This is a courtesy translation. In case of any discrepancy, the German version is the legally binding one.
Imprint
Information pursuant to § 5 DDG (German Digital Services Act)
kaufmeinewebsite.de
Darius Hofman
c/o Smarvo 279
Südstraße 31
47475 Kamp-Lintfort
Germany
Owner:
Darius Hofman
Contact:
Email: kontakt@kaufmeinewebsite.de
We are neither obliged nor willing to take part in dispute resolution proceedings before a consumer arbitration board (§ 36 VSBG).
Privacy policy
1. Privacy at a glance
The notes below give you a simple overview of what happens to your personal data when you visit our website. Personal data means any data by which you can be personally identified.
2. Data collection on this website
Data on this website is processed by the site operator. If you send us an enquiry through a form (contact form, chat adviser, website check, project request, booking), the data you enter is stored so that we can deal with your enquiry. It is passed on to third parties only where that is necessary to perform the contract (for example to a payment provider). To protect against abusive and automatically generated enquiries, we additionally store the exact time of submission, your IP address, your browser’s identifier (user agent) and language settings, and the referring page; from these we determine your approximate location (country, region, city) and network provider locally on our own server using a geolocation database, without transmitting anything to third parties. The form also transmits a technical verification token from which we derive the time taken to fill it in; nothing is stored on your device. From this information and from features of your input (for example whether the domain of your email address accepts mail, whether it is a disposable address, or whether the text contains advertising) we automatically calculate an estimate of how likely the enquiry is genuine; if a visitor profile exists (section 3), we take into account whether you looked around the website beforehand. This estimate is used solely to sort enquiries: every decision about your enquiry is made by a person, and no enquiry is automatically rejected, deleted or held back because of it. We delete your full IP address and the browser identifier after 30 days; afterwards only the shortened network, the approximate location and the estimate remain for as long as your enquiry is stored. After submitting, you may receive an acknowledgement email with an optional “Confirm enquiry” link; if you click it, we store the time of confirmation. The legal basis is Art. 6(1)(b) GDPR (handling your enquiry) and Art. 6(1)(f) GDPR (our legitimate interest in detecting abuse and automatically generated enquiries).
3. Visitor analytics
We analyse every visit in order to improve our website and our offer. This happens without your consent; we rely on our legitimate interest in improving our offer (Art. 6(1)(f) GDPR). We then process: your full IP address; the approximate location derived from it (country, region, city) and your network provider (AS number and organisation) — determined locally on our own server using a geolocation database, without transmitting anything to third parties; device information (browser and version, operating system and version, device type, manufacturer and model where your browser provides them, screen and window size, pixel density, touch capability, number of processor cores, memory class, connection type, language settings, time zone); your usage (pages viewed, time on page, scroll depth, clicks on links and buttons including links to other websites, choices made in the welcome dialogue and interactions with our chat adviser including messages you type); the referring page (without parameters) and campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term, ref, gclid). For clicks we record only the label of the element clicked, never the content of input fields. While you are signed in to your customer account we link this data to your account only if you have explicitly consented to the analysis; if you send us an enquiry or book an appointment, we link it to your visitor profile. A first-party cookie (“kmw_vid”, valid for 12 months) is set for this purpose. The data is deleted after 90 days at the latest. You can object to this processing at any time and without giving reasons (Art. 21(1) GDPR): the “Turn off tracking” switch at the end of this section sets a cookie (“kmw_no_track”, valid for 12 months). We then record nothing further, delete the “kmw_vid” cookie, and discard anything an already-loaded page would still try to send.
Turn off tracking
You can object to visitor analytics at any time, without giving reasons.
3a. Functional preference
If you make a choice in the welcome dialogue (your industry, for example), we store that choice in a functional first-party cookie (“kmw_pref”, valid for 12 months) so that we can show you relevant content when you return. A second functional cookie, “kmw_phase_notice” (valid for 30 days), remembers that you dismissed the notice about the reference phase. Neither contains personal data, neither is linked to analytics data and both stay exclusively in your browser. Legal basis: § 25(2) TDDDG (strictly necessary for the service you expressly requested). You can delete it at any time via your browser's cookie settings.
3b. Chat adviser (website adviser)
Conversations with our chat adviser are stored in pseudonymised form for quality assurance and product improvement: the transcript is linked to a randomly generated session identifier that allows no conclusions about your identity, and IP addresses are not stored. To generate the replies we transmit your messages to an AI language model from a provider in the USA, which we connect through an intermediary service (also in the USA). These services may retain your messages for a time under their own policies, for example to detect abuse. We will name the specific recipients on request. It is linked to analytics data only if you have consented to analytics (see section 3). Transcripts are deleted after 90 days at the latest. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our advisory service). If you submit an enquiry or booking through the chat, section 2 applies in addition. In the contact form and in the chat enquiry form you can have a language model polish your message at the press of a button (“Improve my message”): only then is the text transmitted to the same AI services, solely to produce the suggestion; we ourselves store neither the text nor the suggestion, and it is only used if you confirm it. Legal basis: Art. 6(1)(b) GDPR (your enquiry, at your request).
4. Security logging
To protect our systems against attacks (automated login attempts or denial-of-service attacks, for example) we log security-relevant events including the IP address. These logs are deleted after 30 days at the latest and are used exclusively to detect and defend against attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of our systems).
4a. Blocking abusive access
To protect against abusive access, conspicuous IP ranges can be blocked temporarily. What is stored is the anonymised network (a truncated IP); blocks are deleted when they expire, and with the security log (30 days) at the latest. Legal basis: Art. 6(1)(f) GDPR. Legitimate users are not affected; in case of doubt access is always granted.
