Last updated: 14 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
Optis Digital
Proprietor: Ievgen Syplyvyi
Rückertweg 7
95447 Bayreuth
Germany
Email: is@optis.digital
Contact regarding data protection matters is possible exclusively by email or in writing at the postal address stated above.
2. General Information on Data Processing
We process personal data only to the extent necessary to provide this website, handle enquiries, take steps prior to entering into a contract, perform contracts, safeguard legitimate interests, comply with legal obligations or act on the basis of valid consent.
Depending on the particular processing activity, the following legal bases may apply:
- Article 6(1)(a) GDPR – consent;
- Article 6(1)(b) GDPR – performance of a contract and steps prior to entering into a contract;
- Article 6(1)(c) GDPR – compliance with legal obligations;
- Article 6(1)(f) GDPR – protection of legitimate interests;
- Section 25(1) TDDDG – consent to storing information on terminal equipment or accessing information already stored on it;
- Section 25(2) TDDDG – storage or access that is strictly necessary for technical purposes.
Our website and services are intended exclusively for entrepreneurs within the meaning of section 14 of the German Civil Code (BGB), legal entities under public law and special funds under public law. We do not conclude contracts with consumers within the meaning of section 13 BGB. This does not affect the data protection rights of natural persons.
3. Hosting and Server Log Files
This website and the associated email services are hosted by Hostinger. The provider is Hostinger International Ltd., based in Cyprus. According to Hostinger, data may be processed, depending on the services booked and the technical infrastructure, particularly within the European Union or the European Economic Area.
When this website is accessed, the hosting provider may process the following data in server log files in particular:
- IP address of the requesting device;
- date and time of access;
- requested URL and amount of data transferred;
- referrer URL;
- browser type, browser version and operating system;
- HTTP status code;
- hostname of the accessing device;
- information used to detect and prevent technical attacks.
The data are processed to provide the website securely, reliably and without errors and to detect and prevent misuse and attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the security, functionality and economically viable provision of our online presence.
Server log files are deleted or anonymised as soon as they are no longer required for the stated purposes, unless a security investigation, legal obligation or the establishment, exercise or defence of legal claims requires longer retention. Where required, a data processing agreement has been concluded with the hosting provider.
Further information: Hostinger Privacy Policy.
4. SSL or TLS Encryption
For security reasons, this website uses SSL or TLS encryption. An encrypted connection can generally be recognised by “https://” and the padlock icon in the browser. Nevertheless, complete security of data transmission over the internet cannot be guaranteed. You should therefore not send special categories of personal data or confidential access credentials by unencrypted email or through general contact forms.
5. Cookies and Similar Technologies
We use cookies and comparable technologies. Cookies are small data records that can be stored on or read from a terminal device. Comparable technologies may include local storage, pixels, tags or device identifiers.
Cookies and access that are strictly necessary for technical purposes are used on the basis of section 25(2) TDDDG. Where applicable, the subsequent processing of personal data is based on Article 6(1)(f) GDPR. Our legitimate interest lies in providing a secure and functional website and storing the privacy choices you have made.
Functional, statistical or marketing technologies are used only if you have first consented through the consent management system. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. Consent is voluntary and may be withdrawn at any time with effect for the future.
The cookies currently detected, their providers, purposes and storage periods are displayed in the consent management system. The list displayed there forms part of this privacy information and is updated following new website scans.
Cookies Currently Required for Technical Purposes
- cookieyes-consent: stores the choice made through the consent management system; storage period generally up to one year.
- pll_language: stores the language selected for the website; storage period generally up to one year.
The actual storage period set in the browser may change as a result of technical updates. The current information displayed in the consent management system is authoritative.
6. Consent Management with CookieYes
We use CookieYes to obtain, manage and document your consent choices. The provider is CookieYes Limited, 3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom.
CookieYes processes, in particular, your consent decision, the time and scope of the decision, a pseudonymous identifier, device and browser information and, where applicable, the IP address. This processing is necessary to implement your choices and to demonstrate whether consent was granted or refused.
