leading the next gen · LTNG GmbH
Privacy
Information on the processing of personal data and your rights.
General information
As the operator of this website and as a company, we come into contact with your personal data. This means any data that provides information about you and can be used to identify you. In this privacy policy, we explain how, for what purpose and on what legal basis we process your data.
The controller responsible for data processing on this website and within our company is:
LTNG GmbH
Am Sandtorkai 32
20457 Hamburg
Telephone: +49 (0) 40 226 332 240
Email: office@leadingthenextgen.com
Data protection officer
We have appointed a data protection officer. You can contact the data protection officer at: office@leadingthenextgen.com
No web analytics, no tracking, no advertising, no cookies
We do not use web analytics, tracking or advertising services on this website. Your usage behaviour is not evaluated, no usage profiles are created and no data is processed for advertising purposes. We do not use cookies. A consent banner is therefore not required.
A web analytics service previously used has been discontinued and the data collected has been deleted.
Legal bases
We process personal data on the basis of Art. 6(1)(a) GDPR where you have given your consent, on the basis of Art. 6(1)(b) GDPR to initiate and perform contracts, on the basis of Art. 6(1)(c) GDPR to comply with legal obligations, and on the basis of Art. 6(1)(f) GDPR where we safeguard legitimate interests that do not outweigh your interests.
How long do we store your data?
In some parts of this privacy policy, we inform you how long we or the companies that process your data on our behalf store your data. Where no such information is provided, we store your data until the purpose of the processing no longer applies, you object to the processing or you withdraw your consent.
In the event of an objection or withdrawal of consent, we may continue to process your data if we have compelling legitimate grounds for doing so that override your interests, rights and freedoms, if processing is necessary for the establishment, exercise or defence of legal claims, or if we are legally obliged to retain the data. As soon as these conditions no longer apply, we delete the data.
Hosting
Our website is hosted on a server operated by the following internet service provider:
STRATO AG
Otto-Ostrowski-Straße 7
10249 Berlin
The hosting provider stores our website data. This also includes personal data collected automatically, in particular access data. When processing data, our hosting provider follows our instructions and processes the data only to the extent necessary to fulfil its service obligations. We have concluded a data processing agreement with the hosting provider pursuant to Art. 28 GDPR.
As we use our website to address potential clients and maintain contact with existing clients, data processing by our hosting provider serves to initiate and perform contracts and is therefore based on Art. 6(1)(b) GDPR. We also have a legitimate interest in providing an online presence that meets the necessary requirements for security, speed and efficiency. In this respect, we also process your data on the basis of Art. 6(1)(f) GDPR.
Logging by the web hosting provider
Log data is automatically collected by the system whenever websites are accessed. This is necessary for technical reasons to enable the website to be delivered to the user’s device. The legal basis for this data collection is Art. 6(1)(f) GDPR.
During this process, our web hosting provider STRATO collects and stores the following types of data in its log files: accessed domain, anonymised client IP address, request line, timestamp, status code, response body size, referer, user agent and remote user.
Data is stored in log files to ensure the website functions properly. The data also serves to ensure the security of the information technology systems involved. These purposes also constitute the legitimate interest in data processing under Art. 6(1)(f) GDPR. Collecting data to provide the website and storing data in log files are essential for operating the website.
To detect attacks, STRATO stores non-anonymised IP addresses for a maximum of seven days. They are then irreversibly anonymised.
Further information: www.strato.de/datenschutz and www.strato.de/blog/dsgvo-logfiles
Encryption
This website uses TLS encryption to protect the transmission of your data. You can recognise an encrypted connection by the “https://” displayed in your browser’s address bar.
Contacting us
This website does not provide a contact form. If you contact us by email, telephone or LinkedIn, we process the data you provide in order to respond to your enquiry. This includes, in particular, your name, contact details, company and the content of your enquiry.
The legal basis is Art. 6(1)(b) GDPR where your enquiry serves to initiate or perform a contract. Otherwise, we process the data on the basis of our legitimate interest in responding to business enquiries under Art. 6(1)(f) GDPR. We delete this data as soon as it is no longer required for its purpose and no statutory retention obligations prevent deletion.
Enquiries, proposals and client data
In connection with proposals and engagements, we process contact, contract and billing data, as well as information provided to us during our work together. The legal basis is Art. 6(1)(b) GDPR and, where legal obligations apply, Art. 6(1)(c) GDPR.
Retention obligations under commercial and tax law require us to retain certain documents, in particular under Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO). We delete the data once these periods have expired.
We process personal data on behalf of our clients exclusively on the basis of a data processing agreement pursuant to Art. 28 GDPR and in accordance with the instructions of the respective client.
Service providers we use
For operations, communication and project work, we use service providers that process personal data on our behalf. We have data processing agreements pursuant to Art. 28 GDPR with all service providers. We use:
- Email, office software, file storage and video conferencing: Microsoft 365 by Microsoft Ireland Operations Limited, Dublin, Ireland
- Client, project and invoice management: MOCO by everii Switzerland GmbH, In der Weid 15, 8122 Binz, Switzerland
- Digital whiteboard and collaboration: Miro by RealtimeBoard Inc., San Francisco, USA, with the branch RealtimeBoard BV, Amsterdam, Netherlands
- Hosting of this website: STRATO AG, Berlin
The legal basis is Art. 6(1)(b) GDPR for carrying out our work together and Art. 6(1)(f) GDPR for our interest in secure and efficient operations.
Use of AI tools
We use AI-assisted tools in our own work, in particular for research, structuring, drafts, translation assistance and quality checks. We enter personal data and confidential information belonging to our clients into such tools only after prior agreement with the respective client and only to the extent agreed. Decisions are made by people; no solely automated decision-making within the meaning of Art. 22 GDPR takes place.
Providers used:
- ChatGPT by OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland
- Claude by Anthropic PBC, San Francisco, USA
- Perplexity by Perplexity AI, Inc., San Francisco, USA
- Gemini by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Transfers to third countries
Some of the service providers we use are based outside the European Union or may process data outside the EU.
The European Commission has issued an adequacy decision for Switzerland pursuant to Art. 45 GDPR. For providers based in the United States, we base transfers on the European Commission’s Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and, where the respective provider is certified under the EU-US Data Privacy Framework, on Art. 45 GDPR. On request, we will inform you which basis applies in each individual case.
We link to LinkedIn profiles on our website. Data is transferred to LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland only when you click such a link. LinkedIn is responsible for processing data there; please refer to LinkedIn’s privacy policy for details.
We also operate a company page on LinkedIn. LinkedIn and we are joint controllers under Art. 26 GDPR for the data processed there as part of page statistics. We receive only aggregated statistics and no information about individual people. The legal basis is our legitimate interest in public presentation and outreach under Art. 6(1)(f) GDPR.
Job applications
We receive applications exclusively through the LinkedIn and Indeed platforms. Applications by email are not envisaged.
The respective providers are responsible for processing your data on the platforms themselves: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, and Indeed Ireland Operations Limited, Block B, Capital Dock, 80 Sir John Rogerson’s Quay, Dublin 2, D02 HE36, Ireland. Please refer to the providers’ privacy notices for details.
If you submit an application to us through one of these platforms, we process the data it contains — in particular basic personal and contact details, information about your education and career, and any other documents you provide — exclusively for the purpose of conducting the recruitment process. The legal basis is Section 26(1) of the German Federal Data Protection Act (BDSG) in conjunction with Art. 88 GDPR and Art. 6(1)(b) GDPR.
If we do not enter into a working relationship, we delete your application documents no later than six months after the procedure has concluded, unless you have consented to longer storage or statutory retention obligations prevent deletion.
Fonts
We use fonts on our website that are installed locally on our server. No connection is made to third-party servers.
Your rights
Right to object to data processing
Where this privacy policy states that we have legitimate interests in processing your data and therefore base this processing on Art. 6(1), sentence 1, point (f) GDPR, you have the right to object under Art. 21 GDPR. To do so, you must provide reasons for your objection arising from your particular situation. No reasons are required if your objection concerns the use of your data for direct marketing.
An objection means that we may no longer process your data. The only exceptions are where we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or where the processing serves the establishment, exercise or defence of legal claims. These exceptions do not apply to direct marketing.
No profiling takes place.
Withdrawal of your consent
Where processing is based on your consent, you may withdraw that consent at any time without giving reasons (Art. 7(3) GDPR). From the time of withdrawal, we may no longer process your data on this basis. Exception: we are legally obliged to retain data for a certain period; such periods exist in particular under tax and commercial law.
Access, rectification, erasure, restriction and data portability
You have the right of access to the data stored about you (Art. 15 GDPR), to rectification of inaccurate data (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR), and to data portability (Art. 20 GDPR). To exercise these rights, please use the contact details provided above.
Complaint to the supervisory authority
If you believe that we are infringing the General Data Protection Regulation, you have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority, for example in the Member State of your residence, place of work or the place of the alleged infringement. The data protection supervisory authority responsible for Hamburg is the authority responsible for us; you can find its current contact details on its website.
Changes to this privacy policy
We update this privacy policy when our processing activities or legal requirements change. The version published on this page applies in each case.
Last updated: September 2026