Below we inform you in accordance with Art. 13 and Art. 14 of the General Data Protection Regulation (GDPR) about the nature, scope and purpose of the processing of personal data when you visit this website. Personal data means any information relating to an identified or identifiable natural person. The German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG) apply in addition.
This privacy policy applies to the web presence of Integraleaf GmbH at integraleaf.com.
The controller within the meaning of Art. 4(7) GDPR is:
Integraleaf GmbH
Scheidter Straße 27
66123 Saarbrücken
Germany
Represented by the Managing Director: Julian Vaterrodt
Email: it@integraleaf.de
For all data protection matters and to exercise your rights, you can reach us at the address above or at it@integraleaf.de.
Some of your data is collected because you provide it to us yourself by sending us an email. No contact form is used on this website.
In addition, the web server automatically records technical access data in server log files when the website is requested. This is technically necessary in order to deliver the pages.
We process your data solely in order to provide this website technically, to ensure its stability and security, and to handle your enquiries.
Your usage behaviour is not analysed. We do not create usage profiles, we do not carry out tracking and we do not use advertising networks. Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.
You have the right to obtain information free of charge at any time about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you may revoke this consent at any time with effect for the future. In addition, you have the right to request the restriction of the processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority. You may contact us at any time regarding this and any further questions on the subject of data protection.
This website does not set any cookies. Nor does it use comparable techniques for storing information on your device, in particular no local storage, no session storage and no fingerprinting. No access to information stored on your device within the meaning of § 25 TDDDG takes place. A consent banner is therefore not required.
No analytics, statistics, tracking or advertising services are integrated. In particular, the pages contain no scripts from Google Analytics, Google Tag Manager, Matomo, Meta / Facebook or comparable providers.
Only fonts already present on your device (system fonts) are used to display text. External fonts such as Google Fonts or Adobe Fonts are not loaded.
The page logo and the website icon (favicon) are embedded directly in the source code of the pages. The stylesheet is delivered from our own server. Content delivery networks are not used. The pages contain no embedded third-party content, in particular no iframes, no map services, no video players and no social network buttons.
This website is hosted by an external service provider:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
The purpose of the processing is to store the website files and to deliver the pages to your browser. In doing so, the provider processes all data required for technical provision, in particular access data and IP addresses. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure, stable and economically reasonable provision of our online offering.
The provider acts as a processor. A data processing agreement pursuant to Art. 28 GDPR is in place. According to the provider, the servers are located in data centres in Germany. No transfer of personal data to a third country outside the EU or the EEA takes place in the course of hosting.
Each time a page is requested, the web server automatically collects and stores information in server log files which your browser transmits. These are:
The purpose of the processing is the technical delivery of the pages, safeguarding system security and stability, and investigating and preventing attacks and misuse. The legal basis is Art. 6(1)(f) GDPR. This data is not merged with other data sources and is not evaluated for marketing purposes.
Storage period: according to our hosting provider, log data is stored only for a short time, as a rule a few days and for a maximum of 60 to 90 days depending on the specific security or operational need, and is then deleted. Individual records are retained for longer only where this is necessary to investigate a specific security incident; the data concerned is then kept until the investigation has been completed.
This website is delivered exclusively via an encrypted HTTPS connection. The TLS certificates required for this are provided via our hosting provider. The legal basis is Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR.
No contact form is used on this website. Contact is made via the email addresses provided and, where applicable, by telephone.
If you contact us, we process the data you provide to us in doing so. As a rule this is:
The purpose of the processing is to handle and answer your enquiry and any follow-up questions.
The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry serves the initiation, conclusion or performance of a contract. For all other enquiries the legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in responding to matters addressed to us.
Storage period: we delete your enquiry as soon as the purpose of storage no longer applies, i.e. as a rule once it has been dealt with, and at the latest when you ask us to delete it or revoke any consent given. Where the correspondence is subject to a statutory retention obligation, in particular as a commercial or business letter under § 257 of the German Commercial Code (HGB) or as a tax-relevant record under § 147 of the German Fiscal Code (AO), we retain it for the period prescribed there of six or ten years respectively and restrict processing during that time to fulfilling the retention obligation.
We use Microsoft 365 (Exchange Online) to operate our email accounts. The provider for customers in the European Economic Area is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
The purpose of the processing is the receipt, dispatch, storage and filtering of business email correspondence, including spam and malware protection. The legal basis is Art. 6(1)(b) GDPR for contract-related correspondence and otherwise Art. 6(1)(f) GDPR. The provider acts as a processor; processing is based on a data processing agreement pursuant to Art. 28 GDPR. The storage period corresponds to the period stated above for the respective correspondence.
Third-country transfer: according to the provider, processing for customers in the European Union takes place primarily in data centres within the EU. Access by the provider’s group companies in third countries, in particular in the United States, cannot however be ruled out. In that case the transfer is based on the European Commission’s adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework, under which Microsoft Corporation is certified. In addition, the provider has agreed the European Commission’s standard contractual clauses pursuant to Art. 46(2)(c) GDPR, which continue to apply as a basis for transfers.
This website contains references to external offerings, namely to our company profile on LinkedIn and to the website cannabis-consulting.eu. These are simple hyperlinks only. Plugins, buttons or other embeds of social networks are not used.
Accordingly, no data is transmitted to the operators of the linked offerings when this website is loaded. Data is only transmitted once you actively click a link and open the target page. From that point on, the privacy policy of the respective provider applies, whose processing is beyond our control.
We only pass on personal data to the processors named in this policy, i.e. our hosting provider and our email service provider. Disclosure to further third parties only takes place if you have consented, if we are legally obliged to do so, or if disclosure is necessary for the establishment, exercise or defence of legal claims. Data is not sold.
Providing your data is neither legally nor contractually required. However, without contact details we cannot answer an enquiry.
Many data processing operations are only possible with your express consent. You may revoke consent already given at any time. The lawfulness of the data processing carried out up to the point of revocation remains unaffected by the revocation.
WHERE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT TO PROCESSING FOR DIRECT MARKETING PURPOSES, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE PROCESSED FOR THESE PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
You have the right to request information about the personal data we process concerning you. This right covers in particular information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the envisaged storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, and the existence of automated decision-making including profiling and, where applicable, meaningful information about the details thereof.
You have the right to request without undue delay the rectification of inaccurate personal data or the completion of incomplete personal data stored by us.
You have the right to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.
You have the right to request the restriction of the processing of your personal data if
You have a right to data portability under Art. 20 GDPR, meaning that you can receive the personal data we hold about you in a structured, commonly used and machine-readable format, or request its transmission to another controller.
You have the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority in the member state of your habitual residence, your place of work or the place of the alleged infringement.
The supervisory authority responsible for us is:
Unabhängiges Datenschutzzentrum Saarland
Fritz-Dobisch-Straße 12
66111 Saarbrücken, Germany
Telephone: +49 681 94781-0
Fax: +49 681 94781-29
Email: poststelle@datenschutz.saarland.de
Internet: www.datenschutz.saarland.de
In order to protect all personal data transmitted to us and to ensure that data protection provisions are complied with by us as well as by our external service providers, we have implemented appropriate technical and organisational security measures pursuant to Art. 32 GDPR. For this reason, among others, all data is transmitted between your browser and our server via an encrypted TLS connection.
We update this privacy policy whenever the services used on this website, the actual processing operations or the legal requirements change. The version available on this page applies in each case.
Last updated: 27 August 2026