Privacy policy
This is a translation for your convenience. The legally binding version is the German one, which you can find on the German page. Zur deutschen Datenschutzerklärung.
Protecting your data matters to us. This website is deliberately built to be data minimal: no cookies for visitors, no third party tracking services, no external connections. All content including fonts is delivered from our own server. We only count anonymously which pages are requested, see section 7.
1. Controller
needful-apps, Inhaber: Stefan Reinhardt
Am Wahlebach 6, 34253 Lohfelden, Germany
Email: backoffice@needful-apps.de ·
Phone: 0561 2207 6342
2. Server log files
When you visit this website, our server automatically processes technical information (IP address, date and time, page requested, user agent). This data serves solely to ensure trouble free operation and IT security (Article 6(1)(f) GDPR) and is deleted after 14 days at the latest.
3. Contact form and email
If you contact us through the contact form or by email, we process the data you provide (name, email address, phone number where given, message) solely to handle your inquiry (Article 6(1)(b) GDPR). The data is stored in our own self hosted database and deleted once it is no longer needed and no statutory retention periods apply.
4. Hosting and processing on our behalf
This website runs on a server we operate ourselves in Germany. The database holding inquiries runs on the same infrastructure. No transfer to third countries outside the EU takes place. Where we use service providers, for example for data centre operations or email delivery, this is governed by data processing agreements under Article 28 GDPR.
5. Online appointment booking
For appointment booking we link to Kalendful (kalendful.de), a product of needful-apps. Data is only processed there once you follow that link. The privacy policy of Kalendful applies. This website does not embed the service and establishes no automatic connection to it.
6. No cookies, no third party tracking
This website sets no cookies for visitors and uses no third party analytics services such as Google Analytics or Matomo. Fonts, icons, images and all other resources are loaded locally from our server. No data is transmitted to third parties, which is why no cookie banner is required. A cookie is only set when a staff member signs in to the internal administration area. If you dismiss the “no cookies” notice, your browser remembers that locally (localStorage) – purely functional, with no personal data and no transmission to us.
7. Anonymous page statistics
To understand which content is in demand, we count page views on our own server. This creates no personal reference. We store only how often a page was requested on a given day, plus the language version, a coarse device class (desktop, tablet, smartphone), the domain of the referring site and the geographic origin down to city level (country, region/state and city).
We derive the origin from the IP address via our own service on our infrastructure, which only queries a local location database. The IP address is used for that moment only, never leaves our infrastructure and is not stored. We keep only the aggregated count per country, region and city, never the IP address itself. The city is determined coarsely only (city level from the location database, not a precise position); for each city we additionally store its approximate centre coordinates so we can display the aggregated figures internally on a map.
We explicitly do not store IP addresses, full browser identifiers, cookies, session identifiers or any other characteristic that would allow individual people or devices to be recognised. A visit can neither be attributed to a person nor followed across pages. The data resides solely in our own database in Germany and is never shared. Aggregated counts are deleted automatically after 24 months.
The legal basis is our legitimate interest in designing our offering to meet demand (Article 6(1)(f) GDPR). Since no information is stored on or read from your device, no consent under section 25 TDDDG is required.
8. Data security
Transmission is encrypted exclusively via HTTPS (TLS). Access to the internal administration area is protected by an authentication system capable of two factor login. We take technical and organisational measures under Article 32 GDPR to protect your data against loss and unauthorised access.
9. Retention periods at a glance
- Server log files: 14 days maximum
- Anonymous page and origin counts (country/region/city): 24 months, then deleted automatically
- Contact and course inquiries: until your request is fully handled, then deleted unless commercial or tax retention periods (6 or 10 years) apply
- Contract documents from completed training and projects: for the statutory periods
10. No automated decision making
Automated decision making including profiling under Article 22 GDPR does not take place. We use no AI systems on this website to evaluate visitor data.
11. Your rights
You have the right to information (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21). Where we process data on the basis of legitimate interests, you may object to that processing at any time with effect for the future. An informal message to backoffice@needful-apps.de is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.
Version of this privacy policy: 21 July 2026.