Privacy Policy
This English text is a convenience translation. The legally binding version is the German original.
The party responsible for data processing on this website is
Philip Westphal
Westrath GmbH
Charlottenstraße 14
52070 Aachen
Germany
T +49 241. 51 00 00 43
hello@log-key.de
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions, in particular the EU GDPR, the new German Federal Data Protection Act (BDSG-neu) and the German Telecommunications Digital Services Data Protection Act (TDDDG), as well as this privacy policy. The use of our website is generally possible without providing personal data. Insofar as personal data (for example name, address or e-mail addresses) is collected on our pages, this is always done, as far as possible, on a voluntary basis.
Without your express consent, we do not pass this data on to third parties for purposes other than those described in this policy.
Our website uses no cookies and no comparable techniques for recognising visitors across devices. A cookie banner is therefore not required.
The following privacy policy provides you with an overview of how we ensure the protection of your personal data, what type of data is collected for what purpose, and how you can exercise your rights to protect your data.
Server logs
For technical reasons, and in order to defend against, analyse and investigate attacks on our websites, our web server automatically collects and stores in the log files data which your browser transmits to us. This data is: browser type and browser version, operating system used, referrer URL (previously visited website), host name of the accessing computer, time of the server request, IP address. We cannot attribute this data to any specific individuals. This data is not merged with other data sources; in addition, the data is deleted after 30 days.
Hosting and content delivery network (Cloudflare)
This website is hosted via Cloudflare Pages and delivered through Cloudflare's content delivery network (CDN). The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (“Cloudflare”). When you access our website, Cloudflare processes technical connection data (in particular IP address, page accessed, browser and device information) insofar as this is necessary to deliver the website and keep it secure (e.g. to defend against attacks). This processing is based on our legitimate interest in the secure, fast and efficient provision of our online offering (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-U.S. Data Privacy Framework. Further information can be found in Cloudflare's privacy policy: www.cloudflare.com/privacypolicy.
Cookieless web analytics (PostHog, Matomo)
To statistically analyse the use of our website, we use the analytics service PostHog. We use PostHog's EU cloud exclusively; the data is processed on servers in Frankfurt am Main (Germany). We have deliberately configured PostHog without cookies: no cookies are set and no information is stored on or read from your device on a persistent basis; individual visitors are not recognised across visits. The data collected includes, in particular, pages accessed, referrer, browser and device type, and the approximate country of origin.
In addition, we use the analytics software Matomo, which we operate ourselves on our own infrastructure in the EU; no data is transferred to third parties in this respect. Matomo is likewise configured without cookies and stores no information on your device.
The legal basis for web analytics is our legitimate interest in analysing and improving our online offering (Art. 6(1)(f) GDPR). As no cookies are set and no information is stored on or read from your device, consent under Section 25 TDDDG is not required.
Contact form and e-mail delivery (Brevo)
If you send us an enquiry via a contact form on this website, we process the data you provide (e.g. name, e-mail address, where applicable telephone number and company, as well as your message) in order to handle your enquiry. To receive the form data and to send e-mails, we use the service Brevo, provided by Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France (“Brevo”). Processing takes place on servers in the EU. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures taken at your request) or Art. 6(1)(f) GDPR (our legitimate interest in handling enquiries efficiently). Further information: www.brevo.com/legal/privacypolicy.
Appointment booking (Cal.com)
For the online booking of demo and consultation appointments, we use the Cal.com service in its European instance (cal.eu); booking data is processed on servers in the EU. When you make a booking, we process the data you provide (name, e-mail address, where applicable telephone number and details of your request) as well as the selected appointment, in order to arrange and hold the appointment. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures taken at your request) or Art. 6(1)(f) GDPR (our legitimate interest in straightforward appointment scheduling). Further information: cal.com/privacy.
Customer relationship management / CRM (HubSpot)
To manage prospect and customer relationships, we use the CRM system HubSpot. The provider is HubSpot Ireland Ltd., Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland, a company of HubSpot, Inc. (USA). When you sign up for Log+Key via our website or send us an enquiry via the contact form, we transfer your name, e-mail address, where applicable your telephone number, your company and the plan you selected to HubSpot in order to process your registration or enquiry and to contact you in the course of contract initiation. We use HubSpot with EU data residency: the data is stored in a HubSpot data centre in the EU (data location “EU1”). Access by the US parent company cannot be ruled out entirely; HubSpot, Inc. is certified under the EU-U.S. Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR (contract initiation and performance) or Art. 6(1)(f) GDPR (our legitimate interest in the structured management of prospect and customer enquiries). Further information: legal.hubspot.com/privacy-policy.
Internal notifications (Slack)
Our team is notified internally of new registrations and enquiries via the communication service Slack. The provider is Slack Technologies Limited, Salesforce Tower, 60 R801, North Dock, Dublin, Ireland, a company of Salesforce, Inc. (USA). These internal notifications contain only your first name and the name of your organisation; e-mail addresses and other contact details are not transferred to Slack. The legal basis is our legitimate interest in the swift internal handling of incoming enquiries (Art. 6(1)(f) GDPR). Salesforce is certified under the EU-U.S. Data Privacy Framework. Further information: slack.com/trust/privacy/privacy-policy.
Spam protection (Cloudflare Turnstile)
To protect our forms against spam and abusive automated use, we use Cloudflare Turnstile, a service of our hosting provider Cloudflare (provider details above). Turnstile checks in the background, using technical characteristics (e.g. IP address, browser properties, interaction behaviour), whether a form submission originates from a human or from an automated program. For this purpose, Turnstile may store information in or read information from your browser for the duration of the check. This storage or access is strictly necessary to provide the service you have expressly requested (the secure submission of the form); consent under Section 25(1) TDDDG is therefore not required (Section 25(2) No. 2 TDDDG). The legal basis for the processing of personal data is Art. 6(1)(f) GDPR (our legitimate interest in protecting our website against spam and abuse).
Marketing attribution and Google Ads conversion measurement
On your first visit to our website we store the address of your landing page and the referring page (referrer) in your browser's localStorage for a maximum of 90 days. We use this information solely to understand, in case you later register, how you became aware of us (Art. 6(1)(f) GDPR — legitimate interest in privacy-preserving origin analysis). No cookies are set, no profiles are created and no data is transmitted to advertising networks.
If you reach our website via a Google Ads advertisement (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland — "Google"), the page address contains a click ID (gclid), which is likewise stored only locally in your browser. Only if you explicitly consent during registration (checkbox "Allow ad conversion measurement") do we transmit this click ID together with the time of registration to Google via a server-side upload, so that Google can measure the advertisement's performance. Your name, e-mail address and other contact details are not transmitted to Google. The legal basis is your consent (Art. 6(1)(a) GDPR); if you do not consent, the click ID is deleted and never transmitted. You may withdraw consent at any time with effect for the future, e.g. by e-mailing hello@log-key.de. Google may also process data on servers in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses. More information: policies.google.com/privacy
External links
Our website contains links (= redirects) to other internet services. External links, i.e. links to websites of third-party information providers, are identifiable by the fact that, when you hover the mouse over the link, the corresponding target URL is displayed in your browser's address bar. We are not responsible for the content of pages reached via such a connection. The data processing carried out there takes place within the framework of the privacy policies of the respective providers. The opinions and/or statements of fact reproduced on the linked pages are the sole responsibility of the respective providers and do not reflect the opinion of the responsible party.
Data subject rights (access, restriction, erasure)
Within the framework of the applicable statutory provisions, you have the right at any time to obtain free information about your personal data stored by us, its origin and recipients and the purpose of the data processing and, where applicable, a right to rectification (Art. 16 GDPR), restriction (Art. 18 GDPR) or erasure (Art. 17 GDPR) of this data. Where processing is based on Art. 6(1)(f) GDPR, you may object to it at any time on grounds relating to your particular situation (Art. 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). For this purpose, as well as for further questions regarding the processing of your personal data stored by us, you may contact the responsible party at any time by e-mail or post.
Right to data portability (Art. 20 GDPR)
You have the right to have data that we process in an automated manner handed over to you or to a third party in a common, machine-readable format. Insofar as you request the direct transfer of the data to another controller, this will only be done where it is technically feasible.
Objection to advertising e-mails (Art. 21 GDPR)
The use of contact data published in connection with the imprint obligation by third parties for the purpose of sending advertising and information materials that have not been expressly requested is hereby expressly prohibited. We expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by means of spam e-mails.
Encryption
For security reasons and to protect the transmission of confidential content (e.g. the entries you make in the contact form), we use encryption methods that correspond to the current state of the art (SSL or TLS). We point out that data transmission over the internet (e.g. when communicating by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.
Support chat (HubSpot)
On our support page and our contact page we offer a live chat. The provider is HubSpot Ireland Ltd., 1 Sir John Rogerson's Quay, Dublin 2, Ireland; processing takes place in EU data centres. The chat is loaded exclusively after your explicit consent (Art. 6 (1) (a) GDPR): only when you actively start the chat is HubSpot's chat script loaded. In doing so, data is transferred to HubSpot (including your IP address, device information and the contents of your chat messages) and cookies are set so that your conversation can continue as you move between pages and on later visits. Without your consent, no connection to HubSpot is established. You can withdraw your consent at any time with effect for the future by disabling the chat on either of those pages and deleting the cookies set in your browser. Further information can be found in HubSpot's privacy policy: https://legal.hubspot.com/privacy-policy
Contact via WhatsApp (Meta)
On our website we link to our WhatsApp Business account via a click-to-chat link (wa.me). The link itself loads no content from Meta and sets no cookies; WhatsApp — or the WhatsApp web client — only opens once you click it. The provider of the service is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. If you write to us on WhatsApp, we process your mobile number, the profile name (and where applicable profile picture) stored there, and the contents of your messages in order to answer your enquiry. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures taken at your request) together with Art. 6 (1) (f) GDPR (our legitimate interest in a fast channel of communication that you have chosen yourself). Using WhatsApp is entirely optional — telephone, e-mail and our contact form are available for every enquiry on equal terms.
To provide the service, WhatsApp processes metadata (including connection and usage data, timestamps, device and log information) and may transfer it to Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, and to other Meta companies. Transfers to the USA are based on the EU-US Data Privacy Framework or on standard contractual clauses. The message contents themselves are end-to-end encrypted. We have no influence over the processing carried out by WhatsApp or Meta; for details please see WhatsApp's privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea
Where necessary we transfer your enquiry into our other systems (e.g. e-mail, CRM) in order to handle and document it. Please do not send us particularly sensitive data (such as health data or login credentials) or personal data about third parties without their knowledge over WhatsApp — please use the telephone, e-mail or our contact form for that.