This statement describes which data arises when you visit axr-systems.de, what we process it for and how long it stays. It is deliberately specific: instead of general wording, it states which service receives which data — and at which points no data flows at all.
1. Controller
The controller for data processing on this website is:
Dienstleistungen24 Inh. Jim Eichholz
Ramlerstraße 2, 13355 Berlin, Germany
Email: kontakt@axr-systems.de · Telephone: 030 555 233 75
We have not appointed a data protection officer; the legal conditions requiring one do not apply to us. Please address data protection enquiries to the address given above with the subject line “Datenschutz”.
2. What you will not find here
Because listing what does not happen is often the quicker answer:
- No analytics or tracking services for audience measurement — no Google Analytics, no Matomo, no pixels from social networks. The one exception is ad delivery in blog articles, and that runs only after your explicit consent (section 10).
- No external font providers — all fonts are held on our own server.
- No embedded videos, maps or social media components that establish connections to third parties when the page is loaded.
- No sale and no disclosure of data for advertising purposes.
- No automated decision-making and no profiling within the meaning of Art. 22 GDPR.
3. Hosting
This website is hosted with RAIDBOXES (RAIDBOXES GmbH, Hafenstraße 32, 48153 Münster, Germany); the servers are located in Germany. The provider processes data on our behalf — in particular server log files — in order to deliver the site securely and reliably. A data processing agreement (Art. 28 GDPR) is in place. The legal basis is our legitimate interest in a secure, available service (Art. 6(1)(f) GDPR).
4. Server log files
Every page request generates technical data that your browser transmits automatically: shortened IP address, date and time, the address requested, the volume of data transferred, browser type and operating system, and the page visited previously, provided your browser sends it.
This data serves solely for secure operation, troubleshooting and defence against attacks. It is not combined with other data sources. The legal basis is Art. 6(1)(f) GDPR. The logs are deleted or anonymised after 30 days at the latest.
5. Cookies and storage on your device
We use as little as possible. Without your consent, only what is necessary for operation is stored (§ 25(2) TDDDG, German Telecommunications Digital Services Data Protection Act):
| Name | Type | Purpose and duration |
|---|---|---|
axr_consent |
Cookie | Stores your decision in the cookie banner (value v1:essential or v1:all). Duration one year, SameSite=Lax. Without this cookie we would have to ask you again on every visit. |
axr-theme |
Local storage | Remembers whether you chose the light or dark view. It stays on your device, is never transmitted to us, and you can delete it in your browser at any time. |
| WordPress system cookies | Cookie | Only for logged-in editors (session management). As a visitor you do not receive these cookies. |
| Google AdSense cookies | Cookie | Only after explicit consent, see section 10. |
You can change or withdraw your consent at any time with effect for the future via the cookie settings.
6. Contact form and enquiry assistant
If you write to us via the form or the guided enquiry assistant, we process the details you enter — name, email address, optionally telephone number and company, as well as your message and the answers given to the assistant — in order to respond to your enquiry.
The legal basis is Art. 6(1)(b) GDPR where your enquiry is aimed at a contract, otherwise our legitimate interest in responding (Art. 6(1)(f) GDPR). The details are stored in our WordPress database and additionally delivered to us by email. A technical field for detecting automated submissions is sent along and discarded immediately after the check. We delete enquiries as soon as they have been dealt with and no retention obligation remains — at the latest after three years, at the end of the year.
7. Our free tools
A closer look is worthwhile here, because the four tools work differently:
- The AI check, the ROI calculator and the GDPR quick check run entirely in your browser. Your answers and entries are neither transmitted to us nor stored by us. What you see in the address bar serves solely to let you call up or pass on the result again — where that link goes is entirely your decision.
- The visibility check retrieves the address you enter from our server. For this we process the internet address you enter as well as the technical response of the page checked. The legal basis is your instruction to carry out the check and our legitimate interest in operating the tool (Art. 6(1)(b) and (f) GDPR). Please enter only addresses you are entitled to have checked.
