Privacy Notice
Personal data should only move where responsibility is defined.
This notice explains how INSODEMA processes information when this website is visited or a public enquiry is submitted. It reflects the activated public configuration.
Public information is collected for a defined purpose and handled within the responsible operational context.
1. Controller
Who is responsible for the processing?
INSODEMA
Owner and authorised representative:
Robert Breuss
40597 Düsseldorf
Deutschland
E-Mail: legal@insodema.com
2. Hosting and server logs
Technical delivery and protection of the website.
Recipient category: Hosting-Dienstleister innerhalb Deutschlands
Server location: Deutschland
When the website is accessed, the hosting environment may process technical log data such as IP address, time of access, requested resource, response status, referrer and browser or device information. This is required to deliver the website, identify faults and protect the systems against misuse.
Configured application and server-log retention: up to 14 days, unless a security incident requires longer evidence preservation.
The intended legal basis is Art. 6(1)(f) GDPR: the legitimate interest in secure and reliable operation.
3. Necessary cookies and session data
Only what the requested function needs.
Contact and support forms use server-side session data for CSRF protection, minimum submission timing and request throttling. This information is used only for form security and is not a marketing profile.
The preference cookie insodema_cookie_notice records only that the cookie information has already been shown. It expires after twelve months, uses SameSite=Lax and receives the Secure attribute over HTTPS.
These functions are not used for advertising or cross-site tracking.
4. Contact and collaboration requests
Enquiries are handled in the responsible communication workflow.
The contact form may collect the reason for contact, sender type, name, email address, organisation, role, telephone number, country, preferred language, product or system context, subject and message. Optional campaign parameters and the referring domain may be included when present.
The website validates the submission and transfers it securely to the responsible operational system. The public website does not maintain a separate persistent contact or lead database.
Processing is based on Art. 6(1)(b) GDPR where the request concerns a contract or pre-contractual steps, and otherwise on Art. 6(1)(f) GDPR for the legitimate interest in answering relevant enquiries and evaluating collaboration.
Submitting the form does not create a newsletter subscription, marketing consent or automatic customer relationship.
5. Optional public support route
Support information follows the ticket lifecycle.
When activated, the support form may collect contact details, support category, affected product, urgency, incident time, customer and licence references, existing ticket reference, affected URL, browser or device information, subject and problem description.
A successful submission creates a support record and public reference in the responsible support system. The website itself does not maintain the authoritative ticket history.
Automated tools may assist with classification or prepare a response draft, but final customer communication remains subject to human review and approval.
Support processing is generally based on Art. 6(1)(b) GDPR and, where necessary for security or legal obligations, Art. 6(1)(c) or (f) GDPR.
6. Analytics and marketing
No hidden marketing profile.
INSODEMAweb currently does not use third-party audience analytics.
The website currently does not use marketing cookies or behavioural advertising.
7. Recipients and access
Access follows operational responsibility.
Personal data may be processed by the hosting recipient category, authorised internal systems and specifically authorised service providers only where required for the stated purpose.
Public contact or support data is not distributed automatically across unrelated systems, used for unrestricted research or sold to advertisers.
8. Retention
Records remain only as long as their purpose requires.
Contact requests: Contact requests are retained for the time required to process the enquiry and document the communication context, then deleted or anonymised unless legal, contractual or security reasons require longer retention..
Support tickets: Ticket lifecycle plus 24 months.
Longer retention may apply where required by contractual, security, tax, legal-claim or statutory obligations.
9. Your rights
Data protection rights remain available.
Subject to the applicable requirements, you may request access, correction, deletion, restriction, data portability or object to processing. You may also complain to a competent data-protection supervisory authority.
Privacy requests can use the secure contact workflow.
10. Security and version
Controlled transmission, limited public exposure.
Contact and support requests are transmitted server-to-server over HTTPS. Integration credentials remain server-side and are not exposed to the browser.
Privacy notice version: 2026-07-01
Effective date: 2026-07-16