Privacy Policy
1. Privacy at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on data protection can be found in our privacy policy listed below this text.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by Alendris GmbH as the website operator. You can find the full contact details in the section "Controller" of this privacy policy as well as in our imprint.
How do we collect your data?
Your data is collected, on the one hand, by you providing it to us, e.g. when you send us an email or apply for a position. Other data is collected automatically or with your consent when you visit the website through our IT systems. This is mainly technical data (e.g. internet browser, operating system, IP address, time of page access). The collection of this data takes place automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the website is provided without errors and to guarantee its secure operation. Other data may be used – only after your express consent via our cookie banner – to analyse your user behaviour. No reach measurement takes place without your consent.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
2. Controller and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations (in particular GDPR, BDSG and TDDDG) as well as this privacy policy.
When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
Controller
The controller responsible for data processing on this website within the meaning of the GDPR is:
Alendris GmbH
Pilsener Straße 7
86199 Augsburg
Phone: +49 821 999686-0
E-Mail: info@alendris.de
Internet: www.alendris.de
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Data Protection Officer
We have not appointed a Data Protection Officer. An obligation to appoint one under Art. 37 (1) GDPR applies to public authorities and where a controller's core activities consist of regular and systematic monitoring of data subjects on a large scale or of large-scale processing of special categories of personal data – none of which applies to us. Under § 38 (1) BDSG, an obligation additionally arises as soon as, as a rule, at least 20 people are constantly engaged in the automated processing of personal data; we keep this criterion under continuous review and will appoint a Data Protection Officer as soon as the threshold is reached – their contact details would then be published here. For all questions concerning data protection, the exercise of your rights as a data subject or data protection incidents, please contact the controller named above directly or write to info@alendris.de.
Recipients of your data
Within our company, only those individuals who need it in order to handle your request have access to your data. Beyond that, we pass data on to the service providers named in this policy, who act for us as processors pursuant to Art. 28 GDPR: Cloudflare (hosting and delivery), Microsoft (email processing), Usercentrics/Cookiebot (consent management) and – only with your consent – Google (reach measurement). Further recipients are involved only where we are legally obliged to do so, for example towards tax authorities in the case of business correspondence subject to retention requirements, or where this is necessary for the establishment, exercise or defence of legal claims, for example towards lawyers or courts. Your data is neither sold nor passed on to third parties for advertising purposes.
General storage period
Unless a more specific storage period has been mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you make a legitimate request for deletion or revoke consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing it (in particular commercial and tax retention obligations of 6 or 10 years under §§ 147 AO, 257 HGB).
Obligation to provide your data
Providing personal data is neither legally nor contractually required in order to use this website. You are under no obligation to give us any data: this website has no contact form, no login and no user account. Only the technically necessary connection data – in particular your IP address – is unavoidably generated with every page request and cannot be avoided technically, because otherwise the page cannot be delivered to your device. If you contact us by email or telephone, or apply for a position with us, we need the information you provide in order to deal with your request; without it we cannot answer your enquiry or application, or can do so only to a limited extent. No further disadvantages arise for you from not providing data.
3. Your rights as a data subject
You have the following rights against us at any time with regard to the personal data concerning you:
Right to withdraw consent (Art. 7 (3) GDPR)
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time for the future. The lawfulness of data processing carried out until revocation remains unaffected. For consents relating to cookies/tracking, please use the "Cookie settings" link in the footer or adjust your consent directly via the Cookiebot banner.
Right to object to processing based on legitimate interests (Art. 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR. On this website this concerns in particular the processing of server log files, the application logs, the security reports sent by your browser, and the handling of enquiries that do not serve the initiation of a contract. This also applies to profiling based on these provisions. An informal message to info@alendris.de is sufficient to object. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Right to lodge a complaint with a supervisory authority
In the event of infringements of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany (postal address: Postfach 1349, 91504 Ansbach), phone +49 981 180093-0, email poststelle@lda.bayern.de, https://www.lda.bayern.de. You can also lodge a complaint there using the online form at https://www.lda.bayern.de/de/beschwerde.html. This right to complain exists without prejudice to any other administrative or judicial remedy.
