ANTEMSYS
SolutionsConsultingCompanyInsights
Start a conversation ↗

LEGAL DATA PROTECTION

Privacy notice.

How AntemSYS handles website access, contact requests, newsletter registration, optional analytics, and account security.

Legal review required before publication

This is a structured compliance draft, not a substitute for individual legal advice. The self-hosted architecture, the server location and the email provider are documented below. The Article 28 GDPR agreement between ANTemsys GmbH and its processor, and qualified German legal review, are still outstanding before publication.

01 Controller02 Access logs03 Analytics04 Forms & news05 Your rights
01

Controller and scope

ANTemsys GmbH
Starenweg 11
84095 Furth
Germany
Privacy contact: info@antemsys.eu

This notice applies to the public AntemSYS website, contact and newsletter forms, and—if introduced—registered user accounts. If a data protection officer is appointed, their verified contact details must be inserted here before publication.

02

Website delivery and security access logs

When a page is requested, our Hetzner server processes the IP address, date and time, requested host and path, request method, response status, transferred volume, referrer, and browser or user-agent. We do not request browser geolocation or precise coordinates.

The purposes are delivery of the requested page, technical stability, error analysis, prevention and investigation of attacks or abuse, and protection of the website and its users. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are secure, reliable operation and defence of legal claims.

Standard server access logs are configured to rotate and be deleted after 14 days. Data linked to a detected security incident may be retained until the incident has been investigated and legal claims are resolved. Complete IP addresses will not be reused for marketing or behavioural profiling.

The form service stores only a keyed pseudonymous hash derived from the IP address for rate limiting and consent evidence, not the complete address. For an anonymous page request, these technical records do not reliably identify the natural person behind the device. We associate activity with a named person only when that person knowingly submits identifying information through a form.

03

Optional analytics and consent

Detailed measurement of page views, navigation paths, interactions, referrers, device category, and approximate region will remain disabled until the visitor gives consent. Where possible, analytics records will use a pseudonymous identifier and will not retain the full IP address after deriving a coarse region.

The legal bases are consent under Article 6(1)(a) GDPR and, for storing or reading information on the device, § 25(1) TDDDG. Refusing analytics has no effect on access to the website. Consent can be withdrawn at any time through “Privacy settings” as easily as it was given.

The selected analytics provider, exact events, cookie or storage names, retention—planned maximum 14 months—and any third-country transfers must be documented here before activation. No analytics script may load before that information and the consent mechanism are complete.

04

Necessary local storage

The website stores the selected language and the privacy decision on the visitor’s device. These values are necessary to provide the explicitly requested language and to remember the privacy choice. They contain no form content. The privacy decision is renewed when the notice or processing purposes materially change.

05

Contact requests

The contact form processes name, business email, company, selected topic, message, language, source page, submission time, and technical delivery metadata. General requests are routed to info@antemsys.eu; product and sales enquiries are routed to sales@antemsys.eu. The data is used only to answer, evaluate, and follow up the request.

The legal basis is Article 6(1)(b) GDPR where the request concerns pre-contractual steps or a contract, and otherwise Article 6(1)(f) GDPR based on our legitimate interest in business communication and documenting requests. Contact data is not added to the newsletter without separate consent.

If no business relationship follows, the request is planned to be deleted 12 months after the last substantive communication. Contractual, tax, accounting, security, and legal-claim records may be retained for the applicable statutory periods.

06

Newsletter registration and double opt-in

Newsletter registration is handled through sales@antemsys.eu and processes the email address, language, consent text and version, registration and confirmation timestamps, source page, and a keyed pseudonymous hash derived from the IP address used for registration and confirmation. A subscription becomes active only after confirmation through double opt-in.

The legal basis is consent under Article 6(1)(a) GDPR and the requirements for electronic advertising under § 7 UWG. Contact requests and newsletter consent are separate. Consent can be withdrawn at any time through the unsubscribe link in each message or by contacting us.

The email address is retained until withdrawal. Suppression information may be kept to ensure no further mail is sent. Consent evidence may be retained for up to three years after withdrawal or the last mailing where necessary to demonstrate compliance or defend legal claims.

07

Account, registration, and login security

If registered accounts or protected customer areas are introduced, we plan to record account email or ID, registration time, confirmation status, login and logout times, failed login attempts, session identifier, IP address or pseudonymised security identifier, user-agent, and coarse country or region where provided by the hosting edge.

The purposes are authentication, account administration, fraud and abuse prevention, detection of unusual access, security audits, and support. The legal bases are Article 6(1)(b) GDPR for providing the account and Article 6(1)(f) GDPR for security. Login history is planned for 90 days and failed-attempt logs for 30 days, unless an incident requires longer retention.

The system must not create hidden cross-site identity profiles or infer precise location. Users must be informed before account tracking becomes active, and the final fields, retention, recipients, and security safeguards must be documented here.

08

Hosting, form, email, and analytics providers

Hosting and content delivery are provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on a server located in Nuremberg, Germany. The server is rented and administered by Lenard Buday, who acts as a processor for ANTemsys GmbH; Hetzner Online GmbH is engaged as a sub-processor. Contact and newsletter form records are processed by AntemSYS on its self-hosted service on the same server. Transactional and newsletter email is relayed by Brevo (Sendinblue SAS), 7 rue de Madrid, 75008 Paris, France, which stores customer data on servers in France, Belgium and Germany. No analytics provider is currently used. Article 28 GDPR processing agreements are required with each processor before email sending is activated.

09

Recipients and international transfers

Access is limited to authorised AntemSYS personnel and contracted processors who need the data for the stated purposes. Data is not sold. Website hosting and email storage take place on servers within the European Union. Our email provider Brevo engages sub-processors that may access data from outside the EEA for support, maintenance and monitoring, in particular in the United States and India. Those transfers rely on the Standard Contractual Clauses of the European Commission with supplementary measures, and on the EU-US Data Privacy Framework where the recipient is certified; the current list of sub-processors forms part of the Brevo data processing agreement. No other transfer outside the EEA takes place.

10

Data minimisation and security

We intend to collect only fields required for each purpose, separate contact, newsletter, security, and analytics records, restrict access by role, encrypt data in transit, maintain backups and deletion routines, and review logs for misuse. Sensitive information should not be submitted through the general contact form.

11

Your rights

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, data portability, and objection. You may withdraw consent at any time without affecting processing carried out before withdrawal. You may object at any time to direct marketing. Requests can be sent to the privacy contact above; we may need to verify identity.

12

Right to complain

You may lodge a complaint with a data protection supervisory authority, particularly in the EU Member State of your habitual residence, workplace, or the place of the alleged infringement. For ANTemsys GmbH as a non-public body in Bavaria, the competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de ↗.

13

Automated decisions and profiling

The website does not currently make decisions producing legal or similarly significant effects solely through automated processing. Optional analytics must not be used for such decisions or undisclosed profiling.

14

Version and changes

Draft version: 30 August 2026. We will update this notice when purposes, providers, legal bases, retention, or technical architecture change materially. A new consent will be requested where legally required.

REF

Official legal and regulatory references

GDPR ↗§ 25 TDDDG ↗§ 7 UWG ↗BayLDA: jurisdiction ↗BayLDA: contact ↗BfDI: Log files ↗Hetzner: data protection and DPA ↗DSK guidance ↗

ANTEMSYS

Practical technology.
Real solutions.

ContactImprintPrivacy
© 2026 ANTemsys GmbHGermany · EuropeEN / DE / HU / AR