WaGe-Control management consulting
HomeHow I workExperienceAbout meA change of pace?➜ContactDE|EN

Data protection

Privacy policy

1. Data protection at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information can be found in the sections below.

Who is responsible?

Data processing on this website is carried out by me as the operator. My contact details can be found in the section „Controller“.

How is your data collected?

First, through data you provide to me – for example when you send me an email or call me. This website contains no contact form and no other input fields; you cannot submit any data through the page itself.

Second, the server automatically records technical data when you visit the website, such as browser, operating system or time of access. This collection is technically necessary and is not made dependent on your consent. The section „Server log files“ describes exactly which data this is.

What do I use your data for?

The automatically collected technical data is used solely to deliver the website reliably and to protect the server against attacks. No analysis of your user behaviour takes place. Data you provide by email or telephone is used solely to handle your enquiry. No contracts can be concluded through this website.

Analytics and third-party tools

This website uses no analytics, tracking or statistics software. Your browsing behaviour is not evaluated.

2. Controller

The controller responsible for the processing of personal data on this website is:

Walter Gebert
Management Consulting
Grotzstraße 23
87448 Waltenhofen
Germany

Phone: +49 162 604 5721
Email: walter.gebert@wage-control.com

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.

3. Hosting and server operation

Website operation and processing on my behalf

The technical operation of this website is carried out by Inmati GmbH, Grotzstraße 23, 87448 Waltenhofen, Germany. It processes personal data exclusively on my behalf and according to my instructions. A data processing agreement under Article 28 GDPR is in place, which also governs the use of the sub-processors named below.

External hosting

The website runs on server infrastructure provided by

Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany

The server is located in the Falkenstein data centre in Germany. No personal data is transferred to a third country outside the European Union.

The data processed in the course of hosting is limited to the technical access data required to deliver the website – in particular IP addresses. The section „Server log files“ describes exactly which data this is and how long it is stored. This website contains no forms, so no data entered by you is processed.

A professional host is used in the interest of secure, fast and reliable delivery of this website. The legal basis is Article 6(1)(f) GDPR.

Further information can be found in Hetzner's privacy policy: hetzner.com/legal/privacy-policy

Detection and prevention of attacks

Like any publicly reachable server, this server is subject to automated attack attempts such as vulnerability scans or login attempts with guessed credentials. To protect against these, the software CrowdSec is used. It evaluates the server log files and blocks IP addresses from which attacks demonstrably originate.

When an IP address is identified as a source of attacks, it is transmitted to the provider

CrowdSec SAS
20 rue Maurice Arnoux
92120 Montrouge
France

and block lists compiled from the reports of all participants are received in return.

What is transmitted: the IP address the attack originates from, the network identification derived from it (AS number and country), the detected attack pattern including its version, the start and end of the observation and the number of observed events, the measure taken in response and its duration, an identifier of the server instance, and technical identifiers of the report itself.

What is not transmitted: log files, pages requested, browser identifiers (user agent), or data belonging to regular visitors of this website.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest is protecting the server and the availability of this website against attacks. The provider is established in the European Union; no transfer to a third country takes place.

Further information: crowdsec.net/privacy-policy

4. Data collection on this website

Cookies

This website sets no cookies and uses no comparable recognition technologies such as local storage, session storage or device fingerprinting. Consent under Section 25(1) TDDDG is therefore not required, and no consent banner is needed.

Server log files

When this website is accessed, information is automatically stored in server log files which your browser transmits. These are:

  • browser type and browser version
  • operating system used
  • referrer URL
  • hostname of the accessing computer
  • time of the server request
  • amount of data transferred
  • IP address

This data is not merged with other data sources.

Retention. A distinction is made according to the purpose of the processing:

  • To detect and prevent attacks, the full IP address is processed (see „Detection and prevention of attacks“). All data stored for this purpose is deleted after 48 hours at the latest.
  • For technical operation and troubleshooting, access data is processed with a truncated IP address. For IPv4 the last block of digits is removed, for IPv6 correspondingly, so that attribution to an individual connection is generally no longer possible. This data is deleted after 14 days at the latest.

This data is not included in any backup, so the periods stated above are the actual retention periods.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in the technically error-free presentation and the security of this website.

