

IMPRINT
DATA PROTECTION
Viant Aura GmbH
Staatsstraße 5
97773 Aura
E-Mail: info.aura@viantmedical.com
Telefon: +49(0)9356 9810
Geschäftsführer | Managing Director: Michael Weimer
Handelsregister | Trade Register: Amtsgericht Würzburg HRB 6590
USt-IdNr. | VAT-No: DE 812719 532
Steuer-Nr. | Tax-No: 231/140/90042
DATA PRIVACY DECLARATION
We're glad you've decided to visit our website. In the following document, we inform you which personal data we collect and how we process that data.
This Data Privacy Declaration applies to the website of Viant Aura GmbH at www.viant-aura.de and to personal data collected through this website. Third party websites to which this page refers, for instance via links, are governed by the data privacy notices and declarations provided there.
1. Controller and Data Protection Officer
1.1 The controller responsible for processing personal data in the sense of Art. 4 no. 7 GDPR is Viant Aura GmbH, Staatsstraße 5, 97773 Aura.
E-mail: info.aura@viantmedical.com, Telephone +49(0)9356 9810
Managing Director: Michael Weimer
1.2 The company Data Protection Officer can be contacted at the address indicated above, or at the e-mail address datenschutz@viantmedical.com, Telephone: +49(0)9356 9810.
2. Purposes of data processing and legal bases
In general, we only process your personal data as necessary to provide a functional website and to provide our content and services. Typically, the personal data of website visitors are only processed with their consent. In some exceptional cases, we may not be able to obtain prior consent due to the circumstances of the situation, but may process your data if permitted by law.
2.1 Visiting the website
When you access this website, the browser you use automatically transmits information to our website servers. This information is temporarily saved in a log file. The following information is recorded and deleted automatically after 30 days:
-
Visitor's IP address
-
Date and time of the inquiry
-
Time zone difference to Greenwich Mean Time (GMT)
-
Content of the request (specific page)
-
Access status/HTTP status code
-
Transmitted data quantity
-
Website from which the request comes
-
Information on the browser type and version used
-
Visitor's operating system and interface
-
Language and version of the browser software.
We process these data to ensure a smooth connection and user-friendly operation of the website, to ensure network and information security, to analyze system security and stability, and for administrative purposes.
The legal basis for data processing is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the processing based on the aforementioned purposes of data collection. We do not use the data to make any personal conclusions about users.
In addition, we use cookies and tracking services on the website. Further information is provided under sections 7and 8of this Data Privacy Declaration.
2.2. Using our contact form
If you have questions of any kind, you may contact us using the contact form provided on our website. You must provide a valid e-mail address [and your name] so that we know who sent the inquiry and can answer it. In addition, we record the user's IP address and the date and time of registration. Users may also contact us through the e-mail addressed provided. If they do so, any personal information transmitted in the e-mail will be saved.
Data processing for the purpose of contacting us is based on your consent pursuant to Article 6(1)(a) of the GDPR, on Article 6(1)(b) of the GDPR if your inquiry is aimed at entering into a contract, and otherwise on Article 6(1)(f) of the GDPR. Our legitimate interest lies in processing and responding to your inquiry.
The personal data we collect to use the contact form is deleted after we complete your inquiry, unless there is a legal basis for storing the data or if statutory retention periods apply.
3. Transmission of personal data
We only transmit your personal data to third parties if:
-
you have granted us your consent to do so according to Art. 6 para. 1 lit. a GDPR,
-
transmission is necessary according to Art. 6 para. 1 lit. f GDPR to assert, exercise, or defend against legal claims, and there is no reason to assume that you would have an outweighing protected interest in not transmitting your data,
-
if we have a legal obligation to transmit the data according to Art. 6 para. 1 lit. c GDPR, and
-
if this is permitted by law according to Art. 6 para. 1 lit. b GDPR to carry out contractual relationships with you.
If we process personal data in a third country (e.g. outside of the European Union (EU) or European Economic Area (EEA)) or disclose it to third parties, for instance to take advantage of services by third parties, we only do so if this is necessary to fulfill our (pre)contractual obligations, based on your consent, based on a legal obligation or based on our legitimate interest. Unless we have permission to do so by law, we only have data processed in a third country if the specific requirements of Art. 44 et seqq. GDPR have been fulfilled.
