Skip to content

Legal

Privacy notice

Information on the processing of personal data under Articles 13 and 14 of the General Data Protection Regulation (GDPR), with additional disclosures for the United Kingdom, Switzerland and the United States

Diese Seite auf Deutsch

1. Short version first

This website is an information site. It consists of finished files that are delivered unchanged. There is no contact form, no login, no database and no content management system.

It follows that no cookies are set. For reach measurement we use Vercel Web Analytics, a cookieless statistics service of our host that evaluates page views in aggregate only and builds no visitor profiles (Section 11). The measurement runs only if you consent. If you decline, or if your browser sends a Global Privacy Control or Do Not Track signal, it does not take place. The only thing stored in your browser is your choice, so that we do not ask again on every page (Section 10). You can change it at any time through "Privacy settings" at the foot of every page. We use no tracking or advertising tools. Opening this site establishes no connection to any third party, neither to a font provider nor to a map service nor to a social network; every request goes to our own domain.

Personal data arises in four places: in the technically necessary delivery of the page, in reach measurement, when you write or call us, and when you book an appointment through our booking page. All four are described individually below.

This short version does not replace the sections that follow. The full text governs.

2. Controller

The controller within the meaning of the GDPR and the German Federal Data Protection Act (BDSG) is:

Axiva Industrial GmbHrepresented by its managing director Andreas GeissWerner-von-Siemens-Strasse 2-6, Building 5137c76646 Bruchsal, Germany

Telephone: +49 7251 382250E-mail: info@axiva-industrial.aiWebsite: https://axiva-industrial.ai

Commercial register: Local Court of Mannheim, HRB 758763VAT identification number: DE463431562

For any privacy matter, please use these contact details and mark your message "Privacy" so that it reaches the right place immediately.

3. Data protection officer

We have not appointed a data protection officer and are not required to do so. Fewer than twenty people in our company are permanently engaged in the automated processing of personal data (Section 38(1) sentence 1 BDSG), we carry out no processing that requires a data protection impact assessment under Article 35 GDPR, and we do not process personal data commercially for transfer or for market or opinion research.

Please address your requests to the contact details in Section 2. They are handled by the management.

4. Scope

This notice covers the website at the domain axiva-industrial.ai, including all of its pages, the German language version at `/de/` and the redirect at `/termin`.

It also covers the processing that arises when you contact us through the channels named on this website, and our presence on social networks to the extent that we act as controller or joint controller there (Section 17).

It does not cover third party websites we link to. The respective provider alone is responsible for their content and their processing (Section 13).

5. Terms

This notice uses the terms of the GDPR. The binding definitions are in Article 4 GDPR. Four of them are enough for reading this text:

  • Personal data is any information relating to an identified or identifiable natural person. An IP address counts.
  • Processing is any operation performed on such data, from collection through storage to erasure.
  • Controller is whoever determines the purposes and means of processing. For this website, that is us.
  • Processor is whoever processes data on a controller's documented instructions, for example our host.

6. Principles and legal bases

We process personal data only where a legal basis under Article 6 GDPR applies. The following occur in this notice:

  • Article 6(1)(b) GDPR, performance of a contract or steps taken at your request prior to entering into a contract.
  • Article 6(1)(c) GDPR, compliance with a legal obligation, in particular commercial and tax retention duties.
  • Article 6(1)(f) GDPR, legitimate interests, provided your interests and fundamental rights do not override them. Where we rely on this basis, we name the interest and the outcome of the balancing.
  • Article 6(1)(a) GDPR, consent. On this website only the reach measurement relies on it (Section 11).

We observe the principles of Article 5 GDPR, in particular data minimisation and purpose limitation. We do not collect data as a precaution, we build no visitor profiles and we do not sell data. We do not process special categories of personal data within the meaning of Article 9 GDPR through this website.

7. Visiting the website and connection data

7.1 What arises

When you open this website, your browser sends the information that any web server needs in order to return a response. The following are processed:

  • the IP address of the requesting device or of your access provider,
  • the date and time of the request,
  • the address requested and the method used,
  • the status code of the response and the volume of data transferred,
  • the page previously visited (referrer), where your browser transmits it,
  • the identification of browser and operating system as your browser sends it,
  • a coarse location at country and city level derived from the IP address, which our host uses to select the nearest delivery node.

