Privacy Policy
Last updated: 17 September 2026
This website is a set of static files. It sets no cookies, runs no tracking and no analytics, and embeds nothing from third-party servers — the fonts are served from this domain, not from Google. Opening a page sends no request to anyone but our own server.
Who Is Responsible
Stimulink, Harald Müller, 82205 Gilching, Germany. The full postal address is in our imprint.
You can reach us through our enquiry form or at the email address given in the imprint.
We are not required to appoint a data protection officer and have not appointed one.
What the Server Records
Our hosting provider, netcup GmbH, Karlsruhe, Germany, records the usual access data with each request: IP address, date and time, the file requested, the referring page, the HTTP status and the browser identification. We need this to deliver the site and to find technical faults.
Legal basis: our legitimate interest in a functioning and secure website, Article 6(1)(f) GDPR. Records are kept for [to confirm] days and then deleted. They are not combined with other data and are not used to identify visitors.
The provider processes them on our behalf under an agreement meeting Article 28 GDPR. The servers are located in Germany. No data is transferred outside the European Union.
The Enquiry Form
If you use the form on our contact page, we process what you enter — your name, company, email address, phone number, country, the topic you choose and your message — in order to answer your enquiry. Name, email address, topic and message are needed for us to reply; the other fields are optional.
Legal basis: Article 6(1)(b) GDPR where your message concerns a possible engagement, and Article 6(1)(a) GDPR — your consent, given by ticking the box — for the processing of the message itself. You can withdraw that consent at any time; the withdrawal does not affect processing already carried out.
The form is delivered by email through netcup GmbH, our mail provider, which acts as a processor on our behalf under an agreement meeting Article 28 GDPR. The mailbox is hosted in Germany.
We keep enquiry correspondence for up to twelve months if nothing comes of it. Where an engagement follows, we keep it for the term of the engagement plus the statutory retention periods under German commercial and tax law, which can be up to ten years.
The form contains two technical checks against automated submissions: a field that is hidden from visitors and a timestamp recording when the page was opened. Neither is used to identify you.
If You Write to Us Directly
We process your address and the content of your message in order to answer it — on the basis of Article 6(1)(b) GDPR where it concerns a possible engagement, and Article 6(1)(f) GDPR otherwise. Retention is as described for the enquiry form.
Ordinary email is not encrypted end to end. If you want to send us something sensitive, ask us first and we will agree a different channel.
If You Apply to Us
We process your name, contact details, CV and our correspondence for the purpose of considering you for a position, on the basis of your consent, Article 6(1)(a) GDPR. We keep them for up to twelve months and then delete them.
We pass them to no one. If a role arises with our Indonesian partner company and we would need to pass your application on, we ask you first and only send it on if you agree — that would be a transfer outside the European Union, and we would explain the safeguards before you decide.
You can withdraw your consent and ask for deletion at any time. Please see our careers page for what not to send us at this stage.
Personal Data in Our Client Engagements
When we audit or test software for a client, any personal data in their systems is processed on that client's instructions and on their legal basis. In those engagements we act as a processor under Article 28 GDPR, under a written agreement with the client, and we do not use that data for any purpose of our own.
This policy does not govern that processing — the client's own policy does. Our default is to work on synthetic or pseudonymised data rather than production data, and where a scope requires production data we agree that with the client in writing beforehand.
Your Rights
You can ask us what data we hold about you (Article 15 GDPR), have it corrected (Article 16), have it erased (Article 17), have its processing restricted (Article 18), receive it in a portable form (Article 20), and withdraw consent you have given (Article 7(3)). Write to us and we will answer within one month.
Right to object: where we process your data on the basis of our legitimate interest, you may object at any time under Article 21 GDPR. A short message is enough — we then stop unless we can show compelling grounds that override your interests.
Complaints
You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany). You may also approach the authority where you live or work.
