Privacy Policy


As of: July 2026

Data Controller

Thomas Kötzing, Pfarrer-Reis-Str. 2, 91077 Hetzles, Germany
Email: Thomas@koetzingit.de Phone: 09134-8019745

A data protection officer has not been appointed by law, as the requirements for doing so (including § 38 BDSG) have not been met.

Overview of Processing Steps

The following overview summarizes the types of data processed and the purposes of such processing, and identifies the data subjects.

Types of data processed

  • Master data (e.g., names, addresses)
  • Contact information (e.g., email addresses, phone numbers)
  • Content data (e.g., form entries, comments)
  • Usage data (e.g., pages visited, access times, interest in content)
  • Meta data, communication data, and procedural data (e.g., IP addresses, timestamps, device identifiers)

Categories of data subjects

  • Communication Partners and Prospective Clients
  • Users of the online service (website visitors)

Purposes of Processing

  • Providing contractual services and responding to inquiries
  • Safety measures
  • Measuring Reach and Optimizing the Online Offering
  • Managing and Responding to Inquiries
  • Provision of the Online Service and User-Friendliness

Relevant legal basis

The following are the legal bases under the GDPR on which the processing of personal data is based. Please note that, in addition to the GDPR, national data protection regulations may apply. If more specific legal bases apply in individual cases, these will be specified in the Privacy Policy.

  • Consent (Art. 6(1)(a) of the GDPR) – the data subject has given consent to the processing.
  • Performance of a Contract and Pre-Contractual Inquiries (Art. 6(1)(b) of the GDPR).
  • Legal obligation (Art. 6(1)(c) of the GDPR).
  • Legitimate Interests (Art. 6(1)(f) of the GDPR) – unless the interests, fundamental rights, and fundamental freedoms of the data subject take precedence.

National Regulations in Germany: In addition, the Federal Data Protection Act (BDSG) and the Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (TDDDG). The TDDDG governs, in particular, the use of cookies and access to information on users’ end devices (e.g., for audience measurement, recognition, or embedded third-party content). Required consents are obtained via a cookie/consent dialog (§ 25(1) TDDDG). Technically necessary services are based on § 25(2) TDDDG.

Safety measures

In accordance with Article 32 of the GDPR, appropriate technical and organizational measures are taken to ensure a level of protection appropriate to the risk. These include, in particular, the encryption of data transmission via TLS/SSL (indicated by the „https“ prefix in the address bar) as well as the control of access to data.

Transfer of Personal Data

As part of the processing, data may be transferred to or disclosed to other entities, companies, or individuals (e.g., hosting service providers or payment service providers). The legal basis is Article 6(1)(b) of the GDPR, provided this is necessary for the performance of a contract; otherwise, it is based on legitimate interests or consent. Contracts with data processors are concluded in accordance with Article 28 of the GDPR.

International Data Transfers

If data is processed in a third country (outside the EU/EEA) or if this occurs in connection with the use of third-party services, it is done only in accordance with legal requirements.

For data transfers to the United States, we rely—where applicable—on the EU Commission’s adequacy decision regarding EU-U.S. Data Privacy Framework (DPF) as of July 10, 2023, provided that the respective provider is certified under the DPF. If a provider is not DPF-certified, the transmission is based on the Standard Contractual Clauses (SCC) the European Commission (Art. 46(2)(c) of the GDPR) and appropriate additional safeguards.

Deletion of Data

The processed data will be deleted as soon as the consents granted for its processing are revoked or other authorizations cease to apply (e.g., if the purpose of the processing no longer applies or the data is no longer necessary). Statutory retention requirements (particularly under commercial and tax law, generally 6 or 10 years) remain unaffected; processing will be restricted accordingly for this period.

Rights of data subjects

As a data subject under the GDPR, you have various rights:

  • Right to Object (Art. 21 of the GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data that is carried out pursuant to Article 6(1)(e) or (f) of the GDPR. If data is processed for direct marketing purposes, you may object at any time.
  • Right to Withdraw Consent (Art. 7(3) of the GDPR): You may revoke any consent you have given at any time, effective for the future.
  • Right of Access (Art. 15 of the GDPR).
  • Right to rectification (Art. 16 of the GDPR).
  • Right to erasure and restriction (Art. 17, 18 GDPR).
  • Right to Data Portability (Art. 20 of the GDPR).
  • Right to lodge a complaint with a supervisory authority (Art. 77 of the GDPR): You have the right to file a complaint with a supervisory authority. The competent authority for the data controller is: Bavarian State Office for Data Protection Supervision (BayLDA) Promenade 27, 91522 Ansbach https://www.lda.bayern.de

Use of Cookies

Cookies are small text files or other storage mechanisms that store and retrieve information on end devices. We use cookies in accordance with legal requirements.

