Privacy Policy

This policy explains how personal data is processed when you visit janditgen.com or contact us. It applies to the German and English sections of the website. Personal data means any information relating to an identified or identifiable individual. Examples include a name, email address, telephone number and IP address.

The website does not currently use its own cookies, analytics tools, advertising or marketing pixels, or technology designed to build user profiles. There are no user accounts, newsletters or online shops. Personal data is processed mainly when you submit a contact form, send an email, call us or request a page from the web server. One separate connection needs to be mentioned: a ProvenExpert rating seal shown on German pages is partly loaded directly from ProvenExpert. That request is described in section 10.

1. Controller

The controller responsible for personal data processed through this website is:

EWK Vortrags GmbH & Co. KG
Gartenstr. 6
50996 Cologne
Germany

Telephone: +49 221 80 14 96 11
Email for data protection requests and objections: widerspruch@mail-gvt.de

You may use these contact details for any data protection request. Adding “Data protection” to the subject line of an email will help us direct your request to the right person.

2. Legal bases

We process personal data only where a legal basis is available. Depending on the reason for the processing, the following provisions of the General Data Protection Regulation may apply:

  • Article 6(1)(b) GDPR: processing required to answer an enquiry connected with a possible contract or booking, to take steps requested before a contract is entered into, or to perform an existing contract;
  • Article 6(1)(f) GDPR: processing required for a legitimate interest, such as operating the website securely, preventing misuse, answering general enquiries or presenting verifiable customer ratings;
  • Article 6(1)(c) GDPR: processing required to meet a statutory retention, evidence or cooperation duty;
  • Article 6(1)(a) GDPR: processing based on consent where we expressly ask for it. The ordinary contact forms do not enrol you in a newsletter or an advertising list.

The relevant legal basis is explained in more detail for each type of processing below. The official English text of the GDPR is available from EUR-Lex.

3. Page requests and server logs

Every website request requires the browser to send technical information to a web server. Depending on the server configuration, this may include the requesting device's IP address, date and time, the requested file or URL, referrer, browser type and version, operating system, amount of data transferred, response status and error information. The server needs some of these details to deliver the requested page to your device.

We process this information to provide the website, maintain stable operation, investigate faults and protect the service against attacks or abusive access. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and commercially reasonable operation of the website.

Server logs are not used for audience measurement, advertising or personal visitor profiles. They are kept only for as long as they are required for operation, troubleshooting and security. The precise short-term retention period is governed by the server configuration and the agreement with the hosting provider. If a security incident or specific case of misuse occurs, relevant log entries may be retained until the incident has been investigated and any legal claims have been pursued or defended.

The hosting provider processes server data on our behalf. It may use that data only within the hosting agreement, our instructions and applicable law.

4. Encrypted transmission

The website is delivered over HTTPS. Transport encryption protects information while it travels between your browser and the server, reducing the risk of interception or alteration in transit. A secure connection is usually shown by “https://” in the browser's address bar. Transport encryption cannot protect data already exposed on your own device, and it does not make unnecessary information in a free-text field safer to share.

5. Contact forms

Data submitted through a form

Contact forms are available on several pages. Depending on the form and language version, we may process:

  • your title or form of address;
  • first name and surname;
  • email address;
  • telephone number;
  • company or organisation;
  • proposed event date;
  • the message you enter;
  • an internal form identifier used to show where the enquiry originated;
  • technical submission information such as time, IP address, browser details, delivery status and information used to detect misuse.

Required fields are marked with an asterisk or configured as mandatory in the form. These details are needed to associate an enquiry with a person and send a reply. A telephone number, company and event date are normally optional. Please do not place special categories of personal data in the message field, including health information, religious or political beliefs, trade union membership or other particularly sensitive details, unless they are genuinely needed for your request.

Purposes and legal bases

We use the submitted information to answer your message, ask follow-up questions, check availability for an event, prepare a quotation and, where applicable, arrange or perform a booking or another contract. If your enquiry concerns a prospective or existing contract, Article 6(1)(b) GDPR is the legal basis. General messages without a contractual purpose are handled under Article 6(1)(f) GDPR. The legitimate interest is maintaining orderly, documented business communication and responding to genuine enquiries.

Form data is not automatically added to a newsletter and is not used for personalised advertising or profiling. Any separate marketing communication would require its own legal basis.

