Skip to main content Skip to search Skip to main navigation

Privacy Policy

Last updated: August 2026

This is a translation of the German original. In the event of any discrepancy, the German version prevails.

Controller

Theis Consult / aixzellent Leonhardstrasse 23-27 52064 Aachen Germany

Full contact details, including telephone number and email address, can be found in our legal notice.

Protecting your data is our highest priority. Below we inform you, in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG), about the purpose, nature and scope of the processing of personal data in our online shop.

Principle of data minimisation

In order to limit the collection and processing of personal data as far as possible, we do not use any external analytics tools such as Google Analytics, and we restrict processing to what is necessary to operate the shop and to fulfil our contractual and legal obligations.

You can visit our pages without providing any personal information. Personal data only becomes necessary when you create a customer account or place an order.

Server log files

For technical operating reasons and for security analysis, in order to prevent and evaluate system errors or cyber attacks, server logs are stored automatically.

Data collected:

  • IP address
  • Date and time of access
  • Browser type and version
  • Referrer URL
  • Names of the pages or files requested
  • Volume of data transferred

This information is used exclusively for security and operational purposes and is deleted in full after seven days. It is not combined with other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and uninterrupted operation).

Hosting

Our online shop runs on our own servers in Germany. No data is transferred to an external hosting provider.

Legal basis: Art. 6(1)(f) GDPR and, where provision serves the performance of a contract, Art. 6(1)(b) GDPR.

Cookies

We use strictly necessary session cookies only. These are small text files stored by your browser. They cause no damage to your device and contain no viruses.

These cookies enable core shop functions such as navigation, the shopping cart, login status and protection against form abuse. They are deleted automatically at the end of your visit and are not used for tracking purposes.

Legal basis for storage on your device: Section 25(2) no. 2 TDDDG. Such storage is strictly necessary to provide the service you have expressly requested, and therefore does not require consent. Legal basis for subsequent processing: Art. 6(1)(b) GDPR.

You can configure your browser to notify you when cookies are set and to decide individually which cookies to allow or block. If you disable them, core shop functions, in particular the shopping cart and login, will no longer be available.

Anonymised analysis of visitor traffic

We use the open-source web analytics tool Matomo to analyse how our services are used. The data collected is processed internally only, is not passed on to third parties, and is stored and analysed exclusively on our own servers in Germany.

For anonymisation, the last digits of the IP address (the final byte of the IPv4 address) are masked. This reliably prevents the data from being linked to an individual.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in needs-based design of our services).

Customer account

A customer account is required in order to use our shop.

Data processed:

  • Login data: email address and password. The password is stored solely as a cryptographic hash, never in plain text.
  • Master data: form of address, first and last name, company
  • Contact data: billing address, telephone number
  • Order, subscription and invoice history

Purpose: managing your account, processing orders and subscriptions, providing invoices and access credentials.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures).

Retention period: until your account is deleted. Statutory retention obligations under commercial and tax law remain unaffected; for that period the data concerned is restricted from further processing.

Orders, subscriptions and contract performance

Data processed:

  • Contact data: first and last name, company, email address, telephone number
  • Billing address and, where different, further addresses
  • Order data: services ordered, price, order date, order number
  • Subscription metadata: contract start, billing interval, status, cancellation date
  • Payment-related references: mandate or transaction reference from the payment service provider

We do not store complete payment details such as card numbers or bank account data. From the payment service provider we receive only a payment confirmation and a reference to the mandate on file.

Invoices are sent by email and made available in your customer account.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract); as regards retention, Art. 6(1)(c) GDPR (legal obligation).

Retention period:

  • Contract and accounting data: ten years pursuant to Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code
  • Mandate references: deleted at the end of the contract unless a retention obligation applies

Payment processing via Mollie

For payment processing, in particular recurring payments for subscriptions, we use the following payment service provider:

Mollie B.V. Keizersgracht 126 1015 CW Amsterdam Netherlands

Your payment data is transmitted directly to Mollie and processed there. We receive only the payment confirmation and a mandate or transaction reference.

