Privacy policy

Last updated: 23 August 2026

1. Controller

Safe Pack Solutions GmbH & Co. KG, Im Sundernkamp 19, 32130 Enger, Germany
Phone: +49 5224 93901-0 · Email: team@safepack.de

2. Provision of the website and server logs

When you access the website, the server processes technically necessary connection data, in particular IP address, date and time, requested page, referrer, browser and operating system. Processing is based on our legitimate interests in reliable website delivery, operational security, defence against attacks and fault analysis (Article 6(1)(f) GDPR). Logs are deleted when they are no longer required for these purposes, unless a security incident requires longer retention.

3. Contact requests

If you contact us by form, email or telephone, we process your contact details, company, message and any product reference to respond to your request. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication and otherwise Article 6(1)(f) GDPR; in the latter case, our legitimate interest is the efficient handling of general enquiries. Providing this information is neither legally nor contractually required. Without the information marked as required, however, we cannot process your enquiry. We delete the data when the request has been completed and statutory retention obligations no longer apply.

To protect the contact form from automated misuse, we also verify a signed, first-party form timestamp, require the browser to solve a short cryptographic proof-of-work challenge and temporarily limit repeated submissions. The challenge and its verification run exclusively between your browser and our server; no data is transmitted to a CAPTCHA provider. Only the hash of a random challenge identifier is stored for no more than six minutes to prevent reuse. For rate limiting, the IP address and the normalised email address are converted on our server into separate keyed pseudonyms. The raw values are not stored in the rate-limit cache; the pseudonymous limiter entries are automatically deleted no later than one hour after the last submission. No external CAPTCHA provider, browser fingerprinting or additional cookie is used. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are preventing misuse, securing our systems and maintaining reliable contact channels. If a submission is blocked, you can still contact us by email or telephone.

After these technical checks have been passed, we use the Kimi K3 language model via our processor LLMBase GmbH to assess whether the content is a genuine business enquiry, not actionable, spam or unclear. We transmit only the message, limited to 2,000 characters, any product category, the form language, the message length and whether the message contained a web address. Email addresses, telephone numbers and web addresses contained in the message are replaced before transmission. We do not transmit the name, company, email address, telephone number or IP address entered in the form, nor indicators derived from those identity fields. Enquiries classified with high confidence as spam or not actionable because they lack any identifiable product, application or business context are neither stored nor delivered. Suppression additionally requires predefined reason codes that support the assessment. Unclear, inconsistent or invalid assessments and all enquiries for which the service is unavailable continue to be delivered. LLMBase is contractually bound under Article 28 GDPR, and the selected model is not permitted to use the content for training. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are recognising semantically plausible misuse and reliably separating actionable enquiries from spam and unusable submissions. This filtering has no legal or similarly significant effect; email and telephone remain available as alternative contact channels. Local assessment logs contain only the result, confidence, reason codes, model and action, and are retained for no more than 14 days.

4. Consent settings

Optional services are off by default. Your selection is stored in the first-party cookie sp_cookie_consent_v2 for six months. This storage is necessary to remember the decision you requested (Section 25(2) no. 2 TDDDG). You can withdraw or change consent at any time using “Privacy settings”. Withdrawal does not affect prior lawful processing.

5. Leadinfo

Only after your separate consent, we load Leadinfo from Leadinfo B.V., Rivium Quadrant 141, 2909 LC Capelle aan den IJssel, Netherlands. The service matches the visitor's IP address with publicly available company information and analyses visited pages, visit time and referrer for B2B lead identification and website optimisation. Depending on the account configuration, interaction sequences may also be recorded as a screen recording.

For analytics functions and, if enabled, screen recordings, Leadinfo may set first-party cookies or store information in the browser. According to the provider, storage periods range from the current session to a maximum of two years, depending on the function. Screen recordings are retained for 7 days in the Scale package or 14 days in the Pro package. We delete the visit data available in our Leadinfo account when it is no longer required for the purposes stated above and no statutory retention obligation applies.

The legal basis is your consent under Article 6(1)(a) GDPR and, where information is stored in or read from your device, Section 25(1) TDDDG. Leadinfo processes the visitor data collected through our website on our behalf. Where Leadinfo uses IP addresses and publicly accessible sources to build and maintain its own company database, Leadinfo states that it acts as an independent controller. Further information and an additional provider opt-out are available at Leadinfo Privacy.

6. SalesViewer

Only after your separate consent, we load SalesViewer from SalesViewer® GmbH, Universitätsstraße 60, 44789 Bochum, Germany. A JavaScript-based code collects company-related usage data for marketing, market research and optimisation. According to SalesViewer, processing is cookie-free, company-related and pseudonymised on servers in Germany, and the data is not used to identify individual visitors.

The legal basis is your consent under Article 6(1)(a) GDPR and, where information is stored in or read from your device, Section 25(1) TDDDG. The provider deletes data when it is no longer required for its purpose and no statutory retention obligation applies. Further information and an additional opt-out are available at SalesViewer Opt-out.

7. YouTube videos

Embedded YouTube videos remain blocked until you consent to external media. We then connect to YouTube in privacy-enhanced mode (youtube-nocookie.com). When a video is retrieved, your browser transmits at least your IP address and the address of the page viewed to Google. Google may also process device and usage information and transfer data to the United States. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information is available in Google's privacy policy.

8. Recipients, transfers and security

We use hosting, email and the providers named above where necessary. Processors are contractually bound in accordance with Article 28 GDPR. If data is transferred outside the EEA, we rely on an adequacy decision or appropriate safeguards such as EU standard contractual clauses. We use appropriate technical and organisational measures to protect the data.

9. Your rights

You have the rights of access, rectification, erasure, restriction, data portability and objection under Articles 15 to 21 GDPR, and the right to withdraw consent at any time under Article 7(3) GDPR. You may also lodge a complaint with a data protection supervisory authority. For North Rhine-Westphalia: State Commissioner for Data Protection and Freedom of Information NRW.

Right to object: Where we process data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation (Article 21(1) GDPR).

We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR.