Privacy policy
This English version is provided for convenience. The German version is legally binding.
This is a plain-English reading version of our German privacy policy. It lists the same processing activities, services, legal bases and rights. If anything here differs from the German text, the German text applies.
1. In short
- What this page is about: what happens to your personal data when you visit this website. Personal data means any information that can identify you.
- Who is responsible: Neurolytix GmbH as the operator of this website (contact details in section 3).
- How data reaches us: partly because you give it to us, for example through a contact form; partly because our systems record it when you open the website, either automatically or after you have agreed. This is mostly technical data such as your browser, operating system and the time of your visit.
- Why we use it: to deliver the website without errors and, in some cases, to analyse how visitors use it. Analytics tools are described in section 5.
- Your rights: free information about your data, correction, deletion, restriction, data portability, withdrawal of consent, objection and a complaint to a supervisory authority. Details are in section 3. You can contact us about data protection at any time.
2. Hosting
- Host: Timme Hosting GmbH & Co. KG, Ovelgönner Weg 43, 21335 Lüneburg, Germany.
- What is stored there: all personal data collected on this website, for example IP addresses, contact requests, metadata and communication data, contract data, contact details, names, records of page visits and other data a website generates.
- Legal basis: performing contracts with current and prospective customers (Art. 6(1)(b) GDPR) and our legitimate interest in a secure, fast and efficient website run by a professional provider (Art. 6(1)(f) GDPR). Where we ask for consent, see “Consent instead of legitimate interest” in section 3.
- Safeguards: the host only processes data as far as it needs to in order to provide its services and follows our instructions. We have a data processing agreement with the host, as data protection law requires.
3. Responsibility, legal bases and your rights
Controller
Neurolytix GmbH
Hauptstraße 127
68259 Mannheim
Germany
Email: info@neurolytix.de
The controller is whoever decides, alone or with others, why and how personal data (such as names or email addresses) is processed.
Confidentiality and security
We handle your data confidentially, in line with data protection law and this policy. Sending data over the internet, by email for instance, is never completely secure; full protection against access by third parties cannot be guaranteed. Pages on this website are transmitted with SSL/TLS encryption, for example when you place an order or send us an enquiry. You can tell by “https://” and the padlock in your browser's address bar. While the connection is encrypted, third parties cannot read what you send us.
How long we keep data
Unless a section below gives a specific period, we keep personal data until we no longer need it for the purpose it was collected for. If you justifiably ask us to delete it, or withdraw your consent, we delete it, unless the law allows or requires us to keep it, for example under tax or commercial retention rules. In that case we delete it when that reason ends.
Legal bases we rely on
- Consent: Art. 6(1)(a) GDPR; for special categories of personal data (Art. 9(1) GDPR), Art. 9(2)(a) GDPR; for transfers to third countries based on your explicit consent, also Art. 49(1)(a) GDPR; if your consent covers cookies or access to information on your device (such as device fingerprinting), also Section 25(1) of the German TDDDG.
- Contract: Art. 6(1)(b) GDPR, where we need the data to perform a contract with you or to take steps before entering into one.
- Legal obligation: Art. 6(1)(c) GDPR.
- Legitimate interests: Art. 6(1)(f) GDPR.
Consent instead of legitimate interest: for several services below we rely on our legitimate interest. If we have asked for your consent for such a service, the processing is based only on that consent (Art. 6(1)(a) GDPR and, where cookies or access to your device are involved, Section 25(1) TDDDG).
Transfers to the USA and other third countries
Some tools we use come from companies in the USA or other third countries whose data protection is not considered adequate. When these tools are active, your data may be transferred to and processed in those countries, where protection comparable to the EU cannot be guaranteed. US companies, for example, can be obliged to hand data to security authorities without you having a way to challenge this in court, so US authorities, including intelligence services, may process, evaluate and keep your data on US servers for surveillance. We cannot influence this.
Your rights
- Withdraw consent: you can withdraw any consent at any time. This does not affect processing that took place before you withdrew it.
- Access, correction, deletion: within the limits of the law, you can find out free of charge at any time what data we hold about you, where it comes from, who receives it and why we process it, and you may have a right to have it corrected or deleted.
- Restriction: you can ask us to restrict processing (a) while we check whether data you say is wrong is correct, (b) instead of deletion if the processing was or is unlawful, (c) instead of deletion if we no longer need the data but you need it for legal claims, and (d) after an objection under Art. 21(1) GDPR, until it is clear whose interests prevail. While processing is restricted, we only store the data; any other use needs your consent or must serve legal claims, the protection of another person's rights or an important public interest of the EU or a member state.
- Data portability: data we process automatically on the basis of your consent or a contract can be handed over to you or a third party in a common machine-readable format; a direct transfer to another controller only where technically feasible.
- Complaint: you can complain to a supervisory authority, in particular in the member state where you live, work or where the suspected breach happened. Other administrative or judicial remedies remain available.
