1. General Information
The protection of your personal data is of great importance to SCHUHEN Consulting GmbH. We want you to know what data we collect, when we collect it, and how we use it. Your data is protected in accordance with applicable law.
2. Controller / Data Protection Contact
The controller responsible for data processing on this website is:
SCHUHEN Consulting GmbHChristian Schuhen
Herrnangerweg 6B
85778 Haimhausen (Germany)
Phone: 08133 / 439 8858
E-Mail:
datenschutz@schuhen-consulting.de
3. Your Rights as a Data Subject
You have the following rights with regard to your personal data:
– Right to information
– Right of access
– Right to rectification or erasure
– Right to restriction of processing
– Right to object to processing
– Right to data portability
4. Data Processing
4.1 General Data Processing and Hosting
This website is hosted by ALL-INKL.COM. When the website is accessed, technical access data is temporarily stored in log files. This data is deleted after 90 days.
4.2 Contact Form
When you send us an enquiry, we collect name, e-mail, and message content. This data is processed server-side and forwarded via TLS-encrypted SMTP. Data is not stored permanently in a database.
4.3 Newsletter
We offer a newsletter service on our website. If you wish to subscribe to the newsletter, we use a double opt-in procedure: After entering your e-mail address, you will receive a confirmation e-mail. Your subscription will only be activated after you confirm the link contained therein.
The following data is stored: e-mail address, language preference (DE/EN), time of confirmation, and a technical confirmation token. No further personal data is collected.
Processing is based on your consent pursuant to Art. 6(1)(a) GDPR. Consent may be withdrawn at any time — either via the unsubscribe link in every newsletter e-mail or by e-mail to info@schuhen-consulting.de. Your data will be deleted immediately upon withdrawal. No tracking of open rates or click rates takes place.
4.4 Post by e-mail
On our blog page, we offer the option to have an individual article sent to you by e-mail. To do so, you enter your e-mail address and receive the article as a one-time formatted e-mail delivery.
The e-mail address you enter is used exclusively for this one-time delivery and is not stored thereafter. There is no further processing, no subscription and no disclosure to third parties. The legal basis is Art. 6(1)(b) GDPR (performance of a measure requested by the data subject) or Art. 6(1)(f) GDPR (legitimate interest in providing the requested content).
4.5 Cookie-free visitor statistics
We maintain our own server-side visitor statistics to understand how often our website is accessed and which content attracts particular interest. These statistics operate entirely without cookies, without local browser storage, and without external services. No personal data is stored permanently.
For each page view, our server calculates an anonymous, non-reversible identifier (SHA-256 hash) from your IP address, your browser signature (without detailed version numbers), and a secret additional value (salt) stored on our server. This identifier is stored in our database for a maximum of 12 hours. It serves solely to avoid double-counting multiple visits by the same visitor within that period. After 12 hours, the identifier is automatically deleted. Your IP address cannot be reconstructed from the stored hash — neither by us nor by third parties — as the secret additional value remains on our server and changes every 12 hours.
The following anonymous metrics are collected: number of unique visitors per day, first page accessed per visit (entry page), total number of page views per page. No cross-session tracking takes place, no data is linked with other sources, and no data is shared with third parties.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the statistical evaluation of website usage for the purpose of quality assurance and continuous content improvement).
4.6 Technical Security Measures
We use session cookies (strictly necessary), CSRF tokens, honeypot fields, rate limiting, and anonymised IP recording. No analytics tools or trackers are integrated.
5. Data Security
All data transmitted between your browser and this server is fully encrypted (HTTPS / TLS). Access to internal systems is role-based and restricted.
6. Data Retention and Deletion
We process and store personal data only for as long as is necessary to fulfil our contractual and legal obligations.
7. Updates to this Privacy Policy
We reserve the right to amend this privacy policy as required. The current version is always available on this page.