Privacy Policy
1. General Information
We do not use cookies, tracking pixels, or automated profiling mechanisms. We do not engage in any tracking or analytics.
2. Controller
The Controller responsible for the processing of personal data on this website pursuant to Article 4(7) GDPR is:
- Company Name: Critical Section GmbH
- Representatives: Felix Gilcher, Florian Gilcher (Managing Directors)
- Address: Wallstr. 58/59, D-10179 Berlin
- Email: info@ferrocene.dev
- Phone: +49 (0)30 629396185
3. Categories of Personal Data, Purposes, and Legal Bases for Processing
A. Server Log Files (Website Provision)
When you visit our website, your browser automatically transmits data to our hosting provider. This processing is technically necessary to display our website and ensure system security. This is exclusively information that does not allow any conclusions to be drawn about your person. The processed data includes IP address, Browser type and version, your used Operating system, the domain name of your ISP, Date and time of the server request, and similar information.
Legal Basis: Article 6(1)(f) GDPR (Legitimate Interests). Our legitimate interest lies in the secure, stable, and functional operation of our website. We may evaluate information of this kind statistically in order to optimize our website and the underlying technology.
Storage Duration: The data will be deleted as soon as it is no longer required for the purpose of its collection. In the case of data used to provide the website, this generally occurs once the respective session has ended, unless further retention is legally required for evidentiary purposes.
B. User Registration Portal (Service Provision)
If you register an account through our user portal to purchase and maintain/administer our services, we process the personal data you provide during the registration and checkout process (e.g., name, email address, billing address, account credentials, and selected service tiers). This data is processed exclusively to manage your user account and to provide, deliver, and bill the purchased services.
Legal Basis: Article 6(1)(b) GDPR. The processing is strictly necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Storage Duration: We store your registration and account data for the entire duration of your active contractual relationship or user account. Following the deletion of your account or termination of the contract, your data will be erased within 180 days, unless statutory commercial or tax retention periods (which can require storage for up to 10 years under local law for invoices and accounting data) require a longer retention period.
C. Contacting Us
When you contact us via email or a contact form, we process the information provided (e.g., name, email address, message content) solely to handle and respond to your inquiry.
Legal Basis: Article 6(1)(b) GDPR (if the contact relates to an existing or prospective contract) or Article 6(1)(f) GDPR (Legitimate Interests in processing your request).
Storage Duration: Data will be deleted 6 months after processing the request, except for potential business opportunities which we may consider to arise after that period. If a contractual relationship occurs, we are subject to the statutory retention periods according to the German Commercial Code (HGB) and delete your data after these deadlines. The provision of your personal data is voluntary. However, we can only process your request if you provide us with your name, email address and the reason for the request.
SSL encryption:
In order to protect the security of your data during transmission, we use state-of-the-art encryption methods (e.g. SSL) over HTTPS.
4. Data Recipients and Third-Party Transfers
Recipients of the data may be Processors engaged by us. We do not sell, rent, or disclose your personal data to third parties for marketing purposes. Your data is only disclosed to third parties if:
- You have given explicit consent pursuant to Article 6(1)(a) GDPR.
- It is necessary for the performance of a contract pursuant to Article 6(1)(b) GDPR (e.g., sharing billing details with a payment service provider).
- We are subject to a legal obligation pursuant to Article 6(1)(c) GDPR.
The following organisations, companies or Persons have been commissioned by the operator of this website to process data:
We employ a professional web hosting provider as a data processor pursuant to Article 28 GDPR. This processor handles data strictly in accordance with our documented instructions and inside the European Economic Area (EEA).
We co-operate with a payment provider, given that you purchase our services and products directly over our website.
5. Data Security
We implement appropriate technical and organizational measures (TOMs) pursuant to Article 32 GDPR to ensure a level of security appropriate to the risk, protecting your data against unauthorized access, alteration, or disclosure, e.g. SSL over HTTPS.
6. Rights of the Data Subject
Pursuant to Chapter 3 of the GDPR, you hold the following rights as a data subject:
- Right of Access (Article 15 GDPR): The right to obtain confirmation as to whether or not your personal data is being processed, and access to that data.
- Right to Rectification (Article 16 GDPR): The right to obtain the rectification of inaccurate personal data.
- Right to Erasure / "Right to be Forgotten" (Article 17 GDPR): The right to obtain the erasure of your personal data under certain conditions.
- Right to Restriction of Processing (Article 18 GDPR): The right to restrict data processing under specific legal prerequisites.
- Right to Data Portability (Article 20 GDPR): The right to receive your data in a structured, commonly used, and machine-readable format.
- Right to Object (Article 21 GDPR): The right to object, on grounds relating to your particular situation, at any time to processing based on Article 6(1)(f) GDPR.
You can contact a supervisory authority at any time with a complaint, e.g. to the competent supervisory authority of the federal state of your place of residence or to the authority responsible for us as the responsible authority.
A list of supervisory authorities (for the non-public area) with addresses can be found at: https://www.bfdi.bund.de/DE/Infothek/Anschriften-Links/anadded-links-node.html.
7. Changes to our privacy policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply to your visit again. If you have any questions about data protection, please send us an e-mail or contact the person responsible for data protection in our organization directly: