Skip to content
Phone: +49 (0) 4101 805 0028
VISIONTECHNIK0

Privacy policy

As of: August 2026

This English version is provided for convenience only. In case of any discrepancy, the German version shall prevail.

Protecting your personal and business data matters to us. In this privacy policy we explain which personal data we process when you use our website, when you contact us, when you send product, project or consulting inquiries and in the course of our business relationships, for which purposes this happens and which rights you have.

Our offering is generally aimed at companies. Even in a B2B context, however, personal data may be processed - for example the names, business email addresses or telephone numbers of contact persons.

1.Controller

The controller for the processing of personal data is:

GK VISION GmbH - VISIONTECHNIK

Eggerstedter Weg 18

25421 Pinneberg

Germany

Managing director: Karen Gyurjinyan

Phone: +49 (0) 4101 805 0028

Email: info@visiontechnik.de

Below we also refer to ourselves as “VISIONTECHNIK”, “we” or “us”.

2.General information on data processing

We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG) and other applicable data protection provisions.

Personal data is information relating to an identified or identifiable natural person.

In a business context this can include in particular:

  • name and contact details of a contact person
  • business email address and telephone number
  • position or department
  • the content of business communication
  • information about inquiries, quotations, orders, projects or service cases, where it can be attributed to a natural person

We process personal data in particular to provide and secure our website, for statistical analysis after consent has been given, to handle product, project, consulting and service inquiries, to prepare quotations, to perform contracts, to deliver goods, to provide services, for invoicing, for business communication and to fulfil legal obligations.

3.Hosting and provision of the website

Our website is hosted by the following provider:

IONOS SE

Elgendorfer Straße 57

56410 Montabaur

Germany

When you access our website, your browser transmits technically necessary information to our web server.

The following data in particular may be processed:

  • IP address
  • date and time of access
  • page or file accessed
  • volume of data transferred
  • HTTP status code
  • referrer URL
  • browser type and version
  • operating system
  • language settings
  • technical device information

The processing serves in particular to provide our website technically, ensure it functions, detect technical faults and protect our systems against abusive access, attacks and other security incidents.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website securely, stably and economically.

Server log data is generally deleted after 14 days. It may be stored for longer where there are concrete indications of a security incident, abusive access or unlawful use and the data is required to investigate or pursue legal claims.

Where IONOS processes personal data on our behalf, this is done on the basis of a data processing agreement in accordance with Art. 28 GDPR.

4.Encrypted data transmission

Our website uses TLS/SSL encryption.

This protects data transmitted between your browser and our website against unauthorized access while in transit.

You can recognize an encrypted connection in particular by “https://” in your browser's address bar.

Despite appropriate security measures, completely risk-free data transmission over the internet cannot be guaranteed.

5.Cookies, local storage and similar technologies

Our website may use cookies, local storage, session storage and comparable technologies.

In doing so, information may be stored on your device or information already stored may be read.

We distinguish between technically necessary technologies and optional technologies that require consent.

6.Technically necessary technologies

Technically necessary technologies may be used in particular for:

  • providing the website and making it work
  • the inquiry list
  • storing selected products and quantities
  • assigning an ongoing session
  • language settings
  • form functions
  • security mechanisms
  • spam and abuse protection
  • storing your privacy settings

Where storing or accessing information on your device is strictly necessary to provide a digital service you have expressly requested, this is done on the basis of section 25(2) TDDDG.

Where personal data is subsequently processed, the legal basis depends on the respective purpose and may in particular be Art. 6(1)(b), (c) or (f) GDPR.

Technically necessary information is only stored for as long as it is required for the respective function.

7.Consent management and privacy settings

We provide a way to manage your privacy settings on our website.

There you can decide whether, in addition to technically necessary technologies, analytics or other technologies requiring consent may be used.

In connection with your choice, the following information in particular may be processed:

  • the time of your choice
  • the consent categories selected
  • technical consent identifier
  • version of the underlying privacy settings
  • technical evidence information where applicable

This processing serves to implement your choice technically and to demonstrate that consent was given or refused.

You can change your choice at any time via the “Cookie settings” link available on our website.

Consent once given may be withdrawn at any time with effect for the future.

8.Analysis and statistical evaluation of our website

With your prior consent we use analytics and statistics technologies to understand how our website is used.

