EPSIASoftware development for complex systems · BerlinDE

Privacy policy

This is a translation for information purposes; only the German version is legally binding. This privacy policy describes which personal data EPSIA GmbH processes when you visit this website, for what purpose and on what legal basis. Personal data is any information that can be used to identify you personally. In short: the website sets no cookies, does not track visitors, embeds no third-party services and processes only the data needed to deliver the pages and to answer an enquiry.

Controller

The controller responsible for data processing on this website is EPSIA GmbH, represented by its Managing Director Daniel Erbert, Siegfriedstraße 152, 10365 Berlin, Germany. Email: contact@epsia.io.

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data. EPSIA GmbH is not legally required to appoint a data protection officer; questions about data protection should be sent to the email address above.

Hosting and server logs

The website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany; the servers are located in a data centre in Germany. With every request, your browser transmits technically necessary data, which the server records in log files:

  • IP address of the requesting device
  • date and time of the request
  • requested address, HTTP status code and amount of data transferred
  • previously visited page (referrer), if your browser transmits it
  • browser and operating system

This data is needed to deliver the website and to ensure its stability and security, for example to detect attacks. The legal basis is the legitimate interest of EPSIA GmbH in secure and error-free operation (Art. 6(1)(f) GDPR). The log data is not combined with other data and is deleted after the retention period set by the host.

A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS. It ensures that IONOS processes visitors' data only on the instructions of EPSIA GmbH and in compliance with the GDPR.

Cookies, tracking and third-party services

The website sets no cookies and stores nothing in your browser. There is no audience measurement, no tracking, no advertising and no embedded content from third-party providers such as maps, video platforms or social networks.

Fonts (IBM Plex Sans, IBM Plex Mono), images and videos are stored on EPSIA's own server and delivered from there. When you visit the website, your browser therefore does not connect to any third-party servers, and your IP address is not passed on to any third party. Links to external sites, such as LinkedIn, only take effect when you click them; from then on, the privacy policy of the respective provider applies.

Contact form

If you use the contact form, EPSIA GmbH processes the information you enter: name, email address and message and, if you provide them, company and phone number. In addition, the time of submission and the IP address of your device are processed. The IP address is used to prevent misuse: it shows whether an unusually high number of enquiries come from one connection within a short time.

The form is transmitted encrypted (TLS). The website itself does not store the enquiry but sends it as an email via the email service of IONOS SE (servers in Germany) to the mailbox contact@epsia.io. It is kept there and in the internal processing system of EPSIA GmbH in order to answer it and for follow-up questions. No data is transferred to countries outside the European Union. The data is not passed on to third parties without your consent.

By ticking the checkbox in the form, you consent to your information being processed to handle the enquiry (Art. 6(1)(a) GDPR); the form cannot be submitted without this consent. You can withdraw your consent at any time with effect for the future; an informal email is sufficient. If your enquiry relates to a contract or to steps prior to entering into a contract, Art. 6(1)(b) GDPR is an additional legal basis. For the IP address, the legal basis is the legitimate interest of EPSIA GmbH in the security of its systems (Art. 6(1)(f) GDPR).

The data is deleted once the enquiry has been fully dealt with and there is no reason for further retention, or earlier if you request it or withdraw your consent. Statutory retention obligations, for example for business correspondence under commercial and tax law, remain unaffected.

Enquiries by email

If you send EPSIA GmbH an email, your message and the information it contains are stored in order to handle your request. The same legal bases and deletion rules apply as for the contact form.

Your rights

You have the following rights vis-à-vis EPSIA GmbH regarding your personal data, at any time and free of charge:

  • access to the stored data, its origin, its recipients and the purpose of processing (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability in a common, machine-readable format (Art. 20 GDPR)
  • withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)

An informal email to contact@epsia.io is sufficient.

Right to object

Where processing is based on the legitimate interest of EPSIA GmbH (Art. 6(1)(f) GDPR), you may object to it at any time on grounds relating to your particular situation (Art. 21 GDPR). EPSIA GmbH will then no longer process the data unless it can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your data infringes the GDPR (Art. 77 GDPR). The authority responsible for EPSIA GmbH is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin.

Data security

The website is delivered exclusively in encrypted form via HTTPS; you can recognise an encrypted connection by the padlock icon and by "https://" in your browser's address bar. With unencrypted communication, such as ordinary email, complete protection against access by third parties is not possible.

Last updated

This privacy policy was last updated in October 2026. It will be revised if the website or the legal requirements change.