Who is responsible
Genius High Performance Computing is responsible for the personal information described in this notice. This notice covers our websites, website enquiries, sales correspondence and order administration.
For privacy questions, requests or concerns, use our Contact page or email [email protected]. We will route the request to the person responsible. Contact details for any representative or other statutory privacy contact required under applicable law will be published here when appointed.
Information we collect and its sources
You provide information when requesting a quotation or callback, sending a contact or support request, giving feedback or corresponding about a purchase. It may include your name, email, telephone number, organisation, role, equipment requirements, quantities, budget, delivery destination, preferred contact time and the contents of your message. Required and optional form fields are distinguished on the form.
For orders and after-sales support, we may hold billing and delivery details, order and invoice references, equipment specifications, serial numbers, warranty information, shipment references and related correspondence. We receive delivery updates and relevant business information from carriers, suppliers, manufacturers or your organisation where needed to fulfil the purchase. We do not collect payment-card details through the current website forms.
Technical information is generated when your browser connects to the site, including IP address, request time, requested page, browser information, referring page and response status. If a colleague or business partner supplies your contact details, we use them for the relevant business matter and provide privacy information as required. We do not obtain contact lists for unrelated use merely because you make an enquiry.
Purposes and lawful bases
We use enquiry and purchase information to prepare quotations, discuss configurations, accept and fulfil orders, arrange delivery, issue invoices and provide warranty or support. For an individual purchasing or taking steps to purchase, the basis is performance of a contract or pre-contractual steps under Article 6(1)(b) GDPR, where that basis applies.
For representatives of business customers, suppliers and partners, we normally rely on legitimate interests under Article 6(1)(f): conducting relevant business correspondence, sourcing and supplying equipment, administering commercial relationships and resolving issues. We also rely on legitimate interests for proportionate security, fraud prevention and legal-claim management, balancing these purposes against individuals’ rights and expectations.
We rely on legal obligation under Article 6(1)(c) for records or disclosures required by applicable tax, accounting, trade-control or other law. Where consent is needed for an optional activity, we request it separately and explain how to withdraw it. Sending a form or accepting purchase terms is not blanket consent to every use of your information.
Browsing, hosting and website security
Our hosting and infrastructure service providers process the connection information needed to deliver the website, maintain it and protect it against misuse. We also use a network security and content-delivery service to filter malicious traffic and serve pages. These providers may process IP addresses, request metadata and security events as part of their services.
Website access logs help us investigate faults, suspicious activity and unsuccessful requests. The web server rotates access logs at 10 MiB, retaining up to five rotated files with a seven-day age limit. This is a rotation policy rather than a promise that every active-log entry is deleted within seven days; an active file can contain older entries until rotation.
We do not currently load advertising pixels, optional visitor analytics or embedded social feeds. Product and article images and website fonts are served with the site.
Cookies and browser storage
The equipment basket, comparison selection and quotation equipment list use browser session storage for product identifiers and quantities. These selections remain on your device and are not a customer account. Session storage normally lasts for the browser session, although browser restoration can preserve it. Contact details and message contents are not saved in these selection lists.
Private staff administration uses a secure session cookie for authenticated access, with an eight-hour maximum and a 30-minute inactivity limit. This is for staff access only; public order tracking does not require a customer account or customer sign-in cookie. Security services may also use strictly necessary security storage when they check a request.
You can clear browser site data to remove saved selections, which will also clear the basket or comparison list. Blocking storage may affect those functions. Google reCAPTCHA storage is described below. If optional analytics or marketing storage is introduced, we will update this notice and obtain any consent required before it is activated; continuing to browse is not treated as consent.
Enquiries and email correspondence
When you send a quotation, callback, contact, support or feedback request, we process the fields you submit and route the message to our business mailbox. Our transactional email delivery service, Resend, delivers these messages and the acknowledgement sent to the email address you supply. Google Workspace provides our business email service.
The acknowledgement contains a reference number and relevant request details so that you can continue the correspondence. Transactional delivery providers process recipient information, message content and delivery events. Our enquiry application does not retain submitted message bodies or contact fields in its delivery database; the delivered messages remain in the business mailbox under the retention criteria below.
We keep hashed delivery and abuse-prevention metadata for up to 48 hours in the enquiry application to limit duplicate sends and misuse. These records are distinct from email copies, security-provider records and order records. A failed delivery may require you to retry or contact us through another available route. We do not subscribe form users to marketing automatically.
Google reCAPTCHA
We use Google reCAPTCHA v3 when sending protected forms to assess whether a request is likely to be abusive. The current integration loads the reCAPTCHA service when the send check is requested. Google may process IP address, device and browser information and interaction signals, and may use cookies or other security storage for that assessment.
Our server verifies the result before forwarding the request. Automated risk checks may block or delay a submission; they do not decide whether you are entitled to purchase equipment, obtain credit or receive a warranty remedy. If a form is blocked, you can contact us by replying to an existing transaction email or using the privacy contact where relevant.
Google’s Privacy Policy and Terms of Service apply to its service. Links are provided beside the protected forms and below. We use the assessment for proportionate spam and fraud prevention, not as a website advertising tool. Any consent requirement applicable to non-essential access to your device remains a separate obligation from selecting a GDPR lawful basis.
Order and shipment administration
Our private administration system stores contact and delivery details, equipment lines, order status, shipment references, support notes and a record of administrative changes. Authorised staff use it to fulfil purchases, answer questions and provide after-sales service. An order may have several consignments, each with its own carrier information and delivery updates.
When we send an order update, it may include the order reference, purchased equipment, status and shipment details. Internal administrative notes are excluded from customer update emails. A carrier tracking link takes you to the carrier’s service, which processes the information you provide and your connection details under its own privacy notice.
