1. Scope of this notice
This privacy notice explains how Auditi GmbH processes personal data when you visit this marketing website, use its language and display controls, submit a demo request or contact us. It does not govern the separate Auditi application, which has its own privacy information.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Auditi GmbH
Hansaallee 299
40549 Düsseldorf
Germany
Phone: +49 211 240 922 90
Email: mail@auditi.de
3. Data protection officer
You can contact our data protection officer directly at:
Reinhold Goetz, Dipl.-Ing. Nachrichtentechnik
Ingenieurbüro für Datenschutz- und Informationsmanagement
Kampstraße 6
50374 Erftstadt
Germany
Phone: +49 2235 9947997
4. Principles and legal bases
We process personal data only where this is necessary for a stated purpose and a legal basis applies. Depending on the situation, we rely on steps requested before entering into a contract (Article 6(1)(b) GDPR), legal obligations (Article 6(1)(c) GDPR) or our legitimate interests (Article 6(1)(f) GDPR). Where processing is based on consent, we will say so separately.
5. Hosting and server logs
We host this website with Vercel .
When you access the website, the hosting infrastructure processes technical request data needed to deliver and protect the site. This may include:
- IP address and country or region derived from it
- Date and time of the request
- Requested address, request method and response status
- Referrer address, browser, operating system and device information
- Technical request, deployment and security identifiers
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient delivery of the website, error analysis and protection against misuse.
We do not maintain a separate archive of server logs. Runtime logs available to us through Vercel are retained according to the selected service plan for no more than 30 days. Relevant data may be retained longer where this is necessary to investigate a security incident, establish or defend legal claims or comply with a legal obligation.
Country-based edition suggestion
On the global homepage, Vercel may provide us with the ISO country code derived from the request IP address. We use it once to suggest a more relevant country edition. We do not receive a precise location and do not create a permanent location profile. If you dismiss the suggestion, a preference cookie prevents it from appearing repeatedly.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to present a relevant language and market edition without automatically redirecting visitors.
6. Privacy-focused web analytics
We measure aggregated website use with Vercel Web Analytics .
The service records information such as page and path, referring page, browser, device type, operating system, country, time and campaign parameters. It does not set analytics cookies. A daily changing hash derived from request data is used to count visits and cannot be used by us to recognize a visitor across different days or websites. We do not use this information to build user profiles.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to understand aggregated use of the website and improve its content and navigation.
Performance measurement
We measure technical website performance with Vercel Speed Insights .
The service processes route or path, browser, device type, operating system, network speed, country, web performance values, related page elements, SDK information and event time. According to Vercel, the data points are anonymous, are not tied to a visitor or IP address and cannot reconstruct a browsing session.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to identify technical performance problems and improve the website.
7. Strictly necessary preference cookies
This website does not use advertising or analytics cookies. It stores the following first-party cookies only after you use the corresponding control. They remember an expressly requested display preference and are not used to track you.
The cookies are stored under section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Any related processing of personal data is based on Article 6(1)(f) GDPR and our legitimate interest in retaining the preference you requested.
Cookies used on this website
| Name | Purpose | Duration |
|---|---|---|
| auditi_header_unsticky | Remembers that you chose to unpin the website header for the current browser session. | Browser session |
| auditi_market_prompt_dismissed | Remembers that you dismissed the country-edition suggestion so it is not shown repeatedly. | 1 year |
8. Demo request form
When you submit the demo request form, we process the information you enter and technical context sent with the submission.
The submission contains:
- Name, work email address and firm or company
- Optional message and your answer about how you found us
- Country edition, locale, page path and page address
- Referring page and, when present in the page address, UTM parameters or advertising click identifiers
- Submission time
We use the data to respond to your request, prepare and schedule a relevant demo, take requested pre-contractual steps, protect the form against misuse and understand which campaigns lead to direct inquiries.
The legal basis is Article 6(1)(b) GDPR where you request steps before entering into a contract. For inquiries made on behalf of a firm, abuse prevention and limited source attribution, the legal basis is Article 6(1)(f) GDPR. Our legitimate interests are handling business inquiries, securing the form and measuring the direct response to our marketing.
Name, work email, firm or company and the source field are required so that we can assign and respond to the request. The message field is optional. Without the required information, we cannot process the form.
The form is sent from our server to our processor Zapier, Inc. Zapier forwards it to the responsible Auditi team as part of an automation configured by us. More information: Zapier .
We retain the submission for as long as needed to handle the inquiry and any resulting pre-contractual or contractual relationship. If no relationship results, we delete the data when the inquiry has been conclusively dealt with unless you have asked us to remain in contact or legal retention or claim periods require longer storage.
9. Contact by email, telephone or fax
If you contact us by email, telephone or fax, we process your contact details, the content of the inquiry and related communication data to respond and manage the matter.
The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual communication and Article 6(1)(f) GDPR for other business inquiries. Our legitimate interest is the effective handling and documentation of communications addressed to us.
We delete contact data when the matter has been conclusively dealt with unless a contractual relationship, statutory retention duty, consent to further contact or the establishment, exercise or defence of legal claims requires longer storage.
10. Recipients and processors
Access is limited to authorized Auditi staff who need the data for the relevant purpose. We also use Vercel Inc. for hosting, analytics and performance measurement and Zapier, Inc. for demo-form delivery. These providers process data under contractual data protection obligations and may use listed subprocessors to provide their services. We disclose data to public bodies only where legally required.
11. Processing outside the EEA
Vercel and Zapier are based in the United States and may process data there or through subprocessors in other countries. Where personal data is transferred outside the European Economic Area, the transfer is based on an applicable adequacy decision, including the EU-U.S. Data Privacy Framework where available, or the European Commission’s standard contractual clauses together with supplementary safeguards where required. You may request information about the relevant safeguards from us.
12. Security
This website uses TLS encryption. We and our processors use technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration and disclosure. No transmission or storage method can provide absolute security.
13. General retention rule
Unless a more specific period is stated above, we retain personal data only for as long as the relevant purpose and legal basis continue to apply. We then delete or anonymize the data unless statutory retention periods or the establishment, exercise or defence of legal claims require continued storage.
14. Your rights
Subject to the statutory requirements, you have the right to:
- Request access to your personal data and a copy of it (Article 15 GDPR)
- Request correction of inaccurate or completion of incomplete data (Article 16 GDPR)
- Request erasure of your personal data (Article 17 GDPR)
- Request restriction of processing (Article 18 GDPR)
- Receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller (Article 20 GDPR)
- Withdraw consent at any time with effect for the future where processing is based on consent (Article 7(3) GDPR)
Right to object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is needed to establish, exercise or defend legal claims. You may object to processing for direct marketing at any time without giving reasons.
Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority, in particular in the EEA country of your habitual residence, place of work or the alleged infringement. The supervisory authority responsible for our German establishment is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
15. Automated decisions
We do not use the processing described in this notice for decisions based solely on automated processing that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR. We do not create marketing profiles from website visits.
16. Changes to this notice
We update this notice when our website, providers or legal obligations change. The effective date and version shown at the top identify the current text.