Privacy Policy

Information on how personal data is processed on this website under the GDPR, the German BDSG and the TDDDG.

Last updated: 17 August 2026

GDPR and TDDDG

This notice meets the information duties in Articles 13 and 14 GDPR. The German Telecommunications Digital Services Data Protection Act (TDDDG), which replaced the TTDSG on 14 May 2024, also applies.

1. Overview

We take the protection of your personal data seriously. Personal data means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR), such as a name, email address or IP address.

Processing is allowed only if a legal basis permits it or you have consented. The legal bases are set out in Art. 6 GDPR. Where information is stored on or accessed from your device (cookies and similar technologies), we also apply § 25 TDDDG.

Two-step test under the TDDDG and GDPR: first, whether device access requires consent under § 25 TDDDG; second, which GDPR legal basis covers any personal data obtained that way.

2. Controller

The controller for processing on this website is:

Vionis Labs

Berke Sevenler

 
 
Germany

 

 

No data protection officer has been appointed. Under § 38 BDSG an officer is required only if at least 20 people are regularly involved in the automated processing of personal data.

3. Website hosting

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (“Vercel”). Vercel stores the site content and processes technical data generated when pages are requested. Vercel acts as a processor under Art. 4(8) and Art. 28 GDPR. A data-processing agreement is in place, including the EU Commission’s Standard Contractual Clauses for transfers to the United States.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure, available website) and, where Vercel stores or reads information on your device that is strictly necessary for transmission, § 25(2) TDDDG.

4. SSL/TLS encryption

This website uses TLS encryption (visible as “https://”) to protect personal data in transit. Forms and the chatbot are submitted only over this encrypted connection. This follows the BSI recommendation to use at least TLS 1.2.

5. Server log files

When you visit this website, the host automatically records data in server log files. This typically includes:

  • IP address of the requesting device
  • date and time of the request
  • URL / file requested
  • HTTP status code and volume of data transferred
  • referrer URL (previous page, if sent)
  • browser type and version and operating system

Processing is for delivery of the site, security and abuse detection, and error analysis. We do not use these logs for marketing or profiling. The legal basis is Art. 6(1)(f) GDPR. Retention follows the host’s technical setup and is usually a few days unless a longer period is needed to investigate an attack. IP addresses should as a rule not be kept longer than 7 days.

6. Cookies and similar technologies

Cookies are small text files stored on your device. Similar technologies include local storage and fingerprinting. A consent banner is required only if information is stored or read that does not fall under the exceptions in § 25(2) TDDDG.

Strictly necessary storage (no consent)

Without consent we only store information that is strictly necessary to provide a service you expressly requested or to transmit a message over the network (§ 25(2) TDDDG), and we rely on Art. 6(1)(f) GDPR for the further processing:

  • your cookie choice (local storage), so we do not ask again on every visit
  • the website language setting
  • chatbot UI state (for example that you closed the window) after you have used it

Non-essential technologies (consent required)

Audience measurement and analytics are, according to the German DSK guidance on digital services (November 2024), generally not strictly necessary and therefore require consent under § 25(1) TDDDG. We do not load analytics unless you opt in via the banner. You may withdraw consent at any time via the cookie settings.

We currently do not use marketing cookies, social plugins, tracking pixels or Google Analytics.

7. Audience measurement (Vercel Analytics)

If you consent to the “analytics” category in the cookie banner, we use Vercel Web Analytics (Vercel Inc., USA) to understand which pages are viewed. Vercel states that this product does not set cookies. Device access may still occur; under the TDDDG and DSK guidance we therefore obtain prior consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR).

Without consent, Vercel Analytics is not loaded. You can withdraw consent in the cookie settings. Where personal data is transferred to the USA, this is based on Standard Contractual Clauses and, where applicable, your consent under Art. 49(1)(a) GDPR.

8. Contact form

If you write to us via the contact form (“Get Started”), we process the data you enter (name, email address, message) to handle your enquiry. We apply data minimisation: only fields needed to reply are requested. Transmission uses HTTPS.

Messages are sent using the email service Resend (Resend, Inc., USA) as a processor. The legal basis is Art. 6(1)(b) GDPR (pre-contractual request or performance of a contract) and, where needed, Art. 6(1)(f) GDPR. The contact form is a service you expressly request; technically necessary device access for that purpose is exempt under § 25(2) TDDDG.

We delete enquiries once they have been dealt with, unless statutory retention applies. If a contract follows, commercial and tax retention periods apply (usually 6 or 10 years).

9. Applications

You may submit information about an open role via the careers form. Data is processed to run the application procedure (Art. 6(1)(b) GDPR, § 26 BDSG). The form uses FormSubmit (formsubmit.co). Please also send CVs by email as described on the careers page.

