Skip to content
NexBridge-IT.

Privacy policy

This is a convenience translation. The legally binding version of this document is the German one.

1. Controller

The controller for the processing of personal data on this website is:

NexBridge-IT
Peter Knopp, Manush Vaghani
Gartenstr. 22
68799 Reilingen
Deutschland
nexbridge-it@mailbox.org

2. Data protection officer

If a data protection officer has been appointed, you can reach them at the email address given above.

3. General information on data processing

We process personal data only where this is necessary to provide a functioning website, to handle your enquiries, to carry out pre-contractual or contractual measures, to comply with legal obligations, or to protect legitimate interests.

The legal bases for processing are, in particular, Art. 6(1)(a) GDPR for consent, Art. 6(1)(b) GDPR for contractual or pre-contractual measures, Art. 6(1)(c) GDPR for legal obligations, and Art. 6(1)(f) GDPR for legitimate interests.

4. Provision of the website and server log files

When you access our website, the web server automatically collects and stores information in what are known as server log files. This may include: IP address, date and time of access, page or file requested, referrer URL, browser type and version, operating system used, volume of data transferred, and the requesting provider.

Processing serves the technical provision, stability, security and optimisation of the website. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and uninterrupted operation of our website.

We do not operate our own servers and keep no server log files of our own. Collection, storage and deletion are carried out by our hosting provider according to its retention periods, unless longer storage is required to investigate security incidents.

5. Hosting and processing on our behalf

Our website is hosted by Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA). The hosting provider processes personal data arising from your visit to the website on our behalf. This may include IP addresses, technical access data and communication data.

We have concluded a data processing agreement with the hosting provider pursuant to Art. 28 GDPR, where this is required under data protection law. Processing is based on our legitimate interest in the secure and efficient provision of our online offering pursuant to Art. 6(1)(f) GDPR.

6. Contact by email, telephone or contact form

If you contact us by email, telephone or via a contact form, we process the personal data you provide, for example name, email address, telephone number, subject, message and any further voluntary information.

The contact form on this website does not currently transmit your details to a server of ours. It opens a prepared email in your own email program; the message is then sent via your own email provider.

Processing serves to handle your enquiry and to communicate with you. Where your enquiry is directed at concluding or performing a contract, Art. 6(1)(b) GDPR is the legal basis. In other cases, processing is based on our legitimate interest in handling enquiries properly pursuant to Art. 6(1)(f) GDPR.

The data is deleted once your enquiry has been dealt with conclusively and no statutory retention obligations prevent deletion.

7. NexBridge-IT services and client communication

In the course of our IT services, consulting, project initiation, quotation, contract performance and client support, we process personal data of prospects, clients, contact persons and business partners. This may include contact data, communication data, contract data, project information, billing data and technical information required for the respective service.

The legal bases are Art. 6(1)(b) GDPR where processing is necessary for pre-contractual measures or a contract, Art. 6(1)(c) GDPR where legal obligations exist, and Art. 6(1)(f) GDPR where we have a legitimate interest in efficient business organisation, client care and legally sound documentation.

8. Cookies and similar technologies

We currently set no cookies on this website — neither technically necessary ones nor analytics, marketing or tracking cookies.

Should cookies be used in future, the following applies: technically necessary cookies serve to provide basic website functions and may be used without consent where they are required for operation. For non-essential cookies we obtain your consent in advance. The legal basis for accessing information on your device is § 25 TDDDG. Subsequent processing of personal data takes place, where consent is given, on the basis of Art. 6(1)(a) GDPR. You may withdraw consent at any time with effect for the future.

9. Consent management tool

As we use no services requiring consent, we currently do not use a consent management tool.

Should we use such a tool in future, it will serve to obtain, manage and document your consents. Information such as consent status, time of consent, browser and device information and a shortened or pseudonymised IP address may be processed. The legal basis is Art. 6(1)(c) GDPR where processing is required to meet statutory documentation obligations, and Art. 6(1)(f) GDPR based on our legitimate interest in legally sound consent management.

