Privacy Policy

Preamble

With the following Privacy Policy, we would like to inform you about the types of personal data (hereinafter also referred to as “data”) we process, the purposes for which we process it, and the scope of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and within external online platforms, such as our social media profiles (hereinafter collectively referred to as the “Online Offering”).

The terms used are gender-neutral.

Effective as of: July 29, 2026

Table of Contents

  • Preamble
  • Data Controller
  • Overview of Processing Activities
  • Applicable Legal Bases
  • Security Measures
  • Disclosure of Personal Data
  • International Data Transfers
  • General Information on Data Storage and Deletion
  • Rights of Data Subjects
  • Provision of the Online Offering and Web Hosting
  • Contact and Inquiry Management
  • Plug-ins, Embedded Functions, and Content
  • Changes and Updates
  • Definitions of Terms

Data Controller

Alexander Geckeler

c/o Online-Impressum #9808

Europaring 90

53757 Sankt Augustin

Germany

Email Address: kontakt@technicahistorica.com

Overview of Processing Activities

The following overview summarizes the types of data processed and the purposes of their processing, and identifies the data subjects.

Types of Data Processed

  • Master data.
  • Employee data.
  • Contact data.
  • Content data.
  • Usage data.
  • Meta, communication, and procedural data.
  • Log data.

Categories of Data Subjects

  • Service recipients and clients.
  • Employees.
  • Communication partners.
  • Users.
  • Third parties.
  • Whistleblowers.

Purposes of Processing

  • Provision of contractual services and fulfillment of contractual obligations.
  • Communication.
  • Security measures.
  • Organizational and administrative procedures.
  • Feedback.
  • Provision of our online services and user-friendliness.
  • IT infrastructure.
  • Whistleblower protection.

Applicable Legal Bases

Applicable Legal Bases Under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or our country of residence or domicile. Furthermore, should more specific legal bases apply in individual cases, we will inform you of these in the Privacy Policy.National Data Protection Regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act—BDSG). In particular, the BDSG contains special provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.

  • Consent (Art. 6(1), sentence 1, letter a) GDPR) – The data subject has given consent to the processing of personal data concerning him or her for a specific purpose or for several specific purposes.
  • Performance of a contract and pre-contractual inquiries (Art. 6(1), sentence 1, letter b) GDPR) – The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
  • Legal obligation (Art. 6(1), first sentence, lit. c) GDPR) – The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1), first sentence, lit. f) GDPR) – Processing is necessary to safeguard the legitimate interests of the controller or a third party, provided that the interests, fundamental rights, and fundamental freedoms of the data subject that require the protection of personal data do not override those interests.

Applicability of Data Protection Regulations in the Country of Establishment: In the country where the controller is established, national data protection regulations apply in addition to the General Data Protection Regulation (GDPR).

Security Measures

In accordance with legal requirements and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining its separation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the erasure of data, and responses to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through technical design and privacy-friendly default settings.

Securing Online Connections Using TLS/SSL Encryption Technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of “HTTPS” in the URL. This serves as an indicator to users that their data is being transmitted securely and in an encrypted form.

Transfer of Personal Data

In the course of our processing of personal data, it may occur that such data is transferred to or disclosed to other entities, companies, legally independent organizational units, or individuals.

Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.

International Data TransfersData Processing in Third Countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to other entities or companies, entities, or companies (which can be identified by the postal address of the respective provider or if the data transfer to third countries is expressly mentioned in the privacy policy), this is always done in accordance with legal requirements.For data transfers to the U.S., we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the European Commission dated July 10, 2023. In addition, we have entered into standard contractual clauses with the respective providers that comply with the requirements of the European Commission and establish contractual obligations to protect your data.This dual safeguard ensures comprehensive protection of your data: The DPF serves as the primary layer of protection, while the standard contractual clauses provide additional security. Should changes occur within the framework of the DPF, the standard contractual clauses serve as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of political or legal changes.For each service provider, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/ (in English).For data transfers to other third countries, appropriate safeguards apply, in particular standard contractual clauses, explicit consent, or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.General Information on Data Storage and DeletionWe delete the personal data we process in accordance with legal requirements as soon as the underlying consents are revoked or no further legal basis for processing exists. This applies to cases where the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule apply when legal obligations or specific interests require the data to be retained or archived for a longer period.In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.Our privacy policy contains additional information on the retention and deletion of data that applies specifically to certain processing operations.