No precise location is determined. Permissions for geolocation, camera, microphone and payment are explicitly switched off for this website by the response header `Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=()`.

7.2 Legal basis and retention

The purpose is delivery of the website, keeping it stable and defending against attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest follows from the necessity of technical provision and of IT security. This data is not combined with other data sources.

Without this data no response can technically be delivered. On our assessment your opposing interests weigh less heavily, because the data is not used to build a profile, is not combined with other data sets and is not evaluated for advertising, and because processing stays limited to what is technically required.

On retention in detail:

  • We keep no log archive of our own and do not evaluate the connection data. Access takes place only on a specific occasion, where a fault or a security incident has to be investigated.
  • No export of log data to third parties is configured.
  • No add-on for extended retention is subscribed. On the plan we use, the host retains runtime logs for one day.
  • The website contains no server functions. Runtime logs in the proper sense therefore do not arise.
  • Beyond that, under the data processing agreement the host retains connection data only for as long as operation and security require.

A retention period stated in days is deliberately not given here. Retention takes place in the processor's systems and cannot be configured by us. What governs is therefore its contractual commitment to what operation and security require, together with the findings above on what is actually configured.

8. Hosting and delivery network

8.1 Provider

This website is hosted by:

Vercel Inc.440 N Barranca Ave #4133Covina, CA 91723, United States of America

Vercel provides the server infrastructure and a global content delivery network and processes the connection data listed in Section 7.1 in doing so. The provider acts solely on our instructions. We have concluded a data processing agreement under Article 28 GDPR with Vercel. Under the wording of that agreement it becomes binding upon entering into the customer relationship and requires no separate signature.

8.2 Place of delivery

The website is delivered over the provider's global network. A request is answered by the node closest to you. For requests from Germany that is Frankfurt am Main; we have measured this and our server responses record it. Delivery through nodes outside the European Union is not excluded where the site is opened from there. The website contains no server functions that compute or store data; only finished files are delivered.

8.3 Legal basis

Article 6(1)(f) GDPR. Our legitimate interest is the secure, fast and resilient provision of our web presence.

8.4 Domain and name resolution

The domain `axiva-industrial.ai` is registered through IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany, which also operates the authoritative name servers for the domain. On a name lookup the name server as a rule learns only the address of the resolver you use, typically your access provider's server, not your own IP address. No website content is delivered through IONOS.

9. Security of processing

We take technical and organisational measures under Article 32 GDPR. For this website these are in particular:

  • Transport encryption throughout. The site is reachable only over HTTPS. An unencrypted request is permanently redirected to the encrypted address.
  • HTTP Strict Transport Security. The server instructs your browser to open this domain only over an encrypted connection for one year. Your browser records that instruction locally. It contains no identifier, permits no recognition and serves transport security alone.
  • Protective response headers. `X-Content-Type-Options: nosniff` prevents content type sniffing, `X-Frame-Options: SAMEORIGIN` prevents framing by third parties, `Referrer-Policy: strict-origin-when-cross-origin` restricts the transmission of the originating address.
  • No executable components on the server. The site is static. There is no database, no login and no interface that would accept data.
  • A minimal attack surface. No scripts are loaded from third party servers. The reach measurement script (Section 11) is delivered by our host under our own domain.

These measures are adapted to the state of the art on an ongoing basis. Complete protection of data transmission over the internet is nevertheless impossible, in particular for unencrypted e-mail.

10. No cookies; what is stored on your device

This website sets no cookies. Our server responses contain no instruction to set one. We use no comparable recognition techniques either, in particular no session storage (`sessionStorage`), no browser database (`IndexedDB`), no service worker, no tracking pixels and no device fingerprinting.

One exception: your choice on reach measurement. When you select "Allow" or "Decline" in the reach measurement notice, we store that choice in your browser's local storage (`localStorage`) under the name `axiva.einwilligung`: whether you consented, the day of your choice and the version of the notice. The entry contains no identifier, is transmitted neither to us nor to anyone else and never leaves your browser. Its only purpose is to respect your choice and not to ask you again on every page. After twelve months we ask again. You can change the entry at any time through "Privacy settings" or delete it in your browser. Storing it is strictly necessary under Section 25(2) no. 2 TDDDG to give effect to the choice you expressly made; to the extent personal data is concerned, we rely on Article 6(1)(f) GDPR, our legitimate interest being to respect your choice.

