Privacy policy
Last updated: 30 September 2026
Controller
- Controller
- A/L Werbekonzept GbR — Anna Heuvens, Lena Altmann
- Address
- Alte Furt 28
46499 Hamminkeln
Deutschland - Contact
- E-mail: Info@AL-Werbekonzept.de
General
We take the protection of your personal data seriously and treat it confidentially and in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
This website sets no cookies, embeds no third-party services, and opens no connection to third-party servers when you load it. No Google Analytics, no Meta pixel, no advertising networks, no cross-site tracking and no profiling.
We do run our own data-minimising reach measurement on our own server, so that we know which content is being read. It works without cookies, uses only a pseudonymous identifier that changes every day, and is described separately below.
No cookies are set on this website, and the reach measurement stores no information on your device. A cookie banner is therefore not currently used.
Hosting and server log files
This website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The provider processes the resulting data on our behalf.
With every request — for a page or a file, but also when the contact form is used or a page view is reported to our reach measurement — the web server automatically records in log files:
- the IP address of the requesting device
- the date and time of the request
- the requested address (URL) and the request method
- the HTTP status code and the volume of data transferred
- the previously visited page (referrer), where your browser sends it
- the browser identification (user agent), which shows browser, version and operating system
This data is technically necessary in order to deliver the website, to ensure its stability and security, and to investigate attacks or misuse. The legal basis is our legitimate interest in operating the website securely and reliably under Art. 6 (1) (f) GDPR. The data is not combined with other sources. The server administration software also produces monthly access statistics from the log files (AWStats), which include a list of the requesting IP addresses. These statistics are password-protected and kept for the current and the three preceding months.
The access and error logs are rotated by size rather than after a fixed period: older files are deleted automatically once ten archived files per log have been reached. How long an entry is kept therefore depends on the volume of traffic; in logs that are written to rarely, such as the error log, entries can currently be kept for more than a year. The server's security logs (web application firewall and automatic blocking of attacks), which can also contain IP addresses, are instead deleted on fixed schedules after around eight weeks at the latest.
Our own cookieless reach measurement
We want to know which pages are being read and whether our website is working. We use no external service for this — only our own statistics, running on our own server. Nothing is transmitted to a third party; there is no advertising tracking, no cross-site tracking and no profiling. Reach measurement can be switched on and off for this website: when it is off, no measurement script is loaded and your browser sends no requests to the statistics; when it is switched off, the server stops accepting reports immediately and the script is removed with the next update of the website.
When a page is opened, a small message is sent to our own server. What is evaluated from it:
- the page opened (path without parameters or anchors) and the time it was opened
- the page you came from (the referrer), if it is another website — stored without parameters — plus campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) if the address contains any
- device category, operating system and browser — as broad categories derived from the browser identification (user agent) your browser sends with the request anyway; the full identification string is not stored
- your preferred language, from the language setting your browser sends with every request (Accept-Language; the language subtag only, e.g. “de”)
- a coarse location: country, region and, where available, town
This measurement sets no cookies and stores nothing on your device. The measurement script does not actively access additional device characteristics such as screen or window size or comparable properties. No fingerprinting takes place.
The statistics use your IP address only in the moment the page is opened — for the coarse location, looked up in a database held locally on our own server, for limiting the number of reports per sender, and for a checksum that groups repeat visits within a single day. After that it is discarded: the statistics themselves store no IP addresses. Independently of this, the report to the statistics appears in the server log like any other request (see “Hosting and server log files”).
The checksum is a pseudonymous daily identifier, not anonymous data: it is formed from the IP address and the browser identification using a secret value that applies to one calendar day only and is deleted automatically once it is more than two days old (normally on the third following day). After that, the identifier can no longer be recreated from any input. The same visitor is therefore not recognised across several days, and no user profile is created. Page views less than 30 minutes apart are grouped by the server into one visit with a random session identifier, which is not sent to your browser.
If you send an enquiry through the contact form, it is counted as an enquiry (conversion) in the statistics. In addition, the landing page, the referring website and any campaign parameters of your current visit are attached to your enquiry, where the statistics recorded that visit (see “Contact form”).
The legal basis for this processing is our legitimate interest in a needs-based design and in improving our website under Art. 6 (1) (f) GDPR. The measurement sets no cookies and stores no information on your device.
Individual page views are deleted after 90 days. After that only aggregated daily totals remain, with no individual records, and those are kept for around 25 months. You may object to this processing at any time under Art. 21 GDPR; an informal message to the address given above is enough.
Contact form
The contact form is the only way to reach us directly on this website. If you use it, we process the details you enter:
- required: first name, last name, e-mail address and your message
- optional: telephone number, company or business, postcode and town
- your consent, which is recorded together with the enquiry
Your entries are transmitted over an encrypted connection to our own server and delivered from there by e-mail to the agency mailbox. Dispatch runs through the mail server of IONOS SE. Your e-mail address is set as the reply address so that we can answer you directly. The e-mail contains your details, the language of the form and the time it was sent, but not your IP address.
Where our enquiry inbox is enabled, we keep a copy of the enquiry on the same server once the e-mail has been sent, so that it does not exist only in an e-mail mailbox; where it is not enabled, the enquiry is delivered by e-mail only. It holds your details as in the e-mail and — where our reach measurement recorded them for your current visit — the landing page, the referring website and any campaign parameters (utm_…). No IP address and no daily identifier from the statistics is stored with it. Attaching the landing page and source is based on our legitimate interest in understanding how enquiries reach us (Art. 6 (1) (f) GDPR).
The legal basis is the consent you give explicitly in the form under Art. 6 (1) (a) GDPR and, where your enquiry is directed at a contract, Art. 6 (1) (b) GDPR. You may withdraw your consent at any time with effect for the future; an informal message to us is enough. The lawfulness of processing carried out before the withdrawal is unaffected.
Providing the required fields is neither a statutory nor a contractual obligation. We do need them in order to deal with and answer your enquiry at all — without them the form cannot be accepted. The remaining fields are optional.
The copy in our enquiry inbox is deleted automatically two years after it was received. We keep the e-mail in our mailbox until your enquiry has been dealt with conclusively and no further questions are expected; if the enquiry leads to an engagement, the statutory retention periods apply. On request we will delete your enquiry sooner, unless a retention obligation prevents this.
CAPTCHA-free spam protection
To protect the form against automated bulk enquiries we deliberately do not use a third-party CAPTCHA service. Four checks run on our own server instead:
- an additional field that is invisible to you and that only automated scripts fill in (a honeypot)
- a check on whether the form was completed in a time that is plausible for a person
- a small computation your browser solves in the background as soon as you start filling in the form — fetching the task from our server for this, without any of your entries — which makes bulk submission appreciably expensive
- a limit on the number of enquiries per IP address within a given time window
For the last check we process your IP address briefly in the server's working memory; only enquiries from the last ten minutes are counted, and none of it is stored permanently. If a submission is rejected because of the hidden field or the computation, we note the IP address together with the reason for rejection in our server's application log so that we can investigate misuse; this log is rotated weekly and deleted after around five weeks at the latest. Accepted enquiries are noted there without an IP address. The legal basis is our legitimate interest in a working, abuse-free contact route under Art. 6 (1) (f) GDPR. No data is transmitted to third parties and no cookies are set.
Fonts
The fonts used on this website are stored on our own server and loaded from there. No connection is made to Google Fonts or any other external provider, and no IP address is transmitted to a third party.
Recipients of your data
Your data is received only by us and, for technical reasons, by our hosting and e-mail provider IONOS SE, which processes it on our behalf.
For data backup, our server's database — including the enquiry inbox and the reach-measurement data — is backed up regularly and additionally copied to a separately rented, access-restricted server from the provider Hostinger, which likewise acts on our behalf. Backup copies are deleted automatically after around three months at the latest; until then they may still contain data that has already been deleted.
No transfer to a third country outside the EU is intended. Your data is not passed on for advertising purposes.
Your rights
You have the right at any time to obtain information about the data stored about you (Art. 15 GDPR), to have it corrected (Art. 16), erased (Art. 17) or its processing restricted (Art. 18), to data portability (Art. 20) and to object to processing (Art. 21). You may withdraw consent you have given at any time under Art. 7 (3) GDPR.
To do so, simply contact us at the address given above.
Right to lodge a complaint
If you believe that the processing of your data infringes data protection law, you may lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Changes to this policy
We update this privacy policy when the legal situation or the technology used on this website changes. The version published here, bearing the date shown above, is the one that applies.