Privacy Policy

Last updated: 2 September 2026. This policy describes what data is processed when you visit signalchain.eu. It describes today's status – not what is planned.

1. Who is responsible for processing my data?

Responsible for processing your data is:

Dr. Thorsten Schneider – Online Marketing
Lange Straße 31
32051 Herford
Germany
Phone: +49 5221 691 324
Email: sales@signalchain.eu

For questions, suggestions, or complaints, you can reach us using the contact details given above.

2. Who can I contact with questions about data protection?

Please direct questions about data protection to sales@signalchain.eu or to the address given above.

3. How is my data processed when I visit this website?

We collect and process your data only when we have either obtained your consent or the processing is permitted by law.

3.1 Technically necessary data and log files. When you visit our website purely for informational purposes, we collect the data your browser transmits to our server: IP address, date and time of the request, time zone difference from Greenwich Mean Time, content of the request, amount of data transferred, access status, referring website (referrer), browser type and version, operating system, and browser software language.

This processing takes place to display the website to you, ensure its stability, and for security reasons. The legal basis is Art. 6(1)(f) GDPR. The data is deleted as soon as it is no longer required for these purposes; IP addresses are deleted or anonymized after 30 days at the latest. This collection is strictly necessary for operating the website; there is accordingly no option to object.

3.2 Hosting. This website is operated by a service provider within the European Union, who processes the aforementioned log files on our behalf. We have a data processing agreement with them pursuant to Art. 28 GDPR.

3.3 Cookies, local storage, and reach/success measurement. This website uses cookies and browser storage (localStorage) to the extent you have given your consent or it is technically necessary. On your first visit, we display a consent banner with three categories.

Necessary. Solely your own cookie choice, stored in your browser's local storage, not as a cookie. Without this storage, the banner would be shown to you again on every visit. The legal basis is our legitimate interest in a functioning consent mechanism (Art. 6(1)(f) GDPR); there is accordingly no option to object, because the banner could not fulfil its purpose without this storage.

Also necessary: country and language selection. Separately from your cookie choice, we store your chosen country/language combination in your browser's local storage, likewise not as a cookie, so the page appears in your chosen language on your next visit instead of asking you again. The legal basis is our legitimate interest in a consistent, language-appropriate presentation (Art. 6(1)(f) GDPR); there is accordingly no option to object, because the page would otherwise have to ask for your language again on every visit.

Statistics (only with your consent). We use Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Among other things, this sets the cookies _ga and _ga_<identifier> (distinguishing visitors and session state, respectively, each roughly two years). The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

Also under the Statistics category, but only on the homepage and the sign-up form, we use Mouseflow, a service of Mouseflow ApS, Flæsketorvet 68, 1711 Copenhagen V, Denmark. Mouseflow records mouse movements, clicks, scroll behavior, and page structure to analyze and improve the usability of these two pages; according to the provider, input in form fields is automatically masked. Among other things, this sets cookies matching the name pattern mf_* (including mf_user, to recognize returning visitors; according to the provider, at least for the duration of the session). We have a data processing agreement with Mouseflow pursuant to Art. 28 GDPR. The legal basis is likewise your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

Marketing (only with your consent). We use Google Ads, likewise a service of Google Ireland Limited. If you agree to this category, we use it both to measure ad performance (attributing ad clicks to conversions) and to reach you again with advertising on other websites and on YouTube (remarketing) – for this, Google forms an audience based on your visit to which we can later show ads. Without this consent, neither performance measurement nor remarketing takes place. Details on the cookies this sets are in the table below. The legal basis is likewise your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

Also under the Marketing category, we use OpenAI's advertising pixel. If you agree to this category, we use it to measure ad performance (OpenAI Ads) on the homepage, the order page, and the profile page after a completed purchase – for this, we transmit page views as well as the completion of sign-up and purchase on these pages to OpenAI, without your email address or other details from your business profile in plain text. Without this consent, the pixel is not loaded on any page. Details on the cookies this sets are in the table below. The legal basis is likewise your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

Without your consent, no cookies or comparable information are stored on or read from your device for Statistics or Marketing purposes. When Google Consent Mode is used, cookieless signals may nonetheless be transmitted to Google, for example regarding consent status and with technical information about the request. Your choice is voluntary, is not a prerequisite for using this website for either category, and can be withdrawn at any time with effect for the future:

Overview of the cookies and storage entries used. The following table lists every single entry this website sets – not only cookies in the narrow sense, but also comparable storage in the browser (local storage), because the same rules apply to both (§ 25 TDDDG).

Name / pattern Category Provider Purpose Storage type Duration
sc_cookie_einwilligung Necessary SignalChain (this provider) Stores your cookie choice so the banner doesn't reappear local storage until changed or deleted by you
sc_markt_sprache Necessary SignalChain (this provider) Stores your country/language choice so the site appears in your chosen language on your next visit local storage until changed or deleted by you
_ga Statistics Google Ireland Limited (Google Analytics 4) Distinguishing visitors cookie around 2 years
_ga_<identifier> Statistics Google Ireland Limited (Google Analytics 4) Session state cookie around 2 years
mf_* (incl. mf_user) Statistics – homepage and sign-up form only Mouseflow ApS Recognizing returning visitors, session detection cookie according to the provider, at least session duration
mf_initialDomQueue, mf_transmitQueue Statistics – homepage and sign-up form only Mouseflow ApS Temporary buffer of the session recording before transmission session storage duration of the browser session
_gcl_au Marketing Google Ireland Limited (Google Ads) Attributing ad clicks to conversions cookie around 90 days
_gcl_aw, _gcl_dc Marketing Google Ireland Limited (Google Ads) Attributing ad clicks to conversions (further variants of the same purpose) cookie around 90 days
_gac_<identifier> Marketing Google Ireland Limited (Google Ads) Campaign attribution when linked to Google Analytics cookie around 90 days
_gcl_ls Marketing Google Ireland Limited (Google Ads) Cookieless successor to _gcl_au for the same purpose local storage until deleted
IDE, DSID, AEC, NID, ADS_VISITOR_ID Marketing Google Ireland Limited (Google Ads, some via google.com/doubleclick.net) Forming an audience from your visit for remarketing ads on other websites and on YouTube cookie according to the provider, up to 13 months, varies by cookie
__oppref Marketing – homepage, order page, and the profile page after purchase only OpenAI (OpenAI Ads) Attributing ad clicks to conversions cookie not documented by the provider – see note below
__obref Marketing – homepage, order page, and the profile page after purchase only OpenAI (OpenAI Ads) Recognizing your browser for performance measurement cookie not documented by the provider – see note below
__oaiq_consent, oaiq_consent Marketing – homepage, order page, and the profile page after purchase only OpenAI (OpenAI Ads) Stores the consent status recognized by the pixel itself cookie or local storage not documented by the provider – see note below

We have no provider-published information on the retention periods of the OpenAI entries; we will add it once OpenAI documents it. If you withdraw your consent, we actively delete these entries ourselves (see above, “Not just the signal to Google – we also clean up ourselves”).

3.4 Contacting us by email or phone. If you write or call us, we use the data you provide to handle your inquiry. Depending on the content, the legal basis is Art. 6(1)(b) GDPR for an inquiry connected with a contract or its initiation, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding. Your message is deleted once the matter is resolved and no statutory retention periods apply. It is not passed on to a newsletter service.

3.5 Signing up for SignalChain. When you sign up for SignalChain via our sign-up form, we collect your email address, the business location you selected (district or independent city), your sector(s), a band for annual revenue and number of employees, as well as – likewise mandatory fields, without which the form cannot be submitted – broad information on the goods categories you source and sell, their regions of origin and sale, transport routes used, waterway corridors used, and your energy dependency. Without this information, our report would fall silent precisely on procurement and transport – the two impact channels through which a business is most often hit. We deliberately collect only broad bands and categories here, not supplier or customer names, bills of materials, quantities, contracts, or invoices. We use this information exclusively to provide you with SignalChain for your business, to assess external events for their possible relevance to your business, and to notify you by email of relevant changes.

Your sign-up only becomes effective once you click the confirmation link in the email we send you after submitting the form (double opt-in). Without this click, you will not receive a briefing, and your information is not treated as an active sign-up. The legal basis is your consent under Art. 6(1)(a) GDPR, which you give by checking the mandatory field and clicking the confirmation link. To document this consent, we additionally store the time of sign-up, the IP address from which it was made, and the version of the consent text you agreed to. The form is intended exclusively for commercial or self-employed professional use; you confirm this via the corresponding mandatory field at sign-up.

Technically, your sign-up is first placed in a sealed queue that our web server itself cannot read, and is then transferred from there into our local, publicly unreachable storage; we store your confirmation token only as a check value, not in plain text. Your data remains stored for as long as your sign-up is active. You can unsubscribe at any time via a link in every email, without being asked why and without a retention offer; we record the time of unsubscribing. Beyond that, your rights under section 9 of this policy apply, in particular the right to erasure. Data is not passed on to third parties beyond the data processors named in section 4.

3.6 Paying for SignalChain via Stripe. If you choose the paid tier of SignalChain, you are redirected to Stripe's payment process. There, you enter your email address, company name, payment details, and, if you provide it, your VAT identification number directly with Stripe. Stripe acts as an independent seller for this payment (Managed Payments) and processes this data as its own data controller, not as our data processor – for processing the payment, invoicing, fraud prevention, and to fulfil its own statutory obligations. On our side, the legal basis is Art. 6(1)(b) GDPR, since the redirection is necessary to fulfil the contract concluded with you. Which data Stripe processes in detail, for how long, and for what purpose, is governed by Stripe's own privacy policy. We ourselves store from this process only that and with which plan a contract was concluded – no payment or card data (see also § 4 of the Terms and Conditions).

4. To which recipients is my data transmitted?

We treat your data confidentially. Only people who need access to fulfil the purposes described above are given access.

Data is transmitted to third parties only where this is necessary for the purposes named and legally permitted, or where you have consented. To fulfil our tasks, we use data processors; currently these are the hosting provider and the provider of our email mailbox. In addition, authorities may be recipients where we are legally required to provide information.

If you choose SignalChain, Stripe is additionally a recipient of the data provided during payment (section 3.6) – there, however, not as our data processor, but as an independent data controller for the payment process.

If you agree to the Statistics or Marketing categories (section 3.3), Google is additionally a recipient of the data processed in that context – likewise as an independent data controller for Google Analytics 4 and Google Ads, not as our data processor.

If you agree to the Statistics category and are on the homepage or the sign-up form (section 3.3), Mouseflow is additionally involved as our data processor.

If you agree to the Marketing category and are on the homepage, order page, or the profile page after a completed purchase (section 3.3), OpenAI is additionally a recipient of the data processed in that context – likewise as an independent data controller for OpenAI Ads, not as our data processor.

5. Is my data transferred to countries outside the European Economic Area?

For visiting this website: no. The service providers currently used (hosting, email mailbox) process your data within the European Union. Should this change, we will update this policy beforehand and name the basis for the transfer – an adequacy decision under Art. 45 GDPR or appropriate safeguards under Art. 46 et seq. GDPR – at this point.

For a payment via Stripe (section 3.6), a transfer to the USA may occur if a US-based Stripe entity is involved in the payment process. Which safeguards apply – such as standard contractual clauses under Art. 46 GDPR or certification under the EU-U.S. Data Privacy Framework – is set out by Stripe in its own privacy policy, since Stripe is itself the controller in this respect (section 3.6).

For Google Analytics 4 and Google Ads (section 3.3), a transfer to the USA may likewise occur where consent has been given. Google LLC is certified under the EU-U.S. Data Privacy Framework; details are set out by Google in its own privacy policy, since Google is itself the controller in this respect (section 3.3).

For Mouseflow (section 3.3), processing takes place, according to the provider, within the European Union (office in Copenhagen, Denmark).

For OpenAI Ads (section 3.3), a transfer to countries outside the European Economic Area, including the USA, may likewise occur where consent has been given. Which safeguards apply in detail is set out by OpenAI in its own privacy policy, since OpenAI is itself the controller in this respect (section 3.3).

6. What applies to links to other websites?

Our website and our reports may contain references to third-party offerings – for example to our YouTube channel or to the official and other external sources we cite, such as on the Data Sources and Licenses page. If you leave our offering through such a reference, the privacy provisions of the respective third-party provider apply there; we have no influence over their data processing, and our privacy policy does not apply there.

7. How secure is my data?

We employ technical and organizational security measures in line with the state of the art to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access. The website is delivered exclusively encrypted via HTTPS.

8. What applies to children's data?

Our offering is aimed at businesses. We do not knowingly request personal data from children and do not knowingly process it.

9. What rights do I have regarding my data?

Under Art. 15 GDPR, you have the right to access the data processed about you; under Art. 16 GDPR, the right to rectification; under Art. 17 GDPR, the right to erasure; under Art. 18 GDPR, the right to restriction of processing; and under Art. 20 GDPR, the right to receive the data you have provided in a structured, commonly used, and machine-readable format. The right of access is subject to the restrictions of § 34 BDSG (German Federal Data Protection Act); the right to erasure is subject to the exceptions of § 35 BDSG.

Right to object under Art. 21 GDPR. Where we process your data on the basis of legitimate interests and grounds arising from your particular situation speak against it, you may object to this processing. You may object to processing for direct marketing purposes without restriction and at any time. You can send your objection informally to the contact details given above.

10. Can I withdraw consent I have given?

To the extent we process data on the basis of consent, you can withdraw it at any time. The lawfulness of processing carried out before the withdrawal remains unaffected. You can send your withdrawal informally to sales@signalchain.eu.

11. Do I have the right to lodge a complaint with a supervisory authority?

Under Art. 77 GDPR, you may lodge a complaint with a data protection supervisory authority at any time if you believe that the processing of your data violates applicable law. The competent authority for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (the data protection authority of the German state of North Rhine-Westphalia).

12. Do I have to provide data?

Visiting this website itself requires no information from you beyond the technically necessary data for its delivery. If you choose to fill out a form, the information marked as mandatory there is required for the respective function – without it, the form cannot be submitted. This applies in particular to signing up for SignalChain (section 3.5): there, in addition to email address, location, sector, and revenue/employee band, the information on goods categories, sourcing and sales regions, transport routes, and energy dependency is also mandatory, because without it our report would fall silent on procurement and transport.

13. Does automated decision-making take place?

No. Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

For clarity, because our offering includes automated analysis: SignalChain evaluates public measurement and official data on hazard situations. This evaluation relates to regions, sectors, and goods classes – not to individuals. No profiles of individuals are created, and no decisions with legal effect on you are made.

14. Can this information be changed?

Yes. Since our data processing may change, we update this information from time to time. You will always find the current version at this location.