Skip to content

Legal

Privacy

1. Data controller

Conexa Digital (a brand of Merust Trust SL), represented by Eugen Neifer, CL Río Cervol 2, 46940 Manises (Valencia), Spain. E-mail: info@conexadigital.eu

2. Data collection when visiting this site

When you access conexadigital.eu, your request passes through two stations. In front sits Cloudflare as the delivery network; Cloudflare processes technical access data (IP address, browser type, referrer URL, timestamp) in order to deliver the page and protect it against attacks. The site itself has been held since 19 August 2026 on a server we rent from Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in its Nuremberg data centre. On that server we record no access at all: no logs are created containing visitors' IP addresses or the pages they open. Legal basis: art. 6(1)(f) GDPR — our legitimate interest in a reachable presence protected against attacks.

3. Cookies and local storage

Technically necessary: This site stores your language preference as a cookie (NEXT_LOCALE), together with your cookie decision and an optional loading-screen preference, in your browser's localStorage; the region used for price display is kept in sessionStorage for the duration of the session. This storage is required to operate the site (§ 25(2) TDDDG; art. 6(1)(f) GDPR). Analytics cookies: Google Analytics 4 and Microsoft Clarity are loaded only after your explicit consent via the cookie banner (opt-in) — no analytics cookies are set without consent. Legal basis: § 25(1) TDDDG in conjunction with art. 6(1)(a) GDPR. You can withdraw or change your consent at any time with effect for the future via the “Cookie settings” link in the footer.

4. Web analytics — Google Analytics 4

With your consent, we use Google Analytics 4 (measurement ID G-7WWLSC4J4Q), a web analytics service provided by Google Ireland Limited (Dublin, Ireland). The purpose is reach measurement: we evaluate how our website is used in order to improve it. To this end, GA4 sets cookies (including “_ga” and “_ga_*”). The IP address is processed in anonymised form. The cookies set by GA4 have a lifetime of up to 24 months; the retention of analytics data in GA4 is limited to a maximum of 14 months. This may involve a transfer of data to Google LLC in the USA; it is safeguarded by appropriate guarantees pursuant to art. 44 et seq. GDPR, in particular the EU-US Data Privacy Framework (DPF), under which Google LLC is certified, supplemented by standard contractual clauses (SCC). The sole legal basis is your consent (art. 6(1)(a) GDPR; § 25(1) TDDDG). Without consent, Google Analytics is not loaded. You can withdraw your consent at any time with effect for the future via “Cookie settings” in the footer.

5. Session analysis — Microsoft Clarity

With your consent we use Microsoft Clarity (project ID y0omnxvgfg), an analytics service provided by Microsoft Ireland Operations Limited (Dublin, Ireland). The purpose is to improve usability: we analyse which areas of a page are viewed and clicked (heatmaps) and where visitors drop off. Clarity sets cookies (including “_clck”, “_clsk”) and records the course of a session — mouse movements, clicks, scrolling and page changes. Text entries are not transmitted in clear text: masking is enabled, so input fields and text content are made unreadable before the data leaves our system. The cookies have a lifetime of up to 12 months; recordings are deleted at Microsoft after 30 days. Data may be transferred to Microsoft Corporation in the USA; this is safeguarded by appropriate guarantees under Art. 44 et seq. GDPR, in particular the EU-US Data Privacy Framework (DPF), under which Microsoft Corporation is certified, supplemented by Standard Contractual Clauses (SCC). The legal basis is exclusively your consent (Art. 6(1)(a) GDPR). Without consent, Microsoft Clarity is not loaded. You may withdraw your consent at any time with effect for the future via “Cookie settings” in the footer. Important note on Microsoft's role: Unlike our other service providers, Microsoft does not process this data solely on our behalf but is independently responsible for it (Microsoft expressly describes Clarity as a “data controller” in its own documentation). Microsoft therefore also uses the data for its own purposes, including improving its own products and advertising purposes via Microsoft Advertising. A data processing agreement under Art. 28 GDPR consequently does not exist for Clarity and cannot be concluded with Microsoft for this service. What Microsoft does with the data is set out in the Microsoft Privacy Statement (microsoft.com/privacy/privacystatement).

