Privacy policy

Last updated: 18 August 2026

1. Controller

Controller for the processing of personal data on this website: Sindomat GmbH, Rosmarweg 201, 50226 Frechen, Germany, email: info@sindomat.net.

2. Hosting and server logs

This website is operated on a server of Hetzner Online GmbH (data centre within the European Union). On every request our servers automatically log access data: IP address, date and time, requested page, transferred data volume, browser type and operating system.

The purpose is the secure and stable operation of the website and the detection and prevention of attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation). Log data is deleted automatically after 14 days at the latest.

3. No cookies, no tracking

We do not set any cookies on this website ourselves and do not use localStorage or comparable storage technologies for analytics or marketing purposes. There is no tracking, no reach measurement and no creation of user profiles. Advertising and social media plugins are not used.

Under § 25(2) TTDSG (German Telecommunications-Telemedia Data Protection Act), consent is only required where information is stored on or accessed from your device without being strictly necessary. As we do not perform any such non-essential storage access, this website does not require a consent banner. External services are integrated only where required for a function you request — and, in the case of appointment booking, only after your explicit click.

4. Contact and enquiry forms

When you submit the contact form we process your name and email address (required), subject, company and phone number (optional) and the content of your message. The details are used exclusively to handle your specific enquiry; there is no newsletter sign-up.

Your enquiry is stored encrypted in a database on our server and deleted automatically after 30 days unless required for further business processing. IP addresses are not stored in plain text by the application; only hash values are used for abuse protection and duplicate detection.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in documentation and abuse protection).

5. AI Practical Check by email

If you request optional email delivery of the AI Practical Check, your email address is processed only for the one-time delivery of the download. This creates neither a newsletter subscription nor an automatic CRM entry. The direct download remains available without an email address.

6. Abuse protection with Cloudflare Turnstile

To defend against automated spam submissions we use the Turnstile service of Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA, in our forms. Technical data (in particular IP address, browser and device data and behavioural signals) is transmitted to Cloudflare to verify that the entry originates from a human.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in ensuring the form function and fighting abuse). Data is transferred to the USA; Cloudflare is certified under the EU-US Data Privacy Framework. Submitting the forms is technically not possible without this check — you can instead reach us directly at info@sindomat.net at any time.

7. Email delivery via Brevo

Notification and confirmation emails related to your enquiries are sent via Brevo (Sendinblue GmbH, Cologne, Germany). Your email address and the content to be sent are transmitted to Brevo. A data processing agreement under Art. 28 GDPR is in place with Brevo; Brevo does not use the data for its own purposes.

8. Forwarding of enquiries to our CRM

Contact enquiries are transferred to our CRM system Odoo for processing and follow-up and stored there as a record. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (organisation of enquiry handling). The data is deleted once it is no longer required for these purposes and no statutory retention obligations apply.

Enquiries for the AI Practical Check (section 5) are not transferred to the CRM.

9. Appointment booking via Microsoft Bookings

For booking appointments we integrate Microsoft Bookings (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA) using a two-click solution: the service only loads when you actively click the booking function. Only with this click is data transferred to Microsoft.

The legal basis is the performance of the appointment booking you requested under Art. 6(1)(b) GDPR. Data is transferred to the USA; Microsoft is certified under the EU-US Data Privacy Framework. Alternatively you can arrange appointments by email to info@sindomat.net at any time.

10. Retention periods at a glance

Server logs (Hetzner): IP address, access time, requested page, browser data — deleted after 14 days at the latest.

Form enquiries: encrypted stored details including hash values for abuse protection — automatic deletion after 30 days unless further processing is required.

CRM records (Odoo): until processing is completed, at the longest until statutory retention periods expire.

Cloudflare Turnstile and Microsoft Bookings: the retention periods of the respective providers apply; we have no influence on these and select the services with regard to data protection certifications.

11. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). You may object at any time to processing based on legitimate interests (Art. 21 GDPR) and withdraw any given consent with effect for the future (Art. 7(3) GDPR).

Send requests to info@sindomat.net. You also have the right to lodge a complaint with the competent supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf, Germany.

Official GDPR text: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679

Privacy status

No optional analytics or marketing services are enabled in this local redesign. External booking content remains closed without a configured appointment type and an explicit click.