Privacy policy
Last updated: 6 October 2026 · Version 1.1
1. Controller
The controller responsible for processing personal data on this website and in our business communications is:
Tabernair UG (haftungsbeschränkt), Möhrendorfer Straße 22a, 91056 Erlangen, Germany
represented by its managing director (Geschäftsführer), Martin Stephen
Email: martin_stephen79@tabernair.com · Phone: +49 151 70062826
2. Data protection officer
We have not appointed a data protection officer because we are not legally required to do so. For any data protection question, please contact us using the details above.
3. Overview
We process personal data only as needed to run this website, to produce aggregate usage statistics (section 5), to answer your enquiries (section 7) and for our business outreach by email (section 8). We use no advertising or marketing trackers on this website, and we do not pass your data to anyone for advertising. Your right to object is set out separately in section 14.
4. Website hosting (Framer)
This website is built and hosted with Framer, provided by Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands (“Framer”).
When you visit the site, Framer processes the technical data your browser sends: IP address, date and time of access, page or file requested, referrer URL, browser type and version, operating system, amount of data transferred and status code (server log data). Images, fonts, videos and scripts are delivered from Framer’s servers (framerusercontent.com).
Purpose and legal basis: to deliver the website, keep it stable and secure, and defend it against attacks and misuse. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is a secure, working website.
Processor: Framer processes the data on our behalf under a data processing agreement (Art. 28 GDPR).
Transfers outside the EU: Framer hosts on Amazon Web Services, and the data is also processed on servers in the USA. Transfers rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), where the recipient is certified under it, and otherwise on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Retention: Framer stores this data only for as long as necessary to operate the website securely and to prevent and investigate attacks, and then deletes it. It is kept longer only where needed to investigate a specific security incident.
5. Audience measurement with Framer Analytics
We use Framer’s built-in statistics (“Framer Analytics”) to understand how our website is used, for example page views and visitor numbers, entry and exit pages, referring websites, approximate country, device type, browser and operating system.
To do this, your browser loads a script from events.framer.com. On each page view, it reads the page address (URL), the referring page, and your browser’s time zone, language setting and screen pixel density, and sends them to Framer. To count unique visitors, Framer creates a hash value on its servers from your IP address and browser identifier (user agent), using a key that changes daily and, according to Framer, is deleted every day. No cookies are set and no persistent identifier is stored on your device. We receive only aggregate statistics, from which individual visitors cannot be identified. Framer acts as our processor (see section 4, including on transfers to the USA).
Legal basis: reading the browser information listed above relies on § 25(2) no. 2 of the German TDDDG, and the further processing on Art. 6(1)(f) GDPR; our legitimate interest is designing and improving our website to meet users’ needs.
Objection: you may object at any time (section 14). You can also prevent collection technically by blocking JavaScript from events.framer.com, for example with a tracking blocker.
6. Fonts
The fonts used on this website are embedded locally and delivered from the servers of our hosting provider, Framer (see section 4). No connection is made to Google or any other font provider.
7. Contact by email or phone
If you email or call us, we process your details (such as name, contact details and the content of your enquiry) to deal with your request. Legal basis: Art. 6(1)(b) GDPR where your enquiry is aimed at a contract, and otherwise Art. 6(1)(f) GDPR; our legitimate interest is answering business enquiries.
We use Microsoft 365, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, as our processor for email. This may involve a transfer to the USA, which relies on the EU-US Data Privacy Framework (Art. 45 GDPR) or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
8. Business outreach by email
We contact companies and public bodies whose buildings may be suitable for building-integrated photovoltaics (BIPV) in the façade, by targeted email. This section informs you where we process your data for that purpose without having collected it from you (Art. 14 GDPR).
Categories of data: name, form of address and any academic title, business email address, company or public body, role or area of responsibility, and our correspondence with you (content, date and any reply).
Source: we take these details from publicly available sources, in particular companies’ and public bodies’ websites, legal-notice and contact pages, annual and sustainability reports and press releases, and public professional profiles. Where no personal address is published, we use published function addresses; in some cases we have formed a business email address from the company’s recognisable address pattern.
