innosity
  • Back to website

Privacy Policy

This Privacy Policy explains which personal data we process when you visit this website or contact us, for which purposes and on which legal basis, and the rights available to you.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR), the national data protection laws of the EU Member States and other applicable data protection provisions is:

innosity GmbH
Leutragraben 1
07743 Jena
Germany

Represented by: Thomas Viebranz
Phone: +49 3641 3276620
Email: info@innosity.de

Commercial Register: HRB 516992, Amtsgericht Jena

2. General information on data processing

We process personal data only to the extent necessary to provide a functional website, handle enquiries or protect legitimate interests. Where processing is necessary to take steps prior to entering into a contract or to perform a contract, it is based on Article 6(1)(b) GDPR. Other processing described below is generally based on Article 6(1)(f) GDPR. The information provided when data is collected is governed by Article 13 GDPR.

3. Hosting and technical provision of the website

This website is provided through Azure Static Web Apps. Azure Static Web Apps is a hosting service for static websites with integrated serverless APIs; the contact API is implemented using Azure Functions.

In connection with the technical provision of the website, the following technically necessary data may be processed in particular:

  • IP address
  • Date and time of access
  • Requested file or URL
  • Referrer URL
  • Browser type and version
  • Operating system
  • Hostname of the accessing system

This processing is carried out to ensure stability, security, content delivery and error analysis on the basis of Article 6(1)(f) GDPR.

Where Microsoft processes personal data on our behalf in connection with Azure and Microsoft 365 services, this is governed by Microsoft's contractual data protection terms, in particular the Microsoft Products and Services Data Protection Addendum (DPA).

4. Contact form

If you contact us through the contact form, we process the data you enter in order to handle your enquiry. This includes in particular:

  • Name
  • Company
  • Email address
  • Message

The legal basis is Article 6(1)(b) GDPR where your enquiry relates to entering into or preparing a contract; otherwise, it is Article 6(1)(f) GDPR based on our legitimate interest in efficiently handling business enquiries.

The form data is not stored in a separate website database. It is processed through Azure Functions within the Microsoft Azure platform, dispatched through Azure Communication Services and delivered internally to a business email account of innosity GmbH. The person making the enquiry also receives an automatic acknowledgement email. The data is subsequently processed and stored in our business email system for the purpose of handling the enquiry.

Technical dispatch and error records may contain a request ID, message ID, dispatch or delivery status and technical error information. The full message text is not written to application or Function logs.

To protect the contact API against automated misuse, we use a hidden honeypot field, a plausibility check of the submission time and a persistent rate limit. For the rate limit, the source network address is used only in memory to create a daily rotating pseudonymous hash. The raw address is not stored in the rate-limit store. Counter records are automatically deleted after no more than 24 hours. These security measures are based on Article 6(1)(f) GDPR and our legitimate interest in protecting the website, the email service and associated costs.

5. Contact by email or telephone

If you contact us by email or telephone, we process the personal data you provide solely to handle your enquiry and for any necessary follow-up communication. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual enquiries and otherwise Article 6(1)(f) GDPR.

6. Cookies, tracking and access to terminal equipment

We currently do not use cookies for analytics, marketing or tracking purposes and do not use any non-essential technologies to store information on your device or access information stored on it. If such technologies are introduced in the future, we will first implement the legally required choice mechanism and update this Privacy Policy.

7. Fonts

The fonts used on this website are hosted locally. Loading the website does not establish a connection to external font services, and no personal data is transferred to external font providers for this purpose.

8. Recipients and processors

Where necessary for the purposes described above, personal data may be disclosed to the following categories of recipients:

  • Microsoft Azure hosting and infrastructure services, including Azure Static Web Apps, Azure Functions, Azure Communication Services and Azure Storage
  • Microsoft 365 and Exchange Online as the business email system
  • Internal personnel responsible for handling enquiries

Where external service providers process personal data on our behalf, they do so only under an appropriate data processing agreement or the applicable contractual terms. For Microsoft services, the Microsoft DPA sets out the relevant data protection and security conditions.

We do not sell personal data or disclose it for advertising purposes.

9. Retention period

Form data is not retained in a separate website database. Enquiries and related correspondence stored in the business email system are deleted when the purpose of processing no longer applies, unless statutory or contractual retention obligations require continued storage. Technical dispatch and error records are retained only for the period necessary for delivery monitoring, security and error analysis. Pseudonymous rate-limit counters are deleted automatically after no more than 24 hours.

10. Your rights

Subject to the conditions of the GDPR, you have in particular the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on Article 6(1)(f) GDPR
  • Right to lodge a complaint with a data protection supervisory authority

11. No obligation to provide data

You are not legally required to provide us with personal data. Without certain information, particularly the required details in a contact enquiry, we may be unable to process your enquiry or may only be able to process it in part.

12. Last updated

July 2026

© innosity GmbH 2026, all rights reserved.   Imprint  |  Privacy Policy