The reach measurement script itself places nothing on your device and reads nothing stored there; we have verified this against its source code. It is loaded only if you have consented (Section 11.4).

Beyond that, only two things are placed on your device, both technically indispensable for delivering the page: your browser's ordinary cache for images, stylesheet and script, and the HSTS security instruction described in Section 9. Neither contains an identifier and neither permits any inference about you.

For completeness: in the event of an attack our host is able to interpose a security check that sets a technically necessary identifier for its duration. No such check is configured for us; there are no firewall rules and no attack challenge in place. Were it to be used on that occasion, it would serve defence alone and would be strictly necessary under Section 25(2) no. 2 TDDDG.

To the extent that the cache and the security instruction are regarded as storage on your terminal equipment at all, they are strictly necessary under Section 25(2) no. 2 TDDDG in order to provide the service you have expressly requested, namely retrieval of this website. For reach measurement, by contrast, we ask for your consent under Section 25(1) of the German TDDDG, the national implementation of Article 5(3) of the ePrivacy Directive; see Section 11.4.

11. Reach measurement with Vercel Web Analytics

11.1 What is measured

We want to know which pages are read and how visitors find us. For this we use Vercel Web Analytics, a service of our host Vercel Inc. (address in Section 8.1). If you have consented, your browser loads, when a page opens, a small script that our host delivers under our own domain (`/_vercel/insights/script.js`). The script reports the page view to an address on our own domain (`/_vercel/insights/view`). It transmits:

  • the page requested, without query parameters and without fragment; we remove both before sending,
  • the time of the request,
  • the page you came from (referrer), only if it lies outside our website and your browser provides it,
  • the version of the script.

From the request itself Vercel additionally derives country, region and city from the IP address, and operating system, browser and device type from the browser identification.

11.2 How visitors are distinguished

Vercel Web Analytics sets no cookies and stores nothing in your browser. To group the page views of one visitor within a day, Vercel creates a hash from the incoming request. This association is not stored permanently and is discarded automatically after 24 hours. There is no recognition beyond that period or across other websites, and no combination with other data. We see aggregate figures only, such as views per page, referring pages and countries. We do not see individual visitors, IP addresses or browsing paths. We have not configured custom events, user identifiers or click tracking.

11.3 Legal basis, recipient, retention

The legal basis is your consent under Article 6(1)(a) GDPR and, for triggering the measurement in your browser, under Section 25(1) TDDDG. Without consent there is no measurement. The purpose is to understand, in aggregate form, how our website is used and to align its content accordingly.

Vercel acts as our processor under the same Article 28 GDPR agreement that covers hosting (Section 8.1). Section 18.2 applies to the transfer to the United States. The aggregate reports are available to us for twelve months on our plan. Vercel reserves the right to keep the data for longer; attribution to an individual visitor is no longer possible after the 24 hours in any case.

11.4 Consent and withdrawal

On your first visit a notice on reach measurement appears at the bottom of the page. It states purpose, provider and scope and offers two equal buttons: "Allow" and "Decline". Neither is preselected. Until you choose, nothing is measured and the script is not loaded; the website remains fully usable in the meantime, and the notice covers neither the legal notice nor this privacy notice. If you do not answer the notice, you are not measured.

You may withdraw your consent at any time with effect for the future, as easily as you gave it: through the "Privacy settings" link at the foot of every page. Withdrawal takes effect immediately, including on the page currently open; from that moment no further view is reported. The lawfulness of processing before withdrawal is unaffected (Article 7(3) GDPR). Your consent is valid for twelve months; after that, and whenever we change the scope of the measurement, we ask again.

11.5 Signals from your browser

If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as declining: the notice does not appear and the reach measurement script is not loaded. Most browsers offer these signals in their settings or through an extension.

11.6 No tracking, no advertising

Advertising networks, remarketing identifiers, conversion tracking and data transmitting social network buttons are not used. Google Analytics, Matomo or any comparable service is not embedded.

The pages delivered embed resources of our own domain exclusively. Elements that would transmit data to a third party host, in particular `script`, `link`, `img` and `iframe` with a third party source, are not present.