  • Technically Necessary Cookies are used on the basis of Section 25(2) of the TDDDG or our legitimate interests (Article 6(1)(f) of the GDPR), to the extent that they are necessary for the operation of the website.
  • Cookies and Services Requiring Consent (e.g., audience measurement, embedded third-party content) are set exclusively on the basis of your consent (Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). We obtain this consent via a cookie consent dialog. You can change or revoke your selection at any time via the consent tool’s settings.

Provision of the Online Service and Web Hosting

To ensure that our online services are provided securely and efficiently, we use the services of a hosting provider. Among other things, this involves the processing of visitors’ inventory, contact, content, usage, metadata, and communication data.

Web hosting providers: STRATO GmbH. Registered office: Otto-Ostrowski-Straße 7, 10249 Berlin.
A data processing agreement has been entered into with the service provider in accordance with Article 28 of the GDPR.

Server log files: The web server automatically collects data (so-called server log files) each time a page is accessed, including the page accessed, the date and time of the request, the amount of data transferred, a notification of a successful request, the browser type and version, the operating system, the referrer URL, and the IP address (which may be truncated). The legal basis is our legitimate interest in stable and secure operation (Art. 6(1)(f) GDPR). For security reasons, the log files are stored for a maximum of 7 days and then deleted; data that must be retained for evidentiary purposes remains stored until the incident has been fully resolved.

Contact Us

When you contact us (e.g., via the contact form, email, or phone), the information provided by the person making the inquiry will be processed to the extent necessary to respond to the inquiry. The legal basis is the fulfillment of (pre-)contractual obligations (Art. 6(1)(b) GDPR), provided the inquiry is related to a contract; otherwise, our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR).

Comments and posts

When users leave comments or other posts, their IP addresses are stored for 7 days based on our legitimate interests (Art. 6(1)(f) GDPR). This is for our security in the event that someone posts unlawful content. Names, email addresses, and website information provided are stored permanently until users object.

Reach Measurement with Google Analytics 4

We use Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), to measure reach and optimize our online offerings. In doing so, Google processes usage data (e.g., pages visited, interactions, approximate location data, device and browser information). Users’ IP addresses are truncated by Google within EU/EEA member states and are transferred to the U.S. only in exceptional cases. Google Analytics 4 uses, by default, none No longer does it store IP addresses in the traditional way; the IP address is used only briefly to determine location and is not stored permanently.

Legal Basis This is based solely on your consent pursuant to Section 25(1) of the TDDDG in conjunction with Article 6(1)(a) of the GDPR, which you provide via our consent dialog and may revoke at any time. Transfers to third countries: Google LLC is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses are also in place. A data processing agreement is in place with Google. For more information: https://policies.google.com/privacy.

Fonts (Web Fonts)

To ensure consistent font display, we incorporate third-party web fonts. When you visit a page, your browser downloads the required fonts from the provider’s server, and your IP address is transmitted in the process. This integration is based on your consent (Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Recommendation: Use local integration to avoid transferring data to third parties.

Social Media Presence

We maintain profiles on social media platforms to communicate with users active on those platforms and to provide information about our services. When you access these platforms, their terms of service and privacy policies apply. The providers regularly process user data for market research and advertising purposes, including to create user profiles. The legal basis is our legitimate interest in effective information and communication (Art. 6(1)(f) GDPR). We may operate these platforms jointly with the provider (Art. 26 GDPR).

Networks Used:

  • LinkedIn – LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. https://www.linkedin.com/legal/privacy-policy
  • X (formerly Twitter) – Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland. https://x.com/de/privacy
  • Facebook – Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. https://www.facebook.com/privacy/policy

Changes and Updates to This Privacy Policy

We ask that you review the contents of this Privacy Policy regularly. We will update it as soon as changes to our data processing practices make it necessary.


Scroll to Top