Privacy Policy
Note: The German version of this privacy policy is legally binding.
Controller Information
Controller within the meaning of the GDPR:
A Data Protection Officer has not been appointed. For data protection inquiries, please use the contact details above.
Maximum Data Protection as a Principle
We follow the principle of data minimisation (Art. 5(1)(c) GDPR) and only collect what is technically indispensable.
- No cookies or comparable technologies requiring consent under Sec. 25 TDDDG.
- No tracking, no analytics tools (e.g. Google Analytics, Matomo).
- No external content (e.g. Google Fonts, YouTube, Maps, Social Media).
- Encrypted transmission via HTTPS.
Handling of Contact Data
If you contact us by email or phone, we store your name, email/phone number, the content of your enquiry and any other data you provide.
Legal bases:
- Art. 6(1)(b) GDPR (contractual or pre-contractual enquiries)
- Art. 6(1)(f) GDPR (legitimate interest in efficient processing)
Storage period: until final response; in case of mandate establishment, 6-10 years (statutory retention obligations). No disclosure without consent except where legally required.
Note: Email may have security vulnerabilities.
Access Data (Server Log Files)
Based on our legitimate interest (Art. 6(1)(f) GDPR), we automatically log:
- Anonymised IP address
- Date and time
- Requested URL
- Referrer
- Browser and version
- Operating system
- Access provider
- HTTP status code
Storage period: max. 7 days (longer if needed for evidentiary purposes).
Rights of the Data Subject
You have the right to:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21)
- Withdrawal of consent (Art. 7(3))
- Complaint to a supervisory authority (Art. 77)
To exercise these rights, please contact us using the details in section Controller Information.
Recipients of Data
Data will only be disclosed to third parties if:
- You have given consent (Art. 6(1)(a) GDPR)
- A legal obligation exists (lit. c)
- It is necessary for contract performance (lit. b)
- We pursue a legitimate interest (lit. f) and no overriding interest of yours prevails
Processors: Hosting provider (see Access Data section).
Automated Decision-Making
No automated decision-making, including profiling (Art. 22 GDPR), takes place.
Data Security
We implement technical and organisational measures pursuant to Art. 32 GDPR, in particular SSL/TLS encryption, to protect your data against unauthorised access, loss or destruction.
Currency and Changes to This Privacy Policy
This policy is currently valid. Subject to change; the current version can always be found on our website.