Privacy Policy
- Cookies that are not strictly necessary, for example for web analytics and remarketing, are only set with your express prior consent. You can revoke your consent at any time with future effect via the cookie settings.
- We do not store complete credit card or bank account data on our servers. These are processed exclusively by the respective payment service provider.
- Your data will not be disclosed to third parties for advertising purposes without your express consent.
This privacy policy of A1-ESD Equipment GmbH, Solingen, Germany, is issued pursuant to Art. 13, 14 GDPR and § 25 TDDDG (GDPR, TDDDG, EU-US DPF).
01Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection legislation is:
- Data Controller: A1-ESD Equipment GmbH, Keldersstrasse 15, 42697 Solingen, Germany
- Phone: +49 212 38340680
- Email: datenschutz@fluidics-equipment.com
- Website: fluidics-equipment.com
- Managing Director: Viktor Rudenko
- Commercial Register: Amtsgericht Wuppertal, HRB 29665
- VAT ID: DE269659389
The appointment of a Data Protection Officer is not legally required for our company (§ 38 BDSG). For all data protection inquiries, please contact us directly at the address above.
02Overview of Processing
We process personal data only to the extent necessary for providing a functional website, our content and services. Personal data is processed regularly only with the consent of the user or in cases where processing is permitted by law.
Data Subjects
Visitors and users of our website, customers, prospects, business partners and newsletter subscribers.
Types of Data Processed
- Master data (name, company, address)
- Contact data (email, phone)
- Contract data (orders, payments, delivery addresses)
- Usage data (pages visited, access times, interactions)
- Meta/communication data (IP addresses, device information, browser type)
- Payment data (account details, credit card data, only at the payment service provider)
Purposes of Processing
- Provision of the website and ensuring its functionality
- Processing and fulfilment of orders (contract performance)
- Customer service and responding to enquiries
- Analysis and optimisation of our online offerings
- Sending newsletters (with consent only)
- Advertising and remarketing (with consent only)
- Compliance with statutory retention obligations
- Security and fraud prevention
03Applicable Legal Bases
We process personal data exclusively on the basis of a statutory legal ground:
- Consent (Art. 6(1)(a) GDPR): The data subject has given consent to the processing for one or more specific purposes (e.g. newsletter, marketing cookies, web analytics).
- Contract Performance (Art. 6(1)(b) GDPR): Processing is necessary for the performance of a contract, e.g. order processing, customer account, shipping.
- Legal Obligation (Art. 6(1)(c) GDPR): Processing is necessary for compliance with a legal obligation (e.g. tax retention obligations pursuant to § 147 AO, § 257 HGB).
- Legitimate Interest (Art. 6(1)(f) GDPR): Processing is necessary for the purposes of our legitimate interests, e.g. technical operation, IT security, fraud prevention, provided your interests do not override.
- Cookie Consent (§ 25(1) TDDDG): The storage of non-essential information on your terminal device (cookies, tracking pixels) occurs exclusively on the basis of your express consent.
- Technically Necessary (§ 25(2) TDDDG): Strictly necessary cookies (e.g. shopping cart, session ID) may be set without your consent.
04Hosting & Content Delivery Network (CDN)
Web Hosting
Our website is hosted by a professional hosting provider in Germany. When you access our website, technical access data is automatically collected and stored in server log files (see Section 6).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable and secure provision of the website). A Data Processing Agreement (DPA) pursuant to Art. 28 GDPR has been concluded with the hosting provider.
Cloudflare (CDN & Security)
We use the Content Delivery Network and security services of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare routes traffic through a globally distributed server network to optimise loading times and protect our website against attacks (DDoS protection). In this process, access data (including your IP address) is routed through Cloudflare servers.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and performance). A DPA has been concluded with Cloudflare. For data transfers to the USA, see Section 16.
Further information: Cloudflare Privacy Policy.
05SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, our website uses SSL or TLS encryption. You can recognise an encrypted connection by the browser address bar changing from “http://” to “https://” and by the padlock icon in your browser bar.
When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
06Server Log Files
Our hosting provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and version
- Operating system used
- Referrer URL (the previously visited page)
- Host name of the accessing computer
- IP address (anonymised where applicable)
- Date and time of the server request
This data cannot be attributed to specific individuals. This data is not merged with other data sources. We reserve the right to review this data retrospectively if concrete indications of unlawful use come to our attention.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring error-free operation and IT security).
Retention period: Log files are automatically deleted after no more than 14 days.
08Online Shop & Order Processing
We process our customers' data to enable them to select, purchase or order the chosen products and related services, and to ensure payment and delivery.