This allows us to establish, for example:

  • which pages and product categories are visited frequently
  • which products are viewed particularly often
  • which manufacturers or product groups are of interest
  • which product filters are used
  • which internal search functions are used
  • how visitors navigate through our website
  • which products are added to the inquiry list
  • at which points an inquiry process is started
  • which steps of a form are reached
  • at which points users abandon an inquiry process
  • which consulting or knowledge content is used
  • through which sources visitors reach our website
  • which device types and browsers are used

We use these insights in particular to improve our navigation, our product filters, our product presentation, our content, our forms and our inquiry process.

Storing or accessing information on your device is based on your consent under section 25(1) TDDDG.

The subsequent processing of personal data is based on your consent under Art. 6(1)(a) GDPR.

Consent is voluntary. If you do not consent to analytics technologies, you can still use the essential functions of our website and in particular our product and inquiry functions.

9.Google Analytics 4

If you have consented to the use of analytics and statistics technologies, we use Google Analytics 4.

The provider in the European Economic Area is:

Google Ireland Limited

Gordon House

Barrow Street

Dublin 4

Ireland

Google Analytics allows us to evaluate the use of our website statistically.

Depending on the technical configuration, the following information in particular may be processed:

  • pages visited
  • product pages accessed
  • product categories
  • filters used
  • internal searches
  • interactions with page elements
  • adding products to the inquiry list
  • removing products from the inquiry list
  • opening the inquiry list
  • starting an inquiry process
  • steps reached within a form
  • completing an inquiry process
  • time and duration of sessions
  • approximate geographical region
  • browser
  • operating system
  • device type
  • screen size
  • origin of a website visit
  • technical events
  • pseudonymous usage and session identifiers

We use Google Analytics in particular to understand which information and products are relevant to our visitors and where our website or our inquiry processes can be improved.

No transfer of customer and project content to Google Analytics

Our analytics is technically separated from our customer, contact and project data.

In particular, the following are not deliberately transferred to Google Analytics:

  • names
  • email addresses
  • telephone numbers
  • postal addresses
  • the content of contact inquiries
  • the content of free-text fields
  • specific technical project descriptions
  • customer documents
  • drawings
  • uploaded images or videos
  • quotation documents
  • confidential technical information

For forms we only analyze technical events such as:

  • “form started”
  • “step 3 reached”
  • “form abandoned”
  • “inquiry successfully submitted”

We do not use the content entered into forms for content analysis via Google Analytics.

Google states that individual IP addresses of users in the EU are not logged or stored in Google Analytics. The IP address may be processed briefly to derive an approximate geographical region and is then discarded.

Use takes place exclusively after your prior consent.

The legal bases are section 25(1) TDDDG and Art. 6(1)(a) GDPR.

You can withdraw your consent at any time via our privacy settings.

Data retention in Google Analytics

We generally configure the retention period for user and event data in Google Analytics to 14 months.

Aggregated statistical reports may remain available for longer independently of this, without individual website visitors being readily identifiable from them.

We currently use Google Analytics exclusively for analysis and optimization purposes.

We generally do not activate Google Signals or the use of Analytics data for personalized advertising for as long as we do not provide a corresponding additional function and privacy information.

Google confirms that GA4 allows a retention period of 2 or 14 months to be configured for user and event data.

10.Google Tag Manager

With the corresponding privacy choice we use Google Tag Manager.

The provider is:

Google Ireland Limited

Gordon House

Barrow Street

Dublin 4

Ireland

Google Tag Manager serves to manage the analytics and other website tags used on our website technically.

Services requiring consent that are integrated via Google Tag Manager are activated in accordance with your privacy choice.

We do not use Google Tag Manager to transmit content from contact, product, consulting or project inquiries to Google.

11.Transfer of data in connection with Google services

When Google services are used, processing of data by companies of the Google group outside the European Union or the European Economic Area cannot be entirely ruled out.

Where personal data is transferred to a third country, this is done in compliance with Art. 44 et seq. GDPR.

For participating US companies, the European Commission's adequacy decision on the EU-US Data Privacy Framework currently applies in particular. In addition, further appropriate safeguards such as standard contractual clauses may be used where necessary. The European Commission continues to list the United States as a country with an adequate level of data protection for certified companies.

