With the following privacy policy, we would like to inform you which types of your personal data (hereinafter also referred to briefly as “data”) we process, for which purposes, and to what extent.
The terms used are not gender‑specific.
Björn Ellebrecht
E-mail: imprint (punkt) nospam ]at[ technoartisan [dOt] de
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.
Below you will find an overview of the legal bases under the GDPR on which we process personal data. In addition to the provisions of the GDPR, national data protection provisions may apply in your or our country of residence or registered office.
In addition to the data protection regulations of the GDPR, national regulations apply in Germany, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). The BDSG contains specific provisions on the right of access, erasure, objection, the processing of special categories of data, and automated decision‑making including profiling.
We take appropriate technical and organizational measures in accordance with the statutory requirements, taking into account the state of the art, implementation costs and the nature, scope and purposes of processing, in order to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data. We also take into account the protection of personal data in the development or selection of hardware, software and procedures in accordance with the principle of data protection by design and by default.
TLS/SSL encryption (HTTPS)
To protect users’ data from unauthorized access, we use TLS/SSL encryption technology. If a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL.
In the course of our processing of personal data, it may happen that such data is transferred to other entities, companies, legally independent organizational units or persons. Recipients may include, for example, service providers commissioned with IT tasks or providers of services integrated into a website. In such cases, we comply with the statutory requirements and conclude appropriate contracts that serve to protect your data.
We delete personal data in accordance with the statutory provisions as soon as the underlying consents are revoked or there is no further legal basis for processing.
Exceptions apply where statutory obligations or specific interests require longer retention or archiving of the data. If several retention periods are indicated, the longest period is always decisive.
| Period | Applies to |
|---|---|
| 10 years | Books, records, annual financial statements, inventories, management reports, opening balance sheet (§ 147 AO, § 14b UStG, § 257 HGB) |
| 8 years | Accounting records such as invoices and cost receipts (§ 147 AO, § 257 HGB) |
| 6 years | Other business documents, received/sent commercial letters, tax‑relevant documents (§ 147 AO, § 257 HGB) |
| 3 years | Data for asserting warranty and damage claims (§§ 195, 199 BGB) |
Start of the period: If a period does not explicitly begin on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred.
As a data subject, you are entitled to various rights under the GDPR (Art. 15–21 GDPR):
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions to the user’s browser or device.
Provision on rented storage space
To provide our online offering, we use storage space, computing capacity and software of a server provider (web host). Legal basis: legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Collection of access data and log files
Access to our online offering is logged in the form of “server log files” (requested URL, date/time, amount of data transferred, browser type, operating system, IP address, etc.). Log file information is stored for a maximum of 30 days and then deleted or anonymized. Legal basis: legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
When contacting us (e.g. via contact form, e‑mail, telephone or social media), the information provided by the inquiring persons is processed insofar as this is necessary to respond to contact requests and any requested measures.
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (third‑party providers). Integration always requires that the third‑party providers process the users’ IP address.
Google Fonts (from the Google server)
Retrieval of fonts for technically secure, low‑maintenance and efficient use. The provider is informed of the user’s IP address so that the fonts can be provided in the browser. According to its own statements, Google does not use the information collected to create profiles of end users or to display targeted advertisements.
YouTube videos
Please check the content of our privacy policy on a regular basis. We will adapt the privacy policy as soon as changes in our data processing activities make this necessary. We will inform you when such changes require your cooperation (e.g. consent) or another individual notification.
Where we provide addresses and contact information of companies and organizations in this privacy policy, please note that such addresses may change over time and check the information before contacting them.
Insofar as terms are defined by law, their statutory definitions apply. The following explanations are primarily for understanding.
Quelle: https://www.e-recht24.de
Quelle: https://datenschutz-generator.de
Presence on social networks
We maintain online presences within social networks and process user data in order to communicate with users active there or to provide information.
We would like to point out that user data may be processed outside the territory of the European Union. User data is generally processed for market research and advertising purposes within social networks.
Services used
Instagram
Social network for photos and videos.
Facebook pages
The controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data of visitors to our Facebook page. Users may address requests for access or deletion directly to Facebook.
X (formerly Twitter)