1. Overview of Data Protection

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to all data that can be used to personally identify you. Detailed information on data protection can be found in the Privacy Notice outlined below.

Data Collection on This Website

Who is responsible for data collection on this website?

The controller responsible for data processing on this website is identified in the section "Controller" in this Privacy Notice.

How is your data collected?

Your data is collected firstly when you provide it via this website, for example by entering information into a contact form.

Other data is collected automatically or after your consent when you visit the website through the IT systems used. This data includes technical details (e.g., browser, operating system, or the time of page access). The collection of this data occurs automatically when you access this website.

What is your data used for?

Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze user behavior. If contracts are made or initiated via the website, the transmitted data is also processed for contract offers, orders, or other inquiries.

What rights do you have regarding your data?

You have the right to obtain information about the origin, recipients, and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of this data. If you have given consent for data processing, you can revoke this consent at any time. Furthermore, under certain circumstances, you have the right to restrict the processing of your personal data. Additionally, you have the right to lodge a complaint with the competent supervisory authority.

You can contact the controller at any time with questions regarding data protection.

2. Hosting

The content of this website is hosted by the following provider:

External Hosting

This website is externally hosted. The personal data collected on this website is stored on the servers of the host provider(s). This may include, but is not limited to, IP addresses, contact inquiries, metadata, communication data, contract data, contact details, names, website visits, and other data generated via the website.

External hosting occurs for the purpose of fulfilling contracts with potential and existing customers of the controller (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of this online offering through a professional provider (Art. 6(1)(f) GDPR). If consent has been requested, processing is carried out solely on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, provided that consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting). Consent can be revoked at any time.

The hosting provider processes your data only to the extent necessary to fulfil its service obligations and follows the controller's instructions regarding this data.

The following hosting provider is used:

netcup GmbH
Daimlerstraße 25
D-76185 Karlsruhe

Data Processing Agreement

A data processing agreement (DPA) is in place with the above-mentioned provider. It ensures that personal data of visitors to this website is processed only in accordance with the controller's instructions and in compliance with the GDPR.

3. General Information and Mandatory Disclosures

Data Protection

The controller takes the protection of your personal data seriously. Your data is handled confidentially and in accordance with applicable data protection law and this Privacy Notice.

When you use this website, various personal data is collected. Personal data refers to data that can be used to personally identify you. This Privacy Notice explains what data is collected and how it is used. It also explains how and for what purpose this is done.

Please note that data transmission on the Internet (e.g., when communicating by email) can have security vulnerabilities. It is not possible to completely protect data from third-party access.

Controller

The controller responsible for data processing on this website is:

Tobias Köcher | CRM & Salesforce Solutions
c/o IP-Management #7607
Ludwig-Erhard-Straße 18
20459 Hamburg
Germany
Email: hi (at) tobiaskoecher (dot) de

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.

Storage Period

Unless a specific storage period is mentioned in this Privacy Notice, your personal data will remain with the controller until the purpose for data processing ceases. If you make a legitimate deletion request or revoke your consent for data processing, your data will be deleted unless other legally permissible reasons for storing your personal data exist (e.g., tax or commercial retention periods); in such cases, deletion will occur after these reasons no longer apply.

General Information on the Legal Basis for Data Processing on This Website

If you have given consent for data processing, the controller processes your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR if special categories of data according to Art. 9(1) GDPR are processed. In the case of explicit consent for the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49(1)(a) GDPR. If consent has been requested for the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing is also carried out on the basis of § 25(1) TDDDG. Consent can be revoked at any time. If your data is required to fulfill a contract or for pre-contractual measures, the controller processes your data on the basis of Art. 6(1)(b) GDPR. Furthermore, the controller processes your data if required to fulfill a legal obligation on the basis of Art. 6(1)(c) GDPR. Data processing may also be based on the legitimate interest of the controller pursuant to Art. 6(1)(f) GDPR. Information on the applicable legal basis for each case can be found in the following sections of this Privacy Notice.

Recipients of Personal Data

External service providers are used as part of the business activities. Personal data is disclosed only where this is necessary for the performance of a contract, required by law, based on a legitimate interest pursuant to Article 6(1)(f) GDPR or permitted by another legal basis. Service providers processing personal data on behalf of the controller are engaged on the basis of a valid data processing agreement.

