Privacy
Website privacy notice
Last updated: 11 August 2026
This notice explains how the AroTrace website processes personal data. We use minimized first-party website measurement without cookies or persistent visitor identifiers. We do not use advertising, visitor identification, session replay, third-party analytics, third-party embeds, or marketing cookies. Contact-form submissions are processed through AWS and our Marketing application.
1. Controller
Arorian Technologies GmbHAlfred-Herrhausen-Allee 3–5
65760 Eschborn
Germany
Privacy enquiries and requests concerning your personal data can be sent to privacy@arorian.com. General contact details are available in the provider information.
2. Data Protection Officer
You can contact our Data Protection Officer directly and confidentially:
Data Protection Officer – confidentialArorian Technologies GmbH
Alfred-Herrhausen-Allee 3–5
65760 Eschborn
Germany
Email: dpo@arorian.com
The officer's personal name is not published so the company can provide a stable, role-based contact route.
3. Visiting the website
Delivering the website requires the hosting infrastructure to receive network and request data such as an IP address, requested resource, date and time, response status, referrer where supplied, and browser or device information. We process this data to deliver the requested pages, maintain technical security, diagnose faults, and prevent abuse. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in providing a reliable and secure company website.
We use Amazon Web Services (AWS) to host and deliver this website. AWS processes the network and request data needed to provide and protect the service on our behalf.
Depending on how the service is provided, AWS processing may involve countries outside the European Economic Area. Where required, transfers are protected by the European Commission's Standard Contractual Clauses or another applicable legal safeguard. You can request further information about these safeguards from privacy@arorian.com.
4. Theme preference and terminal storage
If you choose light or dark appearance, your browser stores the value arotrace-theme locally so the site can remember your requested display preference. The website does not transmit this value to us and does not use it to identify or profile you. No non-essential cookie or comparable storage technology is currently implemented.
5. First-party website measurement
We measure aggregate use of the English and German website to understand which page categories and product topics are useful and whether visitors reach the contact form. Controlled events include a page view, language change, selected calls to action and documentation links, contact-form start, a coarse validation category, and a successfully stored contact submission. The measurement event never contains a form value.
This measurement does not set or read analytics cookies, local storage, or another identifier on your device. It does not create a visitor or session ID and does not send the page address, query parameters, referrer, IP address, user agent, contact details, or free text to the Marketing analytics record. A random event ID prevents one technical retry from being counted twice and is not used to recognize a person. Global Privacy Control and Do Not Track signals suppress measurement requests.
We process this minimized measurement under Article 6(1)(f) GDPR, based on our legitimate interest in assessing and improving our company website without identifying individual visitors. Raw events are restricted to authorized Marketing users and removed after seven days; anonymous daily totals remain available for trend comparison. The measurement endpoint uses our AroTrace Marketing application and AWS-hosted infrastructure. You may object to this processing by contacting privacy@arorian.com.
6. Contacting us by email
If you contact us by email, we process the information you provide—typically your name, email address, message, and related communication metadata—to review and answer your enquiry. Where your request concerns a possible contract, the legal basis is Article 6(1)(b) GDPR. Other relevant business communication is processed under Article 6(1)(f) GDPR, based on our legitimate interest in responding to enquiries. Legal retention duties may additionally require processing under Article 6(1)(c) GDPR.
You are not legally or contractually required to provide this information. We need a reachable contact route and the substance of your request if you want an individual response; without them, we may be unable to handle the enquiry. We use Microsoft 365 as our business-email provider. Access is limited to authorized personnel and contracted providers required to operate business email. Please do not send credentials, confidential project data, regulated information, or personal data about other people unless it is necessary and an appropriate channel has been agreed.
7. Contact form
The form asks for your name, business email address and message. Company, area of interest, systems or tools, and preferred next step are optional. It also records the language, form version and source contact page needed to route and evidence the submission. If the contact-page address contains valid campaign identifiers, the controlled source, medium, campaign and content values are recorded; the complete page address, referrer and browsing history are not. We use these details to review and respond to your enquiry under Article 6(1)(b) GDPR where it concerns pre-contractual steps and otherwise under Article 6(1)(f) GDPR.
Contact-form submissions are processed through AWS and stored in our access-controlled Marketing application so we can review and respond to the enquiry.
The optional, initially unchecked choice to receive product news, invitations and practical insights is independent of sending an enquiry. If selected, we record the wording, form version, time and submission context needed to demonstrate consent under Article 6(1)(a) GDPR. You can withdraw that consent at any time by emailing privacy@arorian.com, without affecting processing before the withdrawal.
8. Recipients, transfers, and retention
Personal data is available only to authorized Arorian personnel, AWS for website and contact delivery, Microsoft 365 for business email, and public authorities where disclosure is legally required. We do not sell website visitor or enquiry data. The AWS transfer safeguards described above apply to the website and contact-delivery services.
Contact submissions awaiting transfer to our Marketing application are retained by AWS for no more than 14 days. Related technical logs are retained for 14 days and are configured not to contain form values. After successful delivery, the enquiry is retained in Marketing while we handle it and while relevant business follow-up can reasonably be expected. It is then removed from ordinary use through the Platform's versioned deletion process, unless a statutory retention duty or the establishment, exercise, or defense of legal claims requires restricted retention for longer. Consent and withdrawal evidence is retained only as needed to demonstrate compliance and respect the withdrawal. A justified legal hold takes precedence for its duration.
9. Your rights
Subject to the applicable legal requirements, you may request access to and rectification or erasure of your personal data, restriction of processing, and data portability. You may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it for the future without affecting earlier lawful processing. The website does not make decisions about individuals solely by automated means and does not conduct profiling.
Send a request to privacy@arorian.com. We may need information reasonably necessary to verify identity and protect personal data from unauthorized disclosure.
10. Right to complain
You may lodge a complaint with a supervisory authority, particularly in the EU or EEA country of your habitual residence, place of work, or the place of the alleged infringement. Because the controller is established in Eschborn, the locally competent German authority is:
Der Hessische Beauftragte für Datenschutz und InformationsfreiheitPostfach 3163
65021 Wiesbaden
Germany
Telephone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Online complaint form
11. Security
We use appropriate technical and organizational measures, including HTTPS, access controls, maintained software, monitoring, and documented incident handling. Internet and email transmission cannot be guaranteed to be completely risk-free; avoid sending sensitive material through the website or ordinary email unless an appropriate protected route has been agreed.
12. Changes to this notice
We update this notice when the website changes in a way that materially affects personal-data processing, including the introduction of analytics, external media, new providers, or new storage technologies. The current version date appears at the top of the page.