Privacy Policy
This privacy policy informs you about which personal data are processed when you visit the website www.e-vein.com (also reachable at e-vein.com, e-vein.de and www.e-vein.de) and when you contact us, for what purpose this is done and what rights you have. The applicable laws are the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG).
1. Controller
The controller responsible for data processing within the meaning of Art. 4(7) GDPR is:
e-vein GmbH
Aign 4
83569 Vogtareuth
Germany
Represented by the managing directors Georg Höß and Vitus Höß
E-mail: info@e-vein.com
Telephone: +49 8031 2219886
Commercial register: Amtsgericht Traunstein (Local Court), HRB 27755
VAT ID no.: DE319738109
2. Overview: what this website does – and what it does not
Our website is a purely informational, static company website. It requires very little data processing:
- No cookies are set.
- There are no analytics or tracking services, no social media plugins, no embedded videos or maps.
- There is no contact form, no newsletter, no login area and no shop. You can reach us exclusively by e-mail or telephone.
- There is no profiling and no automated decision-making within the meaning of Art. 22 GDPR.
- We do not base any processing on consent, and there is no consent banner: the only access to your device (storing the language setting, see Section 5) does not require consent under Section 25(2) no. 2 TDDDG.
The following sections explain which data are nevertheless generated for technical reasons when you access the site.
3. Hosting and delivery of the website
The website is hosted by Amazon Web Services (AWS). The website files are stored in the Amazon S3 storage service in the eu-central-1 region (Frankfurt am Main, Germany). They are delivered via the Amazon CloudFront content delivery network, which has delivery locations (edge locations) worldwide. Visitors from the EU are generally served from a location within the EU; depending on your location, however, delivery may also take place via a location outside the EU.
Data processed: In order for the website to be transmitted to your device, your IP address must be transmitted to AWS for technical reasons. It is strictly necessary for establishing the connection and delivering the content. Whether and for how long it is stored in logs beyond this is described in Section 4.
Purpose and legal basis: Provision, stability and security of the website. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the reliable and secure presentation of our company's offering on the internet.
Processor: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. A data processing agreement pursuant to Art. 28 GDPR is in place with AWS (AWS Data Processing Addendum as part of the AWS Service Terms).
Transfer to third countries: Where data are delivered via an edge location outside the EU or the EEA or are processed by the US group company Amazon Web Services, Inc., this is safeguarded by the EU standard contractual clauses (Art. 46(2)(c) GDPR) contained in the AWS Data Processing Addendum. In addition, Amazon Web Services, Inc. is certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR).
Further information: AWS Privacy Notice.
4. Server logs
We do not keep any server logs (log files) of accesses to our website. Access logging of the Amazon CloudFront delivery service is switched off. Your IP address and the other technical connection data (e.g. browser type, page accessed, time) are not logged, stored or analysed by us. Whether and for how long AWS processes connection data for its own operational and security purposes is governed by the AWS privacy notice (link in Section 3).
The legal basis for the purely technical transmission of your IP address to AWS for delivering the website is Art. 6(1)(f) GDPR (legitimate interest in providing the website, see Section 3). Retention period: no storage by us.
5. Stored language setting (localStorage)
Our website is available in German, English and Spanish. If you actively select a language via the language selector, your browser stores the selected language in its local storage (localStorage) under the entry “language” with the value “de”, “en” or “es”. If you do not select a language, nothing is stored. On each subsequent visit, the website reads the stored entry in order to display the page directly in the selected language.
Purpose: The language you have selected is to be retained on your next visit. The entry contains no identifier, does not make it possible to recognise you and is not transmitted to us or to third parties; it remains exclusively in your browser.
Legal basis: Section 25(2) no. 2 TDDDG. Storing the entry and reading it later are strictly necessary in order to provide the service you have expressly requested by making that selection – the display of the website in the selected language. Consent is therefore not required. No personal data reach us in this process; to this extent, no processing under the GDPR by us takes place.
Retention period: The entry remains stored until you delete it. You can remove it at any time via your browser settings (deleting the site data for this website).
6. Embedded third-party content (content delivery networks)
Individual technical components of our website are loaded from external content delivery networks (CDN). When these files are loaded, your browser establishes a connection to the server of the respective provider; in doing so, the provider inevitably receives your IP address, the technical details of your browser and, as a rule, an indication of the page from which the request originates (referrer). No content or input is transmitted.
When any page is accessed:
- Tailwind CSS (styling library) from cdn.tailwindcss.com, operated via Cloudflare, Inc., USA.
Only when the optional 3D model viewer is opened (click on the model). As long as you do not open the viewer, none of this is loaded:
- three.js (library for 3D rendering) from cdn.jsdelivr.net, operated by the open-source CDN jsDelivr (Prospect One, Kraków, Poland) via the networks of Cloudflare, Inc. (USA), Fastly, Inc. (USA), Bunny and GCore.
