Home › Privacy Notice
Privacy Notice
Last updated: 31 August 2026
SI Stuttgart Instruments GmbH (“Stuttgart Instruments”, “we”, “us”, or “our”) respects your privacy. This Privacy Notice explains how we process personal data when you use our websites (including s-instruments.com, related *.pages.dev previews, and any other domains on which we publish this site) and when you contact us through those websites. Traffic to s-instruments.de is redirected to s-instruments.com.
This notice is intended to meet the transparency requirements of the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and applicable rules on cookies and similar technologies (including the German Telecommunications-Telemedia Data Protection Act / TTDSG, as applicable).
It does not cover third-party websites linked from our pages. Please review those providers’ policies separately.
1. Data controller
SI Stuttgart Instruments GmbH
Ernsthaldenstr. 17
70565 Stuttgart
Germany
Phone: +49 (0)711 3420325 0
Email: contact@s-instruments.de
Managing directors: Dr. Tobias Steinle, Benjamin Rudolph
Register: HRB 763282 (Amtsgericht Stuttgart)
VAT ID: DE316080047
If we appoint a Data Protection Officer, contact details will be published here. Until then, please use the contact details above for privacy requests.
2. What this website does (and does not do)
Our public website is a static product and company information site. You can browse product and application content, view publications and events, download product datasheets, and submit:
- a sales / general contact form,
- a technical support form, and
- an optional product-update subscription when downloading a product datasheet (see §3A).
We do not operate user accounts on the public website and do not use third-party advertising or web-analytics trackers (such as Google Analytics) on the public pages described in this notice.
An internal admin area (/admin/) is available only to authorised staff (protected by Cloudflare Access) and is not intended for public use.
3. Categories of personal data we process
Depending on how you interact with us, we may process:
A. Data you submit via forms
- Contact: first and last name, email address, company/institution, subject, message, and your consent confirmation; optionally, phone number. When you visit the Contact page, we may briefly use your approximate location (derived from your IP address via the same hosting/security data described in §3C) to pre-select a default international dialling code for the phone field. This is not logged or stored beyond the request itself.
- Support: name, email address, company/institution (optional), product model, serial number, request category, message, and your consent confirmation
- Product update subscription (optional, on product datasheet download): email address, the product you selected, the date and time of your consent, your IP address as seen by our hosting edge (for abuse prevention and consent documentation), and a reference to the consent text version shown in the form
B. Security / anti-abuse data
- Cloudflare Turnstile challenge tokens and related verification results
- Technical request metadata needed to operate and protect the forms (for example IP address as provided by our hosting edge for verification and abuse prevention)
- Honeypot fields (not intended to be filled by humans; used only to detect bots)
C. Essential technical / log data
When you visit the site, our hosting and security providers may process standard server/edge logs such as IP address, approximate location derived from IP, timestamp, requested URL, referrer, user agent / browser type, and similar diagnostic data.
D. Staff access to internal tools (not public visitors)
If you are an authorised employee or contractor accessing /admin/, we (and Cloudflare Access) may process authentication identifiers, access logs, content you edit (for example events, publications, or career listings), and product subscription statuses you view.
We do not intentionally collect special categories of data (Art. 9 GDPR) via this website.
4. Purposes and legal bases
- Responding to sales / general enquiries. Data: form fields in §3A. Legal basis: your consent (Art. 6(1)(a) GDPR), given by ticking the form checkbox; and/or legitimate interests (Art. 6(1)(f)) in answering B2B enquiries you initiate.
- Handling technical support requests. Data: form fields in §3A. Legal basis: consent (Art. 6(1)(a)) and/or steps prior to a contract / customer support (Art. 6(1)(b)), and legitimate interests (Art. 6(1)(f)) in supporting users of our systems.
- Product update subscriptions (optional). Data: email address, product, consent timestamp, IP address, and consent text version as described in §3A. Legal basis: your consent (Art. 6(1)(a) GDPR). The checkbox is unchecked by default; submitting the subscription option requires your active consent. We send a confirmation email with a link valid for 48 hours and add you to our mailing list only after you click that link.
- Preventing spam, bots, and abuse (Turnstile, honeypot, rate limits). Data: §3B. Legal basis: legitimate interests (Art. 6(1)(f)) in securing our website and communications.
- Operating, securing, and troubleshooting the website (hosting, CDN, logs). Data: §3C. Legal basis: legitimate interests (Art. 6(1)(f)) in providing a secure, reliable website.
- Staff administration of website content via /admin/. Data: §3D. Legal basis: legitimate interests / employment or contractor relationship (Art. 6(1)(f) and, where applicable, Art. 6(1)(b)).
