Martini Software GmbH · Legal information

Privacy policy

This notice explains which personal data is processed when you visit our website or contact us, why it is processed and what rights you have.

1. Data controller

Martini Software GmbH
Sparrstraße 28
13353 Berlin
Germany

Represented by the managing directors Simon Riegel and Steffen Hornung.

Email: [email protected]
Phone: +49 30 54615883

For privacy questions or to exercise your rights, please use the contact details above. No data protection officer has been appointed.

2. Website, hosting and server logs

Our website is hosted by IONOS on a server in Germany. The hosting provider is IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany.

When you access the website, technically necessary connection data is processed. This may include your IP address, the date and time, the requested page or file, HTTP status, volume of data transferred, browser and operating system details, and the referring page where your browser supplies it. This data enables the website to be delivered and technical faults or attacks to be identified and investigated.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable provision of the website. Under the currently configured retention schedule, server logs are automatically deleted after 90 days. We do not use them for statistical analysis of visitor behaviour.

IONOS processes hosting data as a service provider under its data processing terms. Provider information: Privacy at IONOS.

3. Cloudflare as a reverse proxy

We use Cloudflare to deliver the website and protect it against abusive access and attacks. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Website traffic passes through Cloudflare’s network before reaching our server.

Cloudflare receives IP addresses and technical information about connections, requested content, browsers and security events. Data submitted through the contact form also passes through this proxy. Despite encrypted transmission, Cloudflare may therefore have technical access to the content it forwards. Processing is not restricted to the German location of our hosting server.

The legal basis for delivery and protection is Article 6(1)(f) GDPR. Our interest is in keeping the website available and defending against attacks. Retention depends on the function: connection data is processed for transmission, while security logs are processed to identify and investigate abuse under the service’s applicable retention rules. The retention period stated for our server logs does not automatically apply to Cloudflare.

Cloudflare processes data under its data processing terms. Data may also be transferred to the USA and other countries. For transfers to the US company certified under the EU–US Data Privacy Framework, Cloudflare relies on the corresponding adequacy decision. For other transfers requiring safeguards where no adequacy decision applies, its terms provide in particular for EU Standard Contractual Clauses. Details and safeguards are available in Cloudflare’s Data Processing Addendum and Cloudflare’s Privacy Policy ; you can also request a copy of the applicable safeguards from us.

4. Contact form, email and telephone

When you contact us, we process your contact details, message content and the information needed to handle your enquiry. Name, email address and message are required fields in the form. You may also provide a company name and select a topic. Email enquiries include sender information and technical message data; telephone contact may involve your phone number and notes of the conversation.

We use this information to answer your enquiry, clarify questions and, if you wish, discuss potential projects or services. The legal basis is Article 6(1)(b) GDPR where a contract with you or pre-contractual steps at your request are involved. In other cases, such as business contact persons, the basis is Article 6(1)(f) GDPR; our legitimate interest is handling business and other enquiries addressed to us.

Providing information is voluntary. However, we cannot meaningfully process your enquiry without the necessary contact details and content, and the form cannot be submitted without its required fields. Alternatively, you can contact us by email or telephone. Sending an enquiry does not subscribe you to a newsletter.

The form itself does not maintain a message archive in the WordPress database. It sends the enquiry to us by email. Further storage in our mailbox and, where relevant, project records is governed by the purpose of the enquiry and the criteria described under “Retention”.

5. Contact form email delivery via Brevo

We use Brevo for the technical delivery of contact form emails. The delivery service receives the data necessary for delivery: our recipient address, your email address as the reply-to address, the subject and the message content, including your form entries. Brevo also processes technical delivery data such as the sending time, delivery status and error messages. Our company is the recipient of the enquiry.

The service is used to ensure reliable delivery of form enquiries. Processing to handle your enquiry is based on the legal grounds described in section 4; our legitimate interest under Article 6(1)(f) GDPR also applies to technical delivery and troubleshooting. Brevo acts as a delivery service provider under a data processing arrangement.

Technical delivery logs are subject to the retention settings configured in the Brevo account. Without a deletion rule, Brevo does not delete these automatically. If email previews are enabled, copies of message content may also remain with the delivery service. Retention of the enquiry received in our email inbox is separate from this.

