Privacy Policy

Last updated: July 2026

Thank you for your interest in our website and in NXT Spectra. The protection of personal data is important to us. In this Privacy Policy, we inform you about which personal data we process when you visit our website and use the functions offered on it, for which purposes this is done, and which rights you have.

This Privacy Policy applies to the website nxt-spectra.de.

1. Controller

The controller responsible for the processing of personal data on this website is:

ChemInnovation GmbH

Gottfried-Hagen-Str. 60-62

51105 Cologne

Germany

Email: info@cheminnovation.de

Represented by the Managing Director: Philipp Pflüger

Register court: Local Court of Cologne

Commercial register number: HRB 125148

VAT ID No.: DE363241642

2. General information on data processing

We process personal data only to the extent necessary for the operation of our website, the provision of our content and functions, the handling of inquiries, the implementation of pre-contractual or contractual measures, the processing of applications, or the sending of our newsletter, or where you have consented to such processing.

Depending on the specific processing activity, we rely in particular on the following legal bases:

  • Art. 6(1)(a) GDPR, where you give us your consent, for example for the newsletter or for non-essential cookies and external media;
  • Art. 6(1)(b) GDPR, where the processing is necessary for the implementation of pre-contractual measures or for the performance of a contract, for example in the case of demo requests or contract-related communication;
  • Art. 6(1)(c) GDPR, where we are legally obliged to carry out the processing, for example to comply with commercial or tax retention obligations;
  • Art. 6(1)(f) GDPR, where the processing is necessary to protect our legitimate interests, for example for the technical provision, security and stability of the website or for handling general inquiries.

Where we store information on your device or access information stored on your device, for example through cookies, local storage or similar technologies, this is done in accordance with Section 25 TDDDG. We use non-essential technologies only with your consent.

3. Provision of the website and server log files

When you access our website, technically necessary data is processed so that the website can be displayed and operated in a stable and secure manner. This may include, in particular, the following data:

  • IP address;
  • date and time of access;
  • page or file accessed;
  • referrer URL;
  • browser type and browser version;
  • operating system used;
  • language settings;
  • amount of data transferred;
  • HTTP status code;
  • technical device and connection information.

The processing is carried out for the technical delivery of the website, to ensure system security, for error analysis and to prevent misuse.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our website.

4. Hosting and website operation via Webflow

Our website is provided via Webflow. The provider is:

Webflow, Inc.

398 11th Street, 2nd Floor

San Francisco, CA 94103

USA

When operating the website, Webflow processes in particular technical access data, server log data and data required for the display and administration of the website. We use Webflow as a service provider within the framework of data processing on our behalf pursuant to Art. 28 GDPR.

The processing is carried out for the provision, maintenance, security and technical optimization of the website. The legal basis is Art. 6(1)(f) GDPR. Where functions on the website are used for the initiation or performance of a contract, Art. 6(1)(b) GDPR may additionally apply.

When using Webflow, personal data may be processed in the USA. Webflow is certified under the EU-U.S. Data Privacy Framework. In addition, Webflow provides contractual safeguards, in particular standard contractual clauses, where these are required.

5. Cookies, similar technologies and consent management

Our website uses cookies and comparable technologies. Cookies are small text files that are stored on your device. Similar technologies may include, for example, local storage, pixels or scripts.

We distinguish between:

  • technically necessary technologies, which are required for the operation of the website or the provision of certain functions;
  • non-essential technologies, for example for external media or optional services, which are loaded only after you have given your consent.

When you first visit our website, you can use our consent banner to select which non-essential services may be loaded. You can withdraw or change your consent at any time with effect for the future via the cookie settings.

The legal basis for technically necessary technologies is Section 25(2) TDDDG and Art. 6(1)(f) GDPR. Our legitimate interest lies in the functional and secure provision of the website.

The legal basis for non-essential technologies is your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

6. Cookiebot by Usercentrics

We use Cookiebot by Usercentrics to obtain, manage and document your consents. The provider is:

Usercentrics A/S

Havnegade 39

1058 Copenhagen

Denmark

Cookiebot processes information required for the management and documentation of your cookie and privacy settings. This may include, in particular, your consent or refusal decision, the date and time of the decision, technical browser and device information, the visited domain and a pseudonymous identifier.

The use of Cookiebot serves to obtain and document your consents in a legally compliant manner and to allow you to change your settings at a later time.

The legal basis is Art. 6(1)(c) GDPR, insofar as the processing is carried out to comply with our legal documentation obligations. Where the processing serves the user-friendly and legally compliant management of consents, we additionally rely on Art. 6(1)(f) GDPR. Our legitimate interest lies in the privacy-compliant design of our website.

Cookiebot is used as a processor pursuant to Art. 28 GDPR.

7. Newsletter via Rapidmail

You can subscribe to our newsletter on our website. For the subscription, we process the data you provide, in particular:

  • first name;
  • last name;
  • email address;
  • time of registration;
  • time of confirmation;
  • technical data for documenting the registration, for example IP address and confirmation data used.

The newsletter is sent only after you have given your consent using the double opt-in procedure. This means that, after registering, you will receive an email asking you to confirm your subscription. Your email address will only be added to the mailing list after this confirmation.

We use Rapidmail for sending and analyzing the newsletter. The provider is:

Positive Group Deutschland GmbH

Ingeborg-Krummer-Schroth-Straße 18a

79106 Freiburg im Breisgau

Germany

Rapidmail processes the newsletter data on our behalf. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Rapidmail.

We also use Rapidmail to analyze the newsletter dispatch. This may include recording whether a newsletter was opened and which links in the newsletter were clicked. This helps us understand which content is relevant to recipients and improve the content of our newsletter.

The legal basis for subscribing to, receiving and analyzing the newsletter is your consent pursuant to Art. 6(1)(a) GDPR. The legal basis for documenting the subscription is Art. 6(1)(f) GDPR. Our legitimate interest lies in being able to prove the consent given and prevent misuse.

You may withdraw your consent at any time with effect for the future. You can do this by using the unsubscribe link in each newsletter or by contacting us using the contact details provided above. After unsubscribing, your data will be deleted from the newsletter mailing list, unless statutory retention obligations or legitimate documentation interests prevent deletion.

8. Contact by email

If you contact us by email, we process the data you provide. This may include, in particular:

  • name;
  • email address;
  • company;
  • function or role;
  • content of your message;
  • technical communication data;
  • any further information voluntarily provided by you.

The processing is carried out to handle your inquiry, to communicate with you and, where applicable, to implement pre-contractual or contractual measures.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper handling of incoming inquiries. If your inquiry is directed toward the conclusion or performance of a contract, Art. 6(1)(b) GDPR is an additional legal basis.

We delete inquiry data once the respective matter has been completed and no statutory retention obligations or legitimate interests in further storage exist. Business-related and contract-related communication may be retained for longer in accordance with commercial and tax law requirements.

9. Demo booking via Calendly

On our website, we link to Calendly for booking demo and consultation appointments. The provider is:

Calendly, LLC

USA

Calendly is not directly embedded into our website but is opened via an external link. When you click on the Calendly link, you leave our website and Calendly’s privacy information also applies.

When booking an appointment via Calendly, the data you enter is processed, for example:

  • name;
  • email address;
  • company;
  • desired appointment time;
  • information on the use case;
  • information on how you became aware of us;
  • details about your work or professional inquiry;
  • technical data generated when using Calendly.

We use this data to prepare, conduct and follow up on demo, sales, consultation or coordination appointments. Please do not submit any special categories of personal data within the meaning of Art. 9 GDPR or personal data of third parties via Calendly unless this is necessary for the appointment booking.

The legal basis is Art. 6(1)(b) GDPR, insofar as the appointment booking serves the implementation of pre-contractual measures. Otherwise, we rely on Art. 6(1)(f) GDPR. Our legitimate interest lies in efficient and user-friendly appointment scheduling.

Calendly also processes personal data in the USA. Calendly is certified under the EU-U.S. Data Privacy Framework and, according to its own information, uses additional contractual safeguards where required.

We store demo and prospect data for as long as this is necessary to process your inquiry, conduct the communication and initiate or carry out a business relationship. If an inquiry does not result in further communication or a business relationship, we generally delete or anonymize the data after 12 months. Prospect communication with an ongoing business relevance is generally stored for up to three years after the end of the calendar year of the last communication, unless longer statutory retention obligations apply or longer storage is necessary for the establishment, exercise or defense of legal claims.

10. External media: YouTube

We embed video content on our website, in particular via YouTube. For users in the European Economic Area, the provider of YouTube is generally:

Google Ireland Limited

Gordon House

Barrow Street

Dublin 4

Ireland

If you consent to the display of external media, personal data may be transmitted to the respective providers. This may include, in particular, your IP address, technical device and browser information, information about the page accessed and information about your interaction with the embedded content. If you are also logged into a Google or YouTube account, Google may associate your use of the embedded content with your account.

The processing takes place only after you have given your consent. The legal basis is Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

You can withdraw your consent at any time with effect for the future via the cookie settings. Without consent, the embedded video will not be loaded; the rest of the website remains usable.

When using YouTube, personal data may be processed outside the European Union or the European Economic Area. Google LLC is certified under the EU-U.S. Data Privacy Framework. Otherwise, the privacy information and transfer mechanisms of the respective providers apply.

11. Applications

On our website, we point out the possibility of applying to us by email. If you send us an application, we process the application data you provide. This may include, in particular:

  • name and contact details;
  • CV;
  • cover letter;
  • certificates;
  • qualifications;
  • professional background;
  • availability;
  • salary expectations, where provided;
  • other information submitted by you.

The processing is carried out to review your application and conduct the application process.

The legal basis is Section 26 BDSG and Art. 6(1)(b) GDPR, insofar as the processing is necessary for deciding on the establishment of an employment relationship. Where you give us your consent to longer storage, the legal basis is Art. 6(1)(a) GDPR. Where longer storage is necessary for the establishment, exercise or defense of legal claims, Art. 6(1)(f) GDPR may be the legal basis.

