Integritetspolicy

Last updated: 22 September 2026

This Privacy Policy explains how CloudLab Web to Print Solutions GmbH processes personal data when you visit our corporate website or contact us using the contact details and forms provided on it. Personal data means any information relating to an identified or identifiable individual.

The legal framework for this policy is the European Union's General Data Protection Regulation (GDPR) and applicable German data protection legislation, including the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

1. Controller

The controller responsible for the processing described in this Privacy Policy is:

CloudLab Web to Print Solutions GmbH
Gerberstr. 1
44135 Dortmund
Germany

Email: info@cloudlab-solutions.com
Telephone: +49 231 6000 17-17

Represented by: Marc Horriar.

This policy covers our corporate website and the enquiries described below. Data processing within customer-operated software, customer portals or separately operated demonstration systems is not covered by this website policy. The applicable privacy information for those services depends on the service and the respective roles of the parties involved.

2. Data Protection Officer

You can contact our external Data Protection Officer using the following details:

Proliance GmbH
Data Protection Officer
Leopoldstr. 21
80802 Munich
Germany

Email: datenschutzbeauftragter@proliance.ai

Please specify that your enquiry concerns CloudLab Web to Print Solutions GmbH.

3. Purposes and legal bases of processing

We process personal data to provide and protect our website, respond to enquiries, communicate about our products and services, arrange demonstrations, fulfil contractual obligations and comply with legal requirements.

Contractual and pre-contractual processing: Article 6(1)(b) GDPR applies where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.

Legitimate interests: Article 6(1)(f) GDPR applies where processing is necessary for a legitimate interest and your interests or fundamental rights and freedoms do not override that interest. The relevant interests are identified in the sections below, including secure website operation and responding to business enquiries.

Legal obligations: Article 6(1)(c) GDPR applies where processing is necessary to comply with a legal obligation, such as an applicable record-retention requirement.

Consent: Article 6(1)(a) GDPR applies where we request and receive your consent for a specific processing purpose. You can withdraw consent at any time with effect for the future.

The storage of information on your device, or access to information already stored on it, is additionally subject to section 25 TDDDG, as explained in section 6.

4. Website access, hosting and technical data

When you visit our website, technical information transmitted by your browser is processed to deliver the requested content and maintain the website's availability and security. Depending on the request, this includes your IP address, the date and time of access, the page or file requested, the referring website where transmitted, browser and operating-system information, the response status and the amount of data transferred.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are providing a reliable website, identifying and resolving technical problems, and protecting the website and its users against misuse and security threats.

We use Webflow to provide our website and its content. The provider is Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA. Webflow uses hosting and content-delivery infrastructure to process technical requests and deliver website content. This can involve processing personal data in the United States and other countries outside the European Economic Area.

Webflow's processing of website-visitor data on behalf of its customers is governed by its Data Processing Addendum. Information about international transfers is provided in section 9.

Technical data is retained for the purposes of website delivery, diagnosing faults, maintaining availability and investigating security incidents. The retention period is determined by the time needed for the relevant operational or security purpose. Data needed to investigate a specific incident or establish, exercise or defend legal claims may be retained until that purpose has been fulfilled.

Further information is available in Webflow's privacy information and Data Processing Addendum.

5. Contact, product enquiries and demonstration requests

When you contact us by email, telephone or through a website form, we process the information you provide to understand and respond to your request. This includes enquiries about our products, services, integrations, pricing and demonstrations.

The information concerned may include your first and last name, company, country, email address, telephone number, the subject of your enquiry and your message. Correspondence and appointment information may also form part of the enquiry record.

We use this information to communicate with you, answer your questions, assess your requirements and arrange the requested demonstration or service. Please avoid providing sensitive personal information or information about other individuals that is unnecessary for your enquiry.

Where the enquiry concerns a contract with you or steps you request before entering into a contract, processing is based on Article 6(1)(b) GDPR. For general enquiries and correspondence with employees or representatives of business customers, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is responding to business enquiries and maintaining the associated business communication.

You are not legally obliged to contact us or provide personal data for an enquiry. However, we need sufficient information about your request and a way to contact you in order to respond or arrange the requested service. Without that information, we may be unable to handle your enquiry.

Access to enquiry data is limited to the personnel responsible for handling the request and the service providers supporting the relevant website, communication and IT functions. The recipient categories and applicable safeguards are described in sections 8 and 9.

