Zweite Schicht DE, Deutsche Fassung Book a call

Legal

Updated

Privacy policy

This English version is a convenience translation. The German version (Datenschutzerklärung) is authoritative.

This website works without cookies, without tracking pixels and without embedded third-party services. Everything we process is listed here in full.

1. Controller

WDM Webdesign München GmbH, Deisenhofener Str. 45, 81539 Munich, Germany, telephone +49 89 856 371 00, email projekt@wdm.de, represented by the managing director Marie-Anne Le Corre. We are not legally required to appoint a data protection officer; please send any data protection enquiries to the address above.

2. Visiting the website (server log files)

When you visit this website, the web server processes technically necessary data: IP address, date and time, the page requested, the amount of data transferred, browser type and operating system, and the previously visited page (referrer). These data are stored in server log files and deleted after 14 days at the latest. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and stable operation of the website and protection against attacks.

The website is hosted in Germany by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp. A data processing agreement under Article 28 GDPR is in place with Mittwald.

3. Contact form, call booking, tools and email

If you use the contact form, we process the details you enter: your request, company, name, email address and, on a voluntary basis, telephone number, systems in use, message and preferred date. The data are sent to us by email and used to handle your enquiry and to prepare a contract. The legal basis is Article 6(1)(b) GDPR (steps prior to entering into a contract) and Article 6(1)(f) GDPR (answering enquiries).

Call booking

If you choose a slot on the Book a call page, we process the chosen slot, your name, your company, your email address and, on a voluntary basis, telephone number and topic. The details are sent to us by email, and you receive a confirmation with a calendar entry. The legal basis is Article 6(1)(b) GDPR (steps prior to entering into a contract) and Article 6(1)(f) GDPR (organising the call). To prevent a slot from being booked twice, we store the booked time period and a random identifier on our server for 14 days, without name or contact details.

We read the available times from our own calendar. Only time periods are evaluated, not the content of other appointments, and no data are transmitted to the calendar provider.

Potential check

The potential check evaluates your answers in your browser; as long as you do not request the result by email, none of it reaches us. If you request it, we process your answers, the evaluation, your name, your company and your email address in order to send you the result and handle your enquiry. The legal basis is Article 6(1)(b) GDPR (fulfilling your request) and Article 6(1)(f) GDPR (handling prospective customers). The details are stored only in the email to you and to us, not in a database.

Checklist for introducing AI

The boxes you tick on the checklist page are stored only by your browser (localStorage), so that they are still there on your next visit; they are not transmitted to us. You can remove them at any time with "Clear all ticks" or by deleting the website data in your browser. If you request the checklist by email, we process your name, on a voluntary basis your company, your email address and the state of your ticks in order to send you the list (Article 6(1)(b) and (f) GDPR); this is stored only in the email.

Cost calculator

The cost calculator runs in your browser; your figures reach us only if you request the calculation by email. In that case we process your inputs, the result, your name, your company and your email address in order to send you the calculation and handle your enquiry (Article 6(1)(b) and (f) GDPR). The details are stored only in the email to you and to us.

Spam protection and email delivery

To protect against automated submissions, the forms use a time-based check and a hidden field; no cookies are set and no data are transmitted to third parties. Rejected automated submissions are logged with IP address and time for 30 days (Article 6(1)(f) GDPR, prevention of misuse).

To send the form emails and the acknowledgement to you, we use the Postmark service of ActiveCampaign, LLC, 1 North Dearborn Street, Chicago, IL 60602, USA. Your email address and the content of the enquiry, the booking or the requested result are transmitted to Postmark. A data processing agreement including the EU standard contractual clauses is in place with ActiveCampaign; ActiveCampaign is also certified under the EU-US Data Privacy Framework. Postmark stores message content for no more than 45 days.

We store enquiries until they have been dealt with, provided no statutory retention obligations apply. If a contract is concluded, the retention periods under commercial and tax law of up to ten years apply.

4. Audience measurement without cookies

We measure the use of this website with Plausible Analytics (Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia). Plausible sets no cookies, stores no IP addresses and creates no user profiles. It records pages visited, referrer, device type, browser and country, each in aggregate. Processing takes place on servers in the EU. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is evaluating usage in order to improve our offering. Consent is not required, as no information is stored on or read from your device.

5. No cookies, no embedded services

This website sets no cookies. Fonts are loaded from our own server, not from Google or other providers. No third-party maps, videos, social media buttons or chat services are embedded.

6. Recipients and transfers to third countries

The only recipients of your data are the processors named in this policy (Mittwald, ActiveCampaign/Postmark, Plausible). Data are transferred to a third country only for sending via Postmark to the USA, on the basis of the EU-US Data Privacy Framework and the EU standard contractual clauses.

7. Your rights

You have the right of access (Article 15 GDPR), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20) and to object to processing based on Article 6(1)(f) GDPR (Article 21). To exercise these rights, contact us at the address given in section 1. You also have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany.

8. Data protection in our services

How we handle our customers' data in projects, which operating modes we offer and which sub-processors are used for each workflow are described on the Data sovereignty page. For projects, we conclude a data processing agreement under Article 28 GDPR before the first access to any data.

9. Changes

We update this policy when the website or the legal situation changes. Last updated: October 2026.