I. Information on the Processing of Your Personal Data pursuant to Article 13 of the General Data Protection Regulation (GDPR)

1. Data Controller

The controller within the meaning of Article 4(7) GDPR is:

Thrivard GmbH, Merowingerplatz 1, 40225 Düsseldorf, Germany
represented by its Managing Directors Mathias Huhn and Stephan Vennemann
Phone: +49 211 94218698, Email: info@thrivard.com

2. Data processed for the provision of the website

a. Which data is processed for which purpose?

Whenever content on the website is accessed, data is temporarily stored that may allow identification. The following data is collected in this process:

– Date and time of access

- IP address

- Hostname of the accessing device

- Website from which the website was accessed

- Websites accessed via this website

- Page visited on our website

- Status message indicating whether the request was successful

- Amount of data transferred

- Information about the browser type and version used

- Operating system

The temporary processing of this data is necessary for the operation of a website visit in order to deliver the website. We do not create or store log files. Processing at the hosting provider additionally serves to ensure the functionality of the website and the security of the information technology systems. These purposes also constitute our legitimate interest in processing the data.

b. On what legal basis is this data processed?

The data is processed on the basis of Article 6(1)(f) of the GDPR.

c. Are there recipients of the personal data other than the controller?

This website is hosted by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland (Microsoft Azure). The hosting provider receives the data listed above as a processor under a contract pursuant to Article 28 GDPR. The application is deployed in the Azure region “West Europe” (Netherlands). Content is delivered via Microsoft’s globally distributed edge network; connections may therefore also be terminated at locations outside the European Union.

Access by Microsoft group companies established outside the European Union cannot be entirely ruled out in the context of support and maintenance processes. Microsoft has entered into the EU Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR for this purpose; Microsoft Corporation is additionally certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023).

d. How long is the data stored?

We do not create or store log files. The connection data technically required to deliver the website is processed exclusively by the hosting provider; we have no access to it. The retention period there is determined by the hosting provider. This data is not combined with other data sources and is not evaluated for analytical purposes.

Automated decision-making, including profiling, within the meaning of Article 22 GDPR does not take place.

3. Data you send us by email or telephone

a. Which data is processed for which purpose?

We deliberately do not offer a contact form on this website. If you contact us by email or telephone, we process the data you provide – in particular your name, contact details, company and the content of your enquiry – solely in order to handle your request and to deal with any follow-up questions.

b. On what legal basis is this data processed?

Where your enquiry is aimed at entering into or performing a contract, processing is carried out pursuant to Article 6(1)(b) GDPR. In all other cases we base the processing on Article 6(1)(f) GDPR; our legitimate interest lies in responding to enquiries addressed to our company.

c. How long is the data stored?

We delete the data once your request has been conclusively dealt with and no statutory retention obligations apply. Business correspondence is subject to a retention period of six years as commercial correspondence (Section 257(4) HGB, Section 147(3) AO); where it also constitutes an accounting document, the period is eight years. The data is deleted once the applicable period has expired.

4. Cookies, audience measurement and third-party services

This website does not set cookies and does not use any audience measurement, web analytics or tracking technologies. No information is accessed on your terminal equipment within the meaning of Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act); consent is therefore not required.

No third-party content is loaded. In particular, fonts are served locally from our own server; no connection to third-party servers is established when the website is accessed. The website does not embed map services, video platforms or social media plugins. The reference to our LinkedIn profile is a plain hyperlink; data is only transmitted if you actively click on it.

5. Rights of data subjects

a. Right of access

You may request information pursuant to Article 15 GDPR about your personal data that we process.

b. Right to object

You have the right to object on grounds relating to your particular situation (see Section II).

c. Right to rectification

If the data concerning you is incorrect or no longer accurate, you may request rectification pursuant to Article 16 GDPR. If your data is incomplete, you may request completion.

d. Right to erasure

You may request the deletion of your personal data pursuant to Article 17 GDPR.

e. Right to restriction of processing

You have the right to request restriction of the processing of your personal data pursuant to Article 18 GDPR.

f. Right to lodge a complaint

If you believe that the processing of your personal data violates data protection law, you have the right pursuant to Article 77(1) GDPR to lodge a complaint with a supervisory authority of your choice. This includes the supervisory authority responsible for the controller:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.

g. Right to data portability

If the requirements of Article 20(1) GDPR are met, you have the right to receive data that we process automatically on the basis of your consent or in fulfillment of a contract, either for yourself or for transfer to a third party.

The collection of this data is strictly necessary for the operation of the website. They are therefore not based on consent pursuant to Article 6(1)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR, but are justified pursuant to Article 6(1)(f) GDPR. Accordingly, the requirements of Article 20(1) GDPR are not met in this respect.

II. Right to object pursuant to Article 21(1) GDPR

You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data that is based on Article 6(1)(f) GDPR. The controller will then no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or unless the processing serves the establishment, exercise, or defense of legal claims. The collection of this data is strictly necessary for the operation of the website.

Last updated: September 2026