Skip to main content
profilux raffrollosysteme GmbH

Privacy Policy

Last updated: 3/10/2026

1. Data Controller

Data controller within the meaning of the GDPR (Art. 4 No. 7):

profilux raffrollosysteme GmbH

Ferdinand-von-Schill-Str. 9

24321 Lütjenburg

Germany

Phone: +49 4381 / 4 15 25-10

Email: info@profilux.de

Data Protection Officer

A data protection officer is not legally required (fewer than 20 persons regularly processing data).

2. Overview (brief)

When visiting this website, various data may be processed depending on usage:

  • Technical access data through server operation (log files).
  • Reach measurement with Umami Analytics (self-hosted, without cookies).
  • Communication data when contacting us (contact form/email/phone).
  • Security-relevant data within our Web Application Firewall (WAF).

Details, purposes, legal bases, and retention periods can be found in the following sections.

3. Hosting & Server Log Files

Type of data: requested URL, date/time, transferred data volume, HTTP status, referrer, browser/OS, IP address (shortened/anonymized where technically possible).

Purpose: Website delivery, stability, error analysis, IT security.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operation/security).

Retention period: maximum 7-14 days; longer retention only on a case-by-case basis (e.g., incident analysis).

Recipients: Hetzner Online GmbH, Germany, as processor under Art. 28 GDPR.

4. Cookies

We do not use tracking or marketing cookies.

Technically necessary cookies: As part of the WAF, a session cookie may be used to securely assign requests or defend against attacks.

Name: sl-session

Purpose: Security/load balancing functions (no tracking).

Retention: End of session.

Provider: Safeline (self-hosted).

Legal basis: Art. 6(1)(f) GDPR (IT security).

5. Reach Measurement with Umami (self-hosted)

We use Umami Analytics as a privacy-friendly, self-hosted solution.

What is collected? Page views, visited URLs (without UTM/tracking parameters), referrer, browser/OS, screen resolution, approximate region (from anonymized IP), time spent.

What is not collected? No complete IP addresses, no cookies, no user profiles, no sharing with third parties.

Purpose: Anonymous statistics to optimize the website.

Legal basis: Art. 6(1)(f) GDPR.

Objection: We respect your browser's Do-Not-Track (DNT) setting. When DNT is active, no data is collected.

Retention: Aggregated event data for 12 months, then deletion/aggregation.

Processing context: Operation on our servers within the EU/EEA.

6. Security / Web Application Firewall (WAF)

To protect our API and analytics endpoints, we use the "Safeline" WAF (self-hosted).

Processing: Checking requests (e.g., rate limiting, bot and attack detection); if applicable, session token (see above).

Personal data: No profiling, no use for marketing purposes.

Legal basis: Art. 6(1)(f) GDPR (security of our IT systems).

Retention: Security-relevant event logs max. 30 days or longer on a case-by-case basis.

7. Contact (Form, Email, Phone)

Type of data: Content data (message), contact data (name, email, phone), metadata (timestamp).

Purpose: Processing your inquiry and correspondence.

Legal bases:

  • Art. 6(1)(b) GDPR (pre-contractual/contractual), if applicable.
  • Art. 6(1)(f) GDPR (legitimate interest in efficient communication).
  • Art. 6(1)(a) GDPR (consent), if voluntary additional information is provided.

Retention: Inquiries are stored for 6 months after completion; statutory retention periods take precedence.

Recipients: Internal departments; if applicable, processors (e.g., mail provider).

8. Local Fonts (Web Fonts)

Fonts are served locally from our server. No connection to third-party providers (e.g., Google).

Legal basis: Art. 6(1)(f) GDPR (uniform, efficient presentation).

9. Recipients / Processors

We may use service providers (hosting, maintenance, email, security).

Data processing agreements (Art. 28 GDPR) are in place; access only on instruction.

Current categories: Hosting, analytics (self-hosted), email service.

10. Third Country Transfers

No transfer to countries outside the EU/EEA takes place.

(If required in the future: will be based on Art. 46 GDPR – in particular Standard Contractual Clauses – and additional measures if necessary. We will inform you in advance.)

11. Retention Period / Criteria

We process personal data only as long as necessary for the respective purposes. The following factors apply: purpose completion, statutory retention periods, limitation periods, security requirements. After expiration, data is deleted or anonymized.

12. Obligation to Provide Data

The provision of technical data is necessary for the operation of the website. Communication data is necessary for responding to inquiries. Further provision is voluntary; without it, certain functions cannot be used.

13. No Automated Decision-Making / Profiling

No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place.

14. Minors

Our services are intended for persons over 16 years of age. If we become aware of unauthorized transmissions, data will be deleted immediately.

15. Your Rights

You have the following rights at any time (free of charge):

  • Access to your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR); always possible for direct marketing.
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR).

To exercise your rights, you can contact us via the contact details above or our contact form.

Supervisory Authority

Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Independent State Center for Data Protection Schleswig-Holstein (ULD)

Holstenstraße 98, 24103 Kiel, Germany

Phone: +49 431 / 988-1200

Email: mail@datenschutzzentrum.de

Website: https://www.datenschutzzentrum.de

16. TLS/SSL Encryption

This website uses TLS/SSL encryption for secure data transmission. You can recognize this by the https:// prefix and the lock symbol in your browser.

17. Changes to this Policy

We update this privacy policy as needed, for example due to technical or legal changes. The current version can always be found on this page. The date of the last update is shown above.