Skip to content
CLARIST
Why CLARIST? What we help with Method About me Contact DE | EN
Why CLARIST? What we help with Method About me Contact DE | EN
LEGAL

Privacy Policy

Last updated: 30 September 2026

Protecting your personal data is important to us. The following information explains which personal data is processed when you visit this website or contact us.

1. Controller

CLARIST GmbH
Heiligengeiststraße 6–8
26121 Oldenburg
Germany

Represented by the Managing Director: Friederike von Krosigk
Email: contact@clarist.de

2. Hosting and provision of the website

This website is hosted by Raidboxes GmbH, Hafenstraße 32, 48153 Münster, Germany. Raidboxes provides the WordPress hosting for this website with servers located in Germany.

When you access this website, technically necessary data is processed in order to deliver the website to your device and to ensure secure and stable operation. In server access logs, the following information may in particular be processed:

  • IP address
  • date and time of access
  • type of request
  • client information, in particular client type and client version
  • operating system and device information
  • referrer information

The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and technically reliable provision of this website and the detection and resolution of technical errors and security incidents.

Raidboxes processes personal data on our behalf in connection with the hosting service. A data processing agreement with Raidboxes pursuant to Art. 28 GDPR is in place. Where Raidboxes engages sub-processors, their use is governed by this agreement and the applicable data protection requirements.

Raidboxes states that server access logs are retained for a maximum of seven days. Processing beyond this period takes place only where necessary for troubleshooting or the investigation of security incidents, or where statutory or contractual requirements require longer retention.

3. No web analytics or marketing tracking

We currently do not use web analytics, advertising or marketing tracking services on this website. In particular, we do not use Google Analytics or the Meta Pixel.

The server access logs described in section 2 are used for the technical operation and security of the website. We do not use them to create user profiles or to analyse visitor behaviour for advertising purposes.

4. Locally hosted fonts

The fonts used on this website are hosted locally on our web space. These include fonts from the Jost, IBM Plex Sans and JetBrains Mono families.

Loading these fonts does not establish a connection to Google Fonts or other external font services.

5. Cookies and similar technologies

We currently do not use analytics, advertising or marketing cookies on this website.

Where technically necessary information is stored on or accessed from your device, this takes place only where necessary to provide the digital service expressly requested by you or for technically required security and administration functions. The legal basis for such access is section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG); any subsequent processing of personal data is governed by the respective legal bases under the GDPR stated in this policy.

Technically necessary cookies or session information may in particular be used in the WordPress administration area. These generally relate to the administrative use of the website and not to general tracking of website visitors.

If we introduce services in the future that require consent, they will only be activated after your prior consent and this Privacy Policy will be updated accordingly.

6. WordPress

This website is operated using the WordPress content management system. WordPress is run on the hosting infrastructure provided by Raidboxes.

We use WordPress to create, manage and technically provide the website. The website currently does not provide public user accounts, comment functions or other features through which visitors can independently publish personal content in WordPress.

7. Contact by email and Microsoft 365

If you contact us by email, we process the personal data you provide. This may include your name, email address, company details, the content of your message and any other information you voluntarily provide.

We use Microsoft 365 for our business email communications. The provider for European customers is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft processes data in accordance with its contractual data protection terms and the Microsoft Products and Services Data Protection Addendum. Where processing takes place outside the European Economic Area, it is carried out on the basis of the applicable data protection transfer mechanisms.

The data is processed in order to handle and respond to your enquiry. Where your enquiry relates to entering into or performing a contract, the legal basis is Art. 6(1)(b) GDPR. For other business or general enquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to process and respond to communications addressed to us.

The data is deleted once it is no longer required to handle the enquiry, unless statutory retention obligations or other legitimate reasons require further storage.

8. Contact form

A contact form is available on this website. If you use the form, we process the data you enter. This includes your name, email address, company where provided voluntarily, and the content of your message. Your name, email address and message are required to submit and process the enquiry; providing your company is voluntary. The form cannot be submitted without the required information. We currently do not use an external CAPTCHA service for this form.

The information is processed via the WordPress and hosting infrastructure at Raidboxes and transmitted to our Microsoft 365 environment so that we can handle your enquiry. It is not used for newsletters, advertising profiles or other marketing purposes without a separate legal basis or, where required, your consent.

Where your enquiry concerns entering into or performing a contract, processing is based on Art. 6(1)(b) GDPR. For other business or general enquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to process your enquiry and communicate with you for business purposes.

The data is deleted once it is no longer required to handle the enquiry, unless statutory retention obligations or other legitimate reasons require further storage.

9. LinkedIn

This website may contain simple links to profiles or company pages on the LinkedIn social network.

We do not use LinkedIn plugins, the LinkedIn Insight Tag or embedded LinkedIn content. Merely visiting our website therefore does not establish a connection to LinkedIn through these simple links.

Only when you click a LinkedIn link do you leave our website and access LinkedIn. LinkedIn is responsible for the processing of personal data that takes place there.

For users in the European Economic Area, the responsible entity is generally:

LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland

Further information about LinkedIn’s processing of personal data is available in LinkedIn’s privacy policy.

10. Encrypted transmission

This website is provided via an encrypted HTTPS connection. This protects data transmitted between your browser and our server against unauthorised interception in transit in accordance with the current state of the art.

11. No automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR on this website.

12. Your rights

Subject to the statutory requirements, you have in particular the following rights:

  • right of access to personal data concerning you under Art. 15 GDPR
  • right to rectification of inaccurate personal data under Art. 16 GDPR
  • right to erasure under Art. 17 GDPR
  • right to restriction of processing under Art. 18 GDPR
  • right to data portability under Art. 20 GDPR
  • right to object to certain processing under Art. 21 GDPR

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.

13. Right to object to processing based on legitimate interests

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object at any time, on grounds relating to your particular situation, to that processing.

We will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.

14. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The supervisory authority particularly relevant to CLARIST is:

The State Commissioner for Data Protection of Lower Saxony (Der Landesbeauftragte für den Datenschutz Niedersachsen)
Prinzenstraße 5
30159 Hannover
Germany
Telephone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de

15. Changes to this Privacy Policy

We update this Privacy Policy when the services we use, our technical infrastructure, our processing of personal data or the applicable legal requirements change. The version published on this website at the relevant time applies.

CLARIST
Pages
Why CLARIST? What we help with Method About me Contact
CLARIST GmbH
Legal notice Privacy policy LinkedIn