Privacy Policy

TOPTICA EAGLEYARD

We are delighted that you have shown interest in our company. Data protection is a particularly high priority for the management of Eagleyard Photonics GmbH. The Eagleyard Photonics GmbH website can be used without providing any personal data; however, if a data subject wishes to use specific company services via our website, the processing of personal data may be necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain the consent of the data subject.

The processing of personal data such as the name, address, email address, or telephone number of a data subject always complies with the General Data Protection Regulation (GDPR) and the country-specific data protection regulations of Eagleyard Photonics GmbH. With this privacy policy, our company wishes to inform the public about the nature, scope, and purpose of the personal data we collect, use, and process. In addition, this privacy policy informs data subjects of their rights.

Persons under the age of 16 may not provide us with personal data unless the consent of their parents or legal guardians (holders of parental responsibility) has been given (Art. 8(1) GDPR). The consent must then be expressly noted in the message (Art. 8(2) GDPR). We do not request personal data from children and young people. We do not knowingly collect such data.

As the controller, Eagleyard Photonics GmbH has implemented numerous technical and organizational measures to ensure the most comprehensive protection of the personal data processed via this website. However, Internet-based data transmissions can in principle have security gaps, so absolute protection cannot be guaranteed. For this reason, anyone affected is free to transfer personal data to us by alternative means, e.g., by telephone.

1. Definitions

The privacy policy of Eagleyard Photonics GmbH is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our privacy policy should be readable and understandable for the general public as well as for our customers and business partners. To ensure this, we would first like to explain the terminology used.
In this privacy policy, we use the following terms, among others:

a) Personal data
Personal data is any information relating to an identified or identifiable natural person (“data subject”). A natural person is considered identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or one or more special characteristics that express the physical, physiological, genetic, psychological, economic, cultural, or social identity of that natural person.

b) Data subject

The data subject is any identified or identifiable natural person whose personal data is processed by the controller.

c) ProcessingProcessing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) Restriction of processing

Restriction of processing is the marking of stored personal data with the aim of limiting its processing in the future.

e) Profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

f) Pseudonymization

Pseudonymization is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific individual without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

g) Controller or controller responsible for processing

The controller or controller responsible for processing is the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

h) Processor

A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.

i) Recipient

The recipient is a natural or legal person, public authority, agency, or another body to which the personal data is disclosed, whether a third party or not. However, public authorities that receive personal data in the context of a particular inquiry in accordance with Union or Member State law shall not be considered recipients; the processing of such data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

j) Third party

A third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

k) Consent

The consent of the data subject is any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

2. Name and address of the controller

The controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in the Member States of the European Union, and other data protection regulations is:

Eagleyard Photonics GmbH
Rudower Chaussee 29
12489 Berlin
Germany
Phone: +49-30-6392-4520
Email: info@eagleyard.com
Website: www.eagleyard.com


Name and address of the data protection officer

The data protection officer within the meaning of the General Data Protection Regulation (GDPR), other data protection laws applicable in the member states of the European Union, and other data protection regulations is:

HBSN GmbH

Berliner Str. 52 F

38104 Braunschweig

Tel.: +49 531-230400-00

datenschutz@hbsn-gruppe.de


Responsible supervisory authority:
Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstr. 219; 10969 Berlin


3. Cookies

The websites of Eagleyard Photonics GmbH use cookies. Cookies are text files that are stored on a computer system via an Internet browser.
Many websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the cookie. It consists of a string of characters that can be used to assign websites and servers to the respective Internet browser in which the cookie was stored. This enables visited websites and servers to distinguish the individual browser of the data subject from other Internet browsers with other cookies. A specific Internet browser can be recognized and identified using the unique cookie ID.
By using cookies, Eagleyard Photonics GmbH can offer users of this website more user-friendly services that would not be possible without the cookie setting.
Cookies enable the information and offers on our website to be optimized for the user. As already mentioned, cookies enable us to recognize our website users. The purpose of this recognition is to make it easier for users to use our website. Website users who use cookies do not have to enter their login details every time they access the website, for example, as these are taken over by the website and the cookie is stored on the user’s computer system. Another example is the cookie used for a shopping cart in an online shop. The online shop remembers the items that a customer has placed in their virtual shopping cart via a cookie.
Necessary cookies—i.e., those that are required for communication with the server, desired functions (e.g., the shopping cart), or to improve the website (e.g., visitor statistics)—are generally stored on the basis of Art. 6 (1) lit. f GDPR, unless another legal basis applies. The website operator has a legitimate interest in setting these cookies in order to offer the services in a technically error-free and efficient manner. If consent to the use of cookies has been obtained, processing is carried out exclusively on the basis of this consent (Art. 6 (1) (a) GDPR; § 25 (1) TDDDG). Consent can be revoked at any time.
The data subject can prevent the setting of cookies via our website at any time by adjusting the settings of the Internet browser used and thus permanently reject the setting of cookies. In addition, cookies that have already been set can be deleted at any time via an Internet browser or other software programs. This is possible in all common Internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be fully usable.
You can find out which cookies and services are used on our website in this privacy policy.

Consent with Borlabs Cookie

Our website uses the consent technology “Borlabs Cookie”.
This allows us to ask you whether certain cookies or technologies may be stored or used in your browser.
The provider is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg.

When you visit the website, a so-called Borlabs cookie is stored in your browser. This cookie indicates whether you have given your consent or withdrawn your consent.
The information in this cookie is not passed on to the provider of Borlabs Cookie.
This information is stored by us until you request us to delete it or you delete the Borlabs cookie yourself from your browser – or until the storage purpose no longer applies.
Statutory retention periods remain unaffected.
For more information about what data Borlabs Cookie stores, please visit: https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.

The Borlabs cookie consent banner is used because we require your consent for certain cookies.
The legal basis for this is Art. 6 (1) (c) GDPR.4. Processing of general data and information

The Eagleyard Photonics GmbH website processes a range of general data and information when a data subject or an automated system accesses the website.
This data processing is regularly based on our legitimate interest (Art. 6 para. 1 lit. f GDPR), namely the proper provision and security of our website.
This general data and information is stored in the server log files. The following examples are recorded: (1) the browser types and versions used, (2) the operating system of the accessing system, (3) the website from which an accessing system reaches our website (so-called referrer), (4) the sub-websites, (5) the date and time of access to the website, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) all other similar data and information that can be used in the event of attacks on our information technology systems.
When using this general data and information, Eagleyard Photonics GmbH does not draw any conclusions about the subject concerned. Rather, this information is needed to (1) correctly convey the content of our website, (2) optimize both the content of our website and its advertising, (3) ensure the long-term viability of our information technology systems and website technologies, and (4) provide law enforcement agencies with the information necessary for criminal prosecution in the event of a cyberattack. Therefore, Eagleyard Photonics GmbH analyzes anonymously collected data and information statistically with the aim of increasing our company’s data protection and data security and ensuring an optimal level of protection for the personal data we process. The anonymous data in the server log files is stored separately from all personal data provided by a data subject.

5. Subscription to our newsletters

On the Eagleyard Photonics GmbH website, users have the option of subscribing to our company newsletter.
We require your consent as the legal basis for this (Art. 6 (1) (a) GDPR).
This newsletter is sent on the basis of your voluntary consent and your data will only be used for the purpose of sending the newsletter.The input mask used for this purpose determines which personal data is transferred and when the newsletter is ordered by the controller.
Eagleyard Photonics GmbH regularly informs its customers and business partners about business offers via a newsletter. The company’s newsletter can only be received by the data subject if (1) they have a valid email address and (2) the data subject registers for the newsletter. For legal reasons, a confirmation email is first sent to the email address registered by a data carrier as part of the double opt-in procedure before a newsletter is sent. This confirmation email serves to verify whether the owner of the email address is the data subject entitled to receive the newsletter.
During registration for the newsletter, we also store the IP address assigned by the Internet service provider (ISP) and used at the time of registration, as well as the date and time of registration. The collection of this data is necessary in order to understand the (possible) misuse of a data subject’s email address at a later date and therefore serves the purpose of legal protection for the controller.
The personal data collected during registration for the newsletter is used exclusively for the purpose of sending our newsletter and is not passed on to third parties. In addition, subscribers to the newsletter may be informed by email as long as this is necessary for the operation of the newsletter service or the relevant registration, as this may apply in the event of changes to the newsletter offering or changes in the technical situation. No personal data collected by the newsletter service will be transferred to third parties. The data subject can unsubscribe from our newsletter at any time. The consent to the storage of personal data given by the data subject for the purpose of sending the newsletter can be revoked at any time withoutdisadvantage. For the purpose of revoking consent, a corresponding link is provided in each newsletter. It is also possible to unsubscribe from the newsletter at any time directly on the controller’s website or to communicate this to the controller in another way.

6. Newsletter tracking

The Eagleyard Photonics GmbH newsletter contains so-called tracking pixels. A tracking pixel is a miniature graphic embedded in such emails and sent in HTML format to enable log recording and analysis. This enables a statistical analysis of the success or failure of online marketing campaigns. Based on the embedded tracking pixel, Eagleyard Photonics GmbH can see if and when an email was opened from a data carrier and which links in the email were accessed by the data subjects.
The personal data collected in the tracking pixels contained in the newsletters is stored and analyzed by the controller, , in order to optimize the sending of the newsletter and to better tailor the content of future newsletters to the interests of the data subject. This personal data is not passed on to third parties. Data subjects have the right to revoke their separate declaration of consent at any time as part of the double opt-in procedure. After revocation, this personal data will be deleted by the controller. Eagleyard Photonics GmbH automatically considers withdrawal from receiving the newsletter as revocation.

7. Contact via our website and microsite “Give me a name”

The Eagleyard Photonics GmbH website contains information that enables quick electronic contact with our company and direct communication with us, including a general address, i.e., an email address. If a data subject contacts the controller by email, via a contact form, or via the microsite “Give me a name” (toptica-eagleyard.com/givemeaname), the personal data transmitted by the data subject will be stored automatically. Such personal data, which is voluntarily transmitted by a data subject to the controller, is stored for the purpose of processing or contacting the data subject. This personal data is not transferred to third parties.

8. Routine deletion and blocking of personal data

The controller processes and stores the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as far as this is granted by European legislators or other legislators in laws or regulations to which the controller is subject.
If the storage purpose is no longer applicable or a storage period prescribed by European legislators or other competent legislators expires, the personal data is routinely blocked or deleted in accordance with legal requirements.

9. Rights of the data subject

a) Right of confirmation

Every data subject has the right granted by European legislators to obtain confirmation from the controller as to whether personal data concerning him or her is being processed. If a data subject wishes to exercise this right of confirmation, he or she may contact an employee of the controller at any time.

b) Right of access

Every data subject has the right granted by European legislators to obtain from the controller, at any time and free of charge, information about his or her stored personal data and a copy of this information. In addition, European directives and regulations grant data subjects access to the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom personal data have been or will be disclosed, in particular recipients in third countries or international organizations;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the right to request the controller to rectify or erase personal data, to restrict the processing of personal data concerning the data subject, or to object to such processing;
  • the existence of the right to lodge a complaint with a supervisory authority;
  • if the personal data is not collected from the data subject, any available information about its origin;
  • the existence of automated decision-making, including profiling, as referred to in Article 22 (1) and (4) of the GDPR, and, at least in those cases, meaningful information about the logic involved and the significance and intended consequences of such processing for the data subject.

You have the right to lodge a complaint with the competent supervisory authority, in particular with the Data Protection and Freedom of Information Commissioner in Berlin or with the supervisory authority in the Member State of your residence, place of work, or alleged data breach, if you believe that our processing of your personal data violates applicable data protection laws.
In addition, the data subject has the right to obtain information on whether personal data is transferred to a third country or to an international organization. In this case, the data subject has the right to be informed of the appropriate safeguards relating to the transfer.
If a data subject wishes to exercise this right of access, he or she may contact a member of staff of the controller at any time.

c) Right to correction

Every data subject has the right granted by European law to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

If a data subject wishes to exercise this right to rectification, he or she may contact an employee of the controller at any time.

d) Right to erasureEvery data subject has the option of requesting the erasure of their personal data stored by us stored with us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense legal claims.
However, this presupposes that the purposes for processing have ceased to apply, or that you have objected to the processing pursuant to Article 21 GDPR, you have revoked your consent in accordance with Article 7 GDPR, or the processing is unlawful.

e) Right to restriction of processing

Every data subject has the right granted by European law to obtain from the controller restriction of processing where one of the following applies:

  • The accuracy of the personal data is contested by the data subject for a period enabling the controller to verify the accuracy of the personal data.
  • The processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead.
  • The controller no longer needs the personal data for processing, but it is required by the data subject for the establishment, exercise, or defense of legal claims.
  • The data subject has objected to the processing pursuant to Article 21(1) of the GDPR pending verification whether the legitimate grounds of the controller override those of the data subject.

