Privacy Notice
Last updated: 21 July 2026
1. Scope
This Privacy Notice explains how FBI Science e.K. processes personal data when you use the publicly accessible website at https://fbiscience.com, including the German- and English-language pages in the /wp/ directory.
It does not apply to separate customer portals, software products, applications, other domains or third-party websites to which we merely provide links. Separate privacy information may apply to those services.
Personal data means any information relating to an identified or identifiable natural person.
2. Controller
FBI Science e.K.
Kempstraße 75
41748 Viersen
Germany
Telephone: +49 2162 89006-61
Email: info@fbiscience.com
Website: https://fbiscience.com
You may send privacy enquiries and requests concerning your data protection rights to the email address above.
3. Provision of the website and server logs
Whenever you access our website, the web server processes technical access data. This may include the IP address of the accessing device, date and time, requested page or file, HTTP method and protocol version, amount of data transferred, HTTP status code, referrer URL, browser type and version, operating system and device type, requested hostname and technical error or diagnostic information.
We process this information to deliver the website, ensure its stability and security, diagnose errors, prevent abusive access and attacks, and maintain the availability of our systems. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and economically efficient operation of the website and the protection of our systems and users.
Raw log files are stored using a rotation process and are regularly overwritten. Visitor logs are not included in website backups. Data relating to a security incident may be retained until the incident has been fully investigated and, where necessary, for the establishment, exercise or defence of legal claims.
4. Hosting and email infrastructure
The website and associated email infrastructure are operated on a server within infrastructure provided by:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
We have entered into a data-processing agreement with STRATO pursuant to Article 28 GDPR. Contractually bound subprocessors authorised by STRATO may be involved where necessary. The hosting provider processes server, connection and communication data to the extent required to provide, maintain, secure and troubleshoot the infrastructure.
The legal basis is Article 6(1)(f) GDPR. Where processing is necessary for a contract or pre-contractual measures, Article 6(1)(b) GDPR also applies.
5. Pseudonymised access statistics using Webalizer
We use Webalizer software installed on our own server to generate local access statistics from server logs. Directly attributable identifiers are pseudonymised or shortened before the statistical evaluation. Reports are not combined with other data sources and are not used to identify individual visitors.
Webalizer does not set analytics or marketing cookies. Processing takes place on our server, and data is not sent to the developer of Webalizer, Google or other advertising or analytics providers for this purpose. Access to the statistics is password-protected and restricted to authorised persons.
The processing is used to improve and secure the website, plan capacity and identify unusual access patterns. The legal basis is Article 6(1)(f) GDPR. Monthly pseudonymised reports are retained for the current month and up to 24 completed months.
6. Cookies and similar technologies
Our website currently uses only the first-party cookie pll_language. It stores the selected or determined language version for up to one year. The cookie is not used for advertising, audience measurement, user profiling or cross-site tracking.
Storage of or access to the cookie is permitted under Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG), as it is used to provide the multilingual version requested by the user. To the extent that personal data is processed, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the consistent and user-friendly provision of the selected language.
You may delete or block the cookie in your browser settings. The preferred language may then have to be selected again during a later visit.
As the website currently does not use analytics, advertising or other non-essential cookies requiring consent, no consent banner is required. If such technologies are introduced in the future, they will be activated only after valid consent has been obtained where required, and this Privacy Notice will be updated.
7. Website search
When you use the website search, the search term is sent to our server and processed to display the requested results. It may form part of the requested URL and temporarily appear in server logs. The legal basis is Article 6(1)(f) GDPR. Please do not enter personal or confidential information in the search field.
8. Contact and consultation forms
We provide forms on the “Kontakt”, “Contact” and “Consultation” pages. The information processed may include your name, email address, message, any other information supplied voluntarily, time of submission and technical connection information recorded in the server logs.
We use this information solely to handle your enquiry and conduct the communication you requested. Where an enquiry concerns an existing contract or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR. General business or professional enquiries are processed under Article 6(1)(f) GDPR. Where processing is necessary to comply with a legal obligation, Article 6(1)(c) GDPR also applies.
To prevent automated spam, we use only a locally operated arithmetic question and a honeypot field. No external CAPTCHA provider is integrated, and no information is transmitted to Google reCAPTCHA. Messages are forwarded to our own email system; no external form or CRM provider is used.
We erase contact enquiries once they have been finally dealt with and there is no legal retention requirement, contractual necessity or legitimate interest requiring further storage. Depending on their classification, commercial correspondence and accounting records may be subject to statutory retention periods of six, eight or ten years. Information required for legal claims may be retained until the relevant limitation periods have expired.
Please do not submit special categories of personal data within the meaning of Article 9 GDPR, including health data, unless this is strictly necessary and has been agreed with us in advance.
9. Communication by email, telephone, fax or post
If you contact us by email, telephone, fax or post, we process the contact details you provide, the content of the communication and the resulting communication and metadata. The purposes, legal bases and retention principles are the same as those described for contact forms.
Emails are protected by transport encryption where participating mail servers support it. Completely confidential communication over the internet cannot be guaranteed. Please contact us in advance to agree on an appropriate method for particularly confidential information.
10. External links and downloads
Our website contains links to websites and downloads offered by other providers. Merely viewing our pages does not establish a connection to those providers. A direct connection is established only when you click an external link. Your browser may then transmit your IP address, time of access, technical browser data and possibly the referring page. The operator of the destination website is generally responsible for subsequent processing.
11. No external analytics or advertising services
According to the current technical configuration, we do not use Google Analytics, Google Ads, Google reCAPTCHA, externally loaded Google Fonts, the Meta/Facebook Pixel, LinkedIn Insight Tag, embedded YouTube or Vimeo players, or comparable tracking or profiling services. Font files are delivered locally from our own server.
12. Recipients
Depending on the processing activity, personal data may be disclosed to responsible employees, hosting, IT, maintenance and security providers, telecommunications and email providers, professional advisers, public authorities or courts where this is necessary or required by law. Where required, service providers are bound by agreements under Article 28 GDPR. We do not sell personal data or disclose it for third-party advertising.
13. Transfers to third countries
The functions currently integrated into the website do not automatically transmit visitor data to providers outside the European Union or European Economic Area. Where a service provider processes data in a third country in an individual case, this will take place only in accordance with Articles 44 et seq. GDPR.
14. Data security
We use appropriate technical and organisational measures to protect personal data. The website is transmitted using encrypted HTTPS/TLS connections. Despite appropriate safeguards, no transmission of data over the internet can be guaranteed to be completely risk-free.
15. Requirement to provide information
Technical connection information must be processed in order to deliver the website. Fields marked as mandatory in a contact form are required so that we can assign and respond to your enquiry. Without sufficient contact details and information, we may not be able to handle your request.
16. Automated decision-making and profiling
We do not use personal data collected through this website for decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR. We do not carry out profiling.
17. Your rights
Subject to the applicable statutory requirements, you have the right of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR, data portability under Article 20 GDPR, objection under Article 21 GDPR, withdrawal of consent with effect for the future under Article 7(3) GDPR, and the right to lodge a complaint under Article 77 GDPR.
You may exercise your rights by contacting info@fbiscience.com. To prevent unauthorised disclosure, we may request reasonable proof of identity.
18. Specific information about the right to object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims. You may object to processing for direct-marketing purposes at any time without stating reasons.
19. Right to lodge a complaint
You may lodge a complaint with any competent data protection supervisory authority. The authority responsible for our registered office is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Telephone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de
20. Changes to this Privacy Notice
We will update this Privacy Notice whenever the website, services used, processing activities or applicable legal requirements change. The current version will be available on this page.