Privacy Policy
This document is a working draft prepared from the site's actual data processing. It must be reviewed and completed by qualified counsel before launch.
Privacy Policy
Below we explain which personal data we process when you visit this website, for what purpose, and what rights you have. The German version of this policy is the authoritative one.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
[[ FILL: full registered company name, including legal form ]]
[[ FILL: street and number ]]
[[ FILL: postal code and city ]]
[[ FILL: country of the registered office ]]
Email: info@ngginteractive.com
Phone: [[ FILL: business telephone number ]]
This website and the “nggInteractive” brand are operated by the company named above.
[[ FILL: If a data protection officer has been appointed, enter their name and contact details. Otherwise delete this paragraph. ]]
2. Representative in the European Union (Art. 27 GDPR)
[[ FILL: Required only if the controller is established outside the EU/EEA and the offering is directed at people in the EU — then enter the representative's name, address and contact details. Otherwise delete this section. ]]
3. Hosting
This website is hosted on AWS Amplify Hosting, a service of Amazon Web Services, and delivered via the AWS content delivery network. When you access the website, the connection data technically required for delivery, in particular your IP address, is processed on the provider's infrastructure.
- Provider
- Amazon Web Services, [[ FILL: the specific contracting entity, e.g. AWS EMEA SARL, Luxembourg, or AWS, Inc., USA ]]
- Processing region
- [[ FILL: AWS region in which the Amplify app runs, e.g. eu-central-1 ]]
The provider acts as a processor. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the secure, stable and performant provision of the website. A data processing agreement under Art. 28 GDPR is in place: [[ FILL: confirm that the AWS Data Processing Addendum has been accepted ]].
4. Data collected when you visit the website (server log files)
Each time a page is requested, the hosting infrastructure automatically records the data your browser transmits for technical reasons:
- IP address of the requesting device
- date and time of the request
- the address or file requested
- volume of data transferred and HTTP status code
- the previously visited page (referrer), where transmitted
- browser type and version, operating system and language (user agent)
This data is technically necessary to deliver the website and additionally serves operational security and the prevention of misuse. It is not combined with other data sources and is not used to create usage profiles.
The legal basis is Art. 6 (1) (f) GDPR. Retention period: [[ FILL: actual retention period of the access logs, e.g. 14 or 30 days; if access logging is not enabled, state that here ]].
5. Contact form
You can send us a project enquiry via the contact form on the home page. The following information is collected:
- Name (required)
- Company (required)
- Email address (required)
- Industry, selected from a predefined list (required)
- Project description as free text, at least 10 characters (required)
Please do not enter special categories of personal data within the meaning of Art. 9 GDPR, or confidential third-party information, in the free-text field.
How it works technically: your entries are transmitted from your browser over TLS to an interface operated at Amazon Web Services (Amazon API Gateway) and processed there by an AWS Lambda function. The function checks the required fields, truncates the entries to fixed maximum lengths (name 120, company 160, email 254, industry 120, project description 5,000 characters) and then sends the content to our internal mailbox as an email via Amazon SES. The data is not stored in a database.
- Receiving mailbox
- [[ FILL: the recipient address actually configured (TO_EMAIL, optional CC_EMAIL) ]]
- Sender address
- [[ FILL: the sender address actually configured (FROM_EMAIL) ]]
- AWS processing region
- [[ FILL: AWS region of Lambda, API Gateway and Amazon SES ]]
Your email address is set as the reply-to address of the internal notification so that we can reply to you directly. Your IP address is necessarily transmitted to AWS for technical reasons; the function itself neither evaluates nor logs it. Technical logs of the AWS services may, however, contain request metadata.
To protect against automated submissions, the form contains a field that is invisible to people (a honeypot). If that field is filled in, we discard the submission without sending an email. No captcha and no external spam filtering service is used.
The purpose is to handle your enquiry and communicate with you. The legal basis is Art. 6 (1) (b) GDPR where the enquiry serves the initiation or performance of a contract, and otherwise Art. 6 (1) (f) GDPR. Providing the data is voluntary, but we cannot process your enquiry without it.
Retention: we delete your enquiry once it has been dealt with conclusively and no statutory retention obligations apply, at the latest after [[ FILL: specific period, e.g. 12 months after the end of the correspondence ]]. For messages that lead to a contract, statutory retention periods apply: [[ FILL: applicable retention obligations at the controller's registered office ]]. Retention of the technical AWS logs: [[ FILL: configured retention of the CloudWatch log group ]].
6. Media delivery from Amazon S3
The large video assets on this website are not delivered by our web server but loaded directly from the Amazon S3 storage service at the host ngg-interactive.s3.amazonaws.com. Your browser opens its own connection to that host and thereby transmits your IP address, the time of the request, the requested file name and browser and device information to Amazon Web Services.
So that videos start without delay, the connection to this host is prepared as soon as the page loads (preconnect). Contact may therefore occur even if you do not play a video.
The legal basis is Art. 6 (1) (f) GDPR. Storage region: [[ FILL: AWS region of the S3 bucket ]].
7. Fonts
This website uses the “Inter” and “Sora” typefaces. Both are downloaded by the font feature of the web framework we use (next/font) at build time and are subsequently served from our own hosting infrastructure.
This means that no connection to Google servers (such as fonts.googleapis.com or fonts.gstatic.com) is established when you visit this website, and no IP address is transmitted to Google for this purpose. This was verified against the generated build output.
8. Icons embedded from cdn.simpleicons.org
In the “Technologies & Tools” section, vendor icons are loaded from the service cdn.simpleicons.org. Your browser retrieves each icon file directly from that provider and thereby transmits your IP address, the time of the request, the requested icon path and browser and device information. The connection to this host is likewise prepared as soon as the page loads (preconnect).
The legal basis is Art. 6 (1) (f) GDPR. Provider and server location: [[ FILL: operator, registered office and server location of cdn.simpleicons.org, plus the basis for any third-country transfer — alternatively serve the icons locally and delete this section ]].
9. Links to external services
This website links in places to external offerings, in particular to videos on YouTube. This content is not embedded — these are ordinary hyperlinks. No data is transmitted until you actively click the relevant link. From that point on, the privacy policy of the respective provider applies.
10. Cookies
This website sets exactly one cookie:
- Name
- NEXT_LOCALE
- Content
- only the language code “de” or “en” — no identifier, no user ID
- Purpose
- remembering the language version you have opened or selected
- Lifetime
- session cookie with no expiry date configured; deleted when you close your browser
- Other attributes
- SameSite=Lax, path “/” — not accessible to third parties, no cross-site evaluation
This cookie is necessary to provide the language version you requested. The legal basis for storing it on your device is Section 25 (2) no. 2 TDDDG, and for the associated processing Art. 6 (1) (f) GDPR.
No other cookies are set — in particular no analytics, statistics, advertising or recognition cookies. For the same reason we do not use a consent banner. We also do not use the browser's local storage to store personal data.
You can delete or block cookies at any time in your browser settings. If the language cookie is blocked, the website remains fully usable.
11. No analytics, tracking or marketing tools
We expressly do not use any of the following on this website:
- no web analytics (such as Google Analytics, Matomo or Plausible)
- no counting or tracking pixels and no conversion tracking
- no advertising networks, no retargeting, no profiling
- no social media plugins and no embedded third-party content
- no A/B testing or session recording tools
- no newsletter or email marketing integration
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
12. Transfers to third countries
The Amazon Web Services services we use belong to a group headquartered in the USA. Processing in, or access from, a third country can therefore not be ruled out. The transfer is safeguarded by: [[ FILL: the specific basis, e.g. standard contractual clauses via the AWS Data Processing Addendum and/or certification under the EU-US Data Privacy Framework — verify currency before publication ]].
[[ FILL: If the controller itself is established outside the EU/EEA, state here that data is also processed at the controller's registered office, in which country, and on which Chapter V GDPR safeguards this is based. Otherwise delete. ]]
13. Your rights as a data subject
You have the following rights in relation to your personal data:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR)
An informal message to info@ngginteractive.com is sufficient to exercise these rights.
You also have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority. Supervisory authority responsible for us: [[ FILL: competent supervisory authority with address and website ]].
14. Data security
This website is delivered exclusively over encrypted HTTPS/TLS, and contact form submissions are likewise transmitted over TLS. We also take appropriate technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access. Please note that email transmission between mail servers is not necessarily encrypted end to end.
15. Changes to this privacy policy
We update this privacy policy when the technical implementation of the website, the services used or the legal framework change.
Last updated: [[ FILL: date of the current version ]]