This page was automatically translated from German.
In case of discrepancies, the German version shall prevail.
Privacy Policy
§ 1 General Information
In this privacy policy, you will find detailed information about what happens to your personal data when you visit our website johannesauer.com. All data that can be used to personally identify you is considered personal data. When processing your data, we strictly comply with the statutory provisions, in particular the General Data Protection Regulation (“GDPR”). It is very important to us that your visit to our website is completely secure.
§ 2 Data Controller
The party responsible under data protection law for the collection and processing of personal data on this website is:
- Name: Johannes Auer IT Consulting GmbH
- Represented by: Johannes Auer, Managing Director
- Street, house number: Wöhrlweg 6
- Country: Germany
- Email: mail@johannesauer.com
- Phone: +49 175 4144759
§ 3 Access Data (Server Log Files)
When you access our website, we automatically collect data that your browser transmits to us and store it in so-called server log files. This includes:
- Browser type and browser version
- Operating system used
- Referrer URL (the source from which you accessed our website)
- Host name of the accessing device
- Date and time of the server request
- IP address currently used by your device (possibly anonymized)
As a rule, we are neither able nor do we intend to assign this data to a specific person. Processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website.
§ 4 Cookies and Consent Management
For the operation of our website, we ourselves do not use any cookies for analytics, tracking or advertising purposes, and we do not create usage profiles. Technically necessary cookies that serve solely to ensure the secure and error-free operation of the website may be set by our hosting and security provider (Cloudflare, see § 5) – for example when defending against automated attacks. No consent is required for such technically necessary cookies pursuant to Section 25(2) TDDDG; the legal basis for the associated processing is Art. 6(1)(f) GDPR (legitimate interest in the technically flawless and secure provision of our website).
To obtain and manage consent for the setting of non-essential cookies, we use the consent management platform CookieYes, provided by CookieYes Limited. When you access our website, a script from CookieYes is loaded for this purpose. CookieYes stores your cookie choice in a technically necessary cookie (“cookieyes-consent”) on your device so that your selection is taken into account on future visits; this cookie is not used for advertising or analytics purposes. The legal basis for using CookieYes is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (obligation to provide evidence and documentation of consent) and Art. 6(1)(f) GDPR (legitimate interest in legally compliant consent management). Further information can be found in CookieYes’ privacy policy at https://www.cookieyes.com/privacy-policy/.
You can use the consent banner to give, refuse or adjust/withdraw your consent at any time with effect for the future. You can also configure your browser to inform you about cookie usage and to allow cookies only in individual cases or reject them entirely. Please note that the functionality of this website may be limited in this case.
§ 5 Hosting, Fonts and Reach Measurement
A. Hosting (Cloudflare)
Our website is implemented as a purely static site and is delivered via the infrastructure of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (content delivery network and servers). When you access our pages, Cloudflare processes the access data (server log files) described in § 3 on our behalf in order to deliver the website, ensure its security and stability, and defend against automated attacks.
Cloudflare operates servers worldwide; processing on servers outside the European Union can therefore not be excluded. A data processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare. For transfers to third countries, Cloudflare relies on the European Commission’s Standard Contractual Clauses. The legal basis for processing is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure, stable and efficient provision of our website. Further information can be found in Cloudflare’s privacy policy at https://www.cloudflare.com/privacypolicy/.
B. Fonts
The fonts used on our website (including Bricolage Grotesque, Barlow, DM Sans and JetBrains Mono) are loaded exclusively locally from our server or our host’s content delivery network. No connection is made to third-party servers – in particular, no Google Fonts are loaded via the Google CDN. Your IP address is therefore not transmitted to Google or any other third party when the fonts are loaded.
C. No Web Analytics, Advertising or Tracking
We do not use any web analytics, tracking or advertising services on this website. In particular, we do not use Google Analytics, Google Tag Manager, Google Ads, Google Remarketing, Google AdSense or comparable services. No usage profiles are created, and no personal data is processed for advertising purposes or passed on to third parties.