12.Inquiry list

You can first add products to an inquiry list without obligation.

Adding a product to the inquiry list constitutes neither an order nor a contract.

An inquiry list that has not yet been submitted may in particular store:

  • product or part number
  • product name
  • the quantity requested
  • any technical options selected
  • the time of the last change

Where the inquiry list is stored locally in the browser, no personal contact information is transmitted to us before submission.

Inquiry lists that are not submitted are generally deleted or expire no later than 30 days after they were last used.

You can also remove locally stored inquiry list contents at any time by clearing the inquiry list or deleting your browser's website data.

13.Product and quotation inquiries

Via our website you can select products and then send us a non-binding inquiry.

Submitting an inquiry does not place an order and does not conclude a purchase contract.

The following data in particular may be processed for an inquiry:

  • selected products
  • part numbers
  • requested quantities
  • technical options
  • name of the contact person
  • company name
  • business email address
  • telephone number
  • company address, where provided
  • project and application information
  • requested delivery date
  • free-text entries
  • uploaded files
  • date and time of the inquiry
  • technical security information

We use the data in particular to handle your inquiry, to examine technical and commercial requirements, to determine prices and availability, to ask follow-up questions, to select suitable products and to prepare an individual quotation.

If you are yourself a potential contracting party as a natural person, the processing is based in particular on Art. 6(1)(b) GDPR.

If you act as managing director, employee, authorized representative or other contact person of a company, the processing is based in particular on Art. 6(1)(f) GDPR.

Our legitimate interest lies in handling business inquiries and initiating a business relationship with the company you represent.

Mandatory fields are marked as such. Additional details are voluntary.

14.Contact and consulting inquiries

You can contact us in particular about the following topics:

  • technical advice
  • product selection
  • feasibility study
  • software and AI development
  • integration
  • commissioning
  • technical support
  • replacement and successor products
  • other machine vision and automation projects

In doing so we process the data you provide to us in order to handle your inquiry.

This may include your name, company, email address, telephone number, project description, technical requirements and uploaded documents.

Depending on the constellation, the processing is based in particular on Art. 6(1)(b) or (f) GDPR.

15.Feasibility studies and technical project inquiries

Feasibility inquiries may require more extensive technical information.

The following in particular may be processed:

  • details of the test object
  • technical requirements
  • part dimensions
  • field of view
  • working distance
  • defect size
  • tolerances
  • production speed
  • cycle time
  • material
  • surface properties
  • code size and marking method
  • technical drawings
  • images
  • videos
  • datasheets
  • information about good and defective parts
  • information about existing lines or components
  • other technical files

The processing serves the technical assessment of your application and the preparation of a possible product recommendation, feasibility study or project service.

Please do not send us any special categories of personal data within the meaning of Art. 9 GDPR, in particular no health data, biometric data, religious or political information or comparable sensitive personal information, unless this is strictly necessary and has been agreed with us in advance.

16.Internal administration area

To handle our business inquiries in a structured way, we operate an internal administration area.

Product, contact, consulting, feasibility, software, integration and support inquiries received via the website can be stored and processed there centrally.

The following in particular may be processed:

  • contact details
  • company data
  • content of the inquiry
  • selected products
  • part numbers and quantities
  • technical project data
  • uploaded files
  • communication history
  • processing status
  • responsible employee
  • quotation status
  • internal processing notes
  • date and time of processing steps

The internal system serves in particular to organize inquiries, assign them to responsible employees, keep track of progress, prepare quotations and organize communication with prospects and customers in a traceable way.

Depending on the case, the processing is based in particular on Art. 6(1)(b), (c) or (f) GDPR.

Our legitimate interest lies in organizing our business processes efficiently, securely and traceably.

17.Access rights in the internal administration area

Access to personal data in our internal administration area is generally granted only to those employees and, where applicable, commissioned service providers who need it for their respective activity.

We use appropriate technical and organizational measures to protect the administration area.

These may include in particular:

  • individual user accounts
  • role-based permissions
  • secure authentication
  • multi-factor authentication where used
  • time-limited sessions
  • logging of security-relevant operations
  • access restrictions
  • regular security updates

18.Security logging in the administration area

To protect our internal systems, security-relevant access and administrative actions may be logged.

