Privacy Policy
GDPR · Last updated 28 April 2026
This policy explains how A.R.C. Laser GmbH collects, uses, and protects personal data when you visit trublue-laser.com. It follows Regulation (EU) 2016/679 (GDPR) and the German Bundesdatenschutzgesetz (BDSG).
1. Controller
A.R.C. Laser GmbH, represented by its Managing Director Angela Thyzel, is the controller responsible for the processing of personal data on this website.
A.R.C. Laser GmbH
Bessemerstr. 14
90411 Nürnberg, Germany
Phone: +49 (0) 911-21779-0
Email: info@arclaser.de
2. Categories of Data We Process
- Technical data — IP address, browser type, operating system, referring URL, access time, pages viewed.
- Contact / lead-form data — the name, email, role, institution, country, clinical specialty, and message you voluntarily submit.
- Communications — content of emails, phone calls, or fax correspondence you send to us.
- Cookie / consent data — if and when cookies are used, the state of your consent selection.
3. Purposes and Legal Bases
- Providing the website (Art. 6 (1) (f) GDPR — legitimate interest in a secure, functional site).
- Handling inquiries submitted via the lead form or by email (Art. 6 (1) (b) GDPR — steps prior to entering a contract; or Art. 6 (1) (f) — legitimate interest in responding to business inquiries).
- Legal and tax retention (Art. 6 (1) (c) GDPR — compliance with § 257 HGB, § 147 AO).
- Consent-based processing where you have explicitly opted in (Art. 6 (1) (a) GDPR), revocable at any time with effect for the future.
4. Retention Periods
- Server log data: up to 7 days, then anonymized or deleted.
- Lead-form submissions: retained for the duration of our business correspondence, up to 3 years after last contact, unless legal retention periods require longer.
- Accounting-relevant correspondence: 6 or 10 years per German tax law.
5. Recipients and Processors
Personal data is only shared with third parties where strictly necessary to deliver the service and where the third party is bound by a Data Processing Agreement (Auftragsverarbeitungsvertrag) pursuant to Art. 28 GDPR.
5.1 Hosting Provider
This website is hosted by KREATIKA Maximilian A. Grimm, Kuglerstraße 2, 90449 Nürnberg, Germany. A Data Processing Agreement pursuant to Art. 28 GDPR is in place.
6. International Transfers
Personal data is processed in the European Union. Should we occasionally use processors outside the EU, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision under Art. 45 GDPR.
7. Your Rights as a Data Subject
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR). In Bavaria: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
To exercise any of these rights, contact us at info@arclaser.de.
8. Cookies
This website uses technically necessary cookies only. Any additional cookies (analytics, marketing) would be introduced solely after your explicit opt-in through the cookie consent banner, and you may revoke that consent at any time.
9. Security
We apply current technical and organizational measures to protect personal data against loss, alteration, or unauthorized access — including TLS encryption of all connections, access control on our hosting infrastructure, and minimization of the data we collect.
10. Changes to This Policy
We may update this policy to reflect changes in the service or applicable law. The current version is always available on this page with the “last updated” date at the top.