onsector
PLEXecute
Our Features
Intelligent Scheduling
Warnings & Notifications
Flexible Data Management
Solutions
Our Software Solutions
Custom Software
Workflow Automation
Production Planning
Info
Information Overview
All Articles
About Us
Contact UsStart Demo
CzechEnglishFrenchGermanPolishPortugueseSpanish
CzechEnglishFrenchGermanPolishPortugueseSpanish
onsector
Our FeaturesIntelligent SchedulingWarnings & NotificationsFlexible Data Management
Our Software SolutionsCustom SoftwareWorkflow AutomationProduction Planning
Information OverviewAll ArticlesAbout Us
Start DemoContact Us
Language
CzechEnglishFrenchGermanPolishPortugueseSpanish
Home
Privacy Policy

Privacy Policy

Preamble

With the following privacy policy, we aim to inform you about the types of your personal data (hereinafter also referred to as "Data") we process, for what purposes and to what extent. This privacy policy applies to all personal data processing activities we carry out, both in the context of providing our services and particularly on our websites, in mobile applications and within external online presences, such as our social media profiles (collectively referred to as "Online Offer").

The terms used are not gender-specific.
Effective Date: August 31, 2026

Table of Contents

  • Preamble
  • Data Controller
  • Processing on this website
  • Presence in Social Networks (Social Media)
  • International Data Transfers
  • Security Measures
  • General Information on Data Storage and Deletion
  • Rights of Data Subjects

Data Controller

onsector GmbH
Vladyslav Pakhalovych
Hagenbacher Straße 6
76187 Karlsruhe
Germany

Email address: vladyslav.pakhalovych@onsector.de
Imprint: Contact

Processing on this website

This website uses the services described below. Vercel Web Analytics and Speed Insights are active independently of the cookie choice. Google Analytics loads only after analytics consent. Google Ads and Dealfront/Leadfeeder load only after marketing consent. This rule applies to every visitor, regardless of country.

Consent management: Optional analytics and marketing services are used only with your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. Your choice remains valid for six months. You can change or withdraw it at any time through Cookie Preferences in the footer.

Hosting and delivery by Vercel: The website is delivered by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. This involves processing the IP address, time, requested page, status code, and browser and device information. The purpose is secure and reliable website delivery; the legal basis is Article 6(1)(f) GDPR. Third-country transfers rely on an adequacy decision or appropriate safeguards, in particular EU Standard Contractual Clauses. Vercel Privacy Notice · Vercel DPA

Analytics and performance measurement: Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) processes page views, events, approximate region, and device and browser information and may recognise repeat visits for up to two years. It is used only after analytics consent. Vercel Web Analytics processes page views, referrer, approximate region, and browser, operating-system and device class for aggregate statistics. Its daily visitor identifier is discarded after 24 hours; Vercel uses no cookies for this service and states that measurements are not associated with an individual or IP address. Speed Insights processes Web Vitals and broad device and connection characteristics without reconstructing cross-page sessions. Both Vercel services remain active independently of the cookie choice under Article 6(1)(f) GDPR. Google Privacy Policy · Vercel Analytics Privacy · Vercel Speed Insights Privacy

Advertising effectiveness and company identification: Dealfront/Leadfeeder processes IP-based company matching, pages viewed, time, source and technical connection data to identify visiting companies and repeat visits. Recognition is designed to last no longer than one year. Google Ads measures whether a demo-code request followed an advertisement; ad-click information is generally stored for no longer than 90 days. We do not send email addresses or other direct identifiers to Google Tag Manager or Google Ads. These services are used only after marketing consent under Article 6(1)(a) GDPR. Leadfeeder Privacy · Google Ads Data Processing

Contact, demo emails and appointment booking: We use Resend (Plus Five Five, Inc., USA) for contact requests and demo access codes. We process the name, email address, message, language and delivery information. Fields marked as required are necessary to process the request; without them we cannot reply or send the requested access code. A separate consent checkbox is not required for the reply or access-code email that you request. The legal basis is Article 6(1)(b) GDPR where the request concerns a contract or pre-contractual steps; otherwise, Article 6(1)(f) GDPR applies based on our interest in responding to inquiries. Security and abuse prevention also rely on Article 6(1)(f) GDPR. Transfers to the US use the safeguards agreed in the Resend DPA. If you open an appointment link, Microsoft Bookings processes the contact and appointment data entered there to arrange the meeting under Article 6(1)(b) GDPR. Resend Privacy Policy · Resend DPA · Microsoft Bookings GDPR information · Microsoft DPA

Specific retention periods: The cookie choice expires after six months. Google Analytics user and event data are retained for no more than 14 months; aggregate reports may remain longer. Vercel's daily visitor identifier expires after 24 hours; aggregate reports are available, depending on the plan, for no more than 24 months in Web Analytics and 90 days in Speed Insights. Resend retains email and delivery data for 30 days on standard plans. The pending demo email address stored in the browser and the access code expire after ten minutes, and abuse-prevention counters after one hour. We delete contact and demo correspondence and appointment data no later than six months after final handling unless a contract, legal duty or legal defence requires longer retention.

