Privacy policy
We take the protection of your data on our website very seriously and are committed to protecting your personal data in accordance with applicable law (in particular the GDPR). This policy describes which data we collect, how we use it and with whom we share it.
Controller
valexcon GmbH
Odenwaldweg 6, 84048 Mainburg, Germany
Phone: +49 8751 841829
Email: kontakt@valexcon.de
Managing directors: Ralph Müller, Sébastien Chaumiole, Heinrich Fritz, Tobias Jost
Data collected
Non-personal data: non-identifiable technical and aggregated usage information arising from the use of our services.
Personal data: individually identifiable information such as name, email address, postal address, phone number and IP address.
Methods of collection
- Technical access data generated automatically when the website is called up (server log files)
- Information you provide directly when you contact us (e.g. by email)
Purposes of processing
- Provision, secure operation and delivery of the website
- Preventing and analysing technical faults and ensuring IT security
- Handling your enquiries and contact requests
Hosting – Cloudflare Pages
This website is hosted by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) using the “Cloudflare Pages” service, including its global content delivery and security network (CDN). When you access the site, Cloudflare processes technically required connection data (in particular your IP address) in order to deliver the content and protect it against attacks (e.g. DDoS). The legal basis is our legitimate interest in secure and efficient provision (Art. 6(1)(f) GDPR).
A data processing agreement (Art. 28 GDPR) is in place with Cloudflare. Where data is transferred to the USA, this takes place on the basis of the EU Standard Contractual Clauses and – where applicable – the EU-US Data Privacy Framework.
Server log files
Each time the site is accessed, information transmitted by your browser is automatically recorded in server log files: browser type and version, operating system, referrer URL, date and time of access, and the IP address. This data is technically necessary, is not combined with other data sources and is used solely to deliver and secure the website. Legal basis: Art. 6(1)(f) GDPR.
Reach measurement (own, cookieless statistics)
To design our offering in line with demand, we compile privacy-friendly, aggregated statistics about how our website is used. No cookies are set and no cross-device tracking takes place.
For each page view we record: the page accessed, the source/referrer (e.g. search engine, social network or referring website), approximate location data provided by Cloudflare (country, region, city), device type, browser, operating system and language. Clicks on key buttons (e.g. “Contact” or submitting a form) are also counted as anonymous events. We also record technical metrics about the loading performance of the respective page (so-called Web Vitals: loading time of the main content, layout stability, responsiveness to input) – these contain no information about you and merely describe how quickly and reliably our page loaded in your browser.
Your IP address is not stored. To distinguish repeat views within a single day, we derive a non-reversible check value (hash) from your IP address, the browser identifier (user agent), the current calendar day and a secret value stored exclusively on our server. The check value is bound to the calendar day; no recognition beyond that day takes place, and we cannot draw any conclusions about your identity. The grouping of related page views within a visit (session) also takes place exclusively on the server.
The aggregated data collected in this way is stored in a database (Cloudflare D1) within the Cloudflare infrastructure and deleted after no more than 14 months. The legal basis is our legitimate interest in the statistical analysis and demand-oriented design of website usage (Art. 6(1)(f) GDPR). As no information is stored on or read from your device, no consent under Section 25 TDDDG is required.
You can object to the reach measurement at any time by enabling the “Do Not Track” or “Global Privacy Control” setting in your browser; in that case no data is collected.
Site search
Our website offers a search function (magnifier icon in the header). Searching the static page content takes place directly in your browser, without your input being transmitted to a server. To additionally search current news articles, your search term is transmitted to our server, used there solely to determine the results and not stored in that context. The legal basis is our legitimate interest in a functional search (Art. 6(1)(f) GDPR).
To improve our content, we store entered search terms together with the time, language and number of results – only with your consent to statistics collection. Storage is anonymous and without any link to your session or the reach-measurement hash; direct identifiers such as e-mail addresses and phone numbers are removed automatically before storage and the text is limited in length. The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time with effect for the future via the “Cookie settings” link in the footer. Search terms collected this way are deleted after no more than 14 months.
Your most recent searches are stored exclusively locally in your browser so they can be suggested to you when you reopen the search (see the section “Cookies, local storage and consent”); they are not transmitted to us.
“VALI” assistant
Our website provides the digital assistant “VALI”. Frequent questions are answered from a local, predefined knowledge base directly in your browser – without transferring your input to a server. If a question cannot be answered this way, your input (together with the most recent questions and answers of the same chat session) is transmitted to our server and answered by an AI language model within the Cloudflare infrastructure (Cloudflare Workers AI) – i.e. by the same processor that also provides the hosting (data processing agreement pursuant to Art. 28 GDPR; where processing takes place in the USA, the safeguards described in the hosting section apply). Your inputs are not stored by us and, according to Cloudflare, are not used to train AI models. The legal basis is our legitimate interest in providing a functional assistant (Art. 6(1)(f) GDPR); use is voluntary. Please do not enter any personal data into the assistant. AI answers may contain errors and do not constitute binding statements.
To improve our offering, we evaluate which topics VALI was able to answer; in doing so we store only the requested topic in the form of a fixed page reference defined by us or an anonymous counter for AI-answered questions (not any text you entered) as an anonymous event within the reach measurement described above.
Handover to our team: On request you can pass your enquiry from the chat on to our team (“Get a personal reply”). In that case – only after your active input and confirmation – we transmit your e-mail address, optionally your name and the questions you asked in the chat to us by e-mail (sent via Resend, see the “Email delivery” section). The legal basis is the performance of pre-contractual measures at your request (Art. 6(1)(b) GDPR); we treat this data like any other contact enquiry.
If VALI could not answer a question from the knowledge base, we store the text of your question – only with your consent to statistics collection – in order to identify and close gaps in our knowledge base. This text is stored anonymously and without any link to your session or the reach-measurement hash; direct identifiers such as e-mail addresses and phone numbers are removed automatically before storage and the text is limited to 200 characters. The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time with effect for the future via the “Cookie settings” link in the footer. Question texts collected this way are deleted after no more than 14 months. Please do not enter any personal data into the assistant.
Fonts
Fonts are served exclusively locally from our server (or the CDN). There is no connection to Google Fonts or any other external font provider; in particular, your IP address is not transmitted to third parties for this purpose.
Contacting us
When you use our contact form, the details you enter (name, company, email address, phone number and the content of your message) together with your IP address are transmitted to our server to process your enquiry. The technical intake is handled by a Cloudflare Worker operated by us; the subsequent delivery to our mailbox is carried out via the service “Resend” (see below). The same applies when you reach out to us via another form on our website – for example when you optionally request your result in our interactive maturity check (in that case your name, email address, company and your test result are transmitted). If you contact us directly by email instead, we likewise process the submitted data solely to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (handling enquiries). The data is deleted as soon as it is no longer required for the purpose and no statutory retention obligations apply.
Appointment booking (Microsoft Bookings)
The “Pick a slot” button on our contact page takes you to our booking page at Microsoft Bookings (part of our Microsoft 365 workplace; provider: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). The booking page opens in a new window directly at Microsoft – no Microsoft services are loaded on our website itself.
When you book, we process the details you provide (name, email address, phone number if given, and your notes) as well as the selected slot in order to arrange, hold and follow up on the meeting. The data is stored in our Microsoft 365 tenant; Microsoft processes it on our behalf (Art. 28 GDPR, Microsoft Product Terms/DPA). Insofar as data is transferred to the USA, this is done on the basis of the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. The legal basis for the processing is Art. 6(1)(b) GDPR (pre-contractual measures at your request). We delete appointment data once it is no longer required for this purpose and no statutory retention obligations apply.
Newsletter
You can subscribe to our newsletter via the form in the page footer. Only your email address and the language you selected (German or English) are processed, so that you receive the newsletter in the appropriate language version. Signup uses a double-opt-in procedure: after submitting, you receive a confirmation email with a link valid for 48 hours; your address is only added to our recipient list once you click that link – nothing is stored before that. The legal basis is your consent (Art. 6(1)(a) GDPR).
Performance measurement: Our newsletter emails may include a measurement of whether an email was opened and which links were clicked (tracking pixel or measurement links of the delivery service Resend). We use this information exclusively in aggregated form to assess the relevance of our content; it is not shared with third parties and no advertising profiles are created. The performance measurement is part of the newsletter processing covered by your consent (Art. 6(1)(a) GDPR); when you unsubscribe from the newsletter, the measurement ends as well.
We use the service “Resend” to manage the recipient list and to send the confirmation and newsletter emails (see the “Email delivery” section); the form is protected against automated signups by “Cloudflare Turnstile” (see the “Spam protection” section). You can withdraw your consent at any time with effect for the future – via the unsubscribe link in every newsletter or informally to kontakt@valexcon.de. After withdrawal, your address is removed from the recipient list.
Checklist download
On some pages you can request specialist content (e.g. the “PLM data migration checklist”) as a PDF. To do so, we send the download link to the email address you provide (delivery via “Resend”, see the “Email delivery” section; form protection via “Cloudflare Turnstile”, see the “Spam protection” section). We use your address solely for this delivery and do not store it beyond that. The legal basis is the fulfilment of your request (Art. 6(1)(b) GDPR). If you additionally tick the newsletter signup, the double-opt-in procedure described in the “Newsletter” section applies.
Applications
When you apply via our application form, we process the details you provide (in particular your name, email address, any phone number and location, your message and – if provided – availability and salary expectation) and the documents you upload (e.g. CV, cover letter, references) solely for the purpose of conducting the application procedure and deciding on the establishment of an employment relationship.
The legal basis is Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG (initiation of an employment relationship). Insofar as you voluntarily transmit special categories of personal data (e.g. information on health, disability, religious or philosophical beliefs), the processing is based on the consent you give by transmitting them (Art. 9(2)(a) GDPR). Please only provide such information if it is genuinely necessary for your application.
Storage of documents: Your uploaded documents are stored encrypted in a private object store (Cloudflare R2) within Cloudflare’s infrastructure and are accessible only to a narrowly limited group of authorised persons via an access-protected sign-in (Cloudflare Access). Your documents are not sent as email attachments; the internal notification about your application contains only your structured details and an access-protected reference to the documents. We use the service “Resend” for this notification (see below). To protect against automated access (bots), we use “Cloudflare Turnstile” (see below).
Retention period: If no employment relationship is established, we delete your application data and documents no later than six months after the end of the application procedure, unless statutory retention obligations or the establishment, exercise or defence of legal claims (e.g. under the German General Equal Treatment Act, AGG) require otherwise. The files held in the object store are additionally deleted automatically after no more than 180 days. If you would also like to be included in our talent pool, we store your application – only with your explicit consent (Art. 6(1)(a) GDPR) – for up to twelve months in order to contact you about suitable positions. You can withdraw this consent at any time with effect for the future (informally to bewerbung@valexcon.de).
Providing the data is voluntary; however, without the information required for processing we cannot handle your application. No automated decision-making takes place.
Spam protection – Cloudflare Turnstile
To protect our forms (contact, application, newsletter signup) against automated access and abuse (bots, spam), we use “Cloudflare Turnstile”, a service provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Turnstile uses technical characteristics of your browser and your interaction with the page to determine whether the input originates from a human. In doing so, technical information such as your IP address and details about your browser, device and interaction may be processed. Turnstile does not set cookies for this purpose and does not serve advertising or cross-device tracking. The legal basis is our legitimate interest in preventing abuse and securing our systems (Art. 6(1)(f) GDPR).
Email delivery – Resend
For the technical delivery of the notification and confirmation emails triggered by our forms (contact, application, newsletter), for sending our newsletter and for managing the newsletter recipient list, we use the service “Resend” (provider: Plus Five Five, Inc. d/b/a Resend, 2261 Market Street #5039, San Francisco, CA 94114, USA). The data required for delivery (in particular the details you entered in the form as well as sender and recipient information) is transmitted to Resend and processed on our behalf. A data processing agreement (Art. 28 GDPR) is in place with Resend. Insofar as data is transferred to the USA, this is done on the basis of the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(f) GDPR (reliable delivery of your enquiry) or Art. 6(1)(b) GDPR.
Cookies, local storage and consent
We only use technologies that are strictly necessary to operate the website. Non-essential cookies or comparable technologies (e.g. for statistics or marketing) are only used with your explicit consent in accordance with Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
Strictly necessary (no consent required, Section 25(2) TDDDG): To store your privacy choice, we place an entry in your browser’s local storage (key vx-consent). This means we do not have to ask you again on every visit. In addition – likewise only locally in your browser and only if you use the respective feature – we store your manual language choice (key vx-lang) and your decision to hide the VALI assistant or dismiss its hint (keys vx-vali, vx-vali-hint) and your most recent queries in the site search (key vx-recent-searches, see the “Site search” section). These entries contain only the respective selection or input and, where applicable, a timestamp and are not transmitted to us or any third party.
Statistics / marketing & external media: Beyond the cookieless reach measurement described above (based on legitimate interest, without storing your IP address), we do not use any consent-requiring statistics or marketing technologies. Should we integrate such services in the future, they will only be loaded after you have given your consent via our consent banner.
Withdrawal: You can withdraw or adjust any consent given at any time with effect for the future – via the “Cookie settings” link in the footer.
Storage & retention
Data is retained for as long as necessary to provide the services, fulfil legal and contractual obligations and resolve disputes.
Data security
Data is stored on secured servers behind a firewall with HTTPS access. However, absolute protection cannot be guaranteed. Please use secure passwords and do not transmit confidential information via email or instant messaging.
Your rights (EU)
- Withdraw consent you have given
- Obtain information about processing and access to your data
- Data portability (structured format)
- Rectification of inaccurate data
- Erasure of your data
- Object to processing and request restriction of processing
- Lodge a complaint with a supervisory authority
Right to object (Art. 21 GDPR): Insofar as we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to the processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Send your objection informally to kontakt@valexcon.de.
Competent supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht
Promenade 18, 91522 Ansbach, Germany
Phone: +49 981 180093 0 · Email: poststelle@lda.bayern.de
www.lda.bayern.de
International data transfer
A transfer of personal data to a third country (USA) takes place in the context of hosting by Cloudflare and – when you use our forms (contact, application, newsletter) – through Cloudflare Turnstile and the email delivery service Resend (see above). For such transfers outside the EEA, we ensure an adequate level of protection through appropriate safeguards (in particular the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework).
Changes to this policy
This privacy policy may be revised; the version published on the website is always the current one.
Last updated: 13 July 2026