10. Web analytics and reach measurement

We currently use no web analytics or reach measurement services. Your usage behaviour is not evaluated.

Should we use analytics tools in future, tools requiring consent will be used only after your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Where privacy-friendly analytics without cookies and without a consent requirement is used, processing is based on Art. 6(1)(f) GDPR.

11. External fonts, maps, videos and embedded content

All fonts on this website are embedded locally. No maps, videos, social media elements or other third-party content are loaded. No connections to third-party providers are established when this website is accessed.

Should external content be embedded in future, personal data — in particular IP address and technical access data — may be transmitted to the respective providers. Where required, embedding takes place only after your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. For technically necessary or locally embedded services, processing may be based on Art. 6(1)(f) GDPR.

12. Social media presences

We may operate company profiles on social networks or professional platforms, for example LinkedIn, XING, Facebook, Instagram or comparable services. If you visit our profiles or interact with us via these platforms, personal data may be processed by us and by the respective platform operator.

Processing serves external presentation, communication, addressing applicants and clients, and providing information about our services. The legal basis is Art. 6(1)(f) GDPR. The respective platform operators’ own privacy notices additionally apply to their data processing.

13. Job applications

If you apply to us, we process the application data you submit, in particular contact data, CV, qualifications, references and further documents, in order to carry out the application procedure.

The legal basis is § 26 BDSG in conjunction with Art. 6(1)(b) GDPR. Inclusion in an applicant pool takes place only on the basis of your consent pursuant to Art. 6(1)(a) GDPR. Application data is deleted after the procedure has concluded, unless statutory retention obligations or legitimate interests, for example legal defence, prevent deletion.

14. Recipients of personal data

Personal data may be transmitted to internal bodies and to external service providers where this is necessary to fulfil the purposes stated. This may include IT service providers, hosting providers, communication service providers, payment and accounting service providers, tax advisers, legal advisers and public authorities within the scope of statutory obligations.

Where service providers process personal data on our behalf, we conclude data processing agreements pursuant to Art. 28 GDPR where required.

15. Transfer of data to third countries

Personal data is transferred to countries outside the European Union or the European Economic Area only where an appropriate legal basis exists. This may in particular be an adequacy decision of the European Commission, appropriate safeguards such as standard contractual clauses, or your explicit consent.

Our hosting provider Cloudflare, Inc. is based in the USA. This website is delivered via that provider’s global network, so access from a third country cannot be entirely ruled out. Cloudflare provides European Commission standard contractual clauses for transfers to third countries.

16. Storage period

We store personal data only for as long as is necessary for the respective purposes or as statutory retention obligations require. Where the purposes of processing cease to apply or a statutory retention period expires, the data is deleted or blocked, unless another legal basis exists for further processing.

17. Your rights

Within the statutory requirements you have the following rights: right of access pursuant to Art. 15 GDPR, right to rectification pursuant to Art. 16 GDPR, right to erasure pursuant to Art. 17 GDPR, right to restriction of processing pursuant to Art. 18 GDPR, right to data portability pursuant to Art. 20 GDPR, and right to object pursuant to Art. 21 GDPR.

Where processing is based on your consent, you have the right to withdraw that consent at any time with effect for the future. The lawfulness of processing carried out up to the withdrawal remains unaffected.

18. Right to object pursuant to Art. 21 GDPR

Where we process personal data on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing, or the processing serves to establish, exercise or defend legal claims.

19. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection law. The competent authority may in particular be that of your place of residence, your place of work or the place of the alleged infringement.

For NexBridge-IT, based in Baden-Württemberg, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg may be competent in particular.

20. Obligation to provide personal data

Providing personal data is in part necessary in order to use our website, communicate with us or make use of contractual services. Without the required data we may be unable to process or provide certain enquiries or services.

21. Automated decision-making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place on our website unless stated otherwise in this privacy policy.

22. Currency and amendment of this privacy policy

We reserve the right to amend this privacy policy if our website, our data processing or the legal requirements change. The current version published on this website applies in each case.

Version: 08/2026