If multiple retention periods or deletion deadlines are specified for a given piece of data, the longest period shall always apply. We process data that is no longer retained for its originally intended purpose—but rather due to legal requirements or other reasons—exclusively for the purposes that justify its retention.

Retention and Deletion of Data: The following general time limits apply to the retention and archiving of data under German law: Time limit begins at the end of the year: If a time limit does not expressly begin on a specific date and is at least one year in duration, it automatically begins at the end of the calendar year in which the event triggering the time limit occurred. In the case of ongoing contractual relationships in which data is stored, the event triggering the retention period is the date on which the termination or other termination of the legal relationship takes effect.

  • 10 years—retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, as well as the work instructions and other organizational documents necessary for their understanding (Section 147(1)(1) in conjunction with (3) of the German Fiscal Code (AO), § 14b(1) of the Value-Added Tax Act (UStG), § 257(1)(1) in conjunction with (4) of the Commercial Code (HGB)).
  • 8 years—accounting documents, such as invoices and expense receipts (Section 147(1)(4) and (4a) in conjunction with (3), first sentence, of the German Fiscal Code (AO), and Section 257(1)(4) in conjunction with (4) of the German Commercial Code (HGB)).
  • 6 years – Other business records: received commercial or business correspondence, copies of sent commercial or business correspondence, other documents to the extent they are relevant for tax purposes, e.g., hourly wage slips, payroll statements, cost calculation documents, price tags, as well as payroll records, provided they are not already accounting vouchers, and cash register receipts (Section 147(1)(2), (3), and (5) in conjunction with (3) of the German Fiscal Code (AO), Section 257(1)(2) and (3) in conjunction with (4) of the German Commercial Code (HGB)).
  • 3 years—Data required to address potential warranty and damage claims or similar contractual claims and rights, as well as to process related inquiries, based on past business experience and standard industry practices, is stored for the duration of the regular statutory limitation period of three years (Sections 195, 199 of the German Civil Code (BGB)).

Rights of Data Subjects

Rights of data subjects under the GDPR: As a data subject under the GDPR, you are entitled to various rights, which arise in particular from Articles 15 through 21 of the GDPR:

  • Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
  • Right to Withdraw Consent: You have the right to withdraw any consent you have given at any time.
  • Right of Access: You have the right to request confirmation as to whether data concerning you is being processed, as well as access to this data, further information, and a copy of the data in accordance with legal requirements.
  • Right to Rectification: You have the right, in accordance with legal requirements, to request that data concerning you be completed or that inaccurate data concerning you be corrected.
  • Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be erased without delay or, alternatively, to request a restriction on the processing of such data in accordance with legal requirements.
  • Right to Data Portability: You have the right, in accordance with legal requirements, to receive the data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, or to request that it be transmitted to another data controller.
  • Complaint to a Supervisory Authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority—in particular in the Member State of your habitual residence, your workplace, or the place where the alleged infringement occurred—if you believe that the processing of your personal data violates the provisions of the GDPR.

Provision of the Online Service and Web Hosting

We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.Further information on processing operations, procedures, and services:

  • Types of data processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved); log data (e.g., log files regarding logins, data retrieval, or access times).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)); security measures. Provision of contractual services and fulfillment of contractual obligations.
  • Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Storage and Deletion.”
  • Legal Bases: Legitimate interests (Art. 6(1), sentence 1, lit. f) of the GDPR).
  • Provision of Online Services on Leased Storage Space: To provide our online service, we use storage space, computing capacity, and software that we rent or otherwise obtain from a server provider (also known as a “web host”); Legal basis: Legitimate interests (Art. 6(1), sentence 1, lit. f) GDPR).
  • Collection of access data and log files: Access to our online service is logged in the form of so-called “server log files.” Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, a notification of successful access, browser type and version, the user’s operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes—e.g., to prevent server overload (particularly in the event of malicious attacks, so-called DDoS attacks)—and, on the other hand, to ensure server capacity and stability; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Deletion of Data:Log file information is stored for a maximum of 30 days and is then deleted or anonymized. Data that must be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.
  • 1&1 IONOS: Services in the field of providing information technology infrastructure and related services (e.g., storage space and/or computing capacity); Service provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.ionos.dePrivacy Policy: https://www.ionos.de/terms-gtc/terms-privacyData Processing Agreement:https://www.ionos.de/hilfe/datenschutz/allgemeine-informationen-zur-datenschutz-grundverordnung-dsgvo/vereinbarung-zur-auftragsverarbeitung-avv-mit-ionos-abschliessen/.

