Privacy Policy
This is the English version of the privacy policy. In case of discrepancies, the German version at /datenschutz prevails.
Last updated: 14 September 2026
1. Data protection at a glance
General information
The following gives a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. You will find detailed information in the sections below.
Who is responsible?
This website is operated by SCRM Consulting GmbH. You will find the contact details under “Controller”.
How do we collect your data?
Some data is collected when you provide it to us, for example by email or when booking an appointment. Other data is collected automatically by our IT systems when you visit the website (e.g. browser, operating system, time of access). We only measure how the website is used if you have given consent in the consent banner.
What do we use your data for?
To provide the website, to handle your enquiries and appointments and, with your consent, to measure website usage.
What rights do you have?
You have the right to receive information free of charge about the origin, recipients and purpose of your stored personal data, to have it corrected or erased, to restrict processing, to data portability and to withdraw any consent with effect for the future. You also have the right to lodge a complaint with a supervisory authority. Please contact us at any time.
2. Hosting
Servers at Hetzner in Germany
This website runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in data centres in Germany. The servers are operated on our behalf by Digital Impact Technology UG (haftungsbeschränkt), Im Rehwinkel 6, 28816 Stuhr, Germany.
When you access the website, these servers process in particular IP addresses, access times and technical information about your browser (see “Server log files”).
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, fast and reliable provision of our website.
Data processing agreement
We have concluded a data processing agreement with our service provider under Art. 28 GDPR. Processing takes place exclusively on our instructions and within the EU.
3. General and mandatory information
Data protection
We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. Data transmission over the internet, for example by email, may have security gaps. Complete protection against access by third parties is not possible.
Controller
SCRM Consulting GmbH
Daimlerstraße 3, 73469 Riesbürg, Germany
Represented by the managing directors Dr. Marc Wiedenmann and Dr. Manuel Brauch
Phone: +49 1520 7550995
Email: kontakt@scrm-guard.de
The controller is the legal entity that alone or jointly with others determines the purposes and means of processing personal data.
Retention period
Unless a more specific retention period is stated in this privacy policy, your personal data remains with us until the purpose of processing no longer applies. If you make a justified request for erasure or withdraw your consent, we will delete your data unless other legally permissible reasons apply, such as retention periods under tax or commercial law.
Legal bases for processing
Depending on the purpose, we process data on the basis of Art. 6(1)(a) GDPR (consent), (b) (contract or pre-contractual measures), (c) (legal obligation) and/or (f) GDPR (legitimate interests). Storing information on your device or accessing it is additionally governed by section 25 TDDDG (German Telecommunications Digital Services Data Protection Act): with consent under section 25(1) TDDDG or, where strictly necessary, under section 25(2) no. 2 TDDDG.
Recipients of personal data
We work with only a few external parties: server hosting, appointment booking and email via Microsoft 365, and web analytics. Data is only passed on if this is necessary to perform a contract, required by law, justified by a legitimate interest or if you have consented. We have concluded data processing agreements under Art. 28 GDPR with our processors.
Transfers to third countries
Some of the services we use (Microsoft, Cloudflare as a sub-processor of Rybbit) belong to companies based in the USA. A transfer to the USA can therefore not be ruled out. It takes place on the basis of the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), where the recipient is certified, or on the basis of EU standard contractual clauses (Art. 46(2)(c) GDPR).
Withdrawal of consent
Many data processing operations are only possible with your express consent. You can withdraw consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to object under Art. 21 GDPR
Where processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time on grounds relating to your particular situation; this also applies to profiling based on these provisions. Where your data is processed for direct marketing, you may object to this processing at any time.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or to perform a contract in a common, machine-readable format, or to have it transmitted to another controller, where technically feasible.
Access, rectification, erasure and restriction
Within the scope of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin, recipients and the purpose of processing, and a right to rectification, erasure or restriction of processing.
SSL/TLS encryption
For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” in your browser’s address bar.
Objection to advertising emails
We hereby object to the use of the contact details published in our imprint for sending unsolicited advertising and information material.
4. Data collection on this website
Cookies and browser storage
This website does not set cookies.