Processing takes place primarily on servers within the European Union. Where transfer to a third country is required in an individual case, it takes place on the basis of the EU standard contractual clauses (Art. 46(2)(c) GDPR).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Further information about processing by Mollie: https://www.mollie.com/privacy

Transactional emails

As part of contract performance we send emails, in particular order confirmations and access credentials for the services booked. We do not send a marketing newsletter.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Contacting us

When you contact us, for example by email, we process the information you provide in order to handle your enquiry and, should follow-up questions arise, in particular to carry out pre-contractual measures.

Legal basis: Art. 6(1)(b) GDPR where the enquiry relates to a contract or its initiation, otherwise Art. 6(1)(f) GDPR.

Retention period: deleted once the matter has been concluded, unless statutory retention obligations apply.

Please note that data transmission over the internet, for instance when communicating by email, may have security gaps. Complete protection of data against access by third parties is not possible.

Recipients and categories of recipients

We disclose personal data only where this is necessary for the performance of a contract, where you have consented, or where we are legally obliged to do so.

Categories of recipients:

  • Payment service provider (Mollie B.V.)
  • Tax advisors and auditors within the scope of statutory obligations
  • Public authorities and courts where a legal obligation exists

We do not sell or otherwise make data available for advertising purposes.

Transfers to third countries

Processing generally takes place within the European Union or the European Economic Area. Where a transfer to a third country occurs in an individual case, it takes place only on the basis of an adequacy decision of the European Commission (Art. 45 GDPR) or appropriate safeguards, in particular the EU standard contractual clauses (Art. 46 GDPR).

Necessity of providing data

Providing your data is neither required by law nor by contract. However, in order to conclude a contract we need certain information, in particular your name, address, email address and payment details. Without this information we cannot conclude the contract or provide the agreed services.

Automated decision-making

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place. No credit assessment is carried out.

Your rights as a data subject

You have the following rights in relation to personal data concerning you:

  • Access, Art. 15 GDPR
  • Rectification of inaccurate data and completion of incomplete data, Art. 16 GDPR
  • Erasure, Art. 17 GDPR, unless retention obligations or other exceptions apply
  • Restriction of processing, Art. 18 GDPR
  • Data portability, Art. 20 GDPR
  • Withdrawal of consent, Art. 7(3) GDPR. Withdrawal takes effect for the future and does not affect the lawfulness of processing carried out beforehand.

To exercise your rights, an informal message to the contact details given in our legal notice is sufficient.

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR. This applies in particular to the server log files and the anonymised audience measurement. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR).

The supervisory authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen) Kavalleriestrasse 2-4 40213 Duesseldorf, Germany Postal address: Postfach 20 04 44, 40102 Duesseldorf Phone: +49 211 38424-0 Email: poststelle@ldi.nrw.de Website: https://www.ldi.nrw.de

Data security

We take appropriate technical and organisational measures in accordance with Art. 32 GDPR to protect your data against loss, misuse and unauthorised access:

  • This site uses TLS (Transport Layer Security) encryption. You can recognise an encrypted connection by the address bar of your browser beginning with https:// and by the padlock symbol in the browser bar.
  • Passwords are stored solely as cryptographic hashes.
  • Customer accounts are subject to a password policy requiring a minimum length of 20 characters as well as upper and lower case letters, digits and special characters.
  • The shop runs on our own servers in Germany with regular security updates.
  • Access to administrative areas is restricted to authorised persons.

We report personal data breaches to the competent supervisory authority without undue delay in accordance with Art. 33 GDPR, where possible within 72 hours.

Changes to this privacy policy

We reserve the right to amend this privacy policy, for example in response to changes in the law or the introduction of new features. The version published on this page applies. We inform our customers in writing of any fundamental changes.

Information on your right of withdrawal and on cancelling your contract can be found in our terms and conditions.