Right to data portability (Art. 20 GDPR)
You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
Access, rectification and erasure (Art. 15, 16, 17 GDPR)
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient and the purpose of data processing and, if necessary, a right to rectification of inaccurate data or erasure of this data. You can contact us at any time for this and for further questions on the subject of personal data.
Right to restriction of processing (Art. 18 GDPR)
You have the right to request the restriction of the processing of your personal data if you contest the accuracy of the data, the processing is unlawful, we no longer need the data, or you have objected. You can contact us at any time for this.
4. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, such as inquiries that you send to us as the site operator, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties. The encryption is provided via our CDN provider Cloudflare (see section "Hosting and content delivery").
5. Hosting, server log files and logging
For the operation of this website we use infrastructure and services from several providers. Below you will find a transparent list of all service providers involved that may come into contact with the processing of your data.
Domain registration (IONOS)
The domain alendris.de is registered with IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. Within the scope of domain administration, master data of Alendris GmbH (e.g. registrant information) is processed. IONOS does not process any personal data of our website visitors within the scope of the domain registration.
IONOS processes the data exclusively within the European Union. A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with IONOS.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in operating our own domain and a professional online presence).
Hosting and Content Delivery Network (Cloudflare)
This website is delivered via Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA ("Cloudflare"). Cloudflare acts as a Content Delivery Network (CDN) and hosting platform (via Cloudflare Workers). In addition, Cloudflare provides security, TLS termination, bot and DDoS protection functions.
When you visit our website, all requests are routed through Cloudflare's infrastructure. In doing so, technically necessary connection data is processed, in particular IP address, date and time of access, HTTP method and URL accessed, referrer URL, browser used (user agent), operating system, language settings and the amount of data transferred. This data is required to enable the delivery of the website and to protect it from attacks.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the secure, fast and efficient provision of our website as well as in the defence against attacks).
Data transfer to third countries: Cloudflare also processes data in the USA. An adequacy decision of the European Commission of 10 July 2023 exists for the USA (EU-US Data Privacy Framework, DPF). Cloudflare is certified under the EU-US Data Privacy Framework. For transfers to other third countries, EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) serve as an additional basis.
Data processing: A data processing agreement pursuant to Art. 28 GDPR has been concluded with Cloudflare.
Further information can be found in the Cloudflare privacy policy.
Server log files
Each time our website is accessed, our infrastructure provider Cloudflare automatically processes connection data in so-called server log files. This includes: the IP address, the date and time of access, the address requested, the HTTP method and response status, the amount of data transferred, browser type and version, operating system and the referrer URL. We do not truncate the IP address.
The IP address is personal data; in principle the information can be attributed to a person with the help of third parties. We do not, however, combine this data with other sources and we do not evaluate it on a person-related basis. The log files are held by Cloudflare and are not available to us in raw form; Cloudflare deletes them in line with its own platform-side retention periods. The logs we initiate ourselves, and their deletion periods, are described in the following section. Cloudflare may additionally instruct your browser to pre-load subpages of our website in order to shorten loading times; log entries may therefore also be created for pages you did not open yourself.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the technically error-free presentation, optimisation and security of our website).
Application logs (Cloudflare Workers Logs)
This website runs as an application on the Cloudflare Workers platform. Cloudflare's logging function ("Workers Logs") is enabled for this application. Every page request generates a log entry containing the address requested, the HTTP method, the response status, the time of access and technical metadata about the request. In addition, error messages and sampled diagnostic output from our application are logged.
We use these logs solely for troubleshooting, for monitoring availability and for investigating security-relevant incidents. We do not analyse the behaviour of individual visitors and we do not combine this data with other sources.
Storage period: Cloudflare deletes the entries automatically once the platform-side retention period expires; this is currently three days on the free plans and seven days on the paid plans. We do not store the data beyond that.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the stable, error-free and secure operation of our website). Cloudflare processes this data as a processor pursuant to Art. 28 GDPR.
Security reports from your browser (Content Security Policy)
Our website sends your browser a security policy (Content Security Policy) that defines which content may be loaded and prevents third-party content from being loaded. If a resource violates this policy, your browser automatically sends a technical report to our own address alendris.de/api/csp-report. Such a report contains the address of the page accessed, the referring page where applicable, the blocked address and the policy that was violated; if these addresses contain parameters, they are transmitted as well. Form input cannot be included, as this website does not offer any forms. For technical reasons your IP address is transmitted along with the report. We instruct your browser to keep this reporting address for up to 126 days.