D. Online Appointment Booking (Cal.com)
For online appointment booking we use the service Cal.com provided by Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. The booking calendar is embedded exclusively on our booking page; a connection to Cal.com servers is only established when you open that page, which technically involves transmitting your IP address. When you book an appointment, Cal.com processes the data you enter (in particular your name, e-mail address, the selected time slot and any optional details) in order to arrange the appointment.
The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures taken at your request) and Art. 6 (1) (f) GDPR (legitimate interest in simple and reliable appointment scheduling). Where data is transferred to the USA, the transfer is based on the EU Commission’s Standard Contractual Clauses (Art. 46 (2) (c) GDPR). For further information, please see Cal.com’s privacy policy at https://cal.com/privacy.
§ 6 Newsletter
We will only send you our newsletter to your email address at regular intervals with your prior consent. To use this service, you must provide and verify your email address. No further data is collected, or only on a voluntary basis. Your data is used exclusively for sending the newsletter.
The data provided during newsletter registration is processed exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time. An informal notice by email or using the unsubscribe link included in the newsletter is sufficient. Data processing carried out prior to withdrawal remains unaffected.
If you unsubscribe from the newsletter, the data stored for setting up the subscription will be deleted. If this data has been provided to us for other purposes and stored elsewhere, it will remain stored there.
§ 7 Contacting Us
If you contact us, including by email, the data you provide (including your contact details) will be stored in order to process your request and to be available for follow-up questions if necessary. This data will not be shared with third parties without your explicit consent.
Your personal data is processed exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR. You have the right to withdraw this consent at any time without giving reasons. An informal email to us is sufficient to exercise your right of withdrawal. The lawfulness of data processing carried out prior to withdrawal remains unaffected.
The data you provide will be stored until you request deletion, withdraw your consent to storage, or the purpose for storing the data no longer applies. Statutory retention obligations remain unaffected.
§ 8 Retention Period for Comments
We store user comments as well as the related data, including IP addresses. This data is stored until the comment is removed by the user or a legal obligation to delete it exists.
§ 9 Subscribing to Comments
After registering on our website, you can subscribe to comments. We use a double opt-in procedure for this, meaning you will receive a confirmation email to verify your email address. You can unsubscribe from comment subscriptions at any time via a link in the notification emails. The data collected for setting up the subscription will be deleted after you unsubscribe. If this data has already been provided to us for other purposes and stored elsewhere, it will remain stored in our system.
The storage of your comments is based on your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time without giving reasons. A simple email to us is sufficient. Data processing carried out before withdrawal does not become invalid retroactively.
§ 10 Use and Disclosure of Data
We assure you that personal data you provide to us, for example by email (such as your name, address, or email address), will not be sold to third parties or otherwise used commercially. Your data is processed exclusively for the purpose of corresponding with you and fulfilling the purpose for which you provided the data. As part of payment processing, your payment data will be forwarded to the commissioned financial institution.
The data automatically collected when you visit our website is used solely for the purposes stated above. No other use is made of this data.
Protecting your personal data is important to us. We generally do not disclose your data to third parties unless there is a legal obligation to do so or you have given your explicit consent.
§ 11 Encryption (SSL/TLS)
Our website uses SSL/TLS encryption to ensure the security and protection of the transmission of confidential content. This applies in particular to inquiries that you send to us as the website operator. You can recognize an encrypted connection by “https://” in your browser’s address bar and the lock symbol in the browser bar.
SSL/TLS encryption ensures that data you transmit to us cannot be read by unauthorized third parties.
§ 12 Storage Duration
We store the personal data you transmit to us via our website only for as long as necessary to achieve the purpose of the respective data processing. In accordance with commercial and tax retention obligations, certain data may be stored for up to 10 years.
