1. Controller
The controller responsible for data processing on this website is:
Martin Obrecht
Schützenstraße 58, 76135 Karlsruhe, Germany
Email: [Email]
2. General information on data processing
We only process personal data to the extent necessary to provide this website, process inquiries, carry out pre-contractual measures and contracts, or where consent has been given.
- Art. 6(1)(b) GDPR – initiation/performance of a contract (e.g. quotation, project inquiry)
- Art. 6(1)(f) GDPR – legitimate interest (e.g. security/error analysis)
- Art. 6(1)(a) GDPR – consent (e.g. analytics/marketing)
- Art. 6(1)(c) GDPR – legal obligation (e.g. retention obligations)
3. Hosting
This website is hosted by IONOS Germany. The hosting provider processes personal data (in particular IP address and log data) to the extent required to provide the website.
4. Server log files (provision of the website)
When our website is accessed, the server automatically collects information and stores it in log files, for example:
- IP address (possibly shortened)
- Date and time of the request
- Requested page/file
- Referrer URL
- Browser/operating system (user agent)
- Status codes/error codes
Purpose: Operation, security (e.g. defense against attacks), error analysis and stability.
Legal basis: Art. 6(1)(f) GDPR.
Storage duration: 60 days, then deletion.
5. Contact (email / contact form)
If you contact us (e.g. by email or via a form), we process the data you provide (e.g. name, company, email, optional phone number, message) in order to handle your inquiry.
Purpose: Handling the inquiry, preparing offers, communication.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR.
Storage duration: Until the processing is completed, then 6 months unless obligations require otherwise.
6. Excel upload / file upload (optional)
If you upload a file (e.g. Excel/CSV), we process the contents of the file as well as accompanying metadata (e.g. file name, upload time) in order to carry out the Excel check or the requested service.
Notice: Please only upload files you are allowed to upload and remove unnecessary personal data whenever possible. Do not include passwords/keys in plain text.
Purpose: Analysis/initial assessment (“Excel check”), preparation of an offer, and if applicable project execution.
Legal basis: Art. 6(1)(b) GDPR.
Storage duration (Excel check): 30 days after completion, then deletion.
Storage duration (project): /12 months after project completion or according to agreement.
7. Appointment booking
If you book an appointment via a scheduling tool, the entered data (e.g. name, email, appointment time, optional notes) is processed for appointment organization.
Purpose: Appointment management, communication.
Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
8. Cookies & consent management
We use cookies and similar technologies. Technically necessary cookies are required for the operation of the website. For non-essential cookies (e.g. audience measurement/marketing), we obtain prior consent.
You can change or withdraw your consent at any time.
9. Web analytics / tracking
If we use web analytics, we list the provider, data categories and storage duration here.
Tool: Google Analytics
Processed data: Shortened IP, usage data, device information, referrer
Purpose: Audience measurement, improvement of the website
Legal basis: Art. 6(1)(a) GDPR (consent)
Storage duration: 14 months
If you do not use tracking: remove this section.
10. Recipients / disclosure of data
We only disclose personal data if this is necessary (e.g. hosting, email provider, appointment tool) or if you have given consent. Recipients may be processors (Art. 28 GDPR) or independent controllers.
11. Transfers to third countries
If we use services whose providers are located outside the EU/EEA or process data there, a transfer only takes place if the requirements of the GDPR are met (e.g. adequacy decision or standard contractual clauses). We provide details for the respective service where relevant.
12. General storage duration
Unless a more specific storage period is stated in this privacy policy, we only process personal data for as long as necessary for the purposes or as long as statutory retention obligations apply.
13. Your rights
Depending on the requirements, you have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
14. Competent supervisory authority (Baden-Württemberg)
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Heilbronner Straße 35, 70191 Stuttgart
P.O. Box 10 29 32, 70025 Stuttgart
Phone: 0711 615541-0
Email: poststelle@lfdi.bwl.de
15. Security
We implement technical and organizational measures to protect your data against loss, manipulation and unauthorized access. However, complete security for data transmission on the internet cannot be guaranteed.
16. Changes to this privacy policy
We may update this privacy policy if the legal situation, the website or the services used change. The current version is available on this website.