Privacy Policy

1. General Information

This Privacy Policy provides information on the processing of personal data in connection with the use of this website.

Personal data means any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).

2. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

CMBlu Energy AG
Industriestrasse 19
63755 Alzenau
Germany

Represented by:
Constantin Eis (CEO)
Dr. Nastaran Krawczyk (CTO)

Chairman of the Supervisory Board:
Peter Koob

Phone: +49 6023 7062
Email: mail@cmblu.com

3. Data Protection Officer

The controller has appointed a Data Protection Officer:

Collegium Auditores GmbH
Am Apfelbäumchen 4
53757 St. Augustin
Germany

Email: datenschutz@cmblu.de

4. General Information on Data Processing

Legal Basis

Personal data is processed on the basis of the following legal grounds:

  • Art. 6(1)(a) GDPR (consent)
  • Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures)
  • Art. 6(1)(c) GDPR (compliance with a legal obligation)
  • Art. 6(1)(f) GDPR (legitimate interests)

Data Transfers to Third Countries

Where personal data is transferred to recipients outside the European Economic Area (EEA), such transfers are carried out only if an adequate level of data protection is ensured in accordance with Art. 44 et seq. GDPR.

This may be the case in particular where:

  • an adequacy decision pursuant to Art. 45 GDPR exists,
  • appropriate safeguards pursuant to Art. 46 GDPR are implemented (e.g. Standard Contractual Clauses), or
  • the recipient participates in the EU-U.S. Data Privacy Framework (DPF).

Further information on specific transfers is provided in the respective sections below.

Intra-Company Data Sharing

Personal data may be disclosed to subsidiaries and affiliated companies of CMBlu Energy AG where this is necessary for internal administrative purposes, the performance of contractual or pre-contractual measures, or efficient communication within the organization.

Such processing is carried out on the basis of Art. 6(1)(f) GDPR and, where applicable, Art. 6(1)(b) GDPR.

Where personal data is transferred to subsidiaries or affiliated companies located outside the EEA, appropriate safeguards are implemented, in particular Standard Contractual Clauses pursuant to Art. 46 GDPR or participation in the EU-U.S. Data Privacy Framework.

Storage Period

Unless a more specific storage period is stated in this Privacy Policy, personal data will be retained only for as long as necessary to achieve the purpose of processing or to comply with statutory retention obligations.

5. Hosting

This website is hosted by:

Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, CA 94103
USA

In connection with the hosting and delivery of the website, personal data such as IP address, browser type, operating system, referrer URL, and time of access may be processed and stored in server log files.

The use of Webflow is based on Art. 6(1)(f) GDPR. The controller has a legitimate interest in the secure, reliable, and efficient provision of its website.

Where processing requires consent, it is carried out on the basis of Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.

Personal data may be transferred to the United States. A data processing agreement pursuant to Art. 28 GDPR has been concluded.

Further information is available at:
https://webflow.com/legal/privacy

6. Cookies and Consent Management

Cookies

This website uses cookies and similar technologies.

Cookies that are technically necessary for the operation of the website are processed on the basis of Art. 6(1)(f) GDPR.

All other cookies and comparable technologies are used exclusively on the basis of consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.

Consent may be withdrawn at any time with effect for the future.

Consent Management (Usercentrics)

This website uses a consent management platform provided by:

Usercentrics GmbH
Rosental 4
80331 Munich
Germany

Usercentrics enables the collection, management, and documentation of user consents.

In this context, personal data such as IP address, consent status, browser information, and timestamps may be processed.

The processing serves the purpose of complying with legal obligations to obtain and document user consent for certain data processing operations.

The use of Usercentrics is based on Art. 6(1)(c) GDPR.

Further information is available at:
https://usercentrics.com/privacy-policy

7. Contact and Communication

If you contact the controller (e.g. via contact form, email, or telephone), the personal data provided will be processed for the purpose of handling the request.

Depending on the nature of the request, processing is carried out:

  • pursuant to Art. 6(1)(b) GDPR, or
  • pursuant to Art. 6(1)(f) GDPR

The data will not be disclosed to third parties unless necessary for processing the request or required by law.

8. Customer Relationship Management (HubSpot)

The controller uses:

HubSpot, Inc.
2 Canal Park
Cambridge, MA 02141
USA

HubSpot is used to manage contacts, process inquiries, and support communication and marketing activities.

In this context, personal data such as contact details, communication content, and usage data may be processed. HubSpot may also track interactions with emails or website content where corresponding functionalities are enabled.

Processing is carried out:

  • pursuant to Art. 6(1)(f) GDPR, and
  • where applicable, pursuant to Art. 6(1)(a) GDPR

Personal data may be transferred to the United States. HubSpot participates in the EU-U.S. Data Privacy Framework.

A data processing agreement pursuant to Art. 28 GDPR has been concluded.

Further information is available at:
https://legal.hubspot.com/privacy-policy

9. Analytics and Tracking

Google Tag Manager

This website uses Google Tag Manager, provided by:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland

Google Tag Manager is used to manage and deploy scripts and services on this website. The tool itself does not create user profiles, does not store cookies, and does not carry out independent analyses. It merely facilitates the integration and management of other services.

