Privacy Policy
This policy informs you about which personal data we process when you visit this website, on which legal basis this happens and which rights you have.
Last updated: July 27, 2026
Controller and contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is: EL Industries GmbH Reiserdorf 147 92721 Störnstein Germany Represented by the managing directors Robert Siemens and Justin Kowal Email: hello@in-sync.io Commercial register: Local Court (Amtsgericht) Weiden i. d. OPf., HRB 5637 INSYNC is a trade name of EL Industries GmbH. We have not appointed a data protection officer, as the requirements of Section 38 of the German Federal Data Protection Act (BDSG) do not currently apply to us. For all data protection matters, you can reach us at the address above or by email at hello@in-sync.io.
Your rights
With regard to your personal data, you have the following rights vis-à-vis us: - Access (Art. 15 GDPR): You can find out whether and which data we process about you. - Rectification (Art. 16 GDPR): You can have inaccurate data corrected and incomplete data completed. - Erasure (Art. 17 GDPR): You can request the deletion of your data, insofar as no statutory retention obligations prevent this. - Restriction of processing (Art. 18 GDPR) - Data portability (Art. 20 GDPR): You can receive the data you have provided in a structured, commonly used and machine-readable format. - Withdrawal of consent (Art. 7 (3) GDPR): You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out until then remains unaffected. Right to object under Art. 21 GDPR Where we process data on the basis of a legitimate interest under Art. 6 (1) (f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims. If we process your data for direct marketing purposes, you can object at any time without giving reasons. Your data will then no longer be used for this purpose. Exercising your rights A message to hello@in-sync.io is sufficient. We will respond without undue delay, at the latest within one month of receiving your request. This period may be extended by a further two months where necessary due to the complexity or number of requests; in this case, we will inform you of the extension and its reasons. Right to lodge a complaint with a supervisory authority Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27, 91522 Ansbach, Germany www.lda.bayern.de
Provision of the website and server log files
When you access this website, your browser automatically transmits data to our hosting provider. The following data in particular is collected: - IP address of the requesting device - date and time of access - name and URL of the retrieved file - referrer URL - browser type and version - operating system - amount of data transferred and status of the retrieval This processing is technically necessary to deliver the website, to ensure its stability and security and to defend against attacks. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the secure and trouble-free operation of the website. Hosting The website is operated by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel processes the data mentioned above as a processor for us in accordance with Art. 28 GDPR. Vercel is certified under the EU-U.S. Data Privacy Framework; the European Commission has determined an adequate level of data protection for certified companies. Standard contractual clauses apply in addition. Privacy policy: https://vercel.com/legal/privacy-policy Server log files are deleted after 30 days.
Consent management
When you first visit our website, you receive a notice through which you decide on the use of cookies and comparable technologies. All services that are not technically necessary are only loaded after you have given your consent. We use a solution we developed ourselves for this. Your decision is processed exclusively on our own systems; no transmission to an external consent service provider takes place. For documentation purposes, we store the time of your decision, the categories you selected and the version of the notice. The associated cookie has a lifetime of six months; we keep the record of your decision for twelve months. The legal basis is Art. 6 (1) (c) GDPR in conjunction with our obligation to demonstrate consent under Art. 7 (1) GDPR. You can change or withdraw your decision at any time via the "Cookie settings" link in the footer of every page. The legal basis for storing information on your device and accessing it is Section 25 (1) of the German TDDDG (consent) or Section 25 (2) TDDDG, insofar as storage is strictly necessary to provide a service you have expressly requested.
Cookies and similar technologies
We use cookies and comparable technologies such as localStorage in two categories. Technically necessary These enable the basic operation of the website, such as storing your language selection and your cookie decision. They are set without consent, Section 25 (2) No. 2 TDDDG; the legal basis for the subsequent processing is Art. 6 (1) (f) GDPR. Subject to consent All technologies for analytics, audience measurement and marketing. We use these exclusively after your consent, Section 25 (1) TDDDG and Art. 6 (1) (a) GDPR. An overview of the cookies used, including name, purpose and lifetime, can be found in the cookie settings. You can additionally delete cookies in your browser or generally restrict their storage. If cookies are completely blocked, individual functions of this website may be limited. We do not respond separately to "Do Not Track" signals from your browser, as there is no uniform standard for this. Your decision in the consent notice is decisive.
