← Back to website

Privacy Policy

This is a convenience translation. The German version (Datenschutzerklärung) is the legally binding one.

Protecting your personal data matters to us. Below we explain which data is processed when you visit this website, for what purpose and on which legal basis.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Daniel Schroeder
Meller Straße 52
33613 Bielefeld
Germany
Email: kontakt@corresa.de

2. Hosting and server log files

This website is operated on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. When the website is accessed, information transmitted by your browser is automatically processed in so-called server log files. This includes in particular: IP address, date and time of access (timestamp), the browser used and its version (user agent), and the requested page.

The processing serves the secure and stable operation of the website and the prevention and investigation of attacks. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR. The log data is stored only for as long as it is required for these purposes and is then deleted or overwritten. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner Online GmbH; it covers all processing operations run on this server (website, database, audience measurement).

3. Contact form

If you send us an inquiry via the contact form, we collect the data you provide: name, email address and your message. This data is stored in a PostgreSQL database on the same server (Hetzner, see above).

The purpose of the processing is to handle and respond to your inquiry. The legal basis is Art. 6(1)(b) GDPR (steps taken prior to entering into a contract) and/or Art. 6(1)(f) GDPR (our legitimate interest in responding to inquiries). The data is stored until your inquiry has been fully dealt with and any statutory retention obligations have expired.

Providing your data in the contact form is voluntary; it is neither legally nor contractually required. Without it, however, we cannot process and answer your inquiry.

4. Spam and abuse protection

To limit the number of form submissions and prevent abuse, we store the sender's IP address exclusively as a hash value computed with a secret key that exists only on our server (HMAC-SHA-256). Without the key, this value is practically impossible for third parties to reverse; we use it solely to detect repeated form submissions from the same source, and it is deleted automatically after 60 minutes. In addition, we use a hidden form field (honeypot) that is not visible to humans and merely detects automated submissions. No cookies are set for this protection. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR in preventing spam and abuse.

5. Notifications and lead management (processor Brevo)

We are notified by email when new form submissions arrive. To send these notifications we use the email service provider Brevo (Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany). Brevo acts for us as a processor within the meaning of Art. 28 GDPR; a data processing agreement is in place for this. According to the provider, processing takes place on servers within the European Union. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR in handling your inquiry reliably and promptly.

In addition, we store the contact details provided in the contact form (name and email address) in Brevo's CRM system so that we can process and manage your inquiry in a traceable way. Here too, Brevo acts as a processor. This data is not used for advertising or newsletters; we would obtain your separate consent for that. We delete the CRM entry as soon as it is no longer required for managing your inquiry. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR in the traceable management of inquiries.

We operate our email mailbox (kontakt@corresa.de) with Microsoft 365 (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). In this respect, Microsoft acts as a processor; according to the provider, the data is processed within the EU (EU Data Boundary).

6. Audience measurement with Umami

For statistical analysis and to improve our offering, we record in anonymized form how this website is used, provided audience measurement is active. For this we use Umami, an analytics tool that we run ourselves on our own server (Hetzner, see above). No data is transferred to third parties. The statistics collected are aggregated and contain no personal data.

Umami works without cookies and without storing information on your device. Only aggregated details are recorded, such as pages visited, approximate location at country or region level, the referring website, and browser type and device category. Your IP address is not stored; it is used only to generate an anonymous, day-specific identifier that does not allow any conclusions about your identity.

The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR in designing our website to meet demand and in its statistical analysis.

7. Cookies and local storage

This website uses no cookies, neither for advertising nor for tracking, and embeds no third-party tracking services. The web fonts used are self-hosted; no external provider such as Google Fonts is contacted.

If you choose a display mode (light or dark) via the theme switch, this setting is stored in your browser's local storage (key “theme”). This storage is strictly necessary for the function you explicitly requested and is therefore permitted without consent under § 25 Abs. 2 Nr. 2 TDDDG. No personal data is transmitted to us or to third parties in the process; you can delete the entry at any time via your browser settings.

8. No transfers to third countries, no automated decision-making

Your data is not transferred to countries outside the European Union or the European Economic Area. All processing operations mentioned take place on servers in Germany or the EU. There is also no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

9. Your rights as a data subject

Within the statutory framework, you have the right to:

Insofar as processing is based on consent, you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected.

You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR. The supervisory authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, www.ldi.nrw.de. However, you may also contact any other supervisory authority.

10. Contact for data protection matters

For questions about data protection or to exercise your rights, you can reach us at kontakt@corresa.de.

Last updated: July 2026