Privacy Policy

  1. Data Controller

CMMC GmbH

Emilienstraße 45, 09131 Chemnitz, Germany

Phone: +49 163 9678432

Email: nadine.lehnert@cmmc-engineering.com

Data Protection Officer: Dr.-Ing. Nadine Lehnert

 

  1. Scope

This Privacy Policy provides information about the processing of personal data when visiting our website https://www.cmmc-engineering.com and in connection with contacts or business relationships initiated through it. Terms such as “processing,” “controller,” “processor,” or “personal data” correspond to the definitions in Article 4 of the GDPR.

 

  1. Legal Basis

We process personal data in accordance with the GDPR and the TTDSG. Depending on the specific process, we rely on:

  • Art. 6(1)(a) GDPR (consent),
  • Art. 6(1)(b) GDPR (contract/pre-contractual relationship),
  • Art. 6(1)(c) GDPR (legal obligation),
  • Art. 6(1)(f) GDPR (legitimate interest, e.g., IT security, website operation, communication).
  • Section 25(1)–(2) TTDSG applies to the storage/reading of information on end devices (e.g., cookies, local storage).

 

  1. Hosting, Website Provision & Server Log Files

We host the website with an external hosting provider with whom we have a data processing agreement (Art. 28 GDPR). When you visit the pages, server log files are automatically processed (browser type/version, operating system, referrer URL, pages visited, date/time, IP address).

  • Purpose: Operation, stability, security (IT security measures, error analysis).
  • Legal basis: Art. 6(1)(f) GDPR.
  • Retention period: Generally 7 days, extended only in the event of security-related incidents.

 

  1. Encryption

Our website uses TLS/SSL. You can recognize an encrypted connection by the “https://” and the padlock icon in your browser.

 

  1. Contacting Us (Email, Phone, Contact Form)

When you contact us, we process the data you provide (e.g., name, company, email, phone number, content of the inquiry).

  • Purpose: Processing inquiries, communication, and, if applicable, initiating a contract.
  • Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual measures) or (f) (general communication).
  • Retention period: We retain inquiries for as long as necessary to process them; statutory retention periods (particularly under commercial and tax law) may range from 6 to 10 years.

 

  1. Job Applications

When you submit a job application (via email or form), we process the application data you provide solely for the purpose of deciding whether to establish an employment relationship.

  • Legal basis: Section 26(1) BDSG; additionally, Article 6(1)(b) GDPR; in cases of consent, Article 6(1)(a) GDPR.
  • Retention period: If no employment is offered, we generally delete application data 6 months after the conclusion of the process; beyond that, only with consent or in cases of legitimate interest (e.g., defense of legal claims).

 

  1. Cookies, Local Storage & Consent Management

We use technically necessary cookies (e.g., for language selection, security) as well as – with your consent – optional cookies/technologies for statistics, convenience, and external media.

  • Legal basis: Section 25(2) TTDSG (necessary) or consent under Section 25(1) TTDSG in conjunction with Article 6(1)(a) GDPR (all non-necessary).
  • Withdrawal: You can withdraw or modify your consent at any time via the cookie banner. You can also delete or block cookies in your browser; however, this may result in functional limitations.
  • We use a consent management tool (CMP) that logs your consent decisions (time, categories, pseudonymous ID) and allows you to make granular selections.

 

  1. Audience Measurement & Analysis

If you consent, we use Google Analytics 4 provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA, USA (“Google”).

  • Purpose: Audience measurement, usage analysis, and improvement of our website.
  • Legal basis: Consent (Art. 6(1)(a) GDPR; § 25(1) TTDSG).
  • Settings: We use IP anonymization; GA4 truncates IP addresses within the EU/EEA.
  • Data transfer to the U.S.: Google is certified under the EU-U.S. Data Privacy Framework (DPF). We base transfers to the US on the DPF or, if necessary, on SCCs with supplementary measures. Further information on Google’s DPF status can be found in the official registry and in Google’s privacy policy. EUR-Lex+2dataprivacyframework.gov+2
  • Retention period: Event data in GA4 is retained for 2–14 months by default.
  • Withdrawal: You can withdraw your consent via the cookie banner. Additionally, Google offers an opt-out add-on for common browsers.

