Compliance and security are foundational for us - ensuring your integrations meet the highest standards.
Last updated: 08.04.2026
This privacy notice provides information, pursuant to Article 13 of the General Data Protection Regulation (GDPR), on the processing of personal data in connection with the use of the website www.maesn.com (hereinafter "Website") by Maesn GmbH as the controller. Maesn GmbH processes personal data strictly to the extent necessary for the provision, security, and operation of the Website and its services, adhering to the principle of data minimization. "Personal data" within the meaning of Article 4(1) GDPR refers to any information relating to an identified or identifiable natural person (data subject), such as name, address, telephone number, date of birth, email address, or IP address. Information that cannot be linked to a specific individual, for example as a result of anonymization, is not considered personal data.
The controller for the processing of personal data on the website within the meaning of the General Data Protection Regulation (GDPR) is:
Maesn GmbH
Kasernenstraße 67
40213 Düsseldorf
Germany
For data protection inquiries or to exercise your data subject rights, please contact privacy@maesn.com.
The following person has been appointed as Data Protection Officer:
Kertos GmbH
Brienner Straße 41
80333 Munich
Germany
Email: dsb(at)kertos.io
Purpose of processing:
We process your data in order to:
Recipients:
Data processed:
Legal basis: Article 6(1)(f) GDPR. The processing of the specified data is necessary to provide the website and to ensure secure and user-friendly operation.
Retention period: The collected data will be deleted as soon as it is no longer required for the operation of the website, but no later than 30 days, unless a statutory retention obligation applies.
Third-country transfer: Hosting takes place exclusively on servers located in Germany.
Further information: https://www.strato.de/datenschutz/; https://webflow.com/legal/privacy
Purpose: Accelerating and optimizing the delivery of content on our Website through a content delivery network (CDN).
Recipients: Amazon Web Services, Inc. (AWS), One Burlington Plaza, Burlington Road, Dublin 4, D04 RH96, Ireland; Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA.
Data processed:
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in improving website performance and ensuring reliable content delivery.
Retention period: Access logs are deleted as soon as they are no longer required for operational and security purposes, but no later than 30 days, unless a statutory retention obligation applies.
International data transfer: For data transfers to the United States, there is an adequacy decision by the European Commission under the EU-U.S. Data Privacy Framework. AWS is certified under this framework; accordingly, such transfers are based on Article 45 GDPR.
Further information: https://aws.amazon.com/de/privacy/
Purpose: Display of website content and fonts.
Recipients: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Data processed:
Lawful basis: Legitimate interest pursuant to Article 6(1)(f) GDPR in ensuring a technically secure, consistent, and attractive presentation of content and fonts.
Retention period: The data are deleted as soon as the purpose of display has been achieved.
International data transfer: Data may be transferred to servers in the United States. Google is certified under the EU-U.S. Data Privacy Framework, so transfers may be based on Article 45 GDPR. In addition, Standard Contractual Clauses (SCCs) are in place with Google.
Further information: https://policies.google.com/privacy
Purpose: Sending email newsletters to inform about products, services, and company activities.
Recipients: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland.
Data processed:
Lawful basis: Consent pursuant to Article 6(1)(a) GDPR.
Retention period: Data will be stored for as long as you are subscribed to the newsletter. After you unsubscribe, your data will be deleted unless statutory retention obligations require otherwise.
Third-country transfer: All data is processed within the EU.
Further information: You may unsubscribe from the newsletter at any time by clicking the unsubscribe link provided at the end of each newsletter. https://legal.hubspot.com/privacy-policy
Purpose: Provision of a live chat system for direct customer communication and support.
Recipient: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland.
Data processed:
Legal basis: Consent pursuant to Art. 6(1)(a) GDPR for the use of the live chat, legitimate interest pursuant to Art. 6(1)(f) GDPR for processing to improve our customer service and optimize our services. Please note that you can end the live chat at any time and withdraw your consent to data processing. The lawfulness of the processing carried out prior to withdrawal remains unaffected.
Retention period: Chat logs and related data are stored as long as necessary. Contact information may be retained in the CRM system for a longer period in accordance with statutory retention periods and business requirements.
Third-country transfer: All data is processed within the EU.
Further information: https://legal.hubspot.com/privacy-policy
Purpose: Selection of candidates for the potential establishment of an employment relationship.
Recipients: JOIN Solutions AG, Eichenstrasse 2, 8808 Pfäffikon SZ, Switzerland.
Data processed:
Legal basis: Article 6(1)(b) GDPR (performance of pre-contractual measures) and Section 26(1) BDSG; Article 6(1)(f) GDPR, where we have a legitimate interest in the efficient conduct of the application process.
Retention period: We store your personal data until the conclusion of the application process. In the event of a rejection, your data will be retained for up to six months following notification of the decision. In the case of legal disputes, retention may be extended until final resolution. If you are hired, your application documents will be stored in your personnel file for the duration of your employment relationship. You may withdraw your application or object to the processing at any time; in this case, your data will be deleted and your application will no longer be considered.