The following in particular may be processed:

  • user identifier
  • IP address
  • time of access
  • successful and failed login attempts
  • technical system events
  • security-relevant administrative changes

The legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest lies in protecting our systems, detecting unauthorized access and making security-relevant operations traceable.

19.Additional handling of inquiries by email

In addition to being stored in the internal administration area, incoming inquiries may be forwarded automatically or manually to VISIONTECHNIK business email addresses.

An inquiry may therefore be processed both within our administration area and in our business email infrastructure.

This serves in particular to inform the responsible employees of a new inquiry and to enable prompt handling and communication.

Business-relevant email communication may be archived in accordance with statutory retention obligations.

We endeavour to avoid unnecessary duplicate copies, in particular of large or confidential project files.

20.Protection against spam and abusive inquiries

We use technical and organizational measures to protect our forms against spam, automated inquiries and other abuse.

These may include, for example:

  • honeypot fields
  • local security checks
  • plausibility checks based on timing
  • server-side input validation
  • limits on the number of inquiries
  • temporary blocks where abuse is detected

In doing so, the IP address, the time of the inquiry and technical security characteristics in particular may be processed.

The legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest lies in protecting our website, our IT systems and our employees against spam, malware and abusive use.

Unless an external CAPTCHA service is expressly named in this privacy policy, we do not use an external CAPTCHA provider such as Google reCAPTCHA for this purpose.

21.Technical partners on projects and feasibility studies

For technical projects, feasibility studies and application tests, VISIONTECHNIK works where necessary with selected specialist partner companies, manufacturers, laboratories or other technical specialists.

Depending on the task, individual technical tests, feasibility studies or parts of a project may be carried out by such a partner company.

Such involvement may take place as part of our technical handling without a separate agreement with the customer before each individual instance.

Our principle applies here: technical partners generally do not receive customer or contact data.

In particular, as part of this technical collaboration we generally do not transmit:

  • the name of the inquiring person
  • email addresses
  • telephone numbers
  • personal contact details
  • customer numbers
  • other personal information not required for the technical assessment

Where the identity of the inquiring company is not required for the technical task, it is generally not disclosed to the technical partner either.

Only the technical project data required to handle the respective technical task is transmitted.

This may include in particular:

  • technical task definitions
  • requirements and specifications
  • details of field of view and working distance
  • part dimensions
  • tolerances
  • production speed and cycle time
  • material and surface properties
  • technical drawings or extracts from drawings
  • images and videos of test objects
  • information about good and defective parts
  • defect images
  • details of codes and markings
  • technical data of existing components
  • interface information
  • other project data required for the technical assessment

Transmission follows the principle of necessity. Partner companies only receive the technical information they need to handle the task specifically assigned to them.

VISIONTECHNIK generally remains the central point of contact for the customer.

Involving a technical partner for internal project handling generally does not result in that partner contacting the customer directly.

22.Feasibility studies carried out by partner companies

Depending on the specific technical task, a feasibility study or application test may be carried out in whole or in part by a specialist partner company selected by VISIONTECHNIK.

This can make sense in particular where special:

  • test equipment
  • camera technology
  • lighting technology
  • measurement technology
  • software
  • test setups
  • manufacturer knowledge
  • industry-specific experience

is required.

In these cases too, generally only the project data required for the technical investigation is provided.

Customer and contact data is generally not transmitted to the technical partner for this purpose.

23.Confidential handling of project data

Technical project data may contain confidential information, trade secrets, development information, production information or other information worthy of protection.

We treat such project information as confidential.

Partner companies we engage for technical tests, feasibility studies or project tasks are appropriately bound to treat the project information we provide as confidential.

Project information transmitted may generally only be used for the respective technical task.

Use of such project data by a partner for its own sales, marketing or acquisition purposes is not envisaged.

Unauthorized disclosure of the project information to further third parties is not permitted.

As far as technically and practically possible, we ensure that transmitted project files do not contain customer or contact data that is unnecessary for the technical assessment.

24.Special confidentiality requirements

If restrictions apply to your project regarding the disclosure of technical project data to external technical partners - due to a non-disclosure agreement, internal company requirements or other special protection requirements - please point this out expressly when you make your inquiry or before transmitting the information concerned.

We will then examine whether and under what conditions handling without involving an external technical partner is possible.

25.External IT and development service providers

We may engage external IT and development service providers for the development, maintenance, technical support and security of our website and our internal systems.

Where such service providers process personal data on our behalf, the agreements required under data protection law - in particular data processing agreements under Art. 28 GDPR - are concluded where the statutory requirements are met.

Access to productive systems and personal data is restricted as far as possible to those persons and situations where access is technically necessary.

For development and testing purposes we use test data, anonymized, pseudonymized or non-personal information as far as possible.

26.International IT and development service providers

Where external developers or IT service providers outside the European Union or the European Economic Area are engaged and may have access to personal data, the processing takes place only in compliance with Art. 44 et seq. GDPR.

Depending on the country and recipient, adequacy decisions, standard contractual clauses or other statutory safeguards may apply.

27.Preparation of individual quotations

After examining an inquiry we may prepare an individual quotation and send it to the prospective customer, in particular by email.

The following in particular may be processed:

  • company and customer master data
  • contact details of the contact person
  • products and services requested
  • technical specifications
  • prices and discounts
  • delivery times
  • terms of payment and delivery
  • quotation number
  • quotation date
  • quotation validity
  • processing and communication notes

The processing serves the preparation, transmission, administration and follow-up of the quotation.

28.Performance of the contract

If a contract is concluded following an inquiry or quotation, we process the information required to perform the contract.

This may include in particular:

  • company data
  • name of the contact person
  • invoice and delivery address
  • VAT identification number
  • customer, quotation and order number
  • products and services ordered
  • prices and discounts
  • terms of payment and delivery
  • order confirmations
  • communication data
  • delivery and payment status
  • complaint, warranty and service data

Depending on the constellation, the processing is based in particular on Art. 6(1)(b), (c) or (f) GDPR.

29.Invoicing and payment

There is currently no direct online payment processing via our website.

In particular, no credit card or comparable payment information is collected on our website.

In connection with invoicing and payment, the following in particular may be processed:

  • company name
  • invoice address
  • contact person
  • invoice and customer number
  • products and services ordered
  • invoice amount
  • payment term
  • payment date
  • payment status
  • payment reference
  • account holder
  • IBAN

The processing serves the performance of the contract and compliance with commercial and tax law obligations.

30.Delivery and direct shipping

To deliver ordered products, the necessary data may be transmitted to parcel service providers, freight forwarders, suppliers or manufacturers.

This may be necessary in particular for:

  • shipping
  • direct shipping
  • scheduling
  • shipment tracking
  • customs clearance

Generally only the information required for the respective shipping process is passed on.

For international deliveries, data may be transmitted to customs or tax authorities on the basis of statutory obligations.

31.Manufacturers, distributors and suppliers

To handle a product inquiry it may be necessary to obtain prices, availability, delivery times or technical information from manufacturers, distributors or suppliers.

Where no personal data is required for this, we transmit only product and technical project data.

Personal customer data is not passed on to a manufacturer or supplier merely because we obtain technical or commercial information about a product.

32.Guarantee, warranty, repair and service cases

In guarantee, warranty, repair or service cases it may become necessary to transmit data to the respective manufacturer, supplier or service partner.

Depending on the case, the following in particular may be processed:

  • company name
  • contact person
  • contact details
  • product name
  • part number
  • serial number
  • purchase or delivery date
  • fault description
  • images and videos
  • log files
  • technical configurations

Only the data required for handling the case is passed on.

33.Email, administration, ERP and accounting systems

We use email, administration, ERP and accounting systems to handle our business operations.

Possible recipients or service providers may in particular be:

  • providers of our email infrastructure
  • hosting providers
  • IT support service providers
  • administration and ERP providers
  • accounting software providers
  • tax advisors
  • auditors
  • lawyers
  • debt collection and receivables service providers

Where a service provider processes personal data for us on our instructions, this is done on the basis of a data processing agreement under Art. 28 GDPR where required.

34.Appointment booking via Calendly

Our website may offer an external link for booking appointments via Calendly.

The provider is:

Calendly, LLC

115 E Main Street

Suite A1B

Buford, Georgia 30518

USA

Calendly is generally not loaded automatically simply by visiting a VISIONTECHNIK page where we merely link to Calendly.

