Privacy policy
This is a courtesy translation. In case of doubt, the German version of this privacy policy applies.
Overview
This website is a static website. Simply reading it loads nothing from external servers: fonts, images, videos and scripts are all on our own server. Audience measurement and external content such as the video or the booking calendar are only loaded once you agree in the consent banner. Two exceptions apply independently of the banner and are described individually below: the form's spam protection loads as soon as you interact with a form field, and a submitted enquiry is delivered through a service provider.
Personal data therefore arises in the technically necessary server logs, when you write or call us, through the contact form, and — only after your consent — in audience measurement and the external embeds.
Controller
The controller for data processing on this website within the meaning of the General Data Protection Regulation is:
Claritava GmbHLaufertorgraben 2
90489 Nürnberg
Germany
Phone: +49 176 22698335
Email: sales@claritava.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data. We have not appointed a data protection officer; there is currently no legal obligation for us to do so.
Hosting and server logs
This website is operated by an external service provider. The data collected is stored on its servers in Germany.
checkdomain GmbHGroße Burgstraße 27/29
23552 Lübeck
Germany
A data processing agreement pursuant to Art. 28 GDPR is in place with the host. It processes the data exclusively on our instructions.
When a page is requested, the server automatically collects information transmitted by your browser and technically required to deliver the page: the address requested, date and time of access, the volume of data transferred, browser type and version, operating system, the previously visited page and the IP address of your connection.
We do not merge this data with other sources and do not evaluate it on a personal basis. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in flawless delivery and the security of the website. The host deletes the logs automatically, at the latest after seven days, unless they are needed to investigate a security incident.
Consent and the cookie banner
On your first visit a banner asks whether you agree to audience measurement and external content. Before your decision, none of it is loaded. Declining is just as easy as agreeing and sits equally on the same level; nothing is pre-selected.
So that we do not have to ask on every visit, we store your decision together with the time and the banner version in your browser's local storage (key “clv-consent”). This entry never leaves your device and expires after six months, after which we ask again. It is strictly necessary in order to record your decision at all and therefore exempt from consent under § 25 (2) no. 2 TDDDG.
You can withdraw or change your consent at any time with effect for the future via “Cookie settings” at the bottom of every page. Withdrawing is as easy as giving consent. The lawfulness of processing carried out up to that point remains unaffected.
Audience measurement with Google Analytics
If you agree to the “Statistics” category, we use Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Without your agreement the service is not loaded and no request is made to Google.
Google Analytics helps us understand which pages are read, how long visitors stay and how they found us. Cookies are set and usage data is processed for this. IP addresses are truncated before storage. The data is deleted automatically after 14 months at the latest.
In addition we record two occurrences: that a form was submitted successfully and that an appointment was booked in the calendar. All that is transmitted is which form or which calendar was involved and which language version of the page you were on. Your name, your contact details and the text you entered are not part of this and are not passed on to Google.
This involves a transfer to the USA. The legal basis for the processing and the transfer is exclusively your consent under Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. A data processing agreement pursuant to Art. 28 GDPR is in place with Google.
You can withdraw your consent at any time via the cookie settings in the footer. Google additionally offers a browser add-on to opt out: tools.google.com/dlpage/gaoptout.
Google Search Console
We use Google Search Console to see which search queries surface our pages in Google Search. Search Console evaluates only data that arises at Google itself — nothing is stored on this website for it and nothing is sent to Google. Ownership of the domain is verified through an entry in the page head or in DNS, which transmits no visitor data.
External content: booking calendar
The booking calendar on the demo page comes from an external provider. It loads only if you have agreed to the “External content” category. All videos are hosted on our own server; playing them sends no request to any third party.
Calendly
The provider is Calendly LLC, 115 East Main Street, Suite A1B, Buford, Georgia 30518, USA. On loading, your IP address and browser data are transmitted to Calendly; Calendly may set its own cookies. If you book an appointment, Calendly additionally processes the details you enter (name, email address, preferred slot, optional message) and passes them to us. Here too the transfer to the USA relies on your explicit consent under Art. 49 (1) (a) GDPR. Details at calendly.com/legal/privacy-notice.
You can arrange an appointment without Calendly at any time — write to sales@claritava.com.
Getting in touch
Email and telephone
If you contact us by email or telephone, we process your details solely to handle your request and in case of follow-up questions. The legal basis is Art. 6 (1) (b) GDPR where your enquiry relates to a contract or its preparation, and otherwise Art. 6 (1) (f) GDPR.
Form
On the become a partner page you can contact us through a form. The details are assembled into an email on our server and delivered to us through our sending provider. They are not stored on the web server itself and no database is created there. In addition we record your enquiry in our customer management system; details are given below.
We process the fields you complete (first and last name, email address, optionally company, type of partnership, typical client size and your message) as well as the time of submission. The legal basis is your consent under Art. 6 (1) (a) GDPR and Art. 6 (1) (b) GDPR where the enquiry serves to initiate a business relationship.
To protect against automated submissions we check three things: whether an additional field invisible to humans has been filled in, how much time passed between opening and sending, and whether a request has just been sent from the same IP address. For the last check we briefly place a file on our server whose name is a hash of your IP address created with a secret value. It has no content and is deleted after one hour at the latest. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is spam prevention. In addition we use Cloudflare Turnstile; details are given two sections below.
Your enquiry stays in our mailbox until it has been dealt with and no further questions are expected, but no longer than two years. Where it constitutes business correspondence, the statutory retention periods of six and ten years respectively apply.
Spam protection with Cloudflare Turnstile
To keep automated bulk enquiries out of our forms we use Cloudflare Turnstile. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA.
Turnstile checks in the background whether a request comes from a human. To do so the service evaluates technical characteristics of your browser and device and stores an entry in your browser for that purpose. The data transferred includes your IP address, details about your browser and operating system, and information about how you interact with the form page. In most cases you will not have to solve a puzzle.
The Cloudflare script is only loaded once you click into a form field or start typing. As long as you are merely reading a page, no connection to Cloudflare is made.
The legal basis is our legitimate interest in preventing misuse and keeping our systems secure under Art. 6(1)(f) GDPR. A data processing agreement is in place with Cloudflare. The transfer to the USA relies on the European Commission's standard contractual clauses and on Cloudflare's certification under the EU-US Data Privacy Framework.
Without JavaScript enabled, Turnstile is not loaded. Our forms can still be submitted; in that case only the server-side protections apply. If you would rather not use the service, you can reach us by email at any time at sales@claritava.com.
Further information: Cloudflare privacy policy.
Delivery of form messages
To make sure your enquiry reaches us reliably, we send the resulting email through a specialised provider. The provider is Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany, registered at the local court of Charlottenburg under HRB 133191 B, a subsidiary of Sendinblue SAS, Paris.
What is transferred is exactly what you entered into the form — first and last name, email address and the other fields you filled in, together with your message. You also receive a short acknowledgement at the address you gave; it contains no advertising.
Brevo processes the data exclusively on servers within the European Union. No transfer to a third country takes place. A data processing agreement under Art. 28 GDPR is in place with Brevo.
The legal basis is Art. 6 (1) (b) GDPR, because the processing serves to answer your enquiry and thus to take steps prior to entering into a contract. Brevo's delivery logs contain your email address, the subject and the delivery status; they are deleted there after 30 days. We keep the message itself in our mailbox for as long as it takes to deal with your request.
Further information: Brevo privacy policy.
Your enquiry in our customer management system
So that an enquiry does not sit in a mailbox alone and can be handled in a traceable way, we also record it in our customer management system. The provider is weclapp GmbH, Friedrich-Ebert-Strasse 28, 97318 Kitzingen, Germany, registered with the commercial register of the local court of Frankfurt am Main under HRB 129744.
We transmit your first and last name, your email address and, if you provided them, your company and telephone number. Your remaining form entries and your message are stored there as running text in a description field. The transmission takes place only after the email has been sent to us.
weclapp stores the data in a data centre in Frankfurt am Main certified to ISO 27001. No transfer to a third country takes place. A data processing agreement under Art. 28 GDPR is in place with weclapp.
The legal basis is Art. 6 (1) (b) GDPR where your enquiry serves to initiate a business relationship, and otherwise Art. 6 (1) (f) GDPR; our legitimate interest is the orderly and traceable handling of enquiries. The record is deleted once your enquiry has been dealt with and no follow-up questions are to be expected, after two years at the latest. Statutory retention periods apply to business correspondence.
No newsletter is connected with this. You will only receive promotional emails from us if you sign up for them separately.
Further information: weclapp privacy policy.
Recipients, retention and linked services
We do not pass your data on to third parties unless it is necessary to perform a contract, we are legally obliged to do so, or you have consented. The processors involved are: our host, Brevo GmbH for delivering the form messages, weclapp GmbH for our customer management system, Cloudflare, Inc. for the forms' spam protection, and — after your consent — Google for audience measurement and Calendly for booking appointments.
We process personal data only for as long as it is needed for the respective purpose. The specific periods are stated with each individual processing activity.
Links to LinkedIn, to the Claritava application at app.claritava.com or to other websites are plain references. No data is transmitted unless you click the link.
Your rights
You have the following rights regarding your personal data at any time. An informal message to sales@claritava.com is sufficient.
- Access (Art. 15 GDPR)
- You can find out whether and which data we process about you, for what purpose, for how long and to whom we pass it on.
- Rectification (Art. 16 GDPR)
- We must correct inaccurate data and complete incomplete data.
- Erasure (Art. 17 GDPR)
- You can request deletion unless a retention obligation prevents it.
- Restriction (Art. 18 GDPR)
- Instead of deleting, we can also restrict processing.
- Data portability (Art. 20 GDPR)
- Data you gave us on the basis of consent or a contract will be provided in a common, machine-readable format.
- Objection (Art. 21 GDPR)
- You may object to processing based on a legitimate interest on grounds relating to your particular situation.
- Withdrawal of consent
- You may withdraw consent at any time with effect for the future; for cookies via the cookie settings in the footer.
Irrespective of this, you may lodge a complaint with a supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, www.lda.bayern.de.
Encryption and security
This website uses SSL/TLS encryption throughout, recognisable by the “https://” in the address bar. In addition we use security headers that prevent content from being loaded from third-party servers; the only exceptions are the services you have agreed to. No automated decision-making, including profiling, takes place.
Changes to this policy
We adapt this privacy policy whenever the website or the legal situation changes. The version published here always applies. The date of the last change is shown at the end of this page.
Last updated: August 2026 · Claritava GmbH, Nuremberg