Legal

Privacy Notice & Data Protection

Last updated: 11 August 2026

Privacy Notice

1. Controller

The controller responsible for the processing of personal data on this website within the meaning of the EU General Data Protection Regulation (GDPR / DSGVO) is Qynara ("we", "us"). You can contact us regarding data protection matters via the contact details provided in the imprint.

2. Personal data we process

When you visit our website, our hosting provider automatically collects technical information in server log files (IP address, date and time of the request, browser type and version, operating system, referrer URL). This data is used solely to operate the site securely and reliably and is not merged with other data sources.

If you contact us via a form, by email, or register for our newsletter, we process the information you provide (e.g. name, email address, company, message content) in order to respond to your enquiry or provide the requested service.

3. Legal basis

Processing is based on Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in operating and securing our website), as applicable.

4. Recipients of data

Personal data is processed by us and, where necessary, by carefully selected processors acting on our behalf under a data processing agreement (e.g. hosting providers, email service providers, analytics providers). A transfer of personal data to a third country outside the EU/EEA only takes place where appropriate safeguards under Art. 44 et seq. GDPR are in place.

5. Storage period

We store personal data only as long as necessary for the purposes for which it was collected or as required by statutory retention obligations. Data is deleted as soon as it is no longer required.

6. Your rights

Under the GDPR / DSGVO you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing (Art. 21). Where processing is based on consent, you may withdraw your consent at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

7. Cookies

Our website uses only technically necessary cookies required for basic functionality. Any non-essential cookies (e.g. for analytics) are only set with your prior consent, which you can withdraw at any time.

8. Contact

For any questions about this privacy notice or to exercise your rights, please contact us using the details in the imprint.

Data Compliance (DSGVO / GDPR)

Qynara is committed to processing personal data lawfully, fairly and transparently in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the German Federal Data Protection Act (Bundesdatenschutzgesetz, "BDSG").

Principles

  • Lawfulness, fairness and transparency in all processing activities.
  • Purpose limitation: personal data is collected only for specified, explicit and legitimate purposes.
  • Data minimisation: only data adequate, relevant and limited to what is necessary is processed.
  • Accuracy: data is kept up to date and inaccurate data is corrected or deleted without delay.
  • Storage limitation: data is retained no longer than necessary.
  • Integrity and confidentiality: appropriate technical and organisational measures protect data against unauthorised access, loss or alteration.
  • Accountability: we are able to demonstrate compliance with the above principles.

Technical and organisational measures

We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, including encryption in transit (TLS) and at rest where applicable, role-based access controls, audit trails, regular backups, and ongoing review of our security posture. Our platform is designed with audit-trail by design and supports requirements relevant to GMP and 21 CFR Part 11 environments.

Data processors

Where we engage third-party processors, we conclude data processing agreements pursuant to Art. 28 GDPR and select providers that offer sufficient guarantees regarding data protection and information security.

International transfers

Where personal data is transferred to a third country outside the EU/EEA, we rely on adequacy decisions of the European Commission or, where none exist, on appropriate safeguards such as Standard Contractual Clauses pursuant to Art. 46 GDPR.

Data subject requests

Requests to exercise data subject rights are handled without undue delay and in any event within one month of receipt, in accordance with Art. 12 GDPR.

This page provides general information on our data protection practices and does not constitute legal advice. The German version of this notice prevails in case of doubt.