Purpose: to start a business relationship, specifically a conversation about a possible feasibility study or collaboration on BIPV façade projects; also to correct earlier statements and to keep a record of our correspondence.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is contacting people in their professional capacity for business purposes (direct marketing, see Recital 47 GDPR) and, for corrections, putting inaccurate statements right. If you reply and your request is aimed at a contract, we also process your details under Art. 6(1)(b) GDPR.
How we send: we send these emails individually from our Microsoft 365 mailbox (see section 7). We do not record whether or when you open an email or click a link.
Earlier sending via Resend: until early October 2026 we sent emails, including a message dated 16 September 2026, through the email delivery service Resend, provided by Plus Five Five, Inc., USA. On our behalf, Resend processed your email address and the content of the message and recorded whether the email was delivered and whether it was opened. The transfer to the USA relied on the EU-US Data Privacy Framework (Art. 45 GDPR) and the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). We no longer use Resend for outreach.
Retention: if we receive no reply, we delete your contact details no later than 12 months after our last message, unless a statutory retention duty applies or we need the data to establish, exercise or defend legal claims (Art. 17(3)(e) GDPR); the latter currently applies to correspondence relating to our email of 16 September 2026 and its correction. If your reply leads to a business contact, the periods in section 10 apply.
Objection: you can object to the use of your data for our outreach at any time, without giving reasons (Art. 21(2) GDPR), for example by a short reply to our email; we will then not contact you again. So that we can respect your objection permanently, we keep your name, email address and the date of your objection on a suppression list.
No obligation: you are not obliged to provide us with any data or to reply to our email.
9. Recipients
Within our company, only the people who need your data to deal with it have access to it. External recipients are our processors: Framer (hosting, statistics), Microsoft (Microsoft 365), Resend (earlier email sending, see section 8), and IT and software service providers that support us in organising and handling our communications. Where necessary, we pass data to our tax advisers, lawyers, or to authorities and courts where we are legally required to or where this is needed to establish, exercise or defend legal claims. Where processors transfer data to countries outside the EU/EEA, this happens only on the basis of a European Commission adequacy decision (Art. 45 GDPR) or appropriate safeguards, in particular the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). We do not pass your data to anyone for advertising.
10. Retention
We keep personal data only as long as needed for the relevant purpose:
– Enquiries (email, phone) that do not lead to a business relationship: deleted once the enquiry is fully dealt with, and no later than 24 months after the last contact.
– Enquiries that lead to a business relationship, and commercial correspondence: kept for the statutory periods under German commercial and tax law, in particular § 257 HGB and § 147 AO (usually six years, and eight years for accounting records, each counted from the end of the calendar year).
– Our business outreach and the suppression list: see section 8.
– Server log data: see section 4.
– Statistics (Framer Analytics): see section 5.
In any case, we keep data where and for as long as it is needed to establish, exercise or defend legal claims.
11. Cookies and local storage
We do not use cookies or similar technologies on this website for advertising or marketing. Framer may store technically necessary information in your browser’s local storage, such as your language choice or a technical cache. This storage is strictly necessary to provide the website you are visiting (§ 25(2) no. 2 TDDDG) and is not analysed for statistics or advertising. For Framer Analytics, see section 5.
12. Security
This website uses SSL/TLS encryption (HTTPS). You can recognise an encrypted connection by “https://” in your browser’s address bar.
13. Your rights
Subject to the legal conditions, you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR); this does not affect the lawfulness of processing before the withdrawal. To exercise these rights, contact us using the details in section 1.
Right to complain: you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state where you live or work or where the alleged infringement took place. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
14. Right to object (Art. 21 GDPR)
> You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that is based on Art. 6(1)(f) GDPR (legitimate interests). We will then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
> Where your data is processed for direct marketing – which includes our business outreach by email (section 8) – you may object to that processing at any time, without giving reasons; we will then no longer process your data for that purpose.
> An informal message to martin_stephen79@tabernair.com, or a short reply to our email, is enough.
15. Whether you have to provide data
You are under no legal or contractual obligation to provide personal data. Without the data your browser sends automatically, however, the website cannot be displayed, and without your contact details we cannot answer your enquiry.
16. No automated decision-making
We do not use solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
17. Language versions and changes
This privacy policy is also available in German (Datenschutzerklärung). In case of any discrepancy, the German version prevails. We update this policy when the website, the services we use or the law change; the version published here applies.