Data Processed
- Master data (name, company, address, VAT ID where applicable)
- Contact data (email, phone)
- Contract data (order contents, order time, price)
- Payment data (selected payment method, payment data itself only at the payment service provider)
- Shipping address and delivery data
Legal basis: Art. 6(1)(b) GDPR (contract performance and pre-contractual measures), Art. 6(1)(c) GDPR (tax and commercial law retention obligations).
Disclosure to Third Parties
For contract fulfilment, we share your data with the following recipients to the extent necessary:
- Shipping service providers (e.g. DHL, UPS, DPD): name, address, email/phone where applicable for delivery notifications
- Payment service providers: see Section 9
- ERP system (orgaMAX/Deltra): for accounting purposes
- Tax advisor: for fulfilment of tax obligations
Your data will not be disclosed to third parties for advertising purposes without your express consent.
09Payment Service Providers
For payment processing, we use external payment service providers. The payment data you enter during the order process is collected and processed directly by the respective payment service provider.
Stripe
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (parent company: Stripe, Inc., USA).
When you select a payment method processed by Stripe (e.g. credit card), your payment data is transmitted directly to Stripe and processed there. Stripe uses its own cookies for payment processing and fraud detection (see Section 7). Stripe is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6(1)(b) GDPR (contract performance), § 25(2) TDDDG (technically necessary cookies for payment processing). A DPA pursuant to Art. 28 GDPR has been concluded.
Privacy Policy: stripe.com/privacy.
PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
When you select PayPal as your payment method, your payment data is transmitted to PayPal.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Privacy Policy: paypal.com/privacy.
Bank Transfer (Prepayment)
When paying by bank transfer, we process your transfer data (IBAN, BIC, account holder) exclusively for the purpose of matching incoming payments.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Invoice
When paying by invoice, we process your order data and, where applicable, creditworthiness information (see also § 13 of our General Terms and Conditions). Invoicing is carried out via our ERP system.
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(f) GDPR (legitimate interest in credit assessment for purchases on account).
We do not store complete credit card or bank account data on our servers. These are processed exclusively by the respective payment service provider.
10Contact Requests
When you contact us by contact form, email, phone or by any other means, we process the data you provide (name, email address, message content and any other voluntarily provided information) to handle your enquiry.
Legal basis: Art. 6(1)(b) GDPR (where the enquiry relates to a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to your enquiry).
Retention period: Data collected in the course of a contact request is deleted as soon as it is no longer required for the purpose for which it was collected and no statutory retention obligations apply.
11Customer Account
You have the option of creating a customer account on our website. The data entered during registration (name, email, company, address, password in hashed form) is stored.
Legal basis: Art. 6(1)(b) GDPR (contract performance and pre-contractual measures), Art. 6(1)(a) GDPR (consent through registration).
You can request deletion of your customer account at any time by contacting us. Processing of data stored up to the point of deletion remains unaffected. Statutory retention obligations (e.g. for order data) continue to apply.
13Web Analytics
Google Analytics 4
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics uses cookies and comparable recognition technologies to analyse the usage behaviour of our website.
Google Analytics is activated only with your prior consent. Without consent, no tracking takes place.
The information generated by cookies about your use of this website is generally transferred to a Google server in the USA and stored there. We use IP anonymisation, so that your IP address is truncated by Google within Member States of the EU or other contracting states of the Agreement on the European Economic Area beforehand.
- Provider: Google Ireland Limited (parent company: Google LLC, USA)
- Legal basis (cookie): § 25(1) TDDDG (consent)
- Legal basis (data): Art. 6(1)(a) GDPR (consent)
- Third-country transfer: USA, based on the EU-U.S. Data Privacy Framework + SCC (see Section 16)
- DPA: Concluded pursuant to Art. 28 GDPR
- Revocation: At any time via cookie settings or browser add-on
Further information: Google Privacy Policy | Google Analytics Opt-Out Browser Add-on.
14Online Marketing & Remarketing
Google Ads & Conversion Tracking
We use Google Ads, an online advertising programme by Google. As part of Google Ads, we use conversion tracking. After clicking on an advertisement placed by Google, a conversion tracking cookie is set. This cookie expires after 90 days and is not used for personal identification.
If the user visits certain pages of our website and the cookie has not yet expired, Google and we can recognise that the user clicked on the advertisement and was redirected to that page.
Google Remarketing
We use the Google remarketing function to display interest-based advertising on third-party websites. Google analyses your usage behaviour on our website in order to subsequently target you with relevant advertising on other websites. According to Google, pseudonymisation is used in the context of remarketing.
Legal basis: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR (consent). Google Ads and remarketing are only activated after your express consent in the cookie consent banner.
You can deactivate interest-based advertising via the Google Ads Settings.
15Embedded Third-Party Services
Google Fonts (Local)
Our website uses so-called Web Fonts from Google for the uniform display of typefaces. The Google Fonts are installed locally on our server. No connection to Google servers is established as a result.
