Privacy Policy
The protection of your personal data is important to us. Here is all relevant information about data processing on this website.
Last updated: 20 July 2026
1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to identify you personally. Detailed information on data protection can be found in the Privacy Policy set out below.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. The operator's contact details can be found in the section “Controller” of this Privacy Policy.
How do we collect your data?
Some data is collected when you provide it to us. This may include, for example, information you enter into a contact form.
Other data is collected automatically or after you have given consent when you visit the website. This primarily includes technical data, such as your internet browser, operating system or the time at which a page is accessed. This data is collected automatically as soon as you access this website.
How do we use your data?
Some data is collected to ensure the secure and technically correct provision of the website. Optional analytics and marketing cookies, as well as external media, are disabled by default. Analytics and marketing cookies are not currently used. The dynamic ProvenExpert rating seal is loaded as external media only after you have given consent. Where contracts are initiated through the website, we also process the information submitted in order to handle quotations and other service enquiries.
What rights do you have regarding your data?
You have the right to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the rectification or erasure of this data. Where you have given consent to data processing, you may withdraw that consent at any time with effect for the future. Under certain circumstances, you also have the right to request restriction of the processing of your personal data. You further have the right to lodge a complaint with a competent supervisory authority.
You may contact us at any time regarding these rights or any other questions concerning data protection.
2. Hosting
We host the content of our website with the following provider:
External hosting
This website is hosted externally. Personal data collected through this website may be stored on the hosting provider's servers. This may include, in particular, IP addresses, contact enquiries, metadata and communication data, contract data, contact details, names, website-access data and other data generated through the use of a website.
External hosting is used for the performance of contracts with prospective and existing customers under Art. 6(1)(b) GDPR and on the basis of our legitimate interest in the secure, fast and efficient provision of our online services by a professional provider under Art. 6(1)(f) GDPR. Where consent is requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information in the user's terminal equipment, for example device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.
Our hosting provider processes your data only to the extent necessary to fulfil its contractual obligations and follows our instructions regarding this data.
We use the following hosting provider:
HOSTINGER INTERNATIONAL LIMITED
61 Lordou Vironos str.
6023 Larnaca
Cyprus
Processing on behalf of the controller
We have concluded a data processing agreement with the provider for the use of the service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.
3. General information and mandatory disclosures
Data protection
We take the protection of your personal data seriously. We treat your personal data confidentially and in accordance with the applicable data protection laws and this Privacy Policy.
When you use this website, various items of personal data are processed. Personal data is information that can be used to identify you personally. This Privacy Policy explains what data we collect, how we use it and the purposes for which it is processed.
Please note that data transmission over the internet, including communication by email, may be subject to security vulnerabilities. Complete protection of data against access by third parties cannot be guaranteed.
Controller
The controller responsible for data processing on this website is:
Oday Almustafa
trading under the business name SecurBit
Ringstraße 141
04209 Leipzig
Germany
Telephone: 0341 98989011
Email: datenschutz@securbit.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data, such as names or email addresses.
Retention periods
Unless a more specific retention period is stated in this Privacy Policy, your personal data will remain with us until the purpose for which it was processed no longer applies. If you submit a valid request for erasure or withdraw consent to data processing, your data will be erased unless we have other legally permissible grounds for retaining it, such as statutory retention obligations under tax or commercial law. In that case, the data will be erased once those grounds cease to apply.
General information on the legal bases for processing on this website
Where you have given consent to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or, where special categories of personal data under Art. 9(1) GDPR are processed, on the basis of Art. 9(2)(a) GDPR. Where explicit consent has been given for the transfer of personal data to third countries, processing may additionally be based on Art. 49(1)(a) GDPR. Where you have consented to the storage of cookies or access to information in your terminal equipment, such as through device fingerprinting, processing is additionally based on Section 25(1) TDDDG. Consent may be withdrawn at any time.
Where processing is necessary for the performance of a contract or to take steps at your request before entering into a contract, we process your data on the basis of Art. 6(1)(b) GDPR. Where processing is necessary for compliance with a legal obligation, it is based on Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interests under Art. 6(1)(f) GDPR. The legal basis applicable in each individual case is described in the relevant sections of this Privacy Policy.
Recipients of personal data
In the course of our business activities, we work with various external parties. This may require the transfer of personal data to external recipients. We transfer personal data only where this is necessary for the performance of a contract, compliance with a legal obligation, the pursuit of a legitimate interest or where another legal basis permits the transfer.
Where service providers process personal data on our behalf, they are engaged in accordance with Art. 28 GDPR. Where two or more parties jointly determine the purposes and means of processing, an arrangement under Art. 26 GDPR is concluded where required.
International data transfers
Some of the service providers we use may process personal data outside the European Union or the European Economic Area. Such transfers take place only where the statutory requirements are met. Depending on the recipient, we rely in particular on an adequacy decision under Art. 45 GDPR, appropriate safeguards under Art. 46 GDPR, including the European Commission's Standard Contractual Clauses, or, in legally permitted exceptional cases, Art. 49 GDPR.
Where a recipient in the United States is certified under the EU-US Data Privacy Framework, the relevant adequacy decision may be used as the transfer mechanism for data covered by that certification. Further information on the transfer mechanisms used in individual cases is provided in the sections describing the relevant services.
