Thank you for visiting our website. Protecting your personal data is important to us. This privacy policy explains how we process your data when you use this website, in accordance with the General Data Protection Regulation (GDPR) and the German Telecommunications-Telemedia Data Protection Act (TTDSG).

1. Controller and Data Protection Officer

The controller responsible for data processing on this website is:

UNEX Management Consulting GmbH & Co. KG
Bei den Mühren 1, D-20457 Hamburg, Germany
Phone: +49 (40) 822 16 855
Email: hamburg@unex-group.com

For questions about data protection, please contact our Data Protection Officer at datenschutz@unex-group.com

2. What is personal data?

Under Art. 4 (1) GDPR, personal data means any information relating to an identified or identifiable natural person – for example a name, address, phone number, email address or IP address.

3. Collection and processing of personal data

3.1 Visiting our website (server log data)

When you use our website for purely informational purposes, we only collect the data your browser technically transmits to our server or that of our hosting provider. The legal basis is our legitimate interest in a stable and secure website, Art. 6 (1)(f) GDPR. This includes in particular:

  • IP address
  • date and time of the request
  • the page requested
  • access status/HTTP status code and amount of data transferred
  • referring website
  • browser, operating system and language settings

3.2 Password-protected preview area

Individual areas of this website are password-protected internal previews. The access status is stored only locally in your browser (sessionStorage) and is not transmitted to our server. This storage is technically necessary to provide the protected feature; no consent is required under § 25 (2) No. 2 TTDSG. No user profile is created, and the information is deleted once you close the browser tab or session.

3.3 Contact form ("Let's talk")

Our contact form lets you request a live demo or an initial conversation. We process the data you enter (first name, last name, business email address, optionally company, phone number and your message) to handle your request. Submission is technically routed through the form interface of our provider HubSpot (HubSpot Ireland Ltd., Ireland, and/or HubSpot, Inc., USA) within the EU data region ("eu1"). If the HubSpot connection is not active in an individual case, the form instead opens a pre-filled email in your own email client; in that case your details are sent directly to UNEX by email rather than to HubSpot.

The legal basis is your consent under Art. 6 (1)(a) GDPR, given by ticking the consent checkbox before submitting, as well as our legitimate interest in handling your enquiry under Art. 6 (1)(f) GDPR. You may withdraw your consent at any time with future effect by contacting our Data Protection Officer. For more information on HubSpot's data processing, see HubSpot's privacy policy.

3.4 Interactive Power BI dashboards

On individual pages we embed sample dashboards built with Microsoft Power BI. These are not loaded automatically but only once you actively click the dashboard preview ("click-to-load"). Only at that point is a connection established to Microsoft's servers (Microsoft Ireland Operations Ltd. and/or Microsoft Corporation, USA) and your IP address transmitted to Microsoft. The legal basis is your implied consent given by clicking, Art. 6 (1)(a) GDPR. See Microsoft's privacy statement for details.

3.5 Telephone outreach

Where we contact you by phone for an initial approach, we use data from public sources or information you have provided yourself. The legal basis is our legitimate interest under Art. 6 (1)(f) GDPR, as we only contact B2B counterparts regarding matters connected to their business activity.

3.6 Client and engagement data

If you enter into a consulting engagement with us, we process your contact, billing and contract data for the purpose of initiating and performing that contract, Art. 6 (1)(b) GDPR.

3.7 Marketing to existing clients

Within an existing business relationship we may use your email address and postal address to inform you about our own, similar products and services, Art. 6 (1)(f) GDPR in conjunction with § 7 (3) UWG. You may object to this use at any time, free of charge beyond basic transmission costs.

4. Cookies, local storage and similar technologies

4.1 Technically necessary storage

We only use technically necessary storage technologies (see section 3.2). No consent is required for this under § 25 (2) No. 2 TTDSG.

4.2 Fonts

The font used on this website (Manrope) is self-hosted and served from our own server. No connection is made to Google or any other external font provider, and no data is transmitted to them.

4.3 No analytics or marketing cookies

We currently do not use any web analytics, tracking or marketing cookies. Should we introduce such services (e.g. web analytics) in the future, we will obtain your prior consent via a cookie consent banner under § 25 (1) TTDSG in conjunction with Art. 6 (1)(a) GDPR and update this privacy policy accordingly.

5. Embedded services and social networks

We link to our LinkedIn company page and to the personal LinkedIn profile of our contact person. These are plain links, not embedded plug-ins. Only once you click the link are you redirected to the respective platform, where that provider's own privacy policy applies.

6. Recipients and processors

Depending on the processing purpose described above, the following recipients may access your data to the extent necessary for their function:

  • HubSpot (HubSpot Ireland Ltd. / HubSpot, Inc.) – processing of the contact form, EU data region
  • Microsoft (Microsoft Ireland Operations Ltd. / Microsoft Corporation) – display of Power BI dashboards after clicking
  • our commissioned hosting and IT service providers under data processing agreements, Art. 28 GDPR

We have entered into data processing agreements, or rely on appropriate safeguards for transfers to third countries (e.g. EU Standard Contractual Clauses), with all processors. Processors may not use your data for their own purposes.

7. Data deletion and retention

Your personal data is deleted or restricted as soon as the purpose of storage no longer applies, unless statutory retention obligations require otherwise.

8. Protection of your data

We use technical and organisational security measures to protect your data against manipulation, loss, destruction or unauthorised access, and continuously adapt these to the state of the art. Complete security cannot be guaranteed for data transmitted unencrypted over the internet (e.g. by email).

9. Your rights as a data subject

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing (Art. 21). To exercise these rights, please contact our Data Protection Officer. You also have the right to lodge a complaint with a data protection supervisory authority – in our case, in particular, the Hamburg Commissioner for Data Protection and Freedom of Information.

10. Currency and changes to this privacy policy

We update this privacy policy whenever our data processing or the legal situation changes. The version published on this page at any given time applies.

Last updated: 25 July 2026