12. Fonts, images and design assets

The typeface used on this website, Montserrat Alternates, is embedded in four weights directly in our stylesheet and delivered from our own server. There is no connection to Google Fonts or any other font service. No IP address is transmitted to a font provider when the page is opened.

All images, icons and graphics likewise reside on our own server. No images from third party sources are embedded, and there are no map services, no video embeds and no social network buttons.

13. Links to third party services

This website contains links to third party services, namely to our pages on LinkedIn and to our booking page at Microsoft. As long as you do not click such a link, nothing is transmitted to the provider concerned. These are plain links, not embedded content.

If you click a link, you leave this website. Your browser then connects directly to the target provider and transmits the data that provider collects. We have no influence over this. The privacy notice of the respective provider applies.

We have taken two precautions. Every link to a third party service carries `rel="noopener noreferrer"`. As a result no referrer is transmitted to the target provider, and the page opened has no access to the window it was opened from.

The link to appointment booking does not lead directly to the provider. It leads first to our own address `axiva-industrial.ai/termin`, from where our server answers with a permanent redirect (status code 301) to the booking page. This has two effects: before clicking you see our address rather than the provider's, and even on the redirect we transmit nothing to Microsoft. Your browser makes the connection itself, and no referrer is transmitted in the process.

14. Appointment booking through Microsoft Bookings

14.1 Process and data

To arrange an introductory conversation we use Microsoft Bookings, part of Microsoft 365. The booking page is not part of this website; it resides in our Microsoft 365 environment and opens in a new window.

If you book an appointment there, the following are processed:

  • first and last name (mandatory),
  • e-mail address (mandatory),
  • postal address (optional),
  • telephone number (optional),
  • a free text field for particular requests (optional),
  • the appointment, time zone and service selected,
  • the technical connection data that arises whenever a website is opened.

You then receive a confirmation by e-mail and the appointment is entered in our calendar.

14.2 Purpose, legal basis and responsibility

The purpose is arranging, holding and administering the conversation you have requested. The legal basis is Article 6(1)(b) GDPR, because the processing serves steps taken at your request prior to entering into a contract. Where a booking serves no such purpose, we rely on Article 6(1)(f) GDPR with our legitimate interest in orderly appointment management.

We, not Microsoft, are the controller for this processing. Microsoft acts as our processor.

14.3 Processor

Microsoft Ireland Operations LimitedOne Microsoft Place, South County Business ParkLeopardstown, Dublin 18, D18 P521, Ireland

A data processing agreement under Article 28 GDPR is in place with Microsoft in the form of the Microsoft Data Protection Addendum and the Product Terms. Microsoft stores and processes customer data for Microsoft 365 within the EU Data Boundary, that is within the European Union and the EFTA states. Access from third countries is not entirely excluded, for instance in the course of technical support; it is subject to the safeguards described in Section 18.

14.4 Retention

We keep appointment data for the duration of the business relationship and thereafter for as long as required for traceability. If no further business relationship follows, we erase the data no later than six months after the appointment unless statutory retention duties apply. If a business relationship follows, Section 19 applies.

14.5 Holding the conversation

Where the conversation takes place by telephone or as a video call we use telephony or Microsoft Teams from the same Microsoft 365 environment. We do not record conversations and we produce no automatic transcripts. Should a recording be desired in an individual case, we obtain your express consent under Article 6(1)(a) GDPR beforehand.

15. Contact by e-mail and telephone

This website contains no contact form. You can reach us by e-mail and by telephone.

If you write to us, we process your e-mail address, your name, the content of your message and its technical header data. If you call, we process what you tell us in the conversation and the number transmitted.

The purpose is handling your enquiry. The legal basis is Article 6(1)(b) GDPR where your message serves the initiation or performance of a contract, otherwise Article 6(1)(f) GDPR with our legitimate interest in answering enquiries.

Our mailbox runs on Microsoft Exchange Online, in the Microsoft 365 environment named in Section 14.3. Transport is encrypted where the counterpart server supports it. An unencrypted e-mail can be read in transit; for confidential information we will offer another route on request.

We erase your enquiry once it has been dealt with conclusively and no statutory retention duty applies, as a rule after six months for enquiries without further consequence. Business correspondence qualifying as a commercial or business letter is retained for six years under Section 257 of the German Commercial Code and for ten years under Section 147 of the German Fiscal Code; the legal basis is Article 6(1)(c) GDPR.

