Privacy notice
Information on the processing of personal data pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR) when you visit this website and when you contact us.
This is a courtesy translation. In the event of any discrepancy, the German version of this privacy notice is authoritative.
In short: this website uses no analytics, advertising or tracking services and loads no external fonts. On every page except the contact page, no connection to third-party servers is made and no cookies are set. On the contact page you may optionally enable Google reCAPTCHA to protect the form against automated submission; without your consent it is not loaded, and a simple arithmetic question is available instead. We process personal data only when you contact us, and in the form of technical server logs necessary for secure operation.
1. Controller
The controller within the meaning of Article 4(7) GDPR is:
- Legal name
- Rosettastein Consulting GmbH
- Address
- Goethestrasse 2, 85354 Freising, Germany
- Represented by
- Ahmed Sayed, Managing Director
- Telephone
- +49 8161 9100703
- datenschutz@rosettastein.com
We are not required to appoint a data protection officer under section 38(1) of the German Federal Data Protection Act (BDSG), because fewer than 20 people in our company are permanently engaged in the automated processing of personal data. You can reach us on all data protection matters at the address given above.
2. Principles of processing
We process personal data exclusively on the basis of the GDPR, the BDSG and other applicable provisions. We limit processing to what is necessary for the respective purpose (Article 5(1)(c) GDPR) and delete data as soon as the purpose ceases to apply and no statutory retention obligation prevents deletion.
Personal data means any information relating to an identified or identifiable natural person, such as name, address, email address, telephone number or IP address.
3. Visiting the website and server log files
Each time this website is accessed, your device transmits technically necessary data which our web server records in log files. The following is collected:
- the truncated or full IP address of the requesting device,
- the date and time of access,
- the name and URL of the file retrieved,
- the volume of data transferred and notification of successful retrieval,
- the type and version of the browser and the operating system used,
- where applicable, the previously visited page (referrer).
Purpose: establishing and maintaining the connection, ensuring system security and stability, error analysis, and the investigation and prevention of attacks.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the technically faultless and secure operation of this website. This processing is technically unavoidable in order to provide the site.
Retention: log data is deleted or anonymised after no more than seven days. Longer storage occurs only where there is a concrete indication of an attack or misuse; the data concerned is then retained until the investigation is concluded.
This data is not combined with other data sources and is not evaluated for marketing or analytics purposes.
4. Hosting
This website is not operated on our own hardware but by an external service provider:
- Provider
- Amazon Web Services EMEA SARL
- Address
- 38 Avenue John F. Kennedy, L-1855 Luxembourg
- Commercial register
- R.C.S. Luxembourg B186284
- Service used
- Amazon Lightsail
- Server location
- Europe (Frankfurt) region, eu-central-1 – Germany
The website therefore runs on servers in data centres in Frankfurt am Main. The provider processes the log data described in section 3 exclusively on our behalf and on our instructions; we have concluded a data processing agreement with the provider pursuant to Article 28 GDPR (the AWS Data Processing Addendum forms part of the AWS Service Terms).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in the professional, secure and available provision of this website).
5. Encrypted transmission
This website is delivered exclusively over an encrypted connection (HTTPS with TLS). You can recognise this by the padlock symbol in your browser's address bar. While encryption is active, the data you transmit to us cannot be read by third parties. Encryption of the transport route says nothing about the security of your own device.
6. Cookies, local storage and consent
We ourselves set no cookies and store no information in your device's local storage or session storage. A consent banner is therefore not required.
There is one exception, on the contact page: if you explicitly enable Google reCAPTCHA there, Google stores an identifier on your device. That storage takes place solely on the basis of your consent under section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG); without your action reCAPTCHA is not loaded. Details are in section 8.
Nor do we embed external fonts, map services, video platforms, advertising networks or social network buttons. On every page except the contact page — and on that page too, as long as you do not enable reCAPTCHA — no connection to third-party servers is established.
Language selection on the home page
If you request this website's address without naming a specific page, the language setting reported by your browser is evaluated in order to show you either the German or the English version of the home page. This uses the information your browser transmits with every request in any case (the Accept-Language header) or, on hosting environments without server-side redirection, the corresponding setting your browser provides locally on your device.
This evaluation takes place solely for the duration of that one request. Nothing is stored — neither a cookie nor any other entry on your device — no profile is created, and no data is transmitted to third parties. Your own choice via the language switch in the header always takes precedence: the German home page, when requested explicitly, is never redirected.
Legal basis: Article 6(1)(f) GDPR; our legitimate interest is to show you a version you can read straight away. Because no information is stored on or retrieved from your device, consent under section 25(1) TDDDG is not required.
