BOGENHAUS

Privacy

Automatic translation - the original German wording is legally binding.

We appreciate your interest in BOGENHAUS. The protection of personal data is important to us. Below we inform you about which personal data we process when you visit our website and when you contact us.

1. Controller

The controller responsible for data processing is:

BOGENHAUS GmbH
Frohnstr. 13
40789 Monheim am Rhein
Germany

Email: kontakt@bogenhaus.de
Website: www.bogenhaus.de

2. Provision, hosting and security of the website

When our website is accessed, technical connection and request data is processed. This may include, in particular, the IP address, date and time of access, the address accessed, the referrer, the amount of data transferred, browser type and browser version, the operating system, as well as status and error messages.

We process this data in order to deliver the website, ensure its stability and security, limit automated or abusive access and investigate specific security incidents. The legal basis is Art. 6(1)(f) GDPR; our legitimate interests lie in the secure, disruption-free and economical operation of the website.

The website is hosted by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp, Germany. For secure and fast delivery, we additionally use services of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Both companies process technical data within the scope of the services commissioned by us. Where they act as processors, contracts pursuant to Art. 28 GDPR are in place.

Cloudflare operates a globally distributed network. Processing outside the European Economic Area, in particular in the USA, therefore cannot be completely excluded. According to the contractual arrangements, Cloudflare relies for such transfers in particular on the EU-US Data Privacy Framework and, in addition, on the Standard Contractual Clauses of the European Commission. Further information on the safeguards used is available via the contact details stated above.

We use technically necessary cookies only insofar as they are required for the operation and security of the website, for example to protect our forms, manage sessions or defend against automated access. These cookies are not used for reach analysis or personalised advertising.

3. Our own reach analysis without analytics cookies

We operate our own server-side reach analysis used exclusively for this website in order to evaluate the use of our website, the origin of visits and enquiries, and the effectiveness of our own content and campaigns. We do not use analytics cookies, local storage, advertising IDs or an external web analytics service; there is no recognition across websites or devices.

For this purpose, technical usage and origin information, including search terms transmitted by search engines, coarse device and browser characteristics, and approximate regional information are processed. We do not use individual advertising or click IDs; we do not store the full IP address or the full user agent as raw values for reach analysis.

To distinguish genuine page views from automated access, an empty verification signal may be triggered on the client side – for example after a short dwell time or an initial interaction. No information is stored on or read from your device, no recognition feature is created and no additional personal data is collected.

The technical request data arising for this purpose is processed only briefly and removed from the ongoing analytics system no later than within two days. Afterwards, only aggregated statistical values without persistent visitor identifiers and without individual navigation histories remain there. The short-term identifiers and individual events created for reach analysis are not combined with contact, customer or project data to create individual usage profiles.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in being able to understand the use and economic effectiveness of our website and to further develop it according to need, without using external analytics services or persistent user profiles.

You may object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR). In addition, you can disable reach analysis for the browser used via the button offered below. Only in this case do we store your decision in the browser used, so that we can take your objection into account on a lasting basis; for this purpose, only a technically necessary preference cookie is stored that contains solely your choice and no user identifier. This storage serves exclusively the function you requested.

4. Contact via contact form or email

If you contact us via the contact form or by email, we process the information you provide. This may include, in particular, your name, email address, telephone number, message, attachments, and the date and time of the enquiry. Where available, general information about the context and origin of the enquiry may also be stored with the contact record.

We use this information to process your enquiry, ask follow-up questions, coordinate appointments, prepare a requested offer and communicate with you in the factual context of the enquiry.

Information marked as mandatory is required to process your enquiry; without this information, we generally cannot respond to the enquiry. Further information is voluntary.

The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry relates to a contract, an offer or pre-contractual measures. For general business enquiries and communication with contact persons at companies or organisations, Art. 6(1)(f) GDPR is the legal basis; our legitimate interest lies in processing and documenting business enquiries.

When the web form is submitted, we also store the IP address and the time of transmission. This serves to protect against automated, abusive or duplicate submissions and to document that, when and with what content an enquiry was submitted. The documentation may be necessary in particular to prove the legitimacy of subsequent contact or to assert, exercise or defend legal claims. The legal basis is Art. 6(1)(f) GDPR.

After completion of the enquiry, the data record required for evidence purposes is retained only for evidence and legal defence purposes and is generally stored until the end of the third calendar year after completion of the enquiry. If there is a specific complaint, warning notice or legal proceeding, storage may continue until final clarification.

If the enquiry results in a customer, contractual or project relationship, the contact, communication, offer and project data required for this will be transferred to the corresponding customer or project file. We use a voluntarily provided telephone number for follow-up questions in connection with your enquiry. Contacting us does not automatically lead to registration for newsletters or advertising unrelated to the topic.

5. Recipients and service providers

We use technical service providers for hosting, website security, maintenance and email communication, in particular Mittwald CM Service GmbH & Co. KG mentioned in section 2 (hosting, email and technical infrastructure) and Cloudflare, Inc. (delivery and security of the website). They receive personal data only insofar as this is necessary to provide the respective service and process it according to our instructions where they act as processors.

Data is transferred to other recipients only if this is necessary to process an enquiry or perform a contract, if there is a legal obligation, or if this is necessary to assert, exercise or defend legal claims. This may include, in particular, tax advisers, legal advisers, authorities or courts. Personal data is not sold.

6. Storage period

We store personal data only for as long as it is required for the respective purpose or statutory retention obligations exist.

Technical operation and security logs maintained by us are generally deleted within 30 days. In the event of specific security incidents, the data required for this may be retained until the investigation is completed and, if applicable, until the expiry of relevant limitation periods for legal prosecution.

The technical data temporarily required for reach analysis is removed from the ongoing analytics system in accordance with section 3. The aggregated statistical values that remain afterwards do not contain individual identifiers or navigation histories; we retain them for operational comparison and planning purposes and review their continued necessity regularly, at least annually.

For contact enquiries and evidence records, the periods stated in section 4 apply. Contractual, project, accounting and invoice documents may have to be retained for six, eight or ten years depending on the type of document. Further data may be stored until the expiry of the applicable statutory limitation periods insofar as this is necessary to preserve or defend rights.

Deleted data may still be contained in protected backup copies until the defined backup cycles expire. Backup copies are not used for ongoing evaluations, but exclusively for restoration after a technical failure; the applicable deletion rules are applied again in that process.

7. No exclusively automated decisions

We do not make exclusively automated decisions that produce legal effects concerning you or similarly significantly affect you.

8. Data security

We take appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration or disclosure. The website is transmitted via HTTPS encryption. Access to administration and evidence data is restricted to the persons required for this purpose.

9. Your rights

Within the scope of the statutory requirements, you have the right of access, rectification, erasure, restriction of processing and data portability. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object on grounds relating to your particular situation. We will then no longer process the relevant data unless we can demonstrate compelling legitimate grounds or the processing serves to assert, exercise or defend legal claims. You may object to processing for direct advertising at any time without stating reasons.

To exercise your rights, you can contact kontakt@bogenhaus.de.

You also have the right to lodge a complaint with a data protection supervisory authority. For BOGENHAUS GmbH, the competent authority is in particular:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
www.ldi.nrw.de

10. Current status of this privacy policy

We adapt this privacy policy if our website, the procedures used or legal requirements change.

Last updated: 26 June 2026

Objection to reach analysis

You can disable our own reach analysis for this browser. Only in this case do we store your decision; for this purpose, only a technically necessary preference cookie without a user identifier is stored that contains solely your choice and serves the function you requested.