Controller
Overview
This privacy policy explains which personal data is processed when you visit this website, send enquiries, or use optional services. Personal data means any information that can identify you directly or indirectly.
We process personal data only where a legal basis exists, especially to respond to enquiries, carry out pre-contractual measures, provide the website securely, or on the basis of your consent.
Your rights as a data subject
You may request information about the personal data stored by us and how it is processed. You also have the right to rectification, erasure, restriction of processing, objection to processing, and data portability where the legal requirements are met.
If you have given consent, you can withdraw it at any time with effect for the future. You may also lodge a complaint with a competent supervisory authority. A list of supervisory authorities is available from the German Federal Commissioner for Data Protection and Freedom of Information.
Website delivery and server logs
When the website is accessed, technically necessary data is processed so that pages can be delivered and operated securely. This may include IP address, date and time of access, requested URL, referrer, browser type, operating system, and technical status information.
The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is stable, secure, and error-free website operation as well as abuse and attack prevention.
Hosting and processors
Technical service providers may be used to operate this website. Where service providers process personal data on our behalf, this is done under suitable data processing agreements and only according to our instructions.
When selecting service providers, we consider appropriate technical and organisational safeguards, including access controls, encryption, data minimisation, and traceable deletion concepts.
Contact forms and email enquiries
When you contact us by form or email, we process the data you provide in order to respond to your enquiry and handle possible follow-up questions. This usually includes your name, email address, company, and message.
The legal basis is our legitimate interest in simple and traceable communication under Art. 6 para. 1 lit. f GDPR. If your enquiry relates to a quote or engagement, processing also takes place for pre-contractual measures under Art. 6 para. 1 lit. b GDPR.
Enquiry data is deleted no later than six months after final processing unless a contractual relationship is formed. If a contractual relationship exists, statutory retention periods under commercial and tax law apply.
Providing your data is voluntary. Without your name, email address, and enquiry content, however, we usually cannot process your message meaningfully.
Cloudflare Turnstile
We use Cloudflare Turnstile to protect forms from spam and automated abuse. Technical data such as IP address, browser information, and interaction signals may be processed. The legal basis is Art. 6 para. 1 lit. f GDPR, our legitimate interest in security and abuse prevention.
Turnstile is used solely for security checks. The check helps us determine whether an enquiry is submitted by a natural person or automated system. Cookies or comparable technologies may be used where necessary for this security function.
Cookies, local storage, and Matomo analytics
This website does not use analytics cookies or browser local storage for analytics. For this reason, no analytics cookie consent banner is shown.
We use self-hosted Matomo at analytics.sternberg-consulting.com to measure website usage. Matomo is operated with tracking cookies disabled. The data may include page views, referrers, campaign parameters, downloads, outbound links, clicks on contact methods, movement from knowledge to service pages, form status including a coarse completion-time range, scroll depth, active engagement time, FAQ opens, technical device data, and coarsely classified performance metrics such as LCP, CLS, and INP. Form-field contents are not sent to Matomo.
The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest is understanding website usage, improving content, detecting technical issues, and measuring enquiries more reliably. IP addresses are anonymised in Matomo; the data is not used for advertising, retargeting, or selling personal data.
The browser's "Do Not Track" signal is respected. You can also prevent measurement by using browser tracking protection or content blockers.
External links
This website contains links to external websites, for example accreditation bodies, specialist information, or social profiles. When you open external links, the privacy rules of the respective provider apply.
Recipients and categories of recipients
Personal data is passed to third parties only where this is required to process your enquiry, a legal obligation exists, you have consented, or a legitimate interest applies. Possible recipients include technical service providers, hosting providers, email providers, tax advisers, or authorities where legally required.
International transfers
If service providers outside the European Union or European Economic Area are used, transfers take place only on the basis of appropriate safeguards, such as an adequacy decision, standard contractual clauses, or your explicit consent.
Security
We use technical and organisational measures to protect personal data against loss, misuse, unauthorised access, and unauthorised disclosure. These measures include encrypted transmission, access controls, and regular review of the services used.
Right to object under Art. 21 GDPR
You have the right, for reasons arising from your particular situation, to object at any time to processing of personal data based on Art. 6 para. 1 lit. f GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds or the processing serves to assert, exercise, or defend legal claims.
Changes to this privacy policy
We update this privacy policy when legal requirements, technical services, or our processing activities change.