Cedra
DE

Privacy notice

Last updated: July 2026

This is a courtesy translation. The legally binding version is the German original.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Ricardo Giuseppe Mier Castiglione
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen, Germany
Email: contact@cedra-os.com

Legal notice: https://cedra-os.com/en/impressum

2. General information and SSL/TLS encryption

This notice explains which personal data are collected, processed and stored when you visit and use this website, and which rights you have as a data subject. Personal data are all information relating to an identified or identifiable natural person (Art. 4 (1) GDPR) — in particular name, email address and IP address.

This website uses SSL/TLS encryption. You can recognise an encrypted connection by the prefix “https://” and the padlock symbol in your browser’s address bar.

3. Hosting and processing on our behalf

This website is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA.

In the course of hosting, Netlify processes data that arise when the website is accessed — in particular IP address, date and time of access, requested URL, volume of data transferred, HTTP status code, referrer and browser used (server log files). These data are required for the technical operation of the website and are automatically deleted by the hosting provider after a short period.

Netlify also processes the data submitted via the contact form (see section 5), as form submissions are handled and stored through Netlify’s infrastructure.

Legal basis: Art. 6 (1) (f) GDPR. The legitimate interest lies in providing a technically stable, secure and permanently available website.

Processing agreement: A data processing agreement pursuant to Art. 28 GDPR is in place with Netlify, Inc. Netlify processes the data solely on the controller’s instructions and not for its own purposes.

Third-country transfer: As Netlify, Inc. is based in the USA, data are transferred to a third country. The transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (DPF) of July 2023 and, additionally, on Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. Netlify is certified under the EU-US Data Privacy Framework.

4. Cookies and comparable technologies

This website uses no cookies and no tracking technologies. Only your chosen display setting (light or dark mode) is stored locally in your browser (local storage, key “cedra-theme”). This entry does not leave your device, is not transmitted and is not evaluated. It is strictly necessary in order to provide the function you explicitly requested (§ 25 (2) no. 2 TDDDG) and therefore does not require consent. No consent management tool is required.

5. Contact form (Netlify Forms)

This website provides a contact form through which visitors can send a message to the controller. Transmission and storage of form submissions is handled by Netlify Forms, a service of the hosting provider Netlify, Inc.

The following data are processed: name (voluntary), email address (voluntary), message text.

Providing a name and email address is voluntary. If you provide them, they are used solely to handle and reply to your enquiry. They are not passed on to third parties outside the processing relationship with Netlify.

Spam protection: A honeypot field is used — a form field invisible to human users that automated bots typically fill in. Submissions in which this field is filled are discarded as spam. No external service (e.g. reCAPTCHA) is used.

Legal basis: Art. 6 (1) (f) GDPR. The legitimate interest lies in receiving, handling and answering incoming enquiries.

Storage period: The data are deleted once the enquiry has been conclusively dealt with and no statutory retention obligations prevent deletion.

Recipients and third-country transfer: Form submissions are stored and processed on servers of Netlify, Inc. (USA). The safeguards described in section 3 apply.

6. Fonts and media files

This website uses the typeface “Jost”. The font files are served exclusively from our own web server. No connection is established to external font services (e.g. the Google Fonts API). No transmission of your IP address or other data to third parties takes place in connection with the typeface.

Audio files are likewise served directly from the hosting server. No external streaming services or third-party providers are embedded.

7. Analytics, tracking and advertising

This website uses no analytics, tracking or advertising services. No social media plugins, no external ad networks and no third-party counters or statistics services are embedded.

8. Storage periods and deletion

Personal data are deleted or blocked as soon as the purpose of storage ceases to apply. Storage beyond that occurs only where statutory retention obligations require it.

9. Third-country transfers

In the course of hosting and the processing of contact form entries, data are transferred to Netlify, Inc. in the USA. The USA is a third country within the meaning of Art. 44 et seq. GDPR.

Recipient: Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA. Purpose: hosting of the website and processing of data submitted via the contact form.

10. Your rights

As a data subject you have the following rights vis-à-vis the controller: right of access (Art. 15 GDPR), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21) and the right to withdraw consent at any time with effect for the future (Art. 7 (3)).

Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR. The controller will then no longer process the personal data unless compelling legitimate grounds for the processing can be demonstrated which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

To exercise your rights, please contact the controller at contact@cedra-os.com.

11. Right to lodge a complaint

Pursuant to Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.

The competent authority for the controller is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
Website: https://www.lda.bayern.de

You may also contact the supervisory authority of your habitual residence or place of work.

12. Automated decision-making and profiling

No automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR takes place on this website.

13. Changes to this privacy notice

This privacy notice is dated July 2026. Further development of this website or changed legal requirements may make it necessary to update it. The current version is always available at https://cedra-os.com/en/datenschutz.