If any of the above conditions are met and a data subject wishes to request the restriction of the processing of personal data stored by Eagleyard Photonics GmbH, they may contact an employee of the controller at any time. The employee of Eagleyard Photonics GmbH will arrange for the restriction of processing.

f) Right to data portability

Every data subject has the right, granted by European legislation, to receive the personal data concerning him or her, which has been provided to a controller, in a structured, commonly used, and machine-readable format. He or she has the right to transmit this data to another controller without hindrance from the controller to whom the personal data has been transmitted, as long as the processing is based on consent pursuant to point (a) of Article 6(1) of the GDPR or point (a) of Article 9(2) of the GDPR.
Or on a contract pursuant to point (b) of Article 6(1) of the GDPR and the processing is carried out by automated means, as long as the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
In addition, when exercising their right to data portability pursuant to Article 20(1) of the GDPR, the data subject has the right to have personal data transferred directly from one controller to another, provided that this is technically feasible and does not adversely affect the rights and freedoms of others.
To exercise the right to data portability, the data subject may contact any employee of Eagleyard Photonics GmbH at any time.

g) Right to objectRight of withdrawal of consent pursuant to Art. 7 (3) GDPR

You have the right to withdraw your consent from us at any time. As a result, we will no longer be allowed to continue processing data based on this consent in the future.

Right to object pursuant to Article 21 GDPR
If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) (f) GDPR, you have the right to object to the processing of your personal data if there are reasons for this arising from your particular situation or if the objection is directed against direct marketing.
In the latter case, you have a general right to object, which we will implement without you having to specify a particular situation.
If you wish to exercise your right of withdrawal or objection, please contact an employee of Eagleyard Photonics GmbH at any time.

h) Automated individual decision-making, including profiling

Every data subject has the right granted by European legislation not to be subject to a decision based solely on automated processing, including profiling, which has legal effects on him or her or similarly significantly affects him or her, as long as the decision (1) is not necessary for entering into or performing a contract between the data subject and a data controller, or (2) is not authorized by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, or (3) is not based on the data subject’s explicit consent.
If the decision (1) is necessary for entering into, or performance of, a contract between the data subject and the controller, or (2) is based on the explicit consent of the data subject, Eagleyard Photonics GmbH shall implement appropriate measures to safeguard the rights and freedoms and the legitimate interests of the data subject, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
If the data subject wishes to exercise their rights regarding automated individual decision-making, they may contact an employee of Eagleyard Photonics GmbH at any time.

i) Right to lodge a complaint

Every data subject has the right to lodge a complaint with a supervisory authority. To do so, you can contact the supervisory authority of your usual place of residence or workplace or our headquarters.

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59-61
10555 Berlin
Tel.
Fax
Email: mailbox@datenschutz-berlin.de

10. Data protection provisions regarding the application and use of Google Analytics (with anonymization function)

The controller has integrated the Google Analytics component (with the anonymization function) into this website. Google Analytics is a web analytics service. Web analytics is the collection and analysis of data about the behavior of visitors to websites. A web analytics service collects, among other things, data about the website from which a person originates (the so-called referrer), which subpages were visited, or how often and for how long a subpage was viewed. Web analytics are mainly used to optimize a website and to perform a cost-benefit analysis of Internet advertising.
We use Google Analytics on the basis of the consent of the data subject; the legal basis for this is Art. 6 (1) (a) GDPR.

The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, United States.

For web analysis via Google Analytics, the controller uses the application “_gat. _anonymizeIp”. This application shortens and anonymizes the IP address of the data carrier’s Internet connection when we access our websites from a member state of the European Union or another contracting state to the European Economic Area.
The purpose of the Google Analytics component is to analyze traffic on our website. Google uses the collected data and information, among other things, to evaluate the use of our website and to provide online reports showing the activities on our websites, as well as to offer us further services for the use of our website.

Google Analytics places a cookie on the information technology system of the data subject. The definition of cookies is explained above. By setting the cookie, Google can analyze the use of our website. Each time one of the individual pages of this website operated by the controller and into which a Google Analytics component has been integrated is accessed, the Internet browser on the information technology system of the data subject automatically transmits data via the Google Analytics component for the purpose of online advertising and commission processing to Google. In the course of this technical process, Google obtains personal information, such as the IP address of the data subject, which Google uses, among other things, to understand the origin of visitors and clicks and then to generate commission comparisons.
The cookie is used to store personal data, such as the access time, access location, and frequency of visits by the data subject to our website. Each time our website is visited, such personal data, including the IP address of the Internet access used by the data subject, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may pass on this personal data collected through the technical process to third parties.
As stated above, the data subject can prevent the setting of cookies via our website at any time by adjusting the settings of the web browser used and thus permanently reject the setting of cookies. Such an adjustment of the Internet browser used would also prevent Google Analytics from setting a cookie on the IT system of the data subject. In addition, cookies already used by Google Analytics can be deleted at any time via a web browser or other software programs.

Furthermore, the data subject has the option of objecting to data processing generated by Google Analytics relating to the use of this website, as well as to the processing of this data by Google, and the option of excluding such processing. To do this, the data subject must download and install a browser add-on from the link https://tools.google.com/dlpage/gaoptout. This browser add-on informs Google Analytics via JavaScript that data and information about visits to websites may not be transmitted to Google Analytics. The installation of the browser add-ons is considered by Google as an objection. If the information technology system of the data subjects is later deleted, formatted, or reinstalled, the data subject must reinstall the browser add-ons to disable Google Analytics. If the browser add-on has been uninstalled or deactivated by the person concerned or another person assigned to their area of responsibility, it is possible to reinstall or reactivate the browser add-ons.
Further information and Google’s applicable privacy policy can be found at
https://www.google.com/intl/en/policies/privacy/
and at
http://www.google.com/analytics/terms/us.html.
Google Analytics is explained in more detail at the following link: https://www.google.com/analytics/.
Alternatively, you can disable future analysis of your website visit by Google Analytics by clicking on the link below. Clicking on the link will configure a so-called “opt-out cookie,” which means that the analysis of your visit to our site will be prevented in the future:

Activate the “opt-out cookie” for Google Analytics!

Please note that if you delete cookies in your browser settings, this may also delete the opt-out cookie and you may need to reactivate it.


11. Use of Google Tag Manager

We use Google Tag Manager on our website.
The provider of this service is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that enables us to integrate and manage tracking and statistics tools as well as other technologies on our website.
Google Tag Manager itself does not create user profiles, set cookies, or perform any independent analyses.
Its function is limited to managing and deploying the tools integrated through it.
However, Google Tag Manager collects your IP address.
This may also be transferred to Google’s parent company in the United States.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time.
The transfer of data to the United States is based on the European Commission’s Standard Contractual Clauses.
Further details can be found at the following link: https://privacy.google.com/businesses/controllerterms/mccs/.
The company is certified under the “EU-US Data Privacy Framework” (DPF).
The DPF is an agreement between the European Union and the United States that is intended to ensure compliance with European data protection standards when data is processed in the United States.
Every company certified under the DPF undertakes to comply with these data protection standards.
Further information is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780

12. Analysis by Leadinfo

This website uses the service provided by Leadinfo B.V., based in Rotterdam. This service shows us publicly available company data based on IP addresses, such as company names and addresses. Companies are identified solely on the basis of IP addresses. IP addresses are not stored after use.
In addition to this recognition via IP addresses, two first-party cookies are used to provide us with information about how visitors use the website (analytics). These cookies are not linked to any other information and nothing is shared with third parties. The legal basis for data processing is Art. 6 (1) (a) GDPR.
Objection to data collection:
If you wish to opt out of data collection (tracking), please click on the corresponding button at: https://www.leadinfo.com/de/opt-out/ Order data processing:
We have entered into a contract with Leadinfo for commissioned data processing and implement the data protection requirements.

Contact: Leadinfo:
Leadinfo B.V. Rivium
Quadrant 141
2909 LC Capelle aan den IJssel
Netherlands
, hello(at)leadinfo.com+
49 322 2109 6861

13.Use of a Content Delivery Network (CDN) via bunny.net
To optimise loading speeds, improve availability and reduce the load on our server, we use a Content Delivery Network (“CDN”) provided by bunny.net d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia, or its affiliated companies and technical infrastructure.
A CDN is a globally distributed network of specialised servers through which static content such as images, various files and fonts can be delivered. Delivery typically takes place via the geographically nearest server location, thereby reducing loading times and enabling our website to be served more efficiently.
When you visit our website, a connection is established with the servers of bunny.net, provided that content is delivered via the CDN. In doing so, technically necessary connection data is processed, in particular the IP address, the URL accessed, the date and time of access, and other browser- and device-related information. According to bunny.net, visitor log data is processed for analysis, processing, testing and security purposes; IP addresses are anonymised by default.
We have concluded a data processing agreement with bunny.net in accordance with Article 28 of the GDPR.
bunny.net processes the relevant data on our behalf for the technical provision of the CDN service. According to bunny.net, the log data is stored for three days by default.

The use of the CDN is based on our legitimate interest in the secure, stable and efficient provision of our online service in accordance with Article 6(1)(f) of the GDPR.

Where consent is obtained for specific processing operations, processing takes place exclusively on the basis of this consent in accordance with Article

6(1)(a) of the GDPR.

bunny.net operates a global server network with locations across several continents. Depending on the user’s location, data may therefore be processed in different regions in order to deliver content from the nearest server location.
If a user is located in the EU, data processing is guaranteed to take place only on servers that are also located in the EU.
Further information on data processing by bunny.net can be found in bunny.net’s privacy policy (https://bunny.net/privacy) as well as in the information on data protection and logging provided there.

14. Data protection provisions regarding the application and use of
Friendly Captcha


The Friendly Captcha service from Friendly Captcha GmbH, Am Anger 3-5,
82237 Woerthsee, Germany, is an innovative, privacy-friendly protection solution that makes it difficult for automated programs and scripts (“bots”) to use websites. Friendly Captcha thus protects websites from misuse.
The service user integrates the Friendly Captcha program code into specific areas of their website (e.g., in a contact form).
This means that the visitor’s device is connected to Friendly Captcha’s servers in the context of the protected area (e.g., when sending a contact form).
The visitor’s browser receives a puzzle from Friendly Captcha.
The complexity of the puzzle depends on various risk factors.
The visitor’s device solves the puzzle using certain system resources and sends the solution to the service user’s web server.
The service user’s server contacts the Friendly Captcha server via an interface and receives a response indicating whether the puzzle has been solved correctly by the end device.
The visitor’s browser transmits connection data, environmental data, interaction data, and functional data to Friendly Captcha.
Friendly Captcha analyzes this data and determines how likely it is that the visitor is a human user or a bot; it then transmits the result to the service user.
Depending on the result, the service user can treat access to their website or individual functions as human or potentially non-human.
For more information on data protection when using Friendly Captcha and on information processed on the end device, please refer to the privacy policy of the service user who has implemented Friendly Captcha on their website.
All data is used exclusively to identify and deal with potential bots and risks as described above.
The purpose of processing is therefore to ensure the security and functionality of websites.
Friendly Captcha does not use the data to identify a natural person or for marketing purposes.
Friendly Captcha does not store any personal data of the visitor. Data that could identify the visitor, such as IP addresses, is anonymized through one-way hashing.
Friendly Captcha does not use HTTP cookies and does not store any data in the browser’s persistent memory.15. Data protection provisions regarding the application and use of Vimeo

We integrate functional and content elements of the Vimeo video player into our online offering.
Service provider: Vimeo Inc., Attention: Legal Department, 555 West 18th Street New York, New York 10011, USA;
Website: https://vimeo.com;
Privacy policy: https://vimeo.com/privacy;
Data processing agreement: https://vimeo.com/enterpriseterms/dpa;
Basis for third-country transfers: Standard contractual clauses (https://vimeo.com/enterpriseterms/dpa).
This may include images or videos in particular (hereinafter collectively referred to as “content”).
The relevant content is loaded from Vimeo’s servers.
Insofar as Vimeo delivers content to users, it is necessary to process the users’ IP addresses, as the content cannot be transmitted to the respective browser without knowledge of the IP address. The IP address is therefore technically necessary for the provision of the content.
Vimeo may also use so-called pixel tags (invisible graphics, also known as “web beacons”) to collect usage and marketing data and evaluate it statistically. Information obtained through such processes may be stored in pseudonymous form in cookies on the user’s device and may contain technical information about the browser and operating system, referring websites, visit times, and information about the use of our online offering. This data may be merged with information from other sources.

  1. Legal basis
    If we have obtained the prior consent of users for the use of specific third-party providers, the consent given forms the legal basis for the respective data processing
    (Art. 6 (1) (a) GDPR).
    If no consent has been obtained, we base the processing on our legitimate interest in the efficient, economical, and user-friendly provision of our online offering
    (Art. 6 (1) (f) GDPR).
  2. Categories of processed data
    – Usage data, e.g., page views, length of stay, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions;
    – Meta, communication, and procedural data, e.g., IP addresses, time stamps, identification numbers, persons involved, if applicable.
  3. Data subjects
    Users of our online offering.

Purposes of processing
Processing is carried out for the purpose of providing the integrated content and to ensure and improve the user-friendliness of our online offering.

16. AI-powered chatbot (SleekAI / OpenAI)

We use an AI-powered chatbot on our website, which is technically provided via the WordPress plugin SleekAI (Dennis Josek, Paul-Robeson-Straße 49, 10439 Berlin, Email: hi@dennn.is).

The plugin serves as an integration and deployment component between the chat widget embedded on our website, our server and the OpenAI API we use (OpenAI, L.L.C., 3180 18th St., San Francisco, California 94110, USA).

The chatbot assists us in responding to enquiries about our products, our services and frequently asked questions.

Rules of conduct for use

When using the AI chatbot, please ensure that no sensitive personal data (e.g. ID details, health data, bank details) or confidential trade secrets are entered into the chat.

Content that you provide in the chat may be transmitted to OpenAI and may also be stored in logs.

For confidential matters, please use the standard contact form or contact our support team directly.

Data Controller

The data controller responsible for data processing in connection with the chatbot is:

EAGLEYARD Photonics GmbH

Rudower Chaussee 29

12489 Berlin

Telephone: +49 30 6392 452-0

info@toptica-eagleyard.com

Service Providers and Recipients

We use the WordPress plugin SleekAI to operate the chatbot.

Insofar as the plugin itself processes personal data or transfers it to third parties, this is done exclusively within the scope of the technical provision

of the chatbot and in accordance with the configuration actually used by us.

To generate responses, the chat content you enter is transferred to OpenAI, Inc. OpenAI processes the data in this context as a data processor on the basis of a data processing agreement in accordance with Article 28 of the GDPR. Where personal data is transferred to third countries, OpenAI relies on appropriate transfer mechanisms in accordance with the applicable contractual provisions, in particular standard contractual clauses or other applicable safeguards.

Data processed

When using the chatbot, the following data in particular may be processed:

– the chat messages and other content you enter,

– technical metadata, in particular the time of the request,

– a server-side identifier or the IP address of our proxy server,

– pseudonymised or hashed information for the purpose of preventing misuse and

limiting incorrect or abusive use,

– session information to maintain the conversation context,

– chat logs

The end user’s IP address is not transmitted to OpenAI. Processing in this regard takes place solely on our own system and exclusively in pseudonymised form for the purposes of preventing misuse and ensuring the technical security of the service.

Purposes of processing

Processing is carried out exclusively for the following purposes:

– Provision and technical operation of the AI chatbot,

– Responding to your enquiries,

– Maintaining the context of the conversation,

– Monitoring for misuse and security checks,

– Optional documentation of chat histories for quality assurance and

processing of follow-up enquiries.

No processing takes place for advertising, profiling or other third-party purposes.

Legal basis

Where the chatbot is used, the processing of personal data is based on your consent in accordance with Article 6(1)(a) of the GDPR.

Where information is stored on or read from the end device, this is done on the basis of Section 25(1) of the TTDSG, provided that such consent is required.

Where personal data is transferred to OpenAI in a third country, this is also carried out solely on the basis of your express consent in accordance with Article 49(1)(a) of the GDPR, provided that no other permissible basis for transfer can be invoked in the specific case for the transfer in question.

Consent and activation of the chatbot

The chatbot is only loaded after you have given your active consent via our consent/cookie banner. The chatbot is not used until you have given your consent. You may withdraw your consent at any time with future effect by changing the relevant settings in the consent banner or by deactivating the chatbot.

