Privacy Policy

Privacy Policy

Last updated: August 2026

 

1. An overview of data protection

General information

Protecting your personal data is important to us. The following information explains transparently which personal data we process when you use this website, why we need them and what rights you have. Personal data are any information that can identify you directly or indirectly. Detailed information is provided in the sections below.

 

Data recording on this website

 

Who is the responsible party for the recording of data on this website (i.e., the “controller”)?

The data on this website is processed by the operator of the website, whose contact information is available under section “Information about the responsible party (referred to as the “controller” in the GDPR)” in this Privacy Policy.

 

How do we record your data?

We collect your data when you provide it to us. This may include information you enter in a contact form or in the embedded appointment booking portal.

Other data shall be recorded by our IT systems automatically or after you consent to its recording during your website visit. This data comprises primarily technical information (e.g., web browser, operating system, or time the site was accessed). This information is recorded automatically when you access this website.

 

What are the purposes we use your data for?

Some data are processed to ensure the secure and error-free provision of the website. Further data are processed when you provide them to us, in particular to handle inquiries and schedule appointments, or – where required and only after you have given your consent – for statistical analysis of how our website is used.

 

What rights do you have as far as your information is concerned?

You have the right to receive information about the source, recipients, and purposes of your archived personal data at any time without having to pay a fee for such disclosures. You also have the right to demand that your data are rectified or eradicated. If you have consented to data processing, you have the option to revoke this consent at any time, which shall affect all future data processing. Moreover, you have the right to demand that the processing of your data be restricted under certain circumstances. Furthermore, you have the right to log a complaint with the competent supervising agency.

Please do not hesitate to contact us at any time if you have questions about this or any other data protection related issues.

 

2. Hosting

We are hosting the content of our website at the following provider:

 

IONOS

This website is hosted under the IONOS Webhosting Plus plan by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. According to IONOS, when the website is accessed, IONOS processes the referrer, the requested page or file, browser type and browser version, the operating system used, device type, time of access and the IP address in anonymised form. The data are used to ensure the security and stability of the hosting service and, according to IONOS, are retained for eight weeks. According to IONOS, these visitor data are neither disclosed to third parties nor transferred to countries outside the European Union. We have entered into a data processing agreement with IONOS pursuant to Art. 28 GDPR.

According to the IONOS product information, IONOS SiteAnalytics is also used as part of the webhosting service. Data are collected via log files or a pixel without the use of cookies. According to IONOS, the IP address transmitted when a page is accessed is anonymised immediately; the analysis is used exclusively for statistical purposes and the technical optimisation of the website. The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and technically optimised provision of the website. Further information: data processing by IONOS Web Hosting products and IONOS SiteAnalytics.

 

3. General information and mandatory information

Data protection

The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration.

Whenever you use this website, a variety of personal information will be collected. Personal data comprises data that can be used to personally identify you. This Data Protection Declaration explains which data we collect as well as the purposes we use this data for. It also explains how, and for which purpose the information is collected.

We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.

 

Information about the responsible party (referred to as the “controller” in the GDPR)

The data processing controller on this website is:

MolAquaTech GmbH
Business address (administration)
Leverkusenstraße 4
06258 Schkopau
Germany
Managing Director (CEO): Jan Koppe

Phone: +49 3461 3086 300
E-mail: info@molaquatech.com

The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data (e.g., names, e-mail addresses, etc.).

 

Storage duration

Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.

 

General information on the legal basis for the data processing on this website

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9 (2)(a) GDPR, if special categories of data are processed according to Art. 9(1) GDPR. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49 (1)(a) GDPR. If you have consented to the storage of cookies or to the access to information in your end device (e.g., via device fingerprinting), the data processing is additionally based on § 25 (1) TDDDG. The consent can be revoked at any time. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, if your data is required for the fulfillment of a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Furthermore, the data processing may be carried out on the basis of our legitimate interest according to Art. 6(1)(f) GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.

 

Recipients of personal data

In the scope of our business activities, we cooperate with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is required as part of the fulfillment of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Art. 6 (1)(f) GDPR, or if another legal basis permits the disclosure of this data. When using processors, we only disclose personal data of our customers on the basis of a valid contract on data processing. In the case of joint processing, a joint processing agreement is concluded.

 

Revocation of your consent to the processing of data

A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.

 

Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)

Where personal data are processed on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds arising from your particular situation, to the processing of your personal data. This also applies to profiling based on those provisions. The applicable legal basis is set out in this Privacy Policy. If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims (objection pursuant to Art. 21(1) GDPR).

If your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing, including profiling to the extent that it is related to such direct marketing. If you object, your personal data will no longer be used for direct marketing purposes (objection pursuant to Art. 21(2) GDPR).

 

Right to log a complaint with the competent supervisory agency

In the event of violations of the GDPR, data subjects are entitled to log a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred. The right to log a complaint is in effect regardless of any other administrative or court proceedings available as legal recourses.

