Privacy Policy
Last updated: May 2026
1. Controller
Winkler Technik GmbH
Waldhornstrasse 12, 88662 Überlingen, Germany
Phone: +49 (0) 7551 4444
E-mail: info@winkler-technik.de
2. Privacy at a glance
Personal data is any data that can be used to personally identify you. Data processing on this website is carried out by the website operator. Data is collected either when you provide it (e.g. via the contact form) or automatically when you visit the site (server logs for security and stability).
3. Your rights
You have the right to information (Art. 15 GDPR), correction (Art. 16), deletion (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing (Art. 21). You may revoke any consent given at any time with effect for the future. You also have the right to lodge a complaint with the competent supervisory authority.
4. Hosting & content delivery
This website is hosted on the platform Lovable (Lovable AB, Sveavägen 24-26, 111 57 Stockholm, Sweden) and served via the CDN of Cloudflare (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, and Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany). When you access the site, technically necessary connection data is processed (IP address, date/time, requested resource, user agent, referrer) to deliver content, defend against attacks and ensure stability.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the secure and performant provision of the website). For US transfers we rely on EU Standard Contractual Clauses and – where applicable – the EU-US Data Privacy Framework. Data processing agreements are in place with Lovable and Cloudflare.
5. Backend (Lovable Cloud / Supabase)
For backend functionality (e.g. storing requests from the contact or application form) we use the Lovable Cloud platform integrated with Lovable, which is technically based on Supabase (Supabase Inc., 970 Toa Payoh North #07-04, Singapore). The data is stored in data centers in the European Union (Frankfurt, Germany). Legal basis: Art. 6 (1) lit. b GDPR (pre-contractual / contractual) or Art. 6 (1) lit. f GDPR. Data processing agreements are in place.
6. Cookies & similar technologies
We only use cookies and comparable storage technologies (in particular localStorage) where this is technically required or where you have given your consent. Technically necessary is in particular the storage of your cookie choice itself (key winkler_consent_v2 in your browser). Legal basis: § 25 (2) no. 2 TDDDG together with Art. 6 (1) lit. f GDPR (technically necessary) or § 25 (1) TDDDG together with Art. 6 (1) lit. a GDPR (consent).
You can change or revoke your consent at any time via (also linked in the footer).
7. Third-party services
Google Analytics 4 (Statistics – consent only)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, USA. We use Google Analytics 4 for pseudonymous reach measurement (property ID G-LEPHQHTGN9). IP anonymisation is enabled. Data may be transferred to the USA on the basis of EU Standard Contractual Clauses and – where applicable – the EU-US Data Privacy Framework (Google is DPF-certified). A data processing agreement with Google is in place. Storage period: 14 months. Data processed: pseudonymous cookie / device ID, truncated IP address, device/browser information, referrer, pages visited, dwell time, approximate location (country/region).
Legal basis: Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG (consent). The service is only loaded after active consent via our consent banner.
Vimeo (External videos)
Provider: Vimeo, Inc., 555 West 18th Street, New York, NY 10011, USA. On individual product pages we embed videos via Vimeo. The embed is configured in „Do-Not-Track“ mode (dnt=1), i.e. Vimeo does not set tracking cookies and does not analyse viewing behaviour for advertising purposes. As soon as you play a video, technically necessary connection data (in particular your IP address) is transmitted to Vimeo. Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in providing supplementary product information by video). Vimeo is DPF-certified; Standard Contractual Clauses additionally apply. More information: vimeo.com/privacy.
Fonts (locally hosted)
All fonts on this website are served locally from our own server. No connection to Google Fonts or other external font providers takes place.
8. Contact & enquiries
If you contact us via the contact form, the application form, by e-mail or by phone, we process the data you provide in order to handle your request. Mandatory fields are marked as such. Legal basis: Art. 6 (1) lit. b GDPR (pre-contractual / contractual) and Art. 6 (1) lit. f GDPR (legitimate interest in efficient request handling). We do not pass on data to third parties without consent. Data is deleted as soon as the purpose no longer applies; statutory retention periods (in particular under commercial and tax law) remain unaffected.
9. Spam protection (math challenge)
Our contact and application forms are protected against spam by a simple math challenge. No personal data is transmitted to third parties for this purpose.
10. Applicant data
We process applicant data in accordance with § 26 BDSG, Art. 6 (1) lit. b GDPR and, if applicable, your consent (lit. a). In the case of an unsuccessful application, we generally store your data for up to six months after the end of the procedure on the basis of our legitimate interest (Art. 6 (1) lit. f GDPR). Inclusion in an applicant pool only takes place with explicit consent; deletion takes place no later than two years.
11. Storage period
We only store personal data for as long as necessary for the respective purposes or as required by statutory retention periods. The data is then deleted or anonymised.
12. SSL/TLS encryption
For security reasons, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the „https://“ in the address bar and the lock symbol in your browser.
13. Changes to this privacy policy
We update this privacy policy whenever technical or legal conditions change. The current version published on this page applies.
