1) Introduction and General Notes
This privacy policy (as of August 2025) provides you with a transparent overview of which personal data we as the data controller, as well as the data processors commissioned by us, process.
We are subject to German data protection law and the requirements of the European General Data Protection Regulation (GDPR).
For individual or additional activities and operations, further data protection notices as well as other legal documents may apply.
2) Contact details of the controller
Responsible for data processing is:
AMP ENERGY SOLUTIONS GmbH
Schlossgarten 16
74544 Michelbach
Germany
Email: contact@ampenergysolutions.de
We explicitly indicate at the relevant point if there are other controllers responsible for the processing of personal data in individual cases.
3) Scope
This privacy policy applies to all online presences, including all websites.
4) Terms and Legal Foundations
Personal data is all data with the help of which you („data subject“) can be personally identified, directly or indirectly. In this context, we process in particular information that a data subject voluntarily transmits to us when contacting us – for example by post, email, contact form, or telephone. We can store such information, for example, in an address book or using comparable electronic/digital tools.
We process personal data only if at least one of the following legal bases applies.
- Article 6(1)(a) of the GDPR for the processing of personal data with the consent of the data subject. In the event of explicit consent to the transfer of personal data to third countries, data processing is also based on Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing is additionally based on Section 25(1) of the TDDDG. Consent may be withdrawn at any time. The lawfulness of the data processing carried out up to the time of revocation remains unaffected by the revocation.
- Article 6(1)(b) of the GDPR for the necessary processing of personal data to fulfill a contract with the data subject and to take steps prior to entering into a contract.
- Article 6(1)(c) of the GDPR regarding the necessary processing of personal data to fulfill a legal obligation.
- Article 6(1)(d) of the GDPR for the processing of personal data necessary to protect the vital interests of the data subject or another natural person.
- Article 6(1)(e) of the GDPR for the necessary processing of personal data for the performance of a task carried out in the public interest.
- Article 6(1)(f) of the GDPR for the processing of personal data necessary to safeguard our legitimate interests or those of third parties, unless the fundamental rights and freedoms, as well as the interests, of the data subject take precedence. Legitimate interests include, in particular, our interest in being able to conduct activities and operations—whether when visiting our website or in the context of our business relationship—in a sustainable, user-friendly, secure, and reliable manner. In addition, our interest in facilitating communication, ensuring information security, protecting against misuse, enforcing our own legal claims, and complying with applicable law.
5) Nature, scope, purpose, and duration of data processing
The personal data we process may include, in particular, the following categories: account and contact information, browser and device data, content data, metadata or ancillary data, usage data, location data, and payment data.
We process personal data for as long as is necessary for the respective purpose(s) or as required by law. Personal data that is no longer necessary for processing is deleted or anonymized.
We may have personal data processed by third parties. We may process personal data jointly with third parties or transfer it to third parties. Such third parties include, in particular, specialized service providers whose services we use. We also ensure data protection with respect to such third parties.
If you transmit personal data about third parties to us, you are obliged to ensure data protection with respect to such third parties and to ensure the accuracy of the personal data.
We also process personal data that we receive from third parties, obtain from publicly available sources, or collect in the course of our activities and operations, provided that such processing is permitted by law.
6) Rights of Data Subjects
Data subjects whose personal data we process have certain “data subject rights” under the GDPR. These include, in particular, the following rights that benefit you:
- pursuant to Article 15 of the GDPR, to request information about your personal data that we process. In particular, you may request information regarding the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned retention period, the existence of a right to rectification, erasure, restriction of processing, or objection; the existence of a right to lodge a complaint; the origin of your data, if it was not collected by us; and the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding its details;
- in accordance with Article 16 of the GDPR, to request without delay the correction of inaccurate personal data or the completion of your personal data stored by us;
- to request, in accordance with Article 17 of the GDPR, the erasure of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest, or to assert, exercise, or defense of legal claims;
- to request the restriction of the processing of your personal data pursuant to Article 18 of the GDPR, provided that you contest the accuracy of the data, the processing is unlawful but you oppose its erasure, and we no longer need the data but you require it to assert, exercise, or defend legal claims; or you have objected to the processing pursuant to Article 21 of the GDPR;
- In accordance with Article 20 of the GDPR, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or to request that it be transferred to another controller;
- to object to the processing of your personal data pursuant to Article 21 of the GDPR, provided that your personal data is processed on the basis of legitimate interests pursuant to Article 6(1)(f) of the GDPR and provided that there are grounds arising from your particular situation or that the objection is directed against direct marketing. In the latter case, you have a general right to object, which we will honor without requiring you to specify a particular situation. If you object, your personal data will no longer be used for the purposes of direct marketing;
- In accordance with Article 7(3) of the GDPR, you may withdraw your consent at any time. As a result, we may no longer continue processing the data based on that consent in the future; and
- to file a complaint with a supervisory authority pursuant to Article 77 of the GDPR.
7) Notice Regarding Data Transfers to the United States and Other Third Countries
Among other things, we also use tools from companies based in the United States or other third countries that do not provide an adequate level of data protection. Please note that these countries cannot guarantee a level of data protection comparable to that of the EU.
With regard to data transfers to the U.S., the U.S. is considered a safe third country under the „EU-U.S. Data Privacy Framework“ if the data recipient, which is based in the U.S., is certified under the EU-U.S. Data Privacy Framework or provides other appropriate safeguards (e.g., the European Commission’s Standard Contractual Clauses) are in place.
Whenever possible, we try to use tools from EU providers, and if that is not possible, we at least select server locations within the EU, provided that the tool providers offer this option.
