Skip to content
HomeServicesTrainingServiceAbout us
Articles
Latest articlesArchiveInsights & topics
Contact ↗
DE|EN
  1. Home
  2. Data protection

Legal

Privacy.

This notice explains how we process personal data when you visit www.sitsolutions.de or contact us using the methods listed there.

1. Controller

Schmidt IT-Solutions Jörg Schmidt
Am Sonnenhain 13
36039 Fulda
Germany
Telephone: +49 (0)661 95259788
Email: info@sitsolutions.de

2. Website delivery and server logs

When you visit this website, your device transmits technically necessary data to the web server. This includes your IP address, access date and time, requested page or file, HTTP status code, browser and operating system details. The previous page (referrer), if supplied by your browser, and the volume of data transferred may also be logged.

We process this data to deliver the website, maintain its stability and security, and detect technical faults or attacks. The lawful basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and functional operation of our website. We do not combine this data with other information to create usage profiles or analyse it for advertising.

The website is hosted by ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The provider processes the data needed to deliver and secure the hosting service. Further details are available in its privacy information.

Server logs are deleted when no longer needed for operation, troubleshooting or security. Security-related entries may be retained longer in individual cases, for example to investigate an attack or pursue legal claims.

3. Contact by email or telephone

When you contact us by email or telephone, we process the information you provide, particularly your name, contact details, enquiry and any conversation notes, to deal with your request and communicate with you. If you are or wish to become a contracting party and the processing is necessary for that purpose, the lawful basis is Article 6(1)(b) GDPR. For enquiries from employees or representatives of a business and other matters, we rely on Article 6(1)(f) GDPR; our legitimate interest is appropriate handling and communication.

We use Microsoft 365 with Exchange Online for email. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft processes sender and recipient addresses, message contents, attachments and technical transmission data. See the Microsoft Privacy Statement.

Information is deleted once the matter is complete and further retention is unnecessary. Statutory retention requirements, particularly for business correspondence, and the establishment, exercise or defence of legal claims may require longer retention. Senders’ email providers and telecommunications providers are also technically involved in email and telephone communications respectively.

4. WhatsApp Business

If you contact us through WhatsApp, we process your telephone number, profile name, messages and any files you send to answer your enquiry. We use WhatsApp Business from WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. This channel is optional; you can contact us by email or telephone instead.

If you are or wish to become a contracting party and the communication is necessary for that purpose, the lawful basis is Article 6(1)(b) GDPR. Otherwise, we rely on Article 6(1)(f) GDPR and our legitimate interest in prompt communication through your chosen channel. WhatsApp also processes connection and usage data and may transfer data within its group to third countries, particularly the USA. See the WhatsApp Business privacy policy and international transfer information.

We delete our communication content when no longer needed to deal with the matter, subject to statutory retention duties and the protection of legal claims. We do not have complete control over WhatsApp’s own retention.

5. Online meetings with Microsoft Teams

We use Microsoft Teams, also provided by Microsoft Ireland Operations Limited, for agreed online appointments and training. Participation may involve processing your display name, email and IP addresses, device and connection data, participation time and duration, and audio, video, chat or file content you share. Where you are the contracting party and the meeting is necessary for the contract, Article 6(1)(b) GDPR applies. For employees or business representatives and other meetings, we rely on Article 6(1)(f) GDPR for efficient delivery and communication.

Microsoft processes data as part of its Microsoft 365 services. Depending on features and contractual arrangements, transfers to third countries may occur. See the Microsoft Privacy Statement and Microsoft Data Protection Addendum. We retain appointment and meeting data only as needed for organisation and follow-up, subject to statutory retention requirements. We will inform you separately before any recording begins.

6. Appointment booking with Fantastical

Our email signature may include a Fantastical Openings booking link. The booking service is not embedded in this website, so a website visit alone does not transfer data to Fantastical. If you open the email link and request an appointment, the provider, Flexibits Inc., USA, processes your name, email address, selected appointment, any message and technical access data. Flexibits also receives information about our available and occupied time slots to display availability; according to the provider, calendar entry contents are not transferred.

We use this information to arrange appointments. Article 6(1)(b) GDPR applies if you are or wish to become a contracting party and the appointment is necessary for that purpose. Otherwise, Article 6(1)(f) GDPR applies to our legitimate interest in straightforward scheduling. Use is optional; appointments can also be arranged by email or telephone. Flexibits’ privacy policy and data protection terms describe its processing and possible US transfers. We delete appointment data when its purpose ends, unless statutory requirements or legitimate grounds justify further retention.

7. Website check

Our support page offers an optional website check. The form loads only when you explicitly select “Load form”, not when you visit the page. Your browser then connects to compliance.sitsolutions.de, transmitting technically necessary access data such as IP address, time and browser details. The service sets a session cookie (PHPSESSID) to enable the form process.

