Privacy policy
This English version is provided for convenience. The German version is legally binding.
1. Controller and contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Mitac GmbH
Wendenstraße 130
20537 Hamburg
Germany
Email: info@mitac-gmbh.de
Authorised representatives: Ernst Florian Eckhoff (managing director), Ernst-Dieter Eckhoff (deputy managing director). Further details can be found in our imprint.
We have not appointed a data protection officer, as the legal requirements for doing so (Art. 37 GDPR, § 38 BDSG) are not met. For all questions regarding data protection and to exercise your rights, please use the contact details above.
2. The essentials first: no cookies, no tracking
- This website sets no cookies and uses no comparable technologies (such as local storage) for analytics or marketing purposes.
- There is no reach measurement and no analysis of your usage behaviour. No usage profiles are created.
- No third-party services are embedded — no content delivery networks, no map, video or social media embeds, no advertising networks.
- All fonts are stored on our own server (self-hosted). In particular, no Google Fonts are loaded from Google servers; visiting this site creates no connections to third-party servers.
For this reason, this website requires neither a consent banner nor a cookie notice. Should we use consent-requiring services in future, we will obtain your consent in advance (Art. 6(1)(a) GDPR, § 25(1) TDDDG) and update this privacy policy.
3. Provision of the website and server log files
This website is provided on a server operated by us in a data centre in Germany. Each time the site is accessed, information transmitted by your browser is automatically recorded, which is technically necessary to display the page to you:
- IP address of the requesting device
- date and time of access
- name and URL of the file retrieved
- volume of data transferred and notification of successful retrieval
- browser and operating system used
- previously visited page (referrer), where transmitted
Purpose: establishing the connection, system security and stability, error analysis, and the prevention and investigation of attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the technically error-free and secure provision of the website.
Storage period: the log files are deleted automatically after seven days. This data is not merged with other data sources and is not evaluated for marketing purposes.
4. Contact by email
If you write to us by email — for example for a demo request to demo@every-edi.de — we process the data you transmit: your name, your email address and the content of the message including any attachments. Processing takes place exclusively in order to handle your enquiry.
Legal basis: Art. 6(1)(b) GDPR insofar as your enquiry is aimed at concluding or performing a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Storage period: we delete your enquiry once it has been conclusively dealt with and no statutory retention obligations prevent deletion. Retention periods under commercial and tax law (§ 257 HGB, § 147 AO) remain unaffected.
Sample orders for the demo
For a demonstration of every-edi, we ask you to send us sample orders. We use these documents exclusively to create your personal demo. They are not used for any other purpose, not passed on to third parties, and deleted at your request — at the latest once the demo process is complete.
Our recommendation: for the first test, send redacted or non-critical documents. For the quality of the demo it is sufficient that the structure and line-item data of the order are recognisable — prices or personal details can be blacked out.
5. Contact form
You can reach us without obligation via the contact form on this website. The data you enter is processed: name, company, email address, phone number where provided, and your message. Mandatory fields are marked as such.
Purpose: exclusively handling your enquiry and sending you a confirmation of receipt.
Legal basis: Art. 6(1)(b) GDPR (initiation of a contractual relationship); otherwise Art. 6(1)(f) GDPR.
Process and storage period: transmission is encrypted to our server in Germany. From there your enquiry is delivered as an email to our inbox; it is not stored in a database. The data remains in our email inbox and is deleted once the enquiry has been conclusively dealt with and no statutory retention obligations prevent deletion.
Protection against automated submissions: to prevent spam, our server checks technical characteristics of the submission — a field invisible to humans and the time between page load and submission — and limits the number of requests per connection. Your IP address is processed only briefly in memory for this purpose and is not stored permanently. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing misuse). No cookies are set and no profiles are created.
The form deliberately provides no file upload. Please send us sample orders in reply to our confirmation email.
6. Recipients of the data
As a matter of principle, we do not pass your personal data on to third parties. Disclosure only takes place if you have consented, if it is necessary for the performance of a contract, or if we are legally obliged to do so.
For technical operations we use carefully selected service providers who act for us as processors pursuant to Art. 28 GDPR, strictly on our instructions, and with whom we have concluded corresponding agreements:
| Service provider | Service | Location |
|---|---|---|
| netcup GmbH, Karlsruhe | Server infrastructure for the website and contact form | Germany |
| netcup GmbH, Karlsruhe | Sending and receiving our emails | Germany |
7. No transfer to third countries
Your data is processed exclusively on servers within the Federal Republic of Germany. No personal data is transferred to countries outside the European Union or the European Economic Area.
8. Voluntary provision and no automated decision-making
Providing your personal data is neither legally nor contractually required; you are under no obligation to provide it. Without the details marked as mandatory in the contact form, however, we cannot process your enquiry. You will suffer no disadvantage as a result.
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.
9. Data security
This website is delivered exclusively over an encrypted connection (TLS/HTTPS); you can recognise this by the padlock symbol in your browser's address bar. This protects the data transmitted between your browser and our server — in particular your entries in the contact form — against being read by third parties.
In addition, we take appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. We review our measures on an ongoing basis in line with technological developments.
Please note: the unencrypted transmission of emails over the internet can have security vulnerabilities. Complete protection against access by third parties is not possible in this case.
10. Your rights as a data subject
You have the following rights vis-à-vis us regarding the personal data concerning you:
- Access (Art. 15 GDPR) — whether and which data we process about you
- Rectification (Art. 16 GDPR) — of inaccurate or incomplete data
- Erasure (Art. 17 GDPR) — insofar as no statutory retention obligations prevent it
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) — receipt of the data you provided in a structured, commonly used and machine-readable format
- Objection (Art. 21 GDPR) — see the separate section 11
- Withdrawal of consent (Art. 7(3) GDPR) — at any time with effect for the future; the lawfulness of processing carried out up to that point remains unaffected
To exercise your rights, an informal message to info@mitac-gmbh.de is sufficient. Exercising these rights is free of charge for you.
11. Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest).
If you object, we will no longer process your personal data — unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
The objection is not subject to any particular form and can be addressed to the contact details given in section 1.
12. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR) — in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement.
The supervisory authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22, 20459 Hamburg
https://datenschutz-hamburg.de/
13. Changes to this privacy policy
We adapt this privacy policy as soon as changes to our processing activities or to the legal framework make this necessary — for example if we use analytics or marketing services in future. The version published on this page applies in each case.
Last updated: July 2026