01

Privacy at a Glance

General Information

The following information provides an overview of what happens to your personal data when you visit our website. Personal data means any information through which you can be personally identified.

More detailed information is provided in the following sections of this Privacy Policy.

Controller

The controller responsible for processing personal data on this website is:

OrasTEC GmbH
Wiesenweg 1
92551 Stulln
Germany

Represented by its managing directors:

Prof. Dr.-Ing. Christian Bergler
Manuel Schmitt, M.Sc.

Telephone+49 160 956 872 67

The controller determines, alone or jointly with others, the purposes and means of processing personal data.

How Do We Collect Your Data?

Some data is collected when you provide it to us. This applies in particular when you:

  • use our contact form,
  • send us an email,
  • contact us by telephone, or
  • submit an application.

Other data is collected automatically by our IT systems or by our hosting provider when you visit the website. This primarily includes technical information such as your IP address, browser, operating system, pages accessed, and the date and time of access.

What Do We Use Your Data For?

We process personal data in particular:

  • to provide the website securely and without technical errors,
  • to respond to enquiries,
  • to communicate with prospective customers, customers and business partners,
  • to take steps prior to entering into a contract and to perform contracts,
  • to process job applications,
  • to prevent attacks and investigate security incidents, and
  • to comply with legal obligations.

What Rights Do You Have?

Subject to the applicable legal requirements, you have in particular the right:

  • to obtain information about your stored personal data,
  • to have inaccurate data rectified,
  • to have your data erased,
  • to restrict processing,
  • to data portability,
  • to object to certain types of processing,
  • to withdraw consent, and
  • to lodge a complaint with a supervisory authority.

Further details are provided in the section "Your Rights".

02

Controller

The controller within the meaning of the General Data Protection Regulation and other applicable data protection laws is:

OrasTEC GmbH
Wiesenweg 1
92551 Stulln
Germany
Telephone+49 160 956 872 67

Managing directors authorised to represent the company:

Prof. Dr.-Ing. Christian Bergler
Manuel Schmitt, M.Sc.

03

Data Protection Officer

No data protection officer has been appointed.

Should a data protection officer be appointed in the future, the relevant contact details will be published here.

04

Legal Bases for Processing

We process personal data only where a valid legal basis exists. Depending on the circumstances, the following legal bases may apply:

Article 6(1)(a) GDPR — Consent

Where you have given your consent, we process your data on the basis of that consent.

You may withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Article 6(1)(b) GDPR — Contract and Pre-contractual Measures

We process personal data on this basis where processing is necessary:

  • for the performance of a contract,
  • in order to take steps prior to entering into a contract, or
  • to process a specific enquiry relating to a potential business relationship.

Article 6(1)(c) GDPR — Legal Obligation

Where we are legally required to process or retain particular data, processing is based on Article 6(1)(c) GDPR.

Article 6(1)(f) GDPR — Legitimate Interests

Processing may also take place where it is necessary for the purposes of our legitimate interests or those of a third party and those interests are not overridden by the interests, fundamental rights or freedoms of the data subject.

Our legitimate interests include in particular:

  • the secure and economical operation of our website,
  • ensuring IT security,
  • processing general business enquiries,
  • maintaining business relationships,
  • improving our services and business processes, and
  • establishing, exercising or defending legal claims.

Section 25 TDDDG

Where information is stored on or accessed from your terminal device, this is carried out:

  • on the basis of your consent pursuant to Section 25(1) TDDDG, or
  • without consent where access is strictly necessary to provide a digital service expressly requested by you, pursuant to Section 25(2) TDDDG.
05

Hosting and Provision of the Website

Our website is hosted by an external hosting provider.

When you access the website, the hosting provider may process in particular:

  • your IP address,
  • the date and time of access,
  • the URL or file requested,
  • the referring website, where transmitted by your browser,
  • browser type and version,
  • operating system,
  • hostname of the accessing device,
  • the amount of data transferred,
  • the HTTP status code, and
  • additional technical log and diagnostic data where applicable.

These data are normally stored in server log files.

Processing is necessary in order to:

  • deliver the website,
  • ensure stability and functionality,
  • identify technical errors,
  • identify and prevent attacks and misuse, and
  • ensure the security of servers and systems.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional operation of the website.

