1Controller
The controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Bernhard Römer
E-mail: info@facturado.de
For further contact details, please refer to our Imprint.
For any privacy-related questions, please contact us directly by e-mail.
2Legal Bases for Processing
We process personal data only where a legal basis under Art. 6 GDPR applies:
- Art. 6(1)(a) GDPR – You have given your consent (e.g. usage analysis via Google Analytics).
- Art. 6(1)(b) GDPR – Processing is necessary for the performance of a contract or pre-contractual steps.
- Art. 6(1)(f) GDPR – Processing is necessary for our legitimate interests (e.g. IT security, abuse prevention), provided your interests do not override ours.
3Server Log Files
When you visit our website, technical access data is automatically stored in server log files. This includes:
- IP address (anonymised or full, depending on the hosting provider)
- Date and time of the request
- URL requested
- Browser type, version and operating system
- Referrer URL (previously visited page)
- HTTP status code
This data is processed solely to ensure stable operation, analyse security incidents, and optimise our systems. It is not combined with any other personal data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and system stability).
Retention period: up to 7 days, then automatically deleted.
4Google Analytics
This website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics is only loaded after your explicit consent. Without your consent, no GA code is executed and no tracking cookies are set.
Data processed: Google Analytics collects information about your use of the website, e.g. pages visited, time spent, device information, approximate geographic location (based on the anonymised IP address), and interactions.
IP anonymisation: IP anonymisation is enabled on this website (anonymize_ip: true). Your IP address is truncated within the EU/EEA before transmission to Google.
Measurement ID: G-SDMC4XWGD5
Retention period: User data is stored in Google Analytics for a default period of 14 months.
Legal basis: Art. 6(1)(a) GDPR (your consent).
Opt-out: You can withdraw your consent at any time by resetting your preference via the widget on the left side of this page. Alternatively, you can install the Google Analytics opt-out browser add-on to prevent data collection entirely.
For more information on how Google processes data, please refer to Google's Privacy Policy.
5Cookies & Local Storage
Consent storage (localStorage): Your cookie consent decision (accept or decline) is stored in your browser's local storage under the key facturado-cookie-consent. This information does not leave your device and is not transmitted to us. It is used solely to remember your choice so the banner does not reappear on every visit.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in correctly implementing your consent decision).
Analytics cookies (only after consent): If you consent to Google Analytics, Google sets the following cookies:
6International Data Transfers
We do not share your data with third parties for advertising purposes and we do not sell personal data.
If you consent, data is transferred to Google LLC in the USA via Google Analytics. An adequate level of data protection is ensured through:
- The EU-US Data Privacy Framework (DPF), to which Google LLC is certified, and/or
- Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
Server locations for Google Analytics data processing may be within or outside the EEA. However, due to enabled IP anonymisation, IP addresses are truncated within the EU before any transfer to the USA.
7Your Rights
As a data subject, you have the following rights under the GDPR. To exercise them, please contact info@facturado.de:
- Right of access (Art. 15 GDPR): You have the right to obtain information about the personal data we process about you.
- Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate or completion of incomplete data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your data, unless statutory retention obligations apply.
- Right to restriction (Art. 18 GDPR): You may request that we restrict the processing of your data.
- Right to data portability (Art. 20 GDPR): You have the right to receive your data in a machine-readable format.
- Right to object (Art. 21 GDPR): You may object to processing based on our legitimate interests (Art. 6(1)(f) GDPR).
- Right to withdraw consent (Art. 7(3) GDPR): You may withdraw any consent given at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal. Use the consent widget on this page or contact us by e-mail.
8Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data (Art. 77 GDPR), without prejudice to any other administrative or judicial remedy.
In Germany, the competent supervisory authority is the state data protection authority (Landesdatenschutzbehörde) for the controller's place of establishment. For general information and a list of German supervisory authorities, see the Federal Commissioner for Data Protection and Freedom of Information (BfDI):
www.bfdi.bund.de
Customers in other EU member states may contact the national supervisory authority competent for them. A list of all EU supervisory authorities is provided by the European Data Protection Board (EDPB).
9Data Security
This website uses TLS/SSL encryption to protect the transmission of personal data and other confidential content. You can identify an encrypted connection by the padlock icon in your browser's address bar and the https:// protocol prefix.
We implement appropriate technical and organisational measures (TOMs) to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorised access.
10Changes to this Policy
We reserve the right to update this privacy policy to reflect changes in the law or in our data processing activities. The current version is always available on this page. We recommend checking this page regularly to stay informed about any changes.
For material changes, we will notify you proactively where possible. The version current at the time of your visit always applies.