Last updated: April 2026
Privacy Policy
This privacy policy explains how Lean Maritime GmbH (“we”, “us”) processes personal data when you visit this website or contact us through it. We take data protection seriously: we do not use tracking cookies, we do not sell your data, and we work only with processors that meet GDPR requirements.
1. Data controller
The data controller responsible for processing your personal data on this website is Lean Maritime GmbH, Alter Wall 32, 20457 Hamburg, Germany.
For any privacy-related inquiries, please contact us at info@lean-maritime.com or by post at the address above.
2. Data we process
When you use our contact form, we process the data you enter: name, email address, optional company name, your message, and your consent confirmation.
When you visit any page on this site, your browser automatically transmits technical information that our hosting provider briefly records in access logs (date and time, page requested, referring URL, user agent, IP address). These logs are used solely to detect and prevent attacks and are kept for a short period.
We use Plausible Analytics to understand aggregate site usage. Plausible does not set cookies, does not track users across sites, and does not store personal data. It records anonymized metrics such as page views, referrer, country (from IP, discarded immediately), browser and OS family.
3. Purpose and legal basis
Contact form submissions are processed to respond to your inquiry and, where applicable, to prepare a business engagement. Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) in conjunction with your consent under Art. 6 (1) (a) GDPR.
Technical access logs are processed to secure the website and prevent abuse. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest).
Plausible Analytics data is processed to analyse aggregate usage and improve the site. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest). No personal data is processed.
4. Processors
We use the following service providers as data processors under Art. 28 GDPR. Each has appropriate data processing agreements and technical safeguards in place.
- Resend (https://resend.com) — transactional email delivery for contact form messages. Resend receives your name, email address and message content solely to deliver the email to us. Resend is SOC 2 compliant and provides EU Standard Contractual Clauses for any data transfers outside the EU.
- Plausible Analytics (https://plausible.io) — privacy-friendly website analytics. Data is processed in the EU without cookies or cross-site tracking. No personal data is stored.
- Cloudflare (https://cloudflare.com) — hosting and content delivery. Cloudflare may briefly process IP addresses for security and caching purposes.
5. Retention
Contact form submissions are retained for as long as necessary to process your inquiry, plus any legal retention obligations that may apply (German tax and commercial law requires retention of certain business correspondence for up to 10 years). You may request earlier deletion at any time.
Analytics and technical access data are aggregated or deleted within a short period and contain no personal identifiers.
6. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
7. Cookies
This website does not use tracking cookies. Our analytics provider Plausible operates entirely without cookies. The only storage your browser may use is session-local, never persistent for tracking.
8. Changes to this policy
We may update this privacy policy to reflect changes in our practices, the services we use, or legal requirements. The "last updated" date at the top of this page always reflects the current version.
Supervisory authority
If you believe your data protection rights have been violated, you may file a complaint with the competent supervisory authority:
Der Hamburgische Beauftragte für Datenschutz und InformationsfreiheitLudwig-Erhard-Str. 22, 20459 Hamburg, Germany
https://datenschutz-hamburg.de