Withdrawal of consent
Many processing activities are possible only with your express consent. You may withdraw consent at any time. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to object to processing in specific situations and to direct marketing under Art. 21 GDPR
Where processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data. This also applies to profiling based on those provisions. The legal basis on which a particular processing activity is based is stated in this Privacy Policy.
If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.
Where your personal data is processed for direct-marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. This also applies to profiling to the extent that it is related to direct marketing. If you object, your personal data will no longer be used for direct-marketing purposes.
Right to lodge a complaint with a supervisory authority
In the event of an infringement of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. This right is without prejudice to any other administrative or judicial remedy.
The supervisory authority particularly competent for the registered office of our company is:
Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden
Germany
Telephone: +49 351 85471-101
Email: post@sdtb.sachsen.de
Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or in performance of a contract in a commonly used, machine-readable format. Where you request direct transmission of the data to another controller, this will be carried out only where technically feasible.
Right of access, rectification and erasure
Within the framework of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin and recipients, and the purpose of processing. You may also have the right to request rectification or erasure of this data. You may contact us at any time regarding these rights or other questions concerning personal data.
Right to restriction of processing
You have the right to request restriction of the processing of your personal data. You may contact us at any time to exercise this right. The right to restriction applies in particular in the following cases:
- Where you contest the accuracy of personal data stored by us, we generally require time to verify its accuracy. During the verification period, you have the right to request restriction of processing.
- Where the processing of your personal data is or was unlawful, you may request restriction of processing instead of erasure.
- Where we no longer require your personal data for processing purposes but you need it for the establishment, exercise or defence of legal claims, you may request restriction instead of erasure.
- Where you have objected under Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. Until it has been determined whose interests prevail, you have the right to request restriction of processing.
Where processing has been restricted, the data may, apart from storage, be processed only with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
TLS encryption
This website uses TLS encryption to protect confidential content, in particular enquiries submitted through the contact form, during transmission. An encrypted connection can generally be recognised by `https://` and the lock symbol in the browser's address bar.
Where TLS encryption is active, data transmitted during the connection is protected against unauthorised access in accordance with the state of the art. However, complete protection against all risks associated with internet data transmission cannot be guaranteed.
Objection to unsolicited advertising emails
The use of contact details published in connection with statutory legal-notice obligations for the purpose of sending unsolicited advertising or informational material is expressly prohibited. We reserve the right to take legal action in the event of unsolicited promotional communications, including spam emails.
4. Data processing on this website
Cookies and similar technologies
Our website uses cookies and similar technologies. Cookies are small files that may be stored on your terminal equipment. Comparable technologies may store information on your terminal equipment or access information already stored there.
Our Cookie Settings distinguish between the following categories:
Necessary Cookies are required for the basic operation, security and provision of website functions expressly requested by the user. They are always active and cannot be disabled through the consent banner. Where information is stored on or accessed from terminal equipment, this is based on Section 25(2) no. 2 TDDDG. The associated processing of personal data is based, depending on the purpose, in particular on Art. 6(1)(b) or (f) GDPR. Our legitimate interest lies in the secure, stable and technically correct operation of the website.
Analytics Cookies are used to evaluate website usage. They are disabled by default and are not currently used. If analytics services are introduced in the future, they will be activated only after your express consent. The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
Marketing Cookies may be used for advertising, remarketing or external tracking. They are disabled by default and are not currently used. If corresponding services are introduced in the future, they will be activated only after your express consent. The legal basis is Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
External Media allows content from external providers to be loaded. This category is disabled by default. The dynamic ProvenExpert rating seal is currently provided through this category. The rating seal is loaded only after you activate the “External Media” category or select the “Load ProvenExpert” button and thereby consent to loading the external content. Without your consent, no connection is established to ProvenExpert's servers.
Where information is stored on or accessed from your terminal equipment, the legal basis is, where applicable, Section 25(1) TDDDG. The associated processing of personal data is based on Art. 6(1)(a) GDPR.
In the consent banner, you can save your selection for Analytics Cookies, Marketing Cookies and External Media, accept all optional categories, or reject all optional categories. You may withdraw or change your consent at any time with effect for the future through the Cookie Settings or privacy settings provided on the website.
You may also configure your browser to inform you when cookies are set, permit cookies only in individual cases, or delete cookies automatically when the browser is closed. Disabling necessary cookies through browser settings may impair the functionality of the website.
Server log files
The hosting provider automatically collects and stores information in server log files transmitted by your browser when you access the website. This may include, in particular:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing terminal equipment
- date and time of the server request
- IP address
- page or resource accessed
- amount of data transferred and access status
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and technically correct provision of the website, error analysis and protection against attacks and misuse.
Server log files are retained only for as long as necessary for these purposes. Longer retention takes place only where required to investigate a security incident, comply with a legal obligation, or establish, exercise or defend legal claims. The data is generally not combined with other data sources unless this is necessary to investigate a specific security incident.
Contact form
When you contact us through the contact form, we process the information you enter, including your contact details, in order to handle your enquiry and respond to any follow-up questions. The enquiry is transmitted to `info@securbit.de` and processed through Microsