Courtesy translation

This English version is provided for your convenience only. The legally binding version of this privacy policy is the German one. Read the German version

Legal

Privacy.

GDPR-compliant processing

Controller (Art. 4(7) GDPR)

ecc process GmbH

Pfarrer-Melf-Str. 20, 85669 Pastetten

Phone: +49 172 9653608

Email: datenschutz@group-ecc.com

We are not legally required to appoint a data protection officer (Section 38(1) BDSG). Questions about data protection are answered by the management at the address given above.

General data processing

This website processes personal data solely within the scope of applicable data protection law, in particular the GDPR and the German BDSG. Data is processed to provide the website and in the context of the enquiries and applications you submit to us.

Server logs and abuse protection

When you visit this website, technically necessary data is recorded by our hosting provider Vercel Inc. — IP address, date and time of access, requested resource, status code. Execution and delivery run through the Frankfurt region; Vercel is based in the USA, and the transfer relies on standard contractual clauses under Art. 46 GDPR. The logs are used solely to keep the site operational.

In addition, we store your IP address ourselves when you submit a form: it serves as the key of a rate limiter that prevents the same form from being submitted in bulk within a short time. This record is kept in our own database and is deleted automatically after one hour at the latest — it is not linked to any person and is not used for anything else.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a stable operation protected against abuse.

Retention period: The logs are created by our hosting provider and deleted there automatically, after 30 days at the latest. We delete the rate-limiter entries after no more than one hour. There is no storage beyond this, no analysis for other purposes and no merging with other data.

Analytics & error monitoring

To improve the stability and content of this website we use the following services — all without marketing tracking and without cookies:

  • Umami — cookie-free reach measurement on a self-hosted instance (umami.group-ecc.com). It records the pages viewed, the referrer and coarse browser/device information. No cookies are set, no full IP addresses are stored and no cross-visitor profiles are built; the data resides on a server in Germany that we operate ourselves and is not passed to third parties for analysis. Technically, requests to this instance pass through the network of Cloudflare, Inc. (USA), which as a processor handles IP address and connection data to establish and secure the connection (standard contractual clauses under Art. 46 GDPR).
  • Vercel Analytics — cookie-free, aggregated access statistics from our hosting provider Vercel Inc. (USA, standard contractual clauses under Art. 46 GDPR). Visitors are not recognised across pages or devices.
  • Sentry — technical error monitoring (Functional Software, Inc. dba Sentry, USA, standard contractual clauses). If a technical error occurs on the website, the error message, the affected page and technical browser/runtime information are transmitted. We have configured Sentry to minimise data: IP addresses and user identifiers are not transmitted by default, form and request contents are stripped server-side before sending, performance data is only sampled (10 %); session recordings (replay) do not take place.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in a stable, secure operation and in aggregated, ad-free reach measurement.

Access to your device: These services set no cookies. On every page view, the Umami script reads exactly one value from your browser's local storage — the key umami.disabled, which lets you switch the measurement off yourself. Nothing is written and nothing about you is read out; the access serves solely to respect your own opt-out and is therefore exempt from consent under Section 25(2) no. 2 TDDDG.

How to switch the measurement off: You may object to the processing informally at any time (Art. 21 GDPR) — a message to datenschutz@group-ecc.com is enough. The browser route works immediately and without a message: create the key umami.disabled with the value 1 in this website's local storage. As long as it is set, the measurement sends nothing. Many browsers also offer a “Do Not Track” or tracking-protection setting for this.

Retention period: The measurement data from Umami resides on our own instance and is kept only as long as it is needed to analyse how the website is used. Error reports in Sentry are deleted automatically by the provider after its retention period (90 days by default). For the aggregated statistics of Vercel Analytics the provider's default applies; they contain no individual profiles.

Google Maps (loads on click)

On the contact page we embed a Google Maps map using a two-click solution: when the page loads, only a locally rendered placeholder is shown — no connection to Google is made. Only when you click “Load map” is the map fetched from Google. Data (including your IP address) is then transmitted to Google.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC (USA). A transfer to the USA is possible; it relies on standard contractual clauses under Art. 46 GDPR.

Legal basis: Art. 6(1)(a) GDPR — your consent, which you give by clicking “Load map” (Section 25(1) TDDDG). Without this click no connection to Google is made; the consent applies to the respective page view.

Bot protection for forms (Cloudflare Turnstile)

Our public forms are protected against automated submissions by Cloudflare Turnstile. When a form is opened, your browser loads a script from challenges.cloudflare.com; your IP address and technical characteristics of your browser are transmitted to Cloudflare and evaluated there to distinguish humans from machines. As a rule you will not have to solve a puzzle.

Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. The transfer to the USA relies on standard contractual clauses under Art. 46 GDPR. Turnstile is designed to work without cookies and without cross-visitor profiling.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting our forms and mailboxes against large-scale abuse. Without this protection the forms would be open to automated submissions.

Contact and enquiry forms

Data you submit via the “General enquiry” or “Project enquiry” forms (name, company, email, phone, location, description) is processed to answer your enquiry and — for a project enquiry — to prepare a quotation. The transmission is TLS-encrypted.

What happens to your enquiry:

  • It is sent by email to the responsible mailbox; you receive a confirmation of receipt at the address you provided.
  • It is stored in our internal enquiry inbox so that no enquiry is lost.
  • It is handed over to our internal enquiry and quotation tool, in which we document its handling. We operate this tool ourselves; no other company receives your data through it.
  • We create a contact record for you in our CRM so that further correspondence remains traceable. No duplicate record is created for an email address we already know.
  • For a first-time enquiry, an internal note is created with your contact details and the text of the enquiry so that the responsible team can assess the matter.
  • The text is roughly classified automatically (industry, approximate company size, country, keywords). This is purely a sorting aid — decisions about your enquiry are always made by people.

Legal basis: Art. 6(1)(b) GDPR for answering the enquiry itself (steps prior to entering into a contract). For storage in the enquiry inbox, the CRM record and the rough classification, additionally Art. 6(1)(f) GDPR — our legitimate interest in ensuring that no business enquiry is lost and that the course of a business relationship remains traceable.

Recipients / processors (Art. 28 GDPR):

  • Microsoft Ireland Operations Ltd. — sending the enquiry and confirmation emails via our mailboxes (Microsoft 365 / Exchange Online, EU)
  • Supabase Inc. — database for the enquiry inbox, CRM and internal notes (servers in the EU)
  • Vercel Inc. — hosting and execution of the form processing (Frankfurt region; USA, standard contractual clauses under Art. 46 GDPR)
  • Cloudflare, Inc. — bot protection for the form (USA, standard contractual clauses under Art. 46 GDPR); see the section “Bot protection for forms”
  • Anthropic PBC — automated rough classification of the enquiry text (USA, standard contractual clauses under Art. 46 GDPR; your data is not used to train AI models)

Retention period: We delete the enquiry itself no later than 36 months after receipt. We keep the contact and the note in the CRM until you object or it is established that there is no longer any business interest in working together. Statutory retention periods remain unaffected.

Provision of data: Your name and email address are required so that we can reply to you; without them the enquiry cannot be processed. All other details are voluntary, and leaving them out has no disadvantages. There is no statutory or contractual obligation to provide us with this data.

Business contact & sales outreach (B2B)

In the course of business development we research and contact potential business partners and their contact persons at companies. In doing so we process business contact details — name, professional role, company, business phone number and email address — which we obtain from publicly accessible sources (including company websites, legal notices and industry directories).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in initiating business contacts in a B2B context). For contact by email we additionally observe the requirements of Section 7 UWG (German Act against Unfair Competition). Every entry into our CRM and every approach is manually approved beforehand — no automated sending takes place.

Recipients / processors (Art. 28 GDPR):

  • Anthropic PBC — AI-assisted preparation and drafts (USA, standard contractual clauses under Art. 46 GDPR; your data is not used to train AI models)
  • Microsoft Ireland Operations Ltd. — sending the email communication via our mailboxes (Microsoft 365 / Exchange Online, EU)
  • Supabase Inc. — storage of the contact/campaign data (servers in the EU)

For the research itself we use web search services (Tavily Inc., Serper, Brave Software Inc.). We transmit no personal data to them — searches are made by role, industry and region, not for individuals. They are therefore not processors of your data.

Your right to object: You may object at any time, with effect for the future, to the processing of your data for direct outreach (Art. 21 GDPR). An informal message to datenschutz@group-ecc.com is sufficient; we will then stop the processing and delete your data unless statutory retention obligations prevent this.

Retention period: until you object, or until it is established that there is no business interest in working together.

Applicant data (Art. 13 GDPR · § 26 BDSG)

If you apply via the application form or by email, we process the following personal data for the purpose of the application procedure:

  • Master data (name, email, phone)
  • Address (street, house number, postcode, city)
  • Salutation — voluntary; “not specified” is the default
  • Professional background (LinkedIn, cover letter, availability)
  • Application documents (CV, certificates, further documents)
  • The position and area you are applying for
  • Later in the procedure: our notes and assessments from the interviews and the status of your application
  • A technical check result from the automatic spam detection, which every incoming application receives

Legal basis: Section 26(1) sentence 1 BDSG in conjunction with Art. 6(1)(b) GDPR — the processing is necessary for the decision on establishing an employment relationship. We do not ask for consent for this; the application form merely asks you to take note of the privacy information. If you would additionally like to be included in our applicant pool, this requires your separate consent under Art. 6(1)(a) GDPR, which you may withdraw at any time.

Retention period: If your application is unsuccessful, we delete your application documents no later than six months after the end of the application procedure (allowing for the burden-of-proof period under Section 15 AGG plus a safety margin). If you are hired, we transfer the documents into your personnel file. You may object to the retention at any time — we will then delete them without delay.

