Privacy Policy
Last updated: 12 August 2026
This Privacy Policy applies exclusively to the publicly accessible INZIPIO corporate and marketing website, including its company, product, careers, contact and legal pages. It does not apply to the CASPAI application or other password-protected product environments accessed via “Login”.
We process personal data only to the extent necessary to provide a functional, secure and user-friendly website and to handle the activities described below. “Personal data” and “processing” have the meanings given in Article 4(1) and (2) of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”).
This Privacy Policy explains the categories of personal data processed, the purposes and legal bases, recipients, any international transfers, retention criteria, your rights and the third-party services used on the website.
This Privacy Policy is structured as follows:
I. Information about the controller
II. Rights of users and data subjects
III. Information about data processing
I. Information about us as controllers of your data
The party responsible for this website (the “controller”) for purposes of data protection law is:
Inzipio GmbH
Krantzstrasse 7, Building 80
52070 Aachen
Germany
Email: info@inzipio.com
Data-protection enquiries may be sent to info@inzipio.com or by post to the address above, marked “Data Protection”.
II. Rights of users and data subjects
In relation to the processing described below, users and data subjects have the right
- to obtain confirmation as to whether personal data concerning them are processed, access to those data and further information about the processing (Article 15 GDPR);
- to have inaccurate data rectified and incomplete data completed (Article 16 GDPR);
- to have personal data erased, subject to the exceptions in Article 17(3) GDPR, or to have processing restricted (Articles 17 and 18 GDPR);
- to receive personal data they have provided in a structured, commonly used and machine-readable format and, where the legal requirements are met, to transmit those data to another controller (Article 20 GDPR);
- to object, on grounds relating to their particular situation, to processing based on Article 6(1)(e) or (f) GDPR; where data are processed for direct marketing, the objection may be made at any time (Article 21 GDPR);
- where processing is based on consent, to withdraw that consent at any time with effect for the future, without affecting the lawfulness of processing before withdrawal (Article 7(3) GDPR); and
- to lodge a complaint with a data-protection supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR).
The supervisory authority competent for our registered office is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, email: poststelle@ldi.nrw.de. Complaints may also be submitted through the LDI NRW complaint page.
Where required by Article 19 GDPR, we notify recipients of rectification or erasure of personal data or restriction of processing, unless this proves impossible or involves disproportionate effort. Data subjects may request information about those recipients.
III. Information about data processing
Personal data processed when you use our website are erased or restricted once the relevant purpose no longer applies, unless statutory retention obligations or the specific information below require longer storage.
Recipients are limited to authorised employees and service providers who need the data for the stated purposes, as well as public authorities, courts and professional advisers where disclosure is required by law or necessary to establish, exercise or defend legal claims. The relevant processors and other recipients are described in the sections below. International transfers occur only as described for the respective provider.
Unless expressly stated otherwise, providing personal data on this public website is voluntary. Technically necessary connection data are required to deliver the website; without them, the website cannot be provided. We do not use automated decision-making within the meaning of Article 22 GDPR or profiling on this marketing website.
Cookies and consent management (Cookiebot)
We use cookies and similar technologies on this website. Cookies are small data records stored on your device. Similar technologies may store information on your device or access information already stored there.
For storage on or access to your device, Section 25 TDDDG applies. Technologies that are strictly necessary to provide a service you have expressly requested may be used without consent under Section 25(2) No. 2 TDDDG. Where personal data are processed in this context, the legal bases are Article 6(1)(c) GDPR, insofar as processing is necessary to comply with legal obligations, and Article 6(1)(f) GDPR, based on our legitimate interest in the secure and legally compliant operation of the website. All non-essential technologies are used only after your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.
We use Cookiebot as our consent-management platform. Cookiebot is provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot displays the consent interface, records your choices and prevents non-essential services from loading before the required consent has been given.
For consent management and proof of consent, Cookiebot may process an anonymised IP address, the date and time of the decision, browser and device information, the website URL, an anonymous encrypted key and the selected consent categories. The necessary CookieConsent cookie stores your consent status for up to 12 months so that your choice can be recognised on later visits. The legal bases are Section 25(2) No. 2 TDDDG and Article 6(1)(c) and (f) GDPR. Cookiebot processes this information on our behalf.
We use the following categories:
- Necessary: Technologies required to provide the website securely and to store your consent choice. These cannot be disabled through the consent interface.
- Statistics: Google Analytics 4 is loaded only if you consent to statistics technologies. GA4 normally uses the first-party cookies
_gato distinguish users and_ga_<container-id>to maintain session state. Their default maximum lifetime is two years, although browsers may shorten it. Further details are provided in the “Google Analytics 4” section.
