📜 Privacy Policy
Theis Consult / aixzellent
Leonhardstraße 23-27, 52064 Aachen
🔹 1. Controller
Controller within the meaning of the GDPR:
Theis Consult / aixzellent
Leonhardstraße 23-27
52064 Aachen
This Privacy Policy informs you, in accordance with the GDPR, TMG, and BDSG, about:
- The type, scope, and purpose of the processing of your personal data.
- Your rights (e.g., access, deletion, objection).
- The legal bases for data processing.
Note on fines:
In case of violations of the GDPR, fines of up to €20 million or 4% of the global annual turnover (whichever is higher) may be imposed (Art. 83 GDPR). We implement all technical and organizational measures to ensure compliance with the GDPR.
🔹 2. Data Collection When Using the Website
Data Minimization
- No external analytics tools (e.g., Google Analytics).
- No personal data required to visit the website.
- Automatically stored server logs
Purpose: Operational reasons, security (e.g., defense against cyberattacks).
Data collected:
- Anonymized IP address
- Date and time of access
- Browser type and version
- Referrer URL
- Request data (web pages/files)
- Data volume transmitted
Storage period: 7 days (irreversibly deleted afterward).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
🔹 3. Data Collection in the Online Shop
a) Subscription Conclusion and Management
Data collected:
- Contact data: First and last name, email, phone number
- Billing address (if different)
- Payment data:
- Payment mandate (e.g., SEPA mandate or card token) is stored via Mollie.
- We do not store full payment details—only confirmation and reference tokens.
- Subscription metadata: Contract start, billing interval, status, cancellation date
- Invoices: Sent via email or provided in the customer account.
Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).
Disclosure to third parties: Mollie (payment processing), email service providers (if necessary).
Storage period:
- Contract and billing data: 10 years (tax law obligation).
- Mandate references: Deleted after contract ends (unless retention is legally required).
b) Customer Account (if offered)
Data stored:
- Registration data: Username, email, password (encrypted)
- Contact data: Name, address, phone number
- Subscription and invoice history
Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).
Storage period: Deleted after account deletion (unless retention is legally required).
🔹 4. Use of Cookies
- Type: Session cookies (automatically deleted after visit).
- Purpose: Basic functions (navigation, shopping cart, login status).
- No tracking!
- Legal basis: Art. 6(1)(b) GDPR (necessary for operation).
- Note: Disabling cookies may limit functionality (e.g., shopping cart).
🔹 5. Anonymized Analysis (Matomo)
- Tool: Open-source web tracking Matomo (no disclosure to third parties).
- Data collected:
- Anonymized IP address (last byte of IPv4 address masked).
- No cookies—uses anonymized server logs.
- Legal basis: Art. 6(1)(f) GDPR (optimization of services).
- Storage period: 13 months (automatic deletion).
🔹 6. Payment Provider (Mollie)
- Function: Recurring payments (monthly debits).
- Data processing:
- Payment data is transmitted directly to Mollie.
- We only receive confirmation and mandate reference.
- Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).
- Data protection:
- Data Processing Agreement (DPA) concluded with Mollie.
- Data primarily processed on EU servers.
- If transferred to third countries: EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
🔹 7. Right of Withdrawal & Cancellation
Right of Withdrawal
- 14-day right of withdrawal (§ 355 BGB) for services.
- Early termination: If explicit consent is given for immediate service provision (§ 356(4) BGB).
Ordinary Termination
- Possible at any time via the cancellation button in the customer account (§ 312k BGB).
- Debits end with the current billing period.
🔹 8. TLS Encryption
- Security: All data transmissions are TLS-encrypted (https:// + padlock symbol in the browser).
🔹 9. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR): Request information about stored personal data.
- Right to rectification (Art. 16 GDPR): Correct inaccurate data.
- Right to erasure (Art. 17 GDPR): Delete your data (unless retention is legally required).
- Right to restriction (Art. 18 GDPR): Restrict data processing.
- Right to data portability (Art. 20 GDPR): Receive your data in a machine-readable format.
- Right to object (Art. 21 GDPR): Object to processing (e.g., for marketing purposes).
🔹 10. Changes to the Privacy Policy
We reserve the right to adjust the Privacy Policy (e.g., due to changes in laws or new features).
- The current version is always available on this page.
- Significant changes (e.g., new data processing procedures) will be announced via email or the website.
🔹 11. Technical and Organizational Measures (TOM)
🔧 Technical Measures
- Encryption: TLS for all data transmissions; end-to-end encryption for payment data.
- Access controls: Password protection, 2FA for admin areas, role-based permissions.
- Secure storage: Servers in Germany (firewalls, security updates, access logging).
- Backups: Encrypted, automated, stored for max. 30 days.
- Data minimization: Only necessary data for contract fulfillment or legal obligations.
- Logging: Access to download links and admin areas (IP, timestamp).
- Security monitoring: Automated detection and blocking of cyberattacks.
📋 Organizational Measures
- Training: Regular employee training on data protection and IT security.
- Contractual precautions: Data Processing Agreements (DPAs) with all external service providers (e.g., Mollie, hosting providers).
- Regular reviews: Annual audits of TOM; internal/external security audits.
- Emergency plan: Rapid response to data breaches (documentation, notification within 72 hours, Art. 33 GDPR).