The endpoint does not store reports permanently. Incoming reports are limited to 16 kilobytes; larger reports are rejected without being processed. In production we write only around five per cent of incoming reports to our application logs as a sample, truncated to the first 2,000 characters (see above); they are deleted there automatically once the period stated in that section expires. The data is not merged with other data sources and is not analysed by individual person. These reports are sent by your browser; no cookies are set and no information is read from your device in the process.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is to detect attacks on the integrity of our website – in particular the injection of foreign scripts – at an early stage and to correct misconfigurations.
Network error reports (Network Error Logging)
Cloudflare additionally enables what is known as Network Error Logging for this website. Your browser is thereby instructed to report connection and network errors – for example dropped connections, DNS or TLS errors – to the address a.nel.cloudflare.com. Such a report contains the address affected, the type of error, the time and technical connection data including your IP address. Successful requests are not reported. Your browser stores this reporting setting for seven days. The sole recipient is Cloudflare, acting as our processor pursuant to Art. 28 GDPR.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in detecting and remedying delivery faults). For storing the reporting setting on your device we rely on § 25 (2) No. 2 TDDDG, since it serves solely the fault-free provision of the service you requested and contains no identifier that would make you recognisable.
6. Communication and contact
Inquiries by email and telephone
If you contact us by email (e.g. at info@alendris.de) or by telephone, your inquiry including all resulting personal data (in particular name, email address, telephone number, content of the inquiry) will be stored and processed by us for the purpose of processing your concern.
This website itself currently does not include its own online contact form. Contact is made exclusively via the displayed email addresses and telephone numbers.
Legal basis: Art. 6 (1) (b) GDPR if your inquiry is related to the fulfilment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR), if you have given it.
Storage period: We store your inquiry until the purpose for data storage no longer applies (e.g. after completed processing) or you request us to delete it. Mandatory statutory retention obligations – in particular the commercial and tax retention periods of 6 or 10 years (§§ 147 AO, 257 HGB) – remain unaffected.
Email processing via Microsoft 365 / Exchange Online
For the receipt, sending and administration of our business emails we use Microsoft 365 / Exchange Online from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. When you send us an email (e.g. to info@alendris.de or karriere@alendris.de), content, metadata (sender, recipient, timestamp, subject) and any attachments are processed and stored in Microsoft's cloud infrastructure.
A data processing agreement (Microsoft Products and Services Data Protection Addendum, DPA) pursuant to Art. 28 GDPR has been concluded with Microsoft Ireland Operations Limited. Microsoft uses a combination of data centres in the EU ("EU Data Boundary") and infrastructure in the USA.
Data transfer to third countries: Despite the EU Data Boundary, data may be transferred to Microsoft Corporation in the USA. Microsoft Corporation is certified under the EU-US Data Privacy Framework. In addition, EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) are agreed as a basis for third-country transfers.
Applications (careers page)
On our careers page we offer you the opportunity to apply for advertised positions via email (karriere@alendris.de). In doing so, we process the application documents and data you provide, in particular: name, contact details, cover letter, CV, certificates, qualifications, previous activities and other information you voluntarily provide.
The processing of your applicant data takes place for the purpose of conducting the application procedure and deciding on the establishment of an employment relationship. Email sending and receipt takes place via Microsoft 365 / Exchange Online (see above).
Legal basis: § 26 (1) BDSG in conjunction with Art. 88 GDPR (data processing for the purposes of the employment relationship), Art. 6 (1) (b) GDPR (initiation of an employment contract) and – insofar as you voluntarily provide further information – Art. 6 (1) (a) GDPR (consent). For special categories of personal data (e.g. health data, severe disability), Art. 9 (2) (b) GDPR additionally applies.
Storage period: If no employment relationship is established, your application documents will be deleted at the latest 6 months after completion of the application procedure, in order to be able to comply with any statutory evidence obligations (in particular from the AGG). Longer storage only takes place with your express consent (e.g. inclusion in our talent pool) or if we are legally obliged to keep the data longer. In case of successful hiring, the application documents will be transferred to the personnel file.
8. Analytics and third-party tools
We use the following analytics and third-party tools. All tools that use cookies or comparable technologies are activated exclusively after your prior consent via our consent banner (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR).
