Legal
Privacy policy
Thank you for visiting hi-brands.de. Protecting your personal data matters to us. This page explains which data is processed when you visit our website, for what purpose and on what legal basis.
Controller
hi brands GmbH
Rollnerstraße 110b
90408 Nürnberg, Germany
+49 911 928929-0
hi@hi-brands.de
You can reach our data protection officer at:
Datenschutzdoktor Rechtsanwaltsgesellschaft mbH
Arndtstraße 4, 90419 Nürnberg, Germany
+49 911 133 499 12
info@datenschutzdoktor.de
1. Hosting and server log files
This website is hosted on a server in Germany operated by us. When you open a page, your browser automatically transmits data that is stored in server log files: IP address, date and time of access, page accessed, amount of data transferred, HTTP status code, referring page (referrer), browser type and version, and operating system.
This data is technically necessary to display the website to you and to ensure secure operation. The legal basis is Art. 6 (1) (f) GDPR. The log files are deleted after 14 days at the latest, unless they are needed to investigate a security incident.
2. Cookies
Our website uses only technically necessary cookies: a session cookie and a cookie that protects the contact form against abusive submissions (CSRF protection). Neither contains personal data, neither is used for analytics or advertising, and both are deleted when you close your browser or after a short time. The legal basis is Art. 6 (1) (f) GDPR in conjunction with § 25 (2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act). No consent is required for this. We do not use any analytics, tracking or marketing cookies.
3. Contact form and applications
When you write to us via the contact form, we process the data you enter: subject, name, email address, message and – where you provide them – company, phone number, website, budget range, desired position and uploaded files. The information is stored in our content management system and forwarded by email to the responsible contacts at hi brands.
For sending email we use Microsoft 365 provided by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. A data processing agreement is in place with Microsoft; where data is transferred to third countries, this is done on the basis of the EU standard contractual clauses and the EU-US Data Privacy Framework.
The legal basis for enquiries is Art. 6 (1) (b) GDPR (initiation or performance of a contract) or Art. 6 (1) (f) GDPR (our legitimate interest in answering your enquiry). For applications the legal basis is § 26 (1) BDSG (German Federal Data Protection Act). We delete enquiries as soon as they have been dealt with and no statutory retention obligations apply. We delete application documents no later than six months after the application process has ended, unless you have consented to longer storage.
Alternatively, you can reach us at any time by email or phone. In that case, too, we store your details only for as long as is necessary to deal with your request.
4. Fonts (Adobe Fonts)
For consistent display of fonts we use Adobe Fonts provided by Adobe Systems Software Ireland Ltd., 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. When you open a page, your browser loads the required font files from Adobe servers. In doing so, your IP address is transmitted to Adobe. According to Adobe, no cookies are set for this purpose. The use is based on our legitimate interest in a consistent and appealing presentation of our website, Art. 6 (1) (f) GDPR. Further information: Adobe Fonts privacy notice.
5. Map (OpenStreetMap)
On pages with a contact section we show our location on a map by OpenStreetMap. The map tiles are only loaded once the map area is scrolled into view. In doing so, your IP address is transmitted to servers of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom. An adequacy decision by the EU Commission exists for the United Kingdom. The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in a clear presentation of how to reach us. Further information: OpenStreetMap Foundation privacy policy.
Clicking the map opens our location in Google Maps in a new window. Only then is data transmitted to Google; Google’s privacy policy applies.
6. Videos and images
All videos and images on this website are stored on our own server. No data is transmitted to third parties during playback.
7. Links to social networks
We link to our profiles on LinkedIn, Instagram and Facebook. These are simple links without embedded plugins. Data is only transmitted when you click a link; the privacy policy of the respective provider then applies.
8. SSL encryption
This website uses SSL/TLS encryption throughout. Data you transmit to us cannot be read by third parties.
9. Your rights
With regard to the personal data concerning you, you have the following rights towards us: the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing (Art. 21 GDPR). Where processing is based on your consent, you may withdraw it at any time with effect for the future. Simply contact us using the details given above.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany.
10. Objection to advertising emails
Under the statutory imprint obligation we are required to publish our contact details. We hereby object to the use of these contact details for sending unsolicited advertising.
Last updated
September 2026. We will adapt this policy when the website or the legal situation changes.