PRIVACY POLICY
Last updated: August 10, 2026
INTRODUCTION
GOTT WALD Holding LLC (“we”, “us”, or “our”) is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, process, and protect your information when you visit and interact with our website.
Because we prioritize precision, structural integrity, and discretion, this platform operates with minimal invasive tracking and severe data minimization principles.
01 CONTROLLER IDENTITY
The controller responsible for data processing on this website is:
GOTT WALD Holding LLCGeorgia, Tbilisi
Gldani district, Maseli Street N2a
Entrance N2, Office N201
Reference 35.64, Block G
As of September 1, 2026, an EU company (a German GmbH based in Munich) will be designated and is expected to act as the EU-based controller/operator for the European presence. Until then, the Holding (Georgia) is the controller.
For any privacy-related inquiries, you may contact us securely at office@gottwald.world.
02 HOSTING & TECHNICAL ARCHITECTURE
This website uses a modern Next.js frontend, delivered via Vercel Inc. (USA) and its global Edge Network (CDN).
Our application logic and API run on Render (USA); API traffic is routed through Cloudflare (USA). All application data is stored in a PostgreSQL database at Supabase, located in the Frankfurt (EU) region. Images are delivered via Cloudinary (USA). We use Sentry (Functional Software Inc., USA) for error and stability monitoring. Our domain and mailboxes are managed via united-domains (Germany).
During a visit, our servers automatically collect standard technical logs, including IP addresses, timestamps, HTTP status codes, requested resources, and browser/device data. These logs are used solely for operational security and stability (attack prevention and diagnostics). Legal basis: Art. 6(1)(f) GDPR. Retention: typically 14–30 days, after which they are automatically deleted.
03 FORMS & DATA SUBMISSION
When you submit information via our Contact form, Strategic Inquiry form, Careers form, or the GOTT WALD Application form, the data is securely transmitted via our backend API and stored within our PostgreSQL database at Supabase (Frankfurt, EU).
This data is processed exclusively to handle your request, establish contact, or assess professional capabilities. In addition, secure email notifications of these submissions are dispatched to our authorized internal personnel via the Resend API (sender subdomain send.gottwald.world).
Legal bases: Art. 6(1)(b) GDPR (pre-contractual and contractual measures), otherwise Art. 6(1)(f); for applications Art. 6(1)(b) in conjunction with § 26 BDSG.
04 CRM & AUTOMATION TOOLS
We categorically do not route any submissions through third-party interconnected Customer Relationship Management (CRM) platforms, marketing automation systems, or newsletter tools (such as Salesforce, HubSpot, or Mailchimp). Your submitted data remains entirely isolated within our private technical infrastructure.
05 APPLICANT & CAREER DATA
Applicant data submitted through our forms travels to designated HR personnel without the involvement of external Applicant Tracking Systems (ATS). Access to the database and applicant data is strictly limited to authorized personnel. Submissions are dispatched via secure email alerts handled by Resend.
Legal basis: Art. 6(1)(b) GDPR in conjunction with § 26 BDSG. Retention: applicant data is deleted no later than six months after the selection process ends, unless a hire occurs or you consent to longer storage.
06 ANALYTICS & TRACKING PIXELS
We use Google Analytics 4 (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) to understand aggregate, pseudonymised usage of this platform so we can improve it. IP addresses are truncated (IP-anonymisation); we do not use Google Signals, advertising features, or cross-site tracking.
Google Analytics runs under Google Consent Mode v2. Until you actively opt in, it operates in a cookieless mode — no analytics cookies or identifiers are stored, and only aggregated, cookieless signals are transmitted. Cookie-based measurement (the _ga / _ga_* cookies) is activated only when you enable Analytics under “Cookie Settings.”
Legal basis: your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG for cookie-based measurement; for the cookieless default, our legitimate interest under Art. 6(1)(f) GDPR. You may withdraw consent at any time with effect for the future via the “Cookie Settings” trigger in the footer.
We do not use Google Tag Manager, Meta Pixel, Hotjar, LinkedIn Insight Tags, or any other advertising or behavioral tracking suites.
07 COOKIES & CONSENT
We deploy a proprietary, self-contained Cookie Manager. We issue only a single strictly necessary cookie (gottwald_consent), used to record your acknowledgment of this notice — first-party, one-year lifespan, SameSite=Lax. By default we set no analytics, advertising, or behavioral tracking cookies. If you enable Analytics under “Cookie Settings,” Google Analytics additionally sets its own first-party measurement cookies (_ga, _ga_*) — see Section 06. You can switch this off again at any time.
Legal basis: § 25(2) TDDDG (strictly necessary) and Art. 6(1)(f) GDPR. You may review this cookie at any time via the “Cookie Settings” trigger in the footer.
08 EMAIL COMMUNICATION
For all outgoing communications and automated notifications from the website (such as form submission alerts and transactional inquiries), we exclusively utilize Resend (USA) as our secure transactional email infrastructure. We do not utilize external bulk newsletter automation tools.
09 TRANSLATION (GOOGLE)
A Google Translate integration is currently embedded to provide on-the-fly translation. When you use the translation feature, page content is transmitted to Google (Google LLC, USA). This feature will be replaced by an editorial German version in a forthcoming update and will then be removed. Legal basis (while active): Art. 6(1)(f) GDPR.
10 INTERNATIONAL DATA TRANSFERS
Our database is located in the EU (Supabase, Frankfurt). Because our architecture utilizes global infrastructure partners, incidental processing or storage may occur outside the European Economic Area (EEA), in particular in the United States: Vercel, Render, Cloudflare, Cloudinary, Resend, Sentry and, where used, Google. In all such instances, these partners rely on the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs) to ensure a level of protection consistent with European data protection standards.
11 RETENTION & DELETION PERIODS
- Contact & inquiry data: retained only as long as necessary to handle your request, then deleted, unless statutory retention obligations apply.
- Applications: deleted no later than six months after the selection process ends (absent a hire or your consent).
- Server logs: automatically deleted within 14–30 days.
- Consent cookie: stored locally in your browser for up to one year, or until you clear it.
12 YOUR LEGAL RIGHTS
Subject to the applicable provisions of the GDPR, you maintain the following rights:
- Access (Art. 15): to obtain a complete account of your processed data.
- Rectification (Art. 16): to correct inaccurate or incomplete data.
- Erasure (Art. 17): to demand deletion of your records.
- Restriction (Art. 18): to restrict processing.
- Portability (Art. 20): to receive your data in a machine-readable format.
- Objection (Art. 21): to object to processing based on Art. 6(1)(f).
- Withdrawal (Art. 7(3)): to withdraw a given consent at any time with future effect.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). While the controller is established in Georgia without an EU establishment, you may contact the supervisory authority of your EU member state; as of September 1, 2026 (German GmbH, Munich), the competent authority is expected to be the Bavarian State Office for Data Protection Supervision (BayLDA).
To exercise your rights, please submit a formal declaration to office@gottwald.world.