Only when you click the appointment link do you leave our website and access Calendly's service.

When booking an appointment, the following information in particular may be processed:

  • name
  • business email address
  • company name
  • telephone number
  • requested appointment
  • time zone
  • details of the reason for the meeting
  • voluntary messages
  • technical connection and usage information

Processing of personal data in the USA cannot be ruled out.

Where a third-country transfer takes place, it is carried out in compliance with the statutory requirements of Art. 44 et seq. GDPR.

35.Newsletter

You can subscribe to our newsletter voluntarily.

The following in particular may be processed:

  • email address
  • name where applicable
  • company name where applicable
  • time of subscription
  • time of confirmation
  • IP address
  • dispatch status
  • delivery status
  • unsubscribe status

Dispatch takes place on the basis of your consent under Art. 6(1)(a) GDPR.

We generally use a double opt-in procedure.

You can withdraw your consent at any time with effect for the future, in particular via the unsubscribe link in every newsletter email or by sending a message to: info@visiontechnik.de

Newsletter consent is not a prerequisite for an inquiry, consultation, quotation or order.

Should we use an external newsletter service provider or personal open and click tracking in future, this privacy policy will be supplemented before such use.

36.Fonts and external content

Fonts and other basic resources required to display our website are generally provided via our own web infrastructure or our hosting provider.

In particular, any Google fonts we use are provided locally and are not loaded directly from Google servers merely to display a font.

External videos, maps, chats, review services or comparable external content are either only linked or, where necessary, technically blocked until the corresponding consent is given.

37.Recipients of personal data

Within our company, access to personal data is generally granted only to those persons who need it for their respective activity.

Depending on the case, external recipients of personal data may in particular be:

  • hosting and IT service providers
  • email and communication providers
  • administration, ERP and accounting providers
  • Google, subject to consent to analytics
  • Calendly, if you book an appointment yourself
  • manufacturers or service partners, where required for a specific service, guarantee or delivery case
  • parcel service providers and freight forwarders
  • credit institutions
  • tax advisors
  • auditors
  • lawyers
  • debt collection and receivables service providers
  • the competent authorities

Technical partners who merely handle a technical project task or feasibility study transmitted anonymously or without customer reference generally do not receive customer or contact data as part of that technical collaboration.

Personal data is not sold, and it is not passed on to third-party companies for their own general advertising purposes.

38.Transfer of personal data to third countries

Where practicable, we prefer data processing within the European Union or the European Economic Area.

Certain services or business operations may, however, involve processing in countries outside the EU or EEA.

This may be the case, for example, with certain:

  • Google services
  • Calendly
  • international IT service providers
  • international manufacturers or service partners

A third-country transfer only takes place in compliance with Art. 44 et seq. GDPR.

This may in particular involve an adequacy decision of the European Commission, a valid certification under a recognized data protection framework, standard contractual clauses or other statutory safeguards.

39.Data backup

To ensure the availability and recoverability of our systems, we create technical data backups.

Personal information may therefore also be contained in backup copies for a limited period.

Backups are generally used exclusively for security, recovery and emergency purposes.

Data deleted from our active systems may therefore still be contained in technically necessary backup copies until the end of the respective backup cycle.

These backup copies are overwritten or deleted within our planned backup cycles.

40.Retention period and deletion

We generally store personal data only for as long as is necessary for the respective purpose or as long as statutory retention obligations exist.

The following retention periods and criteria generally apply:

Server log data

generally 14 days.

Inquiry lists that were not submitted

generally no more than 30 days after they were last used.

General contact or technical inquiries without a subsequent quotation or business relationship

generally up to six months after they have been dealt with.

Inquiries in the internal administration area

for the handling of the respective case and thereafter in line with further business or legal necessity.

Business-relevant correspondence including quotations as well as commercial and business letters received and sent

generally in line with the statutory retention period of six years, unless another period applies.

Accounting records and invoices

generally in line with the statutory retention period of eight years.

Commercial books, annual financial statements and comparable records subject to statutory retention

generally in line with the statutory retention period of ten years.

Google Analytics user and event data

generally 14 months in line with our configuration.

Newsletter data

until withdrawal or unsubscription; certain evidence data may be stored beyond that where necessary to demonstrate that consent was originally given.

