Privacy Policy

Since 25 May 2018, the uniform requirements of the EU General Data Protection Regulation ( GDPR ) have applied throughout Europe in the field of data protection. In the following privacy information, we inform you about the processing of personal data carried out by us in accordance with the GDPR and the German Federal Data Protection Act ( BDSG ).

Controller

The controller for data processing – i.e. the person who decides on the purposes and means of the processing of personal data – in connection with our services is:
Datenschutz Nordost – Axel Lehmann
Owner: Axel Lehmann
Goldberger Str. 81a
D – 18273 Güstrow, Germany
Phone: +49 3843-229133
Fax: +49 3843-2456021
E-Mail: info@privalexx.com.ua

Data Protection Officer

We are not obliged to appoint a data protection officer. If you have any questions about data protection, please contact us at the address given above.

Scope

This Privacy Policy applies to our online offering on the websites we operate.

Use of our Websites

Whenever you access our websites, information is transmitted by the internet browser of your device to our website server and temporarily stored in protocol files, the so-called log files. The stored data sets may contain the following data, which will be retained until automatically deleted:

  • Date and time of access.
  • Name of the page accessed.
  • IP address of the requesting device.
  • Referrer URL (the URL from which you came to our websites).
  • Amount of data transferred.
  • Loading time.
  • Product and version information of the browser used, your operating system, and the name of your access provider.

Legal basis for processing this data is Art. 6(1)(f) GDPR. Our legitimate interest arises from the need to ensure a smooth connection to our websites, ensure a convenient use of our websites, analyze system security and stability. It is not possible for us to directly identify you from this information, nor will we attempt to do so. You may object to the processing of your personal data based on our legitimate interests at any time.

Security Measures

We take appropriate technical and organizational measures in accordance with statutory requirements to guarantee a level of protection appropriate to the risk. In doing so, we take into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of the processing, as well as the probability and severity of any risk to the rights and freedoms of natural persons. These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as controlling access, entry, transfer, securing availability, and separation of data. In addition, we have established procedures to exercise data subject rights, delete data, and respond to data threats. We also comply with data protection principles when developing and selecting hardware, software, and processes through data protection by design and by default. We describe below other processing activities and services we use in this context: Shortening of IP addresses: If we or service providers and technologies we use process IP addresses and full IP processing is not required, the IP address is shortened („IP masking“). This means that the last two digits or the last part of the IP address after a dot are removed or replaced with placeholders. Shortening the IP address is intended to prevent, or at least significantly hinder, identification of a person based on their IP address. TLS/SSL encryption (https): To protect user data transmitted through our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is a standard technology that ensures the security of internet connections by encrypting data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. You can recognize that a website is protected by an SSL/TLS certificate by the display of Hyper Text Transfer Protocol Secure (HTTPS) in the URL.

Deletion of Data

In accordance with legal requirements, we delete data we process as soon as the original consent to processing is revoked or other legal grounds cease to apply (e.g., if the processing purpose no longer exists or the data is no longer necessary for that purpose). If data cannot be deleted because it is needed for other legally permissible purposes, its processing will be restricted to those specific purposes. This means that data will be blocked and used exclusively for those purposes. This may include, for example, data that must be retained for commercial or tax law reasons, or whose storage is required for the enforcement, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person. Information on specific storage and deletion periods may be included in our privacy notices.

Contract Processing

If you enter into a contract with us, or contact us via our website with a view to concluding a contract, we process the data required to conclude, perform and/or terminate the contract with you. This includes:

  • Master/contact data (e.g. name, address)
  • Payment data (e.g. bank details, invoices, payment history)
  • Contract data (e.g. subject matter of the contract, duration)
  • Usage and communication data (e.g. IP addresses, websites visited, access times)

The legal basis for this is Art. 6(1)(b) GDPR, i.e. you provide us with the data on the basis of the respective contractual relationship between you and us. We also process your data on the basis of legal obligations (Art. 6(1)(c) GDPR) and legitimate interests (Art. 6(1)(f) GDPR). The purpose of the processing is to provide the agreed services and fulfil our contractual obligations. We also take security measures to ensure the integrity and confidentiality of the data, and use office and organisational procedures to handle and respond to inquiries.

Data we store in connection with the conclusion, performance and/or termination of the contract with you is deleted once statutory warranty and similar obligations have expired. As a rule, this period is 4 years, unless the data is stored in a customer account, e.g. due to statutory archiving obligations. Tax-relevant documents such as commercial books, inventories, opening balance sheets, annual financial statements and the related work instructions, organisational documents and accounting vouchers are retained for 10 years. Business letters received and copies of letters sent are retained for 6 years. The retention period begins at the end of the calendar year in which the last entry was made, the inventory, annual financial statement or management report was prepared, the letter was received or sent, or the accounting voucher was created.

Email Communication

If you communicate with us via the email addresses provided on our website, we may use email providers to manage and support email delivery and communication. This may involve processing personal data such as your email address, the content of your email, and other information related to the communication. The legal basis for this processing is either your consent (Art. 6(1)(a) GDPR) or our legitimate interest in efficient communication and the handling of inquiries and orders (Art. 6(1)(f) GDPR). We take appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access or disclosure, and store your emails only for as long as is necessary to fulfil the purpose for which they were collected.

Amendment and Updating of the Privacy Policy

If we make changes to our data processing procedures, we will also adjust this Privacy Policy accordingly. We will inform you if such changes require your cooperation (e.g., consent) or an individual notification. For all other changes, we ask you to regularly review our Privacy Policy to stay informed about its contents. Please note that the addresses and contact details of companies and organizations listed in our Privacy Policy may change over time. Therefore, please check this information before contacting them.

Your Rights

In connection with the processing of personal data by us, you are entitled to rights as a data subject. For example, you have the right to request information about the data we hold about you. You can also withdraw consents you have given us and object to specific processing of data. Furthermore, you have the right to have incorrect data corrected and can demand that we provide you with certain data in a common electronic format. In addition, you have a right to deletion of the data we hold about you. Please note that we may be legally obliged to continue storing data despite the exercise of your right to deletion. In some cases, we may also have a legitimate interest in continuing storage of your data that outweighs your interest in deletion (e.g., if we still have outstanding claims against you).

Your Rights in Detail

The rights set out in this section may be exercised either directly with us ( Controller ) or with our Data Protection Officer . Contact details can be found above in this statement. In addition to the right to withdraw consents granted to us, you also have the following rights, provided the respective statutory conditions are met:

  • Right of access to your personal data stored by us (Art. 15 GDPR): In particular, you may request information about the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been disclosed or will be disclosed, the planned storage period, the origin of your data (if not collected directly from you).
  • Right to rectification of incorrect data or completion of correct data (Art. 16 GDPR).
  • Right to erasure of your data stored by us („right to be forgotten“) (Art. 17 GDPR), as long as no statutory or contractual storage requirements or other legal obligations or rights prevent further storage.
  • Right to restriction of processing (Art. 18 GDPR), if the accuracy of the data is disputed by you, processing is unlawful but you oppose deletion, we no longer need the data but you require it for the establishment, exercise, or defense of legal claims, or you have objected to processing pursuant to Art. 21 GDPR.
  • Right to data portability (Art. 20 GDPR), i.e., the right to have selected data about you stored by us transferred in a commonly used, machine-readable format, or to request transfer to another controller.
  • Right to lodge a complaint with a supervisory authority. You can usually contact the supervisory authority at your habitual residence, place of work, or our company headquarters.

Right to Object

Under the conditions of Art. 21(1) GDPR, processing may be objected to on grounds relating to your particular situation. The above general right to object applies to all processing purposes described in this Privacy Policy, which are processed on the basis of Art. 6(1)(f) GDPR. Unlike the specific right to object to data processing for advertising purposes, we are only obliged to implement such a general objection under the GDPR if you provide us with reasons of overriding importance (e.g., a possible risk to life or health).

Right to Withdraw Consent

If we process data on the basis of consent you have given, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

Supervisory Authority and Right of Complaint

You have the right to lodge a complaint with the supervisory authority responsible for our company. The responsible authority is: State Commissioner for Data Protection and Freedom of Information Mecklenburg-Vorpommern
Lennéstraße 1
19053 Schwerin, Germany
Phone: +49 385 59494-0
E-Mail: info@datenschutz-mv.de
Website: www.datenschutz-mv.de

Hosting and Content Delivery Network (Cloudflare)

Our website is hosted by 1blu and additionally delivered via Cloudflare, Inc. as a content delivery network and security service. When you visit our website, your IP address is technically transmitted to Cloudflare before your request is forwarded to our server. Cloudflare may set technically necessary cookies to protect against attacks (e.g. DDoS protection). We have a data processing agreement with Cloudflare under Art. 28 GDPR. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in a secure and reliable provision of our website. Cloudflare, Inc. is based in the USA; personal data may therefore be transferred to the USA. This transfer is based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework, under which Cloudflare is certified (Art. 45 GDPR), and alternatively on the EU standard contractual clauses (Art. 46(2)(c) GDPR).

Contact form

If you send us an inquiry via the contact form, the details you provide (name, email address, optionally company, your message) will be stored by us for the purpose of processing your inquiry and in case of follow-up questions, and forwarded to us by email. We do not pass on this data to third parties. The legal basis is Art. 6(1)(b) GDPR, as your inquiry serves to take steps prior to entering into a contract; for other inquiries, the legal basis is our legitimate interest in answering them (Art. 6(1)(f) GDPR). To protect against abusive automated use (spam) we use a honeypot method and, after your consent via our consent tool, Cloudflare Turnstile (see next section).

Cloudflare Turnstile (spam protection)

To protect our contact form from automated spam submissions, we use Cloudflare Turnstile, a service provided by Cloudflare, Inc. Turnstile checks in the background whether a form submission comes from a human or an automated program, without requiring you to solve an image or text captcha. This may involve setting technically necessary cookies and transmitting data such as IP address and browser characteristics to Cloudflare. Turnstile is only loaded after you have agreed to it via our cookie banner. The legal basis is your consent (Art. 6(1)(a) GDPR). Without this consent, the online form is available to you in a limited way; alternatively, you can always reach us directly by email at info@privalexx.com.ua. For the associated transfer to the USA, the information in the section “Hosting and Content Delivery Network (Cloudflare)” applies (EU-US Data Privacy Framework, alternatively standard contractual clauses).

Cookie settings and consent tool

On your first visit to our website, we show you a notice banner about the functions used. Technically necessary functions (e.g. storing your language preference via the Polylang plugin) do not require consent. For optional functions such as Cloudflare Turnstile, we obtain your consent before the associated script is loaded. We store your decision exclusively locally in your browser (localStorage), not on our servers. You can delete your browser data at any time via your browser settings to see the prompt again.

.pv-cookie-settings { background: var(–surface-subtle, #f2f3f5); border-radius: var(–radius-card, 24px); padding: 20px 24px; margin: 20px 0; max-width: 560px; }
.pv-cookie-settings .pv-consent-status { margin: 0 0 12px; font-size: 14px; color: var(–accent-text, #5b6b7e); }

Software used, at a glance

Our website is based on WordPress with the Astra theme. For multilingual support we use the Polylang plugin. In addition, we use custom-built, individual website functions (including the contact form, cookie banner, and content display) — this is not third-party software but code written specifically for this website, without any data collection beyond what is described here.

Last updated: 03 October 2026

Scroll to Top