Privacy policy
Information about the processing of personal data on our website.
1. Controller
The controller responsible for data processing on this website is:
GNP Technologies UG (haftungsbeschränkt)Rheinweg 148
41812 Erkelenz
Germany
Managing Director: Tim Lucca Lüngen
Email: kontakt@gnp-tech.de
2. General information
Personal data includes all information through which a natural person can be identified directly or indirectly.
We process personal data only where necessary to provide and secure this website, process contact requests or comply with legal obligations.
3. Provision and hosting of the website
This website and its associated server services are operated by the following hosting provider:
IONOS SEElgendorfer Straße 57
56410 Montabaur
Germany
When the website is accessed, technically necessary connection data is processed. This may include, in particular, the IP address, date and time of access, requested content, transferred data volume, referrer URL, browser type, operating system and requesting provider.
The processing takes place to provide the website securely, reliably and without errors and to prevent and investigate technical attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and stable operation of our website.
Technical log data is stored only for as long as necessary for operation, security and error analysis. It is stored for longer only where a specific security incident must be investigated or legal obligations require it.
Where required, a data processing agreement is in place with the hosting provider.
4. Technical platform and Core API
The website uses a technical platform operated by GNP Technologies. Public requests may be processed through secured server and API systems.
Only the data required for the respective function is transmitted. The systems are not publicly accessible for administrative purposes and are protected through technical and organizational measures.
Depending on the respective operation, the legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
5. Contact form and contact requests
When you contact us through the contact form, we process the information you enter. This includes, in particular, your name, email address, subject, selected category, message and technically necessary security information.
The data is used to process and respond to your request and for any further communication that may be necessary. It is transmitted to our internal ticket system.
If your request relates to a contract or pre-contractual measures, Article 6(1)(b) GDPR is the legal basis. General requests are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest consists of processing incoming requests and communicating with interested parties and users.
Ordinary contact requests are generally deleted no later than six months after their final processing, unless further retention is required.
Communication relevant to contracts, business matters or legal claims may be stored until the applicable statutory limitation period expires. The regular limitation period is generally three years and normally begins at the end of the year in which the relevant claim arose. Statutory retention obligations under commercial and tax law remain unaffected.
6. Email communication
When you contact us by email, we process your email address, the content of your message and any other information you provide in order to handle your request.
We use services provided by IONOS SE for the technical provision of our email services. The legal bases and retention periods correspond to the provisions for contact requests.
7. Cloudflare Turnstile
We use Cloudflare Turnstile to protect our contact form against automated access, spam and misuse. The provider is:
Cloudflare, Inc.101 Townsend Street
San Francisco, California 94107
USA
Turnstile uses technical signals to determine whether a request is likely to have been made by a human. In particular, the IP address, browser and device information, time, referrer and interaction and security information may be processed.
After successful verification, a temporary security token is generated. This token is verified on the server before the contact form is processed.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, systems and contact options against spam, automated access and other misuse.
A transfer of data to the USA cannot be completely ruled out. According to Cloudflare, recognized safeguards for international data transfers are used, in particular the EU-US Data Privacy Framework or EU Standard Contractual Clauses.
Further information is available in the Cloudflare Turnstile privacy policy.
8. Cookies and local storage
This website currently does not use analytics, marketing or tracking cookies that require consent.
Technically necessary storage mechanisms may be used where required for security, page presentation or explicitly requested functions. If services requiring consent are used in the future, they will only be activated after the appropriate consent has been given.
9. Recipients of personal data
Personal data is disclosed to recipients only where this is necessary for the respective processing, a legal obligation exists or another legal basis permits the disclosure.
Potential recipients include in particular:
- hosting and email service providers, particularly IONOS SE,
- security service providers, particularly Cloudflare in connection with Turnstile,
- internal technical systems and authorized employees,
- public authorities or other bodies where a legal obligation exists.
10. Data security
We use appropriate technical and organizational security measures to protect personal data against loss, manipulation, unauthorized access and other misuse.
The website is transmitted in encrypted form using HTTPS. Our security measures are reviewed and developed further in accordance with technological developments.
11. Your rights
Subject to the applicable legal requirements, you have the following rights in particular:
- right of access pursuant to Article 15 GDPR,
- right to rectification pursuant to Article 16 GDPR,
- right to erasure pursuant to Article 17 GDPR,
- right to restriction of processing pursuant to Article 18 GDPR,
- right to data portability pursuant to Article 20 GDPR,
- right to object pursuant to Article 21 GDPR,
- right to withdraw consent with effect for the future.
To exercise your rights, you may contact kontakt@gnp-tech.de .
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.
The supervisory authority responsible for our registered office is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–4
40213 Düsseldorf
Germany
Website: www.ldi.nrw.de
13. Changes to this privacy policy
We update this privacy policy when our website, the services used or the legal requirements change.
Last updated: August 2026