← Back to GPIBee

Privacy Policy

Last updated: 14 July 2026

This Privacy Policy explains how Gossner Electronics & Embedded Systems GmbH ("we", "us") handles personal data when you visit gpibee.com (the "Website"). We take your privacy seriously and collect as little data as possible.

1. Controller

The data controller responsible for this website is:

Gossner Electronics & Embedded Systems GmbH
Gruenberger Str. 5
47506 Neukirchen-Vluyn, Germany
E-Mail: kai@gossner.dev

For the full legal notice see our Impressum.

2. What data we collect and why

2.1 Server log files

When you visit this Website your browser automatically transmits the following data to our web server (or hosting provider):

  • IP address of the requesting device
  • Date and time of the request
  • URL of the requested page
  • HTTP status code and bytes transferred
  • Referrer URL (the page you came from)
  • Browser and operating system type (User-Agent string)

This data is technically necessary to deliver the website to you and is processed on the legal basis of Art. 6(1)(f) GDPR (legitimate interest in operating a secure, functional website). Log files are retained for 30 days and then deleted automatically.

We do not use Google Analytics, Meta Pixel, or any other third-party tracking or advertising technology. We do not use any advertising or tracking cookies. The only cookie set by this website is a short-lived technical session cookie used by the firmware-update signup form — see section 2.4 and section 3 below.

2.2 Interactive 3D model

The product page contains an interactive 3D model rendered by the open-source model-viewer library. This library is served directly from our own server — no external CDN is contacted when you load the 3D model. No additional personal data is processed.

2.3 Contact by e-mail

If you contact us by e-mail, we process the data you send (name, e-mail address, message content) solely to handle your request. The legal basis is Art. 6(1)(b) GDPR (processing necessary to respond to your enquiry) or Art. 6(1)(f) GDPR (legitimate interest in customer communication). Data is deleted once your enquiry has been fully resolved and no statutory retention periods apply.

2.4 Firmware update notifications (optional)

On the firmware page you can voluntarily sign up to be notified by e-mail when a new firmware version is released. If you do, we store:

  • The e-mail address you provide
  • A randomly generated, non-guessable token used to build your personal one-click unsubscribe link
  • The date and time you signed up

The legal basis for this processing is your consent (Art. 6(1)(a) GDPR), given by submitting the form. No confirmation e-mail is sent automatically when you subscribe or unsubscribe — the form shows a confirmation directly on the page instead. Firmware announcements themselves are also not sent automatically by this website; we compose and send them manually. Your address is used solely for this purpose and is never shared with third parties or used for any other kind of marketing.

You can unsubscribe at any time, either via the one-click link included with any e-mail you receive, or directly on the firmware page by entering your e-mail address and clicking "Unsubscribe". Unsubscribing permanently and immediately deletes your e-mail address from our system — there is no retained or "soft-deleted" record. As long as you remain subscribed, your address is kept until you unsubscribe; there is no separate automatic expiry.

To prevent the signup form from being used to check whether a particular address is already subscribed, a repeat submission of the same address only shows "already subscribed" to the same browser session that originally subscribed it (see section 3, Cookies); anyone else submitting that address receives a generic confirmation with no change to our records. To prevent automated bulk signups/unsubscribes, submissions are additionally rate-limited by IP address: our server briefly and temporarily notes the requesting IP address together with a timestamp purely to enforce this limit. This rate-limit data is kept for a short period (a few hours) and then automatically discarded; it is never linked to the e-mail addresses stored above. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse of the signup form).

3. Cookies

This website does not use any advertising, tracking, or analytics cookies.

The firmware-update signup/unsubscribe form (see section 2.4) sets one technical, first-party session cookie (PHPSESSID) when you use it. It contains no personal data itself — it's a random session identifier used only to remember, for the duration of your browser session, which e-mail addresses you have just subscribed, so that a repeat submission can show you an accurate "already subscribed" message without revealing that information to anyone else. This cookie is not set anywhere else on the website, is not used for tracking or analytics, and expires automatically when you close your browser. As it is strictly necessary for this feature to function, no separate consent banner is shown for it (§ 25(2) No. 2 TTDSG / Art. 6(1)(f) GDPR).

4. Disclosure to third parties

We do not sell, trade, or otherwise transfer your personal data to third parties. Data is only shared where strictly required by law or to operate the website (e.g. our hosting provider, acting as a data processor under a Data Processing Agreement).

Our hosting provider is: variomedia AG, Germany. variomedia AG acts as a data processor under a Data Processing Agreement in accordance with Art. 28 GDPR.

5. Data transfers outside the EU/EEA

All assets (HTML, CSS, JavaScript, 3D model) are served from our own server located in Germany. No personal data is transferred to third countries (outside the EU/EEA) in connection with visiting this website.

6. Your rights

Under the GDPR you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) — you may request a copy of the data we hold about you.
  • Right to rectification (Art. 16 GDPR) — you may ask us to correct inaccurate data.
  • Right to erasure (Art. 17 GDPR) — you may ask us to delete your data where no legal retention obligation applies.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR).
  • Right to object (Art. 21 GDPR) — you may object to processing based on legitimate interest.

To exercise any of these rights, contact us at: kai@gossner.dev

You also have the right to lodge a complaint with a supervisory authority. The competent supervisory authority for North Rhine-Westphalia is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
https://www.ldi.nrw.de

7. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always available at this URL. Material changes will be communicated via a notice on the Website.


This privacy policy was written in English. In case of discrepancy between the English and any translated version, the English version prevails.

GPIBEE  ·  XyphroLabs  ·  Engineered and made in Germany  ·  Contact & Support  ·  Impressum  ·  Privacy Policy