You may grant or refuse the optional statistics category. Refusing consent does not prevent use of the core website, but Google Analytics 4 will then remain disabled. You may withdraw or change consent at any time with effect for the future by using the persistent Cookiebot cookie-settings control in the lower-left corner of the website. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal. You can also delete cookies through your browser settings; this does not replace the consent choice for future use.
The current Cookiebot consent interface provides further details about the individual technologies, providers, purposes and storage periods. Further information about Cookiebot is available in the Cookiebot Privacy Policy.
Contact and enquiries
If you contact us by email or use an email contact button on our website, we process the information you provide, such as your name, email address, organisation, area of interest, message, attachments and communication metadata, to handle and respond to your enquiry. Selecting an email contact button opens your local email application. The website itself does not receive or transmit the contents of your message. Data are sent to us only when you send the email.
Where your enquiry concerns a possible or existing contract—for example a product, demo, proposal or service request—the legal basis is Article 6(1)(b) GDPR. For other enquiries, such as general corporate, research, press, investor or partnership enquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to answer enquiries and conduct appropriate business communications. Article 6(1)(c) GDPR may additionally apply where processing is necessary to comply with a legal obligation.
Only authorised staff responsible for the enquiry, our email and IT service providers acting as processors, and professional advisers where necessary receive the data. We delete enquiry data when the matter has been conclusively dealt with and the data are no longer required, unless statutory retention periods, the establishment or performance of a contract, or the establishment, exercise or defence of legal claims require longer storage.
Please do not send patient data, medical images or other health information by email.
Applications
If you apply for a position, internship, working-student role or thesis opportunity, we process the information you submit, including your contact details, curriculum vitae, qualifications, employment history, area of interest, preferred starting date, application documents and communications, to assess your application and conduct the recruitment process.
The legal basis is Section 26(1) of the German Federal Data Protection Act (BDSG) and, where applicable, Article 6(1)(b) GDPR for steps taken at your request before entering into an employment contract.
Recipients are authorised employees and managers involved in recruitment, our email and IT service providers acting as processors, and professional advisers where necessary. Providing application data is voluntary, but without the information needed to assess your application we may be unable to consider it. We do not make recruitment decisions based solely on automated processing.
If no employment relationship is established, application data are generally deleted no later than six months after completion of the application process, unless longer storage is necessary to establish, exercise or defend legal claims or to comply with statutory obligations. Please do not include unnecessary special-category data, such as health information, in your application.
Super.so
We use Super.so to provide and operate our website. The provider is:
Super Publishing Co.
8 The Green, Ste B
Dover, Delaware 19901
United States.
Super.so enables content created in Notion to be published and delivered as a website.
When our website is accessed, Super.so processes technically necessary data, which may include the user’s IP address, browser type and version, device information, the requested page, and access and error logs.
The processing is carried out to deliver our website and ensure its stability, functionality and security. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of our website.
Super.so processes this data as a processor under an agreement pursuant to Article 28 GDPR. Super.so uses additional subprocessors to provide its service, particularly hosting, content-delivery and technical-infrastructure providers.
The data is deleted when it is no longer required to provide, secure or troubleshoot the website, unless legal retention obligations or legitimate reasons require longer storage.
Because Super Publishing Co. is established in the United States and may use subprocessors outside the European Economic Area, processing in third countries cannot be excluded. Where no adequacy decision by the European Commission applies, transfers are based in particular on the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR and supplementary safeguards.
Further information is available at:
https://super.so/data-processing-agreement
Notion
The content of our website is created and managed using Notion. The provider is:
Notion Labs, Inc.
685 Market Street
San Francisco, CA 94105
United States.
Content stored in Notion is published as a website through Super.so. Super.so lists Notion Labs, Inc. as a subprocessor for content storage and source data.
This integration may involve processing the content and settings stored in Notion. Where content or files are retrieved directly from Notion, technically necessary connection data may also be processed, including the IP address, browser and device information, and the time and nature of the request.
The purpose of the processing is to create, manage and provide our website. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the reliable and efficient management and publication of our website content.
Notion states that it processes customer data as a processor and according to the customer’s instructions. Data is deleted when it is no longer required for these purposes, unless legal retention obligations or legitimate reasons require further storage.
Because Notion Labs, Inc. is established in the United States, the transfer of personal data to the United States cannot be excluded. Notion states that it is certified under the EU-US Data Privacy Framework. In addition, Notion’s Data Processing Addendum incorporates the European Commission’s Standard Contractual Clauses for international data transfers.
