Privacy Policy
Last updated: 04. August 2026
1. Data Controller
The party responsible for the processing of personal data on this website is:
IT & GDP Consulting Thomas Kasimirat
Hauptstraße 51
67259 Großniedesheim
Email:
2. Data Collected and Purposes of Processing
Server Log Files
When you access this website, the web server automatically records the following data: IP address, date and time of access, URL requested, HTTP status code and volume of data transferred. This data serves secure operation, error analysis and the defence against automated attacks: after repeated failed attempts the address concerned is temporarily blocked. The full IP address is required for this purpose. The log files are rotated continuously and overwritten in the process; they are not analysed in order to identify individual persons and are not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security).
Contacting us
If you contact us by email or telephone, or use the form to request portal access, we process the details you provide — name, contact details, company and the content of your enquiry — solely in order to handle that enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to entering into a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in responding). We delete this data once the enquiry has been dealt with conclusively and no statutory retention obligations apply.
User Account and Portal Access
To use the customer portal, your email address and password (stored encrypted) are processed. This data is necessary to grant you access to the portal and to handle business transactions (quotes, invoices, projects, tickets). Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Cookies and local storage
Listed below are all entries this website stores on your device. Advertising cookies and third-party cookies are not used.
| Name | Purpose | Duration | Category |
|---|---|---|---|
| sessionid | Keeps you signed in to the portal | until the browser is closed | essential |
| csrftoken | Protection against form abuse | 1 year | essential |
| django_language | Remembers the chosen language (German/English) | 180 days | essential |
| kut_consent | Stores your privacy choice (local storage, not a cookie) | until withdrawn | essential |
| kut_no_track | Remembers your objection to audience measurement | 1 year | essential |
| Visitor identifier | Random identifier for recognising returning visits (local storage) | until withdrawn | Statistics (only with consent) |
Consent and withdrawal
On your first visit we ask whether reach measurement may take place. Without your consent no measurement occurs; the necessary functions of the website remain usable in any case. To document your decision we store a random identifier without personal reference together with the time and the categories chosen. You can change your decision at any time with a single click — via “Cookie settings” in the footer of every page. Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out up to that point. Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.
Web Analytics (Traffic Measurement)
For reach measurement we use a self-hosted, data-minimising analytics solution. It runs exclusively on our own server; no data whatsoever is transmitted to third parties, no advertising profiles are created and no data is combined across multiple websites. The following is recorded:
- requested page path, page title and language
- referring domain (referrer) with a rough channel classification (e.g. search engine, social media, campaign) as well as campaign parameters from the link (utm_*)
- country, derived roughly from the IP address
- rough device type, browser and operating system
- time on page and how far you scrolled
- Clicks on links to other websites and on files to download
- load times and display quality of the page as well as the occurrence of script errors (file and line number, not the error text)
- goals reached, such as a submitted access or appointment request — without any link to the submitted form contents
To distinguish individual visits, a one-way hash is generated from the IP address and the browser identifier. The underlying key changes automatically roughly every 30 days; after that, no link to earlier visits is possible. The IP address itself and the full browser identifier are never stored. If you have consented to statistics, a random identifier stored on your device is added, which allows returning visits to be recognised as such beyond that period; it contains no information about you personally and is deleted when you withdraw consent.
Individual records are deleted automatically after 120 days at the latest, and the figures on loading times and clicks after just 90 days. Only daily totals without any personal reference are retained, so that year-on-year comparisons remain possible. Legal basis: your consent under Art. 6(1)(a) GDPR.
Irrespective of your consent, you can permanently disable measurement for this browser via this link; doing so merely sets a technical marker without personal reference.
Usage measurement in the client portal
In the signed-in area too we measure — provided you have consented — which areas are used, in order to improve the portal. This analysis is deliberately designed so that it allows no conclusions about individual persons: no link to your user account is stored, and identifiers of individual records (such as an invoice number in the page path) are replaced by placeholders before storage. What is analysed is therefore how often an area is accessed — not who accessed it. No performance or behaviour monitoring takes place. Legal basis: your consent under Art. 6(1)(a) GDPR.
Uploaded Documents (DMS)
As part of our collaboration, documents can be exchanged via the portal. These are stored on the server and are only accessible to authorized users. Legal basis: Art. 6(1)(b) GDPR.
3. Disclosure to Third Parties
Personal data is not passed on, sold or rented out for advertising purposes. A transfer only takes place where this is required by law (e.g. duties to provide information to public authorities) or where we engage service providers who act for us on our instructions.
We use such processors in two areas: for the operation of the server on which this website and the portal run, and for sending our emails. Data processing agreements under Art. 28 GDPR are in place with both; processing takes place within the European Union. We will provide information about the providers used on request.
All components of this website — including fonts, icons and program libraries — are served from our own server. When you visit, no connections are therefore made to external servers (such as content delivery networks or font providers) through which your IP address could leak.
To assess our visibility in Google Search we retrieve aggregated figures from the Google Search Console (search terms, impressions, clicks, average position). This retrieval takes place server to server. No data about visitors to this website is transmitted to Google in the process, and no Google scripts are loaded in your browser.
4. Retention Period
Personal data is deleted as soon as it is no longer required for the purpose of processing. Data from business transactions (invoices, contracts) is subject to statutory commercial and tax retention obligations of up to 10 years (§ 147 AO, § 257 HGB).
5. Your Rights (Art. 15–22 GDPR)
You have the right at any time to:
- Access information about the data stored about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure of your data, provided no statutory retention obligations apply (Art. 17)
- Restriction of processing (Art. 18)
- Objection to processing (Art. 21)
- Data Portability (Art. 20) (Art. 20)
- Complaint to the competent data protection supervisory authority (Art. 77)
6. Data Security
This website uses SSL/TLS encryption for all data transfers. Passwords are never stored in plain text, but exclusively as a cryptographic hash with a random salt (PBKDF2-SHA256). Access to the portal is secured by brute-force protection (django-defender).