8. Newsletter
For the newsletter we use the double opt-in procedure: after you sign up you receive an email with a confirmation link. Only then do we add you to the distribution list. We store your email address, the time of sign-up and confirmation, and the IP address used in the process — the latter as evidence that the sign-up actually came from you.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time via the unsubscribe link in every email; we then delete your address from the distribution list. Your data is not passed on to third parties for advertising purposes.
9. Sending email
Outgoing emails — confirmations, replies to enquiries, newsletters — are sent via an authenticated outgoing mail server (SMTP) rather than the server’s default method. This improves deliverability and prevents our messages from being classified as forgeries. In doing so, the service provider engaged processes the recipient address and the content of the message on our behalf.
10. Advertising (Google AdSense)
In blog articles we display advertisements via Google AdSense (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The scripts required for this are loaded exclusively if you have previously given your consent in the cookie banner (Art. 6(1)(a) GDPR). Without consent, no connection to Google is established.
Where consent has been given, Google may set cookies and process usage data, including in third countries, in particular the USA. Google relies for this on standard contractual clauses and on certification under the EU-US Data Privacy Framework. Further details can be found in Google’s privacy policy. You can withdraw your consent at any time in the cookie settings.
11. Fonts, images and security
Fonts are delivered exclusively from our own server; there is no connection to external font providers such as Google Fonts.
Images are converted into a modern format on our server in order to reduce loading time and data volume. This too happens locally, without any third party being involved.
For protection we use safeguards against automated attacks. Failed login attempts may be logged along with the IP address — exclusively for registered accounts, not for ordinary visits. The legal basis is Art. 6(1)(f) GDPR.
12. Notifying search engines of new content
When we publish or change a page, our system automatically reports the address concerned to search engines (IndexNow). Only the address of the page is transmitted — no personal data and no information about visitors.
13. Recipients and processors
We only pass on personal data where this is necessary for operation. At present this concerns the hosting provider and the provider of the outgoing mail server. Data processing agreements (Art. 28 GDPR) are in place with both: they process the data solely on our instructions.
Google as an advertising service is a different case. Google processes the data arising from ad delivery for its own purposes and is a controller in its own right in that respect, not our processor. That is why advertising sits behind explicit consent which you can withdraw at any time (section 10 and the cookie settings). Beyond that, we only pass on data where we are legally obliged to do so.
14. Transfer to third countries
A transfer to countries outside the EU or the EEA only takes place in connection with the delivery of advertisements after your consent (section 10). For all other processing, the data remains within the European Union.
15. Retention periods
We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention periods. These periods are not merely a statement of intent: they are configured in the system and run automatically. The periods currently in force are:
- Enquiries via the contact form and the enquiry assistant: 12 months from receipt.
- Newsletter sign-ups without confirmation: 30 days.
- Unsubscribed newsletter addresses: 90 days after unsubscribing.
- Confirmed newsletter addresses: until you withdraw your consent.
- Server log files: a maximum of 30 days.
Deletion runs automatically and in two steps: first the record is taken out of day-to-day operation, after a further 30 days it is removed for good. Where an enquiry leads to an engagement, the resulting contract and invoice documents are subject to statutory commercial and tax retention periods; those documents are held outside this website.
16. Your rights
You have the right at any time to information about the data stored about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on a legitimate interest (Art. 21). You can withdraw consent you have given at any time with effect for the future (Art. 7(3)).
An informal message to kontakt@axr-systems.de is sufficient to exercise these rights. We reply within the statutory period of one month.
17. Right to lodge a complaint with the supervisory authority
Independently of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin
datenschutz-berlin.de
18. Changes to this statement
We adapt this statement when the processing changes — for instance because a service is added or discontinued. The current version is always available on this page.
This statement describes the actual state of processing to the best of our knowledge. It is not legal advice and does not replace a review by a law firm specialising in data protection law for the individual case.