However, when using Google Tag Manager, your IP address may be transmitted to Google, as the tool is technically loaded from Google servers.

Processing is carried out:

  • pursuant to Art. 6(1)(f) GDPR, or
  • where required, pursuant to Art. 6(1)(a) GDPR

Google Analytics

This website uses Google Analytics, provided by:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland

Google Analytics enables the analysis of user behavior on the website. In this context, data such as pages visited, duration of visits, interactions, and technical information about the device used may be processed.

Google Analytics uses technologies such as cookies or similar recognition mechanisms to analyze user behavior. The information generated is used to evaluate the use of the website, compile reports on website activity, and improve the website.

IP anonymization is enabled.

Processing is based on consent pursuant to Art. 6(1)(a) GDPR.

Personal data may be transferred to the United States. Google participates in the EU-U.S. Data Privacy Framework.

Further information is available at:
https://policies.google.com/privacy

10. Embedded Services and Third-Party Content

YouTube

This website embeds videos from the platform YouTube. The provider is:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland

When you access a page on which a YouTube video is embedded, a connection to YouTube servers may be established. In doing so, personal data such as your IP address and technical information about your device and browser may be transmitted.

If you are logged into your YouTube account, YouTube may be able to associate your browsing behavior directly with your personal profile.

Processing is carried out pursuant to Art. 6(1)(f) GDPR or, where required, Art. 6(1)(a) GDPR.

Personal data may be transferred to the United States. Google participates in the EU-U.S. Data Privacy Framework.

Further information is available at:

https://policies.google.com/privacy

Vimeo

This website uses video content provided by:

Vimeo Inc.
555 West 18th Street
New York, NY 10011
USA

When you access a page containing a Vimeo video, a connection to Vimeo’s servers is established. In this context, personal data such as your IP address, browser information, and device data may be transmitted.

If you are logged into your Vimeo account, Vimeo may be able to associate your browsing behavior with your personal profile.

Processing is carried out pursuant to Art. 6(1)(f) GDPR or, where required, Art. 6(1)(a) GDPR.

Personal data may be transferred to the United States. Vimeo participates in the EU-U.S. Data Privacy Framework.

Further information is available at:

https://vimeo.com/privacy

Dropbox

This website integrates content provided by:

Dropbox, Inc.
1800 Owens Street
San Francisco, CA 94158
USA

When you access content hosted via Dropbox (e.g. downloads or embedded files), a connection to Dropbox servers is established. In this process, personal data such as your IP address and technical information about your device may be transmitted.

Processing is carried out pursuant to Art. 6(1)(f) GDPR or, where applicable, Art. 6(1)(a) GDPR.

Further information is available at:

https://www.dropbox.com/privacy

Finsweet

This website uses services provided by:

Finsweet, Inc., USA

Finsweet is a provider of web development and enhancement services for Webflow-based websites. These services are used to enhance website functionality, including dynamic content filtering, CMS extensions, and interactive features.

In the course of using these services, technical data such as IP address, browser type, device information, and interaction data may be processed.

Processing is carried out pursuant to Art. 6(1)(f) GDPR or, where applicable, Art. 6(1)(a) GDPR.

11. Newsletter

If you subscribe to the newsletter, your email address and any additional information you provide will be processed for the purpose of sending the newsletter.

The newsletter is sent using:

Inxmail GmbH
Wentzingerstraße 17
79106 Freiburg
Germany

In connection with the sending of newsletters, personal data may also be used to analyze opening rates and click behavior.

Processing is carried out exclusively on the basis of consent pursuant to Art. 6(1)(a) GDPR.

Consent may be withdrawn at any time with effect for the future.

A data processing agreement pursuant to Art. 28 GDPR has been concluded.

Further information is available at:
https://www.inxmail.de/datenschutz

12. Job Applications

Applicant Data

Personal data submitted as part of an application process will be processed for the purpose of deciding on the establishment of an employment relationship.

Processing is carried out on the basis of:

  • § 26 BDSG
  • Art. 6(1)(b) GDPR
  • Art. 6(1)(a) GDPR

Personal data will generally be stored for a period of up to six months after completion of the application process.

Greenhouse Recruiting

The controller uses:

Greenhouse Software, Inc.
18 West 18th Street, 11th Floor
New York, NY 10011
USA

Greenhouse processes personal data as a processor pursuant to Art. 28 GDPR.

Personal data may be transferred to the United States. Greenhouse participates in the EU-U.S. Data Privacy Framework.

A data processing agreement has been concluded.

Further information is available at:
https://www.greenhouse.com/privacy-policy

13. Online Meetings

For communication purposes, the controller uses:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland

In this context, personal data such as contact details, communication content, and technical metadata may be processed.

Processing is carried out pursuant to:

  • Art. 6(1)(b) GDPR
  • Art. 6(1)(f) GDPR

Further information is available at:
https://privacy.microsoft.com

14. Rights of Data Subjects

Data subjects have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

In addition, data subjects have the right to lodge a complaint with a supervisory authority.