Skip to main content

Privacy Policy

1. Data protection at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you could be personally identified.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice (Impressum) of this website.

How do we collect your data?

On the one hand, your data is collected when you provide it to us (e.g. via a contact form). Other data is collected automatically or with your consent when you visit the website through our IT systems (particularly server log files).

2. General information and mandatory disclosures

Controller

Balane GmbH

Balanstraße 84

81541 Munich

Germany

Email: contact@balane.tech

Data Protection Officer

We are not legally required to appoint a Data Protection Officer (Section 38 of the German Federal Data Protection Act — BDSG). For data protection enquiries, please contact the controller named above.

Storage period

Unless a more specific storage period is mentioned within this privacy policy, your personal data will remain with us until the purpose for processing no longer applies or until statutory retention periods expire.

SSL/TLS encryption

For security reasons, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser's address line begins with „https://”.

3. Hosting and international data transfers

Vercel (hosting provider)

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Execution and delivery of our Next.js application take place via Vercel's EU regions (in particular Frankfurt am Main, fra1).

Processing agreement: A data processing agreement pursuant to Art. 28 GDPR is in place with Vercel (Vercel Data Processing Addendum).

International transfer: Since the parent company is located in the USA, access from the USA cannot be fully excluded in individual cases (e.g. support access, log aggregation, CDN delivery). This is based on the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and the certification of Vercel Inc. under the EU-US Data Privacy Framework.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable and secure provision of our services).

Server log files

When you visit this website, information that your browser transmits is automatically collected (server log files):

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources.

Purpose: technically error-free operation, optimisation, security of IT systems (protection against misuse).

Legal basis: Art. 6(1)(f) GDPR.

Storage period: 7 days; afterwards deletion or anonymisation, longer storage only in the case of a documented security incident.

4. Cookies and similar technologies

We use cookies and comparable technologies (e.g. localStorage). The legal basis for strictly necessary technologies is Section 25(2) No. 2 of the German Telecommunications Telemedia Data Protection Act (TTDSG/TDDDG) in conjunction with Art. 6(1)(f) GDPR. All non-essential technologies are set exclusively with your consent (Section 25(1) TTDSG in conjunction with Art. 6(1)(a) GDPR).

Name / StorageProviderPurposeDurationCategory
cookieConsent (localStorage)Own websiteStores your consent decision12 monthsNecessary
NEXT_LOCALEOwn websiteLanguage selectionSession / 12 monthsNecessary
umami.* (localStorage)Umami (self-hosted, EU)Anonymous traffic measurementSessionAnalytics (consent)
__or_uid / __or_sid (localStorage)OpenReplay (self-hosted, Hetzner DE)Anonymised session recording for UX analysisSession / 30 daysAnalytics (consent)

You can withdraw your consent at any time with effect for the future via the „Cookie Settings” link in the footer.

5. Services and tools used

Umami Analytics (self-hosted)

We use Umami Analytics for statistical analysis of user behaviour. Umami is privacy-focused open-source analytics software which we operate on our own infrastructure within the EU (Railway).

Data processed: page views, time on page, referrer, anonymised device/browser information.

No persistent storage of your IP address – IP addresses are only hashed by Umami for session identification and are not stored.

Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TTDSG (consent via the cookie banner). Umami is only loaded after you give consent.

OpenReplay (self-hosted)

To improve usability, we use OpenReplay — open-source software that records anonymised sessions. We operate OpenReplay on our own infrastructure at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen — server location: Nuremberg, Germany. No data is transferred to third countries.

Data processed: mouse movements, clicks, scroll events, visited pages (URL paths), viewport size, user agent, anonymised IP address (used only server-side for request attribution and not persisted in the recording).

Not processed: the content of any input fields (forms, passwords, searches) — these are completely ignored by the configuration defaultInputMode: 2 ; HTTP request/response bodies as well as Authorization, Cookie and Set-Cookie headers are also not captured.

Storage period: 30 days, after which the data is automatically deleted from our server.

Legal basis:Art. 6(1)(a) GDPR, Section 25(1) TTDSG (consent via the cookie banner, category „Analytics & Statistics”). OpenReplay is only loaded after you give consent; browser settings with „Do Not Track” are respected.

Withdrawal:You can withdraw your consent at any time via the „Cookie Settings” link in the footer. Recording will stop immediately.

YouTube videos (two-click solution)

On individual sub-pages we embed videos from YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland („Google”). The parent company Google LLC is based in the USA.

Two-click solution: when a page with an embedded video is loaded, noconnection to YouTube/Google is initially established. Only when you actively click the preview image or consent to the „External media” category is the video loaded via youtube-nocookie.com.

Data processed (after consent): IP address, visited page, date/time, browser and device information, potentially cookie/fingerprint identifiers and — if you are logged into your YouTube account — your YouTube/Google account information.

International transfer: Google transfers data to the USA. This is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and certification under the EU-US Data Privacy Framework.

Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TTDSG (consent).

For further information on how Google handles user data, please see Google's privacy policy: policies.google.com/privacy.

„Inter” font

We use the „Inter” font via the Next.js font system (next/font/google). Font files are downloaded at build time and served exclusively from our own domain. When a page is loaded, no connection to Google servers is made and no IP address is transmitted to Google.

Automation maturity assessment (lead form)

At /process/assessment we offer a self-check. Answers are initially evaluated only in your browser. If you request the full report at the end, we additionally process the following data:

  • Name and email address (mandatory)
  • Company (optional)
  • Your assessment answers and the calculated score

Legal basis for sending the report: Art. 6(1)(b) GDPR (pre-contractual measure / your active request).

Legal basis for being contacted:only if you actively tick the additional „Contact allowed” checkbox — Art. 6(1)(a) GDPR (consent, revocable at any time via contact@balane.tech).

Recipients: Odoo CRM (see below).

Storage period: until revocation or in accordance with our CRM lifecycle, no later than 36 months without further interaction.

Odoo CRM

We process contact requests and assessment leads in a self-hosted instance of Odoo (open-source CRM). The instance runs on servers within the European Union.

Processing agreement: a data processing agreement pursuant to Art. 28 GDPR is in place with our hosting provider.

Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR (efficient handling of your request).

Contact form

If you send us enquiries via the contact form, the details provided — including your contact data — will be stored in our Odoo CRM for the purposes of processing your request and for follow-up questions. Legal basis: Art. 6(1)(b) GDPR (initiation/performance of a business relationship) or Art. 6(1)(f) GDPR (general enquiries).

Contact by email or phone

If you contact us by email or telephone, your request — including all resulting personal data (name, request) — will be stored and processed by us for the purpose of handling your enquiry.

6. Your rights

As a data subject, you have the right at any time to:

  • Information / access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

An informal message to contact@balane.tech is sufficient to exercise your rights.

Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht — BayLDA), Promenade 18, 91522 Ansbach, Germany.

Last updated: 15 April 2026