Audience measurement and analytics
We use all services mentioned in this section exclusively on the basis of your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). You can withdraw your consent at any time via the cookie settings. Vercel Web Analytics Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. We use Vercel Web Analytics to evaluate the use of our website. Among other things, pages visited, referrers, country-level location, device type and browser are recorded. The service works without cookies and does not create cross-device profiles. Vercel is certified under the EU-U.S. Data Privacy Framework. Privacy policy: https://vercel.com/legal/privacy-policy Google Analytics 4 Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Measurement ID: G-PP0LKC6LSH. Google Analytics uses cookies and similar technologies to analyze your use of the website. Among other things, pages visited, time spent, referrers, device data, approximate location and a pseudonymous user identifier are processed. IP anonymization is active by default in Google Analytics 4; your IP address is truncated before it is stored. We have deactivated the features for personalized advertising. We have concluded a data processing agreement with Google. A transfer to Google LLC in the USA cannot be ruled out; the company is certified under the EU-U.S. Data Privacy Framework. User and event data is deleted after 14 months. Privacy policy: https://policies.google.com/privacy Microsoft Clarity Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA, represented in the EU by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Project ID: xch4s1tlcp. Microsoft Clarity records your usage behavior on this website so that we can identify usability problems and improve the website. Among other things, mouse movements, clicks, scrolling behavior, page views and information about your device and browser are recorded. Clarity uses this data to create session recordings and heatmaps. Input in form fields is masked before transmission and is not recorded in plain text. Microsoft is certified under the EU-U.S. Data Privacy Framework. The storage period is determined by the specifications of Microsoft Clarity. Privacy policy: https://privacy.microsoft.com/privacystatement Ahrefs Analytics Provider: Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581. Ahrefs Analytics records page views, referrers and information about your device and browser so that we can evaluate the reach of our content. The service works without cookies. There is no adequacy decision by the European Commission for Singapore. The transfer is based on standard contractual clauses under Art. 46 (2) (c) GDPR and your explicit consent under Art. 49 (1) (a) GDPR. Privacy policy: https://ahrefs.com/privacy
Marketing and conversion measurement
We also use the services in this section exclusively after your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). You can withdraw your consent at any time via the cookie settings. Meta Pixel Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Pixel ID: 369416625798062. We use the Meta Pixel to measure the effectiveness of our advertisements on Facebook and Instagram and to show you relevant ads there. Among other things, the pixel sets the _fbp cookie and transmits to Meta the page visited, your IP address, information about your browser and device, and triggered events such as page views and form submissions. With regard to the collection and transmission of this data, Meta and we are joint controllers under Art. 26 GDPR. The corresponding agreement can be found at https://www.facebook.com/legal/controller_addendum. Meta is solely responsible for the further processing by Meta. A transfer to Meta Platforms Inc. in the USA cannot be ruled out; the company is certified under the EU-U.S. Data Privacy Framework. Privacy policy: https://www.facebook.com/privacy/policy Settings for personalized advertising: https://www.facebook.com/settings?tab=ads LeadMetrics (server-side conversion measurement) Provider: LeadMetrics GmbH, Wienerbergstraße 11-12, 1100 Vienna, Austria. Company register: Commercial Court of Vienna, FN 583831a. We use LeadMetrics to understand through which advertisements and channels prospects find us, and to report advertising results back to the advertising platforms. Unlike a pure browser pixel, LeadMetrics works server-side: events are passed from our system to the interfaces of the advertising platforms (including the Meta Conversions API). The following categories of data are processed: - Technical data: IP address, device data, browser type, access times - Usage data: clicks, page views, conversions, attribution to advertising campaigns and touchpoints - Contact data, if you provide it yourself: first name, last name, email address, phone number, postal code - Information from forms that you submit to us Contact data is rendered unrecognizable using a cryptographic hashing procedure before being passed on to the advertising platforms. LeadMetrics acts as a processor for us in accordance with Art. 28 GDPR; a corresponding agreement is in place. Processing takes place on Microsoft Azure servers in Frankfurt am Main, i.e. within the European Union. For sending emails, LeadMetrics uses MailerSend, Inc. (USA) as a sub-processor; this transfer is based on the EU-U.S. Data Privacy Framework. The purpose of the processing is the measurement and optimization of our advertising campaigns. The legal basis is your consent under Art. 6 (1) (a) GDPR. Without your consent, no transmission to the advertising platforms takes place. Provider's imprint and privacy policy: https://www.lead-metrics.com/imprint and https://www.lead-metrics.com/privacy-policy
Delivery of content and media
Images and editorial content on this website are delivered via the content management system and delivery network of Sanity. Provider: Sanity AS, Torggata 15, 0181 Oslo, Norway. Norway is part of the European Economic Area, so the same level of data protection applies to the processing as in the EU. When content is retrieved, your IP address is transmitted to Sanity because it is technically necessary to deliver the content to your browser. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the fast and reliable delivery of our content. Privacy policy: https://www.sanity.io/legal/privacy
Contact and appointment booking
