Controller
For the current public website and Contact channel, the controller is:
Juan Dario Perez Olaverria
AEMISA
Altenburger Straße 32
04275 Leipzig
Germany
Email: contact@aemisa.com
No Data Protection Officer is designated in this Release 1 notice.
What the current website processes
Website and Cloudflare
The website runs on Cloudflare Workers with Cloudflare DNS, security/network services and native observability. Technical request and security data may be processed to deliver, protect and operate the website. This can include request metadata such as IP address, browser and security-event information handled by the Cloudflare service.
Cloudflare describes its network metadata processing and international data-transfer framework in its GDPR information and Data Processing Addendum. Processing is not represented as exclusively located in Germany.
Contact form
The Contact form contains:
- reply email — required;
- name — optional;
- capability/topic — optional;
- message — required.
The current flow is: browser → AEMISA Contact endpoint → Resend → contact@aemisa.com mailbox at IONOS. There is no AEMISA Contact database, CRM, application-side Contact history, account or support-ticket system. Email delivery data exists in the provider and mailbox systems involved in delivery.
Purpose, legal basis and retention
Contact processing is used to understand and answer an inquiry. For an inquiry aimed at discussing or preparing a possible service relationship, processing may rely on Article 6(1)(b) GDPR where it is necessary for steps taken at the visitor’s request before a contract. For a general inquiry that is not covered by that basis, processing may rely on Article 6(1)(f) GDPR for the legitimate interest of responding to a legitimate communication addressed to AEMISA. Not every submission is treated as contractual.
Contact communications are retained only as long as reasonably necessary to handle the inquiry, manage any resulting relationship and comply with applicable legal obligations. No fixed deletion period is promised because messages can remain in the controlled mailbox and provider systems according to their service and legal requirements.
The current site does not use Google Analytics, Meta Pixel, advertising analytics, marketing trackers, advertising identifiers or fingerprinting. Contact messages are not used for marketing mail and the implementation does not send an auto-reply. Open and click tracking are not intentionally enabled for AEMISA Contact delivery.
Language preference storage
The browser’s navigator.languages / navigator.language values are used for initial locale selection. An explicit language choice is remembered in localStorage under aemisa.locale. This is functional preference storage requested by the visitor; it is not an advertising identifier, analytics identifier or marketing cookie. The current implementation does not use a cookie-consent banner solely for this strictly functional preference.
Providers, rights and supervisory authority
Resend and IONOS
Resend is used for server-to-server transactional email delivery. The visitor’s email is preserved as Reply-To. Resend states that customer data, including message content and delivery logs, is stored in the United States, and that an Article 28 GDPR Data Processing Addendum is in force for accounts. The relevant transfer safeguards are described in Resend’s GDPR information and Data Processing Addendum.
IONOS is used as the controlled mailbox service that receives Contact messages at contact@aemisa.com. IONOS is not the host of the public website. IONOS explains that email storage keeps incoming and sent email data in the mailbox service; see its email storage information.
Subject to the GDPR requirements and limitations that apply to a request, data subjects may have rights of access, rectification, erasure, restriction, objection and data portability where applicable. A complaint may be made to a competent supervisory authority.
The supervisory authority for the controller’s establishment in Leipzig is the Sächsische Datenschutz- und Transparenzbeauftragte:
Sächsische Datenschutz- und Transparenzbeauftragte
Postfach 11 01 32
01330 Dresden
Germany
post@sdtb.sachsen.de
The official contact page provides the current authority contact details and complaint routes.