Privacy
Learn how Iridium Works GmbH collects, uses, and protects your personal data in accordance with the GDPR and applicable data protection laws.
Privacy Policy
As of: July 2026
pursuant to Art. 13 General Data Protection Regulation (GDPR)
This Privacy Policy provides information pursuant to Article 13 of the General Data Protection Regulation (GDPR) about the processing of personal data in connection with the use of the websites www.iridium-works.com and maschinenbauseiten.de (hereinafter collectively referred to as the “Websites”) by Iridium Works GmbH as the controller.
“Personal data” within the meaning of Art. 4 No. 1 GDPR means any information relating to an identified or identifiable natural person (data subject), such as name, address, telephone number, date of birth, email address or IP address. Information that cannot be attributed to a specific person, for example as a result of anonymisation, does not constitute personal data.
1. Controller
The controller responsible for the processing of personal data on the Website within the meaning of the General Data Protection Regulation (GDPR) is:
Iridium Works GmbH
Moselweißer Straße 4
56073 Koblenz
Germany
info@iridium-works.com
2. Data Processing on Our Website
2.1.1 Provision of the Website
Purpose of processing: We process your data in order to:
- ensure the reliable operation of the Website
- provide user-friendly access to our Website
- guarantee IT security
Legal basis: Art. 6(1)(f) GDPR. The processing of the aforementioned data is necessary to provide the Website and to ensure its secure and user-friendly operation.
Data processed:
- IP address of the requesting device
- Method (e.g. GET, POST), date and time of the request
- Address of the accessed website and path of the requested file
- Previously accessed/requested website/file, if applicable (HTTP referrer)
- Information about the browser and operating system used
- Version of the HTTP protocol, HTTP status code, size of the delivered file
- Request information such as language, content type, content encoding, character sets
Recipient: Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA (provision and operation of a web-based platform)
Storage period: The collected data is deleted as soon as it is no longer required for the operation of the Website, but no later than after 30 days, provided no statutory retention obligations exist.
Further information: https://webflow.com/legal/eu-privacy-policy
2.1.2 Hosting and contact forms on maschinenbauseiten.de (Onepage)
We use services provided by Onepage GmbH, Hanauer Landstraße 172, 60314 Frankfurt am Main, Germany, to provide and operate the website maschinenbauseiten.de and to process contact enquiries submitted through that website.
When the website is accessed, the following data in particular may be processed:
- IP address
- date and time of access
- page or file accessed
- referrer URL
- browser type and browser version
- operating system and device information
- technical request and log data
When the contact form is used, the information entered by the user is also processed. This may include, in particular, first and last name, email address, telephone number, company, website URL and information about products and the nature of the enquiry. The data is stored using the form and CRM functionality provided by Onepage and is used by us to process the enquiry.
Technical access data is processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and user-friendly provision of the website. Where an enquiry relates to steps taken prior to entering into a contract, the form data is processed on the basis of Article 6(1)(b) GDPR. In other cases, processing is based on Article 6(1)(f) GDPR and our legitimate interest in handling business enquiries. Where consent is expressly requested, Article 6(1)(a) GDPR is the applicable legal basis.
Technical log data is deleted or anonymised once it is no longer required to provide and secure the website. Data submitted through contact enquiries is generally stored until the enquiry has been fully processed. It is retained for longer only where statutory retention obligations apply or where the data is required to initiate or perform a contract.
2.2 Content Delivery Network
Purpose: Accelerating website loading times and protecting against DDoS attacks through the use of a Content Delivery Network (CDN).
Recipient: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Data processed:
- Accessed webpage
- Browser type used
- Operating system
- Referrer URL
- IP address
- Requesting provider
Legal basis: Legitimate interests pursuant to Art. 6(1)(f) GDPR (website security and performance).
Storage period: Data is generally transferred to a Cloudflare server in the USA and stored only for as long as necessary for the purpose stated above.
International data transfer: For the use of Cloudflare, data is transferred to the USA on the basis of the EU–U.S. Data Privacy Framework (Art. 45 GDPR). Cloudflare is certified under the Framework and thus provides an adequate level of data protection.
Further information: https://www.cloudflare.com/privacypolicy/
2.3 3D Content (Spline)
Purpose: Display of interactive 3D content on the Website to enhance the user experience. The 3D scenes are embedded via the Spline service and loaded from the provider's servers.
Recipient: Spline, Inc., USA
Data processed:
- IP address
- Accessed 3D scene (URL of the Spline resource)
- Browser type and version used
- Operating system
- Referrer URL
- Date and time of access
- Technical connection data (e.g. request headers) that are strictly necessary for the delivery of the 3D content
Legal basis: Legitimate interests pursuant to Art. 6(1)(f) GDPR (provision of interactive 3D content, ensuring performance and stability). Where access to the user's terminal device is not strictly necessary, the storage of or access to information is based on consent pursuant to Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
Storage period: Data is processed only for the duration necessary to deliver the 3D content and to ensure technical security.
International data transfer: Spline, Inc. is based in the USA. Data is transferred on the basis of the EU–U.S. Data Privacy Framework (Art. 45 GDPR), where certification exists, or on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
Further information: https://spline.design/privacy
2.4 Analytics and Tracking
Purpose: We use tracking and analytics tools to continuously optimise our Website and tailor it to your needs. For this purpose, information is collected using these technologies or device information is combined (device fingerprinting).
Legal basis: Technically necessary tools that are required for the operation of the Website are used on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR or for the performance of a contract or pre-contractual measures pursuant to Art. 6(1)(b) GDPR. The storage of or access to information on your device is in these cases strictly necessary pursuant to Section 25(2) TDDDG. Optional tools are used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Cookies are small text files stored by your browser on your device. Cookies do not execute programs and do not install malware. Comparable technologies include web storage (local/session storage), fingerprinting, tags and pixels. Most browsers accept these technologies by default; however, you can adjust your settings to block their use or require consent. Please note that blocking cookies or similar technologies may restrict certain functions of the Website.
Google Tag Manager
On maschinenbauseiten.de, we use Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to technically manage and control the activation of website tags. In particular, we use it to manage the Meta Pixel.
According to the provider, Google Tag Manager itself does not set cookies. However, when the Tag Manager container is loaded, technical data such as the IP address, browser and device information, the URL accessed, the referrer URL, and the date and time of access may be transmitted to Google.
Non-essential analytics and marketing tags are activated through Google Tag Manager only after the user has consented to the relevant category through the cookie banner. The Meta Pixel is not loaded without such consent.
Google Tag Manager is used on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the secure, efficient and consent-based management of technologies used on the website. Subsequent analytics and marketing services are activated exclusively on the basis of consent pursuant to Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
When Google Tag Manager is used, processing by Google LLC in the United States cannot be ruled out. Where required, such transfers are based on the EU-US Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission.
Further information: https://policies.google.com/privacy
Meta Pixel
On maschinenbauseiten.de, we use the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, after obtaining your consent. The Meta Pixel helps us attribute visits and conversions to our Facebook and Instagram advertisements, measure their effectiveness and optimise ad delivery.
The data processed may include URLs accessed, the referrer URL, time of access, browser and device information, IP address and events such as page views or completed enquiries. The content entered into form fields is not transmitted to Meta by our current Pixel configuration. Meta also uses the marketing cookies _fbp and, when a visitor arrives through a Meta advertisement, _fbc. Each cookie may be stored for up to 90 days.
The Meta Pixel is loaded only after consent to the “Marketing” category has been given. The legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Consent may be withdrawn at any time with future effect using the cookie icon.
Meta may associate the transmitted information with existing Facebook or Instagram accounts and process it in accordance with its own privacy policy. Processing by Meta Platforms, Inc. in the United States cannot be ruled out. Where applicable, transfers are based on the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.
Further information: https://www.facebook.com/privacy/policy/
Cookie Overview
[Cookie table / overview inserted here in the CMS – no body text was present in the source.]
3. Contact by Email
Purpose: Processing and responding to your enquiry.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in communicating with you). If your enquiry is aimed at concluding or performing a contract, processing is carried out on the basis of Art. 6(1)(b) GDPR.
Data processed:
- Name
- Email address
- Content of your message
Storage period: Your data is stored only for as long as necessary to fully process your enquiry.
4. External Links
Our Website contains links to external third-party websites (e.g. Google, LinkedIn, etc.) over whose content we have no influence. We therefore cannot accept any liability for these external contents.
