Back to home

    Privacy Policy

    Last updated: 4 September 2026

    This privacy policy explains which personal data is processed when you visit our website or contact us. The relevant rules include the GDPR, the German Federal Data Protection Act and, where information is stored on or read from your device, the German Telecommunications Digital Services Data Protection Act (TDDDG).

    Controller within the meaning of GDPR

    Schmidt Embedded Systems GmbH Auf der Grube 9 35041 Marburg Germany Email: info@schmidt-embedded-systems.de Phone: +49 176 39270895

    Contact for privacy questions

    Please direct questions about the processing of your personal data to: Schmidt Embedded Systems GmbH Email: info@schmidt-embedded-systems.de

    Data Collection and Processing

    We collect and process various personal data only to the extent necessary and exclusively for the stated purposes.

    When Visiting the Website

    When you access the website, technically necessary connection data is processed. This may include your IP address, date and time, requested URL, referrer, browser, operating system and access status.

    This processing is necessary to deliver the website, maintain its stability and prevent misuse. Server and security logs are retained only for as long as they are needed for these purposes.

    The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website.

    Contacting us

    Our website does not contain a contact form. If you contact us by email, telephone or through appointment booking, we process the contact details and content you provide in order to respond to your enquiry.

    Processing is necessary to take steps before entering into a contract or to perform a contract under Art. 6(1)(b) GDPR. For other enquiries, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is responding to your enquiry.

    Internal reach measurement

    After you have given consent, the website sends the page path, section identifier, event type, any UTM campaign parameters and a randomly generated session identifier to our API at checkout.ses-intern.de when individual page sections enter the viewport. The identifier is not stored permanently on your device. The server also records the IP address and time. We use this data only to understand which content is viewed.

    The legal basis is your consent under Art. 6(1)(a) GDPR. You may withdraw it at any time through the cookie settings with effect for the future.

    Local Data Storage

    Your cookie settings and a timestamp are stored in your browser's localStorage for 180 days. This means that we do not have to ask you again on every visit. The selection remains on your device and can be removed through your browser settings.

    This storage is necessary to manage the consent choice you made (section 25(2)(2) TDDDG). Where personal data is processed, the legal basis is Art. 6(1)(f) GDPR.

    External Services

    Hosting by Vercel

    The website is delivered through Vercel Inc., USA. Vercel processes connection data needed to deliver and secure the website on our behalf. Runtime logs under our Vercel Pro plan are retained for no more than one day. Processing in the USA or other third countries may occur. Vercel provides safeguards including the EU Standard Contractual Clauses. More information: https://vercel.com/legal/privacy-notice and https://vercel.com/legal/dpa

    Appointment booking through Calendly

    The appointment buttons link to Calendly, a service provided by Calendly LLC, USA. No Calendly content is loaded on our website. Only after you follow the link does Calendly process technical data and the details you enter to book the appointment. The details required for the appointment are shared with us. More information: https://calendly.com/legal/privacy-notice

    Embedded YouTube videos

    Video previews are loaded from our own server. Only when you play a video is a connection established with YouTube through the enhanced privacy domain youtube-nocookie.com. Google Ireland Limited may then receive your IP address, device and browser data and the page you visited, and may store or access information on your device. The legal basis is your choice to play the video in conjunction with Art. 6(1)(a) GDPR and section 25(1) TDDDG. More information: https://policies.google.com/privacy

    Social Media Links

    Our website contains links to LinkedIn. Merely visiting our website does not load content from LinkedIn. Only after you follow a link does LinkedIn process data under its own privacy terms: https://www.linkedin.com/legal/privacy-policy

    Google Tag Manager

    After you have given consent, we load Google Tag Manager from Google Ireland Limited. It provides the technical management of our Google Ads and LinkedIn tags. Connection data is transmitted to Google. Tag Manager is not loaded if you allow essential functions only.

    The legal basis is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG. You may withdraw it at any time through the cookie settings.

    Google Ads

    After you have given consent, we use Google Ads conversion tracking. When you click the appointment booking button, Google may process information about a previous advertising click, the page visited and technical device and browser data, and may store identifiers in cookies. We receive aggregated information about the effectiveness of our advertising. More information: https://policies.google.com/privacy

    The legal basis is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG.

    LinkedIn Insight Tag

    After you have given consent, we use the LinkedIn Insight Tag provided by LinkedIn Ireland Unlimited Company for conversion measurement, aggregated audience reports and retargeting. The URL, referrer, IP address, device and browser characteristics and time are transmitted. LinkedIn states that it removes direct identifiers within seven days and deletes the remaining pseudonymised data within 180 days. More information: https://www.linkedin.com/legal/privacy-policy

    The legal basis is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG.

    Conversion Linker

    After you have given consent, Conversion Linker stores information about an advertising click in first-party cookies with the _gcl_ prefix and in browser storage under _gcl_ls. These identifiers are retained for up to 90 days. This enables Google Ads to associate a later click on the appointment booking button with the advertising click.

    The legal basis is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG.

    Data Security

    The website is transmitted through an encrypted HTTPS connection. We also use appropriate technical and organisational measures to protect personal data against loss, alteration and unauthorised access.

    Data Retention

    We store your personal data only for as long as is necessary for the stated purposes or as required by legal retention periods:

    • Cookie consent (localStorage): 6 months
    • Vercel runtime logs: no more than 1 day
    • Contact and appointment data: until the enquiry has been completed and then only for applicable statutory retention periods
    • Internal reach measurement: until the data is no longer required to evaluate which content was viewed
    • Google Ads identifiers (_gcl_ cookies and _gcl_ls browser storage): no more than 90 days
    • LinkedIn Insight Tag: pseudonymised data for no more than 180 days according to the provider
    • Other data processed by Google, YouTube and Calendly: according to each provider's retention rules

    Your Rights

    Regarding your personal data stored with us, you have the following rights:

    • Right to information (Art. 15 GDPR)
    • Right to rectification (Art. 16 GDPR)
    • Right to erasure (Art. 17 GDPR)
    • Right to restriction of processing (Art. 18 GDPR)
    • Right to data portability (Art. 20 GDPR)
    • Right to withdraw consent (Art. 7(3) GDPR)
    • Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
    • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
    Back to home