The legal bases are Article 6(1)(c) GDPR in conjunction with the applicable data protection accountability obligations and Article 6(1)(f) GDPR. Our legitimate interest lies in legally compliant consent management. The cookie required for this purpose is set on the basis of section 25(2) TDDDG.
The United Kingdom is currently regarded as providing an adequate level of data protection on the basis of an adequacy decision by the European Commission. Additional contractual safeguards are used where required.
Further information: CookieYes Privacy Policy.
Withdrawing or Changing Consent
You may reopen and change your choices at any time by using the cookie settings icon displayed on the website. Alternatively, you may delete cookies in your browser. This does not affect the lawfulness of processing carried out before consent was withdrawn.
7. Language Selection with Polylang
We use Polylang to provide this website in multiple languages. The pll_language cookie may be set to store the language you have selected and provide the same language on a later visit. It is used to provide the language version expressly selected by you on the basis of section 25(2) TDDDG and Article 6(1)(f) GDPR. Our legitimate interest lies in providing a user-friendly multilingual website.
8. Contact by Email and Contact Form
If you contact us by email or through a form, we process the information you submit. This may include, in particular, your name, business email address, company, the content of your message, project information, time of submission and any other information you provide voluntarily.
The data are processed to handle your enquiry. If the enquiry concerns the initiation or performance of a contract, the legal basis is Article 6(1)(b) GDPR. Other business enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in handling business communications and documenting the correspondence.
Separate consent is generally not required solely to handle your enquiry. Any optional consent to receive marketing information or a newsletter is obtained separately.
Contact enquiries that do not result in a contractual relationship are generally deleted once the enquiry has been conclusively dealt with and there are no legitimate interests or legal obligations preventing deletion. Longer retention may be required, in particular, for the establishment, exercise or defence of legal claims.
WPForms
We use WPForms Lite for our forms. Form entries are processed through the website and sent to us as notification emails. According to the provider, WPForms Lite does not normally store entries as accessible records in the WordPress backend. If the optional “Lite Connect” function is activated, encrypted backup copies of form entries may be stored on the WPForms provider’s infrastructure. This function should not be activated unless it is required and expressly documented in this Privacy Policy.
Further information: WPForms Privacy Policy.
Email Delivery via Hostinger SMTP
Form notifications and business emails are sent and received through Hostinger’s SMTP service using the domain email address is@optis.digital. The data processed may include, in particular, the sender and recipient addresses, subject line, message content, time of transmission and technical delivery information. Depending on the content, the legal basis is Article 6(1)(b), (c) or (f) GDPR.
9. Contract Termination Form
Only business customers may use the contract termination form to submit a declaration concerning the termination of a contract. We may process, in particular, the company, the name and authority of the person making the declaration, business email address, customer, quotation, invoice or project number, description of the contract, type and reason for termination, requested termination date and any additional message.
The data are processed to review, allocate, handle, confirm and document the termination on the basis of Article 6(1)(b) GDPR. Where data are needed to comply with statutory documentation or retention obligations, the legal basis is Article 6(1)(c) GDPR. Retention for the establishment, exercise or defence of legal claims may additionally be based on Article 6(1)(f) GDPR.
Submitting the form alone does not modify any contractually agreed notice periods, minimum terms or other requirements. Receipt of the submission and the outcome of the review will be confirmed by email.
10. Newsletter and Marketing Emails
Marketing information or a newsletter will be sent only where valid consent has been obtained or another statutory permission applies. Consent to receive marketing information is voluntary, is requested separately from a general enquiry and does not affect the handling of that enquiry.
The legal basis for a consent-based newsletter is Article 6(1)(a) GDPR in conjunction with the applicable unfair competition and electronic marketing rules. To demonstrate consent, we may store the time and wording of the declaration, the email address and technical evidence. If a regular automated newsletter is introduced, we generally use a double opt-in procedure. No automated newsletter will be sent until this procedure has been technically implemented.
Consent may be withdrawn at any time with effect for the future, for example through an unsubscribe link or by email to is@optis.digital. Following withdrawal, the address will be removed from the active mailing list. A suppression record may be retained where necessary to prevent future unsolicited marketing and to demonstrate the withdrawal.
