Processing of personal data under the GDPR

Privacy Policy · Data Protection at SIMO GmbH

eRecht24 Privacy Seal

1. An overview of data protection

General information

The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website. The term “personal data” comprises all data that can be used to personally identify you. For detailed information about the subject matter of data protection, please consult our Data Protection Declaration, which we have included beneath this copy.

Data recording on this website

Who is the responsible party for the recording of data on this website (i.e., the “controller”)?

The data on this website is processed by the operator of the website, whose contact information is available under section “Information about the responsible party (referred to as the “controller” in the GDPR)” in this Privacy Policy.

How do we record your data?

We collect your data as a result of your sharing of your data with us. This may, for instance be information you enter into our contact form.

Other data shall be recorded by our IT systems automatically or after you consent to its recording during your website visit. This data comprises primarily technical information (e.g., web browser, operating system, or time the site was accessed). This information is recorded automatically when you access this website.

What are the purposes we use your data for?

A portion of the information is generated to guarantee the error free provision of the website. Other data may be used to analyze your user patterns. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders or other order inquiries.

What rights do you have as far as your information is concerned?

You have the right to receive information about the source, recipients, and purposes of your archived personal data at any time without having to pay a fee for such disclosures. You also have the right to demand that your data are rectified or erased. If you have consented to data processing, you have the option to withdraw this consent at any time, which shall affect all future data processing. Moreover, you have the right to demand that the processing of your data be restricted under certain circumstances. Furthermore, you have the right to log a complaint with the competent supervisory authority.

Please do not hesitate to contact us at any time if you have questions about this or any other data protection related issues.

Analysis tools and tools provided by third parties

This website uses no third-party tools that evaluate your behavior for advertising, recognize you across devices, or build a profile of you. No audience measurement either. Section 5 has the details.

We describe each of the third-party services actually in use in detail below: the Cloudflare delivery network with its security and acceleration functions, our Microsoft mailbox for sending your form message, our podcast episodes (which load only once you click them), the consent service, and the AI companion “Mr. SIMO”.

2. Hosting and Content Delivery Networks (CDN)

This website does not run at a web hosting provider. It runs on a server that we operate ourselves, with Cloudflare's delivery network in front of it. We describe both stages here.

Operation on a server of our own

The website runs as an isolated application (a container) on a server that we operate ourselves. The personal data arising in the process are processed on that server. These may include, above all, IP addresses, the addresses you open, technical details about your browser, and the content you send us through a form. No web host is involved.

The server has no port open to the outside. It establishes the connection to the delivery network itself, from the inside out, which means the website can be reached only through Cloudflare. Direct access to the server from the internet is not possible.

The legal basis for operating it is our legitimate interest in the secure, fast, and reliable provision of our online offering (Art. 6(1)(f) GDPR). Where your visit serves to initiate or perform a contract, we also process your data on the basis of Art. 6(1)(b) GDPR.

Until August 8, 2026, this website was delivered by webgo GmbH, Hamburg. Since then it has run on the server of our own described above. The web host details previously given at this point no longer apply to this website.

Server log files

Our server keeps no access log: no file is written that records every page view together with an IP address. The only entries logged are technical fault messages, for example that a form could not be delivered or that an upstream system did not respond. The content of requests, email addresses, and credentials do not appear there.

These fault messages stay on our server, are not combined with any other data, and roll over: once the log storage is full (five files of ten megabytes each), the oldest part is deleted. The legal basis is our legitimate interest in fault-free operation (Art. 6(1)(f) GDPR).

The connection data of your visit, by contrast, arise at Cloudflare, because every request travels through its network. What Cloudflare processes in doing so is described in the following section.

Cloudflare

We use the “Cloudflare” service provided by Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. (hereinafter referred to as “Cloudflare”).

Cloudflare offers a content delivery network with DNS that is available worldwide. As a result, the information transfer that occurs between your browser and our website is technically routed via Cloudflare’s network. This enables Cloudflare to analyze data transactions between your browser and our website and to work as a filter between our servers and potentially malicious data traffic from the Internet. In this context, Cloudflare may also use cookies or other technologies deployed to recognize Internet users, which shall, however, only be used for the herein described purpose.

