Privacy Policy
1. Controller
The controller responsible for the processing of personal data in connection with this website is:
SANCTUARY Systems GmbH
Robert-Bosch-Str. 7
64293 Darmstadt
Germany
E-Mail: [email protected]
2. General Information on Data Processing
This Privacy Policy provides information on which personal data are processed when visiting this website, when accessing the blog, and when contacting SANCTUARY Systems GmbH.
This website is designed with data minimization in mind. No cookies are set, no web tracking is employed, and no analytics, marketing, or profiling services are used. External resources such as web fonts, Content Delivery Networks, Captcha services, embedded maps, video players, or social media plugins are not loaded from third parties.
The website contains an editorial blog with no comment function, user accounts, newsletter subscription, or additional tracking features.
Even during a purely informational visit to the website, technically necessary data is processed. This is necessary so that the website can be delivered to the visiting person's end device, operated securely, and protected against technical disruptions or attacks.
3. Website Provision and Server Log Files
When accessing this website, the web server automatically processes technical access data. This may in particular include:
IP address of the requesting end device, date and time of access, requested page or file, amount of data transmitted, HTTP status code, referrer URL, browser type and browser version, operating system, and the requesting provider.
The processing is carried out for the following purposes:
Provision of the website, ensuring the stability and security of systems, error analysis, abuse and attack detection, and ensuring proper technical operation.
The legal basis is Art. 6(1)(1)(f) GDPR. The legitimate interest lies in the secure, stable, and functional operation of the website and the protection of the technical infrastructure.
Server log files are generally deleted or anonymized no later than 30 days after collection. A longer retention period applies only to the extent necessary for investigating security-related incidents or for asserting, exercising, or defending legal claims.
4. Blog
This website contains a blog through which SANCTUARY Systems GmbH publishes professional articles, company information, and other content.
The blog has no comment function. No user accounts are provided, no posts by website visitors are published, no newsletter is operated through the blog, and no additional analytics or tracking features are employed.
When accessing blog pages, the same technical access data are processed as during the rest of the website visit. This may in particular include IP address, date and time of access, requested page or file, amount of data transmitted, HTTP status code, referrer URL, browser type and browser version, operating system, and the requesting provider.
To the extent that blog posts contain information about authors, such as names, professional details, profile information, or published content, this data is processed for the purpose of editorial publication, professional attribution, and external representation.
The legal basis for the processing of technical access data is Art. 6(1)(1)(f) GDPR. The legitimate interest lies in the provision, security, and stability of the website including the blog.
The legal basis for the publication of editorial author information is Art. 6(1)(1)(f) GDPR, to the extent that no more specific legal basis applies. The legitimate interest lies in the transparent professional classification of published content and corporate communication.
Server log files in connection with blog accesses are deleted or anonymized in accordance with the information in the section 'Website Provision and Server Log Files'.
5. Hosting
This website is operated by an external hosting service provider. Under the current configuration, the following provider is used:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
The hosting service provider processes personal data as part of providing the technical infrastructure, in particular server capacity, storage space, network services, and security functions. To the extent that the hosting service provider processes personal data on behalf of SANCTUARY Systems GmbH, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.
The legal basis for the use of the hosting service provider is Art. 6(1)(1)(f) GDPR. The legitimate interest lies in the secure, efficient, and professional provision of the website.
6. No Cookies, No Tracking, and No External Resources
This website does not use cookies. No comparable technologies are employed that store or read information on the end device for analytics, marketing, or tracking purposes.
No reach measurement is performed. No user profiles are created. No external fonts, CDN resources, Captcha services, maps, video players, or social media plugins are embedded from third parties.
A cookie banner or consent management tool is therefore not required under the described technical design, provided that this website does not actually perform any consent-required storage or access operations on end devices.
7. Contact
When contacting SANCTUARY Systems GmbH, in particular by e-mail or by post, the transmitted personal data is processed. This may in particular include name, e-mail address, postal address, content of the message, time of contact, and technical communication data.
The processing is carried out for handling the inquiry, for communication with the inquiring person, and, where applicable, for carrying out pre-contractual measures or for managing an existing business relationship.
The legal basis is Art. 6(1)(1)(b) GDPR to the extent that the inquiry is directed at concluding or performing a contract. In all other cases, the legal basis is Art. 6(1)(1)(f) GDPR. The legitimate interest lies in the appropriate handling of incoming inquiries and the documentation of business communication.
To the extent that statutory retention obligations exist, the legal basis for the corresponding storage is Art. 6(1)(1)(c) GDPR.
The data transmitted in the context of contact will be deleted as soon as the inquiry has been fully processed and no statutory retention obligations or legitimate interests in further storage exist. Business-relevant communication may be stored until the expiration of statutory retention or limitation periods.
E-mails are regularly transmitted with transport encryption over the internet. End-to-end encryption, however, only takes place if it has been separately set up by the communicating parties.
8. Recipients of Personal Data
Personal data is only transmitted to external recipients to the extent necessary for the operation of the website, the handling of inquiries, the fulfillment of statutory obligations, or the safeguarding of legitimate interests.
Recipients may in particular be hosting, e-mail, and IT service providers acting as processors. No transfer to third parties for advertising, tracking, or analytics purposes takes place.
9. Transfers to Third Countries
Within the scope of the described website operation, no external third-party resources are embedded and no data is transmitted to states outside the European Union or the European Economic Area for analytics, marketing, or tracking purposes.
To the extent that service providers with a third-country connection should be used in individual cases, this will only be done on the basis of the statutory requirements of Arts. 44 et seq. GDPR.
10. Security of Processing
SANCTUARY Systems GmbH takes appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction.
This website is provided via TLS encryption. An encrypted connection is typically recognizable by the website address beginning with 'https://'.
11. Provision of Personal Data
When visiting the website, certain technical access data are processed automatically. Without this processing, the website cannot be technically delivered.
When contacting us, the provision of personal data is voluntary. However, without sufficient contact details and without the information required for processing, an inquiry cannot be answered or can only be answered in a limited manner.
12. Automated Decision-Making and Profiling
No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place.
13. Rights of Data Subjects
Data subjects have the following rights, subject to the statutory requirements:
Right to access the processed personal data under Art. 15 GDPR, right to rectification of inaccurate data under Art. 16 GDPR, right to erasure under Art. 17 GDPR, right to restriction of processing under Art. 18 GDPR, right to data portability under Art. 20 GDPR, and right to object to processing based on Art. 6(1)(1)(f) GDPR under Art. 21 GDPR.
To the extent that processing is based on consent, this consent may be withdrawn at any time with effect for the future. The lawfulness of the processing up to the time of withdrawal remains unaffected.
To exercise these rights, a notification to the following address is sufficient:
Data subjects also have the right to lodge a complaint with a data protection supervisory authority. The following supervisory authority is in particular competent for SANCTUARY Systems GmbH:
The Hessian Commissioner for Data Protection and Freedom of Information
P.O. Box 3163
65021 Wiesbaden
Germany
E-Mail: [email protected]
14. Changes to This Privacy Policy
This Privacy Policy will be updated when changes to the website, the technical infrastructure, the actual data processing, or the legal requirements necessitate this. The current version is available on this website.
Last updated: May 7, 2026