Privacy Policy
Last updated: July 2026
1. Controller
Controller responsible for data processing on this website:
Convios GmbH
Bischof-Riegg-Str. 19a
86899 Landsberg am Lech, Germany
Phone: +49 (0) 160 924 512 00
Email: info@convios.com
No data protection officer has been appointed, as the statutory requirements under Art. 37 GDPR are not met.
2. Overview
This website does not embed any advertising networks for ad delivery; however, Google Ads conversion tracking with Consent Mode v2 is used (see the relevant section). Web analytics is provided by a cookieless service that does not store device data and does not create personal profiles. Calendly is used for appointment scheduling: merely visiting a page does not load any Calendly resources and does not establish any connections to Calendly servers. Only when you actively click an appointment CTA is either an external link to calendly.com opened or a Calendly popup widget loaded, depending on the page (see the relevant section).
3. Google Ads Conversion Tracking (gtag.js)
This website embeds the Google tag (gtag.js, conversion ID AW-1009186260) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The integration uses Google Consent Mode v2. All consent-requiring storage and measurement functions (ad_storage, ad_user_data, ad_personalization, analytics_storage as well as functionality_storage and personalization_storage) are set to "denied" by default; only security-related storage (security_storage) is exempt. Conversion measurement and the associated cookies are only activated after explicit consent via the cookie banner (CookieYes, category Advertisement).
The gtag.js script is loaded from Google servers regardless of your consent; for technical reasons your IP address is transmitted to Google in the process. Before consent is given, the Google tag sends only cookieless status signals (consent status, page visited) to Google; no cookies are set and no advertising profiles are created. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in consent-compliant control of the embedded measurement services).
Purpose: Measuring whether visitors perform a defined action after clicking a Google Ads advertisement.
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent).
Third-country transfer: Google Ireland Limited may forward data to Google LLC, USA. This is done on the basis of the EU-U.S. Data Privacy Framework and additionally on the basis of Standard Contractual Clauses pursuant to Art. 46 GDPR.
You may withdraw your consent at any time via the cookie settings.
Google privacy information: https://policies.google.com/privacy
4. Hosting and Content Delivery Network — Cloudflare
This website is delivered via Cloudflare Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare acts as hosting platform and content delivery network (CDN) and protects the website against attacks (DDoS protection).
When the website is accessed, Cloudflare automatically records technical connection data in server log files: IP address, date and time of access, URL called up, HTTP status code, volume of data transferred, referrer URL, as well as browser type and operating system. Cloudflare may set technically necessary cookies (e.g. __cf_bm for bot detection).
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and performant provision of the website. For technically necessary cookies, Section 25(2) no. 2 TDDDG applies.
Third-country transfer: Cloudflare Inc. is certified under the EU-U.S. Data Privacy Framework (DPF). The transfer takes place on the basis of the European Commission's adequacy decision (Art. 45 GDPR) and additionally on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. A Data Processing Addendum (DPA) pursuant to Art. 28 GDPR is in place with Cloudflare.
Cloudflare privacy information: https://www.cloudflare.com/privacypolicy/
5. Pre-Rendering — Prerender.io
This website uses the pre-rendering service of Prerender.io (operated by Prerender LLC, USA) to provide search engines and social media crawlers with pre-rendered HTML versions of the pages. Prerender.io is activated exclusively for automated requests from crawlers (e.g. Googlebot, LinkedInBot). Regular website visitors are not routed through Prerender.io.
As part of the rendering process, Prerender.io receives the URL of the requested page. No personal data of regular visitors is transmitted to Prerender.io.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the findability of the website by search engines and the correct display of link previews in social networks.
Third-country transfer: Prerender LLC is based in the United States. SCCs pursuant to Art. 46(2)(c) GDPR apply.
Prerender privacy information: https://prerender.io/privacy-and-terms/
6. Web Analytics — Plausible Analytics
This website uses Plausible Analytics, provided by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia.
Plausible works without cookies, without local storage and without fingerprinting. Only aggregated statistics are recorded: pages visited, country of origin (from a truncated IP address), referrer URL, device category and browser type. The IP address is not stored; it is only used to calculate a daily-rotating, anonymised hash that can no longer be reconstructed after 24 hours. No personal profiles are created.
Data is processed exclusively on servers located in Germany (Hetzner, Falkenstein). No transfer to third countries takes place.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the analysis of website usage to improve our offering. Since Plausible does not access end devices and does not store any information on them, Section 25 TDDDG does not apply.
A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Plausible Insights OÜ.
Objection: As Plausible only collects anonymised, aggregated data, an individual technical opt-out is not possible. Anyone who also wishes to prevent this aggregated collection can use the browser extension "Plausible Analytics Opt Out".
Plausible privacy information: https://plausible.io/data-policy
7. Appointment Scheduling — Calendly
To arrange meetings, Calendly, provided by Calendly LLC, 3423 Piedmont Road NE, Atlanta, GA 30305, USA, is offered on all pages of this website. When a page is merely accessed, no Calendly resources are loaded, no connections to Calendly servers are established, and no cookies are set.
Appointment links on this website (e.g. home page, footer, author page) point directly to calendly.com; a click opens the external platform in a new tab. As soon as you follow this link, you leave this website; further processing of your booking data (name, email address, requested time and any messages you enter) is subject to Calendly's privacy policy. This website only receives a notification of the booked appointment.
