Initial consultation
EN

Privacy policy

The data this website processes, the purposes and legal bases, and your rights in relation to that processing.

1 · Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data on this website is:

Company
MSR-Innovations GmbH
Address
Priemershofer Weg 1
95326 Kulmbach
Germany
Represented by
Managing Director Rainer Herold
Telephone
+49 9221 80421-01
Email
info@msr-innovations.de

SysTec.AI is a brand of this company and is not a separate legal entity. Full provider information is available in the legal notice.

2 · Data protection officer

Whether a data protection officer has been appointed and how to contact them - to be clarified by MSR. If no appointment is required, this section is omitted and enquiries are directed to the address in section 1.

3 · Hosting and server log files

When you access a page, your browser transmits technically necessary data to the server hosting this website. These are recorded in log files, typically including the IP address, access date and time, requested file, amount of data transferred, browser type and operating system.

Hosting provider’s company name and address, data processing agreement under Article 28 GDPR, fields actually logged and log retention period - to be determined once the hosting agreement has been concluded

The legal basis is our legitimate interest in the secure and uninterrupted operation of the website under Article 6(1)(f) GDPR. These data are not combined with other data sources.

4 · Encryption

This website is served exclusively over an encrypted connection (TLS). You can recognise this by https:// in the address bar and the padlock symbol in your browser. During an encrypted connection, third parties cannot read the data you send us.

5 · Fonts

The fonts used by this website are stored locally on our server or are taken from the fonts available on your device. There is no connection to Google Fonts or any other external font service; no IP address is therefore transmitted to a font provider when you access a page.

6 · Consent management (CCM19)

We use the consent management tool CCM19 to manage your consent to cookies and similar technologies. On your first visit, a notice lets you choose which categories to allow. Your decision is stored so you do not need to make it again on subsequent visits.

The stored information comprises your consent decision for each category, a timestamp, a random identifier and details of the version of the notice used. Storage is necessary to demonstrate consent; the legal bases are section 25(2), point 2, TDDDG and Article 6(1)(c) and (f) GDPR.

You can change or withdraw your decision at any time. Link to the button that reopens the notice - to be determined once CCM19 has been integrated

CCM19 deployment method (self-hosted or as a service), provider and address, retention period for the consent record and, where applicable, an agreement under Article 28 GDPR - to be specified by MSR

7 · Audience measurement with Google Analytics

Only with your consent. If you allow the statistics category in the notice described in section 6, we use Google Analytics 4 to understand which pages are read and where visitors leave. Without your consent, nothing is loaded or measured.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data processed include pages accessed, time spent, approximate location based on the truncated IP address, device type, browser and the source through which you reached the website. Google truncates the IP address within the EU before further processing; Google Analytics 4 does not store complete IP addresses.

The legal basis is your consent under Article 6(1)(a) GDPR in conjunction with section 25(1) TDDDG. A data processing agreement under Article 28 GDPR is in place with Google.

A transfer to the United States cannot be ruled out. Google LLC is certified under the EU-U.S. Data Privacy Framework; the European Commission’s Standard Contractual Clauses also apply. Further information about Google’s data processing is available at policies.google.com/privacy.

Selected retention period for event data (2 or 14 months), use of Google Consent Mode and Google Tag Manager, account and property identifier - to be specified by MSR

8 · Google Search Console

We use Google Search Console to see which search terms lead to this website in Google Search and whether technical errors occur when pages are retrieved. The analyses come from Google’s search index and are shown to us only in aggregated form. Individual visitors cannot be identified.

Search Console itself sets no cookies on this website and loads no scripts in your browser. Method of ownership verification (HTML file, DNS entry or Analytics tag) - to be specified by MSR

9 · Contact form

You can send us a written enquiry on the initial consultation & contact page. We collect:

  • Subject (selection), name and email address (required)
  • Practice, telephone number and number of staff (optional)
  • Your message
  • Your consent to storage for the purpose of handling your enquiry

The purpose is solely to handle your enquiry and take steps towards a possible contract. The legal bases are your consent under Article 6(1)(a) GDPR and, where the enquiry concerns steps prior to entering into a contract, Article 6(1)(b) GDPR. You can withdraw consent at any time with effect for the future; an informal message to the address in section 1 is sufficient.

How the enquiry is delivered (email inbox, CRM system), the provider involved and the retention period for enquiries - to be decided before the form goes live

10 · AI readiness check

The readiness check asks six questions and then provides an assessment. Your answers remain entirely in your browser: they are not transmitted or stored and disappear when the window is closed. We do not learn that you used the check or what you answered.

11 · Further services

Any additional integrated services will be described individually here, with their provider, purpose, legal basis, retention period and any transfers to third countries.

Check whether the following are used: Google Tag Manager · Google Ads and conversion tracking · LinkedIn Insight Tag · map service on the contact page · embedded videos · appointment booking tool · newsletter delivery · application form · content delivery network · linked social media profiles

12 · Recipients and processors

Complete list of service providers processing data on our behalf (hosting, consent management, audience measurement, email delivery and, where applicable, CRM), each with an agreement under Article 28 GDPR - to follow the decisions in sections 3, 6, 7 and 9

13 · Transfers to third countries

When Google Analytics is used, processing by Google LLC in the United States cannot be ruled out (see section 7). The bases are the European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework and, additionally, the Standard Contractual Clauses. No further transfers to countries outside the European Union are currently planned.

14 · Retention periods

Personal data are deleted as soon as the purpose of processing no longer applies and there is no statutory retention obligation. Commercial and tax retention periods apply to business correspondence, including enquiries that lead to a contract. Retention periods for individual services are stated in the respective sections.

15 · Your rights

You have the following rights in relation to personal data concerning you:

  • Access to information about whether and which data we process (Article 15 GDPR)
  • Rectification of inaccurate data (Article 16 GDPR)
  • Erasure (Article 17 GDPR)
  • Restriction of processing (Article 18 GDPR)
  • Data portability (Article 20 GDPR)
  • Objection to processing based on a legitimate interest (Article 21 GDPR)
  • Withdrawal of consent with effect for the future (Article 7(3) GDPR)

An informal message to the address in section 1 is sufficient for any of these requests.

Right to complain to a supervisory authority

You may also lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Authority
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), the Bavarian State Office for Data Protection Supervision
Address
Promenade 18
91522 Ansbach
Website
www.lda.bayern.de

16 · Changes to this policy

We update this policy whenever the website or the services used change. The version published here is the applicable version.

Last updated: Date of the first reviewed version