Privacy Policy
Last updated: August 2026
This policy explains which personal data we process when you visit this website, for what purpose and on what legal basis. You can use this website without providing any personal information. We only process personal data where it is technically necessary to operate the site, or where you choose to contact us.
1. Controller
The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Flaiz und Eger IT Consulting GbR
Partners: Simon Flaiz, Marcel Eger
Hohenzollernstraße 15
72415 Grosselfingen
Germany
Phone: +49 151 61501208
Email: kontakt@fe-itconsulting.com
We are not required to appoint a data protection officer (Art. 37 GDPR, Sec. 38 BDSG). For any question regarding data protection, please contact us directly using the details above.
2. Principles
We only collect the data required for the respective purpose, and we do not keep it longer than necessary. We do not sell data and do not pass it on to third parties for advertising purposes. Data is shared only with the service providers named in this policy, who act as our processors, and where we are legally obliged to do so. The website is served exclusively over an encrypted connection (TLS/HTTPS). You can recognise this by the padlock symbol in your browser address bar.
3. Hosting and server logs
The creation, technical operation and hosting of this website have been assigned to HaiSoTec GmbH, which acts as our processor pursuant to Art. 28 GDPR. The hosting itself runs on Firebase Hosting, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you open a page, data your browser transmits is recorded automatically. It is technically required to deliver the page:
- IP addressrequired so the requested page can be sent back to your device
- date and time of accesstraceability and troubleshooting
- requested address and volume of data transferredoperation and troubleshooting
- browser type, browser version and operating systemcorrect rendering across different devices
This data is not merged with other data sources and is not used to identify you as a person. It is not evaluated for marketing purposes. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the technically sound and secure operation of the website. We have concluded a data processing agreement with HaiSoTec GmbH pursuant to Art. 28 GDPR. HaiSoTec engages Google as a sub-processor (Art. 28(4) GDPR). Transfer to the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission issued an adequacy decision on 10 July 2023.
4. Cookies, local storage and your consent
This website sets NO cookies — neither before nor after any decision on your part, neither for analytics nor for advertising. Measured in the browser: after visiting every page, not a single cookie is present. Only the following four entries are stored in your browser's local storage:
- localeyour language choice, so the site does not fall back to German on your next visit. This entry is created on your very first visit and records which language version you opened.
- themewhether you selected the light or the dark appearance. Created only once you switch.
- einwilligungyour decision from the consent dialog, so that we can honour it without asking again on every visit. Created only once you decide.
- einwilligung-ida randomly generated identifier under which your decision is recorded. It contains no information about you and is likewise created only once you decide. Section 5 explains what it is for.
The legal basis for `locale` and `theme` is § 25 (2) no. 2 TDDDG: they are strictly necessary to provide the service you explicitly requested — display in your language and your chosen appearance. Storing your consent decision is permitted for the same reason: without it your choice could not be honoured. The consent dialog lets you decide whether the map on the contact page may load (section 8). The language setting and the contact form's spam protection (section 7) cannot be switched off — without them you could not submit the form. A "Statistics" category is visible in the dialog but has no content: no analytics tool is currently in use. You can change your decision at any time via "Privacy settings" at the bottom of every page. You can also delete these entries at any time through your browser settings. The website remains fully usable afterwards; it simply starts again with the default settings.
5. Record of your consent
When you make a decision in the consent dialog — whichever it is — we record that decision. Under Art. 7 (1) GDPR we are required to be able to demonstrate that consent was given. The following is stored:
- Timestampwhen you made your decision
- Truncated IP addressyour IP address WITHOUT the final segment, e.g. 84.132.19.0 instead of 84.132.19.57. The complete address is never stored.
- Your selectionwhich categories you allowed and which you declined
- Version of the textwhich version of the consent text was shown to you at the time
- A random identifiera randomly generated string stored in your browser. It contains no information about you and serves only to match a later change of the same decision.
The legal basis is Art. 6 (1) (c) GDPR in conjunction with Art. 7 (1) GDPR: the storage fulfils our obligation to demonstrate consent. The data is stored in Google Cloud Firestore in the europe-west3 region (Frankfurt am Main, Germany) and is deleted automatically after three years. That period matches the standard limitation period (§ 195 German Civil Code) within which the record might be needed. Access to this data from the browser is technically impossible; it is written exclusively server-side. We state this explicitly: a truncated IP address is not anonymous. The link to an individual is considerably weakened but not entirely removed. If you would rather avoid this, simply make no decision in the consent dialog — the website remains fully usable, and the map on the contact page can still be loaded individually.
