Privacy Policy

Information on how personal data is processed when using this website or contacting NT&D – Nanotechnology and Devices.


Last updated: May 27, 2026

1. General information

The protection of personal data is important to us. This Privacy Policy explains which personal data may be processed when you visit this website or contact NT&D – Nanotechnology and Devices, for which purposes the data is used, and which rights you have under applicable data protection law.

This website is intended to provide information about NT&D, its technologies, services, publications, references and contact options. The website does not currently use analytics, marketing tracking, embedded social media widgets, embedded video services or external web fonts.

The technical images used on this website are own or locally hosted images. The icons are implemented as inline SVG elements or local website elements and do not load external icon fonts or external icon services.

2. Controller

The controller responsible for data processing on this website is:

Dr.-Ing. Borislav Vratzov
NT&D – Nanotechnology and Devices
Wirichsbongardstr. 24
52062 Aachen
Germany

Phone: +49 241 39018
Mobile: +49 171 9500430
Email: info@nt-d.com
Website: www.nt-d.com

For questions regarding data protection, you may contact us using the contact details above.

3. Hosting and server log files

This website is hosted by an external hosting provider. The current hosting provider is:

STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany

When you access this website, technical data may automatically be processed by the hosting infrastructure and stored in server log files.

This data may include:

  • IP address
  • date and time of access
  • requested page or file
  • browser type and browser version
  • operating system
  • referrer URL
  • amount of data transferred
  • access status or error messages

The processing of this data is necessary to provide the website, ensure technical stability, detect errors, maintain security and prevent misuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable and reliable operation of this website.

Server log data is generally not combined with other data sources and is used only for technical and security-related purposes. Log data is stored only as long as necessary for these purposes, unless longer storage is required for security investigations or legal reasons.

Where required, a data processing agreement has been concluded with the hosting provider.

4. Contact by email or phone

If you contact NT&D by email, phone or mobile phone, the information you provide will be processed in order to respond to your inquiry and communicate with you.

This may include:

  • name
  • email address
  • phone number
  • company or institution
  • content of your inquiry
  • project-related information you choose to provide
  • communication metadata

The legal basis depends on the nature of the inquiry. If your inquiry relates to possible services, collaboration, project preparation or contractual communication, the processing may be necessary for pre-contractual or contractual purposes under Art. 6(1)(b) GDPR. In other cases, processing is based on our legitimate interest in responding to inquiries and maintaining professional communication under Art. 6(1)(f) GDPR.

We retain inquiry-related data only as long as necessary to process the inquiry, document communication, fulfill contractual or legal obligations, or protect legitimate business interests. Business correspondence may be retained for longer periods if legal retention obligations apply.

5. Cookies and similar technologies

This website may use cookies or similar technologies that are necessary for the technical operation, security and consent management of the website.

Necessary cookies may be used, for example, to:

  • provide basic website functionality
  • maintain technical security
  • store consent preferences
  • support WordPress functionality
  • prevent misuse or technical errors

The website does not currently use analytics cookies, marketing cookies or tracking cookies.

If non-essential cookies or services are added in the future, they will only be used where legally permitted and, where required, after your consent. The legal basis for consent-based processing is Art. 6(1)(a) GDPR. Where cookies or similar technologies are technically necessary, processing may be based on our legitimate interest under Art. 6(1)(f) GDPR and, where applicable, the relevant provisions for technically necessary access to information on user devices.

You can manage your cookie preferences through the cookie banner or preference settings provided on the website.

Further details are provided in the separate Cookie Policy.

6. Consent management

This website may use a consent management tool to document and manage cookie and service preferences. For this purpose, technically necessary information may be stored, such as your consent status, selected preferences, time of consent and technical identifiers required to recognize your settings.

The purpose is to respect and document your privacy preferences and to operate the website in compliance with data protection and cookie regulations. The legal basis is Art. 6(1)(c) GDPR where processing is necessary to comply with legal obligations, and Art. 6(1)(f) GDPR where processing is based on our legitimate interest in legally compliant website operation.

