Privacy Policy
We take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data are data that can be used to identify you personally. This privacy policy explains which data we collect and what we use them for. It also explains how and for what purpose this happens.
Please note that data transmission over the internet (e.g., when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Controller & Contacts
- Address
- Phone+49 721 754065 50
- Emailinfo@awesome-it.de
- Represented by the managing directors
Daniel Bross
Daniel Morlock
- Data Protection Officer
Sabrina Manieradatenschutz@awesome-it.de
- Information Security Officer (CISO)
Philip Flohrciso@awesome-it.de
Hosting & Server Log Files
Our website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The hosting provider processes personal data (e.g., IP addresses) on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR.
When visiting the website, the web server automatically logs the following data:
- Anonymized IP address (the last 2 bytes are removed)
- Pages and files accessed
- Referrer (previously visited page)
- Date and time of the visit
- Browser used and device type
- Operating system
These data are used to ensure trouble-free operation and for error analysis and are stored for a period of 7 to 30 days. The legal basis is Art. 6 (1) lit. f GDPR.
Web Analytics with Matomo (without cookies)
We use the open-source web analytics software Matomo to analyze the use of our website and improve our offering.
Matomo is operated without cookies. No information is stored on or read from your device.
The following data are collected:
- Anonymized IP address (the last 2 bytes are removed)
- Pages and files accessed
- Referrer (previously visited page)
- Date and time of the visit
- Browser used and device type
- Operating system
Personal identification of visitors is excluded, as we do not use cookies, fingerprinting, or other recognition technologies. No merging with other data sources takes place.
The data are processed exclusively on our own servers in Germany. There is no transfer to third parties.
The legal basis is Art. 6 (1) lit. f GDPR (legitimate interests). Our legitimate interest lies in the statistical analysis of user behavior to optimize our website technically and in terms of content.
You can object to the processing of your data at any time by enabling the “Do Not Track” setting in your browser or by disabling Matomo:
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content—such as orders or inquiries you send to us as the site operator—this site uses SSL/TLS encryption. You can recognize an encrypted connection by the change in the browser’s address line from “http://” to “https://” and by the lock icon in your browser bar.
When SSL/TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
External Content
We do not use external services such as Google Fonts, YouTube, social plugins, or third-party CDNs, except for Matomo (see above).
General Contact Enquiries
If you send us inquiries via a contact form, the information you provide in the form—including the contact details you enter there—will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent. We collect the following data:
- First and last name
- Company
- Company size
- Email address
- Phone number
- Your message
Transmission is encrypted via HTTPS.
The processing of the data entered into the contact form is based solely on your consent (Art. 6 (1) lit. a GDPR). You can revoke this consent at any time. An informal email to us is sufficient. The lawfulness of the data processing operations carried out until the revocation remains unaffected by the revocation.
Reports of illegal content and abuse are covered by the separate information in the following section. This also applies when such a report is submitted through a general contact form or another contact address. Processing required by law for these reports does not depend on consent.
Reliable Delivery of Form Submissions
Contact enquiries, job applications, GitLab access requests and reports of illegal content use a shared technical intake and delivery service. Required information, prepared emails and any application attachments are secured in access-restricted persistent Redis storage before we acknowledge acceptance. The purpose of each enquiry and its applicable legal basis remain relevant.
For reliable handling, we retain a reference number, receipt and sending times, technical delivery states and checksums used to recognise unchanged retries. Acknowledgements are sent to the contact address provided, where available. Failed deliveries can be retried or manually taken over by responsible staff. General technical operations permissions do not automatically grant access to application documents or abuse reports.
Uploads that have not been submitted are generally removed after 24 hours; active preparation is temporarily protected against premature cleanup. Accepted complete messages are retained while delivery is pending or unresolved. Once handoff to the responsible company mailbox is verified and other delivery jobs have been completed or their outcome documented, technical content is deleted within 24 hours. Minimal technical deduplication data without plaintext contact details, messages or attachments are retained for a further seven days.
Business processing and retention of the enquiry or application in its responsible mailbox are separate. They depend on the purpose, ongoing proceedings and necessary statutory retention or evidentiary obligations. Specific information about DSA/abuse reports appears in the following section.
Reports of Illegal Content and Abuse
You can report suspected illegal content in our hosting services and technical abuse to abuse@awesome-it.de. We process the information needed to assess, handle and respond to a report, together with the related correspondence. This information applies regardless of the contact channel used to submit a report.
- Name and email address of the reporting person or entity, where provided
- Reported URLs, IP addresses or other details identifying the electronic location
- Description, explanation and necessary supporting information or evidence, which may include data relating to affected third parties
- Statements concerning the accuracy and completeness of the report, where provided
- Receipt and processing times, correspondence, decisions and necessary delivery information
Where processing is necessary to comply with our legal obligations, its basis is Article 6 (1) (c) GDPR in conjunction with the applicable provisions of Regulation (EU) 2022/2065 (Digital Services Act, DSA), particularly Articles 16 to 18 DSA. This processing does not require consent.
Where additional processing is necessary to prevent technical abuse or to establish, exercise or defend legal claims, it is based on Article 6 (1) (f) GDPR. Our legitimate interests are protecting our services and their users, preventing abuse and safeguarding our rights. We take the interests and fundamental rights of the individuals concerned into account.
Article 16 (2) DSA generally provides for reports to include a name and email address. These details may be omitted for reports concerning suspected offences referred to in Articles 3 to 7 of Directive 2011/93/EU, including child sexual abuse and sexual exploitation. Without an email address, we cannot send individual questions or notifications by email. We assess incomplete reports on the basis of the available information.
Reports are accessible to the persons responsible for handling them and, where necessary, technical service providers acting on our instructions. Information may be shared with affected customers, legal advisers or competent authorities where necessary to assess a report or enforce measures and where legally permitted. We do not routinely disclose the reporting person’s identity to affected customers. Where Article 18 DSA applies, we provide the relevant information to the competent law enforcement or judicial authorities; in Germany, the Federal Criminal Police Office receives this information as the central office under Section 13 DDG.
We retain reports and related records for as long as necessary to handle them, address required follow-up questions, document our decisions or establish, exercise or defend legal claims. We take ongoing proceedings and statutory retention obligations into account. The data are deleted once the relevant retention purpose no longer applies and the applicable obligations have expired. Technical delivery data that are no longer needed are deleted independently of the retention of case records.
Responsible staff members assess reports and decide on measures. We do not make solely automated decisions within the meaning of Article 22 GDPR in this procedure.
Please provide only information needed to assess your report and do not send passwords or files containing suspected illegal content. We process special categories of personal data or personal data relating to criminal offences only where the additional requirements of Article 9 or Article 10 GDPR, respectively, are met.
Newsletter & Registration
Our website does not offer a newsletter or user registration.
Rights of Data Subjects
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Data Transfers to Third Countries
No transfer of personal data to countries outside the EU takes place.
Changes
We reserve the right to adapt this privacy policy when necessary, for example due to technical changes or new legal requirements.
- Last updated: September 2026