 

  1. Tag Management

We may use Google Tag Manager for the technical integration and management of scripts/tags. GTM itself does not set any cookies and (according to Google) does not process user data for its own purposes; the processing of the integrated services is governed by the respective sections. Legal basis: Art. 6(1)(a) GDPR (if tags requiring consent are loaded) or (f) (for tags necessary for purely technical display).

 

  1. External Content & Tools

11.1 Fonts (Google Fonts)

We embed fonts either locally or (if technically necessary) via Google’s servers. When fonts are loaded externally, Google receives, among other things, your IP address and browser data.

  • Legal basis: For external retrieval, consent (Art. 6(1)(a) GDPR; § 25(1) TTDSG); otherwise, legitimate interest (Art. 6(1)(f) GDPR) in consistent presentation.
  • Transfer to third countries: see Section 9 (DPF/SCCs).

11.2 Map/video/audio embeds (e.g., Google Maps, YouTube, Vimeo)

We only load such content after your active consent (“2-click solution” or via consent in the banner).

  • Legal basis: Art. 6(1)(a) GDPR; § 25(1) TTDSG.

11.3 Social media profiles (links only)

On our pages, we provide links to company profiles (e.g., LinkedIn). A simple link does not transfer any data to the platform; when accessed, the privacy policies of the respective providers apply.

 

  1. Business Contacts, Contractual Relationships, and Suppliers

In connection with the initiation and fulfillment of contracts with customers and suppliers, we process contact information, communication data, contract data, and payment data.

  • Legal basis: Art. 6(1)(b) GDPR; where necessary, (c) (legal obligations) and (f) (enforcement of claims, IT/access security).
  • Retention period: In accordance with statutory retention periods (typically 6 or 10 years) and statutes of limitations.

 

  1. Recipients & Categories of Data Recipients

  • IT service providers/hosting/CMP/analytics (processors, Art. 28 GDPR)
  • Consultants & service providers (e.g., tax consulting, legal consulting)
  • Government agencies/public authorities where legally required
  • Payment/shipping service providers on a case-by-case basis for contract fulfillment

Data is not disclosed to third parties for advertising purposes.

 

  1. Transfers to Third Countries

If data processing is carried out by service providers in third countries (particularly the U.S.), we ensure an adequate level of data protection, e.g., through:

  • Adequacy decision (EU-US Data Privacy Framework),
  • Standard Contractual Clauses (SCCs) including a risk/transfer impact assessment and, if necessary, additional technical/organizational measures.

 

  1. Retention Period

Unless otherwise specified in this statement, we delete or anonymize data as soon as the purpose no longer applies and no statutory retention periods preclude this. Statutory periods are, for example, 6 years (commercial correspondence) and 10 years (tax-related documents). Security/incident logs may be stored temporarily for a longer period.

 

  1. Obligation to Provide Data

Certain information is required in the context of contract initiation and execution (e.g., contact and billing information). Without this data, we cannot conclude or fulfill the contract. There is no obligation to provide data for website functions requiring consent—such functions may not be available in such cases.

 

  1. No Automated Decision-Making

No decision-making based solely on automated processing, including profiling as defined in Article 22 of the GDPR, takes place. (Pure usage analysis with GA4, where consent has been given, has no legal effect on data subjects.)

 

  1. Your rights

You have the following rights – subject to the legal requirements:

  • Right of access (Art. 15 GDPR),
  • Right to rectification (Art. 16 GDPR),
  • Right to erasure (Art. 17 GDPR),
  • Right to restriction of processing (Art. 18 GDPR),
  • Data portability (Art. 20 GDPR),
  • Objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR),
  • Withdrawal of consent (Art. 7(3) GDPR) with effect for the future.

Right to lodge a complaint: You may lodge a complaint with a data protection supervisory authority (e.g., with the Saxon Data Protection Commissioner). An overview of supervisory authorities is available from the BfDI. Contact for exercising rights: Please use the contact details provided in Section 1.

 

  1. Security (TOM)

We maintain appropriate technical and organizational measures (TOM) to secure the data, including access controls, encryption, rights/role concepts, backups, and logging. Our data processors are carefully selected, contractually bound, and regularly audited.

 

  1. Changes to this Privacy Policy

We will update this policy as required by changes in the legal landscape, our processing activities, or the services we use. The current version on this page is always the one that applies.

 

As of March 24, 2026

    Do you have questions?