WZ-IT Logo

Privacy Policy

Last updated: July 22, 2026

This privacy policy provides the information required under Articles 13 and 14 GDPR about how we process personal data when you visit wz-it.com, use our website features or contact us.

1. Controller

The controller within the meaning of the General Data Protection Regulation is:
Timo Wevelsiep and Robin Zins GbR
Max-Liersch-Anger 13
59457 Werl
Germany
Phone: +49 2922 875068
Email: [email protected]

You can contact us using these details if you have any questions about data protection or wish to exercise your rights.

Encrypted transmission

Our website uses TLS encryption. Data transmission over the internet may nevertheless involve security risks, particularly when using unencrypted email.

2. General information about processing

Legal bases

We process personal data in particular to take steps before entering into a contract and to perform contracts under Article 6(1)(b) GDPR, to comply with legal obligations under Article 6(1)(c) GDPR and on the basis of our legitimate interests under Article 6(1)(f) GDPR. Where we request consent, processing is based on Article 6(1)(a) GDPR; consent can be withdrawn at any time with effect for the future.

Recipients and processors

Personal data is accessible only to parties that require it for the relevant purpose. These may include hosting, security, communication, email, calendar and IT service providers. Where a provider processes data on our behalf, we enter into the agreements required by Article 28 GDPR. We may also disclose data where this is required for a contract, required by law or permitted by another legal basis.

Retention

We retain personal data only for as long as required for the relevant purpose. We then erase or anonymise it unless statutory retention duties, legitimate evidentiary interests or another legal basis require continued storage. The specific criteria stated below apply to individual processing activities.

Transfers to third countries

Processing in the United States cannot be ruled out when using Cloudflare and Google. Where the relevant US recipient is validly certified under the EU-US Data Privacy Framework, we rely on the European Commission's adequacy decision under Article 45 GDPR. The European Commission's Standard Contractual Clauses under Article 46 GDPR may be used as an additional safeguard.

3. Delivery, hosting and security

Server logs

When you access our website or related services, technically necessary connection data is processed. This includes, in particular, the IP address, date and time, requested URL, amount of data transferred, HTTP status, referrer, browser and operating system. Processing is necessary to deliver content, maintain stability, investigate errors and defend against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of our services. Log data is erased once it is no longer required for these purposes unless a security incident requires longer retention.

Hosting providers

For our website and related first-party services, we use server infrastructure in the European Union provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, and OVHcloud, in particular OVH SAS, 2 Rue Kellermann, 59100 Roubaix, France. The infrastructure involved depends on the service accessed. Further information: Hetzner privacy policy and OVHcloud data protection.

Cloudflare

We use services provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, including DNS, a content delivery network, transport encryption, a web application firewall and protection against abusive traffic. Connections to our website are therefore technically routed through Cloudflare's network. Cloudflare processes the IP address, request data and technical security characteristics, among other data. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is fast, resilient and attack-resistant delivery. Cloudflare is certified under the EU-US Data Privacy Framework and additionally provides for Standard Contractual Clauses. Further information is available in Cloudflare's Privacy Policy and its Data Processing Addendum.

4. Web analytics and storage technologies

Cookie-free web analytics with Umami

We self-host Umami Analytics at analytics.wz-it.com and use it exclusively to measure page-view reach. We do not use individual event or interaction tracking. The data recorded includes the page path without query parameters or URL fragments, page title, referrer, screen size and browser language. Browser, operating system, device type and an approximate region may be derived from technical request data. Umami does not use cookies for audience measurement, states that it does not store directly identifying data and does not create cross-site profiles. The IP address necessarily received when establishing a connection may be processed in infrastructure logs, but it is not displayed in clear text in our analytics reports.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to measure reach, technical quality and content usage in a data-minimising way and to improve our services. Aggregated or anonymous statistics may be retained permanently. Further information about how the software works is available in the Umami documentation.

Cookie-free web analytics is currently active in this browser. You can object here.

Cookies, local storage and session storage

We do not use cookies for advertising or web analytics. Technically necessary cookies or browser storage may be used for features you explicitly request and for security. This includes session storage entries for the state of the AI-assisted offer finder, form steps and notices that have already been displayed. These entries generally last only for the relevant browser session. Your decision to opt out of Umami analytics is stored under umami.disabled in local storage until you remove it using the control above or your browser settings. Cloudflare may set a technically necessary security cookie when a specific security check is performed.

Where information is stored on or read from your device, strictly necessary technologies are used in accordance with section 25(2)(2) TDDDG. Where a technology is not strictly necessary, we request consent in advance in accordance with section 25(1) TDDDG.

5. Contact, forms and cloud cost analysis

Email and telephone

If you contact us by email or telephone, we process your contact details and the content of your enquiry in order to respond and handle follow-up questions. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters and otherwise Article 6(1)(f) GDPR. Our legitimate interest is efficient business communication.

Contact and lead forms

When you use a form, we process the details you submit. Depending on the form, these may include your name, email address, phone number, company, company size, selected services and message. We may also process the current page, referrer, UTM campaign parameters, language, submission time and Turnstile token for attribution and abuse prevention. Mandatory fields are marked as such. We cannot handle the request without the required information.

Form data is encrypted in transit and sent to our automation endpoint, or an endpoint operated on our behalf, at automate.oger.dev, or to a first-party WZ-IT endpoint, before being processed in our communication systems. The legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. We erase form data once the request has been conclusively resolved unless contractual, evidentiary or statutory retention requirements apply.

