Privacy

Privacy Policy

Information about processing personal data on the website and through form and telephone contacts.

Last updated: 13 August 2026

Controller

EA European Atlantic GmbH
Neuer Wall 10
20354 Hamburg
Germany
mail@european-atlantic.com
+49 40 2285 8520

Hosting and server logs

This website is hosted on a Host Europe server. When pages are requested, technically necessary log data may be processed, including IP address, timestamp, requested resource, response status, referrer and user agent. Processing serves secure and reliable operation on the basis of our legitimate interests under Article 6(1)(f) GDPR.

Contact and investor enquiries

When you use a form, we process the information you provide—typically name, business contact details, organization, role and enquiry details—to respond and prepare a possible pilot conversation or assess stated investor interest. The pilot briefing additionally asks about the operational problem and target outcome, relevant systems, scale, data sensitivity, human-review and deployment requirements, initiative stage, timing, an indicative pilot investment range, baseline readiness and an optional case-publication preference. The investor form additionally asks about investor type, typical stage and ticket range. These structured details are used to assess fit and propose a relevant next step before further materials are shared. A stated publication preference is exploratory and does not authorize publication; any case publication requires a separate agreement and approval. The legal basis is Article 6(1)(b) GDPR for pre-contractual requests and otherwise Article 6(1)(f) GDPR for business communication and the structured handling of relevant inbound interest. We retain the information only as long as necessary for the request and applicable retention obligations.

Form and security protection

Contact forms are provided with Contact Form 7. AegisPress analyzes requests locally for abuse and spam signals. It is configured to minimize stored data: salted IP hashes support grouping, raw IP storage is disabled by default, and payload excerpts are redacted and truncated. Security records are normally retained for up to 30 days unless a different reviewed setting is required. The legal basis is Article 6(1)(f) GDPR.

Form protection with Cloudflare Turnstile

For the live website, Cloudflare Turnstile is used to protect contact forms against automated submissions, spam and abuse. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile processes minimal technical signals—including IP address, TLS fingerprint, user agent, the public site key and the verification result—to distinguish people from bots and confirm the check on the server. The service is not used for advertising or audience measurement.

The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the protection of forms and communication channels. Where access to information on the terminal device is necessary, Section 25(2) TDDDG applies. Cloudflare is a global provider and may process information outside the EU/EEA using the transfer mechanisms it identifies, including the EU–US Data Privacy Framework and standard contractual clauses.

Cookies and analytics

The website uses technically necessary functions by default. On the live domain, Google Analytics 4 is used for optional audience and conversion measurement only after explicit consent. This includes parameter-free events for visits to pilot or investor contact paths, opening product views, starting a form and successful form delivery. No form values, names, email addresses, free text or investor details are sent as analytics event parameters. Before consent, analytics and advertising consent signals remain denied; after consent, only analytics storage is granted. No advertising or personalization functions are activated through this consent.

Google Analytics is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The consent can be withdrawn through the cookie settings. The website then prevents renewed analytics loading and attempts to remove reachable _ga and _ga_* cookies. The legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Google may also process data in the United States. Google states that it uses the EU–US Data Privacy Framework and, where required, standard contractual clauses as transfer mechanisms. Details and information about obtaining the clauses are available in Google’s data-transfer framework.

The Logicore Analytics property is configured to retain cookie-linked user-level and event-level data for 14 months. The user-data retention period restarts when new user activity is recorded. This setting does not govern data in standard aggregated Analytics reports. Further details about Analytics cookies appear in the Cookie Policy.

AI-assisted telephone contact

Incoming calls to our central number may initially be handled by “Europa”, an AI assistant based on the sipgate AI Agent. sipgate GmbH processes the spoken content to conduct the interaction and provides EA with a transcript; EA does not use the assistant for outgoing calls. The processing serves the handling and routing of enquiries and, depending on the context, is based on Article 6(1)(b) or (f) GDPR. Callers can end the call and use email instead.

Recipients and transfers

Service providers may process data on our behalf where required for hosting, email delivery, technical support, form protection, optional analytics or the telephone assistant and are bound through appropriate agreements. Relevant providers include Host Europe, Cloudflare, Google and sipgate. Depending on the provider and configuration, processing outside the EU/EEA may occur using an applicable adequacy decision or other appropriate safeguards. We do not sell contact data, and the website does not send contact-form content to external AI providers.

Retention

Server logs, security records and contact data are retained only for as long as required for their respective purpose, incident investigation, contractual communication or statutory obligations. The security configuration currently provides for a normal retention period of up to 30 days for AegisPress records.

Automated decisions

The website and telephone assistant do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect visitors or callers. Automated security checks can reject or flag abusive form requests; legitimate enquiries can also be sent by email.

Your rights

Subject to the legal requirements, you may request access, rectification, erasure, restriction, data portability or object to processing. You may also lodge a complaint with a competent supervisory authority. Contact us at mail@european-atlantic.com.

Changes

We update this notice when the website, providers or legal requirements change materially.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.