Browser storage at a glance: Essential storage covers the consent choice (cookie_consent, 180 days) and temporary demo and contact details (no more than 10 minutes or until the end of the browser session). With functional consent, an offline cache may remain until withdrawal or version cleanup. After analytics or marketing consent, Google and Dealfront/Leadfeeder may use the _ga/_ga_*, _gcl_*/_gcl_ls and _lfa*/_lfa_expiry storage families; depending on the service, their lifetime ranges from no more than 90 days to 2 years. In the current integration, Vercel Web Analytics and Speed Insights set no cookies and create no Local or Session Storage entries.

Presence in Social Networks (Social Media)

We maintain online presences within social networks and process user data within this framework to communicate with active users there or to provide information about us. We point out that in doing so, user data may be processed outside the European Union. This can pose risks for users because, for example, the enforcement of user rights could be made more difficult. Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, based on users' behavior and resulting interests, usage profiles can be created. These may, in turn, be used to display advertisements within and outside the networks that presumably match the users' interests. Therefore, cookies are generally stored on users' computers in which users' behavior and interests are saved. Additionally, data can also be stored in the usage profiles independently of the devices used by the users (especially if they are members of the respective platforms and logged in there). For a detailed presentation of the respective processing forms and objection options (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks. Even in the case of information requests and the assertion of data subject rights, we point out that these can be most effectively asserted with the providers. Only the latter have access to the user data and can directly take appropriate measures and provide information. If you still need assistance, you can contact us.

Processed Data Types: Contact Data: (e.g., postal and email addresses or phone numbers); Content Data: (e.g., textual or visual messages and contributions as well as information related to them, such as author information or time of creation); Usage Data: (e.g., page views and duration, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
Data Subjects: Users (e.g., website visitors, users of online services).
Purposes of Processing: Communication; Feedback (e.g., collecting feedback via online form); Public Relations.
Retention and Deletion: Deletion in accordance with the information provided in the "General Information on Data Storage and Deletion" section.
Legal Bases: Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f) GDPR)

Additional Information on Processing Processes, Procedures and Services:
LinkedIn: Social Network – Together with LinkedIn Ireland Unlimited Company, we are responsible for the collection (but not further processing) of data from visitors used to create the "Page Insights" (statistics) of our LinkedIn profiles. This data includes information about the types of content users view or interact with, as well as actions they take. Additionally, details about the devices used are collected, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from user profiles, such as job function, country, industry, hierarchy level, company size and employment status. Privacy information on the processing of user data by LinkedIn can be found in LinkedIn's privacy notices: https://www.linkedin.com/legal/privacy-policy. We have concluded a special agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum", https://www.linkedin.com/legal/l/page-joint-controller-addendum), which regulates, in particular, the security measures LinkedIn must observe and in which LinkedIn has committed to fulfilling the rights of data subjects (i.e., users can direct information or deletion requests directly to LinkedIn). The rights of users (in particular the right to information, deletion, objection and complaint with the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection and transmission of data to LinkedIn Ireland Unlimited Company, a company based in the EU. Further processing of the data is exclusively the responsibility of LinkedIn Ireland Unlimited Company, particularly regarding the transfer of data to the parent company LinkedIn Corporation in the USA; Service Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal Bases: Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for Third-Country Transfers: Data Privacy Framework (DPF). Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out

Instagram (Meta): We maintain the Instagram profile https://www.instagram.com/onsector_gmbh/. Merely visiting our website does not embed Instagram content or load a Meta Pixel; data is transferred to Meta only when you open the external link. On Instagram, Meta Platforms Ireland Limited, Merrion Road, Ballsbridge, Dublin D04 X2K5, Ireland, processes profile, contact, content, usage, device and cookie data in particular to operate the platform, communicate, advertise and provide statistics. Insofar as we jointly determine the collection and transmission of profile-insights statistics, we are joint controllers; Meta is responsible for further processing. Our legal basis for operating the profile is Article 6(1)(f) GDPR (public relations and communication). Transfers to the US may rely on the EU-US Data Privacy Framework or other appropriate safeguards. Meta Privacy Policy · Page Insights Controller Addendum · Instagram privacy settings

