Privacy Policy

Last updated: 31 August 2026

1. Controller

The controller responsible for the processing of personal data on this website (aterise.com, the "Site") within the meaning of the EU General Data Protection Regulation (GDPR) is:

Aterise GmbH Leopoldstrasse 31 80802 Munich, Germany

Represented by the Managing Director: Valeria Kisler
Email: info@aterise.com
Phone: +49 176 729 73657

2. Overview

We process personal data only where this is necessary to provide this Site and to respond to your inquiries. This policy explains which data we process, for which purposes, on which legal basis, how long we store it, and which rights you have.

3. Hosting and server log files

When you visit the Site, our hosting provider automatically collects and stores information that your browser transmits ("server log files"): the IP address, date and time of access, name of the accessed page or file, volume of data transferred, access status, browser type and version, operating system, device type, and the referrer URL.

We process this data to deliver the Site reliably and securely, to ensure its stability, and to detect, prevent, and investigate attacks and misuse. The legal basis is our legitimate interest in the secure and functional operation of the Site (Art. 6(1)(f) GDPR). Log data is not merged with other data sources and is deleted automatically after a short period, unless a specific entry must be retained longer to investigate a security incident.

Our hosting provider processes this data on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR.

4. Cookies

This Site uses only technically necessary cookies, i.e. cookies that are strictly required to display the Site and provide its basic functions. These cookies do not track you across websites and are not used for advertising or analytics purposes.

The storage of and access to strictly necessary cookies does not require consent (Section 25(2) of the German Telecommunications Digital Services Data Protection Act, TDDDG). Any associated processing of personal data is based on our legitimate interest in the technically error-free provision of the Site (Art. 6(1)(f) GDPR).

You can configure your browser to reject or delete cookies at any time; some functions of the Site may then be unavailable.

5. Contact form and inquiries

If you contact us via the Site, by email, or by phone, we process the data you provide (such as your name, email address, phone number, company, and the content of your message) in order to handle your inquiry and any follow-up questions.

The legal basis is Art. 6(1)(b) GDPR where your inquiry relates to the conclusion or performance of a contract with us, and otherwise our legitimate interest in responding to inquiries addressed to us (Art. 6(1)(f) GDPR).

We store inquiry data until the matter has been fully resolved, and beyond that only to the extent that statutory retention obligations apply or until statutory limitation periods have expired. Data that becomes part of a contractual relationship is retained in accordance with commercial and tax law (up to six or ten years, Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)).

6. Marketing communications

We use your contact details to respond to you and, where you have expressed interest in our services, to follow up on your specific inquiry.

We send newsletters or other marketing emails only with your prior express consent (Art. 6(1)(a) GDPR, Section 7(2) of the German Act Against Unfair Competition (UWG)). You may withdraw your consent at any time with effect for the future — for example via the unsubscribe link included in every such email. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

7. Recipients of personal data

We share personal data only with the following categories of recipients, and only to the extent necessary: our hosting provider (operation of the Site), our IT and email service providers (communication and administration), and — where applicable — professional advisers who are bound by confidentiality obligations. Service providers that process personal data on our behalf are bound by data processing agreements pursuant to Art. 28 GDPR. We do not sell personal data.

8. Transfers to third countries

We generally process personal data within the EU/EEA. Where a service provider processes personal data outside the EU/EEA, we do so only where an adequacy decision of the European Commission applies (Art. 45 GDPR) — for US providers, in particular certification under the EU–US Data Privacy Framework — or on the basis of appropriate safeguards such as the EU Standard Contractual Clauses (Art. 46 GDPR).

9. Storage periods

Unless a specific retention period is stated in this policy, we store personal data only for as long as it is necessary for the purpose for which it was collected, and thereafter only where statutory retention obligations require it. After that, the data is deleted or anonymized.

10. Your rights

You have the following rights with regard to your personal data:

  • Right of access (Art. 15 GDPR) — to obtain confirmation as to whether we process your personal data, and a copy of that data;
  • Right to rectification (Art. 16 GDPR) — to have inaccurate data corrected and incomplete data completed;
  • Right to erasure (Art. 17 GDPR) — to have your data deleted where the legal conditions are met;
  • Right to restriction of processing (Art. 18 GDPR);
  • Right to data portability (Art. 20 GDPR) — to receive the data you provided to us in a structured, commonly used, machine-readable format;
  • Right to withdraw consent (Art. 7(3) GDPR) — where processing is based on your consent, you may withdraw it at any time with effect for the future.

Right to object (Art. 21 GDPR): Where we process your personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. Where personal data is processed for direct marketing purposes, you may object at any time without giving reasons; we will then no longer process your data for this purpose.

To exercise any of these rights, please contact us at info@aterise.com.

11. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority competent for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
https://www.lda.bayern.de

12. Obligation to provide data; automated decision-making

You are neither legally nor contractually required to provide personal data on this Site. However, without your contact details we will not be able to respond to your inquiry. We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

13. Security

We use appropriate technical and organizational measures to protect your personal data against loss, misuse, and unauthorized access, including TLS encryption of this Site. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Changes to this Privacy Policy

We update this Privacy Policy when our processing activities or legal requirements change. The current version, including its date, is always available on this page.