Privacy Policy
Last updated: 19 August 2026
Preamble
With the following privacy policy I would like to explain to you what types of your personal data (hereinafter also referred to briefly as "data") I process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by me, both in the context of providing my services and in particular on my websites and within external online presences, such as my social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Controller
Martin KandziorTheodor-Heuss-Anlage 12
68165 Mannheim
Germany
Email address: mail@kandzior.de
Phone: +49 176 10 20 20 30
Imprint: kandzior.de/en/imprint
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Contact data
- Content data
- Usage data
- Meta, communication and procedural data
- Log data
Categories of data subjects
- Communication partners
- Users
Purposes of processing
- Communication
- Security measures
- Organisational and administrative procedures
- Feedback
- Public relations
- Provision of my online offering and user-friendliness
- Information technology infrastructure
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which I process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or my country of residence or establishment. Should more specific legal bases be relevant in individual cases, I will inform you of these in this privacy policy.
- Consent (Art. 6 (1) sentence 1 (a) GDPR) – The data subject has given consent to the processing of personal data relating to them for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6 (1) sentence 1 (b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection provisions apply in Germany. These include in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission and automated decision-making in individual cases including profiling. In addition, the data protection acts of the individual federal states may apply.
Notice on the applicability of the GDPR and the Swiss FADP: This privacy notice serves to provide information both pursuant to the Swiss Federal Act on Data Protection (FADP) and pursuant to the General Data Protection Regulation (GDPR). For this reason, please note that the terms of the GDPR are used because of their broader territorial application and intelligibility. The legal meaning of the terms is nevertheless determined by the Swiss FADP within its scope of application.
Security measures
In accordance with the statutory requirements and taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, I take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input, disclosure, availability and separation of the data. Furthermore, I have set up procedures which ensure that data subjects can exercise their rights, that data is erased and that responses to threats to the data are possible. I also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in line with the principle of data protection by design and by default.
TLS/SSL encryption (https): To protect the data of users transmitted via my online services, I use TLS/SSL encryption. You can recognise an encrypted connection by the fact that the address bar of your browser shows "https://" instead of "http://", and by the padlock symbol in your browser bar.
Transfer of personal data
In the course of my processing of personal data, it may happen that the data is transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks. In such cases I observe the statutory requirements and in particular conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.
International data transfers
Data processing in third countries: If I process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if the processing takes place in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies, this only takes place in accordance with the statutory requirements. Where the level of data protection in the third country has been recognised by an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. Otherwise, data transfers only take place if the level of data protection is otherwise secured, in particular by standard contractual clauses (Art. 46 (2) (c) GDPR), explicit consent, or in the case of contractually or legally required transfer (Art. 49 (1) GDPR).
EU-US Data Privacy Framework (DPF): Under the so-called "Data Privacy Framework" (DPF), the EU Commission has also recognised the level of data protection for certain companies in the USA as adequate in its adequacy decision of 10 July 2023. The list of certified companies and further information on the DPF can be found on the website of the US Department of Commerce at dataprivacyframework.gov. I inform you within this privacy policy which of the service providers I use are certified under the Data Privacy Framework.
General information on data storage and erasure
I erase personal data that I process in accordance with the statutory provisions as soon as the underlying consent is withdrawn or no further legal basis for the processing exists. This applies to cases where the original purpose of the processing no longer applies or the data is no longer required. Exceptions to this rule apply where statutory obligations or particular interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly. This privacy policy contains additional information on the retention and erasure of data that applies specifically to certain processing operations.
Where several statements are made about the retention period or erasure deadlines for a piece of data, the longest period always applies. Where a period does not expressly begin on a specific date and is at least one year, it starts automatically at the end of the calendar year in which the event triggering the period occurred.
Rights of data subjects
As a data subject you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to obtain access to that data as well as further information and a copy of the data in accordance with the statutory requirements.
- Right to rectification: You have the right, in accordance with the statutory requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right, in accordance with the statutory requirements, to request that data concerning you be erased without undue delay, or alternatively to request restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to me in a structured, commonly used and machine-readable format in accordance with the statutory requirements, or to request its transmission to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
An informal message to mail@kandzior.de is sufficient to exercise these rights. The supervisory authority responsible for me as a controller established in Mannheim is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI)Postfach 10 29 32
70025 Stuttgart, Germany
baden-wuerttemberg.datenschutz.de
Provision of the online offering and web hosting
I process users' data in order to be able to provide them with my online services. For this purpose I process the user's IP address, which is necessary to transmit the content and functions of my online services to the user's browser or device.