The current public Order Tracking page explains how to use shipment references; it does not expose our private order database. Our support forms deliver requests to our team by email. A separate customer helpdesk or ticketing platform is not currently connected, and will be disclosed if introduced.
Who receives personal information
We share information on a need-to-know basis with website hosting and infrastructure providers, network security providers, business email and transactional email providers, and authorised people supporting our operations. They receive only the information relevant to their role. Where they act as processors, applicable data-processing terms and instructions govern their use.
For a purchase, relevant information may also go to carriers and fulfilment providers, equipment suppliers or manufacturers for allocation, delivery, serial-number registration or warranty handling. Accountants, legal advisers, auditors, banks and public authorities may receive information where necessary for payment administration, professional advice, compliance or a legal obligation.
We do not sell personal information or disclose enquiry lists for unrelated third-party advertising. We do not send a financing application to a lender merely because you browse the Financing page. If a transaction requires a new recipient or a different purpose, we will provide appropriate information and obtain consent where necessary before sharing.
International processing and safeguards
Our business and service providers operate internationally. Personal information may be processed in the United Kingdom, the European Economic Area and other countries, including the United States, depending on the relevant email, security or other service. Processing is not represented as confined to Germany or the EEA, and a server location alone does not determine every place from which data can be accessed.
Where a restricted international transfer takes place, the applicable framework must be identified: a valid adequacy decision where it covers the recipient and transfer, or appropriate contractual safeguards such as the EU standard contractual clauses and the relevant UK transfer mechanism, with additional measures where required. We do not assume that every provider or transfer qualifies for the same mechanism.
Contact us for recipient-specific transfer information and a copy or description of the applicable safeguards, subject to lawful redaction. The assessment and documentation of our current provider transfer arrangements are being completed.
How long we retain information
We retain enquiries and correspondence while needed to respond, follow up a relevant request and maintain the commercial record. If an enquiry does not lead to a purchase, the criteria are its ongoing relevance, the last substantive contact and any legitimate need to resolve an issue. We do not keep an enquiry indefinitely simply because it was submitted.
Order, invoice, delivery and warranty records are retained for fulfilment, the applicable warranty and support period, and any further period required by tax, accounting or limitation rules affecting the transaction. A live dispute or legal hold may justify retaining relevant material longer. The applicable period depends on the seller’s final registration and the record type; our detailed schedule is being completed.
Enquiry delivery metadata is removed within 48 hours as described above. Website logs follow the rotation policy stated above. Provider-held security and delivery records follow the applicable provider settings and contracts, whose retention details are being confirmed. Operational backups are kept on a rolling basis for recovery; deleting a live record may not immediately remove a protected backup copy.
Keeping information secure
We use proportionate technical and organisational measures, including encrypted website connections, restricted administrative access, staff authentication, access controls and recovery backups. Access to the private order system requires staff credentials and a second authentication factor.
People handling customer records should access them only for authorised purposes and share them only through appropriate channels. If a personal-data breach occurs, we will assess it and notify the relevant authority and affected individuals where the applicable legal thresholds require notification.
Your data-protection rights
Depending on the legal basis and circumstances, you may request access to your personal information and a copy of it; correction of inaccurate information; erasure; restriction of processing; or transfer of qualifying information in a portable format. These rights have conditions and exceptions, including where records must be retained by law or are needed for a legal claim.
Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. We will explain a simple withdrawal route when requesting consent. A withdrawal does not necessarily require deletion of information that we must retain on a separate valid basis, which we will explain if relevant.
Send requests through our Contact page or to [email protected]. We may ask for proportionate information to verify identity or clarify the request where necessary. We normally respond within one month under applicable GDPR rules; a permitted extension for complexity or volume will be explained within that period. Requests are normally free, subject to the limited exceptions allowed by law.
Your right to object
You can object, for reasons relating to your particular situation, to processing based on legitimate interests. We will stop that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is necessary for legal claims. Tell us which activity concerns you so that we can assess the objection properly.
You can object to direct marketing at any time, including related profiling, without giving a reason. We will stop using your information for that purpose. We may keep a minimal suppression record to ensure that the objection continues to be respected, rather than deleting the preference and accidentally contacting you again.
Complaints and supervisory authorities
You may complain to the Sächsische Datenschutz- und Transparenzbeauftragte at www.datenschutz.sachsen.de, or to the competent data-protection authority where you live, work or believe an infringement occurred.
You do not have to contact us before making a complaint. Your right to complain or seek a judicial remedy remains unaffected.
Required information and automated checks
You can browse without sending an enquiry. If you request a quotation or purchase, we need sufficient contact, equipment and delivery information to respond or perform the contract. Missing required information may prevent us from handling the request or completing the purchase. Information required by law, such as certain invoicing or end-user details, will be identified when requested.
We do not currently make solely automated decisions with legal or similarly significant effects about purchase eligibility or credit. Form-security checks assess spam risk, and a staff member can address a blocked enquiry through an alternative route. If a future service introduces qualifying automated decision-making or profiling, we will explain it and the applicable rights before it is used.
External links and younger visitors
Manufacturer documents, carrier pages and other external links lead to independently operated services. Their privacy notices govern their own collection of information. Simply displaying a link does not transmit a form submission to that site; visiting it establishes a separate connection. Our current product images and article images are served with our website.
Our equipment and services are directed to business purchasers and adults. We do not knowingly seek personal information from children for marketing. If you believe a child has supplied information that should be removed, contact us so that we can assess and address the request.
Changes to this notice
The edition date identifies the current notice. We will update it when the way we collect or use information materially changes, and provide additional notice where required. A revised notice does not retrospectively authorise an incompatible use of information or remove a consent or other legal requirement that applies to a new purpose.