Privacy information
The German privacy notice is legally authoritative. This English version provides a complete explanation for international visitors.
1. Controller
Bruni Giese
Ostringhausen 19
42929 Wermelskirchen
Germany
Telephone: +49 (0) 2196 9 30 43
Email: frank@schadennetzwerk.com
2. Hosting and server logs
The website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Technically necessary connection data may be processed to deliver, secure and troubleshoot the website, including IP address, time, requested resource, transferred volume, referrer, browser and operating-system data and status codes. The legal basis is Article 6(1)(f) GDPR. Logs are retained only for as long as required for operation, fault analysis, abuse prevention or legal evidence.
3. Local media and fonts
Images, stylesheets, JavaScript and fonts are delivered locally by this website. No Google Fonts or other font CDN is contacted.
4. Consent settings
Your choice between essential functions and analytics is stored locally in your browser under sn_consent_v2 so that it can be respected across pages. The legal bases are section 25(2) no. 2 TDDDG and Article 6(1)(f) GDPR. You can change the choice at any time through “Analytics settings” in the footer.
5. Google Analytics 4
Google Analytics 4 of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, measurement ID G-8JKBT24YVR, loads only after active consent. Before consent, the Google tag is not loaded. Processing may include page views, interactions, technical device and browser information and time data. Names, email addresses, telephone numbers, organisations and message text submitted through forms are not sent to Analytics.
The legal bases are consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Consent can be withdrawn for the future at any time. Google may process data in the United States. Google states that Google LLC is certified under the EU-U.S. Data Privacy Framework; supplementary contractual safeguards may also apply. Before launch, user-level retention must be set to two months, while Google signals and advertising personalisation remain disabled.
6. Contact and demo requests
For contact and demo requests we process the submitted information, in particular name, business email address, organisation, role, optional telephone number, topic, message, source and preferred contact method. Processing is required to handle the request and prepare or perform a business relationship. The legal bases are Article 6(1)(b) GDPR and, for general business enquiries, Article 6(1)(f) GDPR.
7. Sample requests
To provide the sample, we process name, business email address, organisation, role, time, source, reference, delivery status and download status. Delivery uses a signed, time-limited token that contains no readable email address or other directly identifying contact data. The legal basis is Article 6(1)(b) GDPR. Consent to receive further specialist information is voluntary, not preselected and not required for the download. Marketing messages are sent only on the basis of separate, verifiable consent.
8. Partner and application requests
For an enquiry as an independent sales or consulting partner, we process the form data and any voluntarily uploaded documents to assess a possible cooperation. The legal basis is Article 6(1)(b) GDPR. If no cooperation is established, the data are normally deleted no later than six months after the selection process has ended, unless consent, legal defence or a statutory duty justifies longer retention.
9. Email delivery
Forms are processed through authenticated SMTP. In the intended Hetzner setup, email is technically handled through the mail infrastructure configured for the domain. Internal notifications are sent to frank@schadennetzwerk.com. If a different email provider is used, this notice must be updated before deployment.
10. Lead database, references and download records
Successful contact, sample and partner requests are stored server-side in a protected SQLite database or, where technically required, a protected file fallback. Stored data include the form fields, reference, time, consent status, source and delivery status as well as sample-download count and most recent download time. General leads are deleted by default after 365 days unless a business relationship, statutory retention duty or other legal basis continues. Unsuccessful partner enquiries are normally deleted after six months.
11. Spam and abuse prevention
Forms use server-side validation, CSRF and origin controls where applicable, honeypot fields, timing and size limits, rate limits, duplicate detection and spam scoring. Complete IP addresses are not stored in the lead database. For temporary rate limiting, a non-reversible keyed hash is processed. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is protecting the website, mailboxes and business processes against abuse.
12. Cloudflare Turnstile
Cloudflare Turnstile is disabled in the delivered default configuration. It will be enabled only if increased bot activity requires it and the privacy information, contractual basis and technical configuration have first been updated and approved.
13. External links and social networks
This website does not embed social-media feeds or LinkedIn tracking elements. Only when you click an external link – in particular to LinkedIn, the book website or R-SOS – does your browser connect to the relevant destination provider. Technically necessary connection data may then be processed. The destination operator is responsible for further processing; please consult its privacy information.
14. Recipients and processors
Recipients may include persons authorised to handle the enquiry and contractually bound hosting, email, IT and analytics providers. Where required, processor agreements under Article 28 GDPR are concluded. Data are disclosed for other purposes only where a legal basis or consent exists.
15. Retention
Personal data are deleted once the relevant purpose no longer applies and no statutory retention, evidence or limitation period prevents deletion. Specific periods are stated above. Security data may be retained until an incident has been investigated and legal claims can be defended.
16. Your rights
Subject to the statutory conditions, you have rights of access, correction, erasure, restriction of processing, portability and objection. Consent may be withdrawn at any time for the future. You also have the right to lodge a complaint with a data-protection supervisory authority.
17. Supervisory authority
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
Postal address: Postfach 20 04 44, 40102 Düsseldorf, Germany
Telephone: +49 (0) 211 38424-0
Email: poststelle@ldi.nrw.de
18. Required information and automated decisions
Fields marked as required are necessary to process the relevant request. Without them, processing or delivery may not be possible. No solely automated decision with legal or similarly significant effect is made.
19. Updates
This notice is updated when services, providers, law or the technical configuration change. The German version published on this website is authoritative.
Accident help and partner referral
For accident-help requests we process contact details, location or postcode, organisational case indicators, requested support and consent records. Data is shared with a suitable vehicle assessor and/or German traffic-law firm only according to your selection and consent.
The indicator of possible personal injury may constitute health-related data. It is used solely for urgency and partner allocation. Do not submit diagnoses or medical documents through the initial form.
An enquiry does not automatically instruct a partner and does not constitute technical or legal assessment by SchadenNetzwerk.