Where the hosting provider processes personal data on our behalf, we have entered into a data processing agreement with the provider in accordance with Article 28 GDPR.

Server log files are generally stored only for as long as necessary for the stated purposes. They may be retained for a longer period where there are specific indications of a security incident or unlawful use, or where statutory retention requirements apply.

Hosting Provider
hostNET Medien GmbH
Osterdeich 107
28205 Bremen
06

Encrypted Data Transmission

This website uses SSL or TLS encryption.

An encrypted connection can generally be identified by the address bar of your browser beginning with "https://" and by the display of a lock symbol.

Encryption is intended to protect information transmitted to us against unauthorised access by third parties.

07

Cookies and Similar Technologies

General Information

Our website may use cookies or similar technologies.

Cookies are small data records stored on your terminal device. They may be technically necessary to provide certain functions of the website or may be used for other purposes.

Strictly Necessary Cookies

Strictly necessary cookies may be used where they are essential for the operation of the website or for a function expressly requested by you.

The legal bases are:

  • Section 25(2) TDDDG for storing information on or accessing information already stored on your terminal device, and
  • Article 6(1)(f) GDPR for the subsequent processing of personal data.

Our legitimate interest lies in providing a technically secure, stable and user-friendly website.

Such cookies may include cookies that:

  • store your selected language,
  • maintain form or session settings,
  • enable security features, or
  • record your privacy choices.

Cookies and Technologies Requiring Consent

Cookies or similar technologies that are not strictly necessary are used only after you have given your consent.

The legal bases are:

  • Section 25(1) TDDDG and
  • Article 6(1)(a) GDPR.

You may withdraw your consent at any time with effect for the future using the cookie or privacy settings provided on the website.

Storage Period

Session cookies are generally deleted when you close your browser.

Persistent cookies remain on your device until their respective storage period expires or until you delete them manually.

You may also configure your browser so that:

  • you are informed when cookies are set,
  • cookies are accepted only in individual cases,
  • cookies are generally or selectively rejected, or
  • cookies are automatically deleted when the browser is closed.

Disabling strictly necessary cookies may restrict the functionality of the website.

08

Contact Form

A contact form is available on our website.

When you use the contact form, we process the information entered by you. This may include:

  • your name,
  • your email address,
  • the subject,
  • the content of your message,
  • any additional information voluntarily provided,
  • the date and time of submission,
  • your IP address and technical connection data, where logged for security purposes.

We use these data solely to process your enquiry, respond to follow-up questions and, where applicable, initiate or manage a business relationship.

Where your enquiry relates to an existing or potential contract, the legal basis is Article 6(1)(b) GDPR.

For general enquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in properly handling incoming enquiries and conducting business communications.

Where explicit consent is requested within the form, Article 6(1)(a) GDPR also applies.

Mandatory fields are required in order for us to process and respond to your enquiry. Without the relevant information, we may be unable to process your request.

The data will be erased once your enquiry has been conclusively dealt with, provided that no statutory retention obligations, contractual reasons or legitimate interests require further storage.

Where the enquiry results in a business relationship, the data may be retained for longer in accordance with applicable commercial and tax retention periods.

09

Contact by Email

If you contact us by email, we process in particular:

  • your email address,
  • your name, where provided,
  • the content of your message,
  • attachments,
  • communication and metadata,
  • the date and time of the communication.

Processing is carried out in order to handle and respond to your enquiry.

Where the communication relates to a contract or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR.

For other enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in proper business communication.

Where statutory retention obligations apply, further storage is based on Article 6(1)(c) GDPR.

Please note that ordinary email communication may involve security risks. Particularly confidential or sensitive information should therefore be sent only after prior consultation and via an appropriate secure transmission method.

10

Contact by Telephone

If you contact us by telephone, we may process in particular:

  • your name,
  • your telephone number,
  • the date and time of the call,
  • the content of the conversation,
  • any company or project information you provide.

Processing is carried out in order to respond to your request and communicate with you.

The legal basis is Article 6(1)(b) GDPR where the communication relates to entering into or performing a contract. In other cases, processing is based on Article 6(1)(f) GDPR.