Enquiries by email or telephone

If you contact me by email or telephone, your enquiry including the personal data arising from it is stored and processed for the purpose of handling your request. I do not pass this data on without your consent.

If your enquiry relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, processing is based on my legitimate interest in handling the enquiries addressed to me effectively (Article 6(1)(f) GDPR).

The data remains with me until you ask me to delete it or the purpose for storage no longer applies, for example once your request has been dealt with. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.

Email is sent and received via Microsoft 365 (Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). Microsoft processes the content of your message as a processor in order to deliver it and keep it available in the mailbox.

5. External content and links

This website embeds no third-party content, fonts, scripts, maps or media. All files are served exclusively from its own server. Visiting this website therefore establishes no connection to third-party servers, and no data is transmitted to third parties.

This website contains a link to a separately operated Via de la Plata application. When you follow this link, you leave this website. The privacy information provided on the destination website applies to the processing of personal data there.

6. General information and mandatory disclosures

Data protection

I take the protection of your personal data very seriously and treat personal data confidentially and in accordance with statutory data protection provisions and this privacy policy.

Please note that data transmission over the internet – for example when communicating by email – can have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Storage period

Unless a more specific storage period is stated in this privacy policy, your personal data remains with me until the purpose for processing no longer applies. If you make a legitimate request for erasure or withdraw consent, your data will be deleted unless there are other legally permissible grounds for storing it, such as tax or commercial retention periods; in that case, deletion follows once those grounds cease to apply.

Legal bases for processing

Where you have consented to processing, it is carried out on the basis of Article 6(1)(a) GDPR. Where your data is required to perform a contract or to carry out pre-contractual measures, processing is based on Article 6(1)(b) GDPR. Where it is required to comply with a legal obligation, processing is based on Article 6(1)(c) GDPR. Otherwise, processing may be based on a legitimate interest under Article 6(1)(f) GDPR. The relevant legal basis in each case is stated in the respective sections of this policy.

Recipients of personal data

I pass personal data to external parties only where this is necessary to perform a contract, where I am legally obliged to do so, where there is a legitimate interest under Article 6(1)(f) GDPR, or where another legal basis permits the disclosure. Where processors are used, data is passed on only on the basis of a valid data processing agreement. The parties involved in connection with this website are named in sections 3 and 4.

Withdrawal of your consent

Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

Right to object to data collection in particular cases and to direct marketing (Article 21 GDPR)

IF DATA PROCESSING IS BASED ON ARTICLE 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, YOUR PERSONAL DATA CONCERNED WILL NO LONGER BE PROCESSED UNLESS THERE ARE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ARTICLE 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING IN SO FAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ARTICLE 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of infringements of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. The authority competent for me is:

Bavarian Data Protection Authority (BayLDA)
Promenade 18
91522 Ansbach
Germany

This right exists without prejudice to any other administrative or judicial remedy.

Right to data portability

You have the right to have data that I process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done where it is technically feasible.

Access, rectification and erasure

Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the processing, and where applicable a right to rectification or erasure of this data. You can contact me at any time about this and any further questions.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. This right exists in particular where you contest the accuracy of the data, where the processing was or is unlawful, where I no longer need the data but you require it to establish or defend legal claims, or where you have objected under Article 21(1) GDPR and the balancing of interests has not yet been concluded.

Where you have restricted processing, this data may – apart from being stored – only be processed with your consent, or to establish, exercise or defend legal claims, to protect the rights of another person, or for reasons of important public interest.

SSL/TLS encryption

For security reasons this site uses SSL/TLS encryption. It protects the retrieval of this website: third parties cannot read which pages you access while in transit, nor alter the content. You can recognise an encrypted connection by the browser address bar changing from „http://“ to „https://“ and by the padlock symbol in your browser bar.

As this website contains no input fields, you do not send any data through the page itself. For an enquiry by email, the note in the section „Data protection“ applies: the transmission of emails is not protected by this encryption.

Objection to advertising emails

The use of contact details published in the context of the legal notice obligation for sending advertising and information material not expressly requested is hereby objected to. I expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam email.

7. Currency of this policy

This privacy notice will be updated if the data processing on this website or the services used change.

Last updated: September 2026

Language

This is a translation provided for convenience. In case of discrepancies, the German version of this privacy policy prevails.

WaGe-ControlManagement Consulting · Walter Gebert
HomeLegal notice