Privacy policy

‍1. Controller

The controller responsible for data processing on this website is:

ENDMARK GmbH
Lindenallee 24
50968 Cologne, Germany

Represented by the Managing Directors: Dr. Bernd M. Samland and Christine Stark

Phone: +49 221 942033 0
Email: info@endmark.de

‍

‍2. General information on data processing

What this is about

Thank you for visiting our website and for your interest in our company. Protecting your personal data is important to us. Personal data is any information that can be related to you as a person, such as your name, address, phone number or email address. This policy explains which data we collect when you visit our website and how we use it.

In principle, you can visit our website without providing any personal data. For technical reasons, however, certain data is generated, which is described in the following sections.

Legal bases

If you have given your consent, we process your data on the basis of Art. 6(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device, Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) also applies. You can withdraw your consent at any time with effect for the future.

If we need your data to perform a contract or to take steps prior to entering into a contract, Art. 6(1)(b) GDPR applies. If processing is necessary to comply with a legal obligation, Art. 6(1)(c) GDPR applies. Processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR. The legal basis that applies in each case is stated in the relevant sections.

Purpose limitation and disclosure

We only use your data for the purposes for which you provided it, i.e., to handle inquiries and, where applicable, to perform contracts. We only use it for further purposes, such as sending information about our services by newsletter, with your separate consent.

We only disclose personal data to third parties if this is necessary for a contract, if we are legally obligated to do so, if there is a legitimate interest under Art. 6(1)(f) GDPR, or if another legal basis permits it. We only share data with processors on the basis of a valid data processing agreement.

Storage period

We only store your data for as long as is necessary for the respective purpose or required by law. If you justifiably request erasure or withdraw your consent, we will delete your data unless there are other legally permissible reasons for storing it, such as retention periods under tax or commercial law. In that case, we will delete the data as soon as these reasons no longer apply.

Transfers to third countries

We use services provided by companies based in the USA. For recipients certified under the EU-U.S. Data Privacy Framework (DPF), the European Commission has determined an adequate level of data protection. For recipients without certification, we base the transfer on the European Commission’s standard contractual clauses. The recipients concerned are listed under the respective services.

‍

‍3. Hosting and content delivery networks

Our website content is hosted and delivered by the following providers.

Webflow

The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (hereinafter Webflow). Webflow collects log files, including your IP address, every time you visit. The log files are only stored for as long as is necessary to operate the website securely and to defend against attacks, after which they are automatically deleted or anonymized.

Webflow is a system for building and hosting websites. It uses cookies or similar technologies that are necessary to display the site, provide individual functions, and ensure security (necessary cookies). Further details can be found in Webflow’s privacy policy: https://webflow.com/legal/eu-privacy-policy.

We use Webflow on the basis of Art. 6(1)(f) GDPR. Our legitimate interest is the reliable presentation of our website. We set the necessary cookies on the basis of Section 25(2) No. 2 TDDDG.

For transfers to the USA, we rely on the European Commission’s standard contractual clauses; see https://webflow.com/legal/eu-privacy-policy. Webflow is also certified under the DPF: https://www.dataprivacyframework.gov/participant/6365

Data processing agreement

We have concluded a data processing agreement with Webflow. It ensures that Webflow processes our visitors’ data only in accordance with our instructions and in compliance with the GDPR.

Cloudflare

We use the Cloudflare service provided by Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter Cloudflare).

Cloudflare operates a globally distributed content delivery network including DNS. Data traffic between your browser and our website is routed through Cloudflare’s network. This allows Cloudflare to analyze the traffic and filter out malicious requests from the internet. Cookies or similar recognition technologies may be used for this purpose only.

This is based on our legitimate interest in providing our website securely and without disruption (Art. 6(1)(f) GDPR). Transfers to the USA are based on the European Commission’s standard contractual clauses. Further information is available at https://www.cloudflare.com/privacypolicy/. Cloudflare is certified under the DPF: https://www.dataprivacyframework.gov/participant/5666

Amazon CloudFront

We use the content delivery network Amazon CloudFront provided by Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg (hereinafter Amazon).

CloudFront is a globally distributed delivery network. Data exchanged between your browser and our website is routed through it, which improves the availability and performance of the site.

The legal basis is our legitimate interest in providing our website securely and without disruption (Art. 6(1)(f) GDPR). Transfers to the USA are based on the European Commission’s standard contractual clauses: https://aws.amazon.com/blogs/security/aws-gdpr-data-processing-addendum/. Further information: https://aws.amazon.com/privacy/. Amazon is certified under the DPF: https://www.dataprivacyframework.gov/participant/5776

‍

4. Access data and cookies

Access data (log files)

When this website or individual files are accessed, Webflow (our host) collects the following data: IP address, the page from which the file was requested, file name, date and time of access, amount of data transferred, and notification of successful retrieval. We use this access data only in non-personalized form to continuously improve our website and for statistical purposes. The legal basis is Art. 6(1)(f) GDPR.

Cookies

Our pages use cookies. These are small text files that your browser stores on your device. They are stored either only for the duration of a session (session cookies) or permanently (persistent cookies). We use cookies to make your visit to our website more convenient and to enable certain functions. Other cookies are used to analyze user behavior or for advertising.

We set cookies that are technically necessary for the communication process or for functions you have requested (necessary cookies) without consent (Section 25(2) No. 2 TDDDG and Art. 6(1)(f) GDPR). We only set all other cookies and similar technologies with your consent (Section 25(1) TDDDG and Art. 6(1)(a) GDPR). You can withdraw your consent at any time.

You can configure your browser to notify you about cookies, to allow cookies only in individual cases, to block them for certain cases or in general, and to delete them automatically when you close the browser. If cookies are disabled, the website may not function fully. You can see which cookies are set in the cookie banner settings and in this policy.

Consent management with Cookiebot

To obtain and document your decisions on cookies and similar technologies, we use the consent solution Cookiebot. The provider is Usercentrics A/S (formerly Cybot A/S), Havnegade 39, 1058 Copenhagen, Denmark (hereinafter Cookiebot).

When you access our website, your browser connects to Cookiebot’s servers to obtain your consent and other declarations regarding the use of cookies. This may involve processing your truncated IP address, information about your browser and device, and the time of your decision. Cookiebot then stores a cookie in your browser so that your decision or its withdrawal can be assigned to you. The data is stored until you ask us to delete it, delete the cookie yourself, or the purpose of storage no longer applies. Mandatory statutory retention obligations remain unaffected. You can change or withdraw your selection at any time.

We use Cookiebot to obtain the consents for cookies required by law. The legal basis is Art. 6(1)(c) GDPR.

‍

5. Inquiries, forms, and marketing automation

Contact by email or phone

If you contact us by email or phone, we store and process your inquiry, including the personal data it contains (for example, your name), in order to respond to your request. We do not pass this data on without your consent unless we are legally obligated to do so.

The legal basis is Art. 6(1)(b) GDPR if your inquiry relates to a contract or concerns pre-contractual measures. In all other cases, processing is based on our legitimate interest in handling inquiries effectively (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if we have asked for it. We keep the data until you request its erasure, withdraw your consent, or the purpose no longer applies, for example once your request has been handled. If your inquiry leads to a project, we also use your details to carry it out. Statutory retention periods remain unaffected.

Forms on our website

On our website, you can use forms to contact us, request a quote, obtain quotes for trademark searches and linguistic checks, complete our brand profile check (Profil-Check Marke), or send us a briefing. In doing so, we collect the details you enter, for example, your first and last name, your company, and your email address. We use them to process your inquiry, to contact you, and to prepare a quote.

Form entries are transmitted to and stored in our marketing automation system SharpSpring (see below). We do not pass them on beyond this without your consent.

