Privacy Policy
Protecting the privacy of all individuals is very important to us. This privacy policy explains which personal data we process when you visit our website and use our online services.
Last updated: July 9, 2026
Controller
The controller responsible for this website under data protection law is:
Identeco GmbH & Co. KG
Dr. Matthias Wübbeling
Joachimstraße 8
53113 Bonn
Germany
Email: contact@identeco.de
Phone: +49 (0) 228 286 285 81
Dr. Matthias Wübbeling is responsible for data protection at Identeco. You can contact him using the contact details above.
Hosting and Technical Provision
Our website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes technical access data on our behalf where this is necessary for the secure and reliable operation of the website.
Each time you access content on the website, your browser transfers technically necessary data to our servers. This data is stored in order to prevent misuse of our systems, analyze technical errors and deliver the website. In particular, the following data may be processed:
- date and time of the request
- IP address and host name of the internet connection or computer used
- page visited on our website
- amount of data transferred
- message as to whether the request was successful
- information about browser type and browser version
- operating system
- referrer URL, if transmitted by the browser
The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the technical provision, security and stability of our website. In order to investigate technical problems and misuse, this access data is generally stored for 72 hours and then deleted, unless longer storage is required to investigate specific security incidents.
Contact Requests and Contact Form
If you contact us via a contact form, by email or by phone, we process the data you provide in order to handle your request and respond to you. This may include, in particular, your name, email address, telephone number, company, message and technical metadata relating to the request.
Depending on the content of your request, the processing is based on Art. 6 para. 1 lit. b GDPR if the request relates to pre-contractual measures or an existing contractual relationship, or on our legitimate interest in handling and documenting requests pursuant to Art. 6 para. 1 lit. f GDPR.
Required fields are indicated in the respective form. Without the information marked as required, we may not be able to process your request, or may only be able to process it to a limited extent. Any additional information is voluntary.
The data will be deleted once it is no longer required to process your request and no statutory retention obligations apply. If the request results in a business relationship, the data may be stored in accordance with statutory retention periods.
Appointment Booking and Meeting Tool
We provide a self-hosted meeting tool for scheduling appointments. If you book an appointment through this tool, we process the data you enter, in particular your name, email address, company, selected appointment time, time zone and any voluntary information entered in free-text fields. In addition, technically necessary access data may be processed in order to provide the tool and prevent misuse.
The processing is carried out for the preparation and execution of the requested appointment on the basis of Art. 6 para. 1 lit. b GDPR or, where there is no contractual context, on the basis of our legitimate interest in efficient appointment scheduling pursuant to Art. 6 para. 1 lit. f GDPR.
Required fields are indicated in the appointment form. Without this information, we cannot book or appropriately prepare the appointment. Any additional information is voluntary.
Appointment booking data is stored only for as long as it is required for scheduling, conducting and appropriately following up on the appointment, or as long as statutory retention obligations apply. Meetings are recorded only if this has been communicated separately and there is an appropriate legal basis.
Threat View and Domain Analysis
On our website, we may use Threat View to provide an initial assessment of the digital exposure of a specified domain. If you enter a domain or open a link with a pre-filled domain, we process the specified domain, technically necessary access data and the report data derived from it.
Threat View uses server-side Identeco systems to evaluate aggregated leak and exposure information from our collection relating to the specified domain and present it in a compact report. In this use case, no personal raw data from leak sources is disclosed in the public Threat View report. In addition, publicly available company information, such as name, description, logo, industry or location, may be used to make the report easier to understand. The browser receives only the normalized results required to display the report.
The processing is based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in providing interested parties with an initial security-related assessment of a specified domain, protecting our systems against misuse and preparing subsequent consultation. If you subsequently contact us or book an appointment, the sections on contact requests and appointment booking also apply.
Please only enter domains that you are authorized to check. Threat View does not make automated decisions with legal effect or similarly significant impact on individuals. The report is a technical initial assessment and does not replace a full security analysis.
Technical access data is processed in accordance with the principles described in the hosting section. Report-related interim results and caches are retained only for as long as this is necessary for providing the service, ensuring stability, preventing misuse and analyzing errors.
Cookies, Local Storage and Similar Technologies
Our website may use technically necessary storage technologies to provide functions, such as language settings, opt-out information or security-related states. Where such technologies are necessary to provide the function requested by you, the processing is based on Art. 6 para. 1 lit. f GDPR.
We use non-essential technologies only where there is a legal basis for doing so. SalesViewer® sets an opt-out cookie as described in the SalesViewer® section.
Analytics
Matomo
On some pages, we use Matomo, formerly Piwik, for web analytics. Matomo is operated locally by us; no usage data is transferred to Matomo or InnoCraft in this context.
The protection of your data is important to us, which is why we have configured Matomo so that your IP address is only recorded in abbreviated form. We therefore process your usage data anonymously. It is not possible for us to draw conclusions about your person.
The processing is based on our legitimate interest in the anonymized analysis and improvement of our online offering pursuant to Art. 6 para. 1 lit. f GDPR. Matomo is used without cookie technology.
SalesViewer®
This website uses SalesViewer® technology from SalesViewer® GmbH on the basis of the website operator’s legitimate interests (Art. 6 para. 1 lit. f GDPR) to collect and store data for marketing, market research and optimization purposes.
For this purpose, a JavaScript-based code is used to collect company-related data and use it accordingly. The data collected using this technology is encrypted by means of a non-reversible one-way function, known as hashing. The data is immediately pseudonymized and is not used to personally identify visitors to this website.
The data stored by SalesViewer® will be deleted as soon as it is no longer required for its intended purpose and there are no statutory retention obligations preventing deletion.
You can object to the collection and storage of data at any time with effect for the future by clicking this link to prevent SalesViewer® from recording your data on this website in the future. An opt-out cookie for this website will be stored on your device. If you delete cookies in this browser, you will need to click this link again.
YouTube
We embed videos from YouTube on our website. The operator of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube by means of a function that only loads the video when you actively start it. This means that data is only sent to Google when you actively consent to the video being played and the data being transferred. When you watch the video, the transfer of data to YouTube partners cannot be excluded. YouTube may also establish a connection to the Google DoubleClick network.
As soon as you start a YouTube video on this website, a connection to YouTube’s servers is established. This tells the YouTube server which of our pages you have visited. If you are logged into your YouTube account, YouTube may assign your browsing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.
YouTube is used in the interest of an appealing presentation of our online offers. This represents a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.
When YouTube is used, a transfer of personal data to third countries, in particular the United States, cannot be excluded. For more information about data protection at YouTube, please see Google’s privacy policy at: https://policies.google.com/privacy?hl=en
Recipients and Processors
Within Identeco, only those departments that need personal data to fulfill the purposes described above receive access to it. External recipients or processors may include, in particular, hosting providers, technical service providers, providers of analytics or marketing technologies, and communication and appointment management systems, where this is necessary for the respective processing.
Where required, we conclude data processing agreements with processors pursuant to Art. 28 GDPR. Transfers to third countries take place only where there is a suitable legal basis or an adequate level of protection, or where you have consented to the processing.
Your Rights
Subject to the statutory requirements, you have the following rights:
- access to the personal data stored by us
- rectification of inaccurate personal data
- deletion of personal data that is no longer required
- restriction of processing
- data portability
- objection to processing based on Art. 6 para. 1 lit. f GDPR
- withdrawal of consent with effect for the future
- complaint to a data protection supervisory authority
The data protection supervisory authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
Website: https://www.ldi.nrw.de/
Depending on your request, we may need additional information from you in order to verify your identity. This allows us to ensure that information is not disclosed to unauthorized persons.