6. Contact form and enquiries
When you write to us using the contact form, we process the details you enter:
- name and email address (required)so we know who is writing and can reply
- your message (required)the content of your enquiry
- company and phone number (optional)only if you provide them — for a call back, for instance
Your enquiry is not stored in a database. It is passed to our mail delivery provider through a processing function in the Frankfurt am Main data centre (Google Cloud Functions, region europe-west3) and delivered from there by email to kontakt@fe-itconsulting.com. After that it resides solely in our mailbox. Delivery is handled on our behalf by HaiSoTec GmbH as a processor pursuant to Art. 28 GDPR. The sender shown is an address belonging to that provider; your email address is set as the reply address so that our answer reaches you directly. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to entering into or performing a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries. Providing the required fields is not a statutory obligation; without them, however, we cannot process your enquiry. We retain your enquiry for as long as needed to handle it. If no business relationship results, we delete the correspondence after two years at the latest. If a contractual relationship arises, the statutory retention periods apply (see section 11). The same applies accordingly if you contact us directly by email or by phone.
7. Protecting the contact form (Google reCAPTCHA)
To prevent our contact form from being abused by automated systems for advertising and spam, we use reCAPTCHA provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA checks whether an entry comes from a human or from a program. In doing so, your IP address, information about your browser and device, and your interaction with the form are transmitted to Google and evaluated there.
reCAPTCHA is only loaded once you actually use the contact form — that is, as soon as you click into a field or type something. If you merely view the page, no connection to Google is established.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our contact form against abuse and keeping it operational. Transfer to the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework. Details on processing by Google are available at https://policies.google.com/privacy. If you would prefer to avoid the transfer to Google, you can reach us equally well by phone or email using the contact details in section 1. You will not be disadvantaged by doing so.
8. Map display (Google Maps)
On our contact page you can display our location on a map from Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The map does not load automatically. If you allowed the "Functional" category in the consent dialog, it appears immediately; otherwise you will first see only a placeholder and can load the map individually with one click. Only then is it fetched, transmitting your IP address to Google. Without your consent or that click, no transmission takes place.
The legal basis is your consent under Art. 6 (1) (a) GDPR — given either in the consent dialog or by clicking the placeholder. Consent given in the dialog is stored and applies until withdrawn; clicking the placeholder applies only to the current visit. You can withdraw it at any time via "Privacy settings" at the bottom of every page. Transfer to the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework. Details at https://policies.google.com/privacy.
9. Fonts
The fonts used on this website are served from our own server. Loading them establishes no connection to servers operated by Google or any other provider, and no IP address is transmitted to third parties.
10. Social networks
We do not embed any social network content, buttons or tracking pixels on this website. Our legal notice contains a plain reference to our Instagram profile. This is an ordinary link: as long as you do not click it, no data is transmitted to the provider. If you do click it, you leave this website; from that point onwards the privacy policy of Meta Platforms Ireland Limited applies.
11. Retention periods
We delete personal data as soon as the purpose of processing no longer applies and no statutory retention obligation stands in the way. Statutory retention periods arise in particular from the German Commercial Code and the Fiscal Code and are generally six or ten years. While such a period is running, processing of the affected data is restricted: it is retained but not used further.
12. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)You can find out whether and which data we process about you, for what purpose and for how long.
- Rectification (Art. 16 GDPR)If your data is inaccurate or incomplete, you can request its correction or completion.
- Erasure (Art. 17 GDPR)You can request the deletion of your data, provided no statutory retention obligation stands in the way.
- Restriction of processing (Art. 18 GDPR)You can request that we only retain your data for the time being and no longer use it.
- Data portability (Art. 20 GDPR)You can receive the data you provided to us in a common electronic format.
- Objection (Art. 21 GDPR)You can object to processing that we base on a legitimate interest — for example the evaluation of server logs.
- Withdrawal of consent (Art. 7(3) GDPR)You can withdraw consent at any time with effect for the future. Processing carried out up to that point remains lawful.
- Complaint to a supervisory authority (Art. 77 GDPR)You can lodge a complaint with a data protection supervisory authority at any time, in particular in the EU member state of your residence, your place of work or the alleged infringement.
An informal message to the contact details in section 1 is sufficient to exercise your rights. The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany
https://www.baden-wuerttemberg.datenschutz.de
13. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
This expressly includes the spam check on the contact form: the reCAPTCHA assessment does not cause your enquiry to be rejected automatically. How an enquiry is handled is always decided by a person.
14. Changes to this policy
We update this privacy policy when the processing described here changes or when the legal situation requires it. The version published on this page is the one that applies.