Home / Imprint

Data Protection

Penta Techsystems GmbH

As of July 2026

The protection of your personal data and the safeguarding of your privacy are of paramount importance to us. We process personal data exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

This privacy policy applies to the use of the website provided at www.pentatechsystems.com

This privacy notice informs you about which personal data we process when you use our website and service portal, for what purposes this is done, and what rights you have as a data subject.

We implement technical and organizational measures to ensure a level of protection appropriate to the risk and to protect your data from loss, misuse, unauthorized access and unauthorized disclosure.

Responsible person

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Penta Techsystems GmbH
Maistraße 21, 85405 Nandlstadt, Germany

Represented by the managing directors: Zeeshan Sabir, Abid Anjum

Telephone: +49 163 1483067
Email: info@pentatechsystems.com
Web: www.pentatechsystems.com

Commercial Register: Munich District Court, HRB 311252

VAT ID No.: DE 462728526

Penta Techsystems GmbH is the data controller responsible for the processing of personal data in connection with the operation of this website and the service portal.


Accessing our website (server log files)

When you access our website, our web server automatically collects information and temporarily stores it in server log files. This includes, in particular:

  • IP address of the requesting device
  • Date and time of access
  • Page/file accessed and amount of data transferred
  • Notification of successful retrieval

This data is processed to ensure a smooth connection, technical stability, and for evaluation purposes related to IT security (e.g., defense against attacks). The legal basis for this processing is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the operation and security of our website. No personal data is analyzed; this data is not combined with other data sources.

Server log files are generally deleted after 90 days, unless longer retention is required in a specific case for evidentiary purposes (e.g., during ongoing security investigations). In this case, deletion occurs immediately after the reason for retention ceases to exist.


 Making contact

When you contact us (e.g. by email or via our contact form), we process the personal data you provide (e.g. name, contact details, content of your request) to process and respond to your request.

When using the contact form, the following information is required: name, email address, and message text. Providing additional information is optional. Form data is transmitted using TLS/SSL encryption.

The legal basis is Article 6(1)(b) GDPR if your request relates to the performance of a contract or pre-contractual measures, and otherwise Article 6(1)(f) GDPR (legitimate interest in responding to inquiries). The data will be deleted as soon as the request has been fully processed and no statutory retention obligations apply.

Purposes and legal bases of processing

Unless otherwise stated in the preceding sections, we process personal data for the following purposes:

  • Provision and operation of the website
  • Answering inquiries
  • Provision and use of the service portal
  • Ensuring IT security
  • Fulfillment of legal obligations (e.g., according to the German Commercial Code (HGB) and the German Fiscal Code (AO))

The legal basis for this includes, in particular:

  • Article 6 paragraph 1 letter b GDPR (contract / pre-contractual measures)
  • Article 6 paragraph 1 letter c GDPR (legal obligation)
  • Article 6 paragraph 1 letter f GDPR (legitimate interests, e.g. effective processing of processes, IT security)

Where we obtain consent in individual cases, the legal basis is Article 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future, e.g., by email to info@pentatechsystems.com.


Recipients of the data / Data processing

Within Penta Techsystems GmbH, only those departments that require your data to fulfill the aforementioned purposes will have access to it (in particular, IT, receivables management, customer service, and, if applicable, human resources). The legal basis for this intra-group transfer is Article 6(1)(f) GDPR (legitimate interest in efficient group-wide task allocation) or Article 6(1)(b) GDPR, insofar as the transfer is necessary for the performance of a contract.

We use service providers for the provision and maintenance of our IT infrastructure, as well as for hosting our website and service portal. These providers act as data processors on our behalf in accordance with Article 28 of the GDPR. They have been carefully selected, are contractually obligated to comply with data protection requirements, and process personal data exclusively on our instructions. This includes, in particular, providers in the categories of web hosting and data center operation, IT infrastructure and system support, and communication services. Processing takes place exclusively on servers within the European Union or the European Economic Area.

Personal data will only be disclosed to other third parties if this is legally permitted or required (e.g., to authorities and courts if there is a corresponding obligation) or if you have expressly consented.


Transfers to third countries

As a general rule, personal data is not transferred to recipients in countries outside the European Union (EU) or the European Economic Area (EEA) via this website.