 

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you should demand the direct transfer of the data to another controller, this will be done only if it is technically feasible.

 

Information about, rectification and eradication of data

Within the scope of the applicable statutory provisions, you have the right to demand information about your archived personal data, their source and recipients as well as the purpose of the processing of your data at any time. You may also have a right to have your data rectified or eradicated. If you have questions about this subject matter or any other questions about personal data, please do not hesitate to contact us at any time.

 

Right to demand processing restrictions

You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. To do so, you may contact us at any time. The right to demand restriction of processing applies in the following cases:

  • In the event that you should dispute the correctness of your data archived by us, we will usually need some time to verify this claim. During the time that this investigation is ongoing, you have the right to demand that we restrict the processing of your personal data.
  • If the processing of your personal data was/is conducted in an unlawful manner, you have the option to demand the restriction of the processing of your data instead of demanding the eradication of this data.
  • If we do not need your personal data any longer and you need it to exercise, defend or claim legal entitlements, you have the right to demand the restriction of the processing of your personal data instead of its eradication.
  • If you have raised an objection pursuant to Art. 21(1) GDPR, your rights and our rights will have to be weighed against each other. As long as it has not been determined whose interests prevail, you have the right to demand a restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – with the exception of their archiving – may be processed only subject to your consent or to claim, exercise or defend legal entitlements or to protect the rights of other natural persons or legal entities or for important public interest reasons cited by the European Union or a member state of the EU.

 

SSL and/or TLS encryption

For security reasons and to protect the transmission of confidential content, in particular your inquiries, this website uses SSL or TLS encryption. You can recognize an encrypted connection by checking whether the browser address changes from “http://” to “https://” and by the lock icon in your browser.

If the SSL or TLS encryption is activated, data you transmit to us cannot be read by third parties.

 

4. Recording of data on this website

Contact form

If you contact us using the contact form, we process the information you enter, in particular your name, e-mail address, an optional telephone number and information on how you found us, for the purpose of handling and responding to your inquiry. Providing a telephone number is voluntary; if provided, it may be used to call you back.

Fields marked with an asterisk must be completed in order to submit the form. Where your inquiry relates to entering into or performing a contract, the processing is based on Art. 6(1)(b) GDPR. In all other cases, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper handling of incoming inquiries.

The form data are sent by e-mail to info@molaquatech.com and processed and stored in our Microsoft 365 / Exchange Online system. Access is limited to employees responsible for handling the inquiry. Contact inquiries and the related communication that do not result in a business relationship are deleted no later than twelve months after the inquiry has been finally handled. Where the communication is required for an existing or specifically initiated contractual relationship, for the establishment, exercise or defence of legal claims, or due to statutory retention obligations, it may be retained for a correspondingly longer period. Further information on processing through Microsoft 365 is provided in the following section.

To protect the form against automated submissions, it uses an integrated arithmetic task (“Basic Captcha”). No external CAPTCHA or spam-protection service is activated.

 

Contact by e-mail or telephone

If you contact us by e-mail or telephone, we process the contact details you provide and the content of your inquiry in order to handle and respond to your request. Where your contact relates to entering into or performing a contract, the processing is based on Art. 6(1)(b) GDPR. In all other cases, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper handling of incoming inquiries.

E-mails sent directly to us are processed and stored in our Microsoft 365 / Exchange Online system. Inquiries and related communications that do not result in a business relationship are deleted no later than twelve months after the inquiry has been finally handled. Where the communication is required for an existing or specifically initiated contractual relationship, for the establishment, exercise or defence of legal claims, or due to statutory retention obligations, it may be retained for a correspondingly longer period.

 

Microsoft 365, Exchange Online and Microsoft Bookings

We use Microsoft 365, Exchange Online and Microsoft Bookings for business e-mail communications and online appointment booking. For users in the European Economic Area, the provider is generally Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft generally processes our customer data as a processor under the Microsoft Products and Services Data Protection Addendum. For certain limited business operations of its own, Microsoft may process personal data as an independent controller.

E-mails submitted through the contact form and e-mails sent directly to us are stored in Exchange Online and accessed through Microsoft Outlook. Microsoft Bookings is embedded on the “Book an appointment” page as an external booking function. Borlabs Cookie blocks the booking interface and loads it only after you have consented to the service in the “External media” category.

Appointments may take place online or on site at our head office or our Engineering & Operations site. When you make a booking, we process in particular the selected appointment and service, date, time and time zone, as well as the information you enter. Under the current configuration, first and last name, e-mail address and the special requests field are marked as required. The special requests field is used to identify the topic of the meeting and to prepare for the appointment appropriately. Address and telephone number are optional. The booking cannot be completed without the required information. Before submission, you must also confirm that you have read and acknowledged the privacy information provided on the booking page.

The embedded booking interface is loaded on the basis of your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR. Where the appointment relates to entering into or performing a contract, the booking data you provide are processed on the basis of Art. 6(1)(b) GDPR. In all other cases, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in organising, preparing for and conducting requested business or professional meetings.