Google Consent Mode v2
For the technical implementation of your cookie consent, we use Google Consent Mode v2. This ensures that all tracking signals (e.g. analytics_storage, ad_storage, ad_user_data, ad_personalization) are set to "denied" by default. Only when you give the corresponding consent in our consent banner are the affected signals set to "granted" and the associated services are allowed to set cookies or transmit data.
Before you give consent, the Google Analytics script is not loaded at all. This means that no connection whatsoever is made to Google servers before your decision, and no cookies are set and no data — including your IP address — is transmitted to Google.
Google Analytics 4 (GA4)
We use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google Analytics 4 uses cookies and similar technologies that enable an analysis of the use of the website. The information generated by the cookie about your use of this website is usually transferred to a Google LLC server and processed there.
Google Analytics 4 truncates IP addresses by default and does not store them permanently; no separate activation by us is required or even possible. The data collected is pseudonymous, not anonymous — it can technically be linked to a device.
Google Analytics is loaded only after you have explicitly consented to statistics cookies via our consent banner. You can withdraw your consent at any time with future effect via the cookie settings.
Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (consent).
Storage period: User and event data is stored by Google for 14 months from the last activity of the user and is then automatically deleted. Aggregated report data (without personal reference) may be retained longer. You can revoke your consent to the setting of the statistics cookies at any time via the "Cookie settings" link in the footer.
Data transfer to third countries: Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023). In addition, EU Standard Contractual Clauses are agreed as the basis for third-country transfers.
Further information can be found in the Google privacy policy.
Fonts (self-hosted)
We use the Plus Jakarta Sans typeface for a consistent display of text. The font files are stored on our own servers and delivered via the Cloudflare CDN; we do not embed Google Fonts or any other external font service. Loading the fonts therefore does not create any connection to Google or any other third party, and no IP addresses or other data are transmitted to third parties.
9. Automated decision-making and profiling
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place on this website. We do not use the data collected via this website for automated individual decisions that would have a legal effect on you or significantly affect you in a similar way.
10. Data transfer to third countries (summary)
In the context of the services described above, data may be transferred to countries outside the European Union and the European Economic Area (in particular to the USA). This particularly affects the services Cloudflare, Microsoft 365 and Google (Analytics).
For data transfers to the USA, an adequacy decision of the European Commission has been in place since 10 July 2023 (EU-US Data Privacy Framework, DPF). All of the US service providers mentioned are certified under the DPF. As an additional safeguard, we have concluded EU Standard Contractual Clauses (SCC) pursuant to Art. 46 (2) (c) GDPR with all relevant service providers. The adequacy decision is the subject of pending proceedings before the Union courts and is kept under continuous review by the European Commission; it remains effective unless and until it is repealed. Should it cease to apply, we will base the affected transfers on the standard contractual clauses referred to above and will amend this privacy policy accordingly.
Despite these safeguards, transfers to the USA carry a residual risk that US security authorities – in particular on the basis of FISA Section 702 and Executive Order 12333 – may access data without data subjects in the EU having effective legal protection against this. We expressly draw your attention to this risk. The transfers relating to hosting and email are not based on your consent, but on the adequacy decision concerning the EU-US Data Privacy Framework and, in addition, on the EU Standard Contractual Clauses. For Google Analytics, your consent under Art. 6 (1) (a) GDPR, given explicitly via our consent banner, is added to this; you may withdraw it at any time with effect for the future, and without that consent not a single item of data is transmitted to Google. We do not infer consent to third-country transfers from your mere use of this website.
We will provide you with a copy of the EU Standard Contractual Clauses agreed with our service providers on request; an informal email to info@alendris.de is sufficient. The contractual documents that apply in each case are also available from the provider directly, for Cloudflare for example at https://www.cloudflare.com/cloudflare-customer-dpa/. In addition, you can view the certifications of the US providers named above under the EU-US Data Privacy Framework at any time in the official list maintained by the US Department of Commerce at https://www.dataprivacyframework.gov/list.
11. Validity and amendment of this privacy policy
This privacy policy is currently valid and has the status shown above. Due to the further development of our website and offers or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version of the privacy policy can be accessed and printed by you at any time at www.alendris.de/datenschutz.
Last updated: July 2026