Data protection
Privacy Policy
Last updated: August 4, 2026
1. Controller
The controller responsible for this website is:
Richard J. WeberSole proprietor
Richard-Breslau-Str. 10
99094 Erfurt
Germany
Email: [email protected]
2. Scope of this policy
This policy applies only to the public nexrow landing page. The page provides information about nexrow and does not provide user accounts, forms, uploads, or functionality of the nexrow software.
We do not use analytics or marketing services, advertising networks, or profiling technologies on this page.
3. Visiting the website and Cloudflare hosting
When you visit the website, technical connection data is processed in order to deliver the requested content. This may include:
- IP address
- Date and time of access
- Requested page, file, and HTTP method
- HTTP status code and transferred data volume
- Referring page, if supplied by the browser
- Browser, operating system, device, and language information
- Routing, connection, and security information
Processing is necessary to operate the website, deliver it securely, maintain its availability, diagnose errors, and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable, and efficient operation of this website.
Cloudflare
We use services of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, and companies of the Cloudflare group for hosting, content delivery, encryption, routing, and protection against abusive traffic.
To the extent Cloudflare processes personal data on our behalf, this processing is governed by a data processing agreement pursuant to Article 28 GDPR. Cloudflare operates a global network, so technical data may also be processed outside the European Economic Area, particularly in the United States.
According to Cloudflare, transfers to the United States are based on its certification under the EU US Data Privacy Framework where it applies. Where that framework does not apply, Cloudflare uses the European Commission's Standard Contractual Clauses and additional safeguards.
Further information is available in the Cloudflare Privacy Policy and the Cloudflare Data Processing Addendum.
Retention
Technical data is retained only for as long as needed to deliver and secure the website, investigate errors or security incidents, and comply with legal obligations. It is then deleted or anonymised under the applicable service configuration and contractual rules. We do not activate optional visitor analytics or detailed long term HTTP log storage for this landing page.
4. Contact by email
The email address on this website is implemented as a mailto link. Clicking it alone does not transmit contact data to us. Processing begins when you send an email.
We may then process your email address, name, subject, message, attachments, time of communication, and technical email headers. We use Cloudflare Email Routing to forward messages sent to the nexrow domain to our destination mailbox. Cloudflare and the provider of the destination mailbox process the information required to deliver and store the message.
If your message relates to steps before entering into a contract or to an existing contract, the legal basis is Article 6(1)(b) GDPR. For general business communication, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to receive, organise, and answer enquiries.
We delete enquiries after they have been fully resolved unless contractual, statutory, or other legitimate reasons require further retention. Business correspondence may be retained for the applicable statutory period. Information required for legal claims may be kept until the relevant limitation period has expired.
5. Cookies and similar technologies
We do not use our own analytics, advertising, or profiling cookies and do not store comparable identifiers for those purposes. Therefore, no consent banner is required for the current configuration of this landing page.
If Cloudflare sets a strictly necessary cookie in an individual case to perform a security check or protect the website, access to the end device is based on Section 25(2)(2) TDDDG. Related processing of personal data is based on Article 6(1)(f) GDPR and our legitimate interest in protecting the website from abusive traffic.
6. Recipients
Personal data is received only by service providers needed for hosting, security, and email communication, as described above. Where required, these providers are contractually bound under Article 28 GDPR. Data may also be disclosed to public authorities or other third parties where required by law or necessary to establish, exercise, or defend legal claims. We do not sell personal data.
7. Your rights
Subject to the legal requirements, you have the right to:
- Access your personal data under Article 15 GDPR
- Rectification under Article 16 GDPR
- Erasure under Article 17 GDPR
- Restriction of processing under Article 18 GDPR
- Data portability under Article 20 GDPR
- Object to processing under Article 21 GDPR
Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation.
To exercise your rights, contact [email protected].
8. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority responsible for our place of establishment is:
Thüringer Landesbeauftragter für den Datenschutz und die InformationsfreiheitHäßlerstraße 8
99096 Erfurt
Germany
www.tlfdi.de
9. Required data and automated decisions
Technical connection data is necessary to display the website. Contact by email is voluntary, although we may be unable to answer without the information needed to process your request. We do not use automated decision making or profiling on this landing page.
10. Changes to this policy
We update this policy when the website, service providers, or legal requirements change. The date shown above identifies the current version.