§ 13 Your Data Protection Rights
As a data subject, you have the following rights against the controller regarding your personal data, in accordance with the applicable legal provisions:
A. Right to Withdraw Consent
Many data processing operations are only possible with your explicit consent. If processing is based on your consent, you have the right to withdraw it at any time with effect for the future pursuant to Art. 7(3) GDPR. Processing carried out before withdrawal remains lawful. Storage for billing and accounting purposes is not affected by withdrawal.
B. Right of Access
Under Art. 15 GDPR, you have the right to obtain confirmation as to whether we process your personal data. If so, you have the right to access the data and information including: purposes of processing, categories of data, recipients, storage period, rights to rectification/erasure/restriction/objection, complaint rights, data sources (if not collected from you), existence of automated decision-making (including profiling), and safeguards under Art. 46 GDPR for transfers to third countries.
C. Right to Rectification
Under Art. 16 GDPR, you have the right to have inaccurate personal data corrected and incomplete data completed.
D. Right to Erasure
Under Art. 17 GDPR, you have the right to request deletion of your personal data where one of the legal grounds applies (e.g., data no longer necessary, consent withdrawn, objection, unlawful processing, legal obligation, etc.).
This right may be restricted where processing is necessary, for example, to comply with a legal obligation, for tasks carried out in the public interest, for public health reasons, for archiving/research/statistics under Art. 89(1) GDPR, or for the establishment/exercise/defense of legal claims.
If we have made your personal data public and are obliged to erase it, we will take reasonable steps (including technical measures) to inform other controllers processing the data that you have requested erasure of links to, copies, or replications of that data.
E. Right to Restriction of Processing
Under Art. 18 GDPR, you have the right to request restriction of processing, e.g., if you contest accuracy, processing is unlawful and you oppose erasure, data is no longer needed but required for legal claims, or an objection under Art. 21(1) GDPR is pending. During restriction, processing generally requires your consent, subject to legal exceptions.
F. Right to Be Informed
Under Art. 19 GDPR, if you exercise your rights to rectification, erasure, or restriction, we must notify recipients to whom the data was disclosed, unless impossible or disproportionate. Upon request, we will inform you of these recipients.
G. Right Not to Be Subject to Automated Decisions (Profiling)
Under Art. 22 GDPR, you have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
This does not apply if the decision is necessary for a contract, authorized by law with safeguards, or based on your explicit consent. Appropriate safeguards include at least the right to obtain human intervention, express your viewpoint, and contest the decision.
H. Right to Data Portability
If processing is based on consent (Art. 6(1)(a) or Art. 9(2)(a) GDPR) or a contract (Art. 6(1)(b) GDPR) and carried out by automated means, you have the right under Art. 20 GDPR to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller, or to have it transmitted by us where technically feasible.
I. Right to Object
If we process your data based on legitimate interests under Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation (including profiling). If you object, we will no longer process the data unless we can demonstrate compelling legitimate grounds overriding your interests, or processing is needed for legal claims.
If data is processed for direct marketing, you may object at any time; then your data will no longer be used for direct marketing (Art. 21(2) GDPR).
J. Right to Lodge a Complaint With a Supervisory Authority (Art. 77 GDPR)
In the event of GDPR violations, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, workplace, or the place of the alleged infringement.
Our competent supervisory authority is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach
Postal address: P.O. Box 1349, 91504 Ansbach
Phone: 0981/180093-0
Email: poststelle@lda.bayern.de
Website: https://www.lda.bayern.de
§ 14 Validity and Changes to This Privacy Policy
This privacy policy takes effect on 25 January 2026. We reserve the right to amend this policy as necessary in compliance with applicable data protection laws. This may be required, for example, to meet new legal requirements or to reflect changes to our website or new services offered via the website. The version of the privacy policy available on our website at the time of your visit is binding.
If changes are made, we will publish them on this page so that you are fully informed about what personal data we collect, how we process it, and under what conditions we may disclose it.