Privacy policy
The German version is the authoritative text.
Controller
controlpunkt GmbH
Basler Straße 3
61352 Bad Homburg v.d.H.
Germany
Managing director: Tomislav Ljubas
Email: hello@controlpunkt.com
In short
This website uses no cookies, embeds no external fonts, and does not send your data to any ad networks. For reach measurement we use cookieless statistics without personal identifiers (section 2); that is why you still do not see a consent banner. There are three places where data is processed: when you visit the site, in these statistics, and when you email us.
1. Visiting the website (server logs)
When you visit, technically necessary data is processed: your IP address, date and time, the requested page, browser type and operating system.
- Purpose: delivering the site, stability and defense against attacks.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is secure, uninterrupted operation.
- Host: Cloudflare, Inc. The site is delivered through their network, which is where the log data above is generated. A data processing agreement is in place with Cloudflare. Cloudflare, Inc. is based in the USA; the transfer is based on the EU Commission's Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework.
- Retention period: these log data are stored only as long as necessary for the stated purposes and then deleted. The technical storage and deletion are handled by our host.
2. Reach measurement (Cloudflare Web Analytics)
We measure which pages are read and how often, using Cloudflare Web Analytics. The tool sets no cookies, stores no identifiers in your browser and does not track you across websites.
- Purpose: Understanding which content is read, to improve the website.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is improving what we offer without intruding on your privacy.
- Provider: Cloudflare, Inc.; the statements on data processing and third-country transfer in section 1 apply.
3. Contacting us by email
This website has no contact form. When you email us, we process what you tell us: your email address, your name and the content of your message.
- Purpose: handling your request and the communication that follows from it.
- Legal basis: Art. 6(1)(b) GDPR where your request is aimed at a contract, otherwise our legitimate interest in answering your request, Art. 6(1)(f) GDPR.
- Email mailbox: our mailbox is operated through Microsoft 365 (Microsoft Ireland Operations Ltd.). Your message reaches us directly, without an additional sending service; no transfer to a third country takes place to handle your request. A data processing agreement with Microsoft is in place on the basis of the Microsoft Data Protection Addendum.
- Retention period: we keep your request as long as necessary to handle it, and afterward within statutory retention periods (in particular Section 257 HGB and Section 147 AO). We then delete it.
4. Your rights
You have the right at any time to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21).
An informal email to us is enough.
You can also file a complaint with a supervisory authority. The competent authority for us is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.
5. No automated decision-making
We do not use automated decision-making or profiling.
6. Changes
We update this policy when the processing changes. The version published on this page at any given time applies. Last updated: July 2026.