The respective provider or operator is always responsible for the content of the linked pages. The linked pages were checked for possible legal violations at the time of linking. No illegal content was apparent at the time of linking.
However, permanent content monitoring of the linked pages is not reasonable without concrete indications of a legal violation. If we become aware of legal violations, we will remove such links immediately.
If you follow an external link, please note that the privacy policy of the respective provider applies and that we have no influence over how these providers process your personal data. We recommend reviewing the privacy policies of the respective third-party websites before using them.
5. International Data Transfers
Personal data is generally processed within the EU/EEA. Transfers to so-called “third countries” take place only in compliance with the requirements of the GDPR and in the presence of appropriate safeguards. Before transferring data to a service provider in a third country, the level of data protection is assessed. A transfer only takes place if sufficient protective mechanisms exist. All service providers must enter into a data processing agreement. Additional measures are required for providers outside the EEA. Pursuant to Art. 44 et seq. GDPR, a transfer is only permissible if at least one of the following conditions is met:
- The European Commission has determined that an adequate level of data protection exists.
- Standard contractual clauses have been concluded with the recipient.
- Other appropriate safeguards pursuant to Art. 46 GDPR are in place.
- In certain exceptional cases pursuant to Art. 49 GDPR.
6. Recipients
Personal data collected by us is only disclosed if:
- You have given us your explicit consent pursuant to Art. 6(1)(a) GDPR;
- Disclosure is lawful and necessary for the performance of a contract with you or to carry out pre-contractual measures at your request (Art. 6(1)(b) GDPR).
- We are legally obliged to disclose the data (Art. 6(1)(c) GDPR); or
- Disclosure is necessary to protect our legitimate interests or to assert, exercise or defend legal claims, and there is no reason to assume that your interests or fundamental rights and freedoms requiring the protection of personal data override these interests (Art. 6(1)(f) GDPR);
Possible recipients include:
- Processors: Group companies or external service providers (e.g. for technical infrastructure and processing, maintenance, payment processing), who are carefully selected and monitored. Processors may only process data in accordance with our instructions.
- Public authorities: Authorities and public bodies (e.g. tax authorities, public prosecutors, courts) to whom we must transmit personal data, e.g. to fulfil legal obligations or to protect legitimate interests.
7. Data Security and Protective Measures
We implement appropriate technical and organisational measures to ensure the security and confidentiality of your personal data. These measures serve to protect against unauthorised access, manipulation, loss or misuse. Our security measures are regularly reviewed and adapted to technological advances and current industry standards.
Please note that despite extensive protective measures, data transmission over the internet may have security vulnerabilities. In particular, with unencrypted communication (e.g. standard email), there is a risk that data may be accessed by third parties. We have no influence over the actions of external third parties. We therefore recommend using encryption or other protective measures when transmitting sensitive information electronically in order to minimise potential risks.
8. Retention and Deletion/Blocking of Data
Personal data is deleted or blocked as soon as the purpose of storage ceases to apply. Further storage takes place only if provided for by regulations of the European Union or national legislation to which the controller is subject. Data is also deleted or blocked when a statutory retention period expires, unless further storage is necessary for the fulfilment of a contractual relationship.
9. Data Subject Rights
You have the following rights with regard to your personal data:
a. Right of access (Art. 15 GDPR, § 34 BDSG): You may request information about whether and which personal data we process, for what purpose, to whom or to which categories of recipients the data is disclosed, and how long it is stored.
b. Right to rectification (Art. 16 GDPR): You may request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.
c. Right to erasure (Art. 17 GDPR): You may request the deletion of your personal data, in particular where it is no longer necessary, you have withdrawn your consent, or the data has been processed unlawfully.
d. Right to restriction of processing (Art. 18 GDPR): You may request the restriction of the processing of your data, e.g. where the accuracy of the data is contested.
e. Right to data portability (Art. 20 GDPR): You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request its transfer to another controller, to the extent that this is technically feasible.
f. Right to withdraw consent (Art. 7(3) GDPR): You may withdraw any consent you have given at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal remains unaffected.
Right to object (Art. 21 GDPR): You may object at any time, on grounds relating to your particular situation, to the processing of your personal data, in particular in connection with direct marketing or related profiling.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection regulations.
For data protection enquiries or to exercise your rights as a data subject, please contact: info@iridium-works.com