The use of Cloudflare is based on our legitimate interest in a provision of our website offerings that is as error free and secure as possible (Art. 6(1)(f) GDPR).

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5666.

Cloudflare performs several functions for this website that take effect directly in your browser. We name them individually here because they cannot be seen in the page source. Cloudflare adds them at the edge of its network while the page is on its way to you:

  • Bot detection: on every page your browser loads a small script from Cloudflare (its address begins with /cdn-cgi/challenge-platform/) that evaluates characteristics of your browser in order to distinguish automated from human access. In this context Cloudflare may set the cookie cf_clearance; it has a lifetime of up to one year.
  • Accelerated loading (Rocket Loader): Cloudflare adds a script that changes the order in which the page's other scripts are executed. Its purpose is faster rendering.
  • Email obfuscation: email addresses appearing in the page text are made unreadable by Cloudflare and are reassembled only in your browser. For this, your browser loads a further small script from Cloudflare. The purpose is to protect those addresses from automated harvesters.
  • Speculative loading: Cloudflare instructs your browser to fetch pages you are likely to open next before you actually do. As a result, a page may be requested without you ever opening it.
  • Audience measurement: Cloudflare measures page views and loading times for us. We describe that processing in full in section 5.

The first four functions serve the security and the speed of our offering. The legal basis is our legitimate interest under Art. 6(1)(f) GDPR. Insofar as information is stored on or read from your device in the process, we rely on Section 25(2) no. 2 TDDDG, because these functions are necessary in order to provide the page you requested. We point out the cf_clearance cookie separately because of its long lifetime; you can delete it in your browser at any time. The audience measurement, by contrast, we treat as requiring consent.

Data processing

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.

3. General information and mandatory information

Data protection

The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration.

Whenever you use this website, a variety of personal information will be collected. Personal data comprises data that can be used to personally identify you. This Data Protection Declaration explains which data we collect as well as the purposes we use this data for. It also explains how, and for which purpose the information is collected.

We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.

Information about the responsible party (referred to as the “controller” in the GDPR)

The data processing controller on this website is:

SIMO GmbH
Würzburger Str. 152
63743 Aschaffenburg, Bavaria, Germany

Phone: +49 6021 32745 50
E-mail: [email protected]

The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g., names, e-mail addresses, etc.).

Storage duration

Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or withdraw your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.

General information on the legal basis for the data processing on this website

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9 (2)(a) GDPR, if special categories of data are processed according to Art. 9 (1) DSGVO. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49 (1)(a) GDPR. If you have consented to the storage of cookies or to the access to information in your end device (e.g., via device fingerprinting), the data processing is additionally based on § 25 (1) TDDDG. The consent can be withdrawn at any time. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, if your data is required for the fulfillment of a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Furthermore, the data processing may be carried out on the basis of our legitimate interest according to Art. 6(1)(f) GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.

Designation of a data protection officer

We have appointed a data protection officer.

Thomas Wassum
Würzburger Straße 152
63743 Aschaffenburg

Phone: +49 6021 32745 50
E-mail: [email protected]

Information on the data transfer to third-party countries that are not secure under data protection law and the transfer to US companies that are not DPF-certified

We use, among other technologies, tools from companies located in third-party countries that are not safe under data protection law, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). If these tools are enabled, your personal data may be transferred to and processed in these countries. We would like you to note that no level of data protection comparable to that in the EU can be guaranteed in third countries that are insecure in terms of data protection law.

We would like to point out that the US, as a secure third-party country, generally has a level of data protection comparable to that of the EU. Data transfer to the US is therefore permitted if the recipient is certified under the “EU-US Data Privacy Framework” (DPF) or has appropriate additional assurances. Information on transfers to third-party countries, including the data recipients, can be found in this Privacy Policy.

Recipients of personal data

In the scope of our business activities, we cooperate with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is required as part of the fulfillment of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Art. 6 (1)(f) GDPR, or if another legal basis permits the disclosure of this data. When using processors, we only disclose personal data of our customers on the basis of a valid contract on data processing. In the case of joint processing, a joint processing agreement is concluded.