Telephone conversations are not recorded without your explicit consent.

11

Business Communications with Customers, Prospective Customers and Partners

In the course of our business activities, we process personal data relating to:

  • customers,
  • prospective customers,
  • suppliers,
  • service providers,
  • cooperation partners,
  • contacts at companies and organisations.

This may include in particular:

  • master data,
  • contact details,
  • company and job function details,
  • communication content,
  • offer and contract data,
  • project information,
  • payment and billing information,
  • documentation and verification data.

Processing is carried out for:

  • taking steps prior to entering into a contract,
  • preparing offers,
  • performing contracts,
  • project communication,
  • providing services,
  • invoicing,
  • maintaining business relationships,
  • complying with legal obligations.

The legal bases are Article 6(1)(b), (c) and (f) GDPR.

12

Applications and Unsolicited Applications

You may apply for advertised vacancies or submit an unsolicited application.

During the application process, we may process in particular:

  • your first and last name,
  • contact details,
  • address,
  • date of birth, where provided,
  • application photograph, where voluntarily submitted,
  • curriculum vitae,
  • certificates and evidence of qualifications,
  • information relating to education and professional experience,
  • salary expectations,
  • possible starting date,
  • content of the cover letter,
  • interview notes and assessments,
  • any other application information submitted by you.

Processing is carried out in order to decide whether to establish an employment relationship.

The legal basis is Section 26(1) of the German Federal Data Protection Act in conjunction with Article 6(1)(b) GDPR.

Where you voluntarily provide special categories of personal data within the meaning of Article 9 GDPR, such data may be processed pursuant to Article 9(2)(b) GDPR where necessary to exercise rights or fulfil obligations under employment law. Otherwise, processing may be based on your explicit consent pursuant to Article 9(2)(a) GDPR.

If your application is successful, the data required for the employment relationship will be transferred to your personnel file.

If no employment relationship is established, application data will generally be erased no later than six months after the conclusion of the application process. Data may be retained for a longer period where:

  • you have explicitly consented to inclusion in an applicant pool,
  • statutory retention obligations apply, or
  • the data are required for the establishment, exercise or defence of legal claims.

You may withdraw your consent to inclusion in an applicant pool at any time with effect for the future.

Please submit application documents preferably in PDF format and avoid providing information that is not required for the application process.

13

External Links

Our website contains links to websites operated by external providers, including links to scientific profiles on Google Scholar.

When you click an external link, you leave our website. From that point onwards, the respective external provider is generally responsible for the processing of personal data.

We have no control over which data the respective provider processes, how long the data are retained or whether data are transferred to countries outside the European Union or the European Economic Area.

Please refer to the privacy information of the respective external provider.

Merely displaying an external link generally does not result in personal data being transmitted to the external provider. Transmission normally occurs only when you click the link and access the external website.

14

Google Scholar

Our website contains links to profiles or publications on Google Scholar.

Within the European Economic Area, Google Scholar is generally provided by:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

When you click such a link, you will be redirected to a Google website. Google may process in particular your IP address, device and browser information, the time of access, the previously visited page and other usage data.

If you are logged into a Google account, Google may associate your visit with your user account.

Google may also transfer data to Google LLC and other group companies in the United States or other third countries.

We have no control over Google's processing after you access the external website. Further information can be found in Google's privacy policy.

The link is provided on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in providing users with further information about scientific publications and professional profiles.

15

Recipients of Personal Data

Within OrasTEC GmbH, personal data are accessible only to persons who require them in order to perform their duties.

Personal data may also be disclosed to the following recipients or categories of recipients:

  • hosting and IT service providers,
  • email and communication service providers,
  • technical service providers and administrators,
  • tax advisers and auditors,
  • lawyers and other professional advisers,
  • banks and payment service providers,
  • authorities and public bodies where required by law,
  • courts and other bodies in connection with legal disputes,
  • business partners where required for contract performance.

Where external service providers process personal data on our behalf, they are engaged on the basis of a data processing agreement pursuant to Article 28 GDPR.

16

Transfers to Third Countries

Personal data are transferred to countries outside the European Union or the European Economic Area only where the requirements of Articles 44 et seq. GDPR are met.

Such transfers may occur in particular where we use service providers that:

  • are established in a third country,
  • use servers or subprocessors in a third country, or
  • form part of an internationally operating corporate group.

Transfers may in particular be based on:

  • an adequacy decision of the European Commission,
  • appropriate safeguards such as the EU Standard Contractual Clauses,
  • binding corporate rules, or
  • a statutory derogation pursuant to Article 49 GDPR.

Where a provider is certified under the EU-US Data Privacy Framework and an applicable adequacy decision exists, transfers to the United States may be based on that adequacy decision.

Where external links are used, a third-country transfer may occur once you access the linked website.

17

Storage Period

We generally retain personal data only for as long as necessary for the respective processing purpose.

The data are subsequently erased unless erasure is prevented by:

  • statutory retention obligations,
  • contractual reasons,
  • ongoing legal disputes,
  • limitation periods, or
  • other legitimate reasons.

Business documents may in particular be subject to commercial and tax retention obligations.

Where processing is based on your consent, we generally retain the data until you withdraw your consent, unless another legal basis permits or requires continued storage.

18

Data Security

We implement appropriate technical and organisational measures to protect personal data against:

  • loss,
  • destruction,
  • alteration,
  • unauthorised access,
  • unauthorised disclosure, and
  • other unlawful processing.

Our security measures are reviewed and adjusted in accordance with technological developments, the level of protection required and the risks involved.

However, completely risk-free data transmission over the internet cannot be guaranteed.

19

No Automated Decision-Making

As a general rule, no decisions based solely on automated processing, including profiling within the meaning of Article 22 GDPR, are made through this website.

Should we use such procedures in the future, we will provide the legally required information.

20

Your Rights

Right of Access

Under Article 15 GDPR, you have the right to request information as to whether and which personal data concerning you are being processed.

Right to Rectification

Under Article 16 GDPR, you have the right to request the correction of inaccurate data or completion of incomplete personal data.

Right to Erasure

Under Article 17 GDPR, you have the right to request the erasure of your personal data, subject to the applicable legal requirements.

Right to Restriction of Processing

Under Article 18 GDPR, you have the right to request restriction of processing, subject to the applicable legal requirements.

Right to Data Portability

Under Article 20 GDPR, you have the right, subject to the applicable legal requirements, to receive personal data that you have provided to us in a structured, commonly used and machine-readable format or to request transmission to another controller.

Right to Withdraw Consent

Under Article 7(3) GDPR, you may withdraw your consent at any time with effect for the future.

Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal.

Right to Lodge a Complaint

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority.

You may in particular contact the supervisory authority responsible for our registered office:

Supervisory Authority
Bavarian State Office for Data Protection Supervision — BayLDA
Promenade 18
91522 Ansbach
Germany

You may also contact a supervisory authority at your habitual place of residence, your place of work or the place of the alleged infringement.

21

Right to Object

Right to Object on Grounds Relating to Your Particular Situation

Where we process your personal data on the basis of Article 6(1)(e) or (f) GDPR, you have the right under Article 21 GDPR to object to processing at any time on grounds relating to your particular situation.

We will then cease processing the relevant personal data unless we can demonstrate:

  • compelling legitimate grounds for processing which override your interests, rights and freedoms, or
  • that processing is necessary for the establishment, exercise or defence of legal claims.

Objection to Direct Marketing

Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing for such marketing.

Following your objection, your personal data will no longer be processed for direct marketing purposes.

22

Requirement to Provide Personal Data

As a general rule, you are not legally or contractually required to provide personal data.

However, when contacting us, entering into a contract or submitting an application, certain information may be required so that we can:

  • process your enquiry,
  • communicate with you,
  • enter into or perform a contract, or
  • make a decision regarding your application.

Without the required information, we may be unable to process your request or may only be able to do so to a limited extent.

23

Amendments to This Privacy Policy

We reserve the right to amend this Privacy Policy if changes are made to:

  • our website,
  • the services used,
  • our processing activities, or
  • the legal requirements.

The version currently published on this website applies.

Last updated July 2026