Privacy Policy

Last updated: 25 September 2026

1. Controller and scope

The controller responsible for processing personal data is:
Niko Schwenzer
Irmerstr. 6
40474 Düsseldorf
Germany
Email: info@chemlens.app

This policy covers this information website and registration for email updates about ChemLens, its development and the planned free trial. It does not cover data processing in the separately offered app. The registration form does not transmit photos or chemical search queries.

2. Website delivery and security

The website is delivered and protected against attacks through Cloudflare. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When you visit, data processed includes your IP address, time of access, requested address, HTTP status, browser and operating system details, and referrer information where available. This enables website delivery, troubleshooting and protection against abuse.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is secure and reliable operation. Connection data is technically required for every request; without this processing, the website cannot be delivered. Fonts and images on the landing pages are served from our own website.

Retention depends on what is necessary for operation, troubleshooting and protection against attacks. In a specific security incident, data required for investigation and legal action may be retained until the matter is resolved. See the Cloudflare Privacy Policy for information about Cloudflare's processing.

3. Form protection with Cloudflare Turnstile

The registration form uses Turnstile to detect automated registrations and spam. The service is called when the landing page loads. Technical signals such as your IP address, browser details, TLS connection characteristics and the website visited are transmitted to Cloudflare to produce a verification result.

Our use of form protection relies on Article 6(1)(f) GDPR; our legitimate interest is preventing abusive registrations. Cloudflare processes signals on our behalf to provide this protection and also acts as a controller when improving its bot detection. See the Turnstile Privacy Addendum for details. Registration through the form requires successful verification; alternatively, you can contact us by email.

4. Email updates and registration through Brevo

If you register, we process your email address and, if provided, your area of work or study (such as school or university and your role). Your email address is required to send updates. Providing your area of work or study is optional and helps us understand enquiries and feedback. Without registering you will not receive email updates, but you can still use the website.

We use Brevo (Sendinblue SAS, France) for the form and email delivery. The form loads a script from sibforms.com when the page is accessed, which technically discloses connection data such as your IP address and browser information to the provider. On submission, form data is sent directly to Brevo. Brevo acts as a processor for recipient management and email delivery. See Brevo's privacy information.

Registration uses double opt-in: after signing up, you receive an email with a confirmation link. Your subscription to updates starts only after confirmation. Registration and confirmation data are processed as evidence, in particular timestamps and technical records collected during these steps, such as IP addresses.

The legal basis for email updates is your consent under Article 6(1)(a) GDPR and section 7(2), no. 2 of the German Act against Unfair Competition (UWG). Technical provision of the form relies on Article 6(1)(f) GDPR (our interest in a functioning registration process). Personalized open and click tracking is disabled; we do not analyze whether you personally opened an email or clicked a link in it.

You can withdraw consent at any time with effect for the future using the unsubscribe link in our emails or by writing to info@chemlens.app. Withdrawal does not affect the lawfulness of processing before withdrawal.

Data needed for delivery is processed until you withdraw consent or we discontinue updates. It is then removed from active mailing. Where necessary, consent records remain stored with restricted use to meet our duty to demonstrate consent (Article 6(1)(c) together with Article 7(1) GDPR) and to defend legal claims (Article 6(1)(f) GDPR) for the applicable evidentiary or limitation period. A minimal suppression record may be retained under Article 6(1)(f) GDPR for as long as necessary to respect your unsubscribe request in future mailings.

5. Contact by email

If you email us, we process your email address, message and any accompanying data to respond to your enquiry. The controller identified above personally manages the mailbox. Technical email service providers are also involved in transmitting and storing messages.

The legal basis is Article 6(1)(b) GDPR for enquiries relating to a contract or pre-contractual steps, and otherwise Article 6(1)(f) GDPR (our interest in responding to enquiries). Providing information is voluntary; without sufficient contact details and information we may be unable to respond. Retention depends on handling your enquiry and any subsequent statutory retention duties or necessary retention to defend legal claims. Data is deleted afterwards.

6. Cookies and access to devices

No advertising or web analytics scripts of our own are embedded in the landing pages. Cloudflare security functions and the external form may access technical device information or use security identifiers. The processing involved also depends on the security features used.

Storing information on or accessing information from your device is additionally governed by section 25 of the German Telecommunications and Digital Services Data Protection Act (TDDDG). An exception under section 25(2) applies only where this is strictly necessary to transmit a communication or provide a service you expressly requested. Other access requires prior consent under section 25(1). Consent to email updates does not replace such consent.

7. Recipients and processing outside the EEA

The service providers described above receive data required for website delivery, security, forms and email operations. Where they act on our behalf, processing is subject to Article 28 GDPR. Data may be disclosed to authorities or legal advisers if required by law or necessary to establish or defend legal claims. We do not sell personal data.

Cloudflare may process data outside the EU or European Economic Area, in particular in the United States. Other providers may also involve international subprocessors. Such transfers are subject to Articles 44 et seq. GDPR. Cloudflare's published data processing agreement provides for EU Standard Contractual Clauses for relevant international transfers. Details and clauses are available in the Cloudflare Data Processing Addendum. Information about Brevo's contractual terms is available in the Brevo Terms of Service. You can request a copy of the safeguards applicable to your data using our contact address above.

8. Your rights

Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). To exercise your rights, contact us using the address above.

Right to object: Where processing relies on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation (Article 21(1) GDPR). You may object to processing for direct marketing at any time without giving reasons (Article 21(2) GDPR). You may withdraw consent at any time with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority, particularly in your place of habitual residence, work or the alleged infringement (Article 77 GDPR). The authority responsible for our location is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

9. Automated decisions and security

This information website does not use automated decision-making with legal or similarly significant effects within the meaning of Article 22 GDPR. Automated spam checks protect the form. We use technical and organizational measures to protect personal data, including encrypted HTTPS connections.

We update this policy when the features offered or our processing of data change.