Formspree

The forms use Formspree, a service supplied by Formspree, Inc. When you submit a form, its contents are sent directly to a Formspree endpoint. Formspree receives the submission, may inspect it for spam or misuse, makes it available through a Formspree dashboard and sends a notification to the configured email address. Formspree and the technical sub-processors it uses therefore receive the form contents and associated connection data.

Formspree states that its service is hosted on Amazon Web Services in the United States. Processing in the United States may therefore occur. Formspree also states that it relies on the European Commission's Standard Contractual Clauses when acting as a processor. These clauses provide contractual safeguards for transfers to a country outside the European Economic Area. They cannot guarantee that the legal environment in a third country will be identical to that of the European Union.

Further information is available in the Formspree Privacy Policy and on the Formspree security page.

Retention of form enquiries

Form enquiries may be held in the Formspree account, in notification emails and in later business correspondence. An enquiry that does not lead to a business relationship is deleted after it has been fully dealt with, provided that no statutory duty or limited legitimate need requires further retention. Relevant considerations include unresolved follow-up questions, documenting a refusal, preventing misuse and the limitation period for possible legal claims.

If the enquiry results in a quotation, booking or other business transaction, German commercial and tax retention rules may apply. Business correspondence and records relevant to taxation may have to be kept for six, eight or ten years under section 147 of the German Fiscal Code, depending on the type of document. The statutory period generally starts at the end of the relevant calendar year. Data is deleted when the applicable period expires unless another legal basis requires continued retention.

6. Email and telephone contact

If you contact us by email, we process the sender address, message, technical email headers and any other information you choose to include. During a telephone call, we may process the number, time of the call, notes about the conversation and an agreed callback. We use this information only to deal with the contact, prepare or perform a business relationship and retain the documentation that is genuinely required.

The same legal bases used for the contact forms apply: Article 6(1)(b) GDPR for contractual and pre-contractual communication, Article 6(1)(f) GDPR for other business enquiries, and Article 6(1)(c) GDPR where retention is required by law.

7. Cookies and browser storage

janditgen.com does not currently set its own cookies. The site also does not store identifiers or usage profiles in your browser's Local Storage or Session Storage. It therefore does not display a consent banner for analytics or marketing cookies. Future technical changes remain subject to the rules governing access to terminal equipment, including section 25 of Germany's Telecommunications Digital Services Data Protection Act.

This statement concerns the technology operated by us on janditgen.com. If you follow a link to a third-party site, that provider's privacy and cookie rules apply. The third party may use cookies or similar technologies on its own website.

8. No analytics, advertising tracking or profiling

The website does not use Google Analytics, Google Tag Manager, Matomo, the Meta Pixel, heatmaps, session recording or comparable analytics and advertising services. We do not run audience measurement that recognises a visitor across pages or separate visits. We do not build interest profiles or combine website use with information from advertising networks or social networks.

The central website script contains a dormant compatibility check for an event function that could previously have been used with analytics. No analytics library is loaded, so the check does not send information to an analytics provider.

9. Locally hosted media and fonts

The regular images, logos, icons, stylesheets, fonts, JavaScript files and videos are supplied from the website's own hosting environment. Loading these local files does not create an additional connection to a font, video or social-media provider. The site does not embed YouTube players, Google Maps, social feeds or external font libraries through scripts or iframes.

10. ProvenExpert rating seal

A ProvenExpert rating seal appears on German pages. The image is currently loaded in part from the domain images.provenexpert.com. Opening a page with that image may therefore establish a connection to ProvenExpert or one of its technical providers. At a minimum, the request can disclose the IP address, time, requested image, browser information and possibly the referring page. Any additional use of cookies or other information by ProvenExpert depends on the provider's technical response and its own privacy policy.

We do not embed a ProvenExpert analytics script or iframe at this point. The image presents customer ratings and supports a verifiable account of our business reputation. Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the transparent display of publicly submitted reviews. Clicking a ProvenExpert link may take you away from our website or to a separate review page, where the relevant provider is responsible for its own processing.

Details about ProvenExpert's processing are available in the ProvenExpert Privacy Policy.