4. Rights of data subjects
You have the right:
-
to request information regarding your personal data processed by us according to Art. 15 GDPR. In particular, you can request information on the purposes of processing, categories of personal information, categories of recipients to whom your data was or will be disclosed, planned storage terms, the existence of a right to correct, delete, restrict processing, or object to use of your data, the existence of a right to submit complaints, the origin of your data if we did not collect it, as well as regarding the use of automated decision-making processes and profiling, and any meaningful information on the details thereof;
-
according to Art. 16 GDPR, you can request the prompt rectification of your personal data we have saved that is incorrect or incomplete;
-
according to Art. 17 GDPR, you can request the deletion of your personal data we have saved, unless the processing is necessary to exercise the right of free expression and information, or fulfill a legal obligation, or unless processing is required in the public interest or to assert, exercise or defend against legal claims;
-
according to Art. 18 GDPR, you can request the restriction of processing for your personal data, insofar as you dispute the correctness of the data, or the data processing is illegal, but you object to its deletion and we no longer require the data, although you require the data to assert, exercise or defend against legal claims, or if you have objected to the processing according to Art. 21 GDPR;
-
according to Art. 20 GDPR, you have the right to receive your personal data which you have provided to us in a structured, common, and machine-readable format or request its transmission to another controller;
-
according to Art. 7 para. 3 GDPR, you have the right to revoke any consent you have granted to us at any time. If you do so, we will no longer be able to carry out data processing based on this consent in the future and
-
according to Art. 77 GDPR, you have the right to submit complaints to a supervisory authority. Typically, you can contact the supervisory authority at your place of residence or workplace, or at our headquarters for this purpose.
5. Your right to object
If your personal data are processed based on legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR, you have the right according to Art. 21 GDPR to object to the processing of your personal data if there are reasons to do so related to your particular situation or if you are objecting to direct advertising. In the latter case, you have a general right to object, which we will implement even if you do not indicate any particular situation.
If you would like to make use of your rights to object or right of revocation, please send an e-mail to the e-mail address provided above.
6. Data Security
We use the SSL protocol (Secure Socket Layer) on the website in conjunction with the highest level of encryption supported by your browser. Typically, this is 256 bit encryption. If your browser does not support 256 bit encryption, we instead use 128 bit v3 technology. You can tell whether individual pages of our website are transmitted in an encrypted manner because you will see the image of a key or lock symbol in your browser's bottom status bar.
Furthermore, we use suitable technical or organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, and against unauthorized access by third parties. Our security measures are continuously revised in response to technological development.
7. Cookies
We use cookies on our website. These are small files that your browser automatically creates and that are stored on your computer, laptop, tablet, smartphone, etc., when you visit our website. Cookies store information related to the specific device you are using. We distinguish between technically necessary cookies and those that are not technically necessary. Technically necessary cookies are used to enable and facilitate your use of our website. For example, we use so-called session cookies to recognize that you have already visited individual pages on our website. These are automatically deleted when you leave our site. In addition, to optimize user-friendliness, we also use temporary cookies that are stored on your device for a specific, predetermined period of time. When you visit our website again, the system automatically recognizes that you have previously visited us and recalls the entries and settings you have made, so you do not have to re-enter them. The use of technically necessary cookies is based on Section 25(2)(2) of the TDDDG.
In addition, we use cookies to collect statistical data on the use of our website and to evaluate this data using tracking tools in order to optimize our offerings for you. These cookies allow us to automatically recognize that you have visited our site before when you return. These cookies are automatically deleted after a predefined period of time. The use of these non-technically necessary cookies is subject to your prior consent in accordance with Section 25(1) of the TDDDG.
The legal basis for the use of technically necessary cookies is Article 6(1)(f) of the GDPR. Our legitimate interest lies in providing a fully functional website. The legal basis for the use of non-technically necessary cookies is your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. When you visit our website for the first time, you will be informed about the use of cookies via a consent management tool (cookie banner) and asked for your consent. You may revoke your consent at any time with future effect.
Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your device or so that a notification always appears before a new cookie is created. Please note, however, that completely disabling cookies may prevent you from using all features of our website.
8. Tracking-Tools
The tracking measures listed below and used by us are implemented only with your prior consent in accordance with Section 25(1) of the German Telemedia Act (TDDDG) in conjunction with Article 6(1)(a) of the General Data Protection Regulation (GDPR). We use these tracking measures to ensure that our website is designed to meet your needs and is continuously optimized. We also use tracking measures to collect statistical data on the use of our website and to evaluate this data for the purpose of optimizing our offerings for you. You may revoke your consent at any time with future effect via our consent management tool.
8.1 Google Analytics
We use Google Analytics on our website. This is a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to simply as “Google.” The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google LLC is certified under the EU-U.S. Data Privacy Framework.
https://www.dataprivacyframework.gov/list
This ensures an adequate level of data protection within the meaning of Article 45 of the GDPR for the transfer of personal data to the United States.
The Google Analytics service is used to analyze usage patterns on our website. The legal basis is your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You may revoke your consent at any time with future effect via our consent management tool.
Usage and user-related information, such as IP address, location, time, or frequency of visits to our website, is transmitted to a Google server and stored there. We use Google Analytics 4 (GA4), which anonymizes IP addresses by default and does not store full IP addresses.
However, we use Google Analytics with the anonymization function. With this function, Google shortens your IP address within the EU or EEA.
Google then uses the data collected to provide us with an analysis of visitors to our website and their user activities here. These data can also be used to provide further services related to the use of our website and use of the internet.
Google states that it does not combine your IP address with other data. In addition, Google provides further data privacy information at
https://www.google.com/intl/de/policies/privacy/partners
for instance on your options for preventing the use of your data.
In addition, Google offers a deactivation add-on at
https://tools.google.com/dlpage/gaoptout?hl=de
with further information on the add-on. This add-on can be installed with common web browsers, and offers you further options to control the data Google records when you access our website. The add-on tells the Google Analytics JavaScript (ga.js) that information on your visit to our website should not be transmitted to Google Analytics. However, this does not prevent information from being transmitted to us or to other web analytics services. Of course, this Data Privacy Declaration also indicates whether we use further web analytics services, and which services these are.
8.2 Google Maps
On our website, we use Google Maps to display our location and provide directions. This is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter referred to as “Google.” The parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google LLC is certified under the EU-U.S. Data Privacy Framework
https://www.dataprivacyframework.gov/list
thereby ensuring an adequate level of data protection within the meaning of Article 45 of the GDPR for the transfer of personal data to the U.S.
To enable the display of certain fonts on our website, a connection to the Google server in the U.S. is established when you visit our website.
If you access the Google Maps component integrated into our website, Google stores a cookie on your device via your web browser. Your user settings and data are processed to display our location and generate directions. In this context, we cannot rule out the possibility that Google uses servers in the U.S.
The legal basis for the use of Google Maps is Article 6(1)(f) of the GDPR. Our legitimate interest lies in optimizing the functionality of our website. To the extent that Google Maps sets cookies that are not technically necessary, this is done only with your prior consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.
Through the connection to Google established in this way, Google can determine from which website your request was sent and to which IP address the directions should be transmitted.
If you do not consent to this processing, you have the option to prevent the installation of cookies by adjusting the settings in your web browser. Details on this can be found above under the heading “Cookies.”
In addition, Google Maps and the information collected through Google Maps are used according to the Google Terms of Use https://policies.google.com/terms?gl=DE&hl=de and the Terms and Conditions for Google Maps
https://www.google.com/intl/de_de/help/terms_maps.html.
In addition, Google offers further information at
https://adssettings.google.com/authenticated
https://policies.google.com/privacy
9. Social Media Plug-Ins
We use social plug-ins to social networks on our website based on Art. 6 para. 1 lit. f GDPR. The underlying advertising purpose is considered being in our legitimate interest under the GDPR. The respective provider must ensure that its operations conform to data privacy requirements. We integrate these plug-ins using the two-click method to provide the best possible protection for visitors to our website.