For this website, those are: the Cloudflare delivery network; our consent service; Microsoft, which operates the mailbox your form message is sent through and arrives in; Google, as the operator of YouTube, once you click to play a podcast episode; and the provider of the language model behind “Mr. SIMO”. Added to these are authorities we are legally obliged to inform. Each is described in this policy at the point where it actually comes into play.

Whether you have to give us data

You are under no statutory or contractual obligation to provide us with personal data. Without the entries marked as mandatory, however, we cannot deal with a request: without your name and email address we cannot reply, without a description of your concern we cannot route your request to the right person, and without the entries in the developer area no key can be issued. Leaving them out has no other consequence. You suffer no disadvantage as a result, and we draw no inferences from it.

Revocation of your consent to the processing of data

A wide range of data processing transactions are possible only subject to your express consent. You can also withdraw at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.

Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)

IN THE EVENT THAT DATA ARE PROCESSED ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA BASED ON GROUNDS ARISING FROM YOUR UNIQUE SITUATION. THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. TO DETERMINE THE LEGAL BASIS, ON WHICH ANY PROCESSING OF DATA IS BASED, PLEASE CONSULT THIS DATA PROTECTION DECLARATION. IF YOU LOG AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE ARE IN A POSITION TO PRESENT COMPELLING PROTECTION WORTHY GROUNDS FOR THE PROCESSING OF YOUR DATA, THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR IF THE PURPOSE OF THE PROCESSING IS THE CLAIMING, EXERCISING OR DEFENSE OF LEGAL ENTITLEMENTS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS BEING PROCESSED IN ORDER TO ENGAGE IN DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING AT ANY TIME. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS AFFILIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to log a complaint with the competent supervisory agency

In the event of violations of the GDPR, data subjects are entitled to log a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred. The right to log a complaint is in effect regardless of any other administrative or court proceedings available as legal recourses.

The supervisory authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 27, 91522 Ansbach, Germany (https://www.lda.bayern.de/).

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you should demand the direct transfer of the data to another controller, this will be done only if it is technically feasible.

Information about, rectification and erasure of data

Within the scope of the applicable statutory provisions, you have the right to demand information about your archived personal data, their source and recipients as well as the purpose of the processing of your data at any time. You may also have a right to have your data rectified or erased. If you have questions about this subject matter or any other questions about personal data, please do not hesitate to contact us at any time.

Right to demand processing restrictions

You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. To do so, you may contact us at any time. The right to demand restriction of processing applies in the following cases:

  • In the event that you should dispute the correctness of your data archived by us, we will usually need some time to verify this claim. During the time that this investigation is ongoing, you have the right to demand that we restrict the processing of your personal data.
  • If the processing of your personal data was/is conducted in an unlawful manner, you have the option to demand the restriction of the processing of your data instead of demanding the erasure of this data.
  • If we do not need your personal data any longer and you need it to exercise, defend or claim legal entitlements, you have the right to demand the restriction of the processing of your personal data instead of its erasure.
  • If you have raised an objection pursuant to Art. 21(1) GDPR, your rights and our rights will have to be weighed against each other. As long as it has not been determined whose interests prevail, you have the right to demand a restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – with the exception of their archiving – may be processed only subject to your consent or to claim, exercise or defend legal entitlements or to protect the rights of other natural persons or legal entities or for important public interest reasons cited by the European Union or a member state of the EU.

SSL and/or TLS encryption

For security reasons and to protect the transmission of confidential content, such as the inquiries and bookings you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock icon in your browser bar.

If the SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.

No automated decision-making

We make no decisions about you that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). No profiling within the meaning of Art. 4(4) GDPR takes place.

Rejection of unsolicited e-mails

We herewith object to the use of contact information published in conjunction with the mandatory information to be provided in our Site Notice to send us promotional and information material that we have not expressly requested. The operators of this website and its pages reserve the express right to take legal action in the event of the unsolicited sending of promotional information, for instance via SPAM messages.

4. Recording of data on this website

Cookies

Our websites and pages use what the industry refers to as “cookies.” Cookies are small data packages that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or they are permanently archived on your device (permanent cookies). Session cookies are automatically deleted once you terminate your visit. Permanent cookies remain archived on your device until you actively delete them, or they are automatically erased by your web browser.

