Skip to content

Datenschutz

This is a static website without cookies, without local storage and without user tracking. We process personal data only to the extent required to operate the site and to answer your enquiries.

Controller

The controller for the data processing on this website within the meaning of the GDPR is:

CEPT GmbH
Pliestermark 9
46284 Dorsten
Phone: +49 2362 96 990 98
E-mail: info@cept.de

No data protection officer has been appointed. [To be verified before publication: obligation to appoint one under Art. 37 GDPR / Section 38 BDSG.]

Hosting and delivery

The website is delivered as static HTML through the Bunny.net content delivery network from locations inside the European Union. When a page is requested, the delivering server processes technically necessary access data:

  • IP address of the requesting device

  • date and time of the request

  • requested address and volume of data transferred

  • referrer and browser identification (user agent)

The purpose of this processing is the secure, stable and abuse-free delivery of the website. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the technical operation of the site and in defending against attacks.

[Retention period for access data: to be added once the log settings of the delivery zone are finalised.]

Contact form

If you write to us using the contact form, we process the details you enter: name, company, e-mail address, optionally a phone number, and the content of your message. Mandatory fields are marked in the form; without them we cannot process the enquiry.

The data is transmitted to an edge script operated by our processor Bunny.net inside the European Union. The enquiry is first stored in a storage zone in the EU that is not publicly accessible and is then forwarded by e-mail to our mailbox info@cept.de so that no enquiry is lost. The e-mail is sent via our processor Postmark.

The legal basis is Art. 6 (1) (b) GDPR where the enquiry concerns the conclusion or performance of a contract, and otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries).

Enquiries submitted through the contact form are deleted no later than six months after they arrive. Where an enquiry leads to a contract, the statutory commercial and tax retention periods apply to the data then held for that engagement.

To protect the form against automated submissions we use a field that is invisible to you, a timing check and a limit on submissions per period. No data is transferred to third parties outside the EU in the process, and no captcha service is used.

No cookies, no tracking

This website sets no cookies and uses neither local storage nor comparable recognition techniques, so no consent banner is required. Fonts and images are served from our own domain; your browser makes no requests to third-party networks while you visit the site.

Audience measurement: a cookieless, EU-hosted audience measurement is currently under review. This section will be updated once the decision has been made; until then no analysis of usage behaviour takes place.

Recipients and processors

  • Bunny.net: delivery of the website and access data, locations inside the EU.

  • Bunny.net: processing and storage of contact form enquiries (edge script and a storage zone that is not publicly accessible, EU); Postmark: sending the notification e-mail about new enquiries.

  • Storyblok: content management system, EU region Frankfurt. Content is retrieved while the website is being built; your visit data never reaches the CMS.

[Provider details and data processing agreements under Art. 28 GDPR will be added before publication.]

Your rights

You have the following rights regarding the personal data we hold about you:

  • access (Art. 15 GDPR)

  • rectification (Art. 16 GDPR)

  • erasure (Art. 17 GDPR)

  • restriction of processing (Art. 18 GDPR)

  • data portability (Art. 20 GDPR)

  • objection to processing based on legitimate interests (Art. 21 GDPR)

An informal message to the contact details above is enough to exercise these rights. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.

Data security

The website is delivered exclusively over an encrypted connection (HTTPS/TLS). Because the pages are generated statically, the website itself has no application database and no user accounts.

Draft: to be reviewed by a lawyer before publication.