Email is currently delivered through Hostinger SMTP. If external newsletter providers or open or click tracking are used in the future, this Privacy Policy will be supplemented before activation with information on the provider, processing purposes, legal bases, storage periods and transfers to third countries.
11. Protection against Misuse with hCaptcha
hCaptcha may be used to protect our forms against automated entries, spam and technical misuse. The provider is Intuition Machines, Inc., 1065 SW 8th St #704, Miami, FL 33130, USA.
hCaptcha may process, in particular, the IP address, device and browser information, mouse movements, keyboard input, interaction data, time, requested page and the outcome of the abuse assessment. The assessment is used to distinguish human entries from automated access.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, forms and communication systems against spam, fraud and attacks. To the extent that hCaptcha stores or reads information on the terminal device that is not strictly necessary for technical purposes, this occurs only after consent in accordance with section 25(1) TDDDG and Article 6(1)(a) GDPR.
Data may be transferred to the United States. According to the provider, such transfers may be based, in particular, on certification under the EU-U.S. Data Privacy Framework or on appropriate contractual safeguards.
Further information: hCaptcha Privacy Policy.
12. Consent-Based Third-Party Services
Depending on the page you visit and the choices you make in the consent management system, the services described below may be used. If a service is not integrated on the particular page or if you have not consented to the relevant category, the processing described for that service does not take place through our website.
Non-essential analytics, marketing and external media services may be loaded only after your consent. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. You may change or withdraw your consent at any time with effect for the future through the cookie settings.
12.1 Google Tag Manager
We may use Google Tag Manager. For users in the European Economic Area, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is used to manage and trigger other website tags. The Tag Manager does not generally perform its own usage analysis, but it may process technical data such as the IP address and browser and device information and may trigger other services. Processing performed by the tags it triggers is described in the relevant sections of this Privacy Policy.
Google Tag Manager is configured so that services requiring consent are not activated before the required consent has been granted. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR.
12.2 Google Analytics 4
We may use Google Analytics 4 to perform statistical analysis of the use of our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics may process, in particular, information about page views, sessions, approximate location, browser, operating system, device, referrer, interactions, events, campaign parameters, pseudonymous identifiers and the IP address. The creation of user profiles and cross-device attribution by Google cannot be ruled out completely.
Google Analytics is activated only after consent to the Statistics or Analytics category. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. The retention period for event-related data in Google Analytics is generally limited to no more than 14 months, unless a shorter period has been configured or longer retention is required due to special circumstances and is legally permissible.
We do not use Google Analytics as the basis for decisions that produce legal effects concerning you or similarly significantly affect you.
12.3 Google Ads and Conversion Tracking
We may use Google Ads, including conversion tracking, to measure the effectiveness of advertisements and optimise advertising campaigns. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
If you reach our website through a Google advertisement and have consented to marketing, cookies or comparable identifiers may be stored. The data processed may include, in particular, advertising and campaign information, interactions, pages viewed, conversion events, pseudonymous identifiers, device and browser information and the IP address.
Google Ads is activated only after consent to the Marketing or Advertisement category. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. Personalised advertising, remarketing or enhanced conversions are used only if the necessary technical and legal requirements are met and the relevant information is provided in the consent management system.
12.4 Hotjar
We may use Hotjar to analyse the use of our website and improve its usability. Hotjar is provided by Hotjar Ltd., Malta, a company within the Contentsquare group.
Hotjar may process, in particular, pseudonymised information concerning page views, clicks, scrolling, mouse and touch interactions, screen size, device type, browser, operating system, language, approximate location and IP address. The content of sensitive form fields should be technically masked. Hotjar must not be used to monitor specific identified individuals.
Hotjar is activated only after consent to the Statistics or Analytics category. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. The storage period depends on the respective Hotjar configuration and is limited to what is necessary for the analysis.
Further information: Hotjar/Contentsquare Privacy Information.
12.5 YouTube
Videos from YouTube may be embedded on individual pages. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Where technically possible, we use privacy-enhanced mode and the youtube-nocookie.com domain. Even in privacy-enhanced mode, data may be transferred to Google or YouTube when a video is played or enabled.