The legal basis is Art. 6(1)(b) GDPR if your inquiry relates to a contract or concerns pre-contractual measures. Otherwise, processing is based on our legitimate interest in handling inquiries effectively (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR). We keep your details until you request their erasure, withdraw your consent, or the purpose no longer applies, for example once your inquiry has been handled. If your inquiry leads to a project, we also use your details to carry it out. Statutory retention periods remain unaffected.

SharpSpring

We use the SharpSpring service. The provider is SharpSpring, Inc., 550 SW 2nd Avenue, Gainesville, FL 32601, USA (hereinafter SharpSpring), a Constant Contact company.

SharpSpring is a marketing automation solution that we use for contact management and email marketing. All details you enter in our forms are transmitted to and stored by SharpSpring. Using a tracking script, SharpSpring can also set cookies and record and analyze user behavior on our website, for example, which pages you visit.

We only use tracking with your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). The processing of your form entries is based on our legitimate interest in handling inquiries effectively and in service-oriented marketing measures (Art. 6(1)(f) GDPR) or on your consent. You can withdraw your consent at any time.

Transfers to the USA are based on the European Commission’s standard contractual clauses and, where the provider is certified, on the DPF. We have concluded a data processing agreement with SharpSpring. More on data protection: https://www.constantcontact.com/legal/privacy-notice.

Appointment booking via Cal.com

On some pages, we use embedded calendars to make booking appointments easier. For this, we use the Cal.com service. The provider is Cal.com, Inc., 340 S Lemon Ave 4133, Walnut, CA 91789, USA (hereinafter Cal.com).

When you book an appointment, you enter the requested details and your preferred time. This data is transmitted to and processed by Cal.com. We only use it to contact you and coordinate the appointment.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). Transfers to the USA are based on the European Commission’s standard contractual clauses or on Cal.com’s certification under the DPF. More in Cal.com’s privacy policy: https://cal.com/privacy.

Newsletter

On our website, you can sign up for news on naming, brand language, and brand security, for example by checking the box in the contact form. For this, we need your email address and, where applicable, your name. SharpSpring handles sending the newsletter and managing the mailing list. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future, for example via the unsubscribe link in every newsletter or by emailing us. We store your data until you unsubscribe and then delete it. We reserve the right to keep your email address on a suppression list to prevent you from being contacted again (Art. 6(1)(f) GDPR).

In our newsletters, we measure whether and when they are opened and which links you click. For this purpose, the emails contain a small tracking pixel and personalized links. The analysis helps us tailor content and topics more closely to your interests. It is part of your consent to the newsletter. By unsubscribing, you also withdraw your consent to this analysis.

‍

6. Analytics and advertising

We only use the following services if you have given your consent in the cookie banner.

Google Analytics 4

We use the web analytics service Google Analytics 4 provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter Google). It is integrated via the Google tag (gtag.js).

Google Analytics enables us to analyze visitor behavior. We receive various usage data, such as page views, time spent on the site, operating systems used, and visitors’ origin. This data is assigned to the respective device, but not to a user ID. Google Analytics also uses modeling to supplement the data sets and applies machine learning in its analysis. For this purpose, it uses technologies that allow recognition, such as cookies or device recognition. According to Google, IP addresses are not logged or stored in Google Analytics 4. The information collected is generally transferred to a Google server in the USA and stored there.

The legal basis is your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). You can withdraw it at any time. Transfers to the USA are based on the European Commission’s standard contractual clauses: https://privacy.google.com/businesses/controllerterms/mccs/. Google is certified under the DPF: https://www.dataprivacyframework.gov/participant/5780

You can prevent Google from collecting data by installing the browser add-on available at https://tools.google.com/dlpage/gaoptout?hl=en. More on how Google Analytics handles user data: https://support.google.com/analytics/answer/6004245?hl=en.

