Datenschutzerklärung
Updated: 2 October 2026. This notice explains the processing of personal data when you visit our website or contact us.
1. Controller
Gewährsmann GmbH
Oldenburger Str. 2
90425 Nürnberg, Germany
Represented by Michael Moses
Telephone: +49 911 37777555
Email: info@gewährsmann.de
2. Website and hosting
Our website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Visiting the website involves processing technical data, including your IP address, date and time, requested page or file, response status and transferred data volume, and browser-supplied information about your browser, operating system and, where applicable, referring page. These data are used to deliver the website, diagnose errors and protect against attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website. STRATO processes data as our hosting provider. According to STRATO, visitors' IP addresses are retained for a maximum of seven days to detect and prevent attacks. IP addresses or hostnames are anonymised in the access logs supplied to website operators. Further information: STRATO's information on hosting and data protection.
3. Contact form, email and telephone
When you contact us, we process the information you provide to handle and answer your enquiry. Name and email address are required in the contact form; you choose the content of your message. Email or telephone contact may additionally involve your sender address, telephone number and other information you provide. Please only supply data needed for your enquiry.
For a contract with you or pre-contractual steps requested by you, the legal basis is Article 6(1)(b) GDPR. Other enquiries, including those from a company's contact persons, are processed under Article 6(1)(f) GDPR; our legitimate interest is communication with prospective customers and business partners.
The form sends your information through STRATO's mail service to our business mailbox. Form contents are not stored in a website database. Access is provided to the people handling your enquiry within our company and, as necessary, technical providers operating our hosting and email services. Disclosure may also occur where legally required or necessary to establish, exercise or defend legal claims.
We retain contact enquiries for as long as necessary to handle the enquiry and, where applicable, to perform a resulting contract. Further retention occurs where statutory retention duties apply or the data are needed to establish, exercise or defend specific legal claims. Once these purposes and duties no longer apply, the data are deleted. Further retention is based on Article 6(1)(c) GDPR for statutory duties and Article 6(1)(f) GDPR for the protection of specific legal claims.
Contacting us is voluntary. We cannot respond without a means of contacting you. Providing data merely to visit the website is not a contractual requirement; processing technical connection data is nevertheless necessary to deliver it.
4. Form security and necessary cookie
Submitting the form sets a technically necessary session cookie named “gewaehrsmann_contact”. It connects submission to a security token to protect against forged form requests. It contains no message and is not used for advertising or tracking browsing behaviour. It is restricted to the form endpoint and configured as a session cookie without a fixed expiry date. Browsers normally remove it when the session ends; session restoration may extend this.
Storage of or access to this necessary cookie is covered by section 25(2), no. 2 TDDDG. Associated personal data processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the secure operation of the contact form you use.
To limit abusive submissions, the form also stores a hashed IP identifier and submission timestamps outside the publicly accessible website directory. A hash is a pseudonymous identifier, not guaranteed anonymisation. Only timestamps from the preceding hour are used for rate limiting. Expired identifiers and timestamps are cleaned up when the form endpoint is next used; without further use they may remain stored until that cleanup. Message contents are not stored in these security files. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protection against spam and overload.
5. Fonts, analytics and external content
Fonts, images and files needed to display the website are loaded from our own webspace. We do not use external Google Fonts, embedded Google Maps, advertising trackers or website analytics services. External links open another website only when followed; that provider's privacy notice then applies.
6. Your rights
Subject to the legal requirements, you have the following rights:
- Access to your personal data and information about its processing (Article 15 GDPR).
- Rectification of inaccurate data and completion of incomplete data (Article 16 GDPR).
- Erasure where there is no legal reason for continued processing (Article 17 GDPR).
- Restriction of processing, for example while disputed accuracy is checked, or when you request restricted use instead of erasure following unlawful processing. The data remain stored, but further processing is generally permitted only under the conditions in Article 18 GDPR.
- Data portability where processing is based on consent or contract and performed by automated means (Article 20 GDPR).
- Withdrawal of consent with future effect, without affecting the lawfulness of processing before withdrawal (Article 7(3) GDPR).
Right to object
Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or processing is necessary to establish, exercise or defend legal claims (Article 21 GDPR). You may object to processing for direct marketing at any time without providing particular reasons.
To exercise your rights, use the contact details above.
Right to complain
You may lodge a complaint with a data protection supervisory authority, particularly in the place of your habitual residence, workplace or the alleged infringement (Article 77 GDPR). The Bavarian State Office for Data Protection Supervision (BayLDA) is generally responsible for private companies based in Bavaria. Information and contact details are available at www.baylda.de.
7. Automated decisions
This website does not use automated decision-making, including profiling, within the meaning of Article 22 GDPR. Technical spam limits only determine whether a form submission is accepted; they do not decide how your enquiry is handled. You can alternatively contact us by email or telephone.