Legal

Privacy Policy

Information on the processing of personal data on this website in accordance with the GDPR.

1. Controller

The controller responsible for data processing on this website is:

Martin Obrecht
Schützenstraße 58, 76135 Karlsruhe, Germany
Email: [Email]

2. General information on data processing

We only process personal data to the extent necessary to provide this website, process inquiries, carry out pre-contractual measures and contracts, or where consent has been given.

  • Art. 6(1)(b) GDPR initiation/performance of a contract (e.g. quotation, project inquiry)
  • Art. 6(1)(f) GDPR legitimate interest (e.g. security/error analysis)
  • Art. 6(1)(a) GDPR consent (e.g. analytics/marketing)
  • Art. 6(1)(c) GDPR legal obligation (e.g. retention obligations)

3. Hosting

This website is hosted by IONOS Germany. The hosting provider processes personal data (in particular IP address and log data) to the extent required to provide the website.

4. Server log files (provision of the website)

When our website is accessed, the server automatically collects information and stores it in log files, for example:

  • IP address (possibly shortened)
  • Date and time of the request
  • Requested page/file
  • Referrer URL
  • Browser/operating system (user agent)
  • Status codes/error codes

Purpose: Operation, security (e.g. defense against attacks), error analysis and stability.
Legal basis: Art. 6(1)(f) GDPR.
Storage duration: 60 days, then deletion.

5. Contact (email / contact form)

If you contact us (e.g. by email or via a form), we process the data you provide (e.g. name, company, email, optional phone number, message) in order to handle your inquiry.

Purpose: Handling the inquiry, preparing offers, communication.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR.
Storage duration: Until the processing is completed, then 6 months unless obligations require otherwise.

6. Excel upload / file upload (optional)

If you upload a file (e.g. Excel/CSV), we process the contents of the file as well as accompanying metadata (e.g. file name, upload time) in order to carry out the Excel check or the requested service.

Notice: Please only upload files you are allowed to upload and remove unnecessary personal data whenever possible. Do not include passwords/keys in plain text.

Purpose: Analysis/initial assessment (“Excel check”), preparation of an offer, and if applicable project execution.
Legal basis: Art. 6(1)(b) GDPR.
Storage duration (Excel check): 30 days after completion, then deletion.
Storage duration (project): /12 months after project completion or according to agreement.

7. Appointment booking

If you book an appointment via a scheduling tool, the entered data (e.g. name, email, appointment time, optional notes) is processed for appointment organization.

Purpose: Appointment management, communication.
Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.

8. Cookies & consent management

We use cookies and similar technologies. Technically necessary cookies are required for the operation of the website. For non-essential cookies (e.g. audience measurement/marketing), we obtain prior consent.

You can change or withdraw your consent at any time.

9. Web analytics / tracking

If we use web analytics, we list the provider, data categories and storage duration here.

Tool: Google Analytics
Processed data: Shortened IP, usage data, device information, referrer
Purpose: Audience measurement, improvement of the website
Legal basis: Art. 6(1)(a) GDPR (consent)
Storage duration: 14 months

If you do not use tracking: remove this section.

10. Recipients / disclosure of data

We only disclose personal data if this is necessary (e.g. hosting, email provider, appointment tool) or if you have given consent. Recipients may be processors (Art. 28 GDPR) or independent controllers.

11. Transfers to third countries

If we use services whose providers are located outside the EU/EEA or process data there, a transfer only takes place if the requirements of the GDPR are met (e.g. adequacy decision or standard contractual clauses). We provide details for the respective service where relevant.

12. General storage duration

Unless a more specific storage period is stated in this privacy policy, we only process personal data for as long as necessary for the purposes or as long as statutory retention obligations apply.

13. Your rights

Depending on the requirements, you have the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Withdrawal of consent (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

14. Competent supervisory authority (Baden-Württemberg)

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Heilbronner Straße 35, 70191 Stuttgart
P.O. Box 10 29 32, 70025 Stuttgart
Phone: 0711 615541-0
Email: poststelle@lfdi.bwl.de

15. Security

We implement technical and organizational measures to protect your data against loss, manipulation and unauthorized access. However, complete security for data transmission on the internet cannot be guaranteed.

16. Changes to this privacy policy

We may update this privacy policy if the legal situation, the website or the services used change. The current version is available on this website.

© 2026 Martin Obrecht · Privacy Policy