Privacy Policy

Here you will find our privacy policy. Please read this statement carefully and at your leisure. You are welcome to contact us at any time if you have any questions about it.

Data protection is particularly important to us:

Vimmera AI Solutions GmbH implements even more extensive measures for data protection and data security than are required by law. -Company data and personal data are sensitive and must be protected without exception. We therefore rely on encryption and additional security measures for data transmission and data storage (if we store data at all).

Please feel free to contact us if you have any questions about this as well.

Fully encrypted and confidential communication with us is possible by email. -We use OpenPGP for this purpose. The public keys for encryption can be found on the relevant key servers.

Privacy Policy

  1. Controller

Controller responsible for the processing of personal data is:

Vimmera AI Solutions GmbH
Löwestrasse 66
14612 Falkensee
Germany

E-Mail: info@vimmera.de

This privacy policy informs you about the processing of personal data when visiting our website www.vimmera.de, when using the publicly accessible chat “Mera”, when contacting us and using forms, when applying for jobs, in connection with our LinkedIn company profile, and in the context of business relationships.

Separate privacy information may apply to non-publicly accessible platform, customer, or project services provided under contract.

  1. Visiting our website

When our website is accessed, technically necessary access data is processed. This includes in particular the IP address, date and time of access, the page or file accessed, browser and device information, as well as status, error, and security data.

The processing is carried out to provide the website, ensure its stability and security, detect technical errors, and defend against abusive access. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of our website and IT systems.

Recipients of the data may include hosting, IT, security, and maintenance service providers used by us who act on our behalf.

The access data is generally deleted or anonymized after 14 days at the latest. If there are concrete indications of a security incident or unlawful use, the necessary data may be stored until the investigation has been completed or legal claims have been enforced or defended.

  1. Contacting us

If you contact us by email, telephone, or contact form, we process your contact details and the content of the communication in order to handle your request and communicate with you.

If the request relates to a contract or pre-contractual measures, Art. 6(1)(b) GDPR is the legal basis. For other inquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper handling of inquiries and the maintenance of business contacts.

Recipients may include hosting, email, communication, and IT service providers used by us.

The data will be deleted once the inquiry has been fully processed and there are no statutory retention obligations or legitimate reasons for further storage. Contract- and billing-related communication is stored in accordance with the statutory retention periods.

Data marked as mandatory is required in order to process your request. Without this information, processing may not be possible. Further information is voluntary.

  1. Forms and feedback

If you use a form for feedback, reviews, suggestions, or other comments, we process the information you enter and the technical data required for transmission. The processing serves to evaluate the feedback and improve our offers, services, or events.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in evaluating feedback and improving our services. Where we obtain consent in individual cases, Art. 6(1)(a) GDPR is the legal basis.

Recipients may include internally responsible persons as well as hosting, form, and IT service providers used by us. Disclosure to other parties takes place only insofar as this is necessary for the stated purpose.

Feedback data is deleted as soon as the evaluation has been completed. Feedback on events is generally deleted no later than three months after the respective event, unless statutory retention obligations or specific legal claims require longer storage.

Please do not enter special categories of personal data, confidential information, or personal data of third parties in forms not intended for this purpose.

  1. Publicly accessible chat “Mera”

When using Mera, we process the content you enter, the responses generated, as well as technical usage, connection, security, and log data. In principle, you do not need to provide your name to use it.

The processing is carried out to provide the chat, answer inquiries, provide information about our company and our services, ensure quality assurance and error analysis, and guarantee technical security and prevent misuse.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in the user-friendly provision of information, efficient communication, and the secure operation of the chat. If your inquiry is specifically aimed at initiating a contract, Art. 6(1)(b) GDPR is an additional legal basis.

Recipients may include hosting, cloud, AI infrastructure, security, and IT service providers used by us who act on our behalf.

The chat content and associated technical data are generally deleted three months after the end of the respective chat session. Longer storage takes place only insofar as this is necessary due to a security incident, for the enforcement or defense of legal claims, or due to legal obligations. Any remaining data in backup copies after regular deletion will be deleted or overwritten within the framework of the defined backup and overwrite cycles within a maximum of three additional months.

Entering special categories of personal data within the meaning of Art. 9 GDPR is neither required nor intended. Please also do not enter access data, trade secrets, or personal data of third parties if you are not authorized to transmit them. If, in exceptional cases, explicit consent is obtained for the processing of special categories of personal data, the processing is based on Art. 6(1)(a) and Art. 9(2)(a) GDPR. Such consent can be withdrawn at any time with effect for the future.

  1. Applications

If you apply to us, we process your contact and application data, application documents, information on qualifications and professional background, as well as the communication and assessment arising during the selection process. The processing is carried out to decide on the establishment of an employment relationship on the basis of Section 26(1) BDSG.

If you voluntarily consent to further processing, this is based on Section 26(2) BDSG in conjunction with Art. 6(1)(a) GDPR. If required application documents contain special categories of personal data, Section 26(3) BDSG and Art. 9(2)(b) GDPR also apply.

Recipients may include persons internally responsible for the application process as well as communication, hosting, and IT service providers used by us.

In the event of a rejection, the application data is generally deleted six months after the conclusion of the application process. Longer storage takes place only with your consent, due to a legal obligation, or insofar as it is necessary for the enforcement or defense of specific legal claims. In the event of hiring, the necessary data is transferred to the personnel file.

  1. Business relationships

In the context of initiating, carrying out, and processing business relationships, we process in particular names, professional contact details, companies and positions of contact persons, as well as communication, contract, project, service, invoicing, and payment data.

The processing is carried out to handle business inquiries, prepare and execute contracts, coordinate projects, communicate, issue invoices, process payments, and fulfill legal obligations as well as enforce or defend legal claims.

If the data subject is themselves a contractual partner or if pre-contractual measures are taken at their request, Art. 6(1)(b) GDPR is the legal basis. We process data of contact persons at companies or organizations on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the efficient initiation, execution, and documentation of the business relationship. Where legal obligations exist, Art. 6(1)(c) GDPR is the legal basis.

Recipients may include internally responsible persons, credit institutions and payment service providers, tax and accounting service providers, legal and specialist advisors, communication, hosting, cloud, and IT service providers, as well as authorities and courts, insofar as this is necessary for the respective purpose.

The data are stored for the duration of the initiation and performance of the business relationship. It is then deleted unless statutory retention obligations or legitimate requirements prevent this. Commercial and business letters are generally retained for six years, accounting records generally for eight years, and books, records, inventories, opening balance sheets, and annual financial statements that must be retained for longer by law are generally retained for ten years. Data required for the enforcement or defense of legal claims may be retained until the expiry of the applicable limitation periods.

  1. Data from other sources

In the business context, we may receive professional contact details from publicly accessible company websites, industry directories, or professional networks, as well as from business partners, intermediaries, or existing business contacts. In doing so, we process in particular names, professional contact details, companies, positions, areas of activity, and the respective source of the data.

The processing is carried out for business initiation, handling business inquiries, and maintaining business contacts on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in targeted business communication. For directly contract-related matters, Art. 6(1)(b) GDPR may apply.

The information required under Art. 14 GDPR will be provided no later than within one month of receiving the data, upon first communication or before the first disclosure, unless a legal exception applies.

Entering special categories of personal data is not permitted. If such data is nevertheless entered, it will not be used for additional purposes and will be deleted within the prescribed deletion periods.

  1. LinkedIn company profile

We maintain a company profile on LinkedIn. If you visit our profile or communicate with us there, we may process publicly visible profile information, comments, reactions, messages, and other content provided by you. The processing is carried out for corporate communication, public relations, and handling inquiries. The legal basis depends on the content of the communication and is Art. 6(1)(b) or Art. 6(1)(f) GDPR. Our legitimate interests lie in presenting our company externally and communicating with interested parties, customers, and business partners.

LinkedIn also processes data under its own responsibility. Further information can be found in LinkedIn’s privacy policy at https://www.linkedin.com/legal/privacy-policy. LinkedIn may also process data outside the European Economic Area. For such transfers, the transfer bases and safeguards specified by LinkedIn apply.

Data processed by us will be deleted as soon as the respective communication has ended and there are no statutory retention obligations or legitimate reasons for further storage. For storage by LinkedIn, LinkedIn’s data protection and deletion provisions apply.

The operator of the platform for users in the European Economic Area is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. If LinkedIn provides us with statistical evaluations of the use of our company profile and joint controllership exists for this purpose, the agreements and privacy information provided by LinkedIn apply in addition.

  1. Transfers to third countries

We prefer the processing of personal data within the European Union and the European Economic Area. If personal data is transferred to recipients outside the European Economic Area or processed there in individual cases, this will only take place under the conditions of Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Information about the safeguards used in the specific case can be requested at info@vimmera.de.

  1. Your rights

Subject to the legal requirements, you have in particular the following rights:

  • Information about your personal data pursuant to Art. 15 GDPR,
  • Rectification of inaccurate data pursuant to Art. 16 GDPR,
  • Erasure pursuant to Art. 17 GDPR,
  • Restriction of processing pursuant to Art. 18 GDPR,
  • Data portability pursuant to Art. 20 GDPR,
  • Objection to processing pursuant to Art. 21 GDPR,
  • Withdrawal of consent given pursuant to Art. 7(3) GDPR, and
  • Complaint to a data protection supervisory authority pursuant to Art. 77 GDPR.

Consent can be withdrawn at any time with effect for the future. The lawfulness of processing carried out up to the withdrawal remains unaffected.

To exercise your rights, you can contact us at info@vimmera.de or via the postal address stated in section 1. Where necessary, we may request appropriate proof of your identity.

  1. Right to object

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right, on grounds relating to your particular situation, to object to the processing at any time. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing or the processing serves the establishment, exercise, or defense of legal claims.

If personal data is processed for direct marketing, you may object to such processing at any time without giving reasons. The data will then no longer be used for direct marketing.

  1. Obligation to provide data

The provision of personal data may be required by law or contract or necessary for the conclusion or performance of a contract. Without the required information, we may not be able to process an inquiry, conclude a contract, or provide an agreed service. Voluntary information does not have to be provided.

As of: 3 August 2026

If you would like to contact us: