Privacy Policy
Last updated: September 2, 2026
1. Controller
The controller responsible for processing personal data on this website is:
Timo Wevelsiep und Robin Zins GbR
Max-Liersch-Anger 13
59457 Werl
Germany
Email: [email protected]
2. Website Delivery, Hosting and Security
When you access this website, technically necessary connection data is processed. This may include your IP address, date and time, requested URL, referrer, browser and operating system information, and HTTP status. Processing is necessary to deliver the website securely and reliably. The legal basis is Art. 6(1)(f) GDPR and, where the visit serves pre-contractual purposes, Art. 6(1)(b) GDPR.
Hetzner
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We have entered into a data processing agreement with Hetzner. For further information, see the Hetzner privacy policy.
Cloudflare
We use services provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, to deliver and protect the website. Cloudflare processes connection and device data in particular to defend against attacks and abusive access. Processing is based on our legitimate interest in security and availability under Art. 6(1)(f) GDPR. Processing in the USA cannot be ruled out; Cloudflare relies on the applicable safeguards under Chapter V GDPR for such transfers. For details, see the Cloudflare privacy policy.
3. Audience Measurement with Umami
We operate Umami on our own servers in Germany to obtain aggregated statistics about use of this website. The data collected includes pages viewed, time of access, referrer, browser, operating system, device type, and approximate country of origin. Umami does not use analytics cookies or create cross-site profiles. Your IP address is transmitted as part of the technical connection but is not stored in plain text in the analytics data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is privacy-friendly audience measurement and improvement of our services.
4. Contact Requests and Appointment Booking
If you contact us by form or email, we process the information you provide to answer your request and any follow-up questions. Forms are processed through our automation services at automate.outacloud.com. Required fields are identified in each form.
For appointment scheduling, we link to Cal.eu, a service provided by Cal.com, Inc. A connection to Cal.eu is established only after you follow the link. Technical connection data and the information you enter in the booking dialog are then processed to organize the appointment. For further information, see the Cal.com privacy policy.
The legal basis is Art. 6(1)(b) GDPR where your request concerns a contract or pre-contractual steps. Otherwise, processing is based on Art. 6(1)(f) GDPR and our legitimate interest in handling business communications.
5. Spam Protection with Cloudflare Turnstile
Our forms use Cloudflare Turnstile to identify automated submissions and abuse. Cloudflare processes the necessary connection, browser, device, and interaction data and sends us a verification result. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is protecting our forms and systems. The Cloudflare information linked above also applies.
6. Cookies and Local Storage
We do not use marketing cookies. Technically necessary cookies or similar storage access may be used by security features. If you dismiss the notice about our study, that selection is stored locally in your browser. Such access is necessary to provide the functions you expressly request (Section 25(2)(2) TDDDG).
7. Retention
We retain personal data only for as long as necessary for its purpose. Inquiry data is deleted once processing is complete unless statutory retention duties or legitimate interests require continued storage. Security logs are deleted once they are no longer required for operations or investigating abuse.
8. Your Rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction of processing, data portability, and objection. You may also lodge a complaint with a data protection supervisory authority. The authority responsible for us is, in particular, the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
Please send privacy questions to [email protected].