LEGAL INFORMATION
Privacy notice
Last updated:
This notice explains the processing of personal data on azureonwhite.com and localization.azureonwhite.com, including their German, English and Chinese versions. The separate MAHR website has its own privacy information.
The websites provide a contact form. There are no user accounts, newsletter subscriptions, ordering or payment features.
This statement also covers the corresponding Sites hosting addresses for these two websites.
1. Controller and privacy contact
Azure on White GmbHMartinstraße 18 A
53177 Bonn
Germany
Represented by managing directors Benjamin Effer and Fritjof Nelting. Send privacy questions or requests to exercise your rights to the email address below or our postal address.
2. Website access and hosting
Accessing a website requires connection data to be transmitted to the hosting infrastructure. This includes your IP address, the time and destination of a request, and information sent by your browser, such as browser and operating system details and, where provided, the referring page. This processing enables delivery of website content. Access and security logs may also support troubleshooting and protection against abusive access.
The legal basis for necessary delivery and security is Article 6(1)(f) GDPR. Our legitimate interests are an available, functional and secure corporate website and the investigation of technical faults and attacks.
These websites are provided through ChatGPT Sites by OpenAI. Under the published Sites terms, OpenAI Ireland Ltd. is the contracting entity for users in the European Economic Area. The terms provide for processing personal hosting data on our behalf. Additional infrastructure providers may be involved.
3. Contact form and email
When you submit the form, our server sends your inquiry through a Google Apps Script web app to our existing Google Workspace mailbox, support@azureonwhite.com. The visitor address is used as Reply-To; the form does not send an automatic acknowledgment.
The form requires name, email address and message; company name and phone number are optional. The source website and language accompany the inquiry. No automatic confirmation is sent to visitors. We use the information only to handle inquiries and related correspondence.
For steps toward or performance of a contract with an individual, the legal basis is Article 6(1)(b) GDPR. For general business inquiries and company representatives it is Article 6(1)(f) GDPR, based on our legitimate interest in handling inquiries.
Server-side protection uses keyed hashes of the platform client IP and ten-minute counters. Expired counters are removed on the next request. Permanent keyed request and content fingerprints, a timestamp and send status prevent duplicate sends. Message bodies, names, email addresses and telephone numbers are not stored in this protection database or application logs.
The existing email links remain an alternative and open your email application. Nothing is sent until you send the email yourself.
4. Cookies, device storage and analytics
The website code we supply does not set cookies or use Local Storage or Session Storage. It contains no analytics, advertising or social-media tracking tools integrated by us. Language selection uses the page address and is not stored by our code in a persistent browser profile.
The information about cookies and browser storage concerns the website functions we supply. The hosting provider’s processing of technical connection data is described in section 2.
5. Local features, fonts and links
When activated, “Copy address” writes only our public email address to your device’s clipboard. Our code does not read existing clipboard contents or transmit your clipboard to us.
The logo and design files are delivered with the website. The code does not embed third-party font files, videos, maps or social-media posts. Text is displayed using available system fonts.
References to MAHR or legal information are ordinary links rather than embedded content. Visiting a linked service also subjects you to its privacy information. Our website code does not load linked services merely by displaying a link.
6. Recipients and access
Within our company, only people who need access to handle an inquiry receive it. Other recipient categories include hosting, email and IT providers where necessary for the activities described. Processing on our behalf is subject to the requirements of Article 28 GDPR.
Disclosure to authorities, courts or advisors bound by professional confidentiality may be necessary to meet legal obligations or establish, exercise or defend legal claims. The basis is Article 6(1)(c) or (f) GDPR, depending on the circumstances. We do not publish inquiries on the website.
7. Processing outside the European Economic Area
International service providers may process personal data outside the European Economic Area.
OpenAI’s published agreements provide for EU Standard Contractual Clauses or a European Commission adequacy decision when European data is transferred onward to affiliates and providers outside the European Economic Area or Switzerland. You may contact us for information about the applicable safeguards and how to obtain a copy.
OpenAI: Sites Data Processing Addendum for individual plans
OpenAI: Data Processing Addendum for business services
8. Retention
We retain inquiries and related correspondence for as long as needed to handle the matter and necessary follow-up communication. Once that purpose is complete, the data is deleted unless legal retention obligations or legitimate grounds justify further storage.
Where a message forms part of records subject to tax or commercial-law retention duties, its scope and retention period follow the applicable obligation, based on Article 6(1)(c) GDPR. Limited additional retention may be necessary to establish or defend claims under Article 6(1)(f) GDPR. Not every inquiry is treated as an invoice for retention purposes.
9. Your data protection rights
Subject to the applicable legal conditions, your rights include:
- Access to information about your personal data and a copy under Article 15 GDPR.
- Correction of inaccurate data or completion of incomplete data under Article 16 GDPR.
- Erasure under Article 17 GDPR and restriction of processing under Article 18 GDPR.
- Data portability under Article 20 GDPR where processing is automated and based on consent or contract.
- Withdrawal of consent for the future under Article 7(3) GDPR, without affecting the lawfulness of processing before withdrawal.
10. Right to object under Article 21 GDPR
Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop the relevant processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.
You may object to processing for direct marketing at any time without giving reasons. After such an objection, the data must no longer be processed for that purpose. The current website does not offer newsletter subscriptions.
11. Complaints
Under Article 77 GDPR you may complain to a supervisory authority, particularly where you habitually reside or work, or where an alleged infringement occurred. For a company in North Rhine-Westphalia, one relevant authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). Its website provides current contact and complaint options.
12. Automated decisions and changes
This informational website’s functions do not make solely automated decisions about visitors with legal or similarly significant effects and do not create related personal profiles.
We update this privacy notice when website functions, the services used or relevant legal requirements change.
