Privacy policy

This English version is provided for convenience. The German version is the legally binding one.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

DiD0m – Dominik Dill
Goldammerweg 25
95119 Naila
Germany

Phone: +49 151 15608302
Email: dominik.dill@did0m.net

No data protection officer has been appointed, as the statutory requirements for a mandatory appointment (§ 38 BDSG) are not met.

2. Principles

This website does not use third-party tracking or marketing services. No third-party content (such as external fonts, maps or videos) is loaded and no data is processed for advertising purposes. Visitor statistics run without cookies on our own servers (see section 7). Personal data is processed only to the extent necessary to operate the website, handle enquiries and perform contracts.

3. Provision of the website and server log files

When you access this website, the server automatically processes information transmitted by your browser: IP address, date and time of access, requested address, referrer URL, browser and operating system. This data is technically necessary to deliver the website and to ensure the security and stability of the system (defence against attacks, troubleshooting).

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure operation). Log files are deleted after seven days at the latest, unless they are needed to investigate a specific security incident.

4. Hosting

The website and all associated systems are operated on servers in Germany. Where an external data centre operator is used, processing takes place on the basis of a data processing agreement under Art. 28 GDPR. Personal data is transferred to third countries outside the EU or EEA only in the cases expressly named in this policy.

5. Contact form and getting in touch

If you contact us via the contact form, by email or by phone, we process the data you provide (name, email address and, optionally, company or club, phone number, subject and message text) in order to handle and answer your enquiry. The only mandatory fields in the form are name, email address and the message itself.

The legal basis is Art. 6 (1) (b) GDPR where the enquiry aims at concluding or performing a contract, and otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries). The data is deleted once the enquiry has been fully dealt with and no statutory retention obligations (§ 147 AO, § 257 HGB) stand in the way. If a contract is concluded, the data is further processed for its performance.

6. Cookies

No cookies are set on the public website. Only when signing in to the customer portal or the internal administration area is a technically necessary session cookie set, which serves solely for authentication. In the customer portal it expires after 14 days at the latest, in the administration area after 90 days at the latest; it is deleted immediately on sign-out. Storing this cookie is exempt from the consent requirement under § 25 (2) no. 2 TDDDG, as it is strictly necessary for the service you have expressly requested. A consent banner is therefore not required.

7. Visitor statistics

To analyse traffic we use a self-hosted instance of Plausible Analytics on a server in Germany. It works without cookies and without persistent identification: the IP address is used only transiently to form a daily-changing, irreversible hash and is not stored. Recorded are the page visited, referrer, browser type, device type and country of origin. No merging with other data and no transfer to third parties takes place.

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in privacy-friendly reach measurement). As no cookies are set and no information is stored on your device, no consent under § 25 TDDDG is required.

8. Customer portal and chat

Customers receive access to a customer portal by invitation. There we process the data required to initiate and perform the contract: login data (email address, password in hashed form or passkey), the details from the intake form, uploaded files, chat messages and the electronic signature under a data processing agreement. The legal basis is Art. 6 (1) (b) GDPR.

Alongside a quotation we may provide you with a clickable draft at its own address, disclosed only to you; access is protected by a username and password and is closed again after a short period. On those pages a button is available for feedback. If you send a message through it, we transmit - in addition to your text - the page you were on and the size of your viewport, so that we can match your feedback to the right screen. This is recorded only when you send a message; merely viewing the draft is not evaluated. The message becomes part of your chat history; the legal basis is Art. 6(1)(b) GDPR.

For chat messages, a draft reply may be generated with the help of an AI service. For this purpose the conversation history is transmitted to Anthropic PBC, 548 Market St, San Francisco, CA 94104, USA. The transfer to the USA is based on standard contractual clauses under Art. 46 (2) (c) GDPR in conjunction with a data processing agreement under Art. 28 GDPR; the content is not used to train models. Every draft is reviewed and approved by a human before it is sent - no automated reply is sent to you.

9. Email dispatch

We send invitations, quotes, invoices and payment reminders by email via our own mailboxes operated in Germany. Outgoing messages are signed with DKIM. Dispatch is logged (recipient, subject, time, delivery status) so that delivery problems can be traced; these logs are deleted after two years.

10. Processing of incoming receipts

We process incoming invoices and receipts to fulfil our tax obligations (Art. 6 (1) (c) GDPR, §§ 147 AO, 257 HGB). If a receipt contains a structured e-invoice (Factur-X, ZUGFeRD, XRechnung), the data is read exclusively locally on our server.

Only for receipts without structured data may automatic text recognition optionally be used. In that case the receipt is transmitted for analysis to Anthropic PBC, 548 Market St, San Francisco, CA 94104, USA. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in efficient receipt processing); the transfer to the USA is based on standard contractual clauses under Art. 46 (2) (c) GDPR in conjunction with a data processing agreement under Art. 28 GDPR. The content is not used to train models. This function is disabled by default; it concerns only receipts we receive ourselves, not data of visitors to this website.

11. Invoice and contract data

To perform contracts we process master and invoice data of our customers (name, address, contact details, contract and payment data). To reconcile incoming payments we evaluate statements of our own bank accounts; in doing so we process the name, IBAN and payment reference of the payer. The legal basis is Art. 6 (1) (b) GDPR and Art. 6 (1) (c) GDPR in conjunction with commercial and tax retention obligations. Invoices and accounting records are retained for eight or ten years in accordance with § 147 AO.

12. Recipients of the data

Within the company, only those who need your data to fulfil the stated purposes have access to it. Data is passed on to external parties only where necessary to perform the contract (e.g. banks for transfers), where a legal obligation exists (e.g. towards tax authorities) or where a processor under Art. 28 GDPR is used (data centre operator; the AI services named in sections 8 and 10).

13. Your rights

You have the following rights towards us regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)

Right to object (Art. 21 GDPR): Where we process your data on the basis of Art. 6 (1) (f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.

To exercise your rights, a message to the contact details above is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de. You may also contact the supervisory authority of your habitual residence.

14. No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Suggestions generated by our systems (such as draft replies or payment reminders) are always reviewed by a human before they take effect.

15. Changes to this policy

We update this privacy policy whenever the legal situation or our processing changes (for example when new payment methods or services are introduced). The version published here applies.

Last updated: September 2026