Privacy policy
Protecting your data is not a side issue for us. This policy follows German and European data protection law (DSGVO / GDPR) and explains which personal data is processed when you visit this website, for what purpose and on what legal basis — and which rights you can exercise at any time.
Controller
The controller for data processing on this website within the meaning of the General Data Protection Regulation (DSGVO / GDPR) is the following entity. Please also direct any questions about data protection and any request to exercise your rights to this address:
- Flash Werbetechnik
- Owner: [FLASH WERBETECHNIK INHABER]
- [STRASSE NR]
- [PLZ] Berlin
- Germany
- Phone: [TELEFON]
- Email: contact@dioriads.solutions
General information on processing and legal bases
We process personal data only to the extent necessary to provide a functioning website along with our content and services. Personal data is any information relating to an identified or identifiable natural person — for example a name, an email address or an IP address.
You do not have to provide any personal data simply to browse this website. When you contact us, you share your data voluntarily; without it, however, we cannot answer your enquiry.
Processing only takes place where you have given your consent or where the law permits it. The legal bases relevant to this website are:
- Art. 6 (1) (a) GDPR — your consent, for example for optional features. You can withdraw consent at any time with effect for the future.
- Art. 6 (1) (b) GDPR — processing for the performance of a contract or for pre-contractual steps, in particular for project enquiries.
- Art. 6 (1) (f) GDPR — our legitimate interest in operating the website securely, reliably and free of abuse, provided your interests and fundamental rights do not override it.
Hosting and server log files
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The host processes the data transmitted through the site exclusively on our behalf and on our instructions; a data processing agreement under Art. 28 GDPR is in place with Hetzner.
Each time a page is called up, the server automatically collects information transmitted by your browser and stores it in what are known as server log files. The purpose of this processing is the technical delivery of the pages, maintaining system security and investigating faults and attempted attacks.
The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in stable and secure operation. Log files are deleted after 30 days at the latest, unless they are needed longer in an individual case to investigate a specific security incident. This data is not merged with other data sources.
The following data is recorded:
- IP address of the requesting device
- date and time of access
- name and address of the page or file retrieved
- referrer URL, i.e. the page visited previously
- browser type and version
- operating system in use
- volume of data transferred and HTTP status code
Contact form
The contact form lets you send us a non-binding project enquiry. It processes your name, your email address, the project type you select, the budget range you state, your message as well as the site language you have selected and the time your enquiry arrives. Providing a phone number is optional. Submitting the form requires you to confirm that you have read this privacy policy; that confirmation is only checked and is not stored separately.
We use this data solely to handle your enquiry and reply to you. The legal basis is Art. 6 (1) (b) GDPR, because the processing serves pre-contractual steps. If your message does not concern a possible contract, we rely on our legitimate interest in answering enquiries under Art. 6 (1) (f) GDPR.
The data is not passed on to third parties, with the exception of the processor used for technical delivery, which we name in the following section. We delete your enquiry once it has been dealt with conclusively and no retention obligations apply — as a rule six months after the last contact at the latest. Statutory commercial and tax retention periods remain unaffected.
To protect against abusive bulk submissions we limit the number of submissions per IP address. For this purpose the IP address is counted for a maximum of ten minutes in the server's working memory only and is not stored permanently. The legal basis is Art. 6 (1) (f) GDPR.
Email delivery via Resend
The details you submit through the contact form are delivered to us by email. We use the Resend service provided by Resend, Inc., USA, for the technical delivery.
Resend processes the content of your enquiry and the associated delivery metadata exclusively on our behalf and on our instructions. A data processing agreement under Art. 28 GDPR is in place with Resend. Where data is transferred to the USA in this context, the transfer is based on the European Commission's standard contractual clauses or on an adequacy decision under Art. 45 GDPR.
The legal basis is Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR. If you would rather avoid any transfer to a service provider outside the European Union, please write to us directly by email or give us a call.
Contact via WhatsApp
This website offers you the option of writing to us on WhatsApp. Using it is entirely voluntary — you can reach us just as well by email, by phone or through the contact form.
When you click the WhatsApp button, you are forwarded to a chat with the number [WHATSAPP_NUMMER]. The service is operated by WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland. In doing so, WhatsApp processes your phone number, your profile details, the content of the conversation and metadata such as timestamps and device identifiers. We have no influence over the scope and purpose of that processing.
WhatsApp belongs to the Meta group. Data may therefore also be transferred via Meta Platforms, Inc. to the USA and to further third countries outside the European Union where a level of protection comparable to the GDPR is not guaranteed. For details, please refer to WhatsApp's privacy notice: https://www.whatsapp.com/legal/privacy-policy-eea
We ourselves process the data transmitted in the chat only in order to answer your enquiry. The legal basis is Art. 6 (1) (a) GDPR — the consent you give by deliberately starting the chat — and Art. 6 (1) (b) GDPR where the communication serves to prepare a contract. Please do not send us special categories of personal data via WhatsApp.
Analytics and marketing services
No analytics, tracking or marketing services are active in the standard operation of this website. We do not measure reach, we do not build visitor profiles, and we embed no social media plugins that establish connections to third parties on their own when a page loads.
The “Statistics” category in the consent banner is prepared but switched off. It only takes effect if we introduce a data-minimising reach measurement in future and you explicitly agree to it. Without your consent no such service is loaded and no script is executed.
Fonts
The fonts used on this website are served locally from our own server. No connection is made to third-party servers, and in particular no external font libraries are loaded. As a result, your IP address is not transmitted to providers outside our hosting.
Rights of the data subject
As a data subject you have comprehensive rights vis-à-vis the controller. An informal message to the email address given above is enough to exercise them; we answer your request within the statutory deadlines and at no cost to you.
Where we process data on the basis of legitimate interests under Art. 6 (1) (f) GDPR, you have the right to object to that processing on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
Your rights in detail:
- right of access to the data we process (Art. 15 GDPR)
- right to rectification of inaccurate or incomplete data (Art. 16 GDPR)
- right to erasure of your data, provided no retention obligations apply (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR)
- right to object to processing (Art. 21 GDPR)
- right to withdraw consent with effect for the future (Art. 7 (3) GDPR)
- right to lodge a complaint with a supervisory authority (Art. 77 GDPR) — the authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin
Data security
This website uses TLS encryption so that content you send us cannot be read by third parties. You can recognise an encrypted connection by the “https://” prefix in your browser's address bar and by the padlock symbol.
In addition, we take appropriate technical and organisational measures under Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. We review these measures regularly and adapt them to technical developments.
Changes to this privacy policy
We update this privacy policy whenever the legal situation, our services or the services we use change. The version published here applies to your visit; the date of the last change is shown at the top of this page.
If a change requires your consent or materially affects your rights, we will inform you separately and obtain your consent again.