The video is not loaded before you give consent. Once it has been enabled, the data processed may include, in particular, your IP address, device and browser information, the page visited, time, interactions with the video and, where applicable, information from your Google or YouTube account. If you are signed in to Google, Google may associate your use with your account.
The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. Consent can be withdrawn through the cookie settings.
12.6 Google Maps
Maps provided by Google Maps may be embedded on individual pages. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Maps is loaded only after you give consent. Once it has been enabled, the data transferred to Google may include, in particular, your IP address, location data, device and browser information, the page visited, time and interactions with the map. If you are signed in to a Google account, Google may associate your use with your account.
The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. If consent is not given, an external link to Google Maps may be provided instead of the embedded map.
12.7 Google Fonts
We aim to provide the fonts used on this website locally from our own server. Where fonts are provided locally, no connection to Google is established when they are loaded.
If Google Fonts are exceptionally loaded externally in certain areas, this occurs only after you give consent. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When fonts are requested externally, the data transferred to Google may include, in particular, the IP address, browser and device information and the page visited. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR.
12.8 General Information on Google Services
When Google services are used, data may be processed by Google LLC and other group companies in the United States or other third countries. Where applicable, transfers may be based on the EU-U.S. Data Privacy Framework, the European Commission’s Standard Contractual Clauses or other safeguards permitted under Chapter V GDPR. Despite these measures, processing in a third country may involve risks, in particular with regard to access rights of foreign public authorities.
Further information:
- Google Privacy Policy
- How Google uses data when you use sites or apps that use Google services
- Google advertising settings
13. External Links and Social Media Profiles
Our website may contain ordinary links to external websites and social media profiles, in particular LinkedIn and X. With an ordinary link, a connection to the relevant provider is generally established only when you actively click the link. From that point onwards, the respective external provider is responsible for the processing carried out there.
If social media plugins, feeds, tracking pixels or embedded posts are used in the future, they will be activated only after the required consent has been obtained and this Privacy Policy will be supplemented in advance.
14. Processing of Customer, Prospective Customer and Business Partner Data
In connection with the initiation and performance of B2B contractual relationships, we process, in particular, master and contact data, company data, communication content, quotation and contract data, project information, access and authorisation information, service records, billing and payment data and tax-related information.
The legal basis is Article 6(1)(b) GDPR where the data subject is a party to the contract or requests steps prior to entering into a contract. Data relating to contact persons, employees, corporate bodies and representatives of a business customer are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in initiating, performing, managing and documenting business relationships. Retention required by law is based on Article 6(1)(c) GDPR.
In individual customer projects, Optis Digital may process personal data on behalf of a customer. Where Optis Digital acts as a processor, an agreement in accordance with Article 28 GDPR will be concluded before the relevant processing begins.
15. Use of AI-Assisted Tools
We may use AI-assisted tools to support research, analysis, idea generation, text and image processing, automation, quality control and the provision of services. Merely visiting this website or submitting a form does not automatically cause the content of your message to be transmitted to an AI provider.
Personal or confidential customer data are processed using an AI service only if there is an appropriate legal basis, a legitimate purpose, the necessary contractual data protection safeguards and appropriate data minimisation. Where Optis Digital acts on behalf of a customer, such processing is carried out only within the scope of the customer’s instructions and the applicable data processing agreement. Special categories of personal data should generally not be entered into publicly available AI services.
If AI chatbots or other systems that interact directly with visitors on this website or transfer visitor data to an AI provider are introduced in the future, users will be informed directly at the relevant system. Before the system is activated, this Privacy Policy will also be supplemented with the specific provider, purpose, legal basis, storage period and possible transfer to a third country.
16. Recipients and Categories of Recipients
Where necessary for the respective purpose and legally permissible, personal data may be disclosed, in particular, to the following categories of recipients:
- hosting, email and IT service providers;
- consent management, security and form providers;
- analytics, advertising and external media services following your consent;
- freelancers or subcontractors, provided they are bound by confidentiality and appropriately integrated into the data protection arrangements;
- tax advisers, legal advisers, banks and payment service providers;
- authorities, courts or other public bodies where there is a legal obligation;
- other recipients where you have given consent or another legal basis applies.
Depending on their role, service providers are engaged on the basis of a data processing agreement, statutory authority or as independent controllers.
17. Transfers to Third Countries
Some of the providers named above or their subprocessors may process personal data outside the European Union and the European Economic Area. Such transfers take place only if the requirements of Articles 44 et seq. GDPR are met.
Relevant safeguards may include, in particular, an adequacy decision by the European Commission, valid certification under the EU-U.S. Data Privacy Framework, the European Commission’s Standard Contractual Clauses and supplementary technical and organisational measures. If a transfer is based on your explicit consent, Article 49(1)(a) GDPR may apply. Despite protective measures, a transfer to a third country may involve risks.
18. Storage Period
We store personal data only for as long as necessary for the respective purpose. The data are subsequently deleted or anonymised unless statutory retention obligations, legitimate interests or legal claims require further storage.
The following criteria may apply in particular:
- general contact enquiries: until the enquiry has been conclusively dealt with and thereafter only to the extent required for documentation or legal defence;
- pre-contractual and contractual communications: for the duration of the business relationship and within the applicable statutory limitation periods;
- tax and commercial records: in accordance with the statutory retention periods applicable at the time, generally six to ten years;
- termination declarations and contract termination records: at least for the duration of the relevant limitation periods and evidentiary obligations;
- newsletter data: until consent is withdrawn; evidence of consent or withdrawal may be retained beyond that date within the applicable limitation periods;
- consent records: for the technically configured validity period and beyond that period where required to comply with data protection accountability obligations;
- analytics and marketing data: in accordance with the periods configured in the relevant service and only within the scope of the consent granted.
19. Your Rights
Subject to the statutory requirements, data subjects have the following rights in particular:
- right of access under Article 15 GDPR;
- right to rectification under Article 16 GDPR;
- right to erasure under Article 17 GDPR;
- right to restriction of processing under Article 18 GDPR;
- right to data portability under Article 20 GDPR;
- right to object under Article 21 GDPR;
- right to withdraw consent under Article 7(3) GDPR;
- right to lodge a complaint with a data protection supervisory authority under Article 77 GDPR.
To exercise your rights, please contact us by email at is@optis.digital. To prevent unauthorised disclosure, we may request reasonable evidence of your identity. Secure and unambiguous identification must not require more data than is necessary to carry out the verification.
20. Withdrawal of Consent
Consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before it was withdrawn. Cookie-related consent can be changed through the cookie settings. Other consent can be withdrawn by email to is@optis.digital.
21. Right to Object under Article 21 GDPR
If we process personal data on the basis of Article 6(1)(e) or (f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
If personal data are processed for direct marketing purposes, you may object to processing for that purpose at any time. Following such an objection, the data will no longer be used for direct marketing.
22. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The following authority is responsible in particular for private-sector businesses established in Bavaria:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
Email: poststelle@lda.bayern.de
Website: www.lda.bayern.de
You may also contact any other supervisory authority with jurisdiction under Article 77 GDPR.
23. Automated Decision-Making and Profiling
As a general rule, we do not make decisions concerning website visitors, prospective customers or customers that are based solely on automated processing within the meaning of Article 22 GDPR and that produce legal effects concerning the individual or similarly significantly affect them. If this changes in an individual case in the future, the persons concerned will be informed separately in advance and the safeguards required by law will be implemented.
24. Requirement to Provide Data
There is generally no statutory or contractual obligation to provide personal data. However, certain data may be required to handle an enquiry or to initiate and perform a contract. Without these data, we may be unable to process an enquiry or provide the requested service.
25. No Use of Contact Details for Unsolicited Marketing
Use of the contact details published in the Legal Notice and this Privacy Policy for sending marketing materials that have not been expressly requested is prohibited. This does not affect legally permissible communications or the statutory rights of data subjects.
26. Amendments to this Privacy Policy
We update this Privacy Policy if the website, the services used, data processing activities or legal requirements change. The version currently published on this website applies. Before a new analytics, marketing, AI, form, newsletter or media service is activated, we will assess whether this Privacy Policy and the consent management system must be updated.
Last updated: 14 August 2026