid and reflects the status as of August 2026.