Privacy Policy
We take the protection of your personal data seriously. This Privacy Policy explains how SONOJET GmbH processes personal data when you visit our website or contact us. Personal data means any information relating to an identified or identifiable natural person.
1. Controller
The controller responsible for processing personal data in accordance with the General Data Protection Regulation (GDPR) is:
SONOJET GmbH
Bayreuther Straße 32
01187 Dresden
Germany
Phone: +49 (0) 351 4659-206
Email: contact@sonojet.com
2. General Information on Data Processing
We process personal data only to the extent necessary to provide and operate our website, communicate with interested parties, customers and business partners, and fulfil our legal and contractual obligations. Depending on the individual processing activity, the legal basis for processing may include:
Art. 6(1)(a) GDPR – consent;
Art. 6(1)(b) GDPR – performance of a contract or steps taken prior to entering into a contract;
Art. 6(1)(c) GDPR – compliance with a legal obligation; or
Art. 6(1)(f) GDPR – our legitimate interests or the legitimate interests of a third party.
Where processing is based on our legitimate interests, these generally include the secure and efficient operation of our website, protection against misuse and cyberattacks, and efficient communication with customers, prospective customers and business partners.
3. Website Hosting and Squarespace
Our website is created and hosted using services provided by Squarespace. For customers established in the European Economic Area, Squarespace services are generally provided by:
Squarespace Ireland Limited
Squarespace House, Ship Street Great, Dublin 8, Ireland, D08 N12C
When you visit our website, Squarespace may process technical information required to provide, secure and operate the website. This may include, in particular:
IP address;
date and time of access;
requested page or resource;
browser type and version;
operating system;
device information;
referring website;
information about interactions with the website; and
technical error and security information.
The processing of such data is necessary to ensure the functionality, stability and security of the website. The legal basis for processing by us is Art. 6(1)(f) GDPR. Squarespace acts as a processor on our behalf for certain processing activities. For certain technical website usage information, Squarespace may also process personal data as an independent controller in accordance with its own privacy policy. Further information about Squarespace's processing of personal data can be found in the Squarespace Privacy Policy.
4. Server Log Files
When you access our website, technical information may automatically be transmitted by your browser and stored temporarily in server log files. Such information may include:
IP address;
date and time of the request;
requested URL;
browser type and version;
operating system;
referrer URL; and
HTTP status information.
This processing is carried out for the purpose of ensuring the reliable operation and security of the website, detecting technical problems and preventing misuse. The legal basis is Art. 6(1)(f) GDPR. Log data is deleted or anonymised once it is no longer required for these purposes, unless longer storage is necessary in an individual case for security, evidence or legal reasons.
5. Cookies and Similar Technologies
Our website uses cookies and similar technologies. Cookies are small files or pieces of information that are stored on or accessed from your device when you visit a website.
5.1 Technically Necessary Cookies
Certain cookies and similar technologies are necessary for the operation, security and basic functionality of our website. Where the storage of information on your device or access to information already stored on your device is strictly necessary to provide the website or a service expressly requested by you, such storage or access is permitted in accordance with Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Where personal data is processed in connection with such technologies, the processing is generally based on Art. 6(1)(f) GDPR.
5.2 Non-Essential Cookies
Cookies and similar technologies used for analytics, performance, personalisation or marketing purposes are only activated where required after you have given your consent. In these cases, the storage of or access to information on your device is based on Section 25(1) TDDDG and the subsequent processing of personal data is based on Art. 6(1)(a) GDPR. You may refuse non-essential cookies without affecting the basic functionality of the website. You can change or withdraw your consent at any time through the cookie settings available on our website. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
6. Squarespace Analytics
We may use Squarespace Analytics to obtain statistical information about how visitors use our website. Depending on the settings and your consent, this may include information such as:
pages viewed;
approximate visitor numbers;
visitor sources;
session information;
interactions with the website;
browser and device information; and
other technical usage information.
Where Squarespace Analytics uses non-essential cookies or similar technologies, these technologies are activated only after you have given your consent. The legal basis for such processing is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. You may withdraw your consent at any time via the cookie settings on our website. Where analytics information is processed without the use of non-essential cookies and without accessing information on your device, processing may be based on our legitimate interest in obtaining aggregated information about the technical use and performance of our website pursuant to Art. 6(1)(f) GDPR, provided that the applicable legal requirements are met.
