Privacy Policy


Privacy Policy (GDPR) - Website - of Sommer Informatik GmbH, Sepp-Heindl-Str. 5, 83026 Rosenheim

In accordance with Article 13 of the GDPR, we provide the following information regarding the processing of personal data when you use our websites, in particular www.sommer-informatik.com, www.sommer-informatik.de, and other websites operated by Sommer Informatik GmbH, to the extent that these websites refer to this privacy policy.

1 Who is responsible for data processing?

The data controller under data protection law is

Sommer Informatik GmbH (Managing Directors: Robert Sommer, Alexander Sommer)
Sepp-Heindl-Str. 5, 83026 Rosenheim
Phone: +49 8031 24881
Email: info@sommer-informatik.de
Website: www.sommer-informatik.com

2 Data Protection Officers

Our Data Protection Officer is Christina Sommer. You can contact her at datenschutz@sommer-informatik.de or by mail at Sommer Informatik GmbH, Sepp-Heindl-Str. 5, 83026 Rosenheim, with the subject line “Data Protection” or “Data Protection Officer.”

3 What data is processed when you visit the website?

When you visit our website, technically necessary access data is processed. This may include, in particular, the IP address, the date and time of access, the page accessed, the referrer URL, the browser type and version, the operating system, the amount of data transferred, as well as status and error messages.

This data is processed to provide the website, ensure its technical functionality, analyze errors, maintain IT security, and detect misuse. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and reliable operation of our website.

4 Hosting and Technical Service Providers

The website is operated on our own IT infrastructure as well as through hosting and cloud service providers. As of now, Google Cloud is used in particular for website hosting, cloud data center services, and database hosting. STRATO is used as the online store and hosting service provider for the integrated online store, to the extent that the online store is used.

Where necessary, data processing agreements pursuant to Article 28 of the GDPR are concluded with the data processors used. Processing generally takes place within the EU or the EEA. If data is transferred to third countries in individual cases, this is done only in accordance with the legal requirements, in particular Chapter V of the GDPR.

5 Cookies and Similar Technologies

Our website may use cookies and similar technologies. Technically necessary cookies are used to provide the website, ensure security, enable form functionality, or store necessary settings. The legal basis is Article 6(1)(f) of the GDPR; to the extent that access to information on the end device is required, this is done in accordance with Section 25(2) of the TDDDG.

Non-essential cookies or similar technologies—particularly those used for statistics, marketing, or external content—are used only if consent has been granted. The legal basis in such cases is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Consent that has been given may be revoked at any time with future effect.

6 Contacting Us, Contact Form, and Demo Requests

If you contact us via the contact form, email, phone, or by requesting a demo, we will process the data you provide in order to handle your inquiry. This may include, in particular, your name, company name, contact information, email address, phone number, message content, product interests, and technical metadata.

The legal basis is Article 6(1)(b) of the GDPR, insofar as the contact is made for the purpose of taking pre-contractual measures or performing a contract. In other cases, the legal basis is Article 6(1)(f) of the GDPR; our legitimate interest lies in processing your inquiry and communicating with you.

The data will be deleted as soon as it is no longer necessary for processing the inquiry, provided there are no legal retention requirements or legitimate interests in longer-term storage.

7 Newsletters and Email Marketing

When you subscribe to our newsletter, we process the data required for this purpose, specifically your email address, name, company (if applicable), subscription date, confirmation date, and technical records of the double opt-in process. The newsletter provides information about products, services, training courses, webinars, and news from Sommer Informatik GmbH.

The newsletter is sent with the support of Mailjet / Sinch Email. The recipients of the data are Sommer Informatik GmbH and the newsletter service provider used. The legal basis for sending the newsletter is generally your consent pursuant to Art. 6(1)(a) of the GDPR. You may unsubscribe from the newsletter at any time; unsubscribing constitutes a revocation of consent for future mailings.

Newsletters may contain open and click data for performance measurement, to the extent that this is technically feasible and legally permissible. The data will be stored for the purpose of receiving the newsletter until you unsubscribe or withdraw your consent, provided there is no other legal basis for further storage.

8 Web Analytics and Online Marketing

To the extent that web analytics or online marketing services are used on the website—in particular Google Analytics or Google Ads—this is done solely on the basis of your consent. In particular, usage data, device information, IP addresses, cookie IDs, referrers, pages visited, and interactions may be processed.

The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Consent that has been given may be revoked at any time with future effect. We use data available to us in aggregated or statistical form to improve our website, our products, and our communications.

9 Embedded Content and Social Networks

The website may include external content or links to social networks and platforms, such as YouTube videos, LinkedIn, XING, Facebook, X/Twitter, or similar services. Simply placing a link does not, in principle, result in any data being transmitted to the provider; when the linked page is accessed, the privacy policy of the respective provider applies.

To the extent that external content is directly embedded on the website, accessing the content may establish a connection to the respective provider’s servers. In particular, IP addresses, browser information, device information, and usage data may be processed in this process. Non-essential integrations are carried out only on the basis of your consent pursuant to Art. 6(1)(a) of the GDPR in conjunction with § 25(1) of the TDDDG.

10 Store and Orders

If you order products, licenses, or services through a linked online store, we process the data necessary for the order and the performance of the contract. This may include, in particular, your name, company name, address, email address, phone number, order details, billing information, payment information, and communication data.

The legal basis is Article 6(1)(b) of the GDPR for the implementation of pre-contractual measures and the performance of a contract, as well as Article 6(1)(c) of the GDPR for compliance with statutory retention and documentation obligations. Recipients may include, in particular, online store/hosting service providers, payment service providers, banks, tax advisors, and government agencies, to the extent necessary.

11 Applications via the website

If you submit your application materials to us via our website, by email, or through a contact form, we will process your data for the purpose of conducting the application process. This may include, in particular, personal information, contact information, application materials, qualifications, certificates, and communication data.

The legal bases are, in particular, Article 6(1)(b) of the GDPR for the implementation of pre-contractual measures and, where applicable, Section 26 of the BDSG. To the extent that special categories of personal data are processed, this is done only on the basis of the relevant legal grounds for processing, in particular Article 9 of the GDPR and, where applicable, Section 26 of the BDSG.

12 Recipients of Personal Data

Personal data will only be disclosed to third parties if this is necessary to provide the website, process your inquiry, fulfill a contract, comply with legal obligations, protect legitimate interests, or based on your consent.

Recipients may include, in particular, IT/hosting service providers, cloud providers, online store and payment service providers, newsletter service providers, communication service providers, tax advisors, government agencies, and other entities involved in the performance of the contract.

13 Transfers to Third Countries

Data processing generally takes place within our own IT infrastructure or through service providers located within the EU/EEA. To the extent that data is transferred to third countries in individual cases, this is done only in accordance with the legal requirements, in particular Chapter V of the GDPR. This may be particularly relevant in the case of globally used cloud, analytics, marketing, or platform services.

14 Retention Period

We process personal data only for as long as is necessary for the respective purpose. To the extent that statutory retention requirements apply—in particular under commercial or tax law—the relevant data will be stored for the duration of the respective retention requirement. Once the purpose no longer applies or the retention obligations have expired, the data will be deleted, provided there is no other legal basis for further storage.

15 Your Rights as a Data Subject

In accordance with the statutory requirements, you have the right to access the personal data we process about you, as well as the right to rectification, erasure, restriction of processing, data portability, and the right to object to certain processing activities.

If processing is based on your consent, you may withdraw your consent at any time with effect for the future. The lawfulness of the processing up until the withdrawal remains unaffected.

16 Right to File a Complaint

You have the right to file a complaint with a data protection supervisory authority regarding our processing of your personal data. In particular, the supervisory authority with jurisdiction is the one in your usual place of residence, your place of work, or the location of the alleged violation.

17 Data Security

We implement technical and organizational measures to protect personal data against loss, destruction, unauthorized access, alteration, or unauthorized disclosure. These include, in particular, access restrictions, encryption during transmission, logging, access control, data backup, and regular audits of the systems in use.

©Sommer Informatik GmbH, Rosenheim, June 30, 2026