Appointment booking data

generally twelve months after the appointment has taken place or been cancelled, unless it has become part of a further business relationship.

Contract, warranty, complaint, repair and service data

for the duration of the contractual or service relationship and thereafter in line with the applicable statutory retention and limitation periods.

Where specific legal claims, disputes or official proceedings exist, the data required for them may be stored until they have been finally resolved.

Once the purpose of processing no longer applies and the applicable retention obligations have expired, the data is deleted or anonymized.

41.Provision of data

Providing technically necessary connection data is required in order for our website to be accessed.

Mandatory fields marked in our forms are required in order to handle the respective inquiry.

Without the required information, an inquiry may not be able to be handled, or not handled in full.

Additional details are generally voluntary.

42.Automated decisions and profiling

We do not take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.

The use of Google Analytics serves the statistical analysis and optimization of our website.

In particular, Analytics data does not automatically determine:

  • whether an inquiry is accepted
  • whether a customer receives a quotation
  • which price a customer receives
  • whether a contract is concluded
  • whether a customer is supplied

There is currently no automated credit decision or automated customer scoring via our website.

43.Data security

We take appropriate technical and organizational measures to protect personal data, in particular against loss, manipulation, unauthorized disclosure and unauthorized access.

Depending on the processing operation, these may include in particular:

  • encrypted data transmission
  • access restrictions
  • role-based permissions
  • secure authentication
  • secure password policies
  • multi-factor authentication where applicable
  • regular security updates
  • data backups
  • logging of security-relevant operations
  • server-side input validation
  • protection against automated attacks
  • organizational confidentiality measures

Our security measures are reviewed and developed further in line with the respective risk and technical progress.

44.Rights of data subjects

Where the statutory requirements are met, you have in particular the following rights:

  • right of access under Art. 15 GDPR
  • right to rectification under Art. 16 GDPR
  • right to erasure under Art. 17 GDPR
  • right to restriction of processing under Art. 18 GDPR
  • right to data portability under Art. 20 GDPR
  • right to object under Art. 21 GDPR
  • right to withdraw consent under Art. 7(3) GDPR
  • right to lodge a complaint with a data protection supervisory authority under Art. 77 GDPR

You can contact us to exercise your rights:

GK VISION GmbH - VISIONTECHNIK

Email: info@visiontechnik.de

45.Withdrawal of consent

Where processing is based on your consent, you can withdraw that consent at any time with effect for the future.

This applies in particular to:

  • Google Analytics
  • other optional analytics technologies
  • the newsletter
  • any future external media or marketing technologies

For website technologies you can change your choice in particular via the “Cookie settings” link.

The lawfulness of processing carried out up to the withdrawal remains unaffected.

46.Objection to processing based on legitimate interests

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you may object to the processing under the conditions of Art. 21 GDPR on grounds relating to your particular situation.

An objection can be sent in particular by email to: info@visiontechnik.de

47.Right to lodge a complaint with a data protection supervisory authority

You have the right to lodge a complaint with a competent data protection supervisory authority.

The supervisory authority generally responsible for us is:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)

Landesbeauftragte für Datenschutz Schleswig-Holstein

Holstenstraße 98

24103 Kiel

Germany

Postal address: Postfach 71 16, 24171 Kiel

Phone: +49 431 988-1200

Email: mail@datenschutzzentrum.de

You may also contact another competent data protection supervisory authority, in particular the authority of your habitual residence, place of work or the place of the alleged infringement.

48.Future functions and services

Our website and our internal systems are continuously developed further.

Should additional functions or services relevant to data protection be used in future, for example:

  • customer accounts
  • direct online orders
  • online payments
  • credit checks
  • Google Ads conversion tracking
  • Microsoft Clarity
  • Hotjar
  • session replay
  • LinkedIn Insight Tag
  • Meta Pixel
  • YouTube embeds
  • map or chat services
  • further analytics, marketing or external media services

we will amend this privacy policy accordingly.

Functions requiring consent are only used in accordance with the statutory requirements and the privacy choice you have made.

49.Updates to this privacy policy

We amend this privacy policy when our data processing, the service providers we use, our technical functions or the legal requirements change.

The version published on our website from time to time is the applicable one.

As of: August 2026