7. Contact by email, telephone or post
If you contact us, we process the data you provide — as a rule your name, contact details and the content of your enquiry — solely in order to handle and answer your request.
Legal basis: Article 6(1)(b) GDPR where your enquiry relates to the conclusion or performance of a contract; otherwise Article 6(1)(f) GDPR on the basis of our legitimate interest in responding to business enquiries.
Retention: we delete the data once your request has been conclusively dealt with and the matter requires no further clarification, and after two years at the latest. If the enquiry leads to a contractual relationship, the commercial and tax retention periods apply (see section 9).
Please note that unencrypted email could be read by third parties in transit. For confidential documents we agree a secure transfer route with you in advance.
8. Contact form
We provide a form on the contact page. The details you enter there are processed: name, optionally company and telephone number, email address, the selected topic and your message. Mandatory fields are marked; all further details are optional.
On submission these details are transmitted to a service we operate on our own server in Frankfurt am Main (see section 4) and forwarded from there as an email to our mailbox, sent via our email provider (see section 11). The sender of that email is our own address; yours is set as the reply address so that we can answer you directly. The form content is not stored permanently in a database — afterwards the enquiry exists only as an email in our mailbox.
Legal basis: Article 6(1)(b) GDPR for contract-related enquiries, otherwise Article 6(1)(f) GDPR.
Retention: the periods in section 7 apply to handling enquiries. To prevent abuse, the service logs the IP address of the submission and the number of attempts per IP address for no more than seven days; the content of your message is not logged.
Protection against automated submissions
The form is protected against machine submissions in several ways. These checks involve no third party:
- an additional field, invisible to you, which indicates an automated programme if filled in,
- a plausibility check on the time between opening the page and submitting,
- a limit on the number of submissions per IP address per hour,
- a simple arithmetic question generated locally by your browser.
The legal basis is Article 6(1)(f) GDPR; our legitimate interest is to protect our mailbox and systems against abusive bulk submissions.
Google reCAPTCHA — only with your consent
In addition, you may optionally enable Google reCAPTCHA on the contact page. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA assesses, from technical characteristics and your behaviour on the page, whether the input comes from a human. Data is transmitted to Google in the process — in particular your IP address, information about your browser and operating system, time spent on the page, and mouse and keyboard events — and an identifier is stored on your device. The assessment produces a score indicating how likely the input is to be human, which our server then checks. According to the provider, the data collected is also used to improve the service.
Legal basis: your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. You give it by ticking the relevant box on the contact page; it is not pre-selected.
It is genuinely optional: without your consent reCAPTCHA is not loaded and no connection to Google is made. You can use the form exactly as it is and answer the arithmetic question instead. You suffer no disadvantage; contacting us does not depend on your consent. You can of course also reach us without the form, by email, telephone or post.
Withdrawal: you may withdraw your consent at any time by unticking the box or reloading the page; components already loaded remain active until the page is reloaded. Withdrawal does not affect the lawfulness of processing carried out beforehand.
Third-country transfer: Google may also transmit data to servers in the United States. See section 12. Further information from the provider is available in Google's privacy policy and its terms of service.
9. Initiating and performing business relationships
In the context of proposals, contracts and projects we process master and contact data of our points of contact as well as contract, billing and communication data.
Legal basis: Article 6(1)(b) GDPR (performance of a contract and pre-contractual measures) and Article 6(1)(c) GDPR for compliance with legal obligations, in particular under the German Commercial Code and the German Fiscal Code.
Retention: we retain commercial correspondence and accounting records for six and ten years respectively in accordance with section 257 of the German Commercial Code and section 147 of the German Fiscal Code. On expiry of the relevant period the data is deleted unless it remains necessary for the pursuit or defence of legal claims.
Personal data that clients pass to us for processing within a project is processed exclusively as a processor on the basis of an agreement under Article 28 GDPR. In such cases the client remains the controller; please direct requests for access or erasure to that client.
10. Job applications
If you send us an application, we process the data it contains solely in order to conduct the recruitment procedure.
Legal basis: section 26(1) BDSG in conjunction with Article 6(1)(b) GDPR; for special categories of personal data additionally Article 9(2)(b) GDPR.
Retention: if no employment results, we delete application documents six months after the procedure concludes; this period serves to defend against possible claims under the German General Equal Treatment Act. Longer retention in a candidate pool takes place only with your express consent under Article 6(1)(a) GDPR, which you may withdraw at any time.