- Types of data processed: Usage data (e.g. access times, websites visited); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); log data (e.g. log files concerning logins or the retrieval of data or access times).
- Data subjects: Users.
- Purposes of processing: Provision of my online offering and user-friendliness; information technology infrastructure; security measures.
- Retention and erasure: Log files are stored for a limited period for security reasons and then erased.
- Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
Further information on processing operations, procedures and services:
- Provision of the online offering on rented storage space: To provide my online offering I use storage space, computing capacity and software that I rent or otherwise obtain from a corresponding server provider. Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
- Collection of access data and log files: Access to my online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes, e.g. to avoid server overload (in particular in the case of abusive attacks, so-called DDoS attacks), and to ensure server utilisation and stability. Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR). Erasure of data: Log file information is stored for a maximum of 30 days and then erased or anonymised. Data whose further retention is required for evidentiary purposes is exempt from erasure until the respective incident has been finally clarified.
- Hetzner: Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacity). Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: hetzner.com; Privacy policy: hetzner.com/legal/privacy-policy; Data processing agreement: A data processing agreement pursuant to Art. 28 GDPR is in place. The data is stored exclusively on servers within the Federal Republic of Germany.
Use of cookies and local storage
This website sets no cookies. There is no reach measurement and no analysis of your usage behaviour, and no profiles are created about you.
When you switch the appearance (light/dark) or the language, your choice is stored in your browser's local storage so that it is preserved on your next visit. This information remains entirely on your device, is never transmitted to me or to third parties and contains no personal data. Such storage is strictly necessary for the service you have expressly requested (§ 25 (2) no. 2 TDDDG). You can delete it at any time via your browser settings.
The fonts used on this website are served from my own server. No connection to font providers such as Google Fonts takes place.
Contact and enquiry management
When you contact me (e.g. via the contact form, email or telephone) and in the context of existing user and business relationships, the details of the enquiring persons are processed insofar as this is necessary to answer the contact enquiries and any measures requested.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. entries in online forms); usage data (e.g. access times, websites visited); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback; provision of my online offering and user-friendliness.
- Retention and erasure: The data is erased as soon as the respective conversation has ended and it can be inferred from the circumstances that the matter concerned has been conclusively clarified. Statutory retention obligations remain unaffected.
- Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6 (1) sentence 1 (b) GDPR).
Further information on processing operations, procedures and services:
- Contact form: When you contact me via the contact form or comparable channels, I process the personal data transmitted to me in order to answer and handle the respective request. The details entered in the input mask (name, email address, message text) are transmitted. The data is not passed on to third parties. As an alternative to the form, you can reach me directly by email at any time. To protect against automated abuse, the server limits the number of submissions per sender. For this purpose your IP address is stored solely as a non-reversible hash with a daily changing salt and is deleted after one day at the latest; the IP address itself is not retained. Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 (1) sentence 1 (b) GDPR); legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
Presences in social networks (social media)
I maintain online presences within social networks and, in this context, process users' data in order to communicate with the users active there or to offer information about myself.
I would like to point out that users' data may be processed outside the European Union in the process. This may result in risks for users because, for example, it could make it more difficult to enforce users' rights.
Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created on the basis of users' usage behaviour and the resulting interests. These profiles may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to users' interests. For these purposes, cookies are generally stored on users' computers in which usage behaviour and interests are recorded. Data may also be stored in the usage profiles independently of the devices used by the users (particularly if the users are members of the respective platforms and are logged in there).
For a detailed description of the respective forms of processing and the options to object (opt-out), I refer to the privacy policies and information provided by the operators of the respective networks.
In the case of requests for information and the assertion of data subject rights, I would also point out that these can be asserted most effectively with the providers. Only the providers have access to users' data and can directly take appropriate measures and provide information. If you nevertheless need help, you can contact me.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. entries in online forms); usage data (e.g. access times, websites visited).
- Data subjects: Users.
- Purposes of processing: Communication; feedback; public relations.
- Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
Further information on processing operations, procedures and services:
- LinkedIn: Social network. Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: linkedin.com; Privacy policy: linkedin.com/legal/privacy-policy.
- Facebook pages and profiles: Profiles within the social network Facebook. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: facebook.com; Privacy policy: facebook.com/privacy/policy.
- X: Social network. Service provider: Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland; Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); Website: x.com; Privacy policy: x.com/en/privacy.
Plug-ins and embedded functions and content
I integrate functional and content elements into my online offering that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may be, for example, graphics, videos or social media buttons and posts (hereinafter uniformly referred to as "content").
These integrations are protected by a two-click solution: Merely opening a page does not establish any connection to the third-party providers. Instead of the content, you first see a notice that comes entirely from my own server. Only when you release this content by an explicit click is a connection established between your device and the server of the respective provider. The legal basis is then your consent declared in this way (Art. 6 (1) sentence 1 (a) GDPR in conjunction with § 25 (1) TDDDG). The consent applies to the respective page view; after reloading the page, no connection takes place without a renewed click.
Integration necessarily requires that the third-party providers process users' IP addresses, since without the IP address they could not send the content to the users' browsers. The third-party providers may also use so-called pixel tags or comparable procedures to evaluate information about the users of this website. If you are logged in with the respective provider, that provider can attribute the page view to your account.
- Types of data processed: Usage data (e.g. access times, websites visited); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users.
- Purposes of processing: Provision of my online offering and user-friendliness; public relations.
- Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR).
- Withdrawal: You grant consent per page view and per item of content. If you reload the page without releasing the content again, the consent has ended.
Further information on processing operations, procedures and services:
- SociableKIT: Display of my public posts from LinkedIn and Facebook via an embedded widget. The service reads the posts on the server side and delivers them as an embedded frame; in doing so, your IP address is transmitted to SociableKIT. Service provider: SociableKIT LLC, United States of America; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: sociablekit.com; Privacy policy: sociablekit.com/privacy-policy; Basis for third-country transfers: Standard contractual clauses (Art. 46 (2) (c) GDPR) and your explicit consent (Art. 49 (1) (a) GDPR).
- X timeline: Display of my public posts on X. Service provider: Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: x.com; Privacy policy: x.com/en/privacy.
- Ticket Tailor: Display and booking of events. Registration and, where applicable, payment take place entirely on Ticket Tailor's own pages; this website neither stores nor processes any of your data in the process. Service provider: Zimma Ltd, United Kingdom; Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); Website: tickettailor.com; Privacy policy: tickettailor.com/privacy-policy; Basis for third-country transfers: Adequacy decision of the European Commission for the United Kingdom (Art. 45 GDPR).
Amendment and updating
Please check the content of this privacy policy regularly. I adapt the privacy policy as soon as changes to the data processing I carry out make this necessary. I will inform you as soon as the changes require an action on your part (e.g. consent) or other individual notification.
Where I provide addresses and contact information of companies and organisations in this privacy policy, please note that addresses may change over time and please verify the details before making contact.
Definitions of terms
This section provides an overview of the terms used in this privacy policy. Insofar as the terms are defined by law, their legal definitions apply. The following explanations are intended primarily to aid understanding.
- Inventory data: Inventory data comprises essential information required for the identification and administration of contractual partners, user accounts, profiles and similar assignments. This data may include personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs).
- Content data: Content data comprises information generated in the course of creating, editing and publishing content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content published on various platforms and media.
- Contact data: Contact data is essential information that enables communication with persons or organisations. It includes, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Meta, communication and procedural data: These are categories containing information about how data is processed, transmitted and managed. Meta data, also known as data about data, includes information describing the context, origin and structure of other data. It may include details of file size, creation date and the author of a document as well as revision histories. Communication data records the exchange of information between users via various channels, such as email traffic, call details, messaging data and social media interactions. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, transaction and activity logs and audit logs.
- Usage data: Usage data refers to information capturing how users interact with digital products, services or platforms. This data covers a broad range of information showing how users use applications, which functions they prefer, how long they stay on certain pages and which paths they take through an application.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Log data: Log data is information about events or activities recorded in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system.
- Controller: "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether collecting, analysing, storing, transmitting or erasing it.
Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke