Controller
EA European Atlantic GmbH, Neuer Wall 10, 20354 Hamburg, Germany, is the controller. General and privacy-related enquiries should be sent to mail@european-atlantic.com for the attention of Daniel Harbeck. No data protection officer has been appointed because the current assessment does not indicate a statutory appointment requirement.
- General contact: mail@european-atlantic.com
- Privacy contact: Daniel Harbeck via mail@european-atlantic.com
- Phone (initially answered by AI assistant “Europa”): +49 40 2285 8520
Purposes and legal bases
Personal data is processed on this website only to the extent necessary for technical website delivery, handling contact requests, complying with legal obligations, or protecting legitimate interests in secure and functional website operations. Relevant legal bases generally include Article 6(1)(b) GDPR, Article 6(1)(c) GDPR, Article 6(1)(f) GDPR, and, for optional audience measurement, Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
- Website delivery and the maintenance of stability and security
- Handling of incoming requests and pre-contract communication
- Compliance with legal retention or verification duties where applicable
- Optional analysis of website usage only after prior consent
Hosting, server logs, and security
When the website is accessed, the hosting and server setup processes technically necessary connection and log data such as IP address, timestamps, requested content, status details, and browser or device information. This is used for website delivery, troubleshooting, and protection against misuse, spam, fraud attempts, phishing, malicious bots, automated attacks, and other security incidents.
- Technically necessary log data is kept only as long as needed for operations, troubleshooting, and security
- No broader use for marketing or optional tracking is intended in the current website baseline
Website security and abuse detection
Custom, self-managed, and externally provided controls identified below are used to secure the website. Security-relevant requests, technical access patterns, and form submissions may be checked in order to detect, document, and respond appropriately to misuse, attack attempts, and automated manipulation. This processing helps protect the website, communication channels, and underlying technical infrastructure.
- Detection of spam, scam, phishing, and fraud attempts
- Protection against malicious bots, credential attacks, infrastructure attacks, and abuse of forms or interfaces
- Assessment of technical patterns, including possible prompt-injection or automated manipulation attempts
- Security data is processed in line with data minimization, pseudonymization or redaction, and limited retention periods
Form protection with Cloudflare Turnstile
We use Cloudflare Turnstile to protect our contact forms against automated submissions, spam, and abuse. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When a protected form is accessed and used, Turnstile processes minimal technical signals to distinguish human access from bots and to confirm a successful check on the server. This security processing is necessary to provide the form securely and is not used for advertising or audience measurement.
- Processed signals may include the client IP address, TLS fingerprint, User-Agent header, the public sitekey and associated origin, and the verification result
- Cloudflare processes signals on our behalf to provide the Turnstile service and, according to its notice, also acts as a controller where signals are used to improve bot detection
- The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protecting forms and communication channels against bots, spam, fraud, and automated attacks. Where access to information on the terminal device is necessary, Section 25(2) TDDDG applies
- Cloudflare is a global provider and states that it primarily stores information in the United States and the European Economic Area. For international transfers, Cloudflare identifies the EU-US Data Privacy Framework and Standard Contractual Clauses as relevant safeguards
- Further information: https://www.cloudflare.com/turnstile-privacy-policy/ and https://www.cloudflare.com/privacypolicy/
Legitimate interest in protection and operations
Security processing is based, where applicable, on Article 6(1)(f) GDPR. The legitimate interest is the protection of the website, communication channels, customers, employees, business partners, and digital infrastructure against misuse and attacks. This includes defending against spam, internet abuse, fraud, phishing, cybercrime, malicious bots, credential attacks, infrastructure attacks, abuse of communication systems, economic crime, business espionage, and automated manipulation or prompt-injection attempts. Processing also helps safeguard the availability, integrity, confidentiality, and operational security of digital systems and communication channels.
- Security processing is not used for audience measurement, advertising, or marketing profiling
- Checks are limited to what is needed for security, troubleshooting, and abuse detection
- The interests and fundamental rights of data subjects are taken into account through data minimization, content redaction, and limited retention periods
Contact form and business inquiries
The contact form processes name, email address, company, service area, message, and acknowledgement of the privacy notice so that enquiries can be assigned and answered. Pre-contract enquiries are processed under Article 6(1)(b) GDPR; other business communication is based on the legitimate interest in handling business enquiries under Article 6(1)(f) GDPR. The required checkbox records acknowledgement of this notice and is not consent to processing.
- Collected fields: name, email, company, service area, message
- Processing for inquiry handling, proposal preparation, and business initiation
- Storage only for as long as needed for the inquiry, follow-up communication, or legal obligations
AI-Readiness Quick Check
The AI-Readiness Quick Check is a rules-based self-assessment tool. In the current version, the twelve assessment answers, dimension scores, overall score, and result level are processed only temporarily in the memory of the open browser tab. This assessment data is not transmitted to EA or an assessment provider, is not stored on the server, and is not placed in cookies, local storage, session storage, or IndexedDB. Reloading or closing the tab discards it.