11. Recipients and processors

Within EWK Vortrags GmbH & Co. KG, access is limited to people who need personal data to answer an enquiry, organise an event, administer a contract, keep accounts or maintain the website. The following categories of recipient may also receive data where necessary:

  • hosting and technical operations providers;
  • Formspree and its sub-processors for form delivery;
  • email and communications providers;
  • ProvenExpert and its technical providers when the externally hosted seal is requested;
  • tax advisers, legal advisers and other professionals subject to duties of confidentiality;
  • public authorities or courts where disclosure is required by law or necessary to establish, exercise or defend legal claims.

Providers that process data solely on our behalf are contractually bound under Article 28 GDPR. We do not sell contact details or disclose them to another company for that company's advertising.

12. Transfers outside the European Union

Use of Formspree may result in data being transferred to and processed in the United States. Formspree refers to Standard Contractual Clauses for its work as a processor. If another provider processes personal data outside the European Union or European Economic Area, such a transfer takes place only where the requirements of Articles 44 to 49 GDPR are met, for example through an adequacy decision, appropriate safeguards or a statutory exception.

13. Requirement to provide data

You are not legally or contractually required to use the contact form. Without the fields marked as mandatory, however, the form cannot be sent or the enquiry cannot be answered properly. Optional details can make a reply easier but are not a condition of contact. If you do not want to submit information through Formspree, you may call or email us instead. An email will still be processed by the email providers involved in its delivery.

14. Automated decision-making

We do not make decisions based solely on information collected through this website that produce legal or similarly significant effects for an individual. No profiling within the meaning of Article 22 GDPR takes place. Technical filters may inspect a form submission for spam or abuse; a person remains responsible for the substantive handling of the enquiry.

15. Your data protection rights

Subject to the conditions set out in law, you have the following rights:

  • Access under Article 15 GDPR: you may ask whether we process your personal data and obtain information about that processing.
  • Rectification under Article 16 GDPR: you may have inaccurate information corrected and incomplete information completed.
  • Erasure under Article 17 GDPR: you may request deletion where no statutory duty or overriding legal ground requires continued retention.
  • Restriction under Article 18 GDPR: you may request restricted processing in the circumstances set out in the GDPR.
  • Data portability under Article 20 GDPR: where the legal conditions are met, you may receive data you provided in a structured, commonly used and machine-readable format.
  • Objection under Article 21 GDPR: you may object to processing based on Article 6(1)(e) or (f) GDPR.
  • Withdrawal of consent under Article 7(3) GDPR: consent may be withdrawn at any time for future processing. Withdrawal does not affect the lawfulness of processing carried out beforehand.

You can exercise these rights by contacting us using the details in section 1. If there is reasonable doubt about identity, we may request suitable evidence so that personal data is not disclosed or changed for an unauthorised person. Any identity evidence should contain only the information needed for that check.

16. Specific information about the right to object

If we process personal data under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing the relevant data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.

You can send an objection to widerspruch@mail-gvt.de.

17. Right to complain to a supervisory authority

Article 77 GDPR gives you the right to lodge a complaint with a data protection supervisory authority. You may contact the authority for your habitual residence, place of work or the location of the alleged infringement. The supervisory authority generally responsible for the controller's registered location is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Telephone: +49 211 38424-0
Email: poststelle@ldi.nrw.de

The authority provides an online complaint form at ldi.nrw.de. You are welcome to contact us first so that we can try to resolve the matter directly, but doing so does not restrict your right to complain.

18. Security and confidentiality

We use technical and organisational measures intended to protect personal data against loss, alteration, unauthorised disclosure and unauthorised access. These measures include encrypted transmission, limited access rights, purpose-based processing and the selection of suitable service providers. No internet service can guarantee absolute security. Particularly confidential information should be sent only through a suitable channel agreed with us in advance.

19. External links

The website links to external information sources, public authorities, studies, social profiles and rating services. Displaying an ordinary text link does not itself send data to the target provider. A connection is made when you open the link, and the target provider becomes responsible for the processing on its service. The direct ProvenExpert image described above is different because the browser may request it as soon as the page loads.

20. Changes to this policy

We update this policy when website functions, providers or legal requirements change. The published version describes the current use of the website. A significant new processing activity, including analytics, advertising or consent-based services, would require technical and legal review and an appropriate update to this notice before deployment.

Last updated: 19 July 2026