The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data are all data with which you can be personally identified. Detailed information on the topic of data protection can be found in our privacy policy listed below this text.
Data processing on this website is carried out by the website operator. You can find their contact details in the section "Notice of the Responsible Body" in this privacy policy.
Your data is collected partly by you providing it to us. This can be, for example, data that you enter in a contact form.
Other data is collected automatically or after your consent when visiting the website through our IT systems. These are primarily technical data (e.g., internet browser, operating system, or time of the page visit). The collection of this data happens automatically as soon as you enter this website.
Some of the data is collected to ensure the error-free provision of the website. Other data can be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data is also processed for contract offers, orders, or other service requests.
You have the right at any time to obtain free information about the origin, recipients, and purpose of your stored personal data. You also have the right to request correction or deletion of this data. If you have given consent for data processing, you can revoke this consent at any time for the future. Furthermore, you have the right, under certain circumstances, to request the restriction of processing your personal data. Additionally, you have the right to lodge a complaint with the responsible supervisory authority.
For this and further questions regarding data protection, you can contact us at any time.
We host the content of our website with the following provider:
This website is externally hosted. The personal data collected on this website is stored on the servers of the host(s). This can mainly include IP addresses, contact inquiries, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.
The external hosting is carried out for the purpose of contract fulfillment towards our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast, and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR). If a corresponding consent was requested, processing is carried out exclusively based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, as far as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. The consent can be revoked at any time.
Our host(s) will only process your data to the extent necessary to fulfill their service obligations and follow our instructions regarding this data.
We use the following host:
IP-Projects GmbH & Co. KG
Am Vogelherd 14
D - 97295 Waldbrunn
We have concluded a contract on order processing (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the processor processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations as well as this privacy policy.
When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.
We point out that data transmission over the internet (e.g., communication by email) can have security vulnerabilities. Complete protection of data against access by third parties is not possible.
The responsible body for data processing on this website is:
AccessGranted X GmbH
Albert-Einstein-Straße 1
95028 Hof (Saale)
Phone: +49 (0) 123 44 55 66
Email: hello@access-granted.de
The responsible body is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a justified deletion request or revoke consent for data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will take place after these reasons cease to apply.
If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, if special categories of data according to Art. 9 para. 1 GDPR are processed. In case of an explicit consent to the transfer of personal data to third countries, data processing also takes place on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing also takes place on the basis of § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data is required for contract fulfillment or to carry out pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if this is necessary to fulfill a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR. Data processing may also be based on our legitimate interest according to Art. 6 para. 1 lit. f GDPR. The respective relevant legal bases are explained in the following paragraphs of this privacy policy.
As part of our business activities, we work with various external entities. This sometimes requires transmitting personal data to these external entities. We only pass on personal data to external parties if this is necessary for contract fulfillment, if we are legally obliged to do so (e.g., data transfer to tax authorities), if we have a legitimate interest in the transfer according to Art. 6 para. 1 lit. f GDPR, or if another legal basis allows data transfer. When using processors, we only transfer customers personal data based on a valid contract on order processing. In the case of joint processing, a contract on joint processing is concluded.
Many data processing operations are only possible with your explicit consent. You can revoke a given consent at any time. The legality of the data processing carried out until revocation remains unaffected by the revocation.
IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RELEVANT LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING SERVES THE ASSERTION, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION ACCORDING TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION ACCORDING TO ART. 21 PARA. 2 GDPR).
In case of violations of the GDPR, data subjects have the right to complain to a supervisory authority, especially in the member state of their habitual residence, workplace, or place of the alleged infringement. The right to complain is without prejudice to any other administrative or judicial remedy.
You have the right to receive data that we process based on your consent or in fulfillment of a contract, in a structured, common, and machine-readable format. You also have the right to transmit this data to another responsible party without hindrance from us, as far as technically feasible.
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as requests you send to us as the site operator. You can recognize an encrypted connection by the "https://" and the lock icon in the address bar of your browser.
If SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
This data is not merged with other data sources.
The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website; for this purpose, the server log files must be collected.
To analyze and optimize the use of our website, we use a self-developed statistics function that runs exclusively on our own servers. No cookies are set, and no information is stored on or read from your device; a consent banner is therefore not required (Section 25 of the German Telecommunications Digital Services Data Protection Act, TDDDG, does not apply).
When you access a page, we collect the date and time of access, the page path accessed, the domain of the referring page (referrer, without the full URL), your browser language, and whether a mobile device or a desktop computer was used. To roughly distinguish repeat visits within the same day, we additionally compute a hash value from your IP address, your browser user agent, and the current date (SHA-256, truncated). Your IP address is processed only briefly to compute this hash value and is not stored in plain text. This hash value changes automatically every day and does not allow any conclusion about your identity; recognition beyond the respective day or across multiple devices is not possible.
In addition, and completely separate from the data described above, without any link to an individual session or visitor, we collect purely aggregated daily counters on how far visitors scroll on average on individual pages (in 25 percent increments) and how often selected buttons and links (for example the contact button, or cross-references between industry and compliance pages) are clicked. These counters never allow us to determine which individual person visited which page at what time, or which path they took through the website.
All of this data is processed on the basis of our legitimate interest (Art. 6 para. 1 lit. f GDPR) in the technically error-free presentation, security, and needs-based design of our website. This data is not merged with other data sources, not passed on to third parties, and not used for advertising or profiling purposes.
If you contact us by email, phone, or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this was requested; consent can be revoked at any time.
Data sent to us via contact inquiries remains with us until you request its deletion, revoke your consent to its storage, or the purpose for which the data was stored no longer applies (e.g., after your request has been fully processed). Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
On our website we offer a free, automated Security Check that allows you to have a domain you enter checked for publicly visible security characteristics (e.g., email security settings, open network services, TLS certificates, DNS configuration, publicly known vulnerabilities). The scan is carried out exclusively against publicly accessible information of the entered domain; no intervention into third-party IT systems takes place.
When using this service we collect and process the domain you entered, your IP address, and the User-Agent of your browser (for abuse and fraud prevention, in particular to limit the number of requests per IP address), as well as the technical results of the automated scan.
Processing is carried out on the basis of our legitimate interest (Art. 6 para. 1 lit. f GDPR) in providing this service, as well as to prepare a possible contract (Art. 6 para. 1 lit. b GDPR) if you subsequently request the full report. The storage duration is governed by the "Storage Duration" section above.
If you request the full report following a Security Check, we additionally collect your first and last name, your email address (this must belong to the checked domain), the company name, and optionally your job title, phone number, and whether you would like to be called back.
We use a double opt-in procedure: the full report is only created and made accessible after you confirm your email address via a link sent to you.
The legal basis is Art. 6 para. 1 lit. b GDPR (carrying out pre-contractual measures at your request).
To create a generally understandable summary of the technical scan results in the PDF report, we use the AI platform Claude by Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. Only the technical scan results of the checked domain are transmitted for this purpose, not names, email addresses, or any other directly identifying contact data of the requesting person.
Since Anthropic is based in the United States, this involves a transfer of data to a third country. This transfer is based on the EU Standard Contractual Clauses (Module 2, controller to processor) under Art. 46 para. 2 lit. c GDPR, which are automatically part of the Anthropic data processing agreement. In addition, Anthropic is certified under the EU-U.S. Data Privacy Framework.
Processing is carried out on the basis of our legitimate interest in providing an understandable presentation of technical results (Art. 6 para. 1 lit. f GDPR).
In the Security Check area of our website we use a session cookie to protect our forms against Cross-Site-Request-Forgery attacks (CSRF token). This cookie is automatically deleted at the end of your browser session.
We also use your browser local storage (localStorage) to show you the same status of your request (e.g., "confirmation pending" or "report ready") when you return to the result page, without you having to start the process again. This stores an access token belonging to your request, as well as the contact data you entered (name, email address, company) to pre-fill an optional appointment booking form. This data remains exclusively on your device, is not transmitted to us, and is automatically deleted after two days at the latest.
Both storage processes are technically required to provide the function you have expressly requested (form protection and status display of your own request); they do not serve analysis or advertising purposes and therefore, in our assessment, do not require separate consent under Section 25 para. 1 TDDDG.
This Privacy Policy also applies to the customer platform at https://app.access-granted.de.