8) Data Processing Security
We take appropriate technical and organizational measures to ensure data security commensurate with the respective risk. Unfortunately, however, we cannot guarantee absolute data security.
Access to our website is secured using transport encryption (SSL/TLS, specifically the Hypertext Transfer Protocol Secure, abbreviated as HTTPS). Most browsers indicate transport encryption with a padlock icon in the address bar.
9) Ninja Firewall
To protect our website, we use the Ninja Firewall plugin. It is provided by NinTechNet Limited, Unit 1603, 16th Floor, The L. Plaza, 367–375 Queen’s Road Central, Sheung Wan, Hong Kong.
Ninja Firewall protects our website from unauthorized access, brute-force attacks, and other security threats. Among other things, it logs the IP address, the time the page was accessed, and the referrer.
To protect your privacy, the IP address is anonymized by removing the last three characters. The collected data is stored exclusively on our own web server, automatically deleted after 45 days, and not shared with the provider of Ninja Firewall or any other third parties.
For more information on data processing by Ninja Firewall, please see the provider's privacy policy at:
https://nintechnet.com/about/ und
https://blog.nintechnet.com/ninjafirewall-general-data-protection-regulation-compliance/
Data processing is carried out pursuant to Article 6(1)(f) of the GDPR (legitimate interest in the secure and uninterrupted operation of our website).
10) Cookies
We may use cookies. Both our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies) are data stored in your browser. Cookies are not software programs and do not contain viruses, Trojans, or other „malware.“ Cookies also cannot access information on your PC or device.
When you visit our website, cookies may be temporarily stored in your browser as „session cookies“ or for a specific period of time as so-called „persistent cookies.“ “Session cookies” are automatically deleted when you close your browser. Persistent cookies have a specific retention period. Cookies enable us, in particular, to recognize your browser the next time you visit our website and thereby, for example, measure the reach of our website. However, persistent cookies can also be used for online marketing, for example.
Where we use cookies and to the extent necessary, we obtain your explicit consent for the use of cookies. If consent to the storage of cookies has been requested, the processing is based exclusively on this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG); the consent can be revoked at any time for the future.
Necessary cookies are stored on the basis of Art. 6 para. 1 lit. f GDPR (our legitimate interest in the technically error-free and optimized provision of our services) if no other legal basis is specified.
You can deactivate or delete cookies in your browser settings at any time, either completely or in part. Without cookies, our website or some of its functions may no longer be fully available.
11) Hosting
Our website is hosted by IONOS. The provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.
When you visit our website, IONOS collects various log files such as browser type and version, operating system used, referrer URL, hostname of the accessing computer, time of the server request, IP address, and much more.
For details, please refer to the IONOS privacy policy at: https://www.ionos.de/terms-gtc/datenschutzerklaerung/
The use of IONOS is based on Art. 6 para. 1 lit. f GDPR (our legitimate interest in a stable and reliable presentation of our website) or on the basis of Art. 6 para. 1 lit. a GDPR (your consent) and Section 25 para. 1 TDDDG; consent can be revoked at any time for the future.
We have concluded a Data Processing Agreement (DPA) with the aforementioned provider.
12) Contact via email and phone
If you contact us by email or telephone, your inquiry, including all resulting personal data (name, email address, telephone number, etc.), will be processed for the purpose of handling your request. This data will not be passed on without your consent.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR (performance of a contract or implementation of pre-contractual measures) or on the basis of Art. 6 para. 1 lit. f GDPR (our legitimate interest in processing inquiries addressed to us) or on the basis of Art. 6 para. 1 lit. a GDPR (your consent).
All data transmitted by you to us in connection with a contact request or other communication will remain with us until you request its deletion, revoke your consent for storage, or the purpose for data storage no longer applies. Mandatory statutory provisions—in particular statutory retention periods—remain unaffected.
13) Microsoft Teams
We use the video conferencing service Microsoft Teams. The provider is Microsoft Ireland Operations Ltd, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
If you participate in a video conference with us via Microsoft Teams, your personal data will be stored on Microsoft's servers. You can read which data Microsoft processes in this regard in Microsoft's privacy policy at https://privacy.microsoft.com/en-us/privacystatement.
Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR (performance of a contract or implementation of pre-contractual measures) or on the basis of Art. 6 para. 1 lit. f GDPR (our legitimate interest in fast and easy communication with customers, prospective customers, employees, or business partners) or on the basis of Art. 6 para. 1 lit. a GDPR (your consent), where applicable in conjunction with Section 25 para. 1 TDDDG. Consent can be revoked at any time with effect for the future.
The data collected by you will be transferred to the USA and stored there on servers of Microsoft Corporation. Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework. Through this certification, Microsoft Corporation undertakes to comply with EU data protection standards.
We have concluded a Data Processing Agreement (DPA) with the aforementioned provider.
14) Google Fonts
On our website, we use „Google Fonts“ for the appealing and uniform display of fonts. Google Fonts is a product provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Fonts are installed locally on our system. This prevents a connection to Google's servers from being established when you visit our website.
Further information on Google Fonts in general can be found at: https://developers.google.com/fonts/faq/privacy?hl=de or in Google's privacy policy at: https://policies.google.com/privacy.
The use of Google Fonts is based on Art. 6 para. 1 lit. f GDPR (our legitimate interest in an appealing and uniform presentation of the typeface on our website) or on the basis of Art. 6 para. 1 lit. a GDPR (your consent) and § 25 para. 1 TDDDG. Consent can be revoked at any time with effect for the future.
We can amend and supplement this privacy policy at any time. We will inform you of such amendments and supplements in an appropriate manner, in particular by publishing the respective current privacy policy on our website.