Privacy Policy

Last updated: July 2026

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is:

Remmler Digital Solutions GmbH

Wierther Str. 8

38159 Vechelde

Germany

Email: office@remmler.digital

2. Data Protection Officer

Based on our current assessment, there is no legal obligation to appoint a Data Protection Officer. For data protection inquiries, please use the contact details above.

3. General Information on Data Processing

We process personal data only to the extent necessary to provide our website, process inquiries, perform pre-contractual measures, fulfill contractual obligations, comply with legal requirements, safeguard legitimate interests, or based on consent. Legal bases include Art. 6(1)(a), (b), (c) and (f) GDPR. Where consent is the legal basis, it may be withdrawn at any time with effect for the future.

4. Hosting and Server Log Files

When you visit this website, the hosting provider processes technically necessary server log files. This includes in particular the date and time of access, requested file, referrer URL, browser and operating system information, status code and transferred data volume. Processing is based on Art. 6(1)(f) GDPR for the technical provision, security and stability of the website.

Hosting provider: STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (Strato Privacy Policy). A data processing agreement exists.

According to STRATO, server log files are available for the last six weeks; older log files are not provided. The host name or IP address of the requesting client is anonymized in the log files for data protection reasons. The graphical web statistics are available for several years and serve anonymized statistical analysis. This does not set cookies and does not create any personal usage profiles.

5. Contact via Email, Telephone or Contact Form

When you contact us via email, telephone or contact form, we process the data you provide to handle your inquiry. This may include:

  • Name
  • Contact details
  • Company / organization
  • Content of inquiry

Legal basis is Art. 6(1)(b) GDPR where the inquiry relates to a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR.

Pure contact inquiries are regularly deleted no later than 6 months after completion. For contract- or business-related communication, statutory retention and limitation periods apply.

The contact form is processed through a PHP script operated on our web hosting. To protect the contact form against misuse and automated spam submissions, we use Cloudflare Turnstile. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When the form is accessed or submitted, Cloudflare processes technical signals such as IP address, user agent, TLS fingerprint, site key and origin page to distinguish human access from automated access.

The legal basis for the use of Turnstile is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website and contact form from spam, misuse and automated attacks. Insofar as Turnstile uses cookies or comparable technologies, this is based on § 25(2)(2) TDDDG, as these are necessary for the protection of the explicitly used contact form.

Cloudflare processes data in the context of providing Turnstile partly as our processor and partly as a separate controller for improving bot detection. This may involve transfers to the United States or other third countries. Cloudflare is, according to its own statements, certified under the EU-U.S. Data Privacy Framework and, where necessary, relies on Standard Contractual Clauses. For more information, see the Cloudflare Privacy Policy and the Cloudflare Turnstile Privacy Addendum.

Email delivery uses the mail infrastructure provided by STRATO. Data is not transferred to an additional external form backend or email marketing provider.

If you contact us by telephone, we process the information you provide as well as telephone-related data. This may include in particular your telephone number, date and time of the call, connection data and, where applicable, further technical communication data. We use services provided by easybell GmbH, Brückenstraße 5a, 10179 Berlin, Germany, for the provision of our telephone services. The processing is carried out to handle your telephone request, to take pre-contractual steps or to perform a contract on the basis of Art. 6 para. 1 lit. b GDPR and, in all other cases, on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in reliable and efficient telephone availability.

You may also contact us via the messaging service WhatsApp. When you contact us via WhatsApp, we process the information you provide to handle your inquiry. Please note that when using WhatsApp, Meta Platforms, Inc. processes your personal data under its own responsibility, in particular communication content, metadata and device information. Data may be transferred to countries outside the EU (in particular the USA). The legal basis for our processing is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in offering you an additional communication channel preferred by many customers. For detailed information on data protection at WhatsApp, please refer to the WhatsApp Privacy Policy.

6. Customer, Contract and Project Data

We process data of customers, contacts, prospects and project participants for quoting, contract performance, project communication, billing, documentation, support and customer care.

Processed data may include:

  • Master data and contact details
  • Contract and billing data
  • Communication content
  • Project information
  • Technical information about systems, networks, software and IT environments
  • Access data where required for service delivery. Access data is used only for its intended purpose, confidentially and to the extent necessary to perform the service.

Legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. Statutory retention obligations arise in particular from commercial and tax law.

7. IT Support, Remote Maintenance and System Access

In the course of IT support, remote maintenance, system integration, hosting, IT security services and software operations, we may gain access to personal data processed in our customers' systems.

Where we process personal data on behalf of a customer, we act as a processor pursuant to Art. 28 GDPR. In this case, a data processing agreement is concluded.

Remote maintenance and system access are performed only for the agreed service. Access data is treated confidentially and used only as required.

8. SaaS, Customer Accounts and Online Services

Where we provide SaaS services, customer accounts, portals or online services, we process data for registration, login, provision, security and administration. Legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. Where content is processed on behalf of the customer, Art. 28 GDPR also applies.

9. Online Shop, Orders and Payments

We do not currently operate our own online shop. Should orders via our website become possible in the future, we will disclose the data processed, payment service providers and legal bases in this privacy policy.

10. Newsletter

We do not currently offer a newsletter. Should a newsletter be set up in the future, it will only be sent on the basis of your consent pursuant to Art. 6(1)(a) GDPR using the double opt-in procedure.

