How we collect, use, and protect your personal data — last updated September 2026
The controller responsible for processing your personal data on this website is:
Phoenix Non Woven GmbH & Co. KG
Phone: +49 (0) 7026 66 21
Email: contact@nonwoven365.com
Website: nonwoven365.com
No Data Protection Officer has been appointed. Please direct all data protection inquiries to the contact details above; they are handled by the management.
This website is deliberately minimal in its data handling:
localStorage entry recording that you have seen our privacy notice, so that we do not show it again.When you submit an inquiry via our contact form, we process the following data:
Purpose: To respond to your inquiry and, where applicable, to initiate or perform a contract or pre-contractual measures at your request.
Legal basis: Art. 6(1)(b) GDPR — processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract; for inquiries that do not lead to a contract, Art. 6(1)(f) GDPR — our legitimate interest in answering business inquiries.
Is providing this data required? No. Sending us an inquiry is entirely voluntary and neither required by law nor by contract. Name and email address are the only mandatory fields, because without them we cannot reply; company and phone number are optional. If you prefer not to use the form, you are welcome to contact us by telephone or post instead. Not providing the data has no consequence other than that we cannot answer you.
Recipient: Submissions are transmitted via Netlify Forms to our hosting provider Netlify Inc., San Francisco, USA. See Section 5 for details on this transfer.
Retention: Submissions are deleted after 12 months from receipt, unless an ongoing business relationship requires longer retention (in which case statutory commercial retention periods of up to 10 years under §147 AO / §257 HGB may apply).
If you contact us directly by email (e.g. at contact@nonwoven365.com), the information you provide will be stored in our email system in order to process your inquiry and for follow-up communication.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual / contractual) or Art. 6(1)(f) GDPR (legitimate interest in business communication).
When you visit this website, our hosting provider (Netlify) automatically records access log data, including:
Purpose: Ensuring website stability, security, abuse prevention, and diagnosing technical errors.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure and reliable website.
Retention: Access logs are held by Netlify under Netlify's own retention policy; we have no influence over that period and do not use these logs for tracking or profiling.
This website sets no cookies. The only browser-side storage used is a single localStorage entry:
| Name | Purpose | Category | Duration |
|---|---|---|---|
nw365-consent | Records that our privacy notice has been displayed to you, together with a timestamp and version number, so that it is not shown on every page. | Strictly necessary | Until you clear your browser storage |
This entry never leaves your device, contains no identifier and permits no recognition of you. Under §25 (2) no. 2 TTDSG it is exempt from consent, because it is strictly necessary to deliver the service you requested.
Why there is no consent banner with accept and reject buttons: a consent banner is required only where storage or access is used that is not strictly necessary — typically for analytics, marketing or personalisation. We use none of these. Asking you to consent to processing that does not take place would be misleading, so instead we display a short notice informing you of exactly this. You can call it up again at any time via Privacy notice in the footer, or directly here:
Using either option deletes the stored record of your acknowledgement, so you are returned to the state before any decision was made.
Should we introduce a service requiring consent in future, we will obtain your prior opt-in through a consent banner offering acceptance and rejection with equal prominence, and will update this policy accordingly.
You may configure your browser to block cookies and storage in general. This will not affect any functionality of this website.
We engage the following processors. Each is bound by a data processing agreement under Art. 28 GDPR that forms part of the respective provider's standard terms and applies automatically on acceptance of those terms; where data is transferred outside the EEA, the EU Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 apply. A separate signed document does not exist and, under this mechanism, is not required.
Service: Website hosting, global content delivery network, and contact form submission processing (Netlify Forms).
Location: 44 Montgomery Street, Suite 300, San Francisco, California 94104, USA. Edge delivery happens via Netlify's global CDN; for visitors from Europe, the closest edge nodes are located in the EU. Forms submissions are processed in the USA.
Data transferred: All data necessary to deliver this website (IP address, request metadata, page content) and all data you submit via the contact form (name, email, optional company / phone, message).
Transfer safeguards: Data Processing Agreement with Phoenix Non Woven GmbH & Co. KG and EU Standard Contractual Clauses (Module 2: Controller-to-Processor).
Privacy policy / GDPR information: https://www.netlify.com/gdpr-ccpa
Service: Inbound email filtering. Email addressed to our domain passes through this filter for spam and malware protection before it is delivered to our mailboxes.
Location: Reutlingen, Germany.
Data transferred: Sender and recipient address, subject, message content and attachments of email sent to us.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in protecting our systems against malware and unsolicited email.
Service: Email hosting for our business mailboxes, including contact@nonwoven365.com.
Location: For customers in the EEA, Microsoft Ireland Operations Ltd. acts as contracting party and data is stored within the European Union; support access from outside the EEA by Microsoft Corporation cannot be excluded.
Data transferred: Sender and recipient addresses, subject, full message content and attachments of any email correspondence with us — including inquiries that reach us through the contact form.
Transfer safeguards: Microsoft Data Protection Addendum with EU Standard Contractual Clauses; Microsoft Corporation is certified under the EU-US Data Privacy Framework.
Privacy policy: https://privacy.microsoft.com/privacystatement
No processors other than those named above receive personal data from us. When you merely load a page, no data is transmitted to Google, Meta (Facebook), LinkedIn, Cloudflare, OpenStreetMap or any advertising provider. External links — for example to LinkedIn or partner websites — transmit data to those providers only if you actively click them.
We do not use automated decision-making or profiling within the meaning of Art. 22 (1) and (4) GDPR.
The public content of this website may be retrieved by crawlers operated by providers of AI systems — among others OpenAI, Anthropic, Google, Perplexity, Apple and Meta. We permit this deliberately via our robots.txt, so that our technical information remains findable in AI-assisted search.
Only content that is publicly accessible anyway is affected: product information, technical specifications and business contact details of our representatives. Contact form submissions, email correspondence and log files are never accessible to these crawlers. We have no influence over how the respective providers subsequently process retrieved content.
As a data subject, you have the following rights with respect to your personal data:
To exercise any of these rights, contact us at contact@nonwoven365.com. We will respond within one month as required by Art. 12 GDPR.
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR. The supervisory authority competent for Phoenix Non Woven GmbH & Co. KG is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-WürttembergThis website is served exclusively over HTTPS (TLS encryption) and uses HTTP Strict Transport Security (HSTS). We implement appropriate technical and organisational measures in accordance with Art. 32 GDPR to protect your personal data against unauthorised access, loss, or disclosure. Our processor Netlify is contractually obliged to maintain equivalent standards.
For all questions, requests, or concerns relating to the processing of your personal data, please contact:
Phoenix Non Woven GmbH & Co. KG
Adolf-Scheufelen-Str. 33, 73252 Lenningen, Germany
Email: contact@nonwoven365.com
Phone: +49 (0) 7026 66 21
We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. The current version is always available at https://nonwoven365.com/privacy/. Material changes will be indicated by an updated "last updated" date.
Last updated: September 2026