Brevo may use additional service providers to operate its services. Where data is transferred to countries outside the EU or EEA without an adequate level of protection, appropriate safeguards such as EU Standard Contractual Clauses are required. Information about the companies involved, recipients and safeguards is available in Brevo’s Privacy Policy and Brevo’s contractual and data processing terms. You can also contact us about the safeguards applicable to our processing.

6. Technical protection of the form

The form uses local checks to protect against automated and repeated enquiries. These include a hidden honeypot field, a security token and a submission frequency limit. The limit uses a check value derived from your email address with a secret key; the address itself is not stored in plain text for this purpose. Such a check value does not constitute full anonymisation.

The counter for repeated enquiries is valid for ten minutes. A random submission receipt prevents duplicate submissions and enables a success message for up to 24 hours. WordPress then treats these temporary entries as expired and removes them when accessed or during scheduled cleanup. They do not contain a copy of the message text.

The legal basis is Article 6(1)(f) GDPR; our legitimate interest is to protect our form and email infrastructure against misuse. The form does not use an external CAPTCHA service for these checks and does not itself set cookies.

7. Cookies, fonts and audience measurement

No audience measurement: We do not use analytics or advertising tracking services on this website. The theme does not set analytics or marketing cookies during an ordinary visit.

Technically necessary functions: WordPress may use cookies for login and administration by authorised users. During security checks, Cloudflare may use cookies or similar technologies to recognise a completed check or prevent automated access. Which technologies are used and how long they remain valid depend on the check triggered and the security features enabled. Provider information is available in the Cloudflare cookies overview.

Storage of information on your device or access to that information is governed by section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG). Processing without consent is only permitted where the statutory exception for transmitting a communication or for an essential function of the expressly requested service applies. For necessary security functions, the data protection basis for associated processing of personal data is Article 6(1)(f) GDPR.

Locally hosted fonts: The Inter and Space Grotesk fonts are delivered through this website. Loading these font files does not establish a connection to Google Fonts or transmit an IP address to Google for that purpose. The information on hosting and Cloudflare applies to their delivery.

8. Recipients and retention

Access is granted to people within our company who handle your enquiry or maintain the website. Technical providers for hosting, protection, email delivery and mailbox services receive data where necessary for their tasks. The described providers are engaged in accordance with the applicable data protection requirements. Data may also be disclosed to authorities or other bodies where legally required or where necessary to establish, exercise or defend legal claims.

Enquiries and related correspondence are deleted once the matter has been resolved and further storage for its purpose is no longer necessary. If an enquiry leads to a business relationship, data may be incorporated into contractual or project records. Statutory retention obligations, particularly for relevant business and tax records, remain applicable; the legal basis is Article 6(1)(c) GDPR. Necessary retention for legal claims is based on Article 6(1)(f) GDPR and ends when that purpose ceases to apply.

The periods or criteria described above apply to server logs, temporary form data and processing by Cloudflare and Brevo. Hosting in Germany does not mean that every service involved processes data exclusively in Germany.

9. Your rights

Subject to the statutory requirements, you may request access to your personal data (Article 15 GDPR), rectification of incorrect or completion of incomplete data (Article 16 GDPR), erasure (Article 17 GDPR) or restriction of processing (Article 18 GDPR).

For automated processing based on consent or a contract, you may receive the data you have provided in a structured, commonly used and machine-readable format and request its transmission where Article 20 GDPR applies.

Where processing is based on your consent, you may withdraw it at any time with future effect. This does not affect the lawfulness of processing before withdrawal. To exercise your rights, contact [email protected].

Right to object under Article 21 GDPR: Where we process data on the basis of Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

In connection with this website, we do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

10. Right to complain

You may lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence, place of work or the alleged infringement (Article 77 GDPR). The following authority is responsible for our company in Berlin:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Phone: +49 30 13889-0
Email: [email protected]
Website: www.datenschutz-berlin.de

Last updated: 9 October 2026

This notice covers our website and contact made through it. We update the information when functions, services or legal requirements change.