6. Getting in touch

If you contact us via the request form or by e-mail, we process the data you provide: name, e-mail address and — where given — company, package of interest, goal, industry and current website, plus your message and your consent. In addition, the form technically transmits which page of our website you submitted it from and which website you came to us from (the domain name only, not the full address). This tells us which content leads to enquiries. Both details appear solely in the notification sent to us; they are not stored beyond it, not used to recognise you and not passed on to third parties. Delivery is handled via our processor Resend as an e-mail to our inbox (info@conexadigital.eu); as a fallback, the enquiry is stored on our server. We do not pass the data on without your consent. Retention period: until the purpose is fulfilled, after which the data is regularly deleted (at least quarterly). Legal basis: art. 6(1)(b) and (f) GDPR.

7. Services used

We explicitly prefer European data processors:

  • Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) — operation of the server on which this website is held, in its Nuremberg data centre. A German company at a German location; no transfer to a third country takes place. No access logs are kept on that server. Legal basis: art. 6(1)(f) GDPR. DPA in place.
  • Cloudflare, Inc. (San Francisco, USA) — upstream delivery network (CDN), DNS and protection against attacks. Cloudflare terminates the encrypted connection at the edge of its worldwide network and passes the request on to our server in Nuremberg; copies of the pages are cached along the way so that they load quickly everywhere. For the regional price display, only the country of origin is read from a Cloudflare header, without being stored in the application code. Legal basis: art. 6(1)(f) GDPR. DPA in place; the transfer to the USA is covered by the EU-US Data Privacy Framework and additionally by standard contractual clauses.
  • Resend (US/EU-routed) — transactional mail (contact form). Data is not reused for marketing purposes. DPA concluded; any transfer to the USA is safeguarded by standard contractual clauses.
  • Anthropic PBC (San Francisco, USA) — AI answers for the chat widget “Frag Eugen” — not currently switched on; this entry applies from the moment it goes live. Only your input is transmitted; message contents are not stored. Legal basis: art. 6(1)(f) GDPR. Third-country transfer to the USA safeguarded by EU standard contractual clauses.
  • Google Analytics 4 (Google Ireland Limited, Dublin, Ireland) — reach measurement, exclusively after consent (art. 6(1)(a) GDPR); this may involve a transfer to the USA (Google LLC), safeguarded pursuant to art. 44 et seq. GDPR (EU-US Data Privacy Framework, supplemented by standard contractual clauses). Details in section 4.
  • Microsoft Clarity (Microsoft Ireland Operations Limited, Dublin, Ireland) — heatmaps and session analysis, only after consent. Text entries are transmitted masked.

No processing of your data by AI systems takes place via this website. We provide AI-supported services exclusively under contract and on a project basis for clients, not towards website visitors.

8. Your rights

  • Access (art. 15 GDPR)
  • Rectification (art. 16 GDPR)
  • Erasure (art. 17 GDPR)
  • Restriction of processing (art. 18 GDPR)
  • Data portability (art. 20 GDPR)
  • Objection (art. 21 GDPR)
  • Complaint to a supervisory authority (art. 77 GDPR)

Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on art. 6(1)(f) GDPR (art. 21 GDPR). The supervisory authority responsible for the controller is the Spanish data protection authority (Agencia Española de Protección de Datos — AEPD, www.aepd.es); you may also contact the supervisory authority at your habitual place of residence. No automated decision-making, including profiling, within the meaning of art. 22 GDPR takes place.

9. SSL/TLS encryption

For security reasons, this site uses TLS encryption. You can recognise this by the lock icon in your browser and the https:// prefix.

As of: August 2026.