Application data is generally deleted 6 months after completion of the respective application process. In the case of unsolicited applications, we generally store the data for up to 12 months. Longer storage takes place only if you have consented to it or if legal reasons require longer storage.

12. Communication and data in connection with tests, demos and technical inquiries

If, in connection with a demo, a test phase or a technical inquiry, you provide us with information about your analytical questions, samples, GC-MS data or other technical requirements, we process this information to review, prepare and carry out the respective inquiry or service.

Where such information contains personal data, the processing is carried out, depending on the context, on the basis of Art. 6(1)(b) GDPR if the processing is necessary for the implementation of pre-contractual or contractual measures, or on the basis of Art. 6(1)(f) GDPR if the processing is necessary for the proper handling of your inquiry.

Please do not provide us with personal data of third parties or special categories of personal data unless this is necessary for the respective purpose or has been expressly agreed with us.

We store such data only for as long as this is necessary for the respective purpose, the communication, the performance of the test or demo service, statutory retention obligations or the establishment, exercise or defense of legal claims.

13. Recipients of personal data

Within our company, only those persons who need access to personal data to perform their respective tasks receive such access.

In addition, personal data may be transmitted to external service providers that we use to provide and operate our website and communication processes. These include, in particular:

  • Webflow for website operation and hosting;
  • Cookiebot by Usercentrics for consent management;
  • Rapidmail for newsletter dispatch and newsletter analysis;
  • Calendly for appointment bookings;
  • providers of external media, insofar as you have consented to their integration;
  • IT, communication and security service providers, where required.

Where service providers process personal data on our behalf, we use them on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Data is transferred to authorities, courts or other bodies only insofar as we are legally obliged to do so or where this is necessary for the establishment, exercise or defense of legal claims.

14. Data transfers to third countries

Some of the services we use are based outside the European Union or the European Economic Area or may process personal data there, in particular in the USA.

A transfer of personal data to third countries takes place only where the requirements of Art. 44 et seq. GDPR are met. This may be based in particular on an adequacy decision, certification under the EU-U.S. Data Privacy Framework, standard contractual clauses of the European Commission or explicit consent.

For services that are loaded only after your consent, for example external media, the data transfer in connection with the use of these services takes place only if you have given your prior consent.

15. Retention period

We store personal data only for as long as this is necessary for the respective purposes. Thereafter, we delete or anonymize the data unless statutory retention obligations, documentation obligations or legitimate interests in further storage exist.

In particular, the following principles apply:

  • technical access data is stored only for as long as this is necessary for operation, security and error analysis;
  • newsletter data is stored until you unsubscribe, unless documentation obligations prevent deletion;
  • inquiry data is deleted after completion of the handling process, unless statutory retention obligations or legitimate interests in further storage exist;
  • demo and prospect data without further contact is generally deleted or anonymized after 12 months;
  • prospect communication with an ongoing business relevance is generally stored for up to three years after the end of the calendar year of the last communication;
  • application data is generally deleted 6 months after completion of the application process; unsolicited applications are generally deleted after 12 months;
  • contract-related, commercial or tax-relevant documents are stored in accordance with statutory retention periods.

16. Your rights

Subject to the statutory requirements, you have the following rights:

  • right of access to the personal data processed by us pursuant to Art. 15 GDPR;
  • right to rectification of inaccurate or incomplete data pursuant to Art. 16 GDPR;
  • right to erasure of personal data pursuant to Art. 17 GDPR;
  • right to restriction of processing pursuant to Art. 18 GDPR;
  • right to data portability pursuant to Art. 20 GDPR;
  • right to object to processing based on Art. 6(1)(e) or Art. 6(1)(f) GDPR pursuant to Art. 21 GDPR;
  • right to withdraw consent given with effect for the future pursuant to Art. 7(3) GDPR;
  • right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.

To exercise your rights, you can contact us using the contact details provided above.

17. Withdrawal of consent

If you have given us consent, you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent until withdrawal remains unaffected by the withdrawal.

You can change or withdraw consent to cookies and external media via the cookie settings on our website.

You can withdraw newsletter consent using the unsubscribe link in the newsletter or by sending us a message.

18. Right to object pursuant to Art. 21 GDPR

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.

Where personal data is processed for direct marketing purposes, you have the right to object to such processing at any time. In this case, the personal data will no longer be processed for direct marketing purposes.

19. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.

The supervisory authority responsible for us is in particular:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia

Postfach 20 04 44

40102 Düsseldorf

Germany

Website: ldi.nrw.de

You may also contact any other competent data protection supervisory authority.

20. No automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR on our website.

21. Security

We take technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration or destruction. Our website is transmitted in encrypted form via HTTPS.

Please note that data transmission on the internet, especially communication by email, may have security vulnerabilities. Complete protection against access by third parties is technically not possible.

22. Changes to this Privacy Policy

We may amend this Privacy Policy if our website, the services used, our processing activities or the legal requirements change. The version published on this website at the relevant time applies.