International data transfer: Data transfer to Switzerland based on the adequacy decision (Art. 45 GDPR).
Further information: https://join.com/de/datenschutz
Cookies are small text files stored by your browser on your device. Cookies do not execute programs or install malware. Comparable technologies include web storage (local/session storage), fingerprinting, tags, and pixels. Most browsers accept these technologies by default; however, you can adjust your settings to block their use or to require consent. Please note that blocking cookies or similar technologies may restrict certain functionalities of the website.
Purpose: We use tracking and analytics tools to continually optimize our website and adapt it to your needs. For this purpose, information is collected using these technologies or device information is combined (device fingerprinting).
Legal basis: Technically necessary tools required for the operation of the website are used on the basis of our legitimate interests in accordance with Art. 6(1)(f) GDPR, or for the performance of a contract or pre-contractual measures pursuant to Art. 6(1)(b) GDPR. The storage of or access to information on your device is strictly necessary in these cases and is based on Section 25(2) TDDDG. Optional tools are used exclusively with your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Below, we outline the tracking and analytics tools used, their respective purposes, and the data processed.
Google Tag Manager
Purpose: Management and triggering of website tags via a unified interface.
Recipients: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, and Google, LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Data processed:
Retention period: Cookies are stored for up to 90 days.
Transfer to third countries: Data transfer to the U.S. based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and additional Standard Contractual Clauses (SCCs).
Further information: https://policies.google.com/privacy
Google Analytics 4
Purpose: Web analytics.
Recipients: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, and Google, LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Data processed:
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Transfer to third countries: For data transfers to the U.S., there is an adequacy decision by the EU Commission, the EU-U.S. Data Privacy Framework. Google is certified under this framework, which is why such transfers are based on the legal basis under Article 45 GDPR. In addition to this, Standard Contractual Clauses (SCCs) have been concluded with Google.
Further information: https://policies.google.com/privacy
Google AdSense
Purpose: To display personalized ads and measure ad effectiveness.
Recipient: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Data processed:
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Retention period: The data is stored for a maximum of 18 months.
Transfer to third countries: Data transfer to the U.S. based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
Further information: https://policies.google.com/technologies/ads
Google Conversion Linker
Purpose: Conversion tracking to analyze website activity and optimize advertising campaigns.
Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Data processed:
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Retention period: Cookies are stored for up to 90 days.
Transfer to third countries: Data transfer to the U.S. based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and additional Standard Contractual Clauses (SCCs).
Further information: https://policies.google.com/privacy
HubSpot Analytics
Purpose: Monitoring the website and supporting and optimizing digital marketing activities.
Recipient: HubSpot, Inc., 25 First Street, Cambridge, MA 02141, USA.
Data processed:
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Retention period: Cookies are stored for up to 90 days.
Transfer to third countries: Data transfer to the U.S. based on the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
Further information: https://legal.hubspot.com/de/privacy-policy
Purpose: Management of cookie consent and user preferences. Cookiebot (a product of Usercentrics A/S) enables us to obtain, manage, and document your consent for the use of cookies and similar technologies on our Website, in compliance with Section 25 TDDDG and Article 7 GDPR.
Recipient: Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.
Data processed:
Legal basis: Article 6(1)(c) GDPR (compliance with legal obligations under Section 25 TDDDG) and Article 6(1)(f) GDPR (legitimate interest in the lawful use of cookies and in documenting consent for evidentiary purposes). The storage of the consent cookie is strictly necessary pursuant to Section 25(2) TDDDG.
Retention period: The consent cookie ("CookieConsent") is stored on your device for up to 12 months. Consent documentation is retained for up to three years for evidentiary purposes.
Third-country transfer: All data is processed within the EU.
Further information: https://www.cookiebot.com/en/privacy-policy/
Purpose: Display of video content embedded directly on our Website.
Recipient: Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
When you access a page on our Website that contains an embedded YouTube video, a direct connection is established between your browser and YouTube's servers. YouTube thereby receives information that you have visited our Website. If you are logged into your YouTube or Google account at the time of access, YouTube may associate your visit with your user profile. The data processed by YouTube after the connection is established is subject to YouTube's privacy policy.
Data processed:
Legal basis: Article 6(1)(f) GDPR in conjunction with Section 25(2) TDDDG. Our interest lies in presenting our content in an appealing audiovisual format.
Retention period: In accordance with YouTube's/Google's privacy policy. Cookies set by YouTube may be stored on your device for varying periods. You can manage or delete cookies at any time through your browser settings.
International data transfer: For data transfers to the United States, there is an adequacy decision by the European Commission under the EU-U.S. Data Privacy Framework. Google is certified under this framework; accordingly, such transfers are based on Article 45 GDPR. In addition, Standard Contractual Clauses (SCCs) are in place with Google.
Further information: https://policies.google.com/privacy
Purpose: To process and respond to your inquiry or to schedule a meeting (e.g., "Talk to an expert") via our online booking tool.