- The normal page request generates technically necessary hosting and server log data; it does not contain the selected answers or calculated result values
- Consent-based audience measurement may record the page view; answers, dimension scores, overall score, and result level are not transmitted as analytics events
- PDF and PNG result files are generated in the browser and are stored only in the location selected by the user
- The prepare email function merely opens a local draft in the configured email application and inserts the overall score and result level. Data is transmitted only if the user sends the message; the information on contact communication then applies
- The Quick Check does not make an automated decision with legal or similarly significant effects
Language handling, cookies, and consent
WPML is used for the multilingual setup of the website. When users actively switch languages, a technically or functionally necessary language-preference cookie may be stored so that the selected language version remains consistent across further page views. The website also uses a lightweight first-party consent script that stores the choice regarding optional audience measurement for 180 days.
- Language preference and language switching via WPML
- Consent choice through the cookie banner and cookie settings control
- Technically necessary security and functional processing remains separate from optional analytics
Optional audience measurement with Google Analytics
Google Analytics 4 is used on the live website for statistical analysis of website usage. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics is loaded only after explicit consent. Without consent, no analytics tags are executed. Processing by Google LLC in the United States cannot be ruled out and is based on the applicable transfer mechanism, in particular the EU-US Data Privacy Framework or Standard Contractual Clauses.
- The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG for non-essential cookies or comparable technologies
- Consent can be withdrawn at any time with future effect through the cookie settings
- The configuration is intended for analytics without advertising or personalization purposes; related signals are disabled
- The website does not set its own User ID for Google Analytics; website consent signals for advertising and personalisation remain disabled
- On withdrawal, the website attempts to delete existing Google Analytics cookies where technically possible through the website
AI-powered telephone assistant
Inbound calls to the central telephone number may initially be answered by “Europa”, EA’s AI assistant. EA uses the sipgate AI Agent only for inbound calls and never for outbound calls (as of July 2026). sipgate technically processes spoken content to enable the interaction and provide EA with a call transcript. The processing is intended to capture and route legitimate enquiries and to reduce spam, scam, and unwanted calls. Please do not disclose confidential or highly sensitive information by telephone.
- Processed data may include the calling number, time, spoken content technically processed to conduct the call, transcript, enquiry, and routing information
- sipgate GmbH acts as a processor. According to sipgate’s product information, AI Agent data is processed in the EU and is not used to train AI models
- Pre-contract enquiries are processed under Article 6(1)(b) GDPR; other business enquiries are based on Article 6(1)(f) GDPR and the legitimate interest in efficient and secure inbound communication
- Anyone who does not wish to use this channel can end the call and contact mail@european-atlantic.com by email
- Transcripts are available only to authorised people in the sipgate account and people who need them to handle the enquiry
- EA deletes available transcripts once they are no longer needed for handling the enquiry and permissible evidence purposes and no statutory retention duty applies
Recipients, processors, and transfers
Within EA, personal data is available only to people who need it for operations, security, or handling an enquiry. External recipients are used only where required for hosting, telecommunications, email delivery, consent-based analytics, or legal duties and where an appropriate contract or other legal basis is in place.
- Hosting and technical delivery: Host Europe under the contracted services
- Telephone assistant and telephony: sipgate GmbH
- Form protection and bot detection: Cloudflare, Inc. through Cloudflare Turnstile
- Optional audience measurement: Google Ireland Limited, with possible onward processing by Google LLC
- AegisPress and other local anti-spam checks are self-managed; new external recipients are reviewed before activation and added to this notice
Retention and deletion
Data is deleted or anonymised when it is no longer needed for its purpose and no statutory retention, evidence, or security requirement applies. Enquiry data is generally retained for the handling period and relevant follow-up; where an engagement results, applicable commercial and tax retention duties apply. Security logs are deleted after a limited risk-based period. We review retention periods regularly and adjust them when the processing or legal requirements change.
- Consent choice: 180 days
- Contact and business correspondence: until the enquiry is completed, and afterwards only where a follow-up purpose or legal duty remains
- Telephone transcript: until the enquiry is completed and afterwards only where a follow-up purpose or legal duty remains
- Google Analytics: according to the event-data retention period configured in the Analytics account; aggregated reports may remain available longer without a direct personal reference
Automated decisions and AI assistance
Neither this website nor the telephone assistant makes solely automated decisions with legal or similarly significant effects within the meaning of Article 22 GDPR. AI may support research, structuring, translation, development, quality assurance, and preparation of communication. EA remains responsible for publication and business decisions. Personal or confidential information may be processed only in approved systems and on an appropriate legal and contractual basis.
Your rights
Under the GDPR, data subjects generally have rights of access, rectification, erasure, restriction, portability, and objection where applicable. There is also a right to lodge a complaint with a competent supervisory authority.
- Privacy contact: Daniel Harbeck via mail@european-atlantic.com
- Right to lodge a complaint, in particular with the Hamburg Commissioner for Data Protection and Freedom of Information or another competent supervisory authority