9.1 LinkedIn
We use components of the network LinkedIn on our website. LinkedIn is a service of the LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (“LinkedIn”). Each time you access a page of our website which contains such components, the component causes your browser to download an icon displaying the LinkedIn component.
This process informs LinkedIn which specific page of our website you are currently visiting. If you click the LinkedIn “Recommend” button while you are logged into your LinkedIn account, you can link the content of our pages to your LinkedIn profile. This allows LinkedIn to associate your visit to our website with your LinkedIn user account.
We can neither influence the data LinkedIn collects nor the scope of this data collected by LinkedIn. We also have no knowledge of the content of data transmitted to LinkedIn. Details on data collection by LinkedIn and on your rights and settings are provided in the LinkedIn data privacy notices. These notices are available at
http://www.linkedin.com/legal/privacy-policy.
10. Usage of AI systems
We use AI systems in our company to assist us in processing and creating content, optimizing internal workflows, and increasing the productivity and efficiency of our employees. In doing so, personal data may also be processed to the extent that it is contained in the content being processed.
This processing is always carried out in compliance with applicable data protection regulations. Unless otherwise specified below, the legal basis for the processing is Article 6(1)(f) of the GDPR. Our legitimate interest lies in improving operational efficiency and competitiveness through the use of modern technologies. The suggestions and content generated by AI tools are intended solely for support purposes and are always subject to human review; no automated decisions with legal or similarly significant effects on data subjects within the meaning of Article 22 of the GDPR are made. Below, we provide information about the specific AI systems we use.
10.1 Microsoft Copilot
We use Microsoft Copilot in our company, an AI-powered productivity tool that is integrated into our Microsoft 365 environment. Microsoft Copilot uses large language models to assist our employees in creating, editing, and summarizing documents, emails, and other content.
When using Microsoft Copilot, the following personal data may be processed, to the extent that it is contained in documents, emails, chat messages, calendar entries, or other content in our Microsoft 365 environment used by our employees:
-
User inputs (prompts) and the responses generated by Copilot;
-
Content from Microsoft 365 applications (e.g., documents, emails, chat messages, calendar entries) that Copilot accesses to answer queries;
-
Usage and telemetry data (e.g., frequency of use, features used, timestamps);
-
User identification data (e.g., name, email address, user ID)
To the extent that your personal data is contained in the content stored in our Microsoft 365 environment, it may be processed by our employees in connection with the use of Microsoft Copilot. Access is granted exclusively within the scope of the respective user’s existing access permissions; Copilot does not grant any expanded access to data.
Data processing by Microsoft is carried out as part of a data processing arrangement pursuant to Article 28 of the GDPR, based on a Data Protection Addendum. Processing generally takes place within the EU Data Boundary. However, remote access by Microsoft personnel from third countries for support or security purposes cannot be completely ruled out; in which case the transfer is based on the Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR. Microsoft engages subprocessors to provide the service; a current list of subprocessors is available at https://aka.ms/subprocessors.
Microsoft has assured that customer data will not be used to train the underlying AI models.
Microsoft Copilot does not make automated decisions with legal or similarly significant effects on data subjects within the meaning of Article 22 of the GDPR. The suggestions and content generated by Copilot are intended solely for support purposes and are always subject to human review.
User inputs (prompts) and the responses generated by Copilot are stored for a period of 30 days and then automatically deleted, provided that no statutory retention requirements preclude this. Usage and telemetry data are processed and deleted in accordance with Microsoft’s retention periods.
For more information about your rights as a data subject in connection with the use of Microsoft Copilot, please refer to Section 4 of this Privacy Policy. If you have any questions about the use of AI-powered tools, you can contact our Data Protection Officer at any time (see Section 1.2).
11. Updates and changes to this Data Privacy Declaration
This Data Privacy Declaration is currently valid and was last updated in September, 2026. We may need to amend this Data Privacy Declaration due to further developments of our website and services, or due to changed legal or official regulations. Therefore, we recommend that you review this Data Privacy Declaration at regular intervals.
