Privacy policy

This English translation is provided for convenience. Only the German version is legally binding: German version. Information on the processing of personal data pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR). Last updated: August 2026.

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Company
INFONET Computer GmbH
Address
Robert-Perthel-Straße 72
50739 Köln
Germany
Represented by
Dipl.-Ing. Mohamed Khater
Phone
+49 221 984300-0
Email
[email protected]

Data protection officer: A data protection officer must be appointed if, as a rule, at least twenty persons are permanently engaged in the automated processing of personal data (§ 38(1) BDSG, German Federal Data Protection Act). Where this requirement is met in our case, you can reach our data protection officer using the contact details above, marked “Data protection officer”.

2. General information on data processing

We process personal data only to the extent that this is necessary to provide a functional and secure website and to deliver our services, or where another legal basis exists.

Where consent is required for processing, the processing takes place only after the relevant consent has been given.

This website does not use analytics or marketing cookies for visitors. No usage profiles are created for advertising purposes, and no personal data is transferred to advertising networks for advertising purposes.

3. Hosting and server log files

When you access this website, the hosting provider processes technically necessary information that your browser transmits automatically. This may include, in particular, the following data:

  • browser type and browser version
  • operating system used
  • referrer URL
  • host name of the accessing computer
  • date and time of the server request
  • page or file accessed
  • IP address

The processing serves to ensure secure, stable and technically error-free operation of the website and to detect and fend off attacks and abusive access.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website securely, reliably and without technical errors.

Storage period: Server log files are, as a rule, deleted after 30 days at the latest, unless longer storage is required in an individual case to investigate or fend off a specific security incident. The data is not combined with other data sources to create user profiles.

Hosting provider

This website is hosted by:

IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany

The servers are located in data centres within the European Union. Where IONOS processes personal data on our behalf, it does so on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Cloudflare content delivery and security network

Where our website or individual domain variants are delivered or protected via Cloudflare services, we use services provided by:

Cloudflare Germany GmbH
Rosental 7
80331 Munich

Parent company:
Cloudflare, Inc.
101 Townsend Street
San Francisco, CA 94107
USA

Cloudflare is used in particular to support the secure, fast and resilient delivery of our website and to fend off attacks and abusive access.

In the process, technically necessary connection data may be processed. This includes in particular the IP address, the web address accessed, the date and time of access, and technical information about the browser and device.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website securely, with good performance and resilience against outages, and in protecting it against cyber attacks.

Where Cloudflare processes personal data on our behalf, it does so on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Data transfers to the USA

It cannot be entirely ruled out that Cloudflare processes personal data outside the European Economic Area, in particular in the USA.

According to its own information, Cloudflare is certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF). Cloudflare can rely on this certification for transfers of personal data from the European Economic Area to the USA. In addition, or in cases where the Data Privacy Framework should not apply, Cloudflare provides for standard contractual clauses of the European Commission and, where necessary, supplementary safeguards.

Further information on data processing by Cloudflare can be found in Cloudflare’s privacy policy.

4. Contacting us

Contact form

If you send us an enquiry via our contact form, we process the data you enter, including the contact details provided, in order to handle your enquiry and to answer any follow-up questions.

Mandatory fields are only your name, email address and message; without this information we cannot answer your enquiry. Optional fields are company, phone number, topic and company size. These fields merely help us to route the enquiry to the responsible person more quickly; if they are left empty, we will still handle your enquiry.

To prevent automated submissions, the form contains a field that is invisible to you and a technical timestamp. Neither is stored, and neither allows any conclusions to be drawn about you personally. No external spam protection service is used.

As a rule, the data is not passed on to third parties unless there is a legal basis for doing so, the disclosure is necessary to handle your enquiry, or you have expressly consented.

Legal basis: Art. 6(1)(b) GDPR, where your enquiry relates to the initiation or performance of a contractual relationship. For other enquiries, the processing is based on Art. 6(1)(f) GDPR; our legitimate interest lies in handling and answering enquiries properly. Where we expressly ask you for consent, the legal basis is Art. 6(1)(a) GDPR.

Storage period

If your enquiry does not lead to a contractual relationship, we will, as a rule, delete the personal data stored in connection with the enquiry no later than six months after it has been fully dealt with, unless statutory retention obligations, legitimate interests or legal claims prevent deletion.

If a contractual relationship is established, or if the correspondence constitutes business records subject to retention requirements, the respective statutory retention periods apply. These may in particular be:

  • ten years for books, records, inventories, annual financial statements and other documents specified by law,
  • eight years for accounting vouchers,
  • six years for commercial and business letters and certain other documents relevant for tax purposes.

The specific retention period depends on the type and content of the documents concerned and on the applicable statutory provisions.

Contacting us by email or phone

If you contact us by email or phone, we process the personal data you provide in order to handle your enquiry. With regard to the legal basis and storage period, the above provisions apply accordingly.

5. TLS encryption

For security reasons and to protect confidential content, this website uses TLS encryption. You can recognise an encrypted connection in particular by the fact that the address of our website begins with “https://” and your browser indicates an encrypted connection.

This protects data transmitted between your browser and our server against unauthorised access by third parties during transmission.