Withdrawal of Consent

Where processing is based on consent, consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

Right to Object to Processing and Direct Marketing (Article 21 GDPR)

IF PERSONAL DATA IS PROCESSED ON THE BASIS OF ARTICLE 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA. THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. IF YOU OBJECT, THE PERSONAL DATA CONCERNED WILL NO LONGER BE PROCESSED UNLESS COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING CAN BE DEMONSTRATED WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.

WHERE PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO SUCH PROCESSING. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO DIRECT MARKETING. FOLLOWING AN OBJECTION, THE PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES.

Right to Lodge a Complaint

In the event of an infringement of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. This right is without prejudice to any other administrative or judicial remedy.

Right to Data Portability

You have the right to receive data that is processed automatically on the basis of your consent or in performance of a contract in a commonly used, machine-readable format, or to request its transmission to another controller where technically feasible.

Access, Rectification and Erasure

Within the framework of the applicable legal provisions, you have the right to obtain information about your stored personal data, its origin and recipients, the purpose of the processing and, where applicable, a right to rectification or erasure.

Right to Restriction of Processing

You have the right to request restriction of the processing of your personal data where the accuracy of the data is contested, the processing is unlawful and erasure is opposed, the data is no longer required but is needed for legal claims, or an objection pursuant to Article 21(1) GDPR is under review. Where processing has been restricted, the data may, apart from storage, be processed only with consent or for the establishment, exercise or defence of legal claims, the protection of the rights of another person, or important public-interest reasons.

SSL or TLS Encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to the controller. You can recognize an encrypted connection by the change in the browser's address bar from "http://" to "https://" and by the lock icon in your browser bar.

If SSL or TLS encryption is activated, the data you transmit to the controller cannot be read by third parties.

4. Data Collection on This Website

Server Log Files

The provider of these pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to the server. This information includes:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources.

The collection of this data is based on Art. 6(1)(f) GDPR. The controller has a legitimate interest in the technically error-free presentation and optimization of this website – for this purpose, the server log files must be collected.

Contact Form and Salesforce CRM

When the contact form is used, the information entered is transmitted to and stored in my Salesforce CRM. The data processed includes first name, last name, company where provided, email address and message. Where available, technical attribution data such as UTM parameters and the referring page is also transmitted.

The data is processed to review and respond to the inquiry, take steps prior to entering into a contract and maintain a traceable record of the communication.

The legal basis is Article 6(1)(b) GDPR where the inquiry relates to an existing or potential contractual relationship. In all other cases, processing is based on my legitimate interest in efficiently handling and documenting incoming inquiries pursuant to Article 6(1)(f) GDPR.

Salesforce is used as a CRM service provider and data processor. Recipients of the data may include Salesforce and subprocessors engaged by Salesforce. Processing outside the European Economic Area cannot be ruled out. Salesforce provides contractual and organisational safeguards, including a Data Processing Addendum, Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

Further information is available at https://www.salesforce.com/company/legal/privacy/ and https://www.salesforce.com/company/legal/trust-and-compliance-documentation/.

If an inquiry does not result in a working relationship, the related data will be deleted or anonymised no later than twelve months after the last contact, unless renewed communication, an ongoing business interest or statutory retention and evidentiary obligations require continued storage. If a contractual relationship is established, the applicable statutory retention periods apply.

The data will not be used for unsolicited marketing without a separate legal basis.

5. Plugins and Tools

Google Fonts (Local Hosting)

This site uses so-called Google Fonts, provided by Google, for the uniform display of fonts. The Google Fonts are installed locally. No connection to Google's servers occurs in this process.

For more information about Google Fonts, visit https://developers.google.com/fonts/faq and Google's Privacy Notice: https://policies.google.com/privacy?hl=en.

Google reCAPTCHA

Google reCAPTCHA (hereinafter “reCAPTCHA”) is used on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

reCAPTCHA is used to verify whether the data entered on this website (e.g., in a contact form) is entered by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. reCAPTCHA evaluates various information for the analysis (e.g., IP address, length of time the website visitor stays on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google. The reCAPTCHA analyses run completely in the background. Website visitors are not notified that an analysis is taking place. The storage and analysis of the data is based on Article 6(1)(f) GDPR. The controller has a legitimate interest in protecting this online offering from abusive automated exploitation and from SPAM. If consent has been requested, processing will be carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time. For more information about Google reCAPTCHA, please refer to Google's Privacy Notice and Google's terms of use at the following links: https://policies.google.com/privacy?hl=en and https://policies.google.com/terms?hl=en.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the US that aims to ensure compliance with European data protection standards when processing data in the US. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.