Last updated:
Data controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) for the website https://nymprimesolutions.de is:
NYM Prime Solutions, Einzelunternehmen (Kleingewerbe).
Address: 84072 Au i.d.Hallertau, Deutschland.
Authorised representative: Marius Constantin Câmaciu.
VAT identification number: Nicht vorhanden.
Website: https://nymprimesolutions.de
Contacting the data controller
If you have questions about data protection or wish to exercise your rights as a data subject, please contact:
Email: info@nymprimesolutions.de
Phone: +4915510371943
General information
Protecting your personal data is important to us. This privacy policy explains what personal data we process in connection with the website nymprimesolutions.de (https://nymprimesolutions.de), for what purposes, and what rights you have.
Personal data means any information relating to an identified or identifiable natural person. Processing is always carried out in accordance with the GDPR and, where relevant to the use of cookies and similar technologies, applicable ePrivacy rules.
This privacy policy applies to the website operated by NYM Prime Solutions. It describes only the processing activities actually implemented in this project.
Legal bases for processing
We process personal data only where a legal basis exists. Depending on the activity, we rely in particular on the following legal bases under the GDPR:
- Art. 6(1)(a) GDPR — consent, e.g. for optional cookies and technologies under applicable ePrivacy rules, and for voluntary use of the contact form where consent is required.
- Art. 6(1)(b) GDPR — processing for the performance of pre-contractual measures or fulfilment of a contract, e.g. when handling your contact enquiry.
- Art. 6(1)(f) GDPR — legitimate interests, e.g. in the secure provision of the website, abuse prevention, technical administration, and storing your cookie consent.
Server log files
When you visit our website, information is automatically collected in server log files as part of the hosting operation. This is done to provide the website in a stable, secure, and error-free manner.
In particular, the following data may be processed: IP address, date and time of the request, requested URL, HTTP status code, amount of data transferred, browser type and version, operating system, referrer URL, and technical error messages.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring operation, IT security, and error analysis. Log data is retained only for as long as necessary for these purposes and is then deleted or anonymised, unless statutory retention obligations apply.
Hosting
This website is hosted by Railway Corporation (Railway.app). The hosting provider processes personal data on our behalf, in particular server log data and technical connection information, to provide and protect the website.
Place of processing: EU/EWR — Amsterdam, Niederlande (Railway-Region europe-west4).
Further information about the provider: https://railway.com.
Where required for operation, a data processing agreement under Art. 28 GDPR is in place with the hosting service provider.
Contact form
When you use our contact form, we process the data you enter to handle your enquiry. The form is connected via the API route /api/contact.
Fields collected: name (required), email address (required), phone number (optional), requested service (optional), message (required), language setting (locale), and confirmation that you have read our privacy policy (required).
Transmission is encrypted via HTTPS. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to initiating or performing a contractual relationship, and Art. 6(1)(f) GDPR based on our legitimate interest in handling enquiries efficiently.
In addition, we store technical metadata for each submission: a SHA-256 hash of your IP address (not the plain-text IP), the user agent, and the delivery status (deliveryStatus) of the message. This serves abuse prevention, error analysis, and traceability.
Contact by email
If you contact us by email, we process the data you provide (e.g. name, email address, content of the message) to handle your request.
The legal basis is Art. 6(1)(b) GDPR where the communication relates to a contract, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries.
Please note that emails may be transmitted unencrypted over the internet. For confidential information, we recommend using encrypted communication channels where available.
Contact by phone
If you reach us by phone at +4915510371943, we process the personal data you share during the call and, where applicable, call metadata (e.g. phone number, date and time) transmitted by your telecommunications provider.
The legal basis is Art. 6(1)(b) GDPR for contract-related matters, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in communicating with prospects and customers.
Contact via WhatsApp
Where configured, we provide an external link to WhatsApp (wa.me). No WhatsApp Software Development Kit (SDK) or WhatsApp embed is used on this website.
When you click the link, you leave our website and are redirected to WhatsApp/Meta. The privacy policy and terms of use of the respective provider apply there. We have no control over data processing on that platform.
The legal basis for providing the link is Art. 6(1)(f) GDPR based on our legitimate interest in offering an additional, voluntary contact option.
Email delivery (SMTP)
Contact form submissions are sent by email on the server side. For delivery, we use nodemailer with SMTP credentials from environment variables (SMTP_HOST, SMTP_PORT, SMTP_USER, SMTP_PASS, CONTACT_FORM_TO, CONTACT_FORM_FROM, and optionally SMTP_SECURE).
Description of email delivery: IONOS SE, Montabaur (Deutschland).
The email service provider processes the data required for delivery on our behalf; to that extent, a processing relationship under Art. 28 GDPR is in place.