Recipient: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland.
Data processed:
Legal basis: Article 6(1)(f) GDPR (legitimate interest in communicating with you and scheduling meetings). If your inquiry or meeting request is aimed at concluding or performing a contract, processing is carried out on the basis of Article 6(1)(b) GDPR. If you additionally consent to receiving further communications from us, processing for this purpose is based on Article 6(1)(a) GDPR. You may withdraw this consent at any time.
Retention period: Your data will only be stored for as long as necessary to fully process your inquiry or meeting request.
Further information: https://legal.hubspot.com/privacy-policy
Purpose: Communication with interested parties, providing information about products and services, and analysing the use of our online social media presences.
Recipients:
Joint Controllership with LinkedIn: In relation to the processing of statistical usage data for our LinkedIn page (so-called "Page Insights"), we and LinkedIn Ireland Unlimited Company act as joint controllers within the meaning of Article 26 GDPR. This joint controllership covers in particular the collection and aggregation of usage data for the purpose of generating Page Insights. The essential information about the allocation of responsibilities between us and LinkedIn, especially with regard to the exercise of data subject rights and compliance with security obligations, can be found in LinkedIn's Joint Controller Addendum (see link below).
Categories of Data Processed:
Legal Basis:
Retention Period: In accordance with the privacy policies of the respective platforms.
International Data Transfer: Data may be transferred to the USA and other third countries, depending on the respective platform.
Further Information:
LinkedIn: https://legal.linkedin.com/pages-joint-controller-addendum
https://www.linkedin.com/legal/privacy-policy
Note: We have no influence over the independent data processing by the platform providers. When visiting our online presences, usage data may be transferred to these providers, who may use this data for their own purposes. Data subject rights can be exercised directly with the respective platform providers.
Purpose: Management and maintenance of relationships with customers, prospects and other contractual or business partners (B2B), including lead management, qualification and prioritisation of leads, documentation of communication and contract histories, planning and control of sales activities, as well as enrichment of contact and company data from public sources and specialised B2B data providers.
Recipients: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland; HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA.
Data processed:
Legal basis:
Storage period: For the duration of the business relationship and thereafter as long as there is a legitimate interest in further storage (e.g. follow-up of enquiries, maintenance of business relationships); subsequent deletion or anonymisation, provided that no statutory retention obligations apply. Contact details of prospects/leads with whom there has been no interaction for a longer period of time are regularly deleted or further processed only in anonymised form for statistical purposes.
Third-country transfer: All data is processed within the EU.
Further information: https://legal.hubspot.com/privacy-policy
Personal data is primarily processed within the EU/EEA. Transfers to so-called "third countries" only occur in compliance with the requirements of the GDPR and where suitable safeguards are in place. Before data is transferred to a service provider in a third country, the level of data protection is assessed. A transfer only takes place if sufficient protection mechanisms exist. All service providers must enter into a data processing agreement. For providers outside the EEA, additional measures are required. Pursuant to Articles 44 et seq. GDPR, a transfer is only permitted if at least one of the following requirements is met:
Purpose: To deliver free content (e.g., white papers, market reports) and to send our newsletter with information about our products, services, and industry insights. The content is provided free of charge in exchange for your consent to receive our newsletter. We use the Double-Opt-In procedure to verify your registration.
Recipient: HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland.
Data processed:
Legal basis: Article 6(1)(a) GDPR. You provide your consent by actively checking the consent box and confirming your email address via Double-Opt-In.
Retention period: Your data will be stored for as long as you remain subscribed to the newsletter. Upon unsubscription, your data will be deleted without undue delay. The Double-Opt-In documentation will be retained for evidentiary purposes for up to three years (Section 195 BGB).
Withdrawal of consent: You may withdraw your consent at any time with effect for the future by clicking the unsubscribe link in any newsletter email or by contacting us at privacy@maesn.com.
Further information: https://legal.hubspot.com/privacy-policy
Personal data collected by us will only be disclosed if:
Possible recipients include:
We implement appropriate technical and organizational measures to ensure the security and confidentiality of your personal data. These measures are designed to protect against unauthorized access, manipulation, loss, or misuse. Our security measures are regularly reviewed and adapted to reflect technological advancements and current industry standards.
Please note that despite extensive protective measures, data transmission over the internet may involve security vulnerabilities. In particular, unencrypted communication (e.g., standard email) carries the risk that data may be accessed by third parties. We have no influence over the actions of external parties. We therefore recommend that you use encryption or other protective measures when transmitting sensitive information electronically to minimize potential risks.
Personal data will be deleted or blocked as soon as the purpose of storage no longer applies. Further storage will only take place if required by European Union or national legal provisions to which the controller is subject. Data will also be deleted or blocked once a statutory retention period expires, unless continued storage is necessary for the performance of a contractual relationship.
You have the following rights with regard to your personal data:
| Date | Version | Reason |
|---|---|---|
| 08.04.2026 | 1.0 | First version of the revised privacy notice in the new format. |