Privacy Policy
Last updated: April 2026
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. Detailed information on the subject of data protection can be found in our privacy policy below.
Data Collection on This Website
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the "Responsible Party" section.
Your data is collected in part by you providing it to us (e.g. via the contact form). Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g. internet browser, operating system or time of page access).
2. Responsible Party
IT Systeme Flores UG (haftungsbeschränkt)
Neufeldweg 25a
51427 Bergisch Gladbach
Germany
Phone: +49 2204 7675640
Email: info@it-flores.de
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
3. Hosting
This website is hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). When you visit our website, the server automatically collects information in so-called server log files. These include:
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address (anonymised)
This data is not merged with other data sources. The basis is Art. 6 (1) (f) GDPR (legitimate interest in the technically flawless provision of the website).
Data Processing Agreement
We have concluded a data processing agreement (DPA) with Hetzner Online GmbH. Data is processed exclusively on servers in Germany.
4. Web Analytics with Creo Analytics
This website uses Creo Analytics, our own web analytics product, operated on servers in Germany (Hetzner Online GmbH). Analysis is performed without cookies and without comparable techniques that store or read information on your device. No cross-device profiles are created and no data is shared with third parties.
Processed per page view: the page requested (without query parameters), the referrer, date and time, browser type and operating system, device class, time on page, scroll depth, and the country derived from the IP address. The IP address is processed only transiently in memory and then discarded. It is never stored.
To count visitors within a calendar day, a check value is derived from the IP address, browser identifier, and a daily-rotating random value; the random value is never stored and is discarded daily. Recognition beyond the calendar day is therefore technically impossible.
The legal basis is our legitimate interest in data-minimising analytics (Art. 6 (1) (f) GDPR). No consent is required, as neither information on your device is accessed (§ 25 TDDDG) nor personal data stored. You may object at any time by enabling "Do Not Track" or "Global Privacy Control" in your browser; visits are then not recorded. More information: analytics.creodigital.de/widerspruch.
5. Google Workspace
We use Google Workspace (Google Ireland Limited) for internal business communication, calendar and file management. When you contact us by email, your data (name, email address, message content) is processed on Google servers as part of handling the email.
Google processes this data under the EU Standard Contractual Clauses. Further information can be found in the Google Workspace Data Processing Agreement.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in efficient business communication).
6. AI-Assisted Data Processing (Anthropic / Claude)
For the internal processing of enquiries and to support our business processes, we use the AI assistant Claude by Anthropic (Anthropic, PBC, San Francisco, USA).
In this context, the following data may be transmitted to Anthropic:
- Content of customer enquiries (name, email, message text)
- Project-related information for internal processing
Anthropic processes data in accordance with their privacy policy. For commercial use (API / Claude Pro), Anthropic states that input data is not used for training AI models.
The transfer to the USA is based on EU Standard Contractual Clauses or the EU-US Data Privacy Framework. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the efficient processing of business operations).
7. Contact Form
If you send us enquiries via the contact form, your details from the form (name, email, phone, message) will be stored by us for the purpose of processing the enquiry and for any follow-up questions. The form first transmits your details to our own server (Hetzner, Germany) and forwards them to us by email from there. No third-party appointment calendars are embedded.
We do not share this data without your consent. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) and Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries).
The data you enter in the contact form will remain with us until you request its deletion, revoke your consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions, in particular retention periods, remain unaffected.
8. Fonts
This website uses exclusively locally hosted fonts. No fonts are loaded from external servers (e.g. Google Fonts). Therefore, no data is transmitted to third parties in connection with fonts.
9. SSL Encryption
This site uses SSL encryption (HTTPS) for security reasons. An encrypted connection is indicated by the browser's address bar changing from "http://" to "https://" and by the lock icon in your browser bar.
When SSL encryption is activated, the data you transmit to us cannot be read by third parties.
10. Your Rights
You have the right at any time to:
- Access your personal data stored by us (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Lodge a complaint with a supervisory authority (Art. 77 GDPR)
Competent supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia), www.ldi.nrw.de.
11. Cookies
This website sets no analytics or marketing cookies and therefore requires no cookie banner. Strictly necessary cookies may be used with the contact form to prevent abuse; these are exempt from consent under § 25 (2) TDDDG.