We process the website URL and email address you submit to carry out the requested analysis and send you the result. The DPMS platform is provided under a processing arrangement by LegalInnovate Technologies GmbH, Issumer Tor 45, 47608 Geldern, Germany. Article 6(1)(b) GDPR applies when you request a pre-contractual service for yourself; for business contacts, we rely on Article 6(1)(f) GDPR. Our legitimate interest is providing the requested check and delivering its result. The session cookie required for the explicitly requested form process falls under section 25(2), no. 2 TDDDG, the German Telecommunications Digital Services Data Protection Act.

We delete this information once the analysis and any follow-up communication are complete, unless retention duties or legitimate grounds justify longer storage. See the platform provider’s privacy notice.

8. Cookies, analytics and external content

A simple visit to this website does not use cookies or comparable storage technologies. We do not use analytics or advertising services. Fonts, images, stylesheets and website scripts are served by our own web server. Pages with live chat make the brief connection to our own support system described below to display availability. The website check form loads from an external provider only after you activate it.

Links to isms.sitsolutions.de and portal.sitsolutions.de open separate support and learning services. Visiting this website alone does not connect to the learning portal. Pages with live chat query support system availability as described below. We host the support system on our own infrastructure; the learning portal is hosted by IONOS. Their respective functions and privacy notices apply when you use them.

Enquiries through the Zammad form

You can create a ticket directly using the enquiry button on our contact or support page. Only after you click does your browser load the form script from isms.sitsolutions.de. This involves technically necessary access data, including IP address, time and browser details. The form also generates a technical identifier from your browser’s canvas rendering and sends it to the support system to secure the form process and help prevent misuse. The required jQuery library is served by our website, without connecting to a jQuery CDN.

When you submit an enquiry, we process your name, email address, message and the technical data described above to register and answer your ticket. Article 6(1)(b) GDPR applies to contractual or pre-contractual enquiries with you; for business contacts and other matters, we rely on Article 6(1)(f) GDPR. Our legitimate interest is handling and securing enquiries. We delete ticket data when no longer needed, unless retention duties or legitimate grounds justify longer storage.

Live chat

On pages with a live chat button, your browser briefly connects by WebSocket to our self-operated support system at isms.sitsolutions.de on page load and periodically thereafter to check availability. The connection closes once availability is reported. Technically necessary data includes your IP address, time, browser details and the visited page. The lawful basis is Article 6(1)(f) GDPR; our legitimate interest is displaying a reliable live chat service or offering an enquiry when unavailable. The status check sets no cookies and stores no chat content.

Only clicking live chat loads the chat script and design from the support system. A further WebSocket connection is then established for the conversation. The chat uses your browser’s Session Storage to associate the current conversation and unsent text during the session. Minimising the window keeps the conversation connection open; ending the chat closes the session. The actual chat window does not load merely by visiting the site.

We process your messages and any additional voluntary information to handle your enquiry. Article 6(1)(b) GDPR applies to contractual and pre-contractual enquiries with you; for business contacts and other enquiries, we rely on Article 6(1)(f) GDPR and our legitimate interest in direct communication. Chat records are retained only as needed, subject to statutory duties and legitimate grounds for longer retention. An unsuccessful chat attempt does not create a ticket when no agent is available. You can use the separate enquiry form instead.

9. Recipients and transfers to third countries

The hosting provider receives the data technically necessary to operate the website. Communication providers receive data needed for your chosen channel. When you explicitly open the website check, LegalInnovate Technologies GmbH receives the data needed for the form and analysis. We have data processing agreements with ALL-INKL, Microsoft and LegalInnovate. Otherwise, data is shared only where needed to handle your enquiry or fulfil a contract, required by law or permitted by another lawful basis.

Pages with live chat contact our own support system, in addition to the website host, to check availability; other pages do not make this check. WhatsApp Business, Microsoft 365/Teams and Fantastical may involve transfers outside the EU or EEA. Their notices linked above explain transfer mechanisms and safeguards.

10. Required information and automated decisions

Technically necessary access data is required to display the website. Otherwise, visiting it creates no statutory or contractual obligation to provide personal data. Contact information is voluntary, but without the information needed to respond, we may be unable to handle your enquiry. The activities described here do not involve automated decision-making, including profiling, under Article 22 GDPR.

11. Your rights

Subject to the GDPR, you have rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18) and, where the legal conditions apply, data portability (Article 20). You may withdraw consent at any time with effect for the future. This does not affect the lawfulness of processing before withdrawal.

Right to object: Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation under Article 21(1) GDPR. We will stop processing the affected data unless compelling legitimate grounds apply or processing serves the establishment, exercise or defence of legal claims.

Please send requests to info@sitsolutions.de. You may also complain to a data protection supervisory authority under Article 77 GDPR. For our location in Hesse, this is the Hessian Commissioner for Data Protection and Freedom of Information. Your right to contact another competent authority remains unaffected.

12. Date of this notice

Source notice: September 2026. The contact form description reflects the direct contact-page access added in October 2026. We update this notice when the website or the processing described here changes.

Practical data protection, information security and compliance.

ServicesTrainingServiceContactLegal noticePrivacy

© SITsolutions 2026