16. Insights and RSS feed

Our Insights articles are part of this website and are delivered like any other page. In addition we provide an RSS feed per language as a static file.

Retrieving the feed is technically an ordinary page request; Section 7 applies. No registration is required or possible. We keep no subscriber list and send no newsletter. If you subscribe to a feed, that happens in your own reader; we learn nothing about it beyond the connection data of the request.

17. Social network presences

17.1 Links on this website

We link to our LinkedIn company page and to the personal profile of our managing director. These are plain links without embedded content; Section 13 applies.

17.2 Our LinkedIn company page

We operate a company page at:

LinkedIn Ireland Unlimited CompanyWilton Plaza, Wilton Place, Dublin 2, Ireland

When you visit our company page, LinkedIn processes your data on its own responsibility under its own terms. In addition, LinkedIn provides us with aggregated statistics on the use of the page (Page Insights). That aggregation is not anonymisation in the legal sense: it rests on the processing of personal data, which is precisely why joint controllership arises. For that processing we and LinkedIn are joint controllers under Article 26 GDPR. LinkedIn makes the essence of that arrangement available at legal.linkedin.com/pages-joint-controller-addendum and has assumed primary responsibility for handling your rights. You may nevertheless assert your rights against us; we will pass your request on.

We have no access to the underlying raw data and cannot identify individual users from these statistics. The legal basis for our part is Article 6(1)(f) GDPR with our legitimate interest in an effective public presence and in reaching prospective clients and candidates.

If you contact us through LinkedIn, we process the information transmitted in order to deal with your enquiry; Section 15 applies accordingly.

18. Recipients and international transfers

18.1 Recipients

We disclose personal data only where a legal basis exists. The recipients are:

RecipientRoleSubject matterLocation
Vercel Inc., Covina, California, USAprocessorhosting and delivery of the website, reach measurementglobal network, Frankfurt am Main for requests from Germany
Microsoft Ireland Operations Limited, Dublin, Irelandprocessorbooking, e-mail, calendar, video conferencingEU Data Boundary (EU and EFTA)
IONOS SE, Montabaur, Germanyregistrar and name server, as a rule not a recipient of visitor datadomain administration and name resolution, see Section 8.4Germany
LinkedIn Ireland Unlimited Company, Dublin, Irelandjoint controllercompany page statisticsIreland, transfer to the USA possible
Tax, audit and legal advisersindependent recipientsstatutory duties and legal claimsGermany
Public authorities and courtsindependent recipientswhere required by lawGermany

Data processing agreements under Article 28 GDPR are in place with Vercel and Microsoft, the two parties that process data on our instructions. No disclosure for advertising purposes takes place. We do not sell data.

18.2 Transfers to third countries

Vercel Inc. is established in the United States. With Microsoft and LinkedIn, access from the United States cannot be entirely excluded either. A transfer to a third country within the meaning of Chapter V GDPR therefore takes place.

We base that transfer on two independent safeguards:

  • Adequacy decision. By decision of 10 July 2023 the European Commission established that the United States affords an adequate level of protection for organisations certified under the EU-US Data Privacy Framework (Article 45 GDPR). Vercel Inc. and Microsoft Corporation are certified under that framework. The participant list is publicly available at dataprivacyframework.gov.
  • Standard contractual clauses. In addition and independently, the European Commission's standard contractual clauses under Article 46(2)(c) GDPR are agreed with our processors and form part of the respective data processing agreements. This safeguard holds even if the adequacy decision were to lapse.

For the joint controllership with LinkedIn, the safeguards referenced by the arrangement named in Section 17.2 apply; they are provided by LinkedIn and not by us.

We monitor developments concerning the adequacy decision and will adjust our processing if it lapses or is restricted. We will provide a copy of the standard contractual clauses on request using the contact details in Section 2.

We further note that United States authorities may under their law access data in certain circumstances and that the available remedies differ from the European ones. The data arising through this website is of limited depth: as a rule it is the connection data of a page request and an aggregate reach measurement, in both cases without any profiling.

19. Business partners, prospective clients and applications

19.1 Business partners and prospective clients

Where we process data of contact persons at our clients, prospective clients, suppliers and partners, we do so to initiate and perform the business relationship on the basis of Article 6(1)(b) GDPR and, as regards communication with a contracting party's staff, on the basis of Article 6(1)(f) GDPR.