7. Contact by E-Mail, Telephone or Contact Form
If you contact us by e-mail, telephone or through a contact form on our website, we process the information you provide in order to handle and respond to your enquiry. Depending on the nature of your enquiry, this may include:
your name;
company or organisation;
email address;
telephone number;
information contained in your message; and
any documents or other information you provide voluntarily.
If your enquiry relates to a potential or existing contractual relationship, processing is based on Art. 6(1)(b) GDPR. For general business communication, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the efficient handling of enquiries and communication with customers, prospective customers and business partners. Where you submit information through a Squarespace contact form, the information is also processed by Squarespace for the purpose of transmitting and managing your enquiry. We retain correspondence for as long as necessary to deal with your enquiry and any subsequent business relationship. Data may be stored for longer periods where statutory retention requirements apply or where storage is necessary to establish, exercise or defend legal claims.
8. E-Mail Communication
When you communicate with us by e-mail, the information contained in your message as well as technical communication data is processed by our email and IT service providers. We use service providers acting on our behalf in accordance with Art. 28 GDPR where applicable. Please note that ordinary email communication may have inherent security risks. For confidential or particularly sensitive information, please contact us beforehand so that an appropriate communication method can be agreed upon.
9. Recipients of Personal Data
We do not sell your personal data. Personal data may be disclosed to service providers or other recipients where this is necessary for the purposes described in this Privacy Policy. Recipients may include, in particular:
website hosting and IT service providers;
email and communication service providers;
technical support providers;
professional advisers such as lawyers, tax advisers or auditors;
public authorities where disclosure is required by law; and
other service providers engaged to support our business operations.
Where service providers process personal data on our behalf, they are contractually bound in accordance with Art. 28 GDPR where required.
10. International Data Transfers
Some of our service providers, including companies within the Squarespace group, may process personal data outside the European Economic Area (EEA), including in the United States. Where personal data is transferred to a country outside the EEA, we ensure that the applicable requirements of Chapter V GDPR are met. Depending on the recipient and destination country, transfers may be based on:
an adequacy decision by the European Commission;
the EU-U.S. Data Privacy Framework, where applicable;
Standard Contractual Clauses approved by the European Commission pursuant to Art. 46 GDPR; or
another legally recognised transfer mechanism.
Squarespace states that transfers to participating entities in the United States may rely on the EU-U.S. Data Privacy Framework and that Standard Contractual Clauses or other safeguards are used where required.
11. Storage Period
We retain personal data only for as long as necessary for the respective processing purpose. The specific retention period depends on the type of data and the purpose for which it is processed. Personal data may be retained for longer periods where:
statutory retention obligations apply;
retention is required for contractual purposes; or
the data is required for the establishment, exercise or defence of legal claims.
Once the relevant purpose ceases to apply and no statutory or contractual retention obligation remains, the data will be deleted or anonymised.
12. Your Rights under the GDPR
Subject to the conditions set out in the GDPR, you have the following rights regarding your personal data:
Right of access pursuant to Art. 15 GDPR;
Right to rectification pursuant to Art. 16 GDPR;
Right to erasure pursuant to Art. 17 GDPR;
Right to restriction of processing pursuant to Art. 18 GDPR;
Right to data portability pursuant to Art. 20 GDPR;
Right to object pursuant to Art. 21 GDPR; and
Right to withdraw consent pursuant to Art. 7(3) GDPR.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal. To exercise your rights, please contact:
SONOJET GmbH
Email: contact@sonojet.com
13. Right to Object
Where we process your personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation in accordance with Art. 21 GDPR. If you object, we will no longer process the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing is required for the establishment, exercise or defence of legal claims. Where personal data is processed for direct marketing purposes, you have the right to object to such processing at any time.
14. Right to Lodge a Complaint
You have the right to lodge a complaint with a competent data protection supervisory authority pursuant to Art. 77 GDPR. The supervisory authority responsible for data protection in Saxony is:
Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17, 01067 Dresden, Germany
Postal address:
Postfach 11 01 32, 01330 Dresden, Germany
Phone: +49 351 85471-101
Email: post@sdtb.sachsen.de
You may also contact another competent supervisory authority, in particular the supervisory authority at your habitual residence, place of work or place of the alleged infringement.
15. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Our website uses encrypted HTTPS/TLS connections to protect data transmitted between your browser and our website. However, no method of transmission or electronic storage can guarantee absolute security.
16. Automated Decision-Making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR in connection with the operation of this website.
17. Changes to this Privacy Policy
We may amend this Privacy Policy where necessary, for example if we change our website, introduce new services or where legal requirements change. The current version of this Privacy Policy is available on our website.
Last updated: 20 August 2026