Cookies can be issued by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of third-party companies into websites (e.g., cookies for handling payment services).

Cookies have a variety of functions. Many cookies are technically necessary because certain website functions would not work without them (on this website, for example, remembering the language you selected or your consent decision). Other cookies may be used to analyze user behavior or for advertising purposes; we do not set cookies of that kind.

Cookies that are required to carry out the electronic communication process or to provide certain functions you have requested (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless a different legal basis is stated. We have a legitimate interest in storing necessary cookies in order to provide our services in a technically error-free manner. Where consent to the storage of cookies and comparable recognition technologies has been requested, the processing takes place exclusively on the basis of that consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); the consent may be withdrawn at any time.

You have the option to set up your browser in such a manner that you will be notified any time cookies are placed and to permit the acceptance of cookies only in specific cases. You may also exclude the acceptance of cookies in certain cases or in general or activate the delete-function for the automatic erasure of cookies when the browser closes. If cookies are deactivated, the functions of this website may be limited.

Which cookies and services are used on this website can be found in this privacy policy.

Which cookies this website sets

Left to itself, this website makes do with exactly one cookie. A second one appears only once you agree to talk to Mr. SIMO. We set none for advertising or to build user profiles. No audience measurement takes place (Section 5).

NEXT_LOCALE: this cookie stores the language you selected (value “de” or “en”). It is set by this website itself, not by a third party, contains no identifier for you personally, and expires when you close your browser. Without it, the language would reset with every page you open. It is exempt from consent under Section 25(2) no. 2 TDDDG because it is strictly necessary for the service you requested.

simo-mrsimo-einwilligung: this cookie appears only after you have expressly agreed in Mr. SIMO's chat window. It records that you agreed, when, and to which version of the consent text. It carries nothing that identifies you. It lasts seven days; after that the companion asks again. The legal basis is your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). Alongside the cookie, the companion keeps your conversation in your browser's local storage (simo-mrsimo-gespraech) so that you can pick it up after an interruption. That entry travels with no request and never reaches our server. You can delete both from the chat window with one click. Details in Section 9.

Security cookies of the delivery network: Cloudflare may set two cookies to fend off automated attacks. __cf_bm is short-lived and distinguishes human from automated use. cf_clearance records for up to a year that a security check was passed. Both serve security and uninterrupted operation only.

The complete list, with purpose, lifetime and legal basis, is in our cookie notice.

We use no consent banner. Simply opening this website triggers nothing that would require consent: no audience measurement, no advertising tools, no recognition across sites. The two entries that do require consent appear only where you trigger them, and the question is asked in the same place: Mr. SIMO's chat window asks before it stores anything. Our podcast episodes are hosted on YouTube and load only once you explicitly click “Play episode”; that click, too, is your consent. Should we ever introduce a tool that requires consent merely to open a page, we will obtain your consent beforehand.

Contact form

If you submit inquiries to us via our contact form, the information provided in the contact form as well as any contact information provided therein will be stored by us in order to handle your inquiry and in the event that we have further questions. We will not share this information without your consent.

The processing of these data is based on Art. 6(1)(b) GDPR, if your request is related to the execution of a contract or if it is necessary to carry out pre-contractual measures. In all other cases the processing is based on our legitimate interest in the effective processing of the requests addressed to us (Art. 6(1)(f) GDPR) or on your agreement (Art. 6(1)(a) GDPR) if this has been requested; the consent can be withdrawn at any time.

The information you have entered into the contact form shall remain with us until you ask us to erase the data, withdraw your consent to the archiving of data or if the purpose for which the information is being archived no longer exists (e.g., after we have concluded our response to your inquiry). This shall be without prejudice to any mandatory legal provisions, in particular retention periods.

On its way to our mailbox, your message passes the stations we disclose here: our website hands it to our own Microsoft 365 mailbox through the Microsoft Graph interface (Microsoft Ireland Operations Limited, Dublin, Ireland), where the spam and malware filter protecting our mailboxes applies. No further delivery service is involved, and no outgoing-mail-server password is used along the way. Your message is not stored on the website itself; there is no database for it.

To guard against automated abuse we limit the number of form submissions per sender. For this purpose your IP address is counted in our server's memory only; five submissions in ten minutes are permitted. The address is not logged, not stored permanently, and not passed on, and it lapses at the latest when the server is next restarted. In addition, the form contains a field that is invisible to you and that only a program would fill in, and we discard submissions that arrive less than three seconds after the page was built. The legal basis is our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).

Request by e-mail, telephone, or fax

If you contact us by e-mail, telephone or fax, your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not pass these data on without your consent.

These data are processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or is required for the performance of pre-contractual measures. In all other cases, the data are processed on the basis of our legitimate interest in the effective handling of inquiries submitted to us (Art. 6(1)(f) GDPR) or on the basis of your consent (Art. 6(1)(a) GDPR) if it has been obtained; the consent can be withdrawn at any time.

The data sent by you to us via contact requests remain with us until you request us to delete, withdraw your consent to the storage or the purpose for the data storage lapses (e.g. after completion of your request). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.

5. Analysis tools and advertising

This website uses no third-party analytics, tracking, or advertising tools. Not even audience measurement.

Specifically not in use: Google Tag Manager, Google Analytics, Google Ads, Google AdSense, Google conversion tracking, Microsoft Clarity, Hotjar, the LinkedIn Insight Tag, the Pinterest tag, and the Meta (Facebook) pixel. Neither Google Analytics nor Microsoft Clarity was ever active on the previous site either.

We set no advertising identifiers, build no profile of you, and pass none of your data on for advertising purposes. What we learn about your visit is limited to the connection data that delivering a page unavoidably produces (Section 2) and to whatever you tell us yourself.

Why no measurement tool is listed here

Our delivery network, Cloudflare, offers cookie-free audience measurement. It is switched off for this site: your browser loads no script from static.cloudflareinsights.com, and no per-pageview identifier is generated. Section 2 covers the connection data that arises at Cloudflare as the operator of our delivery.

Should we introduce any tool for analytics, recognition, or advertising in future, we will update this policy beforehand and obtain your consent where required. No tool requiring consent is loaded without it.

6. Plug-ins and Tools

YouTube with expanded data protection integration

This website integrates videos from the YouTube website. The operator of the website is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of these websites on which YouTube is integrated, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

We use YouTube in extended data protection mode. According to YouTube, videos that are played in extended data protection mode are not used to personalize browsing on YouTube. Ads that are played in extended data protection mode are also not personalized. No cookies are set in extended data protection mode. Instead, so-called local storage elements are stored in the user's browser, which contain personal data similar to cookies and can be used for recognition. Details on the extended data protection mode can be found here: https://support.google.com/youtube/answer/171780.

After activating a YouTube video, further data processing operations may be triggered over which we have no influence.

The use of YouTube is based on our interest in presenting our online content in an appealing manner. Pursuant to Art. 6(1)(f) GDPR, this is a legitimate interest. If appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 (1) TDDDG, insofar the consent includes the storage of cookies or the access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TDDDG. This consent can be withdrawn at any time.

For more information on how YouTube handles user data, please consult the YouTube Data Privacy Policy under: https://policies.google.com/privacy?hl=en.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5780.

Typefaces

The typefaces used on this website are stored as files on our own server and are loaded exclusively from there. No connection to a font service such as Google Fonts or Adobe Fonts takes place, and your IP address is not transmitted to anyone for this purpose.

Cloudflare Turnstile

We use “Cloudflare Turnstile” on this website. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Turnstile”).

We use Turnstile to check whether an entry comes from a human being or from an automated program. We use it in exactly one place: the form with which you request a sandbox key in the developer area. On every other page of this website, including our contact form, Turnstile is not embedded.

The check begins as soon as you open that form. For this, Turnstile evaluates various pieces of information (for example, your IP address, the time you spend on the page, or mouse movements you make). The data recorded during the analysis are forwarded to Cloudflare.

The storage and analysis of the data is based on Art. 6 (1)(f) GDPR. The website operator has a legitimate interest in protecting his web offerings from abusive automated spying and from Spam. If such consent has been obtained, the data will be processed exclusively on the basis of Art. 6 (1)(a) GDPR and § 25 (1) TDDDG, if the consent comprises the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) as defined in the TDDDG (German Telecommunications Act). Such consent may be withdrawn at any time.

The processing of data is based on Standard Contract Clauses, which you can find here: https://www.cloudflare.com/cloudflare-customer-scc/.

For more information on Cloudflare Turnstile, please visit the privacy policy at: https://www.cloudflare.com/cloudflare-customer-dpa/.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5666.

7. Customer and Contract Data

Processing of Customer and Contract Data

We collect, process, and use personal customer and contract data for the establishment, content arrangement and modification of our contractual relationships. Data with personal references to the use of this website (usage data) will be collected, processed, and used only if this is necessary to enable the user to use our services or required for billing purposes. The legal basis for these processes is Art. 6(1)(b) GDPR.

The collected customer data shall be deleted upon completion of the order or termination of the business relationship and upon expiration of any existing statutory archiving periods. This shall be without prejudice to any statutory archiving periods.

Data transfer upon closing of contracts for services and digital content

We share personal data with third parties only where this is necessary in order to perform a contract. Via this website that concerns a single operation: booking paid access to our application programming interface. How that operation works and who is involved in it is described in the following section.

Any further transfer of data shall not occur or shall only occur if you have expressly consented to the transfer. Any sharing of your data with third parties in the absence of your express consent, for instance for advertising purposes, shall not occur.

The basis for the processing of data is Art. 6(1)(b) GDPR, which permits the processing of data for the fulfilment of a contract or for pre-contractual actions.

8. Custom Services

Handling applicant data

You can apply to us by email, by post, or through our careers portal, which is hosted at its own address at https://jobs.simo-online.com. There is no application form on this website. Below we inform you about the scope, purpose, and use of the personal data collected from you in the course of the application process. We assure you that the collection, processing, and use of your data take place in compliance with applicable data protection law and all other statutory provisions, and that your data are treated as strictly confidential.

Scope and purpose of the collection of data

If you submit a job application to us, we will process any affiliated personal data (e.g., contact and communications data, application documents, notes taken during job interviews, etc.), if they are required to make a decision concerning the establishment or an employment relationship. The legal grounds for the aforementioned are § 26 BDSG according to German Law (Negotiation of an Employment Relationship), Art. 6(1)(b) GDPR (General Contract Negotiations) and – provided you have given us your consent – Art. 6(1)(a) GDPR. You may withdraw any consent given at any time. Within our company, your personal data will only be shared with individuals who are involved in the processing of your job application.

If your job application should result in your recruitment, the data you have submitted will be archived on the grounds of § 26 BDSG and Art. 6(1)(b) GDPR for the purpose of implementing the employment relationship in our data processing system.

Data Archiving Period

If we are unable to make you a job offer or you reject a job offer or withdraw your application, we reserve the right to retain the data you have submitted on the basis of our legitimate interests (Art. 6(1)(f) GDPR) for up to 6 months from the end of the application procedure (rejection or withdrawal of the application). Afterwards the data will be deleted, and the physical application documents will be destroyed. The storage serves in particular as evidence in the event of a legal dispute. If it is evident that the data will be required after the expiry of the 6-month period (e.g., due to an impending or pending legal dispute), deletion will only take place when the purpose for further storage no longer applies.

Longer storage may also take place if you have given your agreement (Article 6(1)(a) GDPR) or if statutory data retention requirements preclude the deletion.

Admission to the applicant pool

If we do not make you a job offer, you may be able to join our applicant pool. In case of admission, all documents and information from the application will be transferred to the applicant pool in order to contact you in case of suitable vacancies.

Admission to the applicant pool is based exclusively on your express agreement (Art. 6(1)(a) GDPR). The submission agreement is voluntary and has no relation to the ongoing application procedure. Data subjects may withdraw their consent at any time. In this case, the data from the applicant pool will be irrevocably deleted, provided there are no legal reasons for storage.

The data from the applicant pool will be irrevocably deleted no later than two years after consent has been granted.

Our social media appearances

This privacy policy applies to the following social media presence

Data processing through social networks

We maintain publicly available profiles in social networks. The individual social networks we use can be found below.

Social networks such as Facebook, X etc. can generally analyze your user behavior comprehensively if you visit their website or a website with integrated social media content (e.g., like buttons or banner ads). When you visit our social media pages, numerous data protection-relevant processing operations are triggered. In detail:

If you are logged in to your social media account and visit our social media page, the operator of the social media portal can assign this visit to your user account. Under certain circumstances, your personal data may also be recorded if you are not logged in or do not have an account with the respective social media portal. In this case, this data is collected, for example, via cookies stored on your device or by recording your IP address.

Using the data collected in this way, the operators of the social media portals can create user profiles in which their preferences and interests are stored. This way you can see interest-based advertising inside and outside of your social media presence. If you have an account with the social network, interest-based advertising can be displayed on any device you are logged in to or have logged in to.

Please also note that we cannot retrace all processing operations on the social media portals. Depending on the provider, additional processing operations may therefore be carried out by the operators of the social media portals. Details can be found in the terms of use and privacy policy of the respective social media portals.

Legal basis

Our social media appearances should ensure the widest possible presence on the Internet. This is a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR. The analysis processes initiated by the social networks may be based on divergent legal bases to be specified by the operators of the social networks (e.g., consent within the meaning of Art. 6 (1) (a) GDPR).

Responsibility and assertion of rights

If you visit one of our social media sites (e.g., Facebook), we, together with the operator of the social media platform, are responsible for the data processing operations triggered during this visit. You can in principle protect your rights (information, correction, deletion, limitation of processing, data portability and complaint) vis-à-vis us as well as vis-à-vis the operator of the respective social media portal (e.g., Facebook).

Please note that despite the shared responsibility with the social media portal operators, we do not have full influence on the data processing operations of the social media portals. Our options are determined by the company policy of the respective provider.

Storage time

The data collected directly from us via the social media presence will be deleted from our systems as soon as you ask us to delete it, you withdraw your consent to the storage or the purpose for the data storage lapses. Stored cookies remain on your device until you delete them. Mandatory statutory provisions - in particular, retention periods - remain unaffected.

We have no control over the storage duration of your data that are stored by the social network operators for their own purposes. For details, please contact the social network operators directly (e.g., in their privacy policy, see below).

Your rights

You have the right to receive information about the origin, recipient and purpose of your stored personal data at any time and free of charge. You also have the right to object, the right to data portability and the right to lodge a complaint with the competent supervisory authority. You may also request rectification or erasure of your personal data and, under certain conditions, restriction of its processing.

Individual social networks

Facebook

We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter Meta). According to Meta’s statement the collected data will also be transferred to the USA and to other third-party countries.

We have signed an agreement with Meta on shared responsibility for the processing of data (Controller Addendum). This agreement determines which data processing operations we or Meta are responsible for when you visit our Facebook Fanpage. This agreement can be viewed at the following link: https://www.facebook.com/legal/terms/page_controller_addendum.

You can customize your advertising settings independently in your user account. Click on the following link and log in:https://www.facebook.com/settings?tab=ads.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

Details can be found in the Facebook privacy policy: https://www.facebook.com/about/privacy/.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4452

Instagram

We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

For details on how they handle your personal information, see the Instagram Privacy Policy: https://privacycenter.instagram.com/policy/.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4452

LinkedIn

We have a LinkedIn profile. The provider is the LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.

If you want to disable LinkedIn advertising cookies, please use the following link:https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.

For details on how they handle your personal information, please refer to LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5448

YouTube

We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Details on how they handle your personal data can be found in the YouTube privacy policy: https://policies.google.com/privacy?hl=en.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5780

TikTok

We maintain a profile on TikTok. For users in the European Economic Area the provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

TikTok also processes data outside the European Union. The provider bases transfers to third countries on the European Commission's Standard Contractual Clauses. For details on how your personal data are handled, please see TikTok's privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en.

9. AI companion “Mr. SIMO”

What Mr. SIMO is and why we offer it

Our website offers an AI-assisted conversation partner called “Mr. SIMO”. It helps you frame your situation and find the parts of our offering that are relevant to you. The purpose of the processing is to answer your questions and to give you initial guidance on our services.