- Compliance with legal obligations (e.g. if a request must be retained). Data: as required. Legal basis: legal obligation (Art. 6(1)(c)).
You may withdraw consent at any time (see §9). Withdrawal does not affect processing already carried out lawfully before withdrawal.
Providing form data is voluntary, but without required fields we cannot process your enquiry.
5. Cookies and similar technologies
We aim to keep the public website free of non-essential tracking.
- We do not use marketing or analytics cookies on the public site as currently operated.
- Strictly necessary technologies may be used for security and delivery, in particular Cloudflare infrastructure and Cloudflare Turnstile (which may set or read cookies / local storage equivalents required for the bot challenge).
- Where EU/German law requires consent for non-essential storage/access on your device, we will only use such technologies with consent. If we later introduce analytics or marketing tools, we will update this notice and implement an appropriate consent mechanism.
You can control cookies through your browser settings. Blocking necessary security technologies may prevent form submission.
As of 21 August 2026, manual browser testing confirmed that neither this website nor the Cloudflare Turnstile widget currently sets any cookies in the visitor's browser. Turnstile relies on other browser signals, not cookies, to verify visitors in its current configuration. We periodically re-check this and will update this notice if that changes.
6. Recipients and processors
We use carefully selected service providers that process data on our instructions, including:
- Cloudflare, Inc. / Cloudflare group — website hosting (Cloudflare Pages), content delivery, security, Turnstile, and (for staff) Access
- Resend — transactional email delivery for form submissions (messages are sent from our configured sender address to our sales or support mailboxes; your address may be used as reply-to), confirmation emails for optional product-update subscriptions, and management of our contact list (Audiences) for confirmed product-update subscribers
Data may also be accessible to our managing directors and employees who need it to respond to your request, and to professional advisers or authorities where legally required.
We do not sell personal data.
7. International transfers
Our primary business is in Germany/EU. Some providers (notably Cloudflare and Resend) may process data in countries outside the EU/EEA, including the United States.
Where required, we rely on appropriate transfer safeguards under Chapter V GDPR, such as:
- an adequacy decision of the European Commission (including, where applicable, the EU–US Data Privacy Framework for certified organisations), and/or
- Standard Contractual Clauses (SCCs) with supplementary measures as needed.
Details are available from the respective providers’ privacy documentation; you may also contact us for more information.
8. Retention
- Contact / support enquiries: retained as long as needed to handle your request and for a limited follow-up period (typically up to 24 months after the last correspondence), unless a longer period is required for an ongoing customer relationship, warranty/support matter, or legal claims.
- Product update subscriptions: unconfirmed pending requests are deleted or anonymised after 30 days (email address and IP address removed; only product, status, and expiry timestamp may be retained for statistical purposes). Confirmed subscriptions are kept until you withdraw consent or unsubscribe. Consent records for confirmed subscriptions are retained for as long as necessary to demonstrate compliance.
- Security / server logs: retained for short periods for security and diagnostics (typically up to 90 days, unless needed longer to investigate incidents). This also covers the Turnstile tokens and edge/security metadata described in §3B, which are retained for the same short period as server/security logs.
- Consent records related to form submissions: retained for as long as necessary to demonstrate compliance.
- Admin access logs / content edits: retained according to internal IT and accountability needs.
When retention ends, we delete or anonymise data where feasible.
9. Your rights
Under the GDPR you may have the right to:
- access your data (Art. 15)
- rectification (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent at any time (Art. 7(3))
We do not use solely automated decision-making that produces legal or similarly significant effects concerning you (Art. 22).
To exercise your rights, email contact@s-instruments.de (subject line e.g. “Data protection request”). We may need to verify your identity. We usually respond within one month.
If you subscribed to product updates, you can withdraw consent at any time via the unsubscribe link in our emails or by contacting us at contact@s-instruments.de.
You also have the right to lodge a complaint with a supervisory authority. For our establishment in Baden-Württemberg, this is typically:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Website: https://www.baden-wuerttemberg.datenschutz.de
You may also contact the authority in your place of residence or work.
10. Children’s data
Our website and products are directed to professional / institutional customers. We do not knowingly collect personal data from children.
11. Security
We apply appropriate technical and organisational measures (including HTTPS, access controls for admin tools, bot protection, and least-privilege access to mailboxes and admin systems). No method of transmission or storage is completely secure.
12. Changes to this notice
We may update this Privacy Notice when our processing or the law changes. The “Last updated” date will be revised, and the current version will be published on this page.
13. Contact
Privacy requests: contact@s-instruments.de
Postal address: see §1.