Privacy Policy
Last updated: 3/10/2026
1. Data Controller
Data controller within the meaning of the GDPR (Art. 4 No. 7):
profilux raffrollosysteme GmbH
Ferdinand-von-Schill-Str. 9
24321 Lütjenburg
Germany
Phone: +49 4381 / 4 15 25-10
Email: info@profilux.de
Data Protection Officer
A data protection officer is not legally required (fewer than 20 persons regularly processing data).
2. Overview (brief)
When visiting this website, various data may be processed depending on usage:
- Technical access data through server operation (log files).
- Reach measurement with Umami Analytics (self-hosted, without cookies).
- Communication data when contacting us (contact form/email/phone).
- Security-relevant data within our Web Application Firewall (WAF).
Details, purposes, legal bases, and retention periods can be found in the following sections.
3. Hosting & Server Log Files
Type of data: requested URL, date/time, transferred data volume, HTTP status, referrer, browser/OS, IP address (shortened/anonymized where technically possible).
Purpose: Website delivery, stability, error analysis, IT security.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operation/security).
Retention period: maximum 7-14 days; longer retention only on a case-by-case basis (e.g., incident analysis).
Recipients: Hetzner Online GmbH, Germany, as processor under Art. 28 GDPR.
4. Cookies
We do not use tracking or marketing cookies.
Technically necessary cookies: As part of the WAF, a session cookie may be used to securely assign requests or defend against attacks.
Name: sl-session
Purpose: Security/load balancing functions (no tracking).
Retention: End of session.
Provider: Safeline (self-hosted).
Legal basis: Art. 6(1)(f) GDPR (IT security).
5. Reach Measurement with Umami (self-hosted)
We use Umami Analytics as a privacy-friendly, self-hosted solution.
What is collected? Page views, visited URLs (without UTM/tracking parameters), referrer, browser/OS, screen resolution, approximate region (from anonymized IP), time spent.
What is not collected? No complete IP addresses, no cookies, no user profiles, no sharing with third parties.
Purpose: Anonymous statistics to optimize the website.
Legal basis: Art. 6(1)(f) GDPR.
Objection: We respect your browser's Do-Not-Track (DNT) setting. When DNT is active, no data is collected.
Retention: Aggregated event data for 12 months, then deletion/aggregation.
Processing context: Operation on our servers within the EU/EEA.
6. Security / Web Application Firewall (WAF)
To protect our API and analytics endpoints, we use the "Safeline" WAF (self-hosted).
Processing: Checking requests (e.g., rate limiting, bot and attack detection); if applicable, session token (see above).
Personal data: No profiling, no use for marketing purposes.
Legal basis: Art. 6(1)(f) GDPR (security of our IT systems).
Retention: Security-relevant event logs max. 30 days or longer on a case-by-case basis.
7. Contact (Form, Email, Phone)
Type of data: Content data (message), contact data (name, email, phone), metadata (timestamp).
Purpose: Processing your inquiry and correspondence.
Legal bases:
- Art. 6(1)(b) GDPR (pre-contractual/contractual), if applicable.
- Art. 6(1)(f) GDPR (legitimate interest in efficient communication).
- Art. 6(1)(a) GDPR (consent), if voluntary additional information is provided.
Retention: Inquiries are stored for 6 months after completion; statutory retention periods take precedence.
Recipients: Internal departments; if applicable, processors (e.g., mail provider).
8. Local Fonts (Web Fonts)
Fonts are served locally from our server. No connection to third-party providers (e.g., Google).
Legal basis: Art. 6(1)(f) GDPR (uniform, efficient presentation).
9. Recipients / Processors
We may use service providers (hosting, maintenance, email, security).
Data processing agreements (Art. 28 GDPR) are in place; access only on instruction.
Current categories: Hosting, analytics (self-hosted), email service.
10. Third Country Transfers
No transfer to countries outside the EU/EEA takes place.
(If required in the future: will be based on Art. 46 GDPR – in particular Standard Contractual Clauses – and additional measures if necessary. We will inform you in advance.)
11. Retention Period / Criteria
We process personal data only as long as necessary for the respective purposes. The following factors apply: purpose completion, statutory retention periods, limitation periods, security requirements. After expiration, data is deleted or anonymized.
12. Obligation to Provide Data
The provision of technical data is necessary for the operation of the website. Communication data is necessary for responding to inquiries. Further provision is voluntary; without it, certain functions cannot be used.
13. No Automated Decision-Making / Profiling
No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place.
14. Minors
Our services are intended for persons over 16 years of age. If we become aware of unauthorized transmissions, data will be deleted immediately.
15. Your Rights
You have the following rights at any time (free of charge):
- Access to your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR); always possible for direct marketing.
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
To exercise your rights, you can contact us via the contact details above or our contact form.
Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Independent State Center for Data Protection Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany
Phone: +49 431 / 988-1200
Email: mail@datenschutzzentrum.de
Website: https://www.datenschutzzentrum.de
16. TLS/SSL Encryption
This website uses TLS/SSL encryption for secure data transmission. You can recognize this by the https:// prefix and the lock symbol in your browser.
17. Changes to this Policy
We update this privacy policy as needed, for example due to technical or legal changes. The current version can always be found on this page. The date of the last update is shown above.