Skip to main content
Elivdium ← Back to website

Data protection

Privacy Policy

Effective date: 27 July 2026

1. Controller

The controller responsible for the processing of personal data in connection with this website is:

Elivdium GmbH
Ute-Strittmatter-Straße 10
81248 Munich
Germany

Email: contact@elivdium.com

No data protection officer has been appointed.

2. Hosting and server log files

This website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (“STRATO”). STRATO operates its core hosting infrastructure in data centres in Berlin and Karlsruhe, Germany, and processes hosting data on our behalf under a data processing agreement pursuant to Article 28 GDPR.

When you access this website, technical access data are automatically processed in server log files. These data may include the IP address of the accessing device, the date and time of access, the requested page or file, the HTTP request method and status code, the volume of data transferred, the referring page, and browser, operating-system and user-agent information.

The processing is necessary to deliver the website, ensure its technical stability and security, identify and defend against attacks, investigate technical errors and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable and technically reliable operation of the website and the protection of our systems.

According to STRATO, complete visitor IP addresses are retained for a maximum of seven days for the identification and defence against attacks. Access log files made available through the STRATO customer account are anonymised and may be available for up to six weeks.

3. Contact by email

If you contact us by email, we process the information you provide, such as your name, contact details, organisation, the content of your enquiry and related communication, in order to respond to and manage your request.

Where your enquiry relates to a contract or steps requested before entering into a contract, the legal basis is Article 6(1)(b) GDPR. For other business enquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the efficient handling of business communications. Where processing is necessary to comply with a legal obligation, the legal basis is Article 6(1)(c) GDPR.

Providing information is voluntary. However, we may be unable to process your request if the information required to respond is not provided.

We delete enquiry data when the matter has been finally resolved and the data are no longer required, unless statutory retention obligations, the establishment, exercise or defence of legal claims, or another lawful purpose requires longer storage.

Please do not send health information, patient data or other highly confidential information to the general contact address unless we have expressly requested it and an appropriate secure communication channel has been agreed.

4. External links, including LinkedIn

This website contains ordinary links to external websites, including LinkedIn. No data are transmitted to LinkedIn merely because a normal text or image link is displayed on this website.

When you click an external link, you leave our website. The operator of the linked website then processes personal data under its own responsibility and in accordance with its own privacy information. We have no control over that processing. LinkedIn or other linked providers may process data outside the European Economic Area.

5. Local privacy settings and necessary browser storage

The website uses a local, first-party privacy-settings manager. It does not contact an external consent-management provider and does not send the saved settings record to another recipient. The manager supports the categories Necessary, Preferences, Statistics, Marketing and External media. Under the current configuration, only Necessary is active; no optional service is configured.

Because no optional technology is currently configured, no first-layer consent banner is displayed. The permanent control in the footer opens the detailed settings interface on every public page.

If you save a settings decision, the manager writes one structured record to your browser’s local storage. It contains the consent-manager version, timestamps, expiry, the selected category states, service states, decision type, language, configuration identifier and configuration checksum. It contains no name, email address, IP address, health information, advertising identifier, fingerprint or cross-site identifier.

The record remains for up to 180 days. This period is a configuration choice for this website, not a universally prescribed legal retention period. An expired record or a changed consent configuration is discarded. Withdrawing your saved decision deletes the record immediately.

The storage and retrieval of this record are strictly necessary to provide the privacy-settings function expressly requested by the visitor and are based on Section 25(2) no. 2 TDDDG. If and to the extent that the locally stored settings constitute personal data, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to apply the visitor’s chosen settings reliably and keep optional technologies blocked unless permitted.

Reject all stores Necessary only and prevents optional requests. Accept all enables only the optional services actually listed in the current configuration. Save selection applies the exact active optional categories. At present, there are no optional services, so Reject all, Accept all and Save selection all result in Necessary only. Rejection does not restrict access to website content.

The prior-blocking system activates an optional resource only when that service is explicitly registered in the local configuration and its category has been enabled. Optional scripts have no active source before activation, optional frames have no real source, and deactivation removes activated resources and their explicitly registered storage entries. No optional resource is currently registered or loaded.

Current cookie and browser-storage inventory
Name Provider Category Purpose Type Duration Necessity Recipient
elivdium_consent_v1 Elivdium GmbH Necessary Stores and reapplies the visitor’s privacy-settings decision, including version and expiry information. First-party localStorage Up to 180 days; earlier on withdrawal, expiry or configuration change Required only after the visitor asks the site to remember a settings decision None; remains in the visitor’s browser

6. Cookies and other website technologies

The website itself sets no cookies. It uses locally hosted images and SVG icons and system fonts. It does not load analytics, behavioural tracking, personalised advertising, embedded social-media content, videos, maps, external fonts, CAPTCHA services or other optional third-party website resources.

The only current browser-storage entry is the necessary local privacy-settings record described above, and it is created only after a visitor saves a decision. Ordinary external links are not embedded services and do not contact their destination until clicked.

7. Recipients

Personal data may be disclosed only where this is necessary and legally permitted. Recipients may include STRATO as our hosting provider, the provider operating our business email system, IT service providers acting on our instructions, professional advisers, and public authorities or courts where disclosure is legally required.

Where a service provider processes personal data on our behalf, we use a data processing agreement in accordance with Article 28 GDPR where required.

8. Transfers outside the European Economic Area

Under the current configuration, loading and using this website does not transmit visitor data to optional recipients outside the European Union or the European Economic Area.

If you independently open an external website through a link, such as LinkedIn, the external provider may process data in third countries under its own responsibility. Please refer to the privacy information of the respective provider.

9. General storage principles

We retain personal data only for as long as necessary for the relevant purpose. We may retain data for a longer period where required by statutory commercial, tax or other retention obligations, or where necessary for the establishment, exercise or defence of legal claims. Data are deleted or anonymised when the relevant purpose and any applicable retention grounds cease to apply.

10. Your rights

Subject to the statutory requirements, you have the following rights in relation to your personal data:

  • the right of access under Article 15 GDPR;
  • the right to rectification under Article 16 GDPR;
  • the right to erasure under Article 17 GDPR;
  • the right to restriction of processing under Article 18 GDPR;
  • the right to data portability under Article 20 GDPR; and
  • the right to object under Article 21 GDPR.

Where processing is based on consent, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

To exercise your rights, contact us at contact@elivdium.com. We may request information necessary to verify your identity.

11. Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation. We will then no longer process the relevant data unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

12. Right to lodge a complaint

You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.

The supervisory authority responsible for private-sector organisations with their registered office in Bavaria is:

Bavarian State Office for Data Protection Supervision
(Bayerisches Landesamt für Datenschutzaufsicht – BayLDA)
Promenade 18
91522 Ansbach
Germany

Website: www.lda.bayern.de (opens in a new tab)

13. Automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR in connection with this website.

14. Changes to this Privacy Policy

We may update this Privacy Policy if the website, the services used or the legal requirements change. The version published on this website at the relevant time applies.

Version: 01-20260727

© 2026 Elivdium GmbH

Home Imprint Contact