On individual service pages, the appointment CTA opens a Calendly popup widget within this website. Only with this active click are the widget script and stylesheet (widget.js, widget.css) loaded from assets.calendly.com; for technical reasons this establishes a connection to Calendly servers in the USA and transmits your IP address to Calendly. Only once the widget is loaded can Calendly set cookies on your device. Subsequent processing of your booking data is then subject to Calendly's privacy policy.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) for processing booking data after an appointment has been made. For loading the widget after an active click and the associated transmission to Calendly: Art. 6(1)(f) GDPR (legitimate interest in a seamless appointment booking without leaving the website).
Third-country transfer: Calendly LLC is certified under the EU-U.S. Data Privacy Framework (DPF, participant ID #6050). Additionally, Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR apply as part of Calendly's terms of use. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Calendly LLC.
Calendly privacy information: https://calendly.com/legal/privacy-notice
8. Content Management — Sanity
The content of this website is provided via Sanity AS, Tordenskjolds gate 2, 0160 Oslo, Norway. Sanity is queried server-side during the build process and on dynamic page requests (e.g. article pages). Media files (images, documents) are delivered via the Sanity CDN (cdn.sanity.io); your IP address is transmitted to the CDN when the file is retrieved.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the efficient provision of website content.
Sanity AS is based in Norway (EEA); no third-country transfer takes place with European CDN delivery. For the U.S. infrastructure (Google Cloud), DPF certification and SCCs pursuant to Art. 46 GDPR apply. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Sanity.
Sanity privacy information: https://www.sanity.io/legal/privacy
9. Consent Management — CookieYes
This website uses CookieYes, provided by CookieYes Limited, 3 Warren Yard, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom.
CookieYes sets a technically necessary cookie (cookieyes-consent) that stores your consent decision. This cookie is set without prior consent because it is technically required to store and enforce your preference (Section 25(2) no. 2 TDDDG). Data stored: consent status, timestamp, anonymised IP address. Retention period: 1 year.
Legal basis: Art. 6(1)(c) GDPR (legal obligation to demonstrate consent) and Art. 6(1)(f) GDPR.
The United Kingdom benefits from an adequacy decision of the European Commission (June 2021). A DPA pursuant to Art. 28 GDPR is in place with CookieYes.
CookieYes privacy information: https://www.cookieyes.com/privacy-policy/
10. Social Media Sharing Functions
On our article pages, we offer buttons for sharing content via LinkedIn, X (Twitter), WhatsApp and email. When a page is accessed, these buttons do not load any external scripts and do not transmit any data to third parties. Only when you actively click on a button does the respective platform open in a new browser window. The privacy provisions of the respective provider then apply.
The "Copy link" function only saves the article URL to your local clipboard, without sending any data to external servers. The "Share" function uses your browser's Web Share API and transmits data only to the app of your choice on your device.
Legal basis: Since no data is transmitted to third parties when the page is accessed, data processing only takes place through your active action on the respective platform and is subject to its privacy provisions.
11. Article Feedback
We offer a feedback function on article pages. When you click on a rating button, the following data is transmitted to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland: article identifier, rating (positive or negative), timestamp and page URL. No personal data such as name, email address or IP address is collected or transmitted by us.
Your rating decision is stored locally in your browser (localStorage) to prevent multiple ratings of the same article. This data is stored exclusively locally and is not transmitted to any server.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in improving content quality.
Third-country transfer: Google Ireland Limited may forward data to Google LLC, USA. DPF certification and SCCs pursuant to Art. 46 GDPR apply.
12. Contact by Email
If you contact us by email, the data transmitted (email address, content of the message and, where provided, name and telephone number) will be stored to process your request. No transfer to third parties takes place without your consent.
Legal basis: Art. 6(1)(f) GDPR for general enquiries; Art. 6(1)(b) GDPR for enquiries aimed at initiating a contract.
Retention period: The data will be deleted as soon as it is no longer required for processing, at the latest upon expiry of statutory retention periods.
13. Your Rights as a Data Subject
You have the following rights vis-à-vis the controller:
Access (Art. 15 GDPR): You may request information as to whether and which personal data is processed, for what purposes, from which sources and to whom it is disclosed.
Rectification (Art. 16 GDPR): You may request the correction of inaccurate data and the completion of incomplete data.
Erasure (Art. 17 GDPR): You may request the erasure of your data if it is no longer required for the purpose of processing, if you have withdrawn your consent, or if processing is unlawful. Exceptions apply to statutory retention obligations.
Restriction (Art. 18 GDPR): You may request that your data only be stored and no longer further processed.
Data portability (Art. 20 GDPR): If processing is based on consent or contract and takes place in an automated manner, you have the right to receive your data in a machine-readable format or to have it transferred to another controller.
Withdrawal of consent (Art. 7(3) GDPR): Insofar as processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out until then remains unaffected.
You may withdraw your consent to Google Ads conversion tracking at any time via the cookie settings.
Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de.
Automated decisions (Art. 22 GDPR): No automated decision-making, including profiling, takes place that produces legal effects concerning you or similarly significantly affects you.
To exercise your rights, please contact: info@convios.com
14. Right to Object (Art. 21 GDPR)
Insofar as personal data on this website is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object to this processing at any time on grounds relating to your particular situation. This concerns the processing by Cloudflare (hosting, CDN, server log files), Plausible Analytics (web analytics) and article feedback. Please direct your objection to: info@convios.com. Processing of the data concerned will then cease, unless there are compelling legitimate grounds for the processing that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
15. Data Security
This website only transmits data in encrypted form (TLS/HTTPS). The controller takes technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access.
16. Currency and Changes
This privacy policy was last updated in July 2026. In the event of material changes to the services used or to data processing procedures, the policy will be updated accordingly. The currently valid version can be accessed at https://www.convios.com/en/privacy-policy.