1. Privacy at a Glance
General Information
The following information provides an overview of what happens to your personal data when you visit our websites. Personal data is any information relating to an identified or identifiable natural person. Detailed information can be found in the following sections of this privacy policy.
Data Collection on Our Websites
Who is responsible for data processing?
Data processing on these websites is carried out by LETHE GmbH. You can find the contact details in the “Controller” section.
How do we collect your data?
On the one hand, we receive data directly from you, for example, when you fill out a contact form, contact us by email or telephone, or submit an application.
On the other hand, technical data is automatically processed when you visit our websites. Further data is only processed with your consent, in particular by analysis, marketing, media, or social media services.
What do we use your data for?
We process data in particular for the secure and technically error-free provision of our websites, for processing inquiries and applications, and – with your consent – for reach measurement, analysis, display of external media, and optimization of our marketing measures.
What rights do you have?
In particular, you have the right to access, rectification, erasure, restriction of processing, data portability, and objection. You can revoke any consent granted at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.
2. Controller and Data Protection Officer
Controller
LETHE GmbH
Seehafenstraße 17
21079 Hamburg
Germany
Phone: +49 (0)40 742 163-0
Email:
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data Protection Officer
BREDEX GmbH
Lindentwete 1
38100 Braunschweig
Phone: +49 (0)531 243 30-0
Email:
3. General Information on Data Processing
Legal Bases
We process personal data in particular on the following legal bases:
- Consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG,
- Performance of a contract or implementation of pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR,
- Compliance with legal obligations pursuant to Art. 6 para. 1 lit. c GDPR, and
- Protection of legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.
For applications, Section 26 BDSG also applies. The respective applicable legal basis is mentioned below for the individual processing operation.
Storage Duration
Unless a more specific storage period is specified, we only store personal data for as long as is necessary for the respective processing purpose.
Thereafter, the data will be deleted unless there are legal retention obligations or legitimate reasons for further storage. Statutory commercial and tax retention periods can be six or ten years in particular.
Recipients and Processors
We use external service providers, such as hosting, analysis, marketing, and IT service providers, as part of the operation of our websites.
Insofar as these providers process personal data on our behalf, they are used on the basis of a contract pursuant to Art. 28 GDPR. Data is only transferred to other recipients if there is a legal basis for this or if you have given your consent.
Data Transfers to Third Countries
Individual providers used by us may process data outside the European Economic Area, in particular in the USA.
A transfer only takes place under the conditions of Art. 44 et seq. GDPR, for example, on the basis of an adequacy decision by the European Commission, certification under the EU-US Data Privacy Framework, or appropriate safeguards such as the standard contractual clauses of the European Commission.
Despite these safeguards, residual risks cannot be completely ruled out for third-country transfers.
SSL or TLS Encryption
Our websites use SSL or TLS encryption. You can recognize an encrypted connection in particular by the “https://” in the address bar of your browser.
4. Your Rights
Withdrawal of Consent
You can withdraw any consent granted at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent until the withdrawal remains unaffected.
You can change your cookie settings at any time using the “Manage Consent” function provided on the website.
Right to Object Pursuant to Art. 21 GDPR
If we process personal data on the basis of Art. 6 para. 1 lit. e or f GDPR, you can object to the processing at any time for reasons arising from your particular situation.
If personal data is processed for the purpose of direct marketing, you can object to the processing at any time.
Access, Rectification, Erasure, and Restriction
Within the framework of the legal requirements, you have the right to access your personal data as well as to rectification of incorrect data, erasure, restriction of processing and – where applicable – notification of the recipients of a rectification, erasure, or restriction of processing.
Data Portability
Insofar as we process data automatically on the basis of your consent or for the performance of a contract, you have the right to receive this data in a structured, commonly used, and machine-readable format or – as far as technically feasible – to have it transferred to another controller.
Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
The following is responsible for LETHE GmbH in particular:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22, 7th floor
20459 Hamburg
Email:
5. Hosting and Technical Provision
DomainFactory
The main website is hosted by domainfactory GmbH, c/o WeWork, Neuturmstraße 5, 80331 Munich.
When the website is accessed, the hosting provider processes the following data in particular:
- IP address,
- Date and time of access,
- Content accessed,
- Referrer URL,
- Browser and operating system information, and
- Other technical log data.
Processing is carried out for the secure, stable, and efficient provision of the website on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the technically reliable operation of our online offer.
Insofar as the provider processes personal data on our behalf, this is done on the basis of a contract pursuant to Art. 28 GDPR.
Onepage – Career Page
The career page is provided via
Onepage GmbH
Hanauer Landstraße 172
60314 Frankfurt am Main
.
In this context, technical usage and connection data in particular can be processed. Processing is carried out for the secure and efficient provision of the career page on the basis of Art. 6 para. 1 lit. f GDPR.
Insofar as Onepage processes personal data on our behalf, it is used on the basis of a contract pursuant to Art. 28 GDPR.
Server Log Files
The hosting providers regularly collect and store technical log data that your browser automatically transmits.
This may include the following data in particular:
- Browser type and browser version,
- Operating system used,
- Referrer URL,
- Hostname of the accessing device,
- Time of the server request,
- Content accessed, and
- IP address.
Processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR to ensure the security and stability of our websites and for error analysis.
Log data is only stored for as long as is necessary for these purposes. They are then deleted or anonymized, unless security-relevant storage is required.
6. Cookies and Consent Management
Cookies and Comparable Technologies
Our websites use cookies and comparable technologies.
Technically necessary technologies are used on the basis of Section 25 para. 2 TDDDG. The subsequent processing of personal data is regularly carried out on the basis of Art. 6 para. 1 lit. f GDPR.
Non-essential technologies are only used with your consent pursuant to Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.
You can change your selection at any time using the “Manage Consent” function.
Complianz
We use the consent management tool “Complianz” to obtain, document, and manage consent for cookies and other technologies requiring consent.
In this context, the following information in particular is processed:
- Your consent decision,
- The time of the decision,
- Technical information, and
- A pseudonymous identifier.
The processing is necessary to fulfill our legal obligation to provide proof and is carried out on the basis of Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR.
Our legitimate interest lies in legally compliant and verifiable consent management.
7. Contacting Us
Contact Form
If you contact us via the contact form provided on our website, we process the data you enter into the form.
This includes in particular:
- Your name,
- Your email address,
- The content of your message, and
- Any other information you voluntarily provide.
In addition, technically necessary connection data, in particular your IP address and the date and time of transmission, can be processed.
Processing is carried out to process and answer your inquiry. If your inquiry is aimed at the conclusion or performance of a contract, the processing is based on Art. 6 para. 1 lit. b GDPR.
In all other cases, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the proper, secure, and efficient processing of inquiries addressed to us.
Mandatory fields are marked as such. The provision of further information is voluntary.
Storage of Form Data in WordPress and Flamingo
The data transmitted via the contact form can be temporarily stored in the WordPress database to ensure technical transmission, for processing the inquiry, and for error analysis. The WordPress plugin Flamingo is used for this purpose.
The storage serves in particular to be able to track the receipt of contact inquiries and to be able to restore messages in the event of technical transmission problems.
The form data stored in the WordPress backend is generally deleted after 30 days at the latest, unless it is no longer required for processing the inquiry or for technical error analysis. Longer storage only takes place if there are legal retention obligations or if the data is required for the establishment, exercise, or defense of legal claims.
The legal basis for storage is Art. 6 para. 1 lit. b GDPR, insofar as the inquiry serves the initiation or performance of a contract. In all other cases, storage is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the reliable transmission and traceable processing of the contact inquiry.
Email Dispatch via Microsoft 365 and Microsoft Graph
For the reliable dispatch and forwarding of system and form emails, we use Microsoft 365 and the Microsoft Graph API. The technical connection is made via a WordPress solution from WPO365.
The provider of Microsoft services for users within the European Union is:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland
When you use our contact form, the data entered is transmitted in encrypted form to our website and forwarded via the Microsoft Graph API to the Microsoft 365 mailbox we use.
In this context, the following data in particular can be processed:
- Name,
- Email address,
- Message text,
- Other information provided in the form,
- Time of dispatch and receipt, and
- Technical transmission and log data.
Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, insofar as your contact is aimed at the conclusion or performance of a contract.
In all other cases, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure, reliable, and efficient delivery and processing of contact inquiries and system messages.
Insofar as Microsoft processes personal data on our behalf, it is used on the basis of the data protection agreements for Microsoft 365 and in accordance with Art. 28 GDPR.
Microsoft has established an EU Data Boundary for its enterprise online services, within which customer data and personal data for Microsoft 365 are generally stored and processed. Nevertheless, it cannot be completely ruled out that personal data may also be processed outside the European Union or the European Economic Area in certain cases or made accessible from there.
Insofar as personal data is transferred to the USA or other third countries, this is done in accordance with Art. 44 et seq. GDPR. Microsoft Corporation is certified under the EU-US Data Privacy Framework. In addition, the standard contractual clauses of the European Commission and other contractual guarantees may apply.
Further information on the processing of personal data by Microsoft can be found in Microsoft’s privacy policy.
Inquiries by Email, Telephone, or Fax
When contacting us by email, telephone, or fax, we process the data you provide to handle your request.
The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the communication serves the initiation or performance of a contract. In all other cases, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR.
Our legitimate interest lies in the proper and efficient processing of inquiries addressed to us.
The data will be deleted as soon as the purpose of the processing no longer applies and there are no legal retention obligations or other legitimate reasons for further storage.
8. Analysis and Marketing
Google Tag Manager
We use the Google Tag Manager from
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland.
The Google Tag Manager is used for the central management of website tags. It generally does not create its own user profiles, but it can process technical data such as the IP address and enables the triggering of other services.
The Google Tag Manager is only activated after your consent. The legal bases are Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.
Insofar as data is transferred to the USA or other third countries, this is done in accordance with Art. 44 et seq. GDPR.
Google Analytics 4
We use Google Analytics 4, a web analysis service from
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland.
Google Analytics processes information in particular about:
- Page views,
- Interactions,
- Approximate location,
- Device and browser information,
- Referrer,
- Pseudonymous identifiers, and
- IP address.
According to Google, the IP address is not permanently logged or stored in Google Analytics 4, but is only processed to derive coarse location data.
Use is only made after your consent pursuant to Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time with effect for the future.
Data can be transferred to Google LLC in the USA. A third-country transfer takes place in accordance with Art. 44 et seq. GDPR.
The specific storage duration depends on the retention period configured in Google Analytics.
Meta Pixel
We use the Meta Pixel from
Meta Platforms Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland with your consent.
The Meta Pixel makes it possible to track the actions of visitors, measure the effectiveness of advertising, and form target groups for advertisements.
In this context, the following data in particular can be processed:
- Pages accessed,
- Interactions,
- Technical device and browser data,
- IP address,
- Cookie identifiers, and
- Event identifiers.
This data can be linked to an existing Meta account if necessary.
The legal bases are Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.
Data can be transferred to Meta Platforms, Inc. in the USA. The transfer takes place in accordance with Art. 44 et seq. GDPR.
Facebook Conversion API
The Facebook Conversion API can also be used.
In this case, event data is transmitted to Meta on the server side to measure conversions, evaluate advertising campaigns, and improve data quality.
Depending on the configuration, the following data in particular can be processed:
- Page and event data,
- Timestamp,
- IP address,
- User agent,
- Cookie or event identifiers, and
- Hashed contact data if applicable.
Use only takes place after your consent pursuant to Art. 6 para. 1 lit. a GDPR. Insofar as access to information in your terminal device or the storage of information on your terminal device is affected, use is additionally based on Section 25 para. 1 TDDDG.
Data transfers to the USA take place in accordance with Art. 44 et seq. GDPR.
9. Social Media Elements
Active elements of the social networks Facebook, Instagram, and LinkedIn can be integrated on our websites.
These elements are only activated after you have given your consent. Upon activation, a direct connection to the servers of the respective provider can be established.
The provider regularly receives at least your IP address and information about the page accessed. If you are logged in to the respective social network, the transmitted data can be assigned to your user account if necessary.
The legal bases are Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.
Facebook and Instagram
The provider for users in the European Economic Area is:
Meta Platforms Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland.
Data can be transferred to Meta Platforms, Inc. in the USA. A third-country transfer takes place in accordance with Art. 44 et seq. GDPR.
Further information on data processing and your setting options can be found in Meta’s privacy policy.
The provider is:
LinkedIn Ireland Unlimited Company
Wilton Plaza
Wilton Place
Dublin 2
Ireland.
Data can be transferred to LinkedIn Corporation in the USA. A third-country transfer takes place in accordance with Art. 44 et seq. GDPR.
Further information on data processing and your setting options can be found in LinkedIn’s privacy policy.
10. Integrated Content and Fonts
YouTube
Videos from the YouTube platform can be integrated on our websites, in particular on the career page.
The provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland.