Leadinfo

We use the Leadinfo service provided by Leadinfo B.V., Rotterdam, Netherlands. Leadinfo recognizes visits by companies to our website based on IP addresses and shows us publicly available information about them, such as company names or addresses. In addition, Leadinfo sets two cookies under our own domain (first-party cookies) to analyze user behavior on our website. Leadinfo also processes the domain of email addresses you enter in forms (for example, “company.com” from “name@company.com”) in order to match IP addresses to companies and to improve its own services.

We only use Leadinfo with your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). You can withdraw it at any time. You can also opt out of data collection here: https://www.leadinfo.com/en/opt-out. Leadinfo will then no longer collect your data. More about Leadinfo: https://www.leadinfo.com/en/.

LinkedIn Insight Tag

We use the LinkedIn Insight Tag. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (hereinafter LinkedIn).

Through the Insight Tag, LinkedIn provides us with aggregated, anonymous statistics on the professional characteristics of visitors who are logged in to LinkedIn in the same browser, such as seniority, company size, country, industry, and job title. This helps us tailor our website to target groups. We can also measure whether visitors take a particular action (conversion tracking), including across devices, and use the retargeting function to show targeted ads outside our website. According to LinkedIn, the recipients of these ads are not identified.

LinkedIn also collects log data such as the URL, referrer URL, IP address, device and browser properties, and the time of access. According to LinkedIn, IP addresses are truncated or hashed. Direct identifiers of LinkedIn members are deleted after seven days, and the remaining pseudonymized data within 180 days. We cannot attribute the data collected by LinkedIn to individual persons. LinkedIn stores the data on servers in the USA and uses it for its own advertising.

The legal basis is your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). You can withdraw it at any time. Transfers to the USA are based on the European Commission’s standard contractual clauses: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs. LinkedIn is certified under the DPF: https://www.dataprivacyframework.gov/participant/5448

You can object to analysis and targeted advertising by LinkedIn here: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. LinkedIn members can also control the use of their data for advertising purposes in their account settings. To prevent data from being linked to your LinkedIn account, log out of LinkedIn before visiting our website.

‍

7. Social networks

Our website links to our profiles on Facebook, LinkedIn, YouTube, and Instagram. These are simple links. Your browser only connects to the respective network when you click on a link. The network then learns that you came from our website and your IP address. If you are logged in there, it can associate the visit with your account. We have no knowledge of the content of the transmitted data or how it is used. Further processing is the responsibility of the respective provider.

Facebook and Instagram are provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. YouTube is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For more information, see the providers’ privacy policies: https://www.facebook.com/privacy/explanation, https://privacycenter.instagram.com/policy/ and https://policies.google.com/privacy?hl=en.

‍

8. Data security and email communication

We protect your personal data during collection, storage, and processing through technical and organizational measures so that it is not accessible to third parties. We cannot guarantee complete data security for communication by email. For information requiring a high level of confidentiality, we recommend sending it by mail.

SSL and TLS encryption

For security reasons and to protect confidential content, such as inquiries you send to us, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the browser’s address bar changing from “http://” to “https://” and by the padlock icon. When encryption is active, third parties cannot read the data you send to us.

‍

9. Your rights

You have the right at any time to obtain information free of charge about your stored data, its origin, its recipients, and the purpose of processing. You can request rectification or erasure. You also have the right to restriction of processing, to data portability, and to object to processing. You can withdraw any consent you have given at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.

Your right to object under Art. 21 GDPR

If we process your data on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation. This also applies to profiling based on these provisions. If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims (objection under Art. 21(1) GDPR).

If we process your data for direct marketing purposes, you have the right to object at any time to processing for such marketing. This also applies to profiling to the extent that it is related to direct marketing. If you object, we will no longer use your data for direct marketing purposes (objection under Art. 21(2) GDPR).

If something isn’t right

You can file a complaint about us with a data protection supervisory authority at any time. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW). You can contact it regardless of where you live. Within the EU, you can also contact the authority of the member state in which you live or work.

For requests regarding access, erasure, or rectification, and for any suggestions, you can reach us at info@endmark.de or via the contact details in section 1.

Last updated: October 2026