Privacy Policy
Information on the processing of personal data pursuant to Articles 13 and 14 GDPR. Last updated: July 2026.
The protection of your personal data is important to us. This privacy policy provides comprehensive information on which data we process when you visit this website and when you contact us, for what purpose this takes place, and which rights you have in this regard.
1. Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Schmiel ConsultingRafael Schmiel
Koblenzer Straße 51
56626 Andernach
Germany
Phone: +49 2632 947 8883
Email: info@schmielconsulting.de
No company data protection officer has been appointed, as there is no legal obligation to do so: as a rule, at least 20 people are not constantly employed with the automated processing of personal data (Section 38(1) BDSG), nor does any processing take place that would require an appointment under Art. 37 GDPR.
2. Principles and Legal Bases
We process personal data only to the extent necessary to provide this website, to handle your enquiries, or to comply with legal obligations. Depending on the specific processing activity, we rely on the following legal bases under the GDPR:
- Art. 6(1)(a) GDPR – you have given your consent to the processing, for example when submitting the contact form.
- Art. 6(1)(b) GDPR – processing is necessary to initiate or perform a contract, for example when booking an appointment for an initial consultation.
- Art. 6(1)(f) GDPR – processing is necessary to safeguard a legitimate interest, for example to ensure the technically stable and secure operation of the website.
Which legal basis applies in each individual case is stated in the respective sections of this policy.
3. Your Rights as a Data Subject
You have the following rights against us with regard to your personal data:
- Right of access to the data we process about you (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure of your data (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Right to withdraw any consent given, with effect for the future (Art. 7(3) GDPR)
To exercise these rights, an informal message to info@schmielconsulting.de is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority (see Section 16).
4. Provision of the Website and Server Log Files
This website is hosted by the hosting provider ALL-INKL.COM – Neue Medien Münnich (Hauptstraße 68, 02742 Friedersdorf, Germany). On our behalf, the host processes, as a data processor pursuant to Art. 28 GDPR, the data that is technically necessary to operate and deliver this website.
When you access this website, the web server automatically collects what are known as server log files transmitted by your browser. These include:
- the IP address of the accessing device,
- the date and time of the request,
- the page or file accessed,
- the previously visited page (referrer URL),
- the browser type and operating system used,
- the amount of data transferred and the request status.
This data is used exclusively for the technical delivery of the website, the detection of faults, and the prevention of misuse; it is not combined with other data sources. It is stored for a limited period and then automatically deleted. The legal basis is our legitimate interest in the stable and secure operation of this website (Art. 6(1)(f) GDPR).
5. Contact via Form, Email and Phone
Our contact page provides a contact form. This transmits the mandatory fields name, email address and message, as well as – if completed by you – the voluntary details of company, phone number, requested service and preferred method of contact. Submission is only possible after you have confirmed our privacy notice via the consent checkbox in the form.
The form data is processed server-side on our web server and forwarded by email to our mailbox info@schmielconsulting.de, which is operated via Microsoft 365 (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland). The form entries are not permanently stored in a database – the data is transmitted exclusively by email.
To protect against spam and misuse, we use purely technical measures that do not collect any additional personal data from you:
- a form field that is invisible to humans (a "honeypot"), which is only filled in by automated programs,
- a server-side timing check against forms filled in automatically too quickly,
- an origin check (origin/referer check) to verify that the request actually originates from our website,
- a technically necessary security cookie to protect against manipulated form submissions (see Section 9).
The legal basis for this processing is your consent (Art. 6(1)(a) GDPR); insofar as your enquiry serves to initiate an engagement, additionally Art. 6(1)(b) GDPR. Alternatively, you can also reach us directly by email or phone; in this case, we process the data you provide exclusively to handle your enquiry.
6. Communication via WhatsApp
On this website, we additionally offer a contact link to WhatsApp. This link opens – only if you actively click on it – a pre-filled message in the WhatsApp app or in WhatsApp Web. Data is transmitted to WhatsApp only if you choose this method of contact yourself and actually send a message; no WhatsApp element is automatically loaded on our page.
If you use this method, the communication is additionally subject to the privacy terms of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, as the provider of the service for users in the European Economic Area. In this context, data such as your phone number may also be transferred to the parent company Meta Platforms, Inc. (USA). Using this method of contact is voluntary; alternatively, you can always reach us by email, phone or the contact form. The legal basis is your consent through the active use of this method of contact (Art. 6(1)(a) GDPR).
7. Online Appointment Booking via Calendly
On our contact page, we offer the option to book an appointment for a free initial consultation directly online via the provider Calendly LLC, 271 17th Street NW, Suite 1000, Atlanta, GA 30363, USA. The booking window is loaded automatically when the contact page is opened and is immediately visible, without requiring a separate click.
