Skip to content

Article 13 GDPR

Privacy notice

The public website uses no analytics or tracking services, advertising networks or embedded third-party content. We do not set cookies for ordinary visits. We process the data needed to serve the website, answer your enquiry and prevent misuse.

Amplified Pi operates from Germany under German law. The German version of this notice is the authoritative one; this translation is provided for convenience.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Anton Picardtrading as “Amplified Pi”Sandhöfer Allee 1060528 Frankfurt am MainGermany

Email: datenschutz@amplifiedpi.com

No data protection officer has been appointed. The conditions requiring an appointment under Article 37 GDPR and section 38 BDSG are not met.

2. Principles

We process personal data only where this is necessary to provide this website and the services offered through it.

There is no profiling and no automated decision-making within the meaning of Article 22 GDPR. Fonts are served from our own server, not from an external provider.

When you open the site's root address, your browser's language setting is evaluated locally to open the German or English page first. We do not determine your location or save a language preference in a cookie or in browser storage. You can change language at any time using the language selector.

3. Serving the website

When you open this website, the hosting provider processes technically necessary connection data:

  • IP address of the requesting device
  • date and time of access
  • requested URL
  • volume of data transferred and HTTP status code
  • referrer URL, where transmitted
  • browser type and operating system (user agent)
Purpose
Delivering the website, maintaining system security and stability, and preventing and investigating misuse.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is the technically sound and secure provision of the website.
Retention
Microsoft processes connection and diagnostic data only for as long as necessary to operate the service securely and reliably and to investigate faults. Where these logs are available to us, we use them only for those purposes and do not arrange separate long-term storage. The specific period depends on the deployed Azure configuration and is limited to what is necessary for those purposes.
Processor
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The website is hosted on Azure Static Web Apps. The resource we operate is in the Azure West Europe region. The service additionally delivers static page content through a globally distributed delivery network so that pages load quickly, which can include locations outside the European Union; the safeguards in section 7 then apply. Processing takes place under a data processing agreement based on the Microsoft Products and Services Data Protection Addendum.

This website is served exclusively over an encrypted TLS connection (HTTPS).

4. Contact form

If you use the contact form, we process the data you enter:

  • name
  • email address
  • organization (optional)
  • selected topic
  • the language of the form, so that we reply in the same one
  • your message
Purpose
Handling and answering your enquiry. We do not use these details for advertising, a newsletter or any other approach beyond answering what you asked.
Legal basis
Article 6(1)(b) GDPR where processing is necessary to take steps towards, or to perform, a contract with you. For other enquiries, including where you act as a contact for an organisation, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is answering enquiries and managing business communications. Retention required by law is based on Article 6(1)(c) GDPR.
Processing route
Form submissions are received by an Azure Function running in the Azure West Europe region and delivered by email to our mailbox in Microsoft 365. This tenant's mailboxes are hosted in data centres in Germany. No additional form service is used, and submissions are not written to a separate database.
Retention
Enquiries that do not lead to a business relationship are deleted no later than six months after they are closed, unless a statutory retention duty applies. We record the closure date and the deletion due date, and we include associated replies and copies in Sent Items and Deleted Items. Where a business relationship develops, the data necessary to perform the contract continues to be processed. Records subject to statutory retention are kept for the applicable period: in particular business and commercial correspondence for six years, accounting vouchers for eight years, and books and annual accounts for ten years, where section 257 HGB or section 147 AO applies. Those periods start at the end of the relevant calendar year. A business relationship does not mean that all messages are kept indefinitely. After deletion from the active mailbox, Exchange Online has a 14-day recovery period; the service performs the permanent cleanup afterwards. Separate periods for technical logs are described under Logging.
Necessity
Contacting us is voluntary. Name, email address and message are required fields in the form; it cannot be submitted without them. Providing your organisation is optional. You can also write to us directly by email. For a general enquiry, providing these details is neither a statutory nor a contractual obligation.
Spam protection
To prevent automated and abusive submissions we use a hidden form field, a limit on the size of the request, and limits on sending and repeated submissions. We use no externally embedded CAPTCHA service and no cookies for this purpose. To apply the limits we process your connection's IP address and the combination of your email address and the message text. Only hashes computed with a secret key are stored, together with counters and timing information. The message text, your name and your email address are not stored in readable form in this spam-protection database. The hashes are pseudonyms and remain personal data. They are held in Azure Table Storage in the West Europe region. An entry applies only within its window of at most 24 hours. A scheduled task in the same Azure region then runs an automated purge of lapsed entries once a day, independently of whether the website is visited. In normal operation an entry is therefore deleted about 48 hours after it was created. Technical faults or delayed runs can delay deletion; lapsed entries are not reused to apply limits. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in keeping the form usable and in preventing misuse.
Logging
Email delivery causes Microsoft to process technical metadata, in particular sender and recipient address, subject, timestamp and delivery status. Exchange Online message tracing keeps these records available for up to 90 days. For a form submission the transport message uses our own sender and recipient addresses; your email address appears in the message content and in the reply-to field. For direct emails and for our replies, your address also appears in the transport records. Microsoft 365 additionally records security-relevant mailbox and administrative operations; under our current plan these audit records have a standard retention period of 180 days. We use these logs to investigate delivery problems, to maintain security and to prevent misuse, on the basis of Article 6(1)(f) GDPR. We do not arrange any additional long-term storage for them.

5. Contact by email

If you contact us by email, we process your email address and the content of your message in order to deal with your enquiry. Legal basis and retention are as described in section 4.

6. Recipients

Beyond the processors named in this notice, we do not pass personal data to third parties unless we are legally required to do so.

7. Transfers to third countries

The contact function, the spam-protection storage and its automated purge are all configured in the Azure West Europe region. Mailbox content is stored in the data region assigned to Exchange Online, which is Germany. Execution is a separate question: the globally distributed delivery of static website content, and support and operational processes, can involve processing or access outside the European Union or the European Economic Area. Such transfers take place on the basis of the standard contractual clauses adopted by the European Commission together with supplementary measures under Microsoft's contractual commitments. You can request information about the applicable safeguards and a copy of the relevant contractual clauses at datenschutz@amplifiedpi.com.

8. Your rights

Subject to the applicable legal conditions, you have the right:

  • to access the data processed about you (Article 15 GDPR),
  • to rectification of inaccurate data (Article 16 GDPR),
  • to erasure (Article 17 GDPR),
  • to restriction of processing (Article 18 GDPR),
  • to data portability (Article 20 GDPR).

A message to datenschutz@amplifiedpi.com is enough to exercise your rights.

9. Your right to object

Where we process your personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing the data concerned, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Send your objection to datenschutz@amplifiedpi.com. Explaining your particular situation helps us assess it, but it is not a condition for us to deal with your objection.

10. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und InformationsfreiheitPostfach 316365021 WiesbadenGermany

11. Changes

We update this notice when the processing changes. The version published on this page is the one that applies.

Last updated: 29 September 2026