Contact form If you write to us via the form on our contact page, we process the data you enter: name, company, email address, phone number, optionally your website, the selected budget range, optionally how you became aware of us, and your message. We also store the time of submission. The purpose is to process and respond to your inquiry. The legal basis is Art. 6 (1) (b) GDPR, insofar as your inquiry is aimed at the conclusion or performance of a contract, and otherwise Art. 6 (1) (f) GDPR with our legitimate interest in responding to inquiries. The form data is stored in a database at Airtable Inc., 799 Market Street, San Francisco, CA 94103, USA, which acts as a processor for us in accordance with Art. 28 GDPR. The transfer to the USA is based on the standard contractual clauses under Art. 46 (2) (c) GDPR, which are part of our contract with Airtable. Privacy policy: https://www.airtable.com/company/privacy Email and phone If you contact us directly by email or phone, we process your contact details and the contents of your message for the same purpose and on the same legal basis. Appointment booking We use Calendly to arrange appointments. If you click "Book a call" on our contact page, you will be redirected to a Calendly page. Data is only transmitted to Calendly when you access that page; no Calendly script is embedded on our own website. Provider: Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. When you book, we process your name, your email address, the selected appointment and the information you provide in order to organize the meeting. The legal basis is Art. 6 (1) (b) GDPR. Calendly acts as a processor for us; the transfer to the USA is based on the EU-U.S. Data Privacy Framework and, in addition, on standard contractual clauses. Privacy policy: https://calendly.com/legal/privacy-notice Deletion We delete your inquiries as soon as they have been conclusively processed and no statutory retention obligations prevent this, but at the latest 24 months after the last contact.
Newsletter
If you sign up for our newsletter, we process your email address in order to send you information about our services and content. Registration takes place using the double opt-in procedure: after signing up, you receive an email with a confirmation link. We only add you to the mailing list after your confirmation. To prove your consent, we store the time of registration, the time of confirmation and the IP address used. The legal basis is your consent under Art. 6 (1) (a) GDPR in conjunction with Section 7 (2) No. 2 of the German Act Against Unfair Competition (UWG). You can unsubscribe from the newsletter at any time, for example via the unsubscribe link at the end of every email. After unsubscribing, we remove your email address from the mailing list. We keep the records of your consent until any possible claims have expired.
Job applications
If you apply to us, we process the data you submit, in particular contact details, CV, references and other documents, exclusively for the purpose of conducting the application process. The legal basis is Section 26 (1) BDSG in conjunction with Art. 88 GDPR and Art. 6 (1) (b) GDPR. If you are not hired, we delete your documents six months after the process has been completed. This period serves to defend against possible claims under the German General Equal Treatment Act; the legal basis in this respect is Art. 6 (1) (f) GDPR. If you would like us to consider your documents for future positions beyond this, we will obtain your separate consent.
Recipients and transfers to third countries
We do not pass on your personal data to third parties for our own commercial purposes, nor do we sell or rent it. Access to your data is granted exclusively to: - those employees of our company who need the data to perform their tasks, - the service providers named in this policy, whom we have bound as processors in accordance with Art. 28 GDPR, - authorities and courts, insofar as we are legally obliged to provide information. Transfers to third countries Some of the service providers we use are based outside the European Union, predominantly in the USA. For providers certified under the EU-U.S. Data Privacy Framework, the European Commission determined an adequate level of protection by decision of July 10, 2023. In all other cases, we base the transfer on standard contractual clauses under Art. 46 (2) (c) GDPR and, where applicable, on your explicit consent under Art. 49 (1) (a) GDPR. We would like to point out that third countries may not have a level of data protection fully comparable to that of the EU, and access by government bodies cannot be ruled out in every case. Which service providers we use, where they are based and what the respective transfer is based on can be found in section 3 and in sections 6 to 11. Business transfers Should we become part of a merger, acquisition or sale of the company, personal data may be transferred to the acquirer. We will ensure that this takes place while maintaining confidentiality and will inform affected persons in advance on our website or by email.
Storage periods
We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations. For documents of relevance under tax or commercial law, the retention periods under Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB) apply. After the respective period has expired, we delete the data or restrict its processing. The specific storage periods for the individual processing operations can be found in the respective sections of this policy.
Data security
Data transmitted between your browser and our website is encrypted using TLS. You can recognize this in the address bar of your browser. We take technical and organizational measures in accordance with Art. 32 GDPR to protect your data against unauthorized access, loss and alteration, and we continuously adapt these measures to the state of the art. Complete protection against all conceivable attacks is technically not achievable. In the event of a personal data breach, we will fulfill our notification obligations under Art. 33 and 34 GDPR.
Changes to this policy
We update this privacy policy when our processing operations or the legal framework change. The version published on this page applies in each case. We will additionally inform you of significant changes on our website or by email. If you have any questions, you can reach us at hello@in-sync.io.



