Skip to content

Privacy notice

This notice describes personal-data processing on akilaris.com, in contact and recruitment processes and, where used, in protected account areas.

1. Controller

Akilaris UG (haftungsbeschränkt), c/o Clockwise, Martinistraße 62–66, 28195 Bremen, Germany · Email: info@akilaris.com

2. Website delivery, hosting and logs

The website is delivered through cloud infrastructure; media may be loaded from a Google Cloud Storage bucket. This can process the IP address, timestamp, requested URL, referrer, browser/device information and technical status data. The purpose is secure, stable and efficient delivery. The legal basis is Article 6(1)(f) GDPR and our legitimate interest in secure operation. Logs are kept only as long as needed for operation, troubleshooting and security; longer retention is limited to specific incidents or legal duties.

3. Technically necessary storage

We use necessary cookies and local storage for CSRF protection, language, display, consent status and, where an account is used, sign-in and system messages. The legal bases are section 25(2) TDDDG and Article 6(1)(b) or (f) GDPR. Session cookies generally end with the browser session; the display preference may remain for up to twelve months.

4. Google Analytics – consent only

If you consent in cookie settings, we load Google Analytics 4 provided by Google Ireland Limited. Page views, interactions, technical device information, shortened or Google-derived location information and online identifiers may be processed. Google Signals and advertising personalisation are disabled. The legal bases are consent under section 25(1) TDDDG and Article 6(1)(a) GDPR. The client-side lifetime of typical _ga cookies is limited to no more than six months. Event-data retention follows the period configured in the Analytics property and Google’s subsequent deletion cycles. Transfers to the United States cannot be excluded; Google relies in particular on the EU-US Data Privacy Framework and supplementary safeguards. You may withdraw consent at any time for the future.

5. Contact and data-subject requests

For contact or data-subject requests, we process the contact details and content you provide to respond and communicate. Form emails are delivered through Resend. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters and otherwise Article 6(1)(f); data-subject requests also rely on Article 6(1)(c). Contact requests are generally deleted no later than three years after completion unless legal retention duties apply. Data-subject requests are generally kept for three years as evidence of handling. We request identity evidence only where there are reasonable doubts and only to the extent necessary.

6. Recruitment

Application data is processed only to decide on an employment relationship and communicate during the process. The legal bases are section 26 BDSG and Article 6(1)(b) GDPR; limited retention for legal defence relies on Article 6(1)(f). Unsuccessful application data is generally deleted after six months. Longer talent-pool storage requires separate, revocable consent. This website does not make solely automated recruitment decisions or perform profiling within the meaning of Article 22 GDPR.

7. Accounts and optional billing

If you use a protected account area, we process your email address, sign-in information, optional username, profile image and security/usage data under Article 6(1)(b) GDPR. Paid billing is disabled by default. If it is explicitly enabled for a specific offer, Stripe processes necessary customer, payment and billing data; separate contractual and privacy information is provided before a paid order. Account data is kept until account deletion and afterwards only where legally required.

8. Recipients and international transfers

Access is limited to responsible personnel and necessary hosting, cloud, email, analytics and, where applicable, payment providers. These may currently include Google Cloud/Google, Resend and – only where billing is enabled – Stripe. Where data is processed outside the EEA, we use an adequacy decision, Standard Contractual Clauses or another Chapter V GDPR safeguard. External social-media pages are contacted only when you actively open a link.

9. Security

We use technical and organisational measures proportionate to risk, including TLS, access restrictions, integrity checks and security logging. Absolute security cannot be guaranteed for internet-based communication.

10. Your rights

Subject to the statutory conditions, you may request access, rectification, erasure, restriction, portability or object, and may withdraw consent. You may also complain to a data protection authority; the Bremen State Commissioner for Data Protection and Freedom of Information is particularly relevant to us.

Last updated: 11 August 2026