Notice pursuant to Art. 50 of the AI Act

You are writing to an AI system, not to a human being. We inform you of this expressly pursuant to Art. 50(1) of Regulation (EU) 2024/1689 (the AI Act); the same notice is displayed in the chat window itself. The answers are generated by a machine and may be incomplete or wrong. They do not constitute advice and create no contractual commitment. Only statements made by our advisors are binding. You can reach a human being at any time via our contact form.

What data is processed

Only the following is transmitted to our server:

  • the text you type into the input field (up to 3,000 characters per message),
  • the previous turns of the current conversation (up to 48), so that Mr. SIMO understands the context; older answers from Mr. SIMO are shortened along the way, your own words never are,
  • the title and path of the page you are currently viewing, so that Mr. SIMO can answer questions such as “what am I looking at here?”,
  • the language you selected.

Which personal data is processed is determined solely by what you choose to write. We ask for nothing. Please do not enter credentials, personal data about other people or confidential document contents.

Legal basis

The legal basis is your consent under Art. 6(1)(a) GDPR. You give it by expressly agreeing in the chat window; without that agreement nothing is sent to our server and no content reaches our service provider. Storing your agreement and the conversation on your device rests in addition on Section 25(1) TDDDG. Both happen on your device alone, and never before you have agreed.

Recipients and transfer to the United States

To generate the answers we use the “Claude” language model operated by Anthropic PBC, San Francisco, California, USA. Your input, the conversation so far and the details of the page you are viewing are transmitted to Anthropic’s servers in the United States for that purpose. Your IP address is not transmitted to Anthropic; the connection is made by our server, not by your browser.

The United States is a third country for which no adequacy decision of the European Commission applies to this recipient. We base the transfer on your explicit consent pursuant to Art. 49(1)(a) GDPR. According to its own statements, Anthropic additionally relies on the European Commission’s Standard Contractual Clauses for transfers from the European Union (Art. 46(2)(c) GDPR). We point out that, despite these safeguards, it cannot be ruled out that US authorities may access the transmitted data on the basis of US law and that effective legal remedies may not be available to you in that respect. Further information: https://www.anthropic.com/legal/privacy.

Retention

With us: we do not store your questions or the answers. There is no database and no log of conversation content for the companion. Our technical logs record only figures with no personal reference: the duration of the request, the number of tokens processed and the category of any error. Content never appears there.

On your device: once you have agreed, the companion stores two things with you: a record of your consent (cookie “simo-mrsimo-einwilligung”) and the transcript of the conversation (entry “simo-mrsimo-gespraech” in your browser's local storage). The sole purpose is to let you carry on after a reload, or the next day, instead of starting over. Both last seven days and then expire on their own; the clock runs from your last message, not from your last visit. None of it reaches our server: the transcript sits in local storage and is sent with no request, and the consent record carries nothing that identifies you. You can delete both at any time from the chat window with one click, which returns the companion to exactly where it stood before your first visit.

With Anthropic: according to the provider, inputs and outputs are deleted automatically within 30 days of receipt or generation. If an automated safety system flags an input as violating the usage policy, inputs and outputs are retained for up to two years and the associated classification scores for up to seven years. Under the applicable commercial terms, Anthropic does not use the transmitted content to train its models.

Abuse prevention

To protect the companion against automated abuse and against the cost of mass requests, we limit the number of requests per sender. For this purpose your IP address is counted in our server's memory only. It is not logged, not stored permanently, and not passed on to third parties. Each counter applies for one hour; after that it has no effect, and its entry is removed at the next clean-up run, and at the latest when the server is next restarted. The legal basis is our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).

Withdrawal

You may withdraw your consent at any time with effect for the future. Withdrawing is as easy as giving it, as Art. 7(3) GDPR requires: in the chat window, open “What happens to your message” and click “Delete conversation and consent”. That removes the record of your consent and the stored transcript in one go, and nothing further is transmitted without a fresh agreement. Your language choice is left alone. If you do nothing at all, both expire on their own after seven days. The lawfulness of processing carried out before withdrawal remains unaffected. For access to, or erasure of, content already transmitted, please contact [email protected]; we will pass your request on to our service provider.

No automated decision-making in individual cases

Mr. SIMO makes no decisions about you. There is no automated decision-making producing legal effects or similarly significant effects within the meaning of Art. 22 GDPR, and no profile is built about you.

Last updated: August 9, 2026