6. Cookies and local storage

Cookies for visitors

During a normal visit to our publicly accessible website, we do not use any analytics, tracking or marketing cookies.

Technically necessary session cookie in the administration area

A password-protected administration area is available to our own employees at /verwaltung/. After successful login, a technically necessary session cookie (PHPSESSID) may be set there.

This cookie contains a randomly generated session identifier and serves exclusively to maintain the authenticated session technically. The cookie is deleted on logout or, at the latest, when the browser session ends. The area is not intended for visitors and is blocked for search engines.

Legal basis for access to the device: § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act), as the storage is strictly necessary to provide the administration service expressly requested. Where personal data is processed as a result, this is done on the basis of Art. 6(1)(f) GDPR; our legitimate interest lies in the secure technical provision of our internal administration area.

No prior consent is required for this technically necessary cookie.

7. External content and services

Our website is designed so that, as a rule, no fonts, maps, videos, analytics tools or comparable content are loaded directly from servers of external providers when the site is accessed normally.

Fonts, images and the program code required for display are, as a rule, provided via our own web infrastructure or via the hosting and security services described in this privacy policy. In particular, no connection to Google, Meta, YouTube or comparable platforms is established during a normal page view merely because you visit our website.

OpenStreetMap

On our contact page, we offer the option of displaying an interactive map of our location. The map data is provided by:

OpenStreetMap Foundation
St John’s Innovation Centre
Cowley Road
Cambridge CB4 0WS
United Kingdom

The interactive map is not loaded automatically when the page is accessed. As long as you have not agreed to it being displayed, only a locally provided placeholder or an image delivered from our own web infrastructure is shown. In this state, no connection to OpenStreetMap takes place.

Only when you expressly activate the map is a connection established to the servers of the map service. For technical reasons, your IP address in particular is transmitted to the provider in the process.

Legal basis: Art. 6(1)(a) GDPR on the basis of your prior consent.

An adequacy decision of the European Commission exists for the United Kingdom. The Commission renewed its finding of adequacy on 19 December 2025; the decision applies until 27 December 2031 unless it is repealed or amended beforehand.

Further information on the processing of personal data can be found in the privacy policy of the OpenStreetMap Foundation.

Storage of your consent decision

So that we do not have to ask you again on every page view about your decision regarding external content, your choice is stored locally in your browser’s web storage. The key infonet-einwilligung is currently used for this.

The stored information generally remains on your device and is not transmitted to us. It contains no user or advertising identifier assigned by us and is not used to create a usage profile. Only the information needed to respect your decision is stored, in particular the status of your decision, the service concerned and, where applicable, the time of the decision.

The local storage serves exclusively to manage your privacy decision as you have requested. Where the storage is strictly necessary to provide this expressly requested consent management, it is based on § 25(2) no. 2 TDDDG.

You can change or withdraw your decision at any time with effect for the future via the Privacy settings item in the footer of our website. Deleting the local website data in your browser also removes the stored decision; the next time you access external content that requires consent, you will be asked for your decision again.

The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent before its withdrawal.

External links

Our website may contain links to external websites and services, for example to social networks, manufacturers, partner companies or map services. As a rule, a normal link does not establish a connection to the linked provider merely because you access our website. Only when you actively click such a link do you leave our website, and the privacy provisions of the respective external provider then apply.

8. Your rights

Where we process personal data relating to you, you have in particular the following rights, subject to the statutory requirements:

  • Access to the data processed about you pursuant to Art. 15 GDPR,
  • Rectification of inaccurate data and completion of incomplete data pursuant to Art. 16 GDPR,
  • Erasure of personal data pursuant to Art. 17 GDPR,
  • Restriction of processing pursuant to Art. 18 GDPR,
  • Data portability pursuant to Art. 20 GDPR,
  • Objection to certain processing pursuant to Art. 21 GDPR,
  • Withdrawal of consent at any time with effect for the future pursuant to Art. 7(3) GDPR.

To exercise your rights, an informal message to [email protected] is sufficient.

We handle data protection requests within the statutory time limits. Under Art. 12(3) GDPR, information is, as a rule, provided without undue delay and in any event within one month of receipt of the request. This period may be extended where the statutory conditions are met.

9. Right to object pursuant to Art. 21 GDPR

Processing based on legitimate interests

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you.

Following a valid objection, we will, as a rule, no longer process the personal data concerned, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

You can send your objection in particular to [email protected] or make it by phone on +49 221 984300-0.

Direct marketing: Where personal data is processed for direct marketing purposes, you have the right under Art. 21(2) GDPR to object at any time to the processing of personal data concerning you for such marketing. Following your objection, your personal data will no longer be processed for these purposes.

10. Right to lodge a complaint with a data protection supervisory authority

Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection law.

The supervisory authority responsible for our company is:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Phone +49 211 38424-0 · www.ldi.nrw.de

Irrespective of this, you may, as a rule, also contact any other data protection supervisory authority that is competent under the statutory provisions.

11. Currency and amendment of this privacy policy

We review this privacy policy regularly and adapt it when changes to our website, the technical procedures used, our data processing or the legal situation make this necessary.

The current version published on this website applies.

Last updated: August 2026