- Font Awesome (icon font) from cdnjs.cloudflare.com, operated by Cloudflare, Inc., USA.
Purpose: Correct display of the website and functioning of the 3D viewer, respectively. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest lies in a functional and reliable presentation of our content.
Transfer to third countries: Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) and Fastly, Inc. (USA) are established in the USA; depending on your location, your IP address may be transmitted there. Both companies are certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR). Which network delivers a file via jsDelivr is selected automatically by jsDelivr; we have no influence over this. Further information: Cloudflare Privacy Policy, jsDelivr Privacy Policy.
Retention period: We do not store any data in this context. We have no control over the retention period at the respective provider; its privacy notice is decisive.
7. Fonts
The fonts Inter and Oswald used on this website are delivered from our own hosting (see Section 3). There is no connection to Google Fonts or other external font providers; apart from retrieving the font files, which is part of the normal delivery of the website, no additional data are generated.
8. Contacting us by e-mail or telephone
If you contact us by e-mail (e.g. via the link info@e-vein.com on our website) or by telephone, we process the data you provide: your e-mail address or telephone number, your name if given, the content of your enquiry and, where applicable, your company details.
Purpose: Processing and answering your enquiry, preparing quotations, and initiating, performing and settling contracts.
Legal basis: If your enquiry is aimed at concluding or performing a contract (e.g. request for a quotation, order, complaint), the legal basis is Art. 6(1)(b) GDPR. For other enquiries, it is Art. 6(1)(f) GDPR; our legitimate interest lies in properly answering enquiries addressed to us.
Obligation to provide data: You are neither legally nor contractually obliged to provide us with your data. Without your contact details and the content of your enquiry, however, we cannot process it.
Processor: Our e-mail system is operated via Microsoft 365 (Exchange Online). The provider is Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place with Microsoft (Microsoft Products and Services Data Protection Addendum). The e-mail data are stored within the EU (Microsoft EU Data Boundary).
Transfer to third countries: Access by the US-based Microsoft Corporation, for example for support or security purposes, cannot be entirely ruled out. It is safeguarded by the EU standard contractual clauses (Art. 46(2)(c) GDPR) contained in the Microsoft DPA; in addition, Microsoft Corporation is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). Further information: Microsoft Privacy Statement.
Retention period: We store your enquiry until it has been dealt with conclusively and no further queries are to be expected. If it constitutes business correspondence, we are legally obliged to retain it (Art. 6(1)(c) GDPR in conjunction with Section 257(4) of the German Commercial Code (HGB) and Section 147(3) of the German Fiscal Code (AO)): we retain commercial and business letters for six years and accounting records (e.g. invoices) for eight years, in each case calculated from the end of the calendar year in which the letter was received or sent or the record was created. The period is extended for as long as the documents are relevant to taxes for which the assessment period has not yet expired (Section 147(3) AO). After expiry, the data are deleted.
9. Encryption
The website is delivered exclusively via an encrypted HTTPS connection (TLS). Unencrypted requests via http:// are automatically redirected to the encrypted connection. You can recognise the encryption by the address beginning with https:// in your browser's address bar.
10. Your rights as a data subject
With regard to the personal data concerning you, you have the following rights vis-à-vis us:
- Access (Art. 15 GDPR) to whether and which data we process about you, as well as the further information set out in Art. 15;
- Rectification (Art. 16 GDPR) of inaccurate data or completion of incomplete data;
- Erasure (Art. 17 GDPR), insofar as the processing is no longer necessary and no statutory retention obligations stand in the way;
- Restriction of processing (Art. 18 GDPR) under the conditions set out there;
- Data portability (Art. 20 GDPR): receipt of the data you have provided to us on the basis of a contract in a structured, commonly used and machine-readable format;
- Objection (Art. 21 GDPR) – see Section 11;
- Complaint to a supervisory authority (Art. 77 GDPR) – see Section 12.
A right of withdrawal under Art. 7(3) GDPR presupposes that consent has been given. Since we do not base any processing on your consent, it currently does not apply.
To exercise your rights, an informal message to info@e-vein.com or to the postal address given in Section 1 is sufficient. Exercising your rights is free of charge for you.
11. Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR (legitimate interest).
This concerns in particular the processing operations described in Sections 3, 4, 6 and 8. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
We do not engage in direct marketing; an objection under Art. 21(2) GDPR is therefore without object.
The objection may be made informally and should be addressed to: e-vein GmbH, Aign 4, 83569 Vogtareuth, e-mail info@e-vein.com.
12. Right to lodge a complaint and competent supervisory authority
Without prejudice to any other remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR.
The supervisory authority competent for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA – Bavarian State Office for Data Protection Supervision)
Promenade 18
91522 Ansbach
Telephone: +49 981 180093-0
E-mail: poststelle@lda.bayern.de
www.lda.bayern.de
13. Currency of this privacy policy
This privacy policy is dated 14 September 2026. We will adapt it if the data processing on our website or the legal requirements change. The current version can always be found on this page.