1. Privacy at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data means any data that can be used to personally identify you. For detailed information on the subject of data protection, please read the policy below.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You will find how to contact the controller via the contact form.
How do we collect your data?
Some data is collected when you provide it to us, for example by entering information into a contact form.
Other data is collected automatically or with your consent when you visit the website. This includes mainly technical data
such as the browser, operating system, or the time of the page view. This data is collected automatically as soon as you enter the website.
What do we use your data for?
Part of the data is collected to ensure error-free provision of the website. Other data can be used to analyze your user behavior.
If contracts can be concluded or initiated via the website, transmitted data will also be processed for offers, orders, or other requests.
What rights do you have regarding your data?
You have the right to receive free information at any time about the origin, recipient, and purpose of your stored personal data.
You also have the right to request rectification or deletion of this data. If you have given consent to data processing,
you can withdraw this consent for the future. You also have the right to request restriction of processing under certain circumstances and
a right to lodge a complaint with the competent supervisory authority. You may contact us at any time about this or any other privacy questions.
Analytics and third-party tools
When visiting this website, your surfing behavior may be statistically evaluated. This happens mainly with analytics programs. Details can be found in this policy.
2. Hosting
We host the content of our website with the following provider:
Hetzner
Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
Details can be found in Hetzner’s privacy policy: hetzner.com/legal/privacy-policy/.
The use of Hetzner is based on Art. 6(1)(f) GDPR. We have a legitimate interest in a reliable presentation of our website. If consent has been requested, processing is based solely on Art. 6(1)(a) GDPR and Section 25(1) TDDDG where the consent includes storage of cookies or access to information on the user’s device, such as device fingerprinting. Consent can be withdrawn at any time.
3. General notes and mandatory information
Data protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this policy. When you use this website, various personal data is collected. This policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens. We point out that data transmission on the internet, for example when communicating by email, can have security gaps. Complete protection of data against access by third parties is not possible.
Controller
The controller responsible for data processing on this website can be reached via the contact form.
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
Storage period
Unless a more specific storage period is stated in this policy, your personal data remains with us until the purpose for processing no longer applies. If you make a justified request for deletion or withdraw consent, your data will be deleted unless we have other legally permissible reasons for storing it such as tax or commercial retention periods. In the latter case, deletion takes place after these reasons cease to apply.
Legal bases for data processing on this website
If you have consented to processing, we process your data on the basis of Art. 6(1)(a) GDPR and, if special categories of data under Art. 9(1) GDPR are processed, Art. 9(2)(a) GDPR. In the case of explicit consent to data transfer to third countries, processing is additionally based on Art. 49(1)(a) GDPR. If you consented to the storage of cookies or access to information on your device, processing is also based on Section 25(1) TDDDG. Consent can be withdrawn at any time. If your data is required for performance of a contract or pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. We also process your data where required to fulfill a legal obligation under Art. 6(1)(c) GDPR or based on our legitimate interests under Art. 6(1)(f) GDPR. The relevant legal basis in each individual case is explained in this policy.
Recipients of personal data
In the course of our business we work with various external parties. This can require the transfer of personal data. We only transfer personal data when necessary for contract performance, when we are legally obliged, when we have a legitimate interest under Art. 6(1)(f) GDPR, or when another legal basis permits the transfer. Where we use processors, we only transfer personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.
Withdrawal of your consent to processing
Many processing operations are only possible with your express consent. You can withdraw consent at any time. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to object to processing in specific cases and to direct marketing (Art. 21 GDPR)
If processing is based on Art. 6(1)(e) or 6(1)(f) GDPR, you have the right at any time to object to the processing of your personal data on grounds relating to your particular situation. This also applies to profiling based on these provisions. The respective legal basis for processing can be found in this policy. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
If your personal data is processed for direct marketing, you have the right at any time to object to the processing of personal data concerning you for such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will no longer be used for direct marketing.
Right to lodge a complaint with a supervisory authority
In the event of breaches of the GDPR, data subjects have a right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work, or place of the alleged infringement. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process on the basis of your consent or in fulfillment of a contract delivered to you or to a third party in a commonly used, machine-readable format. If you request direct transfer of the data to another controller, this will only be done where technically feasible.
Access, rectification, and deletion
Within the scope of applicable law, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, the purpose of processing, and, if applicable, a right to rectification or deletion. You can contact us at any time for this purpose and for further questions on the topic of personal data.
Right to restriction of processing
You have the right to request the restriction of processing of your personal data. You can contact us at any time to do so. The right to restriction applies in the following cases:
- If you contest the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of verification you have the right to request restriction of processing.
- If processing is unlawful, you may request restriction instead of deletion.
- If we no longer need your personal data, but you need it for the exercise, defense, or establishment of legal claims, you have the right to request restriction instead of deletion.
- If you have objected under Art. 21(1) GDPR, a balance must be struck between your interests and ours. As long as it is not clear whose interests prevail, you have the right to request restriction.
If processing has been restricted, this data may be processed apart from storage only with your consent or for the establishment, exercise, or defense of legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the EU or a member state.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or requests you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the browser address line switching from “http://” to “https://” and the lock icon in your browser line. With SSL or TLS encryption enabled, data you transmit to us cannot be read by third parties.
4. Data collection on this website
Server log files
The provider of the pages automatically collects and stores information in server log files which your browser automatically transmits to us. This includes:
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing device
- Time of the server request
- IP address
This data is not combined with other data sources. The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of the website, which requires the collection of server log files.
Request by email, phone, or fax
If you contact us by email, phone, or fax, your inquiry including all personal data resulting from it such as your name and inquiry will be stored and processed for the purpose of handling your request. We do not pass on this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR if your request is related to the performance of a contract or necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective processing of requests addressed to us under Art. 6(1)(f) GDPR or on your consent under Art. 6(1)(a) GDPR if requested. Consent can be withdrawn at any time.
Data you send to us via contact requests remains with us until you ask us to delete it, you withdraw your consent to storage, or the purpose for data storage no longer applies such as after completion of your request. Mandatory legal provisions such as statutory retention periods remain unaffected.
Source: e-recht24.de
5. Contact form
When you submit the contact form, we process the data you enter, currently name and message. For security, we also process a short-lived CSRF token and store minimal technical metadata such as timestamp and IP address in server logs to detect abuse.
Purpose handling your inquiry, operating and securing the contact endpoint, and preventing misuse. Legal basis Art. 6(1)(b) GDPR where the request relates to a contract or pre-contractual steps. Otherwise Art. 6(1)(f) GDPR, legitimate interests in effective request handling and service security.
Retention we retain contact requests until your matter is resolved. Server security logs are kept for up to 7 days, unless longer retention is required to investigate abuse or technical incidents.
You can reach the controller via the contact form.
7. Web analytics with Umami
We use Umami, a privacy-focused, cookie-less analytics tool, to measure reach and improve our website.
The provider is Umami Software. We self-host Umami on our own server at
analytics.rivalrytracker.com
. According to the provider, Umami does not use cookies and does not store personal data.
The data is aggregated and anonymized, users are not tracked across websites.
What data is processed? page URL, referrer URL, user agent, timestamp, approximate location on country level, and basic technical metadata. IP addresses are not stored in Umami.
Purpose website analytics in order to monitor stability, understand page usage, and improve content. Legal basis Art. 6(1)(f) GDPR. Legitimate interests: operation and optimization of the website.
No cookies, no device access Umami does not set cookies and does not access information stored on your device, therefore no consent banner is required for this analytics setup.
Further information: Umami documentation.