Microsoft Bookings stores customer, service and appointment data within the Microsoft 365 platform and in Exchange Online. After an appointment has been booked, Microsoft Bookings automatically sends a booking confirmation. An automatic reminder is sent one hour before the scheduled appointment. An individual Microsoft Teams link is generated automatically for the online appointment and provided together with the appointment details. The appointment, including the booking data and Teams link, is stored in the personal Microsoft 365 / Exchange Online calendar of the managing director responsible for conducting the meeting. Regular access within MolAquaTech GmbH is restricted to this managing director. Technically authorised administrators may obtain access only to the extent required for administration, security or troubleshooting. Where a booking does not result in a business relationship, we delete the booking and appointment data stored by us, including the calendar entry and the confirmation, reminder and related communications stored by us, no later than twelve months after the appointment has taken place or been cancelled. Statutory retention obligations and other legally permissible grounds for longer retention remain unaffected.

When you participate in a Microsoft Teams appointment, the display name you use, meeting and connection data, and technical device information are processed in particular. Depending on the functions you use, audio and video data, chat messages and screen content you share may also be processed. Where the appointment relates to entering into or performing a contract, the processing is based on Art. 6(1)(b) GDPR. In all other cases, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in conducting requested business or professional online meetings.

Online meetings are generally not recorded or transcribed, and Microsoft 365 Copilot is not used during these meetings. If a recording or transcription is intended in an individual case, the affected participants will be expressly informed in advance. The relevant function will be activated only after separate consent has been obtained.

Microsoft may use subprocessors to provide the services and may also process data outside the European Economic Area. Where required, Microsoft relies in particular on appropriate safeguards such as standard contractual clauses. Further information: Microsoft Privacy Statement and Microsoft Bookings privacy information.

 

Cookies

Our website uses cookies and comparable technologies. Cookies are small text files that may be stored on your device or may access information stored on your device. They may be stored for the duration of a session or for a longer period.

Cookies and comparable technologies may be used by us or by third-party providers. Where storing information on or accessing information from your device is strictly necessary to provide a digital service expressly requested by you, no consent is required for that operation (Section 25(2) no. 2 TDDDG). Any subsequent processing of personal data is carried out on the legal basis stated for the respective purpose.

Cookies and comparable technologies that are not strictly necessary are used only after you have given your prior consent (Section 25(1) TDDDG). The related processing of personal data is based on Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future.

You can also configure your browser to notify you when cookies are set, to permit cookies only in individual cases, or to reject cookies in certain cases or in general. Disabling cookies may limit the functionality of this website.

 

Consent with Borlabs Cookie

Our website uses the Borlabs consent technology to obtain your consent to the storage of certain cookies in your browser or for the use of certain technologies and for their data privacy protection compliant documentation. The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany (hereinafter referred to as Borlabs).

Whenever you visit our website, a Borlabs cookie will be stored in your browser, which archives any declarations or revocations of consent you have entered. These data are not shared with the provider of the Borlabs technology.

The recorded data shall remain archived until you ask us to eradicate them, delete the Borlabs cookie on your own or the purpose of storing the data no longer exists. This shall be without prejudice to any retention obligations mandated by law. To review the details of Borlabs’ data processing policies, please visit https://borlabs.io/kb/what-information-does-borlabs-cookie-store/.

We use the Borlabs cookie consent technology to obtain the declarations of consent mandated by law for the use of cookies. The legal basis for the use of such cookies is Art. 6(1)(c) GDPR.

 

Jetpack Stats

We use Jetpack Stats to statistically analyse how our website is used. According to Automattic, the company generally responsible for individuals in Europe is Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland. Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA, is also responsible for certain processing activities.

Jetpack Stats processes in particular the IP address, a WordPress.com user ID and username where available, the user agent, the URL visited, the referring URL, the time of the event, browser language and country code. In particular, page and post views, outbound link clicks, referring URLs and search terms, as well as technical page-load performance data, may be recorded. MolAquaTech generally receives aggregated statistics and no directly identifying visitor data.

Jetpack Stats is blocked by Borlabs Cookie and is activated only after you have consented to the “Statistics” category. The legal bases are Section 25(1) TDDDG for storing information on or accessing information from your device and Art. 6(1)(a) GDPR for the related processing of personal data. You may withdraw your consent at any time with effect for the future through the cookie settings.

Automattic states that logs containing directly identifying information such as IP addresses and, where available, WordPress.com usernames are retained for 28 days. As the services are provided worldwide, data may be processed outside the European Economic Area. Automattic states that, where required, it uses European Commission-approved standard contractual clauses or comparable safeguards for such transfers.

Further information: Automattic Privacy Policy and Jetpack Stats privacy information.

Process Stability Starts with Water.

Secure. Precise. Proven.

General

About us

Contact

Book an appointment

Legal notice

Privacy Policy

Contact us

Service

Legionella

Water treatment

Solutions and Services

© MOLAquaTech 2026 - powered by NR.Digital