Data transfer to third countries

Where personal data is transferred to OpenAI in the USA, this constitutes a transfer to a third country outside the European Union. OpenAI processes the data on the basis of contractual safeguards, in particular the Data Processing Addendum and the standard contractual clauses provided therein, or an applicable adequacy decision.

https://openai.com/de-DE/policies/data-processing-addendum

Please note that, despite contractual and technical safeguards, there may be a residual risk when processing data in third countries, particularly with regard to access by the authorities of the third country.

No use for training purposes

Data transmitted via the OpenAI API is not, as a rule, used for training or improving OpenAI models.

However, OpenAI maintains so-called abuse monitoring logs by default; these may contain the content of requests and responses and are generally retained for up to 30 days in accordance with current guidelines, unless longer retention is required by law.

Cookies and local storage

The chatbot uses session mechanisms in the browser to maintain the conversation history during your visit. This data is retained only for the duration of your session.

The chatbot itself does not store any data permanently on the end device.

The chatbot does not set any analytics or marketing cookies. External tracking tools are not used in connection with the chatbot.

Retention period

Where chat histories are stored on our server, they are retained only for the period necessary and in accordance with our data retention policy. We currently store these chat histories for 30 days, after which they are automatically deleted.

By giving your consent, you agree to the storage of chat logs; these may be stored in our database for up to 30 days for documentation or service purposes and to prevent misuse.

After this period, these logs are automatically deleted.

Pseudonymised or hashed IP-related data for the purpose of preventing misuse is only stored for a short period and is regularly deleted.

At OpenAI, data is stored in accordance with their API data controls.

17. Legal basis for processing

Art. 6 (1) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is party, as is the case, for example, when processing measures are necessary for the delivery of goods or the provision of a other service, the processing is based on Article 6(1)(b) GDPR. The same applies to processing operations that are necessary for the implementation of pre-contractual measures, for example in the case of inquiries about our products or services. If our company is subject to a legal obligation that requires the processing of personal data, for example to fulfill tax obligations, then the processing is based on Article 6(1)(c) GDPR.
In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor to our company were injured and their name, age, health insurance details, or other important information had to be passed on to a doctor, hospital, or other third party. In this case, the processing would be based on Art. 6 (1) (f) GDPR. Finally, processing operations may be based on Art. 6 (1) (f) GDPR. This legal basis is used for processing operations that do not fall under the above legal bases, provided that the processing is necessary for the legitimate interests pursued by our company or third parties, unless these interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data. Such processing operations are particularly permissible as they have been expressly mentioned by the European legislator. It considered that a legitimate interest could be assumed if the data subject is a customer of the controller (Recital 47, sentence 2 GDPR).

18. The legitimate interests pursued by the controller or by a third party

If the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is to conduct our business in the interests of all our employees and shareholders.

19. Period for which the personal data will be stored

The criterion for determining the storage period for personal data is the respective statutory retention period. After this period has expired, the corresponding data is routinely deleted, provided that it is no longer required for the performance of the contract or the initiation of a contract.

20. Provision of personal data as a statutory or contractual requirement; prerequisite for concluding a contract; obligation of the data subject to provide the personal data; possible consequences of failure to provide such data

We clarify that the provision of personal data is sometimes required by law (e.g., tax regulations) or may also result from contractual provisions (e.g., information about the contractual partner). Sometimes it may be necessary to conclude a contract in which the data subject provides us with personal data that we must then process. For example, the data subject is obliged to provide us with personal data when our company enters into a contract with him or her. Failure to provide personal data would result in the contract with the data subject not being concluded. Before personal data is provided by the data subject, the data subject must contact each employee. The employer shall inform the data subjects whether the provision of personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and what the consequences of not providing the personal data are.

21. Existence of automated decision-making

As a responsible company, we do not use automated decision-making or profiling.

MENU

PRODUCTS

APPLICATION

COMPANY

NEWS

CONTACT

CONTACT

EAGLEYARD Photonics GmbH
Rudower Chaussee 29
12489 Berlin

Fon: +49 30 6392 452-0
info@toptica-eagleyard.com

CREDENTIALS

EYP Chatbot

Copyright © 2022 TOPTICA EAGLEYARD