Nutrigen Privacy Policy

I. Preamble
This Privacy Policy (“Policy”) explains how Nutrigen Biosciences GmbH (“Nutrigen”, “we”, “us”, or “our”) collects, processes, and protects personal data.

We comply with the EU General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and other applicable German data protection laws.

We collect and process personal data only for specified, explicit, and legitimate purposes and ensure that processing is lawful, fair, and transparent. Nutrigen applies appropriate technical and organizational measures to prevent unauthorized access, disclosure, alteration, or loss of personal data.

II. Data Controller
Nutrigen Biosciences GmbH
Münchner Str. 2, 85411 Hohenkammer, Germany
Email: jozsef.szeles@nutrigenbio.com
Website: acclivum.com
Responsible under Art. 4(7) GDPR: Nutrigen Biosciences GmbH
III. Categories of Personal Data
Depending on your interaction with us, we may process:
Contact data (name, email address, phone number, address)
Website usage data (IP address, browser type, operating system, referrer URL, access time)
Marketing and analytics data (user behavior, campaign interactions, cookie identifiers)
CRM data (customer relationship information, correspondence history, preferences)
Newsletter data (email, subscription confirmation, tracking of opens/clicks if consented)
IV. Purposes and Legal Bases for Processing

We process personal data for the following purposes under the legal bases of Art. 6 (1) GDPR:
Purpose Legal Basis

Responding to contact requests or inquiries  – Art. 6 (1)(b) GDPR – contractual necessity
Sending newsletters or marketing communication – Art. 6 (1)(a) GDPR – consent
Operation and optimization of our website (analytics, cookies) – Art. 6 (1)(a) GDPR – consent
LinkedIn Ads and marketing campaigns – Art. 6 (1)(a) GDPR – consent
Compliance with legal obligations (e.g., tax, accounting) – Art. 6 (1)(c) GDPR
Protection of legitimate business interests – Art. 6 (1)(f) GDPR

We do not use your data for automated decision-making or profiling unless explicitly stated and consented to.

V. Data Sharing and Processors

We may share data with:
Service providers and processors (hosting, CRM, newsletter tools, analytics providers) under Art. 28 GDPR contracts

Advertising and analytics partners, e.g. LinkedIn Ireland Unlimited Company, Google Ireland Limited, subject to your cookie consent

Public authorities, where legally required

Data transfers outside the EU/EEA are only performed if adequate safeguards are in place (e.g., EU Standard Contractual Clauses).

VI. Cookies and Analytics
We use cookies and similar technologies to analyze website usage, deliver personalized ads, and improve functionality.
You can withdraw or change your cookie preferences at any time via our Cookie Consent Banner.

Analytics tools we may use:
Google Analytics 4 (Google Ireland Ltd.) – anonymized IP tracking, usage statistics

LinkedIn Insight Tag – to measure ad conversions and audience analytics

Further details are provided in the Cookie Policy below.

VII. Data Storage and Security
Personal data is stored on secure servers located within the EU. We use encryption (SSL/TLS), access control, and regular backups.

Retention periods depend on the purpose of processing and applicable legal requirements (e.g., 6–10 years for commercial records).

VIII. Your Rights
You have the following rights under the GDPR:
Right to access (Art. 15)
Right to rectification (Art. 16)
Right to erasure (“right to be forgotten”) (Art. 17)
Right to restriction of processing (Art. 18)
Right to data portability (Art. 20)
Right to object (Art. 21)
Right to withdraw consent (Art. 7 (3))
You may exercise your rights by contacting us at [email address].
You also have the right to file a complaint with your local supervisory authority:
Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Graurheindorfer Str. 153, 53117 Bonn, Germany – www.bfdi.bund.de
IX. Website and Social Media Use
When you access our website or interact with us on social media (e.g., LinkedIn), data such as IP address and browser information may be transmitted to third parties.

We are joint controllers with LinkedIn for certain marketing activities under Art. 26 GDPR.
Our website may contain links to external websites. We are not responsible for external content.

X. Updates to This Policy
This Policy was last updated on 1st of December 2025.

We may revise this Policy to reflect legal, technical, or business developments.
Updated versions will be posted on our website at least 10 days before taking effect.