Privacy Policy

Information on personal data processing, data protection measures, and user rights at GSWE.

1. Controller and contact

The controller for personal data processing on gswe.de and the associated website functions on api.gswe.de is GSWE GmbH, Lange Straße 60, 17489 Greifswald, Germany, represented by managing directors Dan Grünzig and Dennis Schäfers.

Telephone: +49 3834 7750730. Email: info@gswe.de. For data protection questions and to exercise your rights, contact datenschutz@gswe.de or write to our postal address, marked “Data protection”.

2. Website access and managed hosting

We operate the website and its interfaces on a managed server provided by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Hetzner processes hosting data on our behalf. Your IP address is technically required when establishing a connection to deliver the requested content to your device.

Page and API requests generate technical access data: requested address, date and time, HTTP method and status code, volume of data transferred, browser and operating system details and the referring page, to the extent your browser transmits this information. Errors may also be recorded in technical error logs. This processing serves website delivery, stability and security, troubleshooting and abuse prevention. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are the secure and reliable operation of our website.

According to its documentation, Hetzner anonymises IP addresses in web server logs: the last octet of IPv4 addresses is replaced, and the last 88 bits of IPv6 addresses are anonymised. The IP address is nevertheless processed when establishing the connection.

Hetzner specifies a default retention of seven days for Apache access and error logs; this period is configurable in konsoleH. Hetzner specifies seven days for mail server logs and 14 days for encrypted backups. Application data such as inquiries and applications have their own retention rules; these log retention periods do not constitute database deletion periods. See the Hetzner data protection documentation for hosting information.

3. Language, browser storage and usage statistics

The language of our pages follows the German or English URL you open. The current website does not set a new language cookie; you can delete older “i18n_redirected” cookies in your browser.

For technical error recovery, the website may store the affected page path and the time of a reload attempt in your browser's session storage under “gswe:stale-route-reload”. This prevents repeated automatic reloads after a version change. The entry lasts until the end of the tab session; the repeat prevention uses a one-minute interval. This serves delivery of the requested page. The legal bases are Section 25(2), point 2, of the German Telecommunications Digital Services Data Protection Act (TDDDG) and, where personal data is concerned, Article 6(1)(f) GDPR.

Additional browser-based usage analytics are disabled. No new events recording page views, scroll depth, time spent or form interactions are collected through this mechanism. Future activation of analytics requiring consent will take place only after prior voluntary consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.

Internal statistics from before deactivation may contain page paths, timestamps, event types, content and filter references, language, country indicators, broad device and screen classes, referring domains, time spent, scroll levels and error indicators. The event table contains no visitor identifier, IP address or form entries. Server logs generated by HTTP requests are separate. Personal data in older records without a basis for continued retention must be deleted. Section 8 explains objections to processing based on legitimate interests.

4. Inquiries, callbacks and business contact

When you contact us by form, email or telephone, we process, depending on the channel, your salutation, first and last name, company, email address, telephone number, message, language, selected inquiry topic and acknowledgement of our privacy notice. Emails also include sender, recipient, time and attachments.

We use this data to answer your inquiry, make a requested callback, prepare a proposal and initiate or perform a business relationship. For an inquiry concerning a contract with you, the legal basis is Article 6(1)(b) GDPR. For general inquiries or when you act for a company, processing is based on Article 6(1)(f) GDPR; our legitimate interest is handling communications and business requests. Statutory documentation and retention obligations are based on Article 6(1)(c) GDPR.

The form cannot be submitted without the information marked as required. You may contact us by email instead. Please limit optional information to what is necessary. Acknowledging the privacy notice is not consent to advertising.

If you open a campaign link, the URL parameter “gswe_ad” may identify the associated advertisement. When you subsequently submit an inquiry, this advertising reference is stored with it. This helps us understand the request and evaluate the source of incoming inquiries. Link attribution is neither proof of a paid click nor an individual Google visitor identifier. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in handling business inquiries transparently and evaluating their sources. This mechanism alone does not transmit your form data to Google.

The responsible sales, management and administration personnel receive access. Data is retained until the inquiry and any resulting business relationship have been dealt with. Further retention depends on statutory duties applicable to the particular document and the need to safeguard legal claims. Data that is no longer required must be deleted.

5. Job applications

When you apply, we process your name and contact details, salutation, telephone number, email address, selected position, message and any CV uploaded as a PDF. Processing status and acknowledgement of the privacy notice are also recorded. The sources are your application and subsequent communication.

The purposes are assessing suitability, communicating with you and deciding whether to establish an employment relationship. The legal basis is Section 26(1) of the German Federal Data Protection Act (BDSG). Where special categories of personal data are necessary for employment law obligations, Section 26(3) BDSG and Article 9(2)(b) GDPR apply. Submit particularly sensitive information, such as health or religious information, only where necessary.

Access is granted to the responsible recruitment personnel, decision-makers and necessary technical administrators. Application PDFs are processed as protected files.

Application data is stored until the procedure has concluded and for no more than six months afterwards, unless longer retention is legally required or necessary to safeguard specific legal claims. Retention for legal defence is based on Article 6(1)(f) GDPR and, for special categories where applicable, Article 9(2)(f) GDPR. If you are hired, only data necessary for the employment relationship continues to be processed. Inclusion in a longer-term applicant pool requires a separate basis, in particular voluntary consent.

6. External links, social networks and ChatGPT

Fonts and website files required for display are delivered through our website or our own API. Links to LinkedIn, Instagram, Facebook, X and ChatGPT point to external services. Simply visiting our website does not load embedded social media feeds or chat windows from these providers.

When you actively open such a link, you leave our website. The ChatGPT link may first open a short-link page on api.gswe.de which redirects to the external service. The relevant provider processes connection data and, where applicable, your account, communication and input data under its own privacy policy. Processing outside the European Economic Area may take place. Please consult the relevant provider before using the service, for example OpenAI's privacy policy.

Data that you actually send to us through external services is processed as described in Section 4 or 5. These services are optional; the form, email and telephone are available as alternatives.

7. Recipients, security and retention

In addition to the responsible staff, commissioned hosting, maintenance and communication service providers may receive data where necessary for their tasks. Processing on behalf of a controller is subject to Article 28 GDPR. Authorities, courts or professional advisers receive data only where there is a legal obligation or another legal basis.

The website and forms use HTTPS; access rights are limited according to tasks. Backups serve recovery from technical incidents and have their own overwrite cycle. Retention duties and necessary preservation of evidence may limit immediate deletion.

8. Your rights

Subject to the statutory conditions, you have rights of access to your personal data, rectification of inaccurate data, erasure, restriction of processing and data portability (Articles 15 to 20 GDPR). You may withdraw consent at any time with future effect. Processing before withdrawal remains unaffected.

Objection: If your data is processed under Article 6(1)(e) or (f) GDPR, you may object under Article 21 GDPR on grounds relating to your particular situation. We will then stop processing unless we demonstrate compelling legitimate grounds or need the data for the establishment, exercise or defence of legal claims. You may object to processing for direct marketing at any time without giving reasons; your data will then no longer be processed for that purpose.

Contact datenschutz@gswe.de to exercise these rights. We generally handle requests within one month and inform you of any legally permitted extension.

You may also complain to a data protection supervisory authority under Article 77 GDPR, particularly in your place of residence, workplace or the place of the alleged infringement. The authority responsible for our registered office is the State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania: Lennéstraße 1, 19053 Schwerin, Germany, email info@datenschutz-mv.de, authority contact page.

The website forms described here do not involve decisions based solely on automated processing with legal or similarly significant effects within the meaning of Article 22 GDPR.

Last updated: 9 September 2026.