Privacy policy
This policy explains which personal data we process when you visit this website, for what purpose and on what legal basis. We process only the data required to operate the website and to handle your enquiry. We run no newsletter, no user accounts and no comment function.
Controller
The controller within the meaning of Art. 4(7) GDPR is:
Standartisator GmbH
Kreuz 16, 83558 Maitenbeth
Germany
Represented by the managing directors, each authorised to represent the company alone: Ievgenii Shevchenko, Viktoriia Savchenko.
Phone: +49 8072 6163999
Email: impressum@standartisator.de
Your rights
You have the following rights at any time regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
Withdrawal and complaints
Where processing is based on your consent, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR). This does not affect the lawfulness of processing carried out before the withdrawal.
A message to impressum@standartisator.de is sufficient to exercise your rights.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Deutschland.
Hosting and server log files
This website is hosted by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. The provider processes data on our behalf as a processor under a contract pursuant to Art. 28 GDPR.
When a page is requested, technically necessary data is processed: IP address, date and time of the request, the address requested, HTTP status code, volume of data transferred, referrer, and browser and operating system identifiers.
The purpose is delivery of the website together with its security and stability, in particular defence against automated attacks. The legal basis is our legitimate interest in secure and uninterrupted operation (Art. 6(1)(f) GDPR).
This processing involves a transfer to the United States. It takes place on the basis of the safeguards provided by the provider under Art. 44 et seq. GDPR (standard contractual clauses or certification under the EU-US Data Privacy Framework).
Fonts
All fonts used on this website are stored on and delivered from our own server. There is no connection to Google Fonts or any other external font provider. No data is transferred to third parties when fonts load, and your IP address is not disclosed to any font provider.
Cookies and local storage
We set no cookies for analytics or advertising without your consent. We use no third-party consent platform; the notice is served by our own website.
Necessary cookie std_consent: stores only your decision on the notice (granted or declined). First-party, one-year lifetime, SameSite=Lax. Without it we could not honour a refusal; the legal basis is § 25(2)(2) TDDDG together with Art. 6(1)(c) and (f) GDPR.
Session storage std_utm: contains campaign parameters (utm_*) only if they were present in the address you opened. The entry is held in your browser's sessionStorage, is deleted when you close the tab, and serves solely to attribute a subsequently sent enquiry to the correct campaign.
If JavaScript is disabled in your browser, no cookies are set and no external services are loaded.
Contact form
Name, email address and your consent are mandatory. Phone number, company and message are optional. We additionally transmit the language and the address of the page the enquiry was sent from, and the campaign parameters described above where present.
The purpose is to handle your enquiry, to contact you and to prepare a possible contractual relationship. The legal basis is your consent (Art. 6(1)(a) GDPR) and the steps preceding a contract (Art. 6(1)(b) GDPR).
The enquiry is transmitted to and processed in our customer management system: HighLevel Inc., 400 North Saint Paul St., Suite 920, Dallas, TX 75201, USA. The provider acts as a processor under Art. 28 GDPR. This too involves a transfer to the United States on the basis of the safeguards under Art. 44 et seq. GDPR.
To guard against automated submissions the form contains an additional field invisible to you. It evaluates only whether the field was filled in by a machine, sets no cookie and performs no recognition. Submissions identified in this way are not transmitted.
Providing the data is voluntary. Without a name, an email address and your consent, however, we cannot process your enquiry.
We erase the data as soon as it is no longer required for the stated purpose, and at the latest 3 years after the last contact, at the end of that year. Statutory retention obligations, in particular under § 147 AO and § 257 HGB, remain unaffected.
Appointment booking
The booking link leads to a booking form operated by HighLevel Inc.. Clicking it takes you off this website; processing of the data you enter there serves to arrange the appointment (Art. 6(1)(b) GDPR). We do not embed the booking form in our pages, so no data reaches the provider before you click.
The WhatsApp link opens the WhatsApp application or its web interface. Data is transferred to the operator of WhatsApp only once you click; no WhatsApp widget is embedded on this website. The provider’s own privacy terms additionally apply to any subsequent conversation.
Google Tag
After you consent we load Google Tag or Google Tag Manager (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The service records usage data and sets cookies to measure reach and the effectiveness of our advertising.
The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Before consent every consent type is technically set to "denied" and no script is loaded. You may withdraw consent at any time by deleting the cookie in your browser and choosing again in the notice.
A transfer to the United States is possible and takes place on the basis of the safeguards under Art. 44 et seq. GDPR.
No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
Encryption
This website is delivered exclusively over an encrypted connection (TLS). Data you send through the form is protected against interception in transit.
Changes to this policy
We update this policy when the processing described here changes, for example through new features or service providers. The version published here is the one that applies.
Last updated: August 21, 2026