Legal

Privacy

This is a translation for your convenience. If the two versions differ, the German version prevails.

The essentials in brief

This website works without advertising, without third-party tracking and without a cookie banner. Fonts, images and scripts are served from our own server. The visitor statistics run on our own server, set no cookies and truncate your IP address. If you write to us, we use your details only to reply to you.

1. Who is responsible (controller)

WERTEWIRKER GmbH, Im Holderbusch 32, 76872 Minfeld, Germany, represented by its managing director Karsten Zimmer. Email: info@wertewirker.de, phone: +49 7275 4024 999.

For any question about data protection, and to exercise your rights, an informal message to this address is all it takes.

2. Visiting the website and server logs

The website runs on a server we rent from IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. IONOS processes the data on our behalf.

For every request, the web server logs: date and time, your IP address, the address requested, the status code, the amount of data transferred, the page you came from (if your browser sends it) and your browser’s identifier. We need this data to deliver the site, find errors and fend off attacks. Logs containing the full IP address are deleted automatically after 14 days. For longer-term analysis – such as which pages are not found or how much load automated requests cause – we keep a second log in which the IP address is truncated to the point where it can no longer be traced to an individual internet connection. We delete this log after 26 weeks. We do not combine the logs with other data.

The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).

3. Contact form, intro call and email

When you submit one of the forms, we receive your details as an email: name, email address, your message and – for the intro call – the optional details on role, organisation, topic, technology and preferred dates. None of this is stored on the web server, and the logs of the form service contain neither names nor email addresses nor IP addresses.

To send the email we use SMTP2GO (Sand Dune Mail Ltd, 96-106 Manchester Street, Christchurch 8011, New Zealand) via its servers in the EU. SMTP2GO processes the email on our behalf and keeps the email’s header data (sender, recipient, subject, time) for 35 days so that delivery problems can be resolved. The European Commission has recognised New Zealand as providing an adequate level of data protection. The email arrives in our mailbox at Microsoft 365 (Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). Microsoft processes the data on our behalf and stores it in data centres in the EU. Where data is transferred to Microsoft Corporation in the USA in individual cases, this is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, under which Microsoft is certified.

To protect against spam and abuse, we check every enquiry automatically: a field invisible to humans must remain empty, a timestamp shows whether the form was submitted unrealistically fast, and the number of enquiries per IP address and per day is limited. So that the same message is not delivered several times, we keep a one-way checksum of the message text in memory until midnight. Obvious spam is discarded; suspicious messages are delivered and flagged. This does not involve any decision with legal effect for you; if your enquiry remains unanswered, please write to us directly.

We use your details to answer your enquiry and – if it leads to working together – to prepare that work. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract), otherwise our legitimate interest in answering enquiries (Art. 6(1)(f)). For spam protection, the basis is our legitimate interest in a working mailbox (Art. 6(1)(f)). We delete enquiries once they have been dealt with, after twelve months at the latest – unless a contractual relationship arises or we are legally required to keep them for longer.

4. Visitor statistics with Matomo

We would like to know which pages are read and where links lead nowhere. For this we use the open-source software Matomo on our own server (analytics.wertewirker.de). The data goes to no one else.

We have set Matomo up to be sparing with data: no cookies are set and nothing is stored on your device. Your IP address is truncated by its last two bytes before it is stored. We record the page visited, the page you came from, date and time, device type, browser and operating system, roughly which country you are visiting from, as well as clicks on individual buttons and the submission of a form (only the fact that a form was submitted, not its content). You are not recognised across several days. We delete the raw data after 180 days; after that, only aggregated figures remain, which do not relate to individuals.

The legal basis is our legitimate interest in improving the website (Art. 6(1)(f) GDPR). Because Matomo neither stores nor reads anything on your device, no consent under Section 25 of the German Telecommunications and Digital Services Data Protection Act (TDDDG) is required.

How to object: switch on “Do Not Track” or “Global Privacy Control” in your browser. We respect both, and your visit is then not counted at all. However, we will then not notice if you run into an error, such as a link leading nowhere – in that case we would be glad of a short note. You can also simply write to us.