Further information is available at:
https://www.notion.com/help/privacy
https://www.notion.com/privacy
LinkedIn company page
We maintain a company page on LinkedIn and link to it from this website. A simple hyperlink does not establish a connection to LinkedIn until you click it.
The provider for users in the European Economic Area is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, United States, is an affiliated company.
If you follow the link, your browser connects to LinkedIn. LinkedIn may process your IP address, browser and device information, referrer information and the date and time of access. If you are logged in to LinkedIn, LinkedIn may associate your visit with your account.
LinkedIn processes the data received through its services under its own responsibility. LinkedIn Ireland shares certain personal data with LinkedIn Corporation in the United States. LinkedIn states that it uses the EU-U.S. Data Privacy Framework and the European Commission's Standard Contractual Clauses for relevant international transfers.
Further information is available at:
LinkedIn information on EU/EEA data transfers
Google Analytics 4
With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States, is an affiliated company.
Google Analytics helps us understand how visitors use the website and improve its content and performance. The Google Analytics library is not loaded until you consent to statistics cookies through Cookiebot. If you do not consent, we do not load Google Analytics and do not send analytics data to Google.
Once consent has been granted, Google Analytics may process information including page views, session and interaction data, approximate location, browser and device information, referrer information and technical identifiers. Google states that it does not log or store individual IP addresses of users in the EU. IP addresses are used in the EU for deriving approximate location information and are then discarded before the data is logged.
Google Signals and advertising-personalisation features are disabled in our implementation. We do not use Google Analytics on this website for personalised advertising or cross-device advertising profiles.
The legal bases are your consent under Article 6(1)(a) GDPR and, where information is stored on or accessed from your device, Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future through the cookie settings.
In our GA4 property, the retention period for user-level and event-level data is set to 2 months, and these data are deleted automatically once that period expires. User-level and event-level data are deleted after the configured retention period; aggregated reports may be retained for longer where they no longer permit us to identify individual users.
Google may process data in the United States and other third countries. Google LLC participates in the EU-U.S. Data Privacy Framework. Where required, Google also uses other safeguards, including the European Commission's Standard Contractual Clauses.
Further information is available at:
Google Analytics information for EU users
Google data-transfer frameworks
Location map and OpenStreetMap link
We display a static location illustration based on OpenStreetMap data. The image is delivered through Amazon S3, as described in the “Amazon Web Services / Amazon S3” section, and is not loaded from OpenStreetMap servers.
The illustration includes a link to the interactive map on openstreetmap.org. A simple hyperlink does not establish a connection to OpenStreetMap until you click it. After you click the link, your browser connects to services operated by the OpenStreetMap Foundation. The OpenStreetMap Foundation may process connection and usage data, including your IP address, browser and device information, referrer information, the requested page and the date and time of access, under its own responsibility.
Further information is available at:
OpenStreetMap Foundation Privacy Policy
OpenStreetMap copyright and licence information
Map data © OpenStreetMap contributors, available under the Open Database License.
Google Fonts
This website currently retrieves the “Work Sans” font from Google Fonts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. To deliver the stylesheet and font files, your browser connects to Google servers. In doing so, Google receives technically necessary connection data, in particular your IP address, browser and device information, the requested resource, referrer information and the date and time of the request.
The processing serves the consistent and efficient presentation of the website. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in a consistent, readable and technically efficient presentation of our website. Google may process data in the United States and other third countries. Google LLC participates in the EU-U.S. Data Privacy Framework and, where required, uses additional safeguards such as the European Commission's Standard Contractual Clauses.
Further information is available in the Google Privacy Policy and under Google data-transfer frameworks.
Amazon Web Services / Amazon S3
We use Amazon Simple Storage Service (Amazon S3) to store and deliver image files used on this website. The files are delivered from an AWS region in the European Union. The provider for customers in the European Economic Area is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg.
When an image is requested, AWS processes technically necessary connection data, including the IP address, browser and device information, the requested file, referrer information and the date and time of the request. The processing is necessary to deliver the images reliably, securely and efficiently. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and performant provision of our website content.
AWS processes relevant data on our behalf under its data-processing terms. Access from or processing in third countries cannot be completely excluded. AWS states that it uses the EU-U.S. Data Privacy Framework and, where required, the European Commission's Standard Contractual Clauses and supplementary safeguards for international transfers. Technical log data are deleted or anonymised when no longer required for delivery, security and error analysis, subject to legal retention obligations.
Further information is available at:
Parts of this Privacy Policy are based on the Model Data Protection Statement provided by Anwaltskanzlei Weiß & Partner