A connection to Calendly's servers is established as soon as the contact page is loaded. In doing so, your IP address and other technical data (for example, browser type, device type, approximate region) are transmitted to Calendly, and Calendly may set cookies. If you go on to actually book an appointment, Calendly additionally processes the data you enter in the booking window (for example, name, email address, requested appointment) in order to carry out the booking and send you a confirmation.
A data processing agreement pursuant to Art. 28 GDPR is in place with Calendly. The legal basis for embedding this service is our legitimate interest in providing a straightforward, directly usable online appointment booking option without requiring an additional click (Art. 6(1)(f) GDPR), as well as – once you actually book an appointment – the performance of a pre-contractual relationship (Art. 6(1)(b) GDPR). If you do not wish the automatic connection to Calendly to be established when the contact page is opened, please use our contact form, email, phone or WhatsApp instead – no data is transferred to Calendly through these channels.
For further information on how Calendly handles your data, please see the provider's privacy policy: calendly.com/privacy.
8. Linked Social Media Profiles
In the header and footer of this website, we link to our profiles on Instagram, Facebook and TikTok. These are exclusively simple hyperlinks to the respective profile pages, not embedded social plugins, like buttons or widgets. Simply visiting this website therefore does not result in any data being transmitted to the platforms mentioned; this only occurs once you actively click the link and visit the respective platform. From that point on, the privacy terms of the respective provider apply (Meta Platforms Ireland Limited for Instagram and Facebook, TikTok Technology Limited for TikTok).
9. Cookies on This Website
This website uses only a single, first-party cookie of its own:
| Name | Purpose | Storage Period | Legal Basis |
|---|---|---|---|
csrf_token |
Protects the contact form against manipulated submissions (double-submit cookie) | Session cookie, deleted when the browser is closed | Art. 6(1)(f) GDPR, technically necessary |
This cookie is technically essential for the contact form to function securely; it serves neither to analyse your behaviour nor for advertising purposes and therefore does not require consent via a consent banner.
In addition, cookies may be set by Calendly when its booking window is automatically loaded on the contact page. These are described in Section 7 and are outside our sphere of influence. No personal data is stored via any other storage mechanisms of our own, such as local storage or session storage in the browser.
10. Recipients and Data Processors at a Glance
In the course of operating this website, personal data is disclosed to the following external parties:
| Recipient | Purpose | Location |
|---|---|---|
| ALL-INKL.COM – Neue Medien Münnich | Hosting and delivery of the website | Germany |
| Microsoft Ireland Operations Limited (Microsoft 365) | Receiving and managing emails sent to info@schmielconsulting.de, including contact form enquiries | Ireland / global Microsoft infrastructure |
| Calendly LLC | Providing the online appointment booking window | USA |
| WhatsApp Ireland Limited | Communication if you actively use the WhatsApp link | Ireland / global Meta infrastructure |
Where necessary, data processing agreements pursuant to Art. 28 GDPR are in place with these service providers.
11. Data Transfers to Third Countries
When using Calendly (USA) and in connection with the Microsoft and Meta infrastructure, personal data may be transferred to the USA or other third countries outside the EU/EEA. This transfer takes place on the basis of EU Standard Contractual Clauses pursuant to Art. 46 GDPR, which are provided by the respective providers and ensure an adequate level of data protection.
12. No Analytics, Marketing or Tracking Services
This website deliberately refrains from using analytics, marketing and tracking services. In particular, the following are not used: Google Analytics, Google Tag Manager, Google Ads, Meta Pixel, TikTok Pixel, Microsoft Clarity, Hotjar and comparable services. No user profiles are created, no cross-device or cross-site tracking is carried out, and no advertising cookies are set. External fonts are likewise not loaded; the website uses exclusively the system fonts already present on your device, so that no connection to an external provider is established through this. Chatbots or AI-powered dialogue systems are likewise not used on this website.
13. No Automated Decision-Making and No Profiling
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
14. Storage Period
Personal data from contact enquiries is deleted as soon as it is no longer required to handle your enquiry and no statutory retention obligations under commercial or tax law preclude deletion. Server log files are automatically deleted after a short, technically determined period (see Section 4). The security cookie csrf_token is a session cookie and is automatically deleted at the latest when you close your browser.
15. Data Security
This website is delivered exclusively via an encrypted HTTPS (TLS) connection. Submission of the contact form is additionally secured against manipulation and automated misuse by the technical measures described in Section 5. In all other respects, we take appropriate technical and organisational measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons.
16. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. For us, as a business based in Rhineland-Palatinate, this is:
State Commissioner for Data Protection and Freedom of Information of Rhineland-PalatinateHintere Bleiche 34
55116 Mainz, Germany
www.datenschutz.rlp.de
17. Currency of This Privacy Policy
This privacy policy describes the state of the technology used on this website as of the date stated above. If the services used or the legal situation change, we will update this policy accordingly. The version published at the time of your visit to this page shall apply.