International Data Transfers

Data Processing in Third Countries: If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if the processing takes place within the framework of using third-party services or the disclosure or transfer of data to other persons, entities, or companies, this only occurs in accordance with legal requirements. If the data protection level in the third country has been recognized by an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only occur if the data protection level is otherwise ensured, particularly through standard contractual clauses (Art. 46 para. 2 lit. c) GDPR), explicit consent, or in the case of contractual or legally required transfers (Art. 49 para. 1 GDPR). Furthermore, we inform you about the bases for third-country transfers for individual providers from the third country, where adequacy decisions take precedence as bases. Information on third-country transfers and existing adequacy decisions can be found in the EU Commission's information offer: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de. Under the so-called "Data Privacy Framework" (DPF), the EU Commission has also recognized the data protection level for certain companies from the USA as secure within the framework of the adequacy decision dated July 10, 2023. You can find the list of certified companies as well as further information about the DPF on the website of the U.S. Department of Commerce: https://www.dataprivacyframework.gov/ (in English). We inform you within the privacy notices which service providers we use that are certified under the Data Privacy Framework.

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with legal requirements and considering the state of the art, the implementation costs and the nature, scope, context and purposes of processing as well as the likelihood and severity of varying risks to the rights and freedoms of natural persons.

These measures include, in particular, securing the confidentiality, integrity and availability of data by controlling physical and electronic access to data as well as access related to the data, input, transfer, ensuring availability and their separation. Furthermore, we have established procedures that ensure the exercise of data subjects' rights, the deletion of data and responses to data endangerment. We also consider the protection of personal data during the development or selection of hardware, software and procedures in accordance with the principles of data protection by design and by default.

Securing Online Connections through TLS/SSL Encryption Technology (HTTPS): To protect users' data transmitted through our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and encrypted.

General Information on Data Storage and Deletion

We delete personal data we process in accordance with legal provisions as soon as the underlying consents are withdrawn or no further legal bases for processing exist. This applies to cases where the original processing purpose ceases or the data is no longer needed. Exceptions to this rule exist if legal obligations or special interests require longer storage or archiving of the data. In particular, data that must be retained for commercial or tax reasons or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons must be archived accordingly. Our privacy notices contain additional information on the retention and deletion of data that apply specifically to certain processing processes. When multiple indications are given regarding the retention period or deletion deadlines of a date, the longest period always applies. If a period does not explicitly begin on a specific date and is at least one year long, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships within the framework of which data is stored, the event triggering the period is the effective date of termination or other termination of the legal relationship. Data that is no longer needed for the originally intended purpose but is retained due to legal requirements or other reasons is processed exclusively for the reasons justifying its retention.

Rights of Data Subjects

Rights of Data Subjects under the GDPR: As a data subject, you have in particular the rights under Articles 7(3), 15 to 21 and 77 GDPR:
  • Right to Object You have the right to object at any time to the processing of your personal data for reasons arising from your particular situation, based on Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such purposes; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to Withdraw Consent: You have the right to withdraw your given consents at any time.
  • Right to Information: You have the right to obtain confirmation as to whether personal data concerning you is being processed and to obtain information about this data and a copy of the data in accordance with legal provisions.
  • Right to Rectification: You have the right to demand the completion of your personal data or the correction of inaccurate personal data concerning you in accordance with legal provisions.
  • Right to Erasure and Restriction of Processing: You have the right to demand that personal data concerning you is deleted without delay, or alternatively, to demand a restriction of processing of the data in accordance with legal provisions.
  • Right to Data Portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format or to demand its transmission to another controller in accordance with legal provisions.
  • Right to Lodge a Complaint with a Supervisory Authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, particularly in the member state of your habitual residence, your place of work, or the place where the alleged infringement occurred, if you believe that the processing of your personal data violates the GDPR.

Created with the free Privacy Policy Generator by Dr. Thomas Schwenke

Company

  • About Us
  • Imprint
  • Privacy Policy

PLEXecute

  • Our Features
  • Intelligent Scheduling
  • Warnings & Notifications
  • Flexible Data Management

Solutions

  • Our Software Solutions
  • Custom Software
  • Workflow Automation
  • Production Planning

Contact

onsector GmbH

Hagenbacher Str. 6

76187 Karlsruhe

Germany

info@onsector.de

Follow

  • LinkedIn
  • Instagram

© 2026 onsector GmbH · All rights reserved

Made in Germany