4b. Server log files
Every time our website is accessed, our web server automatically logs: IP address, date and time, the address requested, HTTP method, status code, amount of data transferred, referring page and browser identifier (user agent). For analysis we transfer these entries to our database; in doing so we remove all parameters (the part after “?”) and access tokens from the requested address and the referring page, determine the approximate location (country, city) and the network provider from the IP address locally on our own server, and derive browser, operating system and device type from the browser identifier. The purpose is the secure and stable operation of the website: error analysis and detecting and defending against attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the operation and security of our systems). The analysed entries are deleted after 14 days, the log files on the web server after 15 days at the latest. They are not combined with the visitor profile from section 3 or any other data source. No cookies are set for logging.
5. Recipients and processors
We use carefully selected service providers that process data for us strictly on our instructions (Art. 28 GDPR): InsForge (database and application backend), Strato (email delivery), Notion (internal mirroring of enquiries), an AI language model from a provider in the USA together with an intermediary service (chat adviser replies, the “Improve my message” feature and drafts for approaching businesses, section 6). Where we name a service only by category, we will tell you the specific recipient on request. Where payments are offered, Stripe is added as the payment provider and processes payment data under its own responsibility. Any transfer to third countries takes place solely on the basis of the EU standard contractual clauses. The InsForge database, which also stores the security and server logs (sections 4 and 4b) and the block lists, is hosted in the “eu-central” data-centre region (EU); our own server additionally keeps a cache of the block list. Location and network provider, by contrast, are determined exclusively on our own server: the geolocation database used for this (DB-IP) is only downloaded, and no addresses are transmitted to DB-IP.
6. Data from public sources (approaching businesses)
To approach commercial businesses we process contact details taken from publicly accessible sources (business directories, map services, public posts) — specifically the business name, address, phone number, email address and website. The purpose is to make contact about an offer relevant to that business; the legal basis is Art. 6(1)(f) GDPR. We state where the data came from in every first approach (Art. 14 GDPR). Drafts for this first approach may be suggested by the AI language model from section 5, based on the business name, industry, town and rating or on the public post; every draft is checked by a person and sent by hand. In individual cases we also create a non-binding website draft for the business and make it available at an address that cannot be guessed and is not indexed by search engines; besides the details above, it also shows the rating publicly listed in the map service and the opening hours. The website draft is labelled as such, states its source and the date of retrieval, and is deleted together with the other data no later than 90 days after the last approach. You can object informally at any time — by email to kontakt@kaufmeinewebsite.de or via the objection link in our message; we then permanently block those contact details against any further approach.
7. Your rights
You have the right at any time to information about, correction of, deletion of and restriction of the processing of your stored personal data, as well as a right to object and a right to data portability. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the authority at your place of residence or at our seat is competent.
8. Deleting your account
If you have a customer account, you can delete it yourself: in the dashboard under “Settings”, next to “Sign out”. Deletion takes effect immediately and removes your profile, every file you uploaded (from file storage too, not just from the list), your support tickets, notifications and preferences, and your address from enquiries and appointments. If our audience measurement linked your browser to your account (section 3), we delete that analytics profile too, including IP address, device details and click path. Messages in ongoing matters are kept as a record, but no longer linked to you. Two things remain, and we name them explicitly. First, invoice and payment records — statutory retention periods of up to ten years apply to them (§ 147 AO, § 257 HGB); your name is no longer attached. Second, the bare sign-in entry (email address) at our backend provider: its interface currently offers no way to delete it, so we remove it by hand as soon as your deletion reaches us. Signing in is no longer possible from the moment of deletion. Invoices created through our payment provider Stripe are held there and subject to its own retention periods. Before that you can download the data we hold as a JSON file under “Settings” (Art. 15 and Art. 20 GDPR). You may also request deletion informally by email to kontakt@kaufmeinewebsite.de.
Terms of the reference phase
1. What this is about
kaufmeinewebsite.de is currently in a reference phase: we build websites for selected businesses free of charge in order to establish a solid portfolio. These terms apply to all services rendered free of charge during this phase.
2. No charge
No fee is owed for the build — neither a deposit nor a later invoice. There is no entitlement to have an enquiry accepted, nor to a particular scope or delivery date. A commitment only comes about through express confirmation.
3. Scope and your cooperation
The scope is agreed in advance. You provide the required content (copy, images, logo) in good time and in a usable format, and name a contact person who can be reached. Without that cooperation the work may be paused or ended.
4. Rights in the result
You receive a simple right of use in the finished result, unlimited in time and territory, including all files and access. Your rights in content you supply remain untouched; you warrant that it may lawfully be used. Third-party components used (open-source libraries, fonts and the like) remain subject to their own licences.
5. Being named as a reference — voluntary
Whether the result may be shown as a reference is your decision — made after completion, separately, and revocable at any time. Being named is expressly <strong>not a condition</strong> of the service: you keep your website in full even if you decline, or later withdraw a consent you have given.
6. Domain and hosting
Domain and hosting are not part of the service. You enter into those contracts yourself and in your own name and bear the running costs (typically around €5–15 a month depending on the provider). That way the address and the data are yours from the outset; we help with choosing and setting them up.
7. End of the reference phase
The reference phase ends once a defined number of projects has been reached; regular pricing applies from then on. Services already rendered free of charge remain free of charge and are never billed retroactively. Services after the end of the phase are governed by the terms published at that time; you will be told beforehand.
8. Liability and warranty
For services rendered free of charge, liability is limited to intent and gross negligence. This does not affect liability for damage arising from injury to life, body or health, or from breach of material contractual obligations; in the latter case liability is limited to the foreseeable damage typical of such contracts.
9. Responsibility for operation
After handover, operating the website is your responsibility. You are responsible for content you publish yourself and for meeting the obligations that apply to your business (such as the imprint and privacy policy of your website).
Note: this is a simplified version and is no substitute for legal advice.