Legal
Privacy Policy
Effective 9 September 2026
1. Controller
The controller responsible for processing personal data on this website is:
Schimanski GmbH
Kufsteiner Str. 8a
85521 Riemerling
Germany
Phone: +49 176 41592738
This policy covers visitors to this website and anyone who contacts us through the contact form, by phone or by email.
2. Data we collect
We limit collection to what an enquiry actually requires:
- Contact form data — your name, company name, phone number, email address if you supply one, the service selected and the text of your brief.
- Server and technical data — browser and device type, approximate location derived from your IP address, and which pages were opened.
- Anything shared voluntarily — details you give us by phone or email while we discuss a possible project.
The scope calculator on our home page runs entirely in your browser. Your selections are not transmitted to us, logged or stored anywhere.
We do not process payment card details through this website, and we never ask for passwords or identity documents in the contact form.
3. Purposes
- Answering your enquiry and preparing a proposal or estimate.
- Performing a contract once we begin working together, including correspondence and invoicing.
- Operating the website securely and understanding which sections visitors use.
- Meeting statutory obligations, in particular retention duties under German commercial and tax law.
We do not sell personal data and we do not use it for third-party advertising.
4. Legal basis
Processing is based on Article 6(1) GDPR, read together with the German Federal Data Protection Act (BDSG): point (a) consent, where you submit the contact form; point (b) steps taken at your request before entering into a contract and performance of that contract; point (f) our legitimate interest in a secure, functioning website; and point (c) compliance with legal obligations.
5. Hosting and server logs
This website is hosted by an external content-delivery and hosting provider. When you open a page, the provider's servers automatically record technical information such as the requesting IP address, time of access, the page requested, referrer and user agent. This is necessary to deliver the site and to defend against attacks, and rests on Article 6(1)(f) GDPR. Log data is retained only briefly and is not combined with other data to identify you.
6. Retention
Enquiries that do not lead to a project are kept for up to twelve months in case you return to us. Data connected to an active or completed contract is kept for the duration of the engagement and afterwards for the statutory retention periods under the German Commercial Code (HGB) and Fiscal Code (AO), which run to six or ten years depending on the document.
7. Recipients
We do not disclose personal data to third parties for their own purposes. It may be processed on our behalf, strictly as needed to run the business, by:
- our hosting and content-delivery provider, including attack protection;
- the service that receives and forwards contact form submissions;
- email and project-management tools used by our team;
- our tax advisers, and public authorities where the law requires disclosure.
Each processor operates under a data processing agreement pursuant to Article 28 GDPR.
8. Transfers outside the EEA
Some of our technical providers run infrastructure outside the European Economic Area. Where data is transferred, it takes place on the basis of an adequacy decision of the European Commission or on Standard Contractual Clauses under Article 46 GDPR, so the level of protection follows the data.
9. Cookies
The site uses only cookies that are technically necessary to load and display it, which fall under Section 25(2) TDDDG and require no consent. Should we introduce analytics or other non-essential cookies, they will only be set after you have given consent, and this policy will be updated accordingly.
10. Your rights
Under Articles 15 to 21 GDPR you have the right to:
- obtain confirmation of whether we process data about you, and receive a copy;
- have inaccurate data corrected;
- have data erased where there is no longer a basis to keep it;
- restrict processing, or object to processing based on our legitimate interest;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise any of these, contact us using the details in section 1.
11. Right to complain
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work. For our office the competent authority is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Ansbach.
12. Security
We apply appropriate technical and organisational measures under Article 32 GDPR: encrypted connections (TLS/HTTPS), access to enquiries limited to the people who need it, and regular updates to the systems we operate. No transmission over the internet can be guaranteed absolutely secure, and we make no such claim.
13. Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect data from anyone under the age of 16.
14. Changes
We may update this policy when our processes or the applicable law change. The effective date at the top of the page always reflects the current version, and material changes will be marked here.