Cloud cost analysis and file upload

For the cloud cost analysis, we additionally process the invoice or cost overview you upload, including the file name, file type and file contents. The documents are read and evaluated automatically in order to calculate the requested savings potential and email you the result. The analysis has no legal effect and is not a substitute for an individual review. The legal basis is Article 6(1)(b) GDPR. Please redact personal or confidential information that is not required for the cost analysis and do not upload special categories of personal data under Article 9 GDPR. Uploads are erased once the analysis and required follow-up are complete unless another legal basis requires longer storage.

6. Online appointment booking

For online appointment booking we use the Cal.eu platform provided by Cal.com, Inc. The booking dialog is only loaded once you actively start a booking (by clicking an appointment button). Only then are the embed script from app.cal.eu and the booking calendar from cal.eu retrieved; in the process, technically necessary connection data, in particular your IP address and browser information, is processed. If you book an appointment, we process in particular your name, email address, company and other voluntary details, appointment time, time zone and booking metadata. The legal basis for conducting the appointment is Article 6(1)(b) GDPR and, for efficient appointment management, Article 6(1)(f) GDPR.

Cal.com, Inc. processes booking data on our behalf; a data processing agreement pursuant to Article 28 GDPR is in place. We specifically use the European Cal.eu region. According to the provider, scheduling data in this region is stored and processed within the EU. The service is nevertheless operated by Cal.com, Inc., a US company, and the provider's general privacy policy therefore also contains information about possible international data transfers. Where a transfer to a third country occurs in an individual case, the contractually agreed safeguards pursuant to Articles 44 et seq. GDPR apply. Further information is available on the Cal.eu information page, in the Cal.com Privacy Policy and in Cal.com's security and DPA area. The email and calendar services we use may receive the information required for confirmations and calendar entries. Booking data is erased when it is no longer needed for the appointment and related communication unless contractual or statutory retention requirements apply.

7. Spam protection and embedded videos

Cloudflare Turnstile

We use Cloudflare Turnstile to protect our forms against automated submissions. The widget loads code from challenges.cloudflare.com and, according to Cloudflare, processes the IP address, TLS fingerprint, user-agent, sitekey and associated origin, as well as signals from the browser environment. These signals are used to distinguish humans from bots. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the availability and security of our forms and the prevention of spam. To the extent that Turnstile stores or reads strictly necessary information on the device, we rely on section 25(2)(2) TDDDG.

Cloudflare processes some signals on our behalf and some in its own capacity to improve its bot detection. Cloudflare is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses may additionally apply. Details are provided in the Turnstile Privacy Addendum.

YouTube in privacy-enhanced mode

Some pages contain YouTube videos. Only a locally stored preview image is shown before playback. A connection to youtube-nocookie.com and Google services is established only when you start playback. Your IP address, device and browser information, the page viewed and your interaction may then be transmitted to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and potentially Google LLC in the United States. If you are signed in to Google, Google may associate the view with your account.

By deliberately starting the video, you consent to this processing and, where necessary, to storing or reading information on your device. The legal bases are Article 6(1)(a) GDPR and section 25(1) TDDDG. You can withdraw consent for the future by closing the video and not starting it again. Google LLC is certified under the EU-US Data Privacy Framework. Further information: Google Privacy Policy and Google data transfer frameworks.

8. AI-assisted offer finder

Our AI-assisted offer finder matches a project description you submit with relevant WZ-IT services. We process your text, the request language and source, technical connection data and the generated result. Processing takes place server-side through our API at offerbot-api.wz-it.com on infrastructure we control. We use a European Mistral AI model and curated WZ-IT content to generate the response. There is no direct browser connection to a US chatbot platform. Inputs are not used to train AI models. Do not enter passwords, credentials, special categories of personal data or confidential documents.

Use for a non-binding assessment is based on Article 6(1)(f) GDPR. Our legitimate interest is efficient initial information tailored to the request. If you then submit the result as a contact request, we additionally process the contact details you voluntarily provide and the full request and result context under Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. The assessment is stored in your browser's session storage so that it remains available during navigation; it generally ends with the browser session or is erased when you select “New request”.

The offer finder provides an initial technical assessment. It does not make a solely automated decision with legal or similarly significant effects within the meaning of Article 22 GDPR.

9. Audio and video conferences

We use Google Meet, among other tools, for scheduled online meetings. This may involve processing master and contact data, start, end and duration of participation, IP address, device and connection data, and any audio, video, chat or file content you provide. Using a camera or microphone is generally voluntary unless it is required for the meeting you requested. Meetings are recorded only after prior notice and on a separate legal basis.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis is Article 6(1)(b) GDPR for contractual and pre-contractual communication and otherwise Article 6(1)(f) GDPR. Google LLC is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses may additionally apply. Further information is available in Google's Privacy Policy.

10. Your rights

Subject to the applicable legal requirements, you have the following rights in particular:

  • access to the personal data processed under Article 15 GDPR,
  • rectification of inaccurate data under Article 16 GDPR,
  • erasure under Article 17 GDPR,
  • restriction of processing under Article 18 GDPR,
  • data portability under Article 20 GDPR where applicable,
  • withdrawal of consent with effect for the future under Article 7(3) GDPR,
  • objection, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR. You may object to direct marketing at any time without giving reasons.

To exercise your rights, send a message to [email protected]. We may request suitable proof of identity where this is necessary to protect your data.

Right to lodge a complaint

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our registered office is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, phone: +49 211 38424-0, email: [email protected], www.ldi.nrw.de. You may also contact any other supervisory authority competent under Article 77 GDPR.

11. Changes to this privacy policy

We update this privacy policy when our processing activities or legal requirements change. The current version published on this page applies.