Application data is deleted after the process ends if no hire is made, unless law or a legitimate interest (for example defending claims, typically up to 6 months) requires longer storage. If you are hired, the data is moved into the personnel file.

10. AI chatbot on this website

You can use a text chatbot on this website. Your inputs and the session history are sent to our server and from there to OpenAI (OpenAI, LLC / OpenAI Ireland Ltd.) to generate a reply. We do not keep chat histories in a permanent customer account; the provider may still process data as part of its operations and security.

The legal basis is Art. 6(1)(b) GDPR where the chat is used to initiate a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in providing fast information about our services). Please do not enter special-category data (Art. 9 GDPR) or unnecessary identity data in the chat.

OpenAI also processes data in the United States. Transfers rely on Standard Contractual Clauses and other appropriate safeguards under Art. 46 GDPR. OpenAI is an independent controller for parts of its own processing; we are controller for collection on our website and transmission to the provider.

11. Fonts

We do not load fonts from Google servers at runtime. The Inter typeface is downloaded when the site is built and then served locally from our hosting. Visiting the site therefore does not create a connection to Google for the purpose of loading fonts. This follows the recommendation to host web fonts locally instead of fetching them from a third-party server on each page load (§ 25(1) TDDDG; Regional Court Munich I, judgment of 20 January 2022, 3 O 17493/20).

12. No social plugins, no embedded videos

We do not embed social plugins (such as Like or Share buttons). Loading this website does not automatically send your IP address to Facebook, X or similar services. Links (for example to our LinkedIn page) are ordinary HTML links; data is sent to the third party only if you click the link.

No YouTube or Vimeo videos are embedded in a way that transfers data to the video provider merely by loading the page.

14. Recipients and processors

Personal data is shared only with parties that need it for the purposes above, in particular:

  • Vercel Inc., USA – hosting and, with consent, audience measurement
  • Resend, Inc., USA – sending contact-form messages
  • FormSubmit – transmitting application forms
  • OpenAI, USA / Ireland – processing chatbot inputs
  • IT, tax and legal service providers where necessary and bound to confidentiality

Where these parties act as processors, Art. 28 GDPR contracts are in place. We do not sell addresses to data brokers.

15. Transfers outside the EEA

Some of the providers above are established in the United States. The US is a third country without a general adequacy decision covering all processors. Where a provider is certified under the EU–US Data Privacy Framework, we rely on the Commission’s adequacy decision. Otherwise we use the Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) plus technical and organisational measures (TLS, access control, data minimisation).

For transfers based on consent (analytics), Art. 49(1)(a) GDPR may also apply. You may ask us which safeguards are used in a given case.

16. Retention

We keep personal data only as long as needed for the purpose or required by law:

  • Server logs: usually a few days, longer only if needed for security (guidance: up to 7 days for IP addresses)
  • Cookie consent: until you change or delete it, at most 12 months, after which we ask again
  • Contact enquiries: until handled, then deletion or limited retention where statutory periods apply
  • Contract and invoice data: 6 years (§ 257 HGB) or 10 years (§ 147 AO)
  • Unsuccessful applications: usually up to 6 months after rejection
  • Chatbot session: only for the browser session on our side; no permanent chat archive of our own

17. Security

We apply technical and organisational measures under Art. 32 GDPR and § 19 TDDDG, including TLS in transit, restricted hosting access, the ability to stop using the chat and forms at any time, and – where reasonable – use of the site without a mandatory account. The internet cannot offer absolute security.

18. Personal data breaches

A personal data breach that is likely to result in a risk to your rights and freedoms will be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33 GDPR). If the risk is high, we will also inform you under Art. 34 GDPR.

19. Automated decisions

We do not use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). The website chatbot answers information questions; it does not decide on contracts, creditworthiness or similar legal consequences.

20. Your rights

You have the following rights vis-à-vis us:

  • access (Art. 15 GDPR) to the personal data we hold about you
  • rectification (Art. 16 GDPR) of inaccurate data
  • erasure (Art. 17 GDPR) unless a statutory exception applies
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR) in a commonly used, machine-readable format
  • objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR); objection to direct marketing needs no reasons
  • withdrawal of consent (Art. 7(3) GDPR) with effect for the future, for example via the cookie settings

You can exercise these rights by contacting us using the details above. We may ask for suitable identification.

21. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or alleged infringement. For us as a business established in Bavaria the competent authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de/

22. Obligation to provide data

You are not legally or contractually required to provide personal data merely to visit the website. Technical server-log data arises automatically when pages are requested. You can use the contact form, careers form and chatbot only if you provide the information those tools need. Without it we cannot handle your request.

23. Changes to this notice

We will update this privacy notice if processing, the services we use or the law changes. The current version is always published on this page with the date above.

Privacy contact

To request access, rectification, erasure or to exercise other data-subject rights, contact the controller. A data protection officer is not appointed.

Email:  

Address:

 
 
Germany