When playing a video, a connection to Google servers is established. In this context, the following data in particular can be processed:
- IP address,
- Device and browser information,
- Content accessed,
- Interactions,
- Cookie data, and
- Account data if applicable.
Since not all videos are necessarily integrated in extended data protection mode, YouTube content is only loaded after your consent.
The legal bases are Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.
Data can be transferred to Google LLC in the USA. A third-country transfer takes place in accordance with Art. 44 et seq. GDPR.
Google Fonts
For the uniform display of fonts, fonts from Google Fonts can be used on our websites.
Insofar as the fonts are not loaded locally but from Google servers, your browser establishes a connection to Google when the website is accessed. In this context, your IP address in particular is transmitted to Google.
The provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland.
Externally provided Google Fonts are only loaded after your consent. The legal bases are Section 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR.
Insofar as the fonts are provided locally on our servers, no connection to Google takes place in connection with the display of the fonts.
Font Awesome
Font Awesome is used on our websites for the uniform display of symbols and icons.
The files required for this are provided locally on the servers of LETHE GmbH or the hosting provider it uses. When our websites are accessed, no connection is therefore established to the servers of the provider of Font Awesome in connection with the display of the icons.
A transfer of personal data to Fonticons, Inc. does not take place in connection with the local display of the icons.
Local integration is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in a technically reliable, uniform, and appealing presentation of our websites.
11. Applications and Career Page
Application Process
When you apply to us, we process the applicant data you transmit.
This includes in particular:
- Master and contact data,
- Information on qualifications and professional experience,
- Application documents,
- Answers from application forms,
- Communication content, and
- Interview and evaluation notes.
Processing is carried out to decide on the establishment of an employment relationship on the basis of Section 26 para. 1 BDSG.
Insofar as special categories of personal data are processed, processing is carried out in accordance with Section 26 para. 3 BDSG in conjunction with Art. 9 para. 2 lit. b GDPR.
Voluntary inclusion in an applicant pool only takes place on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR. You can withdraw this consent at any time with effect for the future.
Authorized Persons
Within LETHE GmbH, only those persons who are involved in processing the application and in the selection process receive access to applicant data.
In addition, IT, hosting, and recruiting service providers used by us can receive access to the data insofar as this is necessary for the provision of the technical systems.
Personio
We use the recruiting platform Personio for the publication of job offers and the implementation of online application processes.
The provider is:
Personio SE & Co. KG
Seidlstraße 3
80335 Munich
Germany
Our websites may contain links to job offers or career pages from Personio. The mere display of such a link does not transmit any personal data to Personio.
Only when you access the link do you leave our website and establish a connection to Personio’s servers.
If you apply for a position via Personio, the data you provide as part of the application process will be processed via the recruiting platform provided by Personio.
This may include the following data in particular:
- Name and contact details,
- Address,
- Application documents,
- CV,
- Certificates,
- Information on qualifications and professional experience,
- Information on the desired employment relationship,
- Communication content, and
- Other information you voluntarily provide.
LETHE GmbH remains responsible for carrying out the application process and deciding on your application. Personio provides the technical recruiting platform and generally processes the applicant data as a processor in accordance with Art. 28 GDPR as part of this service.
Processing is carried out to decide on the establishment of an employment relationship on the basis of Section 26 para. 1 BDSG.
Insofar as processing is necessary for the implementation of pre-contractual measures, it can additionally be based on Art. 6 para. 1 lit. b GDPR.
Insofar as data is processed for the establishment, exercise, or defense of legal claims, this is done on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the protection and enforcement of our legal interests.
Inclusion in an applicant pool only takes place on the basis of separate consent pursuant to Art. 6 para. 1 lit. a GDPR.
Further information on data processing within the framework of the Personio platform can be found in the privacy policy provided in the respective application process.
Storage Duration for Applications
If no employment relationship is established, we generally delete applicant data no later than six months after completion of the application process.
Longer storage only takes place if you have consented to longer storage, in particular for inclusion in an applicant pool, or if the data is required longer for the establishment, exercise, or defense of legal claims.
In the event of a successful application, the data required for the employment relationship will be transferred to the personnel file and stored in accordance with the applicable statutory and operational retention periods.
12. Validity and Amendment of this Privacy Policy
We adapt this privacy policy if the legal situation, our websites, or the services we use change.
The version published on our websites at any given time is authoritative.
Status: July 3, 2026