1. Data Protection at a Glance
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations at all times.
Personal data means all data that can be used to identify you personally. Data is collected when you provide it to us, for example by contacting us, and automatically or after your consent when you visit the website, primarily as technical data.
Part of the data is collected to ensure error-free provision of the website. Other data may be used to analyze user behavior.
You have the right to receive information free of charge about the origin, recipients, and purpose of your stored personal data, and to request rectification, deletion, restriction of processing, or revocation of consent. You also have the right to lodge a complaint with the competent supervisory authority.
2. Controller
The controller responsible for data processing on this website is CP Medical Technology GmbH, Lindenstraße 24, 59387 Ascheberg, Germany.
Phone: +49 2599 501 95-0
Email: info@cp-medtec.com
Cookies and Storage Period
Our internet pages use cookies. Session cookies are deleted automatically after your visit; other cookies remain stored until you delete them. You can configure your browser to restrict or delete cookies, although deactivating cookies may limit the functionality of this website.
Unless a more specific storage period is specified, personal data remains with us until the purpose for data processing no longer applies. If you request deletion or revoke consent, data will be deleted unless legally permissible grounds for storage remain.
3. Legal Bases and Recipient Information
Where you consent to processing, data is processed on the basis of Art. 6(1)(a) GDPR and, where applicable, Art. 9(2)(a) GDPR, Art. 49(1)(a) GDPR, and Section 25(1) TDDDG. Contractual, pre-contractual, legal-obligation, and legitimate-interest processing is based on Art. 6(1)(b), Art. 6(1)(c), or Art. 6(1)(f) GDPR as applicable.
In the course of business activities, personal data may be transferred to external parties where required for contract performance, legal obligations, legitimate interests, or another permitted legal basis. Processors are used only on the basis of a valid data processing agreement.
Data Subject Rights
You may revoke consent at any time with effect for the future. You have rights to object to processing in special cases and to direct marketing under Art. 21 GDPR, to lodge a complaint with a supervisory authority, to data portability, to access, rectification, deletion, and restriction of processing.
This site uses SSL/TLS encryption for security. The operators object to the use of imprint contact data for unsolicited advertising and reserve the right to take legal action against unsolicited promotional information.
5. Data Collection on This Website
The old website identified Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA, as hosting provider. Webflow may collect log files, including IP addresses, and use technologies required for display, functions, and security.
The old policy also described Cookiebot consent technology by Cybot A/S, server log files, contact form inquiries, and inquiries by email, telephone, or fax. Inquiry data is processed to handle requests and retained until deletion is requested, consent is revoked, or the processing purpose no longer applies, subject to statutory retention duties.
- Server log files may include browser type and version, operating system, referrer URL, hostname, time of request, and IP address.
- Contact and inquiry processing may rely on Art. 6(1)(b), Art. 6(1)(f), or Art. 6(1)(a) GDPR depending on the inquiry and consent status.
Contact Form Data
When you use the website contact form, we process your name, email address, optional telephone number, optional company, enquiry type, subject, optional product reference, message, technical submission metadata, and the recorded acknowledgement of this privacy notice.
The contact workflow stores submissions in Payload and sends notification and confirmation emails through the configured email provider, currently Resend where enabled. Recipient configuration, processor details, retention period, legal basis, and possible international-transfer safeguards must be reviewed and confirmed by the site owner and legal counsel before production use.
The privacy acknowledgement records the notice version, locale, source path, and timestamp. It is not acceptance of general terms and conditions and does not include marketing consent.
6. Analytics and Marketing Tools
The old policy named Google Tag Manager, Google Analytics, Google Ads, and Google Conversion Tracking as analytics and marketing tools. Where consent was requested, processing was described as based on Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Google Analytics IP anonymization was described as active. The policy referenced Google browser opt-out tools, Google privacy information, data processing agreements, Standard Contractual Clauses, and EU-US Data Privacy Framework certifications.
7. Plugins and Tools
The old policy named Google Fonts and Google Maps. It described connections to Google servers for uniform font display and map functionality, and referenced Google privacy information.
8. Applicant Data
Applications submitted through the website application form may include name, email address, optional telephone number, optional cover letter, optional earliest start date, the selected vacancy, technical submission metadata, consent records, and one CV PDF. Application documents are stored in private server-side storage and are only available to authenticated administrators after server-side file checks and malware scanning.
Processing is intended to decide on establishing an employment relationship. The intended legal bases and retention periods must be reviewed and confirmed by legal counsel before production use. The current implementation records the privacy notice version, locale, source path, and acceptance timestamp; this acknowledgement is not treated as acceptance of general terms and conditions.
Operational processors may include private infrastructure storage, a malware-scanning service such as ClamAV/clamd or an approved equivalent, and Resend or another configured email provider for confirmation and internal notification emails. Processor names, locations, transfer safeguards, and data processing agreements must be verified before production use.
Future-vacancy consideration is optional, unchecked by default, and recorded separately from the mandatory privacy acknowledgement. Applicant-pool retention periods must be reviewed before production use. Applicants may request withdrawal or deletion through the controller contact details above, subject to applicable statutory retention duties.