The place of processing is the European Union (Germany).
If the SMTP configuration is not fully set up, emails are not sent. In that case, you receive an error message; successful delivery is not simulated.
The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR, depending on the nature of the enquiry.
Spam protection
To protect against automated and abusive submissions, we use technical measures.
The contact form contains a honeypot field invisible to humans (“website”). If this field is filled in, the submission is treated as spam and not processed further. No error message is shown to the sender in this case.
Inputs are sanitised on the server and client side (removal of invisible control characters, HTML tags, and excessively long content). The legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in protecting our systems.
Rate limiting
To prevent abuse, we limit the number of contact form submissions per IP address. By default, a maximum of 5 requests within 15 minutes is permitted. These limits can be adjusted via environment variables (CONTACT_RATE_LIMIT_MAX, CONTACT_RATE_LIMIT_WINDOW_MS).
If the limit is exceeded, the request is rejected with HTTP status 429. The legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in the availability and security of our services.
Consent management
For non-essential cookies and similar technologies, we obtain your consent under applicable ePrivacy rules before they are set or read.
You can choose “Accept all”, “Reject all”, or make an individual selection in the cookie settings. Optional categories (preferences, analytics, marketing) are disabled by default and are activated only after your consent.
You can change your decision at any time via the cookie settings. The legal basis for consent management is Art. 6(1)(c) GDPR in conjunction with applicable ePrivacy rules, as well as Art. 6(1)(f) GDPR based on our interest in a compliant website.
Strictly necessary technologies
Strictly necessary technologies are required for the operation of the website and cannot be disabled. This includes in particular the consent storage nym_cookie_consent.
These technologies ensure core functions such as documenting your cookie decision, language selection, and basic website availability.
The legal basis is Art. 6(1)(f) GDPR. Where applicable ePrivacy rules apply, the exception for strictly necessary cookies applies.
Optional categories
Optional technologies are activated only after your explicit consent. Available categories:
- Preferences — optional comfort settings; no active services are currently configured.
- Analytics — statistical evaluation of website usage; Google Analytics 4 is activated and is loaded only after your consent in this category.
- Marketing — embedded third-party content; Google Maps and YouTube are registered but currently disabled (enabled: false).
Google Analytics
This website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. GA4 helps us understand how the website is used so that we can improve it.
GA4 is loaded only after you consent to the “Analytics” category. Until then no GA4 script is loaded and no analytics cookie is set. Google Consent Mode v2 defaults to “denied” and is updated only in line with your decision.
After your consent, GA4 processes in particular: a pseudonymous identifier in cookies and local storage, your truncated IP address (we activate IP anonymisation via anonymize_ip), the pages you visit, the referring page, date and time, the approximate location derived from the truncated IP address, and technical details about your device and browser. The measurement ID is configured via the environment variable NEXT_PUBLIC_GA_MEASUREMENT_ID.
Google Ireland Ltd. acts as our processor in this respect; a transfer to Google LLC in the USA is possible. Google LLC is certified under the EU-US Data Privacy Framework, supplemented by the EU standard contractual clauses. The cookies used and their storage periods are listed in the cookie table of our cookie policy.
The legal basis is your consent under applicable ePrivacy rules and Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future via “Cookie settings” in the footer; the GA4 scripts are then removed and the associated cookies are deleted.
Google Maps
Google Maps is registered in the service catalogue as a marketing service but is not currently active (enabled: false). No maps are embedded and no Maps scripts are loaded.
If Google Maps is activated in future, interactive map content would be displayed only after consent in the “Marketing” category. Provider: Google Ireland Ltd.
If activated in future, the legal basis would be your consent under applicable ePrivacy rules and Art. 6(1)(a) GDPR.
YouTube
YouTube embeds are provided for in the service catalogue but are not currently active (enabled: false). No YouTube videos are embedded and no YouTube scripts are loaded.
If YouTube is activated in future, embedded videos would be displayed only after consent in the “Marketing” category. Blocked content is shown via a consent prompt (ConsentBlockedEmbed). Provider: Google Ireland Ltd.
If activated in future, the legal basis would be your consent under applicable ePrivacy rules and Art. 6(1)(a) GDPR.
External links
Our website may contain links to external third-party websites (e.g. WhatsApp wa.me, social media profiles where configured). When you click them, you leave our website.
The operators of external sites are solely responsible for the processing of personal data on those pages. We recommend reading the privacy notices of the linked providers.
The legal basis for providing external links is Art. 6(1)(f) GDPR based on our legitimate interest in user-friendly information provision.
Structured data (JSON-LD)
To improve findability in search engines, we include structured data in JSON-LD format (Schema.org type LocalBusiness). This information is output inline in the HTML.