We process name, role, business contact details, correspondence, and contract and billing data. Erasure follows Section 20.

19.2 Data not obtained from you

Where we approach you in a business context without your having given us your data yourself, the information comes from publicly available sources, namely your company's website, professional networks such as LinkedIn, industry events or commercial registers. We then process name, role, company and business contact details.

The legal basis is Article 6(1)(f) GDPR with our legitimate interest in initiating business relationships in a commercial setting. You receive this information under Article 14 GDPR at the latest when we first approach you. You may object at any time; we then cease the approach and record your objection so that it is observed. Marketing by e-mail and telephone takes place only within the limits of Section 7 of the German Act against Unfair Competition.

19.3 Applications

Applications reach us by e-mail. We process the information and documents you submit in order to conduct the application procedure.

The legal basis is Article 6(1)(b) GDPR. The processing serves steps taken at your request prior to entering into a contract, here with a view to a possible employment relationship. We rely directly on the Regulation and not on Section 26(1) sentence 1 of the German Federal Data Protection Act. By judgment of 30 March 2023 (Case C-34/21) the Court of Justice of the European Union held that a national provision which merely repeats the conditions of the Regulation is not a more specific rule within the meaning of Article 88 GDPR. The wording of the provision at issue corresponds to that of Section 26(1) sentence 1 BDSG. That provision is not material to our processing.

If you send us special categories of personal data, for example information on a severe disability, we process it on the basis of Article 9(2)(b) GDPR in conjunction with Section 26(3) BDSG, because the processing is necessary for exercising rights and performing obligations under employment law. That provision rests on a separate opening clause of the Regulation and is unaffected by the judgment referred to above.

If no appointment follows, we erase the documents no later than six months after the procedure ends. That period reflects the statutory time limits: claims under the German General Equal Treatment Act must be asserted in writing within two months (Section 15(4) AGG) and an action must be brought within three months of that assertion (Section 61b(1) of the German Labour Court Act). The legal basis for retention during that period is Article 6(1)(f) GDPR with our legitimate interest in defending against such claims.

Any retention beyond that, for example to include you in a candidate pool, takes place solely with your consent under Article 6(1)(a) GDPR, which you may withdraw at any time with effect for the future.

20. Retention and erasure

We store personal data only for as long as the respective purpose requires or the law prescribes:

DataPeriodBasis
Connection data of a page requestonly as long as operation and security require, no archive of our ownArticle 6(1)(f) GDPR
Your choice on reach measurement, in your browser's storagetwelve months, then asked again; changeable at any timeSection 25(2) no. 2 TDDDG
Association of a visitor in reach measurement24 hours, then discardedArticle 6(1)(a) GDPR
Aggregate reach statisticsavailable for twelve months, without reference to individual visitorsArticle 6(1)(a) GDPR
Enquiries without further consequenceerasure as a rule after six monthsArticle 6(1)(b) and (f) GDPR
Bookings without a business relationshiperasure no later than six months after the appointmentArticle 6(1)(b) GDPR
Application documents without appointmenterasure no later than six months after the procedure endsArticle 6(1)(b) and (f) GDPR, Section 15(4) AGG, Section 61b(1) ArbGG
Commercial and business letterssix yearsSection 257(4) German Commercial Code
Accounting records and tax relevant documentsten yearsSection 147(3) German Fiscal Code

Once the applicable period expires the data is erased or, where erasure is technically impossible, restricted from further processing.

21. No automated decision making, no profiling

Automated decision making including profiling within the meaning of Article 22(1) and (4) GDPR does not take place. We do not evaluate you automatically, we build no user profiles and we take no decisions about you based solely on automated processing.

22. Use of artificial intelligence

We use no artificial intelligence system that processes your data for the operation of this website. There is no chatbot, no assistant and no automated evaluation of your behaviour.

In designing the website we used generative systems to create image motifs. Nine of the ten motifs used were produced that way, and their origin was determined from the image files themselves. One of them, the stage motif in the closing section of the content pages, depicts our managing director and was produced with his consent. No personal data of visitors to this website was involved in their creation at any point.