7. Local fonts

This website uses locally hosted fonts. This means that fonts are loaded from the website’s own hosting environment and not from external font providers such as Google Fonts.

No connection to external font servers is established for the purpose of loading fonts.

8. Images and icons

This website uses technical images, graphics and icons to illustrate NT&D’s technologies, services and application fields.

The images are own or locally hosted website assets. They are loaded from this website and not from external image platforms. The icons are implemented as inline SVG elements or local website elements and do not require requests to external icon libraries, icon fonts or content delivery networks.

As long as these assets are loaded locally, they do not create additional third-party data transfers and do not set cookies.

9. External links and LinkedIn

This website may contain links to external websites, including a normal external link to LinkedIn. These links are provided for information and communication purposes.

No LinkedIn widget, feed, tracking pixel or embedded social media plugin is currently integrated into this website. When you click an external link, you leave this website. The external provider is then responsible for any data processing on its own website.

Please review the privacy policies of external websites before using them.

10. No analytics, marketing tracking or embedded media

This website does not currently use:

  • Google Analytics
  • Matomo or similar analytics tools
  • marketing pixels
  • remarketing technologies
  • embedded YouTube videos
  • embedded Google Maps
  • embedded LinkedIn feeds or social media widgets
  • external Google Fonts
  • external icon fonts or external icon libraries

If such services are added in the future, this Privacy Policy and the Cookie Policy will be updated accordingly. Services requiring consent will only be activated in accordance with applicable legal requirements.

11. Recipients and processors

Personal data may be processed by technical service providers where this is necessary for hosting, maintenance, security or website operation.

The website is hosted by an external hosting provider. The hosting provider processes technical data required to deliver and secure the website. Where required, service providers are engaged on the basis of appropriate data processing agreements.

Personal data is not sold and is not shared with third parties for advertising purposes.

12. Transfer of data outside the European Union or European Economic Area

The website is currently designed to avoid unnecessary third-party services and external tracking. No intentional transfer of website visitor data to providers outside the European Union or European Economic Area is currently implemented through analytics, marketing or embedded media services.

If services involving international data transfers are introduced in the future, this Privacy Policy will be updated and appropriate safeguards will be considered where required.

13. Data security

Appropriate technical and organizational measures are used to protect personal data against unauthorized access, loss, misuse or alteration.

This website uses encrypted transmission via HTTPS. However, internet-based communication can never be completely secure. If you contact us by email, please consider that email communication may involve security risks depending on your email provider and transmission route.

14. Retention periods

Personal data is retained only for as long as necessary for the purposes described in this Privacy Policy.

Different retention periods may apply depending on the type of data and processing purpose:

  • technical log data is retained only as long as necessary for operation, troubleshooting and security
  • inquiry data is retained as long as necessary to respond and manage communication
  • business correspondence may be retained where legal retention obligations apply
  • consent preferences may be retained as long as necessary to document and manage privacy choices

Data will be deleted or restricted when it is no longer required, unless legal obligations or legitimate interests require further retention.

15. Your rights

Subject to the requirements of applicable data protection law, you have the following rights regarding your personal data:

  • right of access under Art. 15 GDPR
  • right to rectification under Art. 16 GDPR
  • right to erasure under Art. 17 GDPR
  • right to restriction of processing under Art. 18 GDPR
  • right to data portability under Art. 20 GDPR
  • right to object to processing under Art. 21 GDPR
  • right to withdraw consent at any time, where processing is based on consent

If you withdraw consent, this does not affect the lawfulness of processing carried out before the withdrawal.

To exercise your rights, you may contact us using the contact details provided above.

16. Right to lodge a complaint

You also have the right to lodge a complaint with a data protection supervisory authority if you believe that your personal data is being processed unlawfully.

The supervisory authority responsible for North Rhine-Westphalia is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany

Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Website: www.ldi.nrw.de

17. Changes to this Privacy Policy

This Privacy Policy may be updated from time to time if the website, technical setup, services used or legal requirements change.

Please review this page regularly to stay informed about how personal data is processed.

Scroll to Top