It may include: company name, description, website URL, service types, phone number, email address, and postal address — each only where configured in the website settings.
The structured data serves solely to describe our business in a machine-readable form. No user tracking takes place. The legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in appropriate presentation in search engines.
Fonts
We use the Inter and Cormorant Garamond fonts via next/font/google from Next.js to display the website.
Font files are obtained from Google Fonts during the build process and then self-hosted on our website. During regular page views, no dynamic requests to Google Fonts servers are sent by your browser.
The legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in a consistent and readable presentation of the website.
Recipients of data
We disclose personal data only where necessary for the stated purposes, a legal basis exists, or we are legally obliged to do so.
Possible categories of recipients:
- Hosting service provider (Railway Corporation (Railway.app)) — provision and operation of the website.
- SMTP/email service provider — delivery of contact form messages where configured (IONOS SE, Montabaur (Deutschland)).
- WhatsApp/Meta — only if you voluntarily use an external wa.me link; no SDK on this website.
- Google Ireland Ltd. — Google Analytics 4 after your consent in the “Analytics” category; Google Maps and YouTube are currently not activated.
Transfers to third countries
Our website is operated at Railway Corporation (Railway.app); the place of processing is EU/EWR — Amsterdam, Niederlande (Railway-Region europe-west4). The provider is based in the USA, so access from the USA for support and maintenance purposes cannot be ruled out. EU Standard Contractual Clauses under Art. 46 GDPR are in place for such cases.
For email delivery we use IONOS SE, Montabaur (Deutschland). Processing takes place within the European Union; no transfer to a third country occurs in this context.
Google Analytics 4 is active after your consent in the “Analytics” category; transfers to the USA are possible here as well, safeguarded by the EU-US Data Privacy Framework and, in addition, by the EU Standard Contractual Clauses. Google Maps and YouTube are currently not activated.
When you voluntarily use external links (e.g. WhatsApp), processing outside the EU/EEA by the respective provider may occur.
Retention period
We retain personal data only for as long as necessary for the respective purposes or where statutory retention periods apply.
- Cookie consent (nym_cookie_consent): 12 months.
- Contact form submissions: for the duration of handling your enquiry; technical metadata (IP hash, user agent, deliveryStatus) only for as long as required for abuse prevention and error analysis.
- Server log files: according to the hosting provider's requirements, generally limited to the technically necessary period.
- Administration logs: currently only in the development environment as console output (recordSubmissionForAdmin); no persistent storage takes place.
Obligation to provide data
Providing personal data is neither legally nor contractually required unless expressly stated otherwise.
No data transmission is required to use the website in essence without contacting us. However, to process a contact enquiry we need at least your name, email address, and message, as well as confirmation of the privacy policy.
Without this information, we cannot process your enquiry.
Automated decision-making
We do not use automated decision-making, including profiling within the meaning of Art. 22 GDPR, that produces legal effects concerning you or similarly significantly affects you.
Technical checks (spam detection via honeypot, rate limiting) serve solely to protect our systems and do not result in legally relevant decisions concerning you.
Rights of the data subject
You have the following rights regarding your personal data:
To exercise your rights, please contact info@nymprimesolutions.de. We will handle your request without undue delay and within one month at the latest.
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
Withdrawal of consent
Where we rely on your consent for processing, you may withdraw it at any time with effect for the future.
You can withdraw consent via the cookie settings on this website or by contacting us at info@nymprimesolutions.de. The lawfulness of processing carried out before withdrawal remains unaffected.
Objection
Where we rely on Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.
Where personal data is processed for direct marketing, you have the right to object at any time. We do not currently operate profile-based online marketing on this website.
Send your objection to info@nymprimesolutions.de.
Data security
We implement appropriate technical and organisational measures to protect your personal data against loss, misuse, and unauthorised access.
These include in particular transmission via HTTPS/TLS, input validation and sanitisation, spam protection (honeypot), rate limiting, hashing of the IP address for contact form submissions (SHA-256), and restricting email delivery to configured SMTP credentials.
Absolute security cannot be guaranteed for internet transmissions. Please do not submit particularly sensitive data unencrypted via the contact form.
Changes to this privacy policy
We reserve the right to amend this privacy policy when the legal situation, our services, or data processing changes.
For material changes, in particular to consent categories or third-party services, the policy version (2026-08-ga4) will be updated. In that case, your consent may be required again.
The current version is always available on this page.
Status of the privacy policy
Version: 2026-08-ga4.
Last updated: 2026-07-30.
This privacy policy is the primary legally binding version in German for the website https://nymprimesolutions.de operated by NYM Prime Solutions.
