返回

Privacy Policy

Last updated: March 3, 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

 

LeCoCa Investment Management GmbH

(operating under the brand Arveum)

Jägerberg 23, 82335 Berg

Germany

 

Managing Director: Albrecht Senden

Email: datenschutz@arveum.com

 

Contact person pursuant to German Telemedia Act (TMG):

Philipp Montgelas

Email: datenschutz@arveum.com

2. General Information on Data Processing

We process personal data of our users only to the extent necessary for the provision of a functional website and our content and services.

 

Processing only takes place with the user's consent or where a legal basis exists.

3. Hosting and Server Log Files

This website is operated on our own server. The following data is automatically recorded in server log files with each page request:

 

– IP address of the requesting device

– Date and time of the request

– Name and URL of the retrieved file

– Referrer URL (previously visited page)

– Browser and operating system used

– HTTP status code

 

This data is not merged with other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interests).

Retention period: maximum 7 days.

4. Contact Form

When you submit an inquiry via the contact form, the following data is processed: name, company, email address, phone number, EBIT figure, and your message.

 

This data is used exclusively for processing your inquiry and for any follow-up questions and will not be shared with third parties without your consent.

 

Transmission occurs via email through a secured SMTP server (TLS encryption). Form data is not permanently stored in a database.

 

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

Retention period: Until final processing of your inquiry, no later than 3 years.

5. Cookies and Consent

We use technically necessary cookies required for the operation of this website, as well as – with your consent – analytics cookies from Google Analytics 4 (GA4).

 

Strictly Necessary Cookies:

These cookies are required for basic website functions and cannot be disabled. They store your cookie preferences, selected language version, and color scheme setting. No personal data is transferred to third parties.

 

– arveum-theme: Display setting (light or dark mode). Duration: 1 year.

– arveum-locale: Selected language after manual language switch. Duration: 1 year.

– arveum-consent: Cookie consent (version, timestamp, preferences). Duration: 12 months.

 

Local Browser Storage (LocalStorage):

– arveum-theme: Mirror of display setting as fallback.

 

Legal basis for necessary cookies: Art. 6(1)(f) GDPR (legitimate interest) and Art. 6(1)(a) GDPR (for arveum-consent).

 

Analytics Cookies (only with your consent):

With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow St, Dublin 4, Ireland.

 

GA4 uses cookies (_ga, _gid, _ga_*) to collect anonymized information about the use of this website (pages visited, time spent, approximate geographic origin).

 

IP addresses are anonymized before storage (IP anonymization is active by default in GA4).

 

Legal basis: Art. 6(1)(a) GDPR (consent).

Third-country transfer: Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; additionally, Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR apply.

Retention period: up to 26 months.

Right of withdrawal: You can withdraw your consent at any time with future effect by clicking on "Cookie Settings" in the footer of this website.

 

You can delete cookies and local storage at any time via your browser settings.

6. Bot Protection (Cloudflare Turnstile)

On our contact and newsletter form pages, we use the bot protection service Cloudflare Turnstile. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.

 

Cloudflare Turnstile analyzes user behavior based on various characteristics (e.g., browser environment, interaction patterns) to distinguish automated requests (bots) from human users.

 

Data may be transferred to Cloudflare servers in the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF), ensuring an adequate level of data protection.

 

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention).

7. Fonts

This website uses exclusively self-hosted fonts (Space Grotesk, Inter). No requests are sent to external servers.

 

Third parties therefore receive no information about your website visit.

8. Data Security

This website uses TLS/SSL encryption. You can recognize an encrypted connection by the https:// in the address bar of your browser.

9. Your Rights as a Data Subject

As a data subject, you have the following rights:

 

– Right of access (Art. 15 GDPR)

– Right to rectification (Art. 16 GDPR)

– Right to erasure (Art. 17 GDPR)

– Right to restriction of processing (Art. 18 GDPR)

– Right to data portability (Art. 20 GDPR)

– Right to object (Art. 21 GDPR)

– Right to withdraw consent (Art. 7(3) GDPR) – at any time with future effect

 

To exercise your rights, contact: datenschutz@arveum.com

10. Right to Lodge a Complaint

You have the right to lodge a complaint with the competent data protection supervisory authority:

 

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

Promenade 27, 91522 Ansbach, Germany

Phone: +49 981 53-1300

Email: poststelle@lda.bayern.de

Website: www.lda.bayern.de

11. Policy Updates

We reserve the right to update this privacy policy in the event of changes to legal requirements or our data processing practices. The version current at the time of your visit shall apply.