1. Controller
Edith Rommelfangen (sole proprietor)
Translator / Interpreter
Trierer Straße 50, D-54439 Saarburg, Germany
Phone: 06581 994172 · Mobile: 0176 782 585 491 / +352 691 665 845
Email: kontakt@edith-rommelfangen.de
No obligation to appoint a data protection officer.
2. Purposes, legal bases, categories of personal data
2.1 Enquiries (contact/quote)
Purpose: handling your enquiry, preparing quotations, communication.
Categories: identification/contact details (e.g., name, email, phone), communication content (message/attachments), matter-related information.
Legal basis: Art. 6(1)(b) GDPR (pre-/contractual) ; optional details under Art. 6(1)(f) (efficient communication).
Note: Submitting special categories of personal data (Art. 9 GDPR) is neither necessary nor intended.
2.2 Log data (server/application)
Purpose: secure and stable website operation, error analysis.
Categories: IP address, timestamp, requested URL, user agent.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests).
3. Recipients / Processors (categories)
We use processors (Art. 28 GDPR) for hosting/operation/maintenance/backup and for communication services (email). Data is otherwise disclosed to third parties only where required by law or with consent. A list of categories of service providers is available on request.
4. Third-country transfers
Transfers outside the EU/EEA only where necessary, based on consent, or with appropriate safeguards under Arts. 44 et seq. GDPR (in particular EU Standard Contractual Clauses).
5. Cookies / Consent management
We use only technically necessary cookies (legal basis: Art. 6(1)(f) GDPR). No non-essential services (analytics/marketing) are used; therefore, no separate consent is required. If this changes in the future, consent will be obtained beforehand.
6. Storage periods and deletion
– Enquiries/quotes: up to 12 months after communications end; if a contract is concluded, storage in business records according to statutory retention (6/10 years).
– Log data: max. 180 days, then deletion or anonymisation.
– Backups: file backups and logical database backups, rotation 60 days, used solely for restoration.
7. Technical and organisational measures (Art. 32 GDPR)
Protection aligned with the state of the art: TLS/HTTPS, role-based access to internal admin areas, password policy (admin accounts ≥ 12 characters, no forced rotation), logging of security-relevant events, patch/update processes, monitored backup & restore, and regular effectiveness reviews. Multi-factor authentication is used where technically available.
8. Data subject rights (Arts. 15–22 GDPR)
Right of access, rectification, erasure, restriction, portability, objection (Art. 21); withdrawal of consent with future effect.
Contact: kontakt@edith-rommelfangen.de. We respond within one month; identity verification may be required. Requests are generally free of charge (Art. 12(5) GDPR).
9. Right to lodge a complaint
With any data protection supervisory authority, in particular at your place of residence or work or the place of the alleged infringement.
10. Updates
This policy will be updated as needed. The current version is available on this page.