Data Policy

Data Policy

Last updated: June 2026

1. Data controller; Data Protection Officer

Controller within the meaning of data protection laws, in particular the EU General Data Protection Regulation (GDPR), is:

Neumüller Elektronik GmbH
Gewerbegebiet Ost 7
D-91085 Weisendorf
Tel.: +49 9135 73666-0
Fax: +49 9135 73666-60
info@neumueller.com

The Data Protection Officer is

Rechtsanwältin Nicola Scholz-Recht
Tel.: +49 911 580560-0
ds@neumueller.com

2. Collection and Storage of Personal Data; Purposes of data processing

When you access our website, general information is automatically collected. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your Internet service provider, the date and time of access, and your IP address (usually truncated).

The data is processed for the following purposes:

  • to ensure that the website connects smoothly
  • to ensure a convenient user experience on the website
  • for technical security reasons, in particular to defend against attempted attacks on our web servers
  • to evaluate system security and stability
  • for administrative purposes.

The legal basis for data processing is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the stated purposes of the processing. At no time is data processed for the purpose of drawing conclusions about your identity.

3. Your rights as a data subject

You may exercise the following rights at any time:

  • Information about your stored personal data and its processing (Art. 15 GDPR),
  • Correction of inaccurate personal data (Art. 16 GDPR),
  • Erasure of your data stored with us (Art. 17 GDPR),
  • Restriction of processing where erasure is not yet permitted (Art. 18 GDPR),
  • Objection to the processing of your data (Art. 21 GDPR),
  • Transfer of the data you have provided to us in a structured, commonly used, and machine-readable format, or transmission of such data to another controller (Art. 20 GDPR),
  • Withdrawal of consent you have given us (Art. 7(3) GDPR), meaning that we may no longer continue processing the data based on that consent in the future,
  • Complaint to a supervisory authority (Art. 77 GDPR). You may contact the supervisory authority in your place of residence or work, or the supervisory authority responsible for our company. A list of supervisory authorities is available at bfdi.bund.de

4. Disclosure of Data

Information will only be disclosed to third parties if:

  • You have given your explicit consent (Art. 6(1)(a) GDPR),
  • processing is necessary for the performance of a contract with you (Art. 6(1)(b) GDPR),
  • processing is necessary for compliance with a legal obligation (Art. 6(1)(c) GDPR),
  • processing is necessary to protect legitimate interests and there are no overriding legitimate interests on your part that would prevent it (Art. 6(1)(f) GDPR).

5. Erasure and blocking of data

We follow the principles of data minimisation and storage limitation. We therefore store your personal data only for as long as is necessary for the purposes set out above or as required by statutory retention periods. After the respective purpose has ceased or these periods have expired, the corresponding data is routinely blocked or erased.

6. Hosting

We host this website on virtual servers provided by our IT service provider, bITma solutions GmbH, Pommernstraße 8, 91052 Erlangen, Germany (“bITma”). When you visit our website, bITma processes metadata and communication data (e.g., IP address, time of the request, files accessed, amount of data transferred) on our behalf to ensure the delivery of the website, its stability and security, and to defend against attacks.

The servers are operated at the data center of TERRA CLOUD GmbH, Hankamp 2, 32609 Hüllhorst, Germany, which acts as a subcontractor for this purpose. No processing takes place outside of Germany.

We have entered into a data processing agreement with bITma in accordance with Article 28 of the GDPR, which also governs the use of subprocessors. The legal basis is Article 6(1)(f) of the GDPR (legitimate interest in the reliable and secure provision of our website).

Our website uses cookies and comparable technologies (e.g. localStorage). Cookies are small text files stored by your browser. They allow us to provide essential functions, to recognise your privacy choices, and – with your consent – to measure how the site is used and to display relevant advertising.

We distinguish four categories: »Necessary« (always active), »Functional« (e.g. embedded YouTube videos), »Statistics« (Google Analytics 4) and »Marketing« (Google Ads, LinkedIn, WiredMinds LeadLab). Cookies and technologies in the last three categories are only loaded once you have explicitly given your consent in our consent banner.

Legal basis for setting non-essential cookies and accessing information on your device is § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR (consent). For necessary cookies the legal basis is § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR (legitimate interest in operating a secure website).