Recipients: Your data is viewed only by authorised members of our recruiting team and the management. It is not passed on to third parties, with the exception of the technical processors with whom contracts under Art. 28 GDPR are in place:

  • Supabase Inc. — database, authentication and storage of your uploaded application documents (servers in the EU)
  • Vercel Inc. — hosting of the website and execution of the form processing (Frankfurt region; USA, standard contractual clauses under Art. 46 GDPR)
  • Microsoft Ireland Operations Ltd. — email dispatch (Microsoft 365 / Exchange Online, EU)
  • Cloudflare, Inc. — network services in front of our servers: name resolution, transport encryption and mitigation of denial-of-service attacks as well as the bot protection for our forms (USA, standard contractual clauses)
  • Railway Corp. — operation of our signing service as soon as an offer leads to contract signing (EU, Amsterdam data centre)

Storage location: Your master data, the processing status and your uploaded documents reside in the same database environment within the European Union. The documents are kept there in a non-public area: they cannot be retrieved via any direct address, but only through our authenticated recruiting interface, which logs every access. Transmission is encrypted throughout.

Withdrawing your application, access, deletion: You may withdraw your application at any time without giving reasons and request the deletion of your documents — informally, by email to datenschutz@group-ecc.com. If you have additionally consented to being included in our applicant pool, you may revoke that consent just as informally; the revocation takes effect for the future. On request we will send you an overview of all data stored about your application (Art. 15 GDPR).

Personal invitation links

If you have received a personal invitation from us to maintain a profile with us, separate privacy information applies. It is enclosed with the invitation and permanently available at group-ecc.com/network/datenschutz — even after your link has expired.

Contract signing and offer acceptance

If you accept a quotation or sign a contract via a link we send you, we process, in addition to the contract data, your signature, the time of signing, your IP address and your browser identifier. We store these three technical details because they prove who signed and when — without them the electronic signature would be worthless in a dispute.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR for the evidence data — legitimate interest in being able to prove an electronically submitted declaration. Recipients: Railway Corp. (operation of our signing service, EU/Amsterdam) and Supabase Inc. (database, EU); contracts under Art. 28 GDPR are in place with both. Retention period: for the duration of the contractual relationship and thereafter in line with statutory retention periods (as a rule six or ten years under German commercial and tax law).

Automated decision-making and profiling

An automated individual decision that produces legal effects concerning you or similarly significantly affects you does not take place here (Art. 22 GDPR). Decisions on enquiries, applications and quotations are always made by people.

In two places software assists us with pre-sorting, as follows:

  • Enquiries from the contact forms are roughly classified automatically (industry, approximate company size, country, keywords) so that they reach the right team.
  • Incoming applications pass through automatic spam detection. It may flag a submission as probably automated — no application is discarded because of this; a person reviews the flag.

We do not machine-read your application documents. Your CV, certificates and other documents are neither read by a language model nor automatically searched for content; they are not scored and not matched against job profiles. They are stored in a private location that is not publicly accessible and are opened only by a person. The spam detection mentioned above checks only the text of your cover letter against fixed rules.

In both cases the assessment remains a sorting aid. You may ask us at any time to explain or correct the classification.

Third-country transfers

Some of the processors named above are based in the United States (Vercel Inc., Cloudflare Inc., Anthropic PBC, Functional Software Inc. dba Sentry). Where personal data is transferred to a third country, we rely on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR and have concluded contracts under Art. 28 GDPR with all providers named.

We will provide you with a copy of these safeguards on request. Simply write to datenschutz@group-ecc.com.

Cookies

We use only technically necessary cookies (e.g. the login session of protected areas). These are permitted without consent under Section 25(2) TDDDG. Marketing or tracking cookies (Google Analytics, Meta Pixel etc.) are NOT used. Where we additionally access your browser's local storage, this is described above with the processing concerned — for the reach measurement, for the bot protection and for temporarily saving long forms.

You can bring the cookie notice banner back at any time by removing the localStorage entry “ecc_cookie_consent” for our domain in your browser.

Your rights as a data subject

You have the right at any time to:

  • obtain access to the data stored about you (Art. 15 GDPR)
  • have inaccurate data rectified (Art. 16 GDPR)
  • have your data erased (Art. 17 GDPR)
  • have the processing restricted (Art. 18 GDPR)
  • receive your data in a portable format (Art. 20 GDPR)
  • object to the processing (Art. 21 GDPR)
  • withdraw consent you have given (Art. 7(3) GDPR)
  • lodge a complaint with a supervisory authority — in Bavaria: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach

For an access request under Art. 15 GDPR, or to exercise any of your other rights, simply email us at datenschutz@group-ecc.com. We will handle your request without delay, at the latest within the statutory period of one month.

Data security

Transmission takes place over TLS. Data is stored encrypted, and access to the application system is restricted to a closed group of people via email-based two-factor login.

Last updated: August 2026 · This policy is updated continuously.