11. Recipients and processors
We disclose your data only where this is necessary to fulfil the respective purpose or where we are legally obliged to do so. Potential recipients are in particular:
- Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg – hosting of this website in the Frankfurt region (see section 4);
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland – firstly for our email and office communication services (Google Workspace); the content of any email correspondence you conduct with us, and messages sent through the contact form, reach this provider. Secondly — and only after your consent — as the provider of reCAPTCHA (see section 8);
- our tax advisers and, in the event of an audit, the tax authorities,
- credit institutions for the processing of payments,
- legal advisers and courts, where necessary to enforce or defend legal claims,
- specialist partner companies, but only after prior agreement with you or your organisation.
We conclude data processing agreements under Article 28 GDPR with service providers that process personal data on our behalf. We do not sell data, nor do we use it for third-party advertising.
12. Transfers to third countries
The data of this website is stored exclusively in data centres in Germany (see section 4). Our contracting parties for hosting and email are companies established in the European Union (Luxembourg and Ireland respectively).
Both providers belong to corporate groups whose parent company is in the United States. It therefore cannot be ruled out in every case that group companies outside the European Union may obtain access in the course of technical support, maintenance or fault resolution. Where that happens, the transfer relies on the European Commission's standard contractual clauses under Article 46(2)(c) GDPR, which form part of the respective data processing agreements, supplemented by the providers' technical and organisational measures. For transfers to the United States, the European Commission's adequacy decision of 10 July 2023 (EU-US Data Privacy Framework) may also apply, in so far as the company concerned is certified under it.
If you enable reCAPTCHA on the contact page (section 8), the data collected is processed by Google and may reach servers in the United States. That transfer rests on your consent under Article 49(1)(a) GDPR in conjunction with the safeguards named above. We note that public authorities in the United States may have broader access to personal data than European law provides for, and that equivalent legal remedies may not be available to you there. Without your consent this transfer does not take place.
No transfer of personal data beyond this to countries outside the European Union and the European Economic Area is envisaged. Should one become necessary in the course of a business relationship, it will take place exclusively on the basis of an adequacy decision (Article 45 GDPR) or appropriate safeguards under Article 46 GDPR, supplemented by a case-by-case assessment of the level of protection.
13. Automated decision-making and profiling
No automated decision-making within the meaning of Article 22 GDPR and no profiling takes place. Where we use machine learning methods in projects, we do so on the basis of our clients' data and not on the basis of data collected through this website.
14. Your rights as a data subject
You have the following rights in relation to us:
- Access to whether and which data concerning you we process (Article 15 GDPR),
- Rectification of inaccurate data and completion of incomplete data (Article 16 GDPR),
- Erasure, unless a ground for retention or a legal obligation prevents it (Article 17 GDPR),
- Restriction of processing under the conditions of Article 18 GDPR,
- Data portability in a structured, commonly used and machine-readable format (Article 20 GDPR),
- Objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR),
- Withdrawal of consent with effect for the future (Article 7(3) GDPR).
A message to datenschutz@rosettastein.com or to the postal address given above is sufficient to exercise these rights. To prevent improper disclosure we may request additional information to identify you if we have doubts about your identity (Article 12(6) GDPR). Handling your request is free of charge.
Right to object in an individual case
You have the right to object at any time, on grounds relating to your particular situation, to processing of your data that is based on a legitimate interest (Article 6(1)(f) GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
15. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Article 77 GDPR). The authority responsible for us is:
Bavarian Data Protection Supervisory Authority
(Bayerisches Landesamt für Datenschutzaufsicht, BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de
Alternatively you may contact the supervisory authority of your habitual residence or place of work.
16. Obligation to provide data
To browse this website you need provide no data beyond the technically necessary connection data. If you wish to contact us or enter into a contract, the details marked as mandatory are required; without them we cannot process the enquiry or conclude the contract. Further details are optional and their absence has no disadvantage for you.
17. Data security
We take technical and organisational measures under Article 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. These include encrypted transmission, access restrictions on the principle of least privilege, regular updating of the software in use, and a degree of data minimisation that is built into the design of this website. We review our measures continuously and adapt them to technical developments.
18. Changes to this privacy notice
We update this privacy notice when changes to this website, to our processing activities or to the legal position require it. The version published on this page applies to each subsequent visit.
Version 3.0 — as of August 2026. Changed from version 2.1: contact form with server-side sending (section 8), optional Google reCAPTCHA subject to consent (sections 6, 8, 11, 12). Previously, from version 2.0: identification of the hosting provider (section 4), naming of recipients (section 11) and clarification on third-country transfers (section 12). This notice supersedes all previous versions.