11. Cookies and Consent Management

This website uses only technically necessary cookies and comparable technologies that are required for the operation, security or expressly used functions of the website. This may include in particular the protection of the contact form through Cloudflare Turnstile. A consent banner for analytics or marketing purposes is currently not required, as no analytics or marketing services are deployed.

Legal basis for technically necessary cookies and comparable technologies is § 25(2)(2) TDDDG. Where personal data is processed in this context, this is based on Art. 6(1)(f) GDPR.

12. Web Analytics and Marketing

We do not currently use any web analytics or marketing tools on this website. No data is transmitted to third parties for advertising purposes. Should analytics or marketing services be deployed in the future, this will only be done on the basis of your consent and will be disclosed in this policy.

13. Online Presences on Social Networks and Platforms

We maintain online presences on social networks, business platforms, developer platforms, business directories and other platforms. These may include in particular LinkedIn, Google Business Profiles and other platforms on which we present our company, publish posts, communicate with prospects, customers, applicants or business partners, or provide information.

When you visit our online presences or interact with us through these platforms, personal data may be processed. This may include profile information, contact details, communication content, comments, reactions, reviews, publicly visible interactions as well as technical usage and statistical data.

We process data made available to us through these platforms for the purpose of presenting our company, publishing information, communicating, handling inquiries, maintaining business contacts and evaluating the reach and use of our online presences. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in modern corporate communication, public relations, customer and prospect communication and the further development of our online offerings. Where an inquiry relates to the conclusion or performance of a contract, Art. 6(1)(b) GDPR also applies.

Please note that when visiting such platforms, the respective platform operators also process personal data under their own responsibility. This may include usage data, device information, IP addresses, location data, interactions and information for reach measurement. We have only limited influence over the nature and scope of this processing. Further information can be found in the privacy notices of the respective platform operators.

Where we receive aggregated statistics or so-called insights via platforms, we process them to analyze the use and reach of our online presences. These statistics are generally provided to us in aggregated form. Where joint controllership with the respective platform operator exists in this context, the agreements and information provided by the respective platform apply additionally.

Messages or inquiries sent directly to us via platforms are deleted once they are no longer required for processing and no statutory retention periods apply. Content that you publish publicly on platforms generally remains visible until you delete it yourself or the respective platform removes it.

14. External Content and Services

Our website does not embed external content such as maps, videos, or external fonts. Cloudflare Turnstile is used to protect the contact form from spam (see Section 5). No further external services are integrated.

15. Applications and Employee Data

If you apply to us, we process your application data for the purpose of conducting the application process. Legal basis is § 26 BDSG and Art. 6(1)(b) GDPR. If an application is rejected, we regularly delete application data no later than 6 months, unless consent for longer storage or legal reasons prevent this.

16. Recipients of Personal Data

Personal data may be transferred to the following recipients where necessary:

  • Hosting and IT service providers (STRATO GmbH)
  • Providers of telephone and telecommunication services, in particular easybell GmbH, Brückenstraße 5a, 10179 Berlin, Germany, where you communicate with us by telephone
  • Security services (Cloudflare Inc., Turnstile – spam protection)
  • Operators of social networks, business platforms, developer platforms, business directories and other platforms, where we maintain online presences there or communicate with you there
  • Tax advisors and accounting
  • Banks and payment service providers
  • Authorities, courts and public bodies
  • Service providers within the scope of data processing
  • Customers or project partners where required for contract performance

17. Third-Country Transfers

Transfers of personal data to countries outside the European Union or the European Economic Area (third countries) do not generally take place for website hosting or contact form processing.

Cloudflare Turnstile, used for spam protection, may transmit IP addresses and technical signals to Cloudflare Inc. servers in the United States or other third countries. Cloudflare is, according to its own statements, certified under the EU-U.S. Data Privacy Framework. Where necessary, Cloudflare additionally relies on Standard Contractual Clauses for third-country transfers. For more information: Cloudflare Privacy Policy.

18. Storage Duration

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations. Commercial and tax records are generally retained for six and ten years respectively. Contract and project data is stored for the duration of the business relationship and thereafter in accordance with statutory limitation and retention periods.

19. Your Rights

Data subjects have the following rights in accordance with statutory provisions:

  • Access pursuant to Art. 15 GDPR
  • Rectification pursuant to Art. 16 GDPR
  • Erasure pursuant to Art. 17 GDPR
  • Restriction of processing pursuant to Art. 18 GDPR
  • Data portability pursuant to Art. 20 GDPR
  • Objection pursuant to Art. 21 GDPR
  • Withdrawal of consent pursuant to Art. 7(3) GDPR
  • Lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR. Our competent supervisory authority is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragter für den Datenschutz Niedersachsen).

20. Right to Object

Where we process personal data on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you may object to processing on grounds relating to your particular situation. Where personal data is processed for direct marketing purposes, you may object to such processing at any time.

21. Security

We implement appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration and disclosure. During your website visit, we use the TLS/SSL procedure in conjunction with the highest encryption level supported by your browser.

22. Currency and Changes to This Privacy Policy

This privacy policy is currently valid as of July 2026. We reserve the right to amend this privacy policy if our data processing, our website, the service providers we use or legal requirements change.