Which motif was produced how is set out individually in the image credits of our legal notice, and every motif concerned carries a visible notice on the page itself. This also discharges the transparency obligation in Article 50(4) of Regulation (EU) 2024/1689 (the AI Act), which has applied since 2 August 2026.

23. Obligation to provide data

You are under no statutory or contractual obligation to provide us with personal data. This website can be viewed without providing anything; the connection data described in Section 7 arises technically and cannot be avoided when retrieving any website.

If you write to us or book an appointment, we need the fields marked as mandatory in order to deal with your request. Without them no reply or confirmation is possible. Further details are optional and omitting them has no disadvantage.

24. Children

Our offering is directed at businesses and their staff, not at children. We do not knowingly collect data from persons under sixteen years of age, and for visitors in the United States we do not knowingly collect data from children under thirteen within the meaning of the Children's Online Privacy Protection Act. If we learn that such data has been provided to us without the required authorisation, we erase it without delay.

25. Your rights under the GDPR

You have the following rights against us. An informal message to the contact details in Section 2 is enough to exercise them, and exercising them is free of charge. We respond without undue delay and at the latest within one month; for complex requests that period may be extended by two further months, of which we will inform you.

25.1 Access, Article 15 GDPR

You may request confirmation of whether and which personal data we process about you, for which purposes, to which recipients, for how long and from which source, and you may request a copy.

25.2 Rectification, Article 16 GDPR

You may request that inaccurate data be corrected and incomplete data completed.

25.3 Erasure, Article 17 GDPR

You may request erasure, in particular where the data is no longer necessary, where you have withdrawn consent or where you have effectively objected. The right does not apply where processing is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.

25.4 Restriction, Article 18 GDPR

Instead of erasure you may request restriction of processing, for example while the accuracy of the data is being verified.

25.5 Data portability, Article 20 GDPR

Where processing is based on consent or on a contract and is carried out by automated means, you may receive the data concerning you in a structured, commonly used and machine readable format or request its transmission to another controller, where technically feasible.

25.6 Withdrawal of consent, Article 7(3) GDPR

You may withdraw consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal is unaffected.

25.7 Notification, Article 19 GDPR

Where you have requested rectification, erasure or restriction, we notify all recipients to whom we disclosed your data unless this proves impossible or involves disproportionate effort. On request we will name those recipients.

25.8 Complaint to a supervisory authority, Article 77 GDPR

Without prejudice to any other remedy you may lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement. The authority competent for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-WürttembergHeilbronner Strasse 35, 70191 Stuttgart, GermanyPostfach 10 29 32, 70025 Stuttgart, GermanyTelephone: +49 711 615541-0E-mail: poststelle@lfdi.bwl.deWeb: https://www.baden-wuerttemberg.datenschutz.de

26. Right to object

Right to object under Article 21 GDPR. You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Article 6(1)(e) or (f) GDPR. This includes profiling based on those provisions.

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where your data is processed for direct marketing, you may object at any time and no reason is required. After such an objection we will no longer use your data for that purpose.

No particular form is required. A message to info@axiva-industrial.ai is enough.

27. United Kingdom

Where the UK General Data Protection Regulation and the Data Protection Act 2018 apply to our processing, the descriptions above apply accordingly, with the following additions.

We are established in Germany and have no establishment in the United Kingdom. Where we are nevertheless subject to the UK GDPR because we offer goods or services to individuals in the United Kingdom, we have not appointed a UK representative under Article 27 UK GDPR, since our processing is occasional, is limited to the categories described above and involves no large scale processing of special category data.

For transfers to the United States we rely on the UK Extension to the EU-US Data Privacy Framework and, in addition and independently, on the International Data Transfer Addendum to the European Commission's standard contractual clauses. You may lodge a complaint with the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom.

28. Switzerland

Where the Swiss Federal Act on Data Protection (FADP) applies, the descriptions above apply accordingly. For transfers to the United States we rely on the Swiss-US Data Privacy Framework and, in addition and independently, on the standard contractual clauses as recognised by the Swiss Federal Data Protection and Information Commissioner. You may contact the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, Switzerland.

We have not appointed a Swiss representative under Article 14 FADP, since our processing of data of persons in Switzerland is neither extensive nor regular and presents no high risk.

29. United States

29.1 How this section applies

We are a German company. We have no establishment, no branch, no employees and no assets in the United States. Our processing is governed in the first place by the GDPR, which we apply to every visitor irrespective of where they live.