Should a transfer to a third country be necessary in individual cases (e.g., when using certain IT services), we ensure that an adequate level of data protection exists in accordance with Art. 44 et seq. GDPR, for example through EU standard contractual clauses and supplementary measures.


Automated decision-making / profiling

No automated decision-making, including profiling as defined in Article 22 of the GDPR, takes place during purely informational use of our website and service portal. Should this change in the future, we will inform you separately and obtain any necessary consent.


Storage duration

Unless a more specific storage period is stated in this privacy policy, we only store personal data for as long as is necessary to achieve the stated purposes or as required by law.

Furthermore, we refer to our internal deletion and blocking concept, which provides for differentiated deadlines for the individual processing activities (e.g. receivables management, portals, HR, applicants).


Information request pursuant to Article 15 GDPR

You have the option of requesting information pursuant to Article 15 of the GDPR via our website. We provide a form for this purpose, which you can use to submit your request electronically. We process the data you enter solely for the purpose of processing and responding to your request.

The following data is processed as part of this form: first name, last name, email address, customer number or file number, the content of your request, and any other information you voluntarily provide. Mandatory fields are those required to process and assign your request. This processing is based on Article 6(1)(c) GDPR to fulfill our legal obligation to provide you with the information required under Article 15 GDPR.

To prevent misuse and protect your data, we may request additional information for identity verification if there are legitimate doubts. Your information will only be processed to the extent necessary for reviewing, processing, and responding to your request for information.

We process requests for information without undue delay, and at the latest within one month of receipt. In justified cases, this period may be extended; we will inform you of this in a timely manner. After processing is complete, the data will be deleted unless there are legal retention obligations or legitimate reasons for further storage.


Purposes and legal bases of processing

Unless otherwise stated in the preceding sections, we process personal data for the following purposes:

  • Provision and operation of the website
  • Answering inquiries
  • Provision and use of the service portal
  • Ensuring IT security
  • Fulfillment of legal obligations (e.g., according to the German Commercial Code (HGB) and the German Fiscal Code (AO))

The legal basis for this includes, in particular:

  • Article 6 paragraph 1 letter b GDPR (contract / pre-contractual measures)
  • Article 6 paragraph 1 letter c GDPR (legal obligation)
  • Article 6 paragraph 1 letter f GDPR (legitimate interests, e.g. effective processing of processes, IT security)

Where we obtain consent in individual cases, the legal basis is Article 6(1)(a) GDPR.


Your rights as a data subject

Within the framework of legal regulations, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to certain processing (Art. 21 GDPR)

Insofar as we base the processing on your consent, you have the right to withdraw this consent at any time with effect for the future (Art. 7 para. 3 GDPR).

Special note regarding your right to object pursuant to Article 21 GDPR

Insofar as we process your personal data based on our legitimate interests pursuant to Article 6(1)(f) GDPR, you have the right, pursuant to Article 21 GDPR, to object to this processing at any time on grounds relating to your particular situation. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of establishing, exercising or defending legal claims. To exercise your right to object, please contact us using the contact details provided above.

You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection regulations (Art. 77 GDPR). The supervisory authority responsible for our company is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach

Telephone: 0981 180093-0

E-mail: poststelle@lda.bayern.de

Web: www.lda.bayern.de

To exercise your rights, you can contact the controller or data protection officer using the contact details provided above.


 Obligation to provide data

Providing personal data is not required for purely informational use of our website. However, using the service portal and processing certain requests (e.g., inquiries regarding a claim) may require providing specific data; without this data, using the portal or processing your request may be impossible or severely limited.

 Data security

We implement technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

We use TLS/SSL encryption to ensure secure data transmission. You can recognize an encrypted connection by the prefix “https://” and the padlock symbol in your browser’s address bar.


 Use of plugins and technical extensions

Our website uses various technical extensions and plugins to provide and improve its functionality, user-friendliness, accessibility, multilingualism, and security. Depending on the integrated function, this may involve the processing of personal data, particularly when content is loaded, settings are saved, or technical log data is processed. The legal basis for this processing is, where necessary, Article 6(1)(f) GDPR, our legitimate interest in a secure, functional, and user-friendly website, and, for functions requiring consent, Article 6(1)(a) GDPR.