Controller
The controller responsible for processing personal data on this website is:
Impression LabsWebsite access
When you request a page, the systems used to deliver and protect this website can automatically process technical connection data. This can include your IP address, the date and time, the requested file, referrer information, browser and operating-system details, transferred data volume, and the response status.
Processing is necessary to serve the website reliably, maintain technical security, detect abuse, and investigate faults. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.
Technical log data is retained only for as long as it is needed for delivery, security, and troubleshooting. It may be kept longer where a specific security incident must be investigated or a legal obligation or claim requires it.
Contact by email
If you contact us by email, we process the information you choose to send, typically your email address, name, message, and technical message metadata. We use it to answer you and manage the resulting communication.
Where your message concerns a possible or existing contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, the basis is our legitimate interest in responding and maintaining business communication under Article 6(1)(f) GDPR.
We delete correspondence when it is no longer required for the enquiry or business relationship, unless statutory retention duties or the establishment, exercise, or defence of legal claims require longer storage.
Cookies and tracking
This website does not set cookies and does not use analytics, advertising trackers, tracking pixels, user accounts, or contact forms.
The email link opens your own email application. Sending an email is your decision and is then handled by the email providers involved in delivery.
Recipients
Technical data may be processed by hosting, infrastructure, security, or email providers where this is necessary to operate the website and communications. Where a provider acts on our behalf, it is bound by data-protection requirements.
We disclose personal data to public authorities or other recipients only where required by law, necessary to protect legal rights, or otherwise permitted under applicable data-protection law.
International transfers
We do not add services to this website for the purpose of transferring visitor data outside the European Economic Area. If an infrastructure provider processes data in a country outside the EEA, the transfer must be covered by an applicable GDPR safeguard, such as an adequacy decision or standard contractual clauses, together with any supplementary measures required.
Your rights
Subject to the legal requirements, you may have the right to:
- request access to and a copy of your personal data;
- have inaccurate data corrected;
- request erasure or restriction of processing;
- receive data you provided in a portable format;
- object to processing based on legitimate interests; and
- withdraw consent at any time where processing relies on consent.
You also have the right to lodge a complaint with a competent data-protection supervisory authority, in particular in the EU member state where you live, work, or believe an infringement occurred.
To exercise a right, email [email protected]. We may need enough information to verify your identity and locate the relevant data.
Automated decisions
We do not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.
Security and updates
We use appropriate technical and organisational measures designed to protect personal data against accidental loss, misuse, or unauthorised access. No internet transmission or storage system can be guaranteed to be completely secure.
We may update this notice when the website, our processing, or the legal framework changes. The current version and its effective date will remain available on this page.