Privacy Policy
Last updated: December 2025
EcoComply GmbH (“EcoComply”, “we”, “our”, “us”) respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect and use your data when you interact with our website or contact us for information or quotes.
It also describes your rights under the EU General Data Protection Regulation (GDPR).
1. Who We Are
EcoComply GmbH
c/o Campus Founders Bildungscampus 11
74076 Heilbronn, Germany
For all privacy-related inquiries: privacy@ecocomply.ai
We act as the data controller for the data collected through this website.
2. Personal Data We Collect
We may collect, use, store, and process the following categories of personal data:
Identity and Contact data:
- Identity and contact data: name, company name, work email, telephone number
- Inquiry & business data: information you provide in our contact or quote request forms, optional product description files you choose to upload (public information only)
- Technical & usage data: IP address, browser type and version, operating system, page visited, time and date of access, interaction with our website, your choice regarding marketing communication (if you sign up)
We do not intentionally collect sensitive personal data.
3. How We Collect Personal Data
- Direct Interactions: When you fill in a form, send us an email, book a meeting, or upload an optional product description
- Automated Technologies: Technical data is collected via cookies, analytics tools, and server logs.
- Third-Party Providers: We may receive analytics or technical information from services like Google Analytics.
4. How We Use Your Data
We use your personal data for the following purposes:
a) Responding to Inquiries and Preparing Quotes: To assess your request, communicate with you, and prepare proposals.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps)
b) Service Support & Website Operation: To maintain and secure our website, ensure performance, detect errors, and prevent
misuse. Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
c) Analytics & Improvement (with consent): To understand how visitors use our website and improve our content and user experience.
Legal basis: Art. 6(1)(a) GDPR (consent)
d) AI-Assisted Analysis. We may use AI tools to help extract regulatory requirements and analyse product descriptions you provide.
- AI is used only for your inquiry
- Data is not used to train models
- No automated decisions with legal or significant effects
- All results are reviewed by EcoComply staff
Legal basis: Art. 6(1)(b) & 6(1)(f) GDPR
e) Legal & Compliance Obligations: To comply with applicable laws, regulations, and archival requirements.
Legal basis: Art. 6(1)(c) GDPR
5. Cookies & Tracking Technologies
We use:
- Strictly Necessary Cookies required for website functionality
- Analytics Cookies (with consent)
You can withdraw consent at any time via our cookie banner.
6. Sharing Your Personal Data
We may share your personal data with:
Trusted vendors who process data on our behalf, such as:
- Webflow (website hosting)
- Google Cloud Platform (secure storage of optional uploaded files)
- HubSpot (CRM, email workflows)
- Google Analytics (analytics, if consented)
These providers may process data in the EU or the United States under the EU–US Data
Privacy Framework or Standard Contractual Clauses.
Accredited Testing Laboratories
If your request requires product testing, we may share strictly necessary product information with accredited laboratories under NDA or contractual confidentiality obligations.
Legal and Regulatory Authorities
If required by law.
We do not sell or trade personal data.
7. Where Your Data Is Stored
- Inquiry data: HubSpot CRM
- Optional file uploads: Google Cloud Platform (EU region)
- Website hosting: Webflow (USA)
- Analytics: Google Analytics (global infrastructure)
All providers implement industry-standard security measures.
8. Data Security
We implement technical and organizational measures to protect your data, including encryption, access control, secure cloud infrastructure, and risk-based security practices. No internet-based system is ever completely secure, but we take reasonable steps to protect your information.
9. Data Retention
We retain personal data only as long as necessary for each purpose:
- Inquiry and quote data: up to 24 months
- Optional uploaded files: deleted once the inquiry is handled
- Analytics data: according to Google’s retention settings
- Legal obligations: per statutory retention periods
10. Your Legal Rights
Under GDPR, you have the right to:
- Request access to your personal data
- Request correction
- Request deletion
- Object to processing
- Restrict processing
- Request data portability
- Withdraw consent at any time (for analytics or marketing)
To exercise these rights: privacy@ecocomply.ai
11. International Transfers
Some of our service providers may process data outside the EU (e.g., USA). We rely on the EU - US Data Privacy Framework, Standard Contractual Clauses, or equivalent safeguards.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Any changes will be posted on this page, with the revision date updated accordingly.