Privacy
On this page
We, the editors of the OR Laserservice website, take the protection of your personal data very seriously and adhere strictly to the rules of data protection laws. Personal data is collected on this website only to the extent that is technically necessary. Where we collect personal data away from the website – for example on a paper form at our stand at a trade fair – this policy covers that collection too; see the section on trade fairs below. Under no circumstances will the collected data be sold or passed on to third parties for other reasons.
As new technologies and the ongoing development of this website may result in changes to this privacy policy, we recommend that you review the privacy policy at regular intervals.
Data processing on this website
We automatically collect and store information that your browser transmits in server log files. This includes browser type/version, operating system used, website visited, host name of the accessing computer (IP address), time of server request, and the amount of data sent in bytes. This data cannot be attributed to specific individuals and is not combined with other data sources. Log data is used to ensure site security and is anonymized before analysis.
Cookies and local storage
We do not use tracking cookies. The site stores a small amount of data in localStorage to make the experience consistent across visits. This includes language preference and UI settings ("or-tweaks") as well as the quote-cart contents ("or-cart"). You can delete this data at any time by clearing your browser storage.
Collection and processing of personal data
You can visit this website without providing any personal information. If you contact us through this website or by email, we process the information you provide only to answer your enquiry and not for marketing follow-up. We do not pass your information to third parties without your consent. Contact details you hand us on a signed form at a trade fair are a separate category with their own legal basis and their own retention period – see the section on trade fairs below.
Data collected at trade fairs and other events
At trade fairs and comparable events we collect contact details on paper forms at our stand. These are your name, company, role, email address, telephone number and country, the products or services you tell us you are interested in, anything written in the free-text notes field on the form, and the date and signature with which you give your consent. We use these details for one purpose only: to contact you by email or telephone about the products and services you indicated on the form. The legal basis is your consent under Art. 6(1)(a) GDPR, which you give by ticking the consent box and signing the form. Without that consent the form is destroyed at the stand and none of your details are recorded.
Contact details collected in this way are held on a dedicated trade-fair contact list. That list is kept separate from our general marketing distribution list, and entries are not transferred from one to the other. Your data is not passed to third parties and is not used to build any advertising profile. You can withdraw your consent at any time with effect for the future, by email to info@or-laserservice.de; we then delete your entry from the trade-fair contact list.
We keep trade-fair contact details for 24 months after the event, or for 24 months after our last contact with you about your enquiry if that is later. They are deleted once that period ends. If you withdraw your consent earlier, we delete them at that point. Statutory retention obligations – for example where an enquiry has led to a business transaction – remain unaffected.
Third-party services
This website uses Vercel Web Analytics and Vercel Speed Insights, provided by Vercel Inc., to count page views and measure page-loading performance. Both work without cookies: they set no cookies, store nothing on your device, and use no cross-site identifiers. Visitors are counted using a hash derived from the incoming request that is discarded after 24 hours, so no browsing session can be reconstructed across pages, days, or websites. The data is aggregated and covers the page address and route, the referring page, approximate region, device type, operating system, browser, and page-performance measurements. The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in operating a secure, fast and reliable website). We use no social media plugins. This policy will be updated when customer accounts and quote processing are integrated with Odoo (phase 2).
Our contact form and our partner-programme form are protected against automated misuse by Cloudflare Turnstile, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. This happens in two steps. When you open a page carrying one of those forms, the Turnstile script is loaded from Cloudflare, and your IP address, browser information and your interaction with the page are transmitted to Cloudflare so that a human visitor can be told apart from an automated one. When you then send the form, our server transmits the token issued by Turnstile together with your IP address to Cloudflare a second time, in order to have the result confirmed. We use the service for one purpose only: to stop the forms and our mail servers being abused to send mail. According to Cloudflare's Turnstile privacy notice, the signals collected are used to detect and block bots, not to identify, profile or target individuals; for that purpose Cloudflare acts as a processor on our instructions. Cloudflare additionally processes the same signals to improve Turnstile's own bot detection, and is a data controller in its own right for that second purpose, on the basis of its legitimate interest. The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in protecting our forms and our email infrastructure from automated abuse).
We do not store the Turnstile data ourselves: the token and Cloudflare's confirmation are discarded with the request and are written neither to a database nor to a customer record. To limit automated bursts, our server additionally holds the IP addresses of form submissions in working memory for a rate-limit window of 10 minutes. Once that window has passed, an address no longer counts towards the limit and is removed from memory the next time that list is used, at the latest when the server process ends; the addresses are not stored permanently and are not linked to your enquiry. Cloudflare, Inc. is based in the USA and is certified under the EU-U.S. Data Privacy Framework, so the transfer takes place on the basis of the adequacy decision of the European Commission (Art. 45 GDPR). Turnstile was introduced on 7 September 2026 after automated abuse of our contact form; until that date this policy stated that we used no captcha services.
Cloudflare's privacy notice for Turnstile is available at cloudflare.com/turnstile-privacy-policy, and its general privacy policy at cloudflare.com/privacypolicy.
Links to other websites
This privacy policy covers this website and the personal data we collect away from it, such as on paper forms at trade fairs. It does not apply to websites owned by third parties. Our web pages may contain links to other websites that we believe may be of interest to our visitors. We cannot guarantee the privacy standards of websites to which we link.
Data security
We make every effort to protect users from unauthorized access to, or unauthorized modification, disclosure, or destruction of data. We restrict access to personal data to authorized personnel who need it to process your request.
Rights of data subjects
You have the right to obtain information about the data stored about you, its origin and recipients, and the purpose of storage. You also have the right to object to the processing of your personal data and to request correction or deletion, provided no legal retention obligations apply.
Where processing is based on your consent, you can withdraw that consent at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal is not affected by it.
You also have the right to lodge a complaint with a data protection supervisory authority if you consider that our processing of your personal data infringes data protection law (Art. 77 GDPR). The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit) in Wiesbaden.
If you have any questions regarding the collection, processing, or use of your personal data, or if you wish to revoke your consent, please contact us at info@or-laserservice.de.