You can review or change your selection at any time via the privacy fingerprint at the bottom left of every page, or via the button below. Your choice is stored in the first-party cookie nme_consent (6 months).

You can also disable cookies entirely via your browser settings. Please note that some features of our website may then no longer work properly.

The following overview lists all cookies and similar technologies that may be used on this website. Whether a service is actually loaded depends entirely on your consent (see the privacy fingerprint at the bottom left of every page). You can change your selection at any time.

9. Google Tag Manager (incl. server-side)

We use Google Tag Manager (provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to manage tracking and marketing tags. The Tag Manager itself does not set any tracking cookies and only loads the individual tags after you have given your consent in our consent banner.

Additionally, we operate a server-side Google Tag Manager on our own subdomain gtm.neumueller.com. This allows us to process tracking requests in a first-party context, to reduce the data transferred to third parties, and to enable cookieless measurement modes. Legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

10. Google Analytics 4

Subject to your consent, this website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited (»Google«). GA4 uses cookies and event-based data collection to help us understand how visitors use our website, so that we can improve it.. GA4 nutzt Cookies und eine ereignisbasierte Datenerfassung, damit wir verstehen, wie Besucher unsere Website nutzen, und sie verbessern können.")

GA4 anonymises and shortens IP addresses automatically by default before they are used or stored. The data generated is processed via our server-side Tag Manager (gtm.neumueller.com) and then forwarded to Google. We have concluded a Data Processing Agreement with Google in accordance with Art. 28 GDPR.

Legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw your consent at any time via the privacy fingerprint at the bottom left. Further information on Google's data processing is available at policies.google.com/privacy.

11. Google Ads (conversion tracking, remarketing, Enhanced Conversions)

Subject to your consent, we use Google Ads (Google Ireland Limited) to display ads on Google Search, on partner websites within the Google Display Network and on YouTube, to measure the success of those campaigns and to address visitors with ads tailored to their interests (remarketing).

When you click on one of our Google ads, Google sets a cookie on your device. This allows us and Google to recognise that you came via an ad and which actions you take afterwards on our website (e.g. submitting a contact form). The cookies do not contain personally identifying information.

We additionally use »Enhanced Conversions for Leads«: when you submit our contact or application form, hashed values (SHA-256) of your email address, phone number and name are transmitted to Google so that conversions can be attributed more reliably. The hashing happens in your browser before transmission – Google does not receive your plaintext data from this site.

Legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can object to interest-based advertising via adssettings.google.com or revoke your consent here at any time via the privacy fingerprint.

12. Google Maps

Where we use Google Maps to visualise location information, Google Ireland Limited collects, processes and uses data about the use of map functions. Loading Google Maps is only triggered after you actively interact with the map element, in order to minimise data transfer. For details please see policies.google.com/privacy.

13. Embedded YouTube videos (two-click solution)

Some of our pages contain embedded videos from YouTube, a service provided by Google Ireland Limited. We use a two-click solution: no data is transferred to YouTube/Google until you actively start a video.

When you click on the play button, the video is loaded from the privacy-enhanced YouTube domain youtube-nocookie.com . At this point your browser establishes a connection to YouTube's servers. Among other things, your IP address, browser identifiers, and information about which page on our site is currently being viewed are transmitted to Google. If you are logged into a YouTube account, the playback can be attributed to your account.

Loading YouTube videos requires consent in the »Functional« category. Without this consent the player is not loaded; instead our consent banner opens and offers you the opportunity to enable the category. Legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

Further information: policies.google.com/privacy.

14. LinkedIn Insight Tag

Subject to your consent in the »Marketing« category, we use the LinkedIn Insight Tag, a tracking technology provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. The Insight Tag enables conversion tracking, retargeting and audience building for our LinkedIn advertising campaigns and provides us with aggregated, anonymous reports about ad activity and how you interact with our website.

For these purposes LinkedIn sets cookies. The information collected is transmitted to LinkedIn servers (also in the USA) and stored there. LinkedIn does not share any personal data with us; we only receive aggregated reports. We are joint controllers with LinkedIn for the data collected via the Insight Tag (Art. 26 GDPR). The corresponding joint controller agreement is available at legal.linkedin.com/dpa.

Legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). LinkedIn's privacy policy: linkedin.com/legal/privacy-policy. You can opt out of interest-based ads from LinkedIn at linkedin.com/psettings/guest-controls/retargeting-opt-out .

15. WiredMinds LeadLab

Subject to your consent in the »Marketing« category, our website uses the pixel-code technology of WiredMinds GmbH, Lindenspürstraße 32, 70176 Stuttgart, Germany, to analyse visitor behaviour for B2B lead identification purposes. The IP address of a visitor is processed exclusively to identify the company behind the visit (e.g. company name). IP addresses of natural persons are excluded from further use through a whitelist procedure; the IP address itself is not stored in LeadLab under any circumstances.

WiredMinds uses this information to create anonymous usage profiles based on visitor behaviour. The collected data is not used to identify visitors to our website personally. Legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

More information: wiredminds.com/datenschutz. You can revoke your consent at any time via the privacy fingerprint at the bottom left.

16. Data transfer to third countries

Some of the services used here (in particular those by Google and LinkedIn) involve a transfer of personal data to the United States. Where the receiving company is certified under the EU-U.S. Data Privacy Framework (DPF), the transfer is based on an adequacy decision of the EU Commission (Art. 45 GDPR). Where this is not the case, we ensure an appropriate level of protection through EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. You can obtain a copy of these safeguards from us at any time using the contact details in section 19.

17. SSL/TLS encryption

To protect the security of your data during transmission, we use state-of-the-art encryption (SSL/TLS) over HTTPS.

18. Contact form and e-mail

If you contact us via our contact form, application form or by e-mail, the data you provide (e.g. name, e-mail address, telephone number, message content) will be processed to handle your request and for any follow-up questions. Legal basis is Art. 6(1)(b) GDPR (where the request relates to a contract) or Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).

Your data is deleted after final processing of your request, provided no statutory retention obligations apply (e.g. § 257 HGB, § 147 AO).

To protect against automated submissions (spam) we use a simple arithmetic question (e.g. »3 + 4 = ?«). No third-party CAPTCHA service (such as Google reCAPTCHA or Friendly Captcha) is used, so no data is transferred to third parties for this purpose.

When you submit the contact form, we additionally record a coarse marketing origin of your visit (e.g. Google Ads, organic search, social network, satellite site, direct access). This origin is determined on first access to the website – based on UTM parameters, the referrer and any ad click identifier – and held exclusively in the temporary server-side session described above (cookie nme_session).

Together with your enquiry, the origin is forwarded to our internal CRM system, where it is linked to your specific request – without this link we would not be able to attribute an enquiry to a marketing channel. It is a coarse category from eight values (»WEB:1« to »WEB:8«), not an individual tracking ID. No cross-visit profile is created, no advertising identifier is set, and the information is not transferred to external services such as advertising networks or analytics providers. Cross-visit evaluations (»which channel triggered how many enquiries last month?«) are performed only as aggregated reports inside our CRM, exclusively by employees with a legitimate need. Legal basis is Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our own marketing channels).

19. Job applications

If you apply for a position with us – either via our online application form, by e-mail or by post – we process the personal data you provide (e.g. name, contact details, CV, cover letter, certificates) for the purpose of running the application procedure and deciding on entering into an employment relationship.

Depending on the channel, your application data is stored in the following systems:

  • Communication and any uploaded attachments (CV, certificates, etc.) are processed by our HR team via Microsoft Outlook / Microsoft 365.
  • For the further selection process, the application is additionally recorded in our internal CRM system, which is hosted on our own infrastructure.

Legal basis is § 26(1) sentence 1 BDSG in conjunction with Art. 6(1)(b) GDPR (initiation of an employment relationship). If you give us your separate consent to keep your application on file for future positions, the legal basis for the longer storage is Art. 6(1)(a) GDPR; you can withdraw this consent at any time.

If the application procedure does not lead to a recruitment, your application data will be deleted no later than six months after the rejection notice, unless legitimate interests on our part (e.g. defence against claims under the General Equal Treatment Act, AGG) require longer storage.

If your application leads to a recruitment, the data will be transferred to your personnel file and processed for the purposes of the employment relationship.

20. Changes to this privacy policy

We reserve the right to amend this privacy policy to reflect changes in the law or in our services (e.g. when introducing new functionality). The version that applies to your next visit will be the version published at that time.