Google Maps
We may embed maps from Google Maps. Provider: Google Ireland Limited. When you access a page containing Google Maps, a connection to Google servers is established. Google Maps is only loaded after your prior consent (two-click solution).
Legal basis: Art. 6(1)(a) GDPR (consent).
YouTube (Enhanced Privacy Mode)
We may embed videos from YouTube. Provider: Google Ireland Limited. We use YouTube in enhanced privacy mode. According to YouTube, no information about website visitors is stored in this mode before the video is viewed. Embedding is done via a two-click solution (prior consent).
Legal basis: Art. 6(1)(a) GDPR (consent).
Google reCAPTCHA
We may use “Google reCAPTCHA” to protect against abusive automated access. Provider: Google Ireland Limited. reCAPTCHA analyses the behaviour of website visitors based on various characteristics (e.g. IP address, time spent on site, mouse movements).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and protection against spam/abuse).
16Data Transfers to Third Countries
Insofar as we use services from providers based outside the EU/EEA (particularly the USA), personal data may be transferred to third countries.
EU-U.S. Data Privacy Framework (DPF)
For data transfers to the USA, we primarily rely on the adequacy decision of the European Commission pursuant to Art. 45 GDPR regarding the EU-U.S. Data Privacy Framework. The US providers we use are certified under the DPF:
- Google LLC: DPF certified
- Cloudflare, Inc.: DPF certified
- Stripe, Inc.: DPF certified
The political and legal stability of the EU-U.S. Data Privacy Framework is not conclusively assured. Should the DPF become invalid, we additionally rely on EU Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR as a safeguard measure. We also conduct Transfer Impact Assessments (TIA).
Additional Safeguards
- Conclusion of Standard Contractual Clauses (SCC) with all US providers as additional protection
- Conducting Transfer Impact Assessments (TIA)
- IP anonymisation for Google Analytics
- Data minimisation: only data strictly necessary for the service is shared
- Encryption of all data transfers (TLS)
17Retention & Deletion
We store personal data only for as long as is necessary for the respective processing purpose or as required by statutory retention periods.
- Server log files: 14 days. Basis: legitimate interest (IT security).
- Order data / invoices: 10 years. Basis: § 147 AO, § 257 HGB.
- Commercial correspondence (incl. quotes): 6 years. Basis: § 257 HGB.
- Contact form enquiries: until resolved + 6 months. Basis: legitimate interest.
- Newsletter consent (proof): 3 years after unsubscription. Basis: burden of proof obligation.
- Customer account data: until deletion by the customer. Basis: contract performance.
- Cookie consent proof: 3 years. Basis: documentation obligation TDDDG/GDPR.
After expiry of the respective retention period, data is routinely deleted or anonymised, unless it is still required for contract performance or initiation.
18Your Rights as a Data Subject
As a data subject, you have the following rights under the GDPR. To exercise your rights, you may contact us at any time (contact details in Section 1).
- Right of Access (Art. 15 GDPR): You may request information about your personal data processed by us.
- Rectification (Art. 16 GDPR): You may request the correction of inaccurate data or the completion of incomplete data.
- Erasure (Art. 17 GDPR): You may request the deletion of your stored data, unless statutory retention obligations apply.
- Restriction (Art. 18 GDPR): You may request restriction of the processing of your data where certain conditions are met.
- Data Portability (Art. 20 GDPR): You may receive your data in a structured, machine-readable format or have it transmitted to a third party.
- Objection (Art. 21 GDPR): You may object to the processing of your data based on legitimate interests at any time.
- Withdrawal of Consent (Art. 7(3) GDPR): You may withdraw any consent given at any time with effect for the future.
- Automated Decisions (Art. 22 GDPR): No solely automated decision-making (profiling) takes place that produces legal effects concerning you.
Where your personal data is processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to the processing pursuant to Art. 21 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms.
19Right to Lodge a Complaint
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR (Art. 77 GDPR).
Competent Supervisory Authority
- State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
- Address: Postfach 20 04 44, 40102 Düsseldorf, Germany
- Phone: +49 211 38424-0
- Email: poststelle@ldi.nrw.de
- Website: www.ldi.nrw.de
20Changes to This Privacy Policy
We reserve the right to amend this privacy policy to ensure it always complies with current legal requirements or to implement changes to our services or data processing. The updated privacy policy will apply to your subsequent visits.
Material changes will be communicated separately where required.
Last updated: April 2026
For all data protection inquiries, please contact us directly, also by phone at +49 212 38340680.
A1-ESD Equipment GmbH, Keldersstrasse 15, 42697 Solingen, Germany. Amtsgericht Wuppertal, HRB 29665. Managing Director: Viktor Rudenko. VAT ID: DE269659389.