We store your choice in the consent banner in your browser’s local storage (localStorage, entry “scrm-consent”) so that the banner does not reappear on every page. The entry remains until you delete it in your browser or change your choice. The legal basis is section 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. Other entries are only stored by the web analytics, and only after your consent (section 5).
Server log files
Our web server automatically collects and stores information transmitted by your browser: page requested, browser type and version, operating system, referrer URL, time of the request and IP address. This data is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the technically error-free presentation and security of the website.
Enquiries by email or phone
If you contact us by email or phone, we process your details (e.g. name, company, email address, phone number, content of your enquiry) to handle your request. We process emails via Microsoft 365 (Microsoft Ireland Operations Limited). We do not pass on this data without your consent.
The legal basis is Art. 6(1)(b) GDPR if your enquiry relates to a contract or pre-contractual measures, otherwise Art. 6(1)(f) GDPR (efficient handling of enquiries). We delete the data once your request has been fully dealt with, unless statutory retention periods apply.
Appointment booking via Microsoft Bookings
To arrange initial calls, we use Microsoft Bookings, a service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The booking page is not embedded on this website, only linked. Data is only transmitted to Microsoft once you click “Book an initial call” and the booking page opens in a new window.
When you book, we process the data you provide (name, email address, selected slot, and phone number and notes if given). You receive a confirmation by email, and the appointment is entered in our calendar. If the call takes place as an online meeting via Microsoft Teams, Microsoft processes the data needed to take part (e.g. display name, connection data, audio and video during the call).
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). Microsoft processes the data on our behalf under a data processing agreement (Microsoft Products and Services Data Protection Addendum). Microsoft stores data of Microsoft 365 customers in the EU (EU Data Boundary); a transfer to the USA is nevertheless possible, see “Transfers to third countries”. Microsoft’s privacy statement also applies on the booking page: privacy.microsoft.com/en-gb/privacystatement.
We delete booking data once it is no longer needed for the appointment and any follow-up questions, unless statutory retention periods apply.
5. Web analytics with Rybbit
Scope of processing
To understand how our website is used, we use the open-source web analytics tool Rybbit as a cloud service of the provider Rybbit (rybbit.com). The analytics script is only loaded after you click “Accept” in the consent banner.
Rybbit records pages visited (address, title, URL parameters), the referring page, browser, operating system, device type, screen size, language, country and region, and the duration and path of the visit. According to the provider, your IP address is only processed briefly to determine country and region and is not stored. Rybbit does not set cookies but stores a randomly generated visitor identifier in your browser’s local storage (localStorage, entry “rybbit-visitor-id”) to recognise returning visits. This identifier contains no information about you; we do not combine the analytics data with other data.
Legal basis and withdrawal
The legal basis is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG. You can withdraw consent at any time via “Privacy settings” in the footer or in section 3 of this privacy policy. On withdrawal, the visitor identifier is deleted from your browser and the script is no longer loaded.
Provider, hosting and retention
Rybbit processes the data on our behalf under a data processing agreement (Art. 28 GDPR). According to the provider, the data is stored on servers of Hetzner Online GmbH in Germany. Rybbit uses Cloudflare, Inc. (USA) as a sub-processor to deliver the script; a transfer to the USA is possible and safeguarded by EU standard contractual clauses. We keep the analytics data for as long as it is needed for evaluation, at most for the retention period agreed with Rybbit. Provider’s privacy policy: rybbit.com/privacy.
6. Social media: LinkedIn
We maintain a company page on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland). This website only contains a simple link to that page; no LinkedIn plugins, buttons or tracking pixels are embedded. Visiting this website therefore does not transmit any data to LinkedIn.
Only when you follow the link does LinkedIn process your data under its own terms. We are joint controllers with LinkedIn for the page statistics (“Page Insights”, Art. 26 GDPR). The legal basis for operating the company page is Art. 6(1)(f) GDPR (public relations and communication with prospects). LinkedIn privacy policy: www.linkedin.com/legal/privacy-policy.
7. Fonts
Locally hosted fonts
For consistent display we use the Manrope font. It is served from our own server. No connection to Google or other font providers is made when you visit this website.