Skip to main content Skip to search Skip to main navigation

📜 Privacy Policy

Theis Consult / aixzellent
Leonhardstraße 23-27, 52064 Aachen


🔹 1. Controller

Controller within the meaning of the GDPR:
Theis Consult / aixzellent
Leonhardstraße 23-27
52064 Aachen

This Privacy Policy informs you, in accordance with the GDPR, TMG, and BDSG, about:

  • The type, scope, and purpose of the processing of your personal data.
  • Your rights (e.g., access, deletion, objection).
  • The legal bases for data processing.

Note on fines:
In case of violations of the GDPR, fines of up to €20 million or 4% of the global annual turnover (whichever is higher) may be imposed (Art. 83 GDPR). We implement all technical and organizational measures to ensure compliance with the GDPR.


🔹 2. Data Collection When Using the Website

Data Minimization

  • No external analytics tools (e.g., Google Analytics).
  • No personal data required to visit the website.
  • Automatically stored server logs

Purpose: Operational reasons, security (e.g., defense against cyberattacks).

Data collected:

  • Anonymized IP address
  • Date and time of access
  • Browser type and version
  • Referrer URL
  • Request data (web pages/files)
  • Data volume transmitted

Storage period: 7 days (irreversibly deleted afterward).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).


🔹 3. Data Collection in the Online Shop

a) Subscription Conclusion and Management

Data collected:

  • Contact data: First and last name, email, phone number
  • Billing address (if different)
  • Payment data:
    • Payment mandate (e.g., SEPA mandate or card token) is stored via Mollie.
    • We do not store full payment details—only confirmation and reference tokens.
  • Subscription metadata: Contract start, billing interval, status, cancellation date
  • Invoices: Sent via email or provided in the customer account.

Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).
Disclosure to third parties: Mollie (payment processing), email service providers (if necessary).

Storage period:

  • Contract and billing data: 10 years (tax law obligation).
  • Mandate references: Deleted after contract ends (unless retention is legally required).

b) Customer Account (if offered)

Data stored:

  • Registration data: Username, email, password (encrypted)
  • Contact data: Name, address, phone number
  • Subscription and invoice history

Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).
Storage period: Deleted after account deletion (unless retention is legally required).


🔹 4. Use of Cookies

  • Type: Session cookies (automatically deleted after visit).
  • Purpose: Basic functions (navigation, shopping cart, login status).
  • No tracking!
  • Legal basis: Art. 6(1)(b) GDPR (necessary for operation).
  • Note: Disabling cookies may limit functionality (e.g., shopping cart).

🔹 5. Anonymized Analysis (Matomo)

  • Tool: Open-source web tracking Matomo (no disclosure to third parties).
  • Data collected:
    • Anonymized IP address (last byte of IPv4 address masked).
    • No cookies—uses anonymized server logs.
  • Legal basis: Art. 6(1)(f) GDPR (optimization of services).
  • Storage period: 13 months (automatic deletion).

🔹 6. Payment Provider (Mollie)

  • Function: Recurring payments (monthly debits).
  • Data processing:
    • Payment data is transmitted directly to Mollie.
    • We only receive confirmation and mandate reference.
  • Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).
  • Data protection:
    • Data Processing Agreement (DPA) concluded with Mollie.
    • Data primarily processed on EU servers.
    • If transferred to third countries: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).

🔹 7. Right of Withdrawal & Cancellation

Right of Withdrawal

  • 14-day right of withdrawal (§ 355 BGB) for services.
  • Early termination: If explicit consent is given for immediate service provision (§ 356(4) BGB).

Ordinary Termination

  • Possible at any time via the cancellation button in the customer account (§ 312k BGB).
  • Debits end with the current billing period.

🔹 8. TLS Encryption

  • Security: All data transmissions are TLS-encrypted (https:// + padlock symbol in the browser).

🔹 9. Your Rights as a Data Subject

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR): Request information about stored personal data.
  • Right to rectification (Art. 16 GDPR): Correct inaccurate data.
  • Right to erasure (Art. 17 GDPR): Delete your data (unless retention is legally required).
  • Right to restriction (Art. 18 GDPR): Restrict data processing.
  • Right to data portability (Art. 20 GDPR): Receive your data in a machine-readable format.
  • Right to object (Art. 21 GDPR): Object to processing (e.g., for marketing purposes).

🔹 10. Changes to the Privacy Policy

We reserve the right to adjust the Privacy Policy (e.g., due to changes in laws or new features).

  • The current version is always available on this page.
  • Significant changes (e.g., new data processing procedures) will be announced via email or the website.

🔹 11. Technical and Organizational Measures (TOM)

🔧 Technical Measures

  • Encryption: TLS for all data transmissions; end-to-end encryption for payment data.
  • Access controls: Password protection, 2FA for admin areas, role-based permissions.
  • Secure storage: Servers in Germany (firewalls, security updates, access logging).
  • Backups: Encrypted, automated, stored for max. 30 days.
  • Data minimization: Only necessary data for contract fulfillment or legal obligations.
  • Logging: Access to download links and admin areas (IP, timestamp).
  • Security monitoring: Automated detection and blocking of cyberattacks.

📋 Organizational Measures

  • Training: Regular employee training on data protection and IT security.
  • Contractual precautions: Data Processing Agreements (DPAs) with all external service providers (e.g., Mollie, hosting providers).
  • Regular reviews: Annual audits of TOM; internal/external security audits.
  • Emergency plan: Rapid response to data breaches (documentation, notification within 72 hours, Art. 33 GDPR).