Your right to object (Art. 21 GDPR)
If we process your data on the basis of Art. 6(1)(e) or (f) GDPR, you can object at any time for reasons arising from your particular situation; this includes profiling based on those provisions. The legal basis of each processing activity is named in this policy. After an objection, we stop processing the data concerned unless we can show compelling legitimate grounds that outweigh your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims (Art. 21(1) GDPR).
If we use your data for direct marketing, you can object to this at any time, including any profiling connected with it. Your data will then no longer be used for direct marketing (Art. 21(2) GDPR).
Unsolicited advertising
We do not agree to the contact details in our legal notice being used to send us advertising or information material we have not asked for, and we reserve the right to take legal action against unsolicited advertising such as spam emails.
4. Data collected on this website
Cookies
- What they are: small files stored on your device that do not harm it. Session cookies disappear when your visit ends; permanent cookies stay until you or your browser delete them. Third-party companies may also set cookies when you visit us, for example to handle payments.
- Purposes: some cookies are technically necessary (for example for the shopping cart or for showing videos); others analyse how the website is used or display advertising.
- Legal basis: necessary cookies (for the electronic communication, for functions you request such as the shopping cart, or for optimising the website, such as audience measurement): Art. 6(1)(f) GDPR, unless another basis is named; our interest is a technically faultless and optimised website. Where we ask for consent to cookies or similar recognition technologies: only that consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG), which you can withdraw at any time.
- Your options: your browser can notify you about cookies, accept them only case by case, block them for certain cases or entirely, and delete them when it closes. Without cookies, parts of the website may not work.
- Third-party and analytics cookies are explained under the relevant service in this policy, and we ask for your consent where required.
Borlabs Cookie (consent management)
- Provider: Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany.
- What happens: we use Borlabs Cookie to ask for and record your consent to certain cookies and technologies. A Borlabs cookie in your browser stores the consents you give or withdraw. This data is not sent to Borlabs.
- Storage: until you ask us to delete it, you delete the cookie yourself, or the purpose ends; mandatory retention periods remain unaffected. Details from the provider (in German): https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.
- Legal basis: Art. 6(1)(c) GDPR, because the law requires us to obtain consent for certain cookies.
Server log files
- What happens: the provider of these pages automatically stores information your browser sends: browser type and version, operating system, referrer URL, host name of the accessing computer, time of the request and IP address. We do not combine this with other data sources.
- Legal basis: Art. 6(1)(f) GDPR; we need the log files to present the website without technical errors and to optimise it.
Contact form, email, telephone and fax
- What happens: when you send us an enquiry through the contact form, by email, by telephone or by fax, we store what you send us, including your contact details and other personal data in the enquiry (such as your name), so that we can deal with it and with any follow-up questions. We do not pass it on without your consent.
- Legal basis: Art. 6(1)(b) GDPR if the enquiry relates to a contract or to steps before a contract; otherwise our legitimate interest in handling enquiries effectively (Art. 6(1)(f) GDPR) or, if we asked for it, your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
- Storage: until you ask us to delete the data, withdraw your consent, or the purpose ends (for example once your enquiry has been dealt with). Mandatory statutory rules, especially retention periods, remain unaffected.
ProvenExpert
- Provider: Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin, Germany (https://www.provenexpert.com).
- What happens: a ProvenExpert seal on our website shows customer reviews of our company submitted on ProvenExpert. When you visit our website, your browser connects to ProvenExpert, so ProvenExpert learns that you have visited us. ProvenExpert also reads your language settings to show the seal in your language.
- Legal basis: Art. 6(1)(f) GDPR; our interest is to present customer reviews in a transparent way. Where we ask for consent, see “Consent instead of legitimate interest” in section 3.
5. Analytics and advertising
Google Tag Manager
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- What happens: Tag Manager is used to add and manage tracking, statistics and other tools on our website. It does not build user profiles, set cookies or run analyses of its own, but it does record your IP address, which may also be sent to Google's parent company in the USA.
- Legal basis: Art. 6(1)(f) GDPR; our interest is to add and manage tools quickly and easily. Where we ask for consent, see “Consent instead of legitimate interest” in section 3.
Google Analytics
- Provider: Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
- What happens: we analyse how visitors use our website, for example pages viewed, time spent, operating system and where visitors come from. The data is grouped under a user ID linked to your device. We can also record mouse and scroll movements and clicks. Google adds modelled data and uses machine learning in the analysis, and recognises users with cookies or device fingerprinting.
- Google signals: we use Google signals. Google Analytics then also records data such as your location, search history, YouTube history and demographic data. This can be used for personalised advertising and, if you have a Google account, is linked to that account for personalised ads. It is also used for anonymised statistics on how our users behave.
- Transfers outside the EU: the data is usually sent to and stored on Google servers in the USA, based on the European Commission's standard contractual clauses: https://privacy.google.com/businesses/controllerterms/mccs/.
- Legal basis: your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG), which you can withdraw at any time.
- Safeguards: we have a data processing agreement with Google and apply the strict requirements of the German data protection authorities in full.
- Your options: a browser add-on from Google stops the collection: https://tools.google.com/dlpage/gaoptout?hl=en. How Google handles this data: https://support.google.com/analytics/answer/6004245?hl=en.