Contact and Inquiry Management

When you contact us (e.g., by mail, contact form, email, phone, or via social media) and within the context of existing user and business relationships, the information provided by the inquiring individuals is processed to the extent necessary to respond to contact inquiries and any requested actions.Further information on processing procedures, methods, and services:

  • Types of data processed: Contact data (e.g., mailing and email addresses or phone numbers); content data (e.g., text or image-based messages and posts, as well as related information such as details regarding authorship or the time of creation). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
  • Data subjects: Communication partners.
  • Purposes of processing and legitimate interests: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via an online form). Provision of our online services and user-friendliness.
  • Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Storage and Deletion.”
  • Legal Bases: Legitimate interests (Art. 6(1), first sentence, lit. f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, lit. b) GDPR).
  • Contact Form: When you contact us via our contact form, by email, or through other communication channels, we process the personal data you provide to us in order to respond to and handle your specific inquiry. This typically includes information such as your name, contact information, and, if applicable, additional information provided to us that is necessary for proper processing. We use this data exclusively for the stated purpose of establishing contact and communication; Legal Bases: Performance of a contract and pre-contractual inquiries (Art. 6(1), sentence 1, lit. b) GDPR), Legitimate Interests (Art. 6(1), sentence 1, lit. f) GDPR).

Plug-ins, Embedded Features, and Content

We integrate functional and content elements into our online offering that are retrieved from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos, or city maps (hereinafter collectively referred to as “content”).

This integration always requires that the third-party providers of this content process the users’ IP addresses, as they would not be able to send the content to the users’ browsers without an IP address. The IP address is therefore necessary for the display of this content or these functions. We make every effort to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These “pixel tags” allow information—such as visitor traffic on the pages of this website—to be analyzed. This pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, the time of the visit, and other details regarding the use of our online services; it may also be linked to such information from other sources.

Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is this consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services).

In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.Further information on processing activities, procedures, and services:

  • Types of data processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online offerings and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information provided in the section “General Information on Data Storage and Deletion.” Storage of cookies for up to 2 years (Unless otherwise specified, cookies and similar storage methods may be stored on users’ devices for a period of two years.).
  • Legal basis: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1), first sentence, lit. f) GDPR).
  • Google Fonts (Retrieval from Google’s server): Retrieval of fonts (and icons) for the purpose of ensuring technically secure, maintenance-free, and efficient use of fonts and icons with regard to up-to-date content and loading times, their consistent display, and compliance with any applicable licensing restrictions. The font provider is provided with the user’s IP address so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is necessary for the provision of the fonts depending on the devices used and the technical environment. This data may be processed on a server belonging to the font provider in the United States. When users visit our website, their browsers send HTTP requests to the Google Fonts Web API (i.e., a software interface for retrieving fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) from Google Fonts and, subsequently, the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the Internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the User-Agent, which describes the browser and operating system versions of website visitors, as well as the referrer URL (i.e., the webpage on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers, and they are not analyzed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user-agent, and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wishes to load fonts. This data is logged so that Google can determine how often a specific font family is requested. With the Google Fonts Web API, the user-agent must match the font generated for the respective browser type. The user-agent is primarily logged for debugging purposes and used to generate aggregated usage statistics that measure the popularity of font families. These aggregated usage statistics are published on the “Analytics” page of Google Fonts. Finally, the referrer URL is logged so that the data can be used for production maintenance and to generate an aggregated report on the top integrations based on the number of font requests. According to Google, it does not use any of the information collected by Google Fonts to create profiles of end users or to serve targeted ads; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://fonts.google.com/Privacy Policy:https://business.safety.google/privacy/Basis for transfers to third countries: Data Privacy Framework (DPF). Further information: https://developers.google.com/fonts/faq/privacy?hl=de.
  • We use the “Real Cookie Banner” consent tool to manage the cookies and similar technologies (tracking pixels, web beacons, etc.) we use, as well as the related consents. You can find details on how “Real Cookie Banner” works at https://devowl.io/de/rcb/datenverarbeitung/. The legal bases for the processing of personal data in this context are Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR. Our legitimate interest is the management of the cookies and similar technologies used, as well as the related consents. The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obligated to provide personal data. If you do not provide personal data, we cannot manage your consents.