Enquiry data is retained while the enquiry is being handled and while any related follow-up or contractual matter remains open. Once the matter has been concluded and no further communication is necessary, the data is deleted unless an applicable retention obligation or a specific need to establish, exercise or defend legal claims requires continued retention.

Contacting us or requesting a demonstration does not, by itself, constitute consent to receive a newsletter or to advertising tracking.

6. Cookies and similar technologies

Cookies and similar technologies can store information on your device or access information already stored there. Such technologies can support website functionality and the storage of user preferences. Device storage and access are legally distinct from any subsequent processing of personal data.

Where storage or access is strictly necessary to provide a digital service expressly requested by you, it is permitted under section 25(2), no. 2 TDDDG without a separate consent requirement. Where subsequent processing of personal data is necessary for secure and functional website operation, the legal basis is Article 6(1)(f) GDPR, subject to the requirements of that provision.

Storage or access that requires consent is subject to section 25(1) TDDDG. Processing of personal data on the basis of that consent is governed by Article 6(1)(a) GDPR. Consent relates to the particular purposes and services explained when it is requested.

You can withdraw a consent by contacting us using the details in section 1. Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out before withdrawal. Where a record of consent or withdrawal is necessary to demonstrate compliance or respect your choice, that record is retained separately from any processing for the original optional purpose.

You can also use your browser settings to restrict or delete cookies. Restricting technically necessary cookies may affect website functionality. Deleting cookies does not itself delete personal data already held by a service provider or automatically communicate a withdrawal of consent to that provider.

7. External websites and social-media links

Our website contains links to external websites and our social-media profiles. When you follow an external link, the provider of the destination service processes personal data in connection with your visit. Please consult that provider's privacy information for details of its purposes, legal bases, storage periods and your rights.

This website policy does not replace the privacy information applicable to the external service. A product integration described on our website does not, merely by being mentioned, establish that the integration provider receives your personal data when you visit our website.

8. Recipients of personal data

Within CloudLab, access to personal data is limited to those who require it for the purposes described in this policy.

External recipients may include providers of website hosting and content delivery, electronic communication, technical support and IT administration, insofar as their services are necessary for the relevant processing. Webflow is described in section 4. These service providers receive the information necessary to perform their respective functions.

Where a service provider processes personal data on our behalf and on our instructions, processing is subject to the requirements of Article 28 GDPR, including appropriate contractual arrangements and confidentiality obligations.

Personal data may also be disclosed to legal or professional advisers where necessary to establish, exercise or defend legal claims, or to public authorities and courts where disclosure is required by law. The legal basis is Article 6(1)(f) GDPR for the protection of legal interests or Article 6(1)(c) GDPR for compliance with a legal obligation, as applicable.

9. International data transfers

Although CloudLab is based in Germany, the use of service providers can involve processing outside the European Economic Area. In particular, the Webflow services described in section 4 involve a provider based in the United States.

International transfers are subject to the requirements of Chapter V GDPR. An adequacy decision adopted by the European Commission under Article 45 GDPR may provide a basis for a transfer where it covers the relevant country or recipient and processing.

Webflow states in its published privacy information that it is certified under the EU-U.S. Data Privacy Framework. For transfers covered by that certification and the European Commission's corresponding adequacy decision, the transfer basis is Article 45 GDPR. Webflow's Data Processing Addendum also incorporates the European Commission's Standard Contractual Clauses for transfers where that mechanism applies.

Where no applicable adequacy decision exists, appropriate safeguards under Article 46 GDPR, such as Standard Contractual Clauses, are required, together with any necessary supplementary measures.

You can request further information about the safeguards relevant to your data, including a copy where applicable, by contacting us using the details in section 1. Information may be redacted where necessary to protect confidential information or the rights of others.

10. Retention and deletion

We retain personal data for the purposes for which it is processed. The criteria applicable to technical data and enquiries are described in sections 4 and 5. Relevant considerations include whether a request is still open, whether a contractual relationship requires further processing, whether a specific security incident remains under investigation, and whether legal retention duties or legal claims require continued storage.

Where data forms part of records that must be retained under German commercial or tax law, the applicable statutory retention period governs those records. A retention requirement does not permit unrelated use of the retained data.

Where consent is withdrawn or a valid objection is made, processing for the relevant purpose ends unless another legal basis permits or requires retention for a separate purpose. Any such continued retention is limited to that separate purpose. Data is deleted when the applicable grounds for retention no longer exist.

11. Data security

We use technical and organisational measures appropriate to the risks of processing to protect personal data against unauthorised access, unlawful processing, accidental loss, destruction and damage. These measures include access restrictions and the protection of data transmission.

Our website uses HTTPS with TLS encryption to protect data transmitted between your browser and the website. Security measures are reviewed and adapted to technical developments and the nature of the processing. No method of transmission or electronic storage can guarantee absolute security.

12. Your data protection rights

Subject to the conditions and exceptions set out in the GDPR, you have the following rights:

Access, Article 15 GDPR: You can request confirmation of whether we process personal data concerning you, access to that data and information about the processing.

Rectification, Article 16 GDPR: You can request the correction of inaccurate personal data and the completion of incomplete data.

Erasure, Article 17 GDPR: You can request deletion of your personal data where the legal conditions are met, including where the data is no longer necessary for its purpose and no exception requires continued retention.

Restriction, Article 18 GDPR: You can request that we restrict processing where the legal conditions are met, for example while the accuracy of disputed data is being assessed.

Data portability, Article 20 GDPR: Where processing is based on consent or a contract and is carried out by automated means, you can request the personal data you have provided in a structured, commonly used and machine-readable format. Where technically feasible, you can request direct transmission to another controller.

Withdrawal of consent, Article 7(3) GDPR: You can withdraw consent at any time. This does not affect the lawfulness of processing based on consent before withdrawal.

Automated individual decisions, Article 22 GDPR: Subject to the exceptions in that provision, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.

To exercise your rights, contact us or our Data Protection Officer using the details above. If there are reasonable doubts about your identity, we may request the additional information necessary to confirm it. Requests are generally handled free of charge, subject to the exceptions permitted by law.

13. Right to object

Where we process your personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. This also applies to profiling based on that provision.

If you object, we will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.

Where personal data is processed for direct marketing, you may object at any time without giving reasons. This includes profiling to the extent that it is related to direct marketing. Following such an objection, your data will no longer be processed for those purposes.

You can send an objection to info@cloudlab-solutions.com or use the other contact details provided above.

14. Right to lodge a complaint

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. You may contact an authority in particular in the EU Member State of your habitual residence, place of work or the alleged infringement.

The supervisory authority responsible for private-sector organisations based in North Rhine-Westphalia is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Postfach 20 04 44
40102 Düsseldorf
Germany

Email: poststelle@ldi.nrw.de
Telephone: +49 211 38424-0
Website: LDI NRW contact and complaint information

15. Changes to this Privacy Policy

We update this Privacy Policy when our data processing changes or when legal requirements make an update necessary. The date at the beginning of this policy indicates the latest revision.

Where a change requires additional information or renewed consent, we will provide that information or request consent as required by law. Publishing an updated policy does not, by itself, replace a requirement to obtain consent.

Information i enlighet med 5 § i den tyska lagen om telemedier (TMG)

CloudLab Web to Print Solutions GmbH
Gerberstr. 1, 44135 Dortmund, Tyskland
telefon
+49 231 6000 17-17info@cloudlab-solutions.com

Företräds av: Marc Horriar



Dataskydd är viktigt för oss och därför förklarar vi i denna integritetspolicy hur vi samlar in och behandlar personuppgifter (kortfattat: "personuppgifter", dvs. uppgifter som rör en identifierad eller identifierbar person, såsom namn, adress, nationalitet, e-postadress, intressen och hobbyer, användarbeteende på webbplatser). Denna integritetspolicy är baserad på EU:s allmänna dataskyddsförordning (GDPR).

(1) CloudLab Web to Print Solutions GmbH ansvarar för dataskyddet.
(2) Kontaktuppgifterna till det externa dataskyddsombudet är följande:
Proliance GmbH

Dominik Fünkner

Adress: Leopoldstr. 21, 80802 München

Telefon: +4989250039227

E-post: datenschutzbeauftragter@proliance.ai


2. Insamling av personuppgifter och ändamål med behandlingen

(1) Vi begränsar behandlingen av personuppgifter främst till sådana uppgifter som vi tar emot i samband med våra tjänster och produkter från våra kunder, våra samarbetspartners eller andra berörda personer, eller som vi samlar in från användare på våra webbplatser, appar eller andra applikationer.

(2) I synnerhet samlar vi in följande personuppgifter från dig från fall till fall och beroende på ändamålet (se nedan):