Google conversion tracking
- Provider: Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
- What happens: Google and we can see whether users took certain actions, for example which buttons were clicked how often and which products were viewed or bought most. From this we get conversion statistics: the total number of users who clicked our ads and what they did next, but nothing that identifies a person. Google uses cookies or similar technologies to recognise users.
- Legal basis: your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG), which you can withdraw at any time.
- More information: https://policies.google.com/privacy?hl=en.
Facebook Pixel
- Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
- What happens: the pixel measures conversions: it shows what visitors do on our website after clicking one of our Facebook ads, so we can judge how well the ads work for statistics and market research and improve future campaigns. To us the data is anonymous. Facebook, however, stores and processes it, can link it to the user's profile and can use it for its own advertising, on and off Facebook, under its data use policy. We have no influence on this.
- Transfers outside the EU: according to Facebook, data is also sent to the USA and other third countries, based on the European Commission's standard contractual clauses: https://www.facebook.com/legal/EU_data_transfer_addendum and https://www.facebook.com/help/566994660333381.
- Legal basis: your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG), which you can withdraw at any time.
- Joint controllers (Art. 26 GDPR): for collecting the data on our website and passing it to Facebook, we and Meta Platforms Ireland Limited are jointly responsible; what Facebook does with the data afterwards is not covered. The agreement is available at https://www.facebook.com/legal/controller_addendum. Under it, we provide the data protection information and implement the tool securely on our website; Facebook is responsible for the security of its products. You can exercise your rights regarding data processed by Facebook directly with Facebook; if you contact us, we have to forward your request to Facebook.
- Your options: Facebook's privacy information: https://www.facebook.com/about/privacy/. If you are logged in to Facebook, you can switch off “Custom Audiences” in your ad settings: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. Without a Facebook account, you can opt out of usage-based advertising on the website of the European Interactive Digital Advertising Alliance: https://www.youronlinechoices.eu/.
6. Newsletter
What we need
To send you our newsletter, we need your email address and information that lets us check that the address is yours and that you want the newsletter. Anything else is optional. We use the newsletter service provider described below.
Sendinblue
- Provider: Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. The data you enter to subscribe is stored on Sendinblue servers in Germany.
- What happens: Sendinblue sends our newsletters and lets us analyse them: whether a newsletter was opened, which links were clicked and how often, and whether a defined action such as a purchase followed (conversion rate). Sendinblue can also group recipients (“clustering”), for example by age, gender or place of residence, so that we can tailor newsletters to each group. The only way to avoid this analysis is to unsubscribe, using the link in every newsletter. Sendinblue's description of its functions (in German): https://de.sendinblue.com/newsletter-software/.
- Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time without affecting processing that has already taken place.
- Storage: until you unsubscribe; your address is then removed from the mailing list. Data stored for other purposes is not affected. To make sure you receive no further mailings, we or Sendinblue may keep your address on a blocklist, used only for that purpose and not combined with other data. This serves your interest and ours in meeting the legal rules for newsletters (Art. 6(1)(f) GDPR). The blocklist entry has no time limit; you can object if your interests outweigh ours. Sendinblue's privacy information (in German): https://de.sendinblue.com/datenschutz-uebersicht/.
- Safeguards: we have a data processing agreement with the provider, as data protection law requires, so it processes our visitors' data only on our instructions and in line with the GDPR.
7. Plugins and tools
Google Fonts and Font Awesome
We use both, installed locally, to display fonts consistently. Your browser does not connect to Google or to Fonticons, Inc. for them. More information: https://developers.google.com/fonts/faq, https://policies.google.com/privacy?hl=en and https://fontawesome.com/privacy.
Google reCAPTCHA
- Provider: Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
- What happens: reCAPTCHA checks whether entries on this website, for example in a contact form, come from a person or a bot. From the moment you open the website, it analyses your behaviour in the background, for example your IP address, how long you stay and how you move the mouse, and sends the results to Google. You are not notified that this analysis is running.
- Legal basis: Art. 6(1)(f) GDPR; our interest is protecting the website against automated misuse and spam. Where we ask for consent, see “Consent instead of legitimate interest” in section 3.
- More information: https://policies.google.com/privacy?hl=en and https://policies.google.com/terms?hl=en.
ManageWP
- Provider: GoDaddy.com WP Europe, Trg republike 5, 11000 Belgrade, Serbia.
- What happens: we use ManageWP to administer the website, monitor its security and performance and make automatic backups. ManageWP therefore has access to all website content, including our databases, and runs on the provider's servers.
- Legal basis: Art. 6(1)(f) GDPR; our interest is running the website as effectively and securely as possible. Where we ask for consent, see “Consent instead of legitimate interest” in section 3.
- Safeguards: we have a data processing agreement with the provider, as data protection law requires.
8. Orders and payment
- What happens: we use customer and contract data to set up, shape and change our contracts with you. Data about your use of this website (usage data) is only used as far as necessary to let you use the service or to bill it.
- Legal basis: Art. 6(1)(b) GDPR.
- Storage: deleted once the order is complete or the business relationship has ended and any statutory retention periods have expired.
