Table of contents
Privacy Policy
The protection of your personal data is important to us. This privacy policy explains which personal data we collect on this website, for which purposes we process it and which rights you have. Processing is carried out in accordance with the EU General Data Protection Regulation (GDPR) and applicable German data protection law.
1. Controller
The controller responsible for data processing on this website is:
Hauck & Autoren Talstraße 93c 40217 Düsseldorf Germany
Represented by: Dr. Johannes Weigl Phone: +49 211 86942731 E-mail: [email protected]
2. Hosting and content delivery (Cloudflare)
This website is delivered as a static site via Cloudflare Pages, operated by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare runs a global content delivery network and provides protection against attacks (e.g. DDoS).
When you access the website, Cloudflare processes technically necessary connection data (in particular IP address, date and time of the request, transferred data volume, browser type and version, operating system, referrer URL). This data is required for the delivery, stability and security of the website. The legal basis is our legitimate interest in a secure and performant website (Art. 6(1)(f) GDPR).
Cloudflare is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses apply in addition. Further information: Cloudflare Privacy Policy.
3. Server log files
Each time the website is accessed, general technical information is automatically stored in log files (browser used, operating system, referrer URL, date and time of access, IP address, page requested). This data does not allow us to draw direct conclusions about your identity and is stored separately from any other data you provide. It is used solely to deliver content correctly, to ensure system security and for statistical evaluation in anonymised form.
4. Cookies and consent management
This website uses cookies and comparable technologies. Cookies are small text files stored on your device.
On your first visit, a cookie banner appears that lets you decide which categories to allow:
- Necessary – technically required cookies, in particular to store your consent decision. These cannot be disabled.
- Analytics – cookies for reach measurement (Google Analytics 4). Set only after your consent.
- Marketing – cookies for conversion measurement and remarketing (Google Ads, Meta). Set only after your consent.
Without your consent, no analytics or marketing cookies are set (Google Consent Mode v2). You can change or withdraw your selection at any time via the “Cookie settings” link in the website footer. The legal basis for non-essential cookies is your consent (Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG).
5. Contact and enquiries
5.1 Enquiry form and appointment booking (LeadConnector / HighLevel)
For our enquiry form and online appointment booking we use the services of HighLevel Inc. (LeadConnector), 400 North Saint Paul St., Suite 920, Dallas, TX 75201, USA. The form and the booking calendar are loaded as embedded content from HighLevel servers.
When you submit the form or book an appointment, we process the data you provide (e.g. name, e-mail address, phone number, details of your request, preferred appointment) in order to handle your enquiry, prepare a non-binding offer and manage appointments. The legal basis is the performance of pre-contractual measures or the performance of a contract (Art. 6(1)(b) GDPR).
The data is stored in our customer relationship management system (CRM) provided by HighLevel. Transfer to the USA is based on standard contractual clauses. Further information: HighLevel Privacy Policy.
5.2 E-mail and phone
If you contact us by e-mail or phone, we process your details to answer your enquiry and for any follow-up questions. No data is passed to third parties unless this is necessary to perform a contract or required by law.
5.3 WhatsApp
You can contact us via WhatsApp (WhatsApp Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland). If you actively choose this channel, the WhatsApp privacy terms additionally apply; data (e.g. your phone number, communication metadata) may be transferred to Meta servers, including outside the EU. Use is voluntary; the form, e-mail and phone are available as alternatives. Further information: WhatsApp Privacy Policy.
6. Google Tag Manager
We use Google Tag Manager (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). The Tag Manager itself does not set cookies and does not create user profiles; it manages and consent-controls the services described below. All analytics and marketing tags are triggered only after your corresponding consent.
7. Google Analytics 4
If you have consented (category “Analytics”), we use Google Analytics 4, a web analytics service of Google Ireland Ltd. Google Analytics uses cookies and similar technologies to evaluate the use of the website (e.g. pages visited, time on page, approximate region of origin, device used). IP addresses are processed in truncated form; full IP addresses are not stored by Google Analytics 4.
These reports help us improve content and usability. Data may be transferred to Google LLC servers in the USA; Google is certified under the EU-U.S. Data Privacy Framework. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the cookie settings. Further information: Google Privacy Policy.
8. Google Ads conversion tracking and remarketing
If you have consented (category “Marketing”), we use Google Ads conversion tracking and Google remarketing (Google Ireland Ltd.). This allows us to measure whether users perform certain actions after clicking one of our ads (e.g. submitting an enquiry, booking an appointment) and to show interest-based ads to website visitors on other platforms.
Cookies are set and pseudonymised identifiers are processed; transfer to the USA is possible (safeguards as described in section 7). The legal basis is your consent, which you can withdraw at any time via the cookie settings.
9. Meta Pixel (Facebook/Instagram)
If you have consented (category “Marketing”), we use the Meta Pixel of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. This allows conversions to be measured and relevant ads to be shown to website visitors on Facebook and Instagram. Meta may link this data to your Meta account and use it for its own advertising purposes in accordance with the Meta Data Policy; data may be transferred to the USA (Meta is certified under the relevant Data Privacy Framework programmes).
The legal basis is your consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time via the cookie settings.
10. International data transfers
We only transfer personal data to third countries where this is necessary to fulfil the purposes described. Where a recipient is located in a country without an adequate level of data protection (in particular the USA), we ensure protection through appropriate safeguards – namely certification of the recipient under the EU-U.S. Data Privacy Framework or standard contractual clauses.
11. Retention period
We process and store personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations (e.g. commercial and tax retention periods of generally up to ten years). After that, the data is deleted or anonymised.
12. Your rights
Under the GDPR you have, in particular, the following rights:
- Access to whether and which personal data we process about you (Art. 15 GDPR)
- Rectification of inaccurate personal data (Art. 16 GDPR)
- Erasure of your personal data, unless retention obligations apply (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a common electronic format (Art. 20 GDPR)
- Objection to certain processing and withdrawal of consent given, with effect for the future (Art. 21, Art. 7(3) GDPR)
To exercise your rights, an informal message to the contact details in section 1 is sufficient. To prevent misuse, we may request proof of identity.
You also have the right to lodge a complaint with a supervisory authority – for our registered office, this is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen).
13. Data security
We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access. This website is transmitted in encrypted form throughout via HTTPS/TLS.
14. Changes to this privacy policy
We may adapt this privacy policy at any time, in particular in the event of changes to the services used or the legal situation. The version published on this website at the time applies.