5. Comments on the blog

You can comment below the blog articles. For this we use the open-source software Remark42 on our own server (kommentare.wertewirker.de). The comment section is only loaded when you scroll close to it.

To comment, you sign in – either with a sign-in link that we send to your email address (sent via SMTP2GO, see section 3), or with your account at LinkedIn, Microsoft, Google or Apple. A connection to one of these providers is only established when you click on it. The provider learns that you are signing in to wertewirker.de; from the provider we receive your name, an identifier and, where applicable, your profile picture and email address. Processing by the provider is governed by its own privacy notice (LinkedIn Ireland Unlimited Company, Microsoft Ireland Operations Ltd., Google Ireland Ltd., Apple Distribution International Ltd., all in Ireland).

We store: your display name, an identifier derived from your sign-in, your profile picture (as a copy on our server), your comment with date and time, and a one-way short hash of your IP address in order to detect abuse. We store your email address only if you subscribe to notifications about replies; you can unsubscribe in every notification. After sign-in, the comment section sets cookies that keep you signed in and protect forms against abuse. They are strictly necessary for the comment function (Section 25(2) no. 2 TDDDG) and disappear when you sign out or when they expire.

Your name, profile picture and comment are publicly visible. Comments remain until you or we delete them. You can edit your comment for a short time after posting; after that, we delete comments and your user account on request – a message is enough. The legal basis is our legitimate interest in enabling discussion below the articles and protecting it against abuse (Art. 6(1)(f) GDPR).

6. Security reports from your browser

This website gives your browser strict security rules (Content Security Policy and Permissions Policy). If something violates them – for example a browser extension injecting content – your browser automatically sends a technical report to our service provider URIports (URIports B.V., Netherlands), which evaluates it for us. The report contains the page address concerned, the rule violated and your browser’s identifier. For technical reasons URIports sees your IP address when receiving the report but, according to its own statements, does not store it. URIports’ servers are located in the Netherlands. Names, form input or cookies are not included. The same applies to network errors (Network Error Logging): if your browser cannot reach this website at some point within one day of your visit – for example because of a timeout – it reports this to URIports in a fraction of cases so that we notice outages. The report contains the address, the type of error and the time. The legal basis is our legitimate interest in the security of the website (Art. 6(1)(f) GDPR).

7. What is stored on your device

The website itself sets no cookies. If you switch between the light and dark colour scheme, your browser remembers this choice in its local storage so that it is kept for your next visit. The entry is not transmitted to us and can be deleted in your browser settings. This is necessary for the function you requested (Section 25(2) no. 2 TDDDG). The only other items are the sign-in cookies of the comment section, if you sign in there (section 5).

Links to LinkedIn and other sites are ordinary links. Data only flows once you click them; that provider’s privacy notice then applies. There is no embedded third-party content (videos, maps, fonts, social media buttons) on this website.

9. Who receives your data

Only the service providers named in this policy, who work on our behalf and according to our instructions: IONOS (server), SMTP2GO (email delivery), URIports (security reports) and Microsoft (mailbox). Each of them receives only the data it needs for its task: IONOS the data that arises from operating the server, SMTP2GO and Microsoft the emails from the forms and the comment section, URIports the technical reports from your browser. So your message does not go to URIports, and the visitor statistics do not leave our server at all. In addition, there is the sign-in provider if you use it to sign in to the comment section (section 5); your comment itself is public. We do not sell data and do not pass it on for advertising purposes.

10. Your rights

You have the right to access, rectification, erasure, restriction of processing and data portability (Arts. 15–20 GDPR).

Right to object: Where we process data on the basis of a legitimate interest (sections 2 to 6), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). You can object to the statistics without giving reasons, see section 4.

You may also lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), Hintere Bleiche 34, 55116 Mainz, Germany.

You are under no obligation to provide us with data. Without a name and email address, however, we cannot answer an enquiry. We do not make automated decisions within the meaning of Art. 22 GDPR.

11. Last updated

September 2026. If anything changes technically on the website, we will update this policy.