Zum Inhalt springen

Legal

Privacy

This notice informs you under Article 13 GDPR which personal data is processed when you visit this website and contact us. For application flows we operate on behalf of employers, see section 12. This translation is provided for convenience; the German version is legally binding.

As of September 2026

1. Controller

The controller within the meaning of Article 4(7) GDPR is:

Hironaut Sole proprietorship Owner: Sascha Denis Blömer Grünewalder Straße 29–31, Haus 4 42657 Solingen Germany Email: datenschutz@hironaut.de

No data protection officer has been appointed, as the requirements for mandatory appointment under § 38 BDSG and Article 37 GDPR are not met.

2. Overview

This website provides information about our services. It has no newsletter, no user accounts, no embedded videos and no social media buttons. It sets no analytics or advertising cookies and loads no fonts or scripts from Google, Meta or other advertising networks. In particular, no Meta pixel is used on this website.

Personal data arises when the page is technically retrieved (sections 3 and 4), in the enquiry chat (section 6) and when you contact us by email (section 7).

3. Hosting

This website runs on the Onepage platform, provided by Onepage GmbH, Hanauer Landstraße 172, 60314 Frankfurt am Main, Germany. Onepage uses data centres of Amazon Web Services and Google Cloud which, according to the provider, are located exclusively in the European Union. Fonts are served by Onepage itself.

A data processing agreement under Article 28 GDPR is in place with Onepage. The legal basis is our legitimate interest in providing the website securely (Article 6(1)(f) GDPR).

4. Access data and logs

When you open a page, your browser technically transmits IP address, date and time, address requested, status code, amount of data transferred, and browser type and operating system. For error analysis and system security, Onepage stores IP address, request type and status code of a small share of requests for one month and provides reach statistics without personal reference.

The legal basis is Article 6(1)(f) GDPR.

5. Cookies and storage on your device

This website sets no cookies that require consent, which is why we do not show a consent banner. When you switch language, we store your choice in your browser’s local storage and, for the duration of the page change, the scroll position in session storage; this is strictly necessary for the function you requested (§ 25(2) No. 2 TDDDG) and is not transmitted to us. Onepage may set technically necessary cookies required to deliver the page and protect it against attacks.

6. Enquiries through the enquiry chat

When you write to us through the enquiry chat, we process topic, description of your request, name, email address and optionally your company, solely to answer your enquiry and, where relevant, to prepare an offer. The chat is a guided flow with fixed questions; no artificial intelligence is used. Your details are only transmitted when you tap send and are stored in Onepage’s customer management system.

The legal basis is Article 6(1)(b) GDPR insofar as your enquiry concerns a contract, otherwise Article 6(1)(f) GDPR. Retention is governed by section 11.

7. Contact by email

When you contact us by email, we process your contact details and the content of your enquiry to answer it. The legal basis is Article 6(1)(b) or (f) GDPR. For email we use a provider with servers in Germany as a processor.

8. Contact via WhatsApp

This contact option is not enabled for this website at present. Before we enable it, we will complete this section with all details on the provider, technical service provider, third-country transfers and any AI-assisted replies.

9. Recipients

Recipients are Onepage GmbH as processor for hosting and customer management with sub-processors Amazon Web Services and Google Cloud (data centres in the EU), and our email provider. Agreements under Article 28 GDPR are in place with all processors. Data is only passed to other third parties if we are legally obliged to do so.

10. Transfers to third countries

Processing takes place within the European Union. Onepage’s sub-processors are subsidiaries of US groups; according to the provider, data is processed exclusively in EU data centres. In case of access from the USA, both parent companies are certified under the EU-US Data Privacy Framework (Article 45 GDPR).

11. Retention

– access logs at Onepage: at most one month – enquiries without a contract: until resolved, at most twelve months – contract-related correspondence: six to ten years under § 257 HGB and § 147 AO

12. Application flows on behalf of employers

We build and operate recruiting funnels, ads and applicant management for employers. If you apply through such a flow or are contacted through it, the respective employer is the controller under the GDPR. We act as a processor under Article 28 GDPR on the basis of a contract with the employer. Funnel, ads and messages run under the employer’s name, with its imprint and privacy notices.

In that case you receive the information under Articles 13 and 14 GDPR from the employer, usually in the application form. You exercise your rights towards the employer; we support them in doing so. Requests that reach us directly are forwarded to the controller. No assessment of applicants by artificial intelligence takes place in the flows we operate; pre-qualification follows fixed rules set by the employer.

13. Your rights

– access (Article 15 GDPR) – rectification (Article 16 GDPR) – erasure (Article 17 GDPR) – restriction of processing (Article 18 GDPR) – data portability (Article 20 GDPR) – withdrawal of consent (Article 7(3) GDPR)

An informal message to datenschutz@hironaut.de is enough. We reply within one month.

14. Right to object

Where we process your data on the basis of a legitimate interest, you may object at any time on grounds relating to your particular situation (Article 21(1) GDPR). We do not carry out direct marketing through this website; should we nevertheless send you promotional messages, you may object at any time (Article 21(2) GDPR).

15. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestraße 2–4 40213 Düsseldorf, Germany www.ldi.nrw.de

16. No automated decision-making

We make no decisions based solely on automated processing and carry out no profiling within the meaning of Article 22 GDPR. You are under no obligation to provide personal data; without contact details, however, we cannot answer an enquiry.

17. Encryption and changes

This website is delivered exclusively over an encrypted connection (TLS). We update this notice when the law, technology or services change. The version published here applies.