Changes and Updates

We ask that you review the content of our Privacy Policy regularly. We will update the Privacy Policy as soon as changes to our data processing activities make this necessary. We will notify you as soon as the changes require action on your part (e.g., consent) or any other individual notification.

If we provide addresses and contact information for companies and organizations in this Privacy Policy, please note that these addresses may change over time, and we ask that you verify the information before contacting them.

Definitions of Terms

This section provides an overview of the terms used in this Privacy Policy. To the extent that these terms are defined by law, their legal definitions apply. The explanations below, however, are primarily intended to aid understanding.

  • Employees: Employees are defined as individuals who are in an employment relationship, whether as staff members, salaried employees, or in similar positions. An employment relationship is a legal relationship between an employer and an employee that is established by an employment contract or agreement. It includes the employer’s obligation to pay the employee compensation in exchange for the employee’s work. The employment relationship comprises various phases, including the establishment phase, during which the employment contract is concluded; the performance phase, during which the employee performs their work; and the termination phase, when the employment relationship ends, whether through termination, a mutual termination agreement, or otherwise. Employee data refers to all information relating to these individuals and pertaining to their employment. This includes aspects such as personal identification data, identification numbers, salary and bank details, working hours, vacation entitlements, health data, and performance evaluations.
  • Master Data: Master data comprises essential information necessary for the identification and management of contractual partners, user accounts, profiles, and similar assignments. This data may include, among other things, personal and demographic details such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Master data forms the basis for any formal interaction between individuals and services, institutions, or systems by enabling unique identification and communication.
  • Content data: Content data includes information generated during the creation, editing, and publication of all types of content. This category of data can include text, images, videos, audio files, and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself but also includes metadata that provides information about the content, such as tags, descriptions, author information, and publication dates.
  • Contact Data: Contact data is essential information that enables communication with individuals or organizations. It includes, among other things, phone numbers, mailing addresses, and email addresses, as well as communication channels such as social media handles and instant messaging identifiers.
  • Meta, communication, and operational data: Meta, communication, and operational data are categories that contain information about how data is processed, transmitted, and managed. Meta data, also known as data about data, includes information that describes the context, origin, and structure of other data. It may include details on file size, creation date, the author of a document, and revision histories. Communication data captures the exchange of information between users across various channels, such as email correspondence, call logs, social media messages, and chat histories, including the individuals involved, timestamps, and transmission methods. Process data describes the processes and procedures within systems or organizations, including workflow documentation, transaction and activity logs, as well as audit logs used to track and verify operations.
  • Usage Data: Usage data refers to information that tracks how users interact with digital products, services, or platforms. This data encompasses a wide range of information that reveals how users use applications, which features they prefer, how long they stay on specific pages, and the paths they take when navigating through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content, and improving products or services. In addition, usage data plays a crucial role in identifying trends, preferences, and potential problem areas within digital offerings
  • Personal Data: “Personal data” refers to any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
  • Log data: Log data consists of information about events or activities that have been logged in a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages, and other details regarding the use or operation of a system. Log data is often used to analyze system issues, monitor security, or generate performance reports.
  • Data Controller: “Data controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: “Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data, whether it involves collection, evaluation, storage, transmission, or deletion.

[Created using the free Datenschutz-Generator.de by Dr. Thomas Schwenke]