Whether a United States state privacy statute applies to us depends on that statute's own scope test, and those tests differ. The California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the laws of Virginia, Colorado, Connecticut and Utah use revenue or volume thresholds. The Texas Data Privacy and Security Act uses no numeric threshold at all and instead exempts businesses that qualify as small businesses under the definition of the United States Small Business Administration.

We make no conclusive determination on that question here, and we do not need to. What follows applies to the extent that any such statute applies to our processing, and we grant the rights described below to residents of United States states in any event, voluntarily. Nothing in this section is an admission that a particular statute applies to us, and nothing in it limits the rights you have under the GDPR.

We nevertheless set out below how we handle the matters those statutes address, and we grant the corresponding rights to residents of those states on a voluntary basis. Nothing in this section is an admission that any particular statute applies to us.

29.2 Categories of personal information

Measured against the categories used in the CCPA, the following may arise through this website:

Category under the CCPADo we process itSourcePurpose
Identifiers, for example name, e-mail address, IP addressyesfrom you, or automatically on a page requestdelivering the site, answering enquiries, arranging appointments
Commercial information, for example the service bookedyes, if you bookfrom youperforming the appointment
Internet or other electronic network activitylimited to the connection data in Section 7 and the aggregate reach measurement in Section 11automaticallyoperation, security and aggregate statistics
Geolocation dataonly country, region and city derived from the IP addressautomaticallyselecting the nearest delivery node, aggregate statistics
Sensitive personal informationnonot applicablenot applicable
Biometric informationnonot applicablenot applicable
Inferences used to create a profilenonot applicablenot applicable

We retain each category only for as long as the purpose requires. The periods and their bases are set out in Section 20.

29.3 No sale, no sharing, no targeted advertising

We do not sell personal information, and we have not sold personal information in the preceding twelve months. We do not share personal information for cross context behavioural advertising within the meaning of the CPRA, and we have not done so in the preceding twelve months. We do not engage in targeted advertising or in profiling that produces legal or similarly significant effects.

Because there is nothing to opt out of, we do not operate a "Do Not Sell or Share My Personal Information" mechanism. We nevertheless honour the Global Privacy Control signal: if your browser sends it, our website treats it as declining and does not load the reach measurement script (Section 11.5). The reach measurement runs only with your consent in any case.

We do not use personal information to discriminate against anyone exercising a privacy right, and we offer no financial incentive in exchange for personal information.

29.4 Rights of residents of United States states

To the extent granted by the law of your state, and in any event voluntarily, you may request to know what personal information we hold about you, to receive a copy of it, to have it corrected, to have it deleted, and to opt out of any sale, sharing, targeted advertising or profiling. You may also appeal a refusal, where the law of your state provides for an appeal. Exercising these rights is free of charge and carries no disadvantage.

Please direct requests to info@axiva-industrial.ai. We verify a request by comparing it against the information we already hold, for example by replying to the e-mail address on record. An authorised agent may make a request on your behalf if you provide written authorisation; we may still ask you to confirm the authorisation directly.

We respond within forty five days and will tell you if we need a further forty five days.

29.5 Other jurisdictions

Where the law of another jurisdiction grants you rights over your personal data and applies to our processing, we honour those rights within its scope. Please use the contact details in Section 2.

30. Privacy by design

We built this website from the ground up so that as little data as possible arises (Article 25 GDPR). The decisions behind this were deliberate:

  • There is no contact form, because an e-mail address suffices.
  • Reach measurement works without cookies, strips query parameters from the reported address and does not run if your browser sends Global Privacy Control or Do Not Track.
  • The typeface is embedded, so that no third party learns your IP address when the page opens.
  • The site is static, so that neither a database nor a login is required.
  • Links to third party services transmit no referrer.

31. Changes to this notice

This privacy notice is dated September 2026. Further development of this website, changes in legal or regulatory requirements or a change in the services used may make an amendment necessary. The current version is always available at axiva-industrial.ai/privacy/.

For a matter already concluded, the version in force at the time of collection applies. Where a material change requires consent, we obtain it beforehand.

32. Governing version

This privacy notice exists in German and in English. The German version governs. The English version is provided for information and additionally addresses readers outside the German speaking area.


As at August 2026. The German version is the authoritative one.