PrüfExpress

Privacy Policy

Stand: 8/2/2026

1. Controller

Graubner Industrie-Beratung GmbH
Schwimmbadstraße, 26
76332 Bad Herrenalb

Phone: +49 800 47 28 26 3
Email: info@graubner-gmbh.de

2. Data Protection Officer

Achim Barth – Barth Datenschutz GmbH
Email: info@barth-datenschutz.de

3. Overview of data processing

We process personal data when you visit our website, contact us, or – depending on the configuration – use features such as appointment booking, newsletters, analysis, or marketing tools.

Typical data categories:
• Access data (e.g., IP address, date/time, page visited, referrer URL, browser/device information)
• Communication data (e.g., email content, contact details)
• Content and form data (information you enter into fields)
• Consent and cookie data (consent status, cookie identifiers)

4. Basic processing

4.1 Provision of the website and server logs

Purpose: Delivery of the website, ensuring stability and security, abuse and attack detection, error analysis.Data: IP address, timestamp, accessed content, technical information (browser/operating system), referrer URL, log data.Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and functional operation).Recipients: Technical service providers (e.g., hosting, IT) within the scope of data processing agreements.Storage duration: Log data is stored only as long as necessary for security and error analysis (typically: a few days to a few weeks), then deleted or anonymized.

4.2 Use of service providers and data processing

For the operation and maintenance of the website, we use service providers (e.g., hosting, IT, support, web development). Where necessary, a data processing agreement pursuant to Art. 28 GDPR has been concluded with these service providers.

4.3 Cookies and consent management

We use cookies and similar technologies (e.g., local storage) to provide the website technically (necessary), to offer features, and – optionally and only with consent – to measure reach or enable marketing.
If cookies or technologies requiring consent are used, we obtain your consent before use.Legal basis: Art. 6 (1) (a) GDPR (consent) for cookies and tools requiring consent; Art. 6 (1) (f) GDPR for the operation and logging of consent status.Change or revoke consent: Cookie settings

4.4 Contacting us

Purpose: Processing your request, communication.Data: Contact details, message content, metadata if applicable.Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures or contract) or Art. 6 (1) (f) GDPR (legitimate interest in efficient communication), depending on the content of the request.Storage duration: Until the request is fully processed; beyond that, only if necessary (e.g., proof, follow-up questions) or due to legal retention obligations.

5. Processing in detail

Newsletter

Purpose: Sending information, news, and offers.Data: Email address, name if applicable; log data for registration (double opt-in: time, IP address).Legal basis: Art. 6 (1) (a) GDPR (consent).Revocation: At any time via the unsubscribe link in the newsletter or by sending us a message.Recipients: Newsletter service provider (data processing pursuant to Art. 28 GDPR).Storage duration: Until consent is revoked; log data as long as required for proof.

Appointment booking

Purpose: Scheduling and conducting appointments.Data: Name, contact details, requested appointment, notes if applicable.Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures or contract); if the tool uses tracking or cookies: Art. 6 (1) (a) GDPR.Recipients: Appointment service provider (data processing pursuant to Art. 28 GDPR if applicable).Storage duration: Until the appointment is completed and the follow-up purpose is fulfilled; thereafter, deletion as needed or according to legal deadlines.

Analysis and reach measurement

Purpose: Measuring usage, optimizing the website.Data: Usage data, device and browser data, interactions, cookie IDs if applicable.Legal basis: Art. 6 (1) (a) GDPR (consent).Revocation: Via the cookie settings.Recipients: Analysis service provider (data processing pursuant to Art. 28 GDPR if applicable).Third country: Possible, depending on the provider (see section 6).Storage duration: Depending on tool settings; deletion or anonymization according to configuration.

Tag management

Purpose: Technical management and deployment of website tags (analysis, marketing).Data: Technically required: IP address, device information; otherwise dependent on the tags loaded via it.Legal basis: If tags requiring consent are loaded via it: Art. 6 (1) (a) GDPR.Note: Tag management is not a neutral component – the tags activated through it are decisive.

Marketing, conversion, and retargeting

Purpose: Ad delivery, performance measurement, retargeting.Data: Interactions, visit and conversion events, cookie IDs, campaign assignment if applicable.Legal basis: Art. 6 (1) (a) GDPR (consent).Revocation: Via the cookie settings.Recipients: Marketing and advertising service providers; joint controllership depending on tool design (to be checked in individual cases).Third country: Possible, depending on the provider.

Embedded content

Purpose: Display of external content (video, audio, maps, widgets).
Data: IP address, device information if applicable; cookies or tracking depending on the provider.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent) if the provider uses cookies
or tracking; otherwise Art. 6 para. 1 lit. f GDPR (legitimate interest in
user-friendly presentation) for purely technical integration without tracking.
Recipients: Respective provider of the embedded content.
Third country: Possible, depending on the provider.

Social media links

Purpose: Linking to external social media profiles.
Data: For pure linking, no data is transferred by us to social media providers;
you only leave our website upon clicking.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in information and
communication).

Security services

Purpose: Protection against misuse, spam, and attacks (WAF, bot protection, spam protection).
Data: IP address, request data, technical identifiers, risk and score values if applicable.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in security).
Recipients: Security service providers (data processing agreement pursuant to Art. 28 GDPR, if
necessary).
Third country: Possible, depending on the provider.

6. Recipients

Depending on the functions used, data may be transmitted to the following categories of recipients:
• IT and hosting service providers (data processing)
• Communication, form, and appointment service providers
• Analytics and marketing service providers (only upon corresponding activation)
• Providers of embedded content (video, audio, widgets)
• Payment service providers (for payment functions)

7. Third country transfers

Depending on the service providers used, personal data may be processed
outside the EU or the EEA. In these cases, we rely – where necessary – on appropriate
guarantees (e.g., standard contractual clauses) and take measures to minimize risk.

Note: For transfers to third countries, a residual risk (e.g., government
access possibilities) cannot be completely excluded.

8 Storage duration

We store personal data only as long as it is necessary for the respective purposes.
Subsequently, data is deleted or anonymized, provided no statutory retention
obligations prevent this.

9. Your rights

You have the following rights:
• Access to your stored data (Art. 15 GDPR)
• Rectification of incorrect data (Art. 16 GDPR)
• Erasure of your data (Art. 17 GDPR)
• Restriction of processing (Art. 18 GDPR)
• Data portability (Art. 20 GDPR)
• Objection to processing based on Art. 6 para. 1 lit. f GDPR (Art.
21 GDPR)
• Withdrawal of granted consent with effect for the future (Art. 7 para. 3 GDPR)

Assertion: Via the contact details of the controller or the
Data Protection Officer (info@barth-datenschutz.de).

10. Right to lodge a complaint

You have the right to lodge a complaint with a competent data protection supervisory authority
(Art. 77 GDPR).

11. Obligation to provide data

For the mere use of the website, the provision of certain data is technically
necessary (e.g., IP address). If you contact us or request services,
certain information is required to process your request.

12. Automated decisions and profiling

Automated decision-making including profiling within the meaning of Art. 22
GDPR does not generally take place. If individual marketing or analysis modules
can create profiles, this occurs exclusively after prior consent (Art. 6 para.
1 lit. a GDPR).