Privacy Policy
Maas Real Estate GmbH
Last updated: July 2026
1. Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit our website or are in business contact with us. Personal data is any data by which you can be personally identified. For detailed information on data protection, please refer to the privacy policy set out below this text.
Data collection on this website
Who is responsible for data collection on this website? Data processing on this website is carried out by the website operator. The operator's contact details can be found in the section "Controller" in this privacy policy.
How do we collect your data? On the one hand, your data is collected when you provide it to us. This may, for example, be data you enter into a contact form or send to us by email or telephone. Other data is collected automatically, or after your consent, by our IT systems when you visit the website (e.g. internet browser, operating system or time of the page view).
What do we use your data for? Part of the data is collected to ensure the error-free provision of the website. Other data may be used to analyse your user behaviour and to initiate, process and maintain business relationships.
What rights do you have regarding your data? You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
2. Controller
The controller responsible for data processing on this website and within the scope of our business activities is:
Maas Real Estate GmbH
Bremer Str. 42, 48155 Münster, Germany
Represented by the managing partners: Lennard Maas, Christoph Ehler
Phone: (+49) 251 5904 859 0
Email: info@maasrealestate.com
Commercial register: Amtsgericht Münster, HRB 21073
VAT identification number: DE361907864
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
3. General information and mandatory disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. We point out that data transmission on the internet (e.g. when communicating by email) may be subject to security gaps. Complete protection of data against access by third parties is not possible.
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the deletion takes place after these reasons cease to apply.
Legal bases for data processing
If you have consented to data processing, we process your personal data on the basis of Art. 6 (1) lit. a GDPR or Art. 9 (2) lit. a GDPR. In the case of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 (1) lit. a GDPR. If the processing is necessary for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6 (1) lit. b GDPR. Processing for compliance with a legal obligation is carried out on the basis of Art. 6 (1) lit. c GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 (1) lit. f GDPR.
Recipients of personal data
In the course of our business activities, we work together with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only pass on personal data to external parties if this is necessary in the context of contract performance, if we are legally obliged to do so, if we have a legitimate interest in the transfer or if another legal basis permits the data transfer. When using processors, we only pass on our customers' personal data on the basis of a valid data processing agreement.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection (Art. 21 GDPR)
If data processing is carried out on the basis of Art. 6 (1) lit. e or f GDPR, you have the right at any time to object to the processing of your personal data on grounds relating to your particular situation; this also applies to profiling based on these provisions. If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. For Maas Real Estate GmbH, the competent authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen).
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place to the extent that it is technically feasible.
Information, correction and deletion
Within the scope of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction or deletion of this data. You can contact us at any time for this purpose and for further questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the cases specified in Art. 18 GDPR.
SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, such as enquiries you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
4. Data collection on this website
Cookies
Our website partly uses so-called cookies. Cookies are small text files and do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Cookies that are required to carry out the electronic communication process, to provide certain functions you have requested or to optimise the website are stored on the basis of Art. 6 (1) lit. f GDPR, unless another legal basis is specified. If consent to the storage of cookies and comparable recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 (1) lit. a GDPR and Section 25 (1) TDDDG); consent can be revoked at any time. You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address
This data is not merged with other data sources. This data is collected on the basis of Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website; for this purpose, the server log files must be collected.
Contact (form, email, telephone)
If you contact us by contact form, email or telephone, your enquiry including all resulting personal data (name, enquiry, contact details) will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent. This data is processed on the basis of Art. 6 (1) lit. b GDPR if your enquiry is related to the performance of a contract or is necessary for carrying out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6 (1) lit. f GDPR) or on your consent (Art. 6 (1) lit. a GDPR) if this has been requested. The data you send to us remains with us until you request its deletion, revoke your consent to storage or the purpose for the data storage no longer applies.
Web analytics with Cloudflare Web Analytics
For the statistical evaluation of visitor access to our website, we use "Cloudflare Web Analytics", a service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare Web Analytics works without cookies and without storing unique identifiers (fingerprinting). No personal data such as IP addresses is stored permanently or used to recognise individual visitors. Only aggregated, anonymous usage data is collected, such as the number of page views, pages accessed, origin of the visits (referrer), browser and device type used and the approximate country of origin. It is not possible for us to draw conclusions about individual persons.
The use of this service is based on our legitimate interest in a statistical, privacy-friendly analysis of user behaviour to optimise our web offering (Art. 6 (1) lit. f GDPR). As Cloudflare Web Analytics does not set cookies and does not process personal data for recognition purposes, no separate consent (cookie banner) is required. Further information on data protection at Cloudflare can be found at https://www.cloudflare.com/privacypolicy/. Insofar as data is transferred to the USA, Cloudflare bases this on the standard contractual clauses of the EU Commission and on certification under the EU-U.S. Data Privacy Framework.
5. Customer data and business relationships (CRM)
Processing of prospect and customer data
For the initiation, performance and maintenance of business relationships, in particular in the areas of investment management, consulting and development as well as subsidy consulting, we process personal data of prospects, customers, business partners and their contact persons. This includes in particular name, function, company affiliation, contact details (email, telephone, address), correspondence and information on projects and investment interests. The legal basis is Art. 6 (1) lit. b GDPR (contract / pre-contractual measures) and Art. 6 (1) lit. f GDPR (legitimate interest in maintaining business relationships and in approaching potential business partners).
Use of HubSpot (CRM)
To manage our customer and prospect contacts and to organise our sales and marketing processes, we use the customer relationship management system "HubSpot". The provider is HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland (parent company: HubSpot, Inc., USA). In HubSpot, we store and process the contact and communication data of the persons in contact with us (e.g. name, company, email address, telephone number, correspondence history, interactions with our emails and content). The use of HubSpot serves the efficient organisation and documentation of our business relationships and needs-based communication.
The processing is carried out on the basis of Art. 6 (1) lit. b GDPR (initiation and performance of contracts) and Art. 6 (1) lit. f GDPR (legitimate interest in efficient customer management). Where consent has been requested, for example for tracking or marketing measures, the processing is carried out on the basis of Art. 6 (1) lit. a GDPR. We have concluded a data processing agreement (DPA) with HubSpot in accordance with Art. 28 GDPR. Data transfers to the USA are based on the standard contractual clauses of the EU Commission and the EU-U.S. Data Privacy Framework. Further information can be found in HubSpot's privacy policy at https://legal.hubspot.com/privacy-policy.
Email communication and marketing
If we send you information by email in the context of existing or initiated business relationships, this is done on the basis of your consent (Art. 6 (1) lit. a GDPR) or our legitimate interest in direct communication in a business context (Art. 6 (1) lit. f GDPR, where applicable in conjunction with Section 7 UWG). You can object to receiving such messages at any time without incurring any costs other than the transmission costs according to the basic rates. Every marketing email contains an unsubscribe link.
6. Social media
We maintain a company profile on the professional network LinkedIn and use LinkedIn for external communication, establishing contacts and approaching potential business partners. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (parent company: LinkedIn Corporation, USA). When you interact with our LinkedIn presence (e.g. follow our profile, comment on posts, send us a message or accept a contact request), LinkedIn processes your personal data. For the processing carried out by LinkedIn in connection with the operation of our company page, LinkedIn and we are joint controllers within the meaning of Art. 26 GDPR.
Insofar as we use LinkedIn (including LinkedIn Sales Navigator and InMail) for the targeted approach of professional contacts and potential business partners, we process professional data (name, position, company, publicly visible profile information). The legal basis is our legitimate interest in establishing business contacts and maintaining our network (Art. 6 (1) lit. f GDPR). Where consent is required for interactions, the processing is carried out on the basis of Art. 6 (1) lit. a GDPR. Data transfers to the USA are based on the standard contractual clauses and the EU-U.S. Data Privacy Framework. Details on data processing by LinkedIn can be found in LinkedIn's privacy policy at https://www.linkedin.com/legal/privacy-policy. You can assert your rights as a data subject (information, deletion, etc.) both against us and against LinkedIn.
7. Data transfers to third countries
Some of the services we use (e.g. HubSpot, LinkedIn) have parent companies or servers in the USA or other third countries. Personal data is only transferred to third countries if an adequate level of data protection is guaranteed. Where no adequacy decision of the EU Commission exists, we base such transfers on the standard contractual clauses of the European Commission, on certification under the EU-U.S. Data Privacy Framework or on your express consent (Art. 49 (1) lit. a GDPR).
8. Your rights at a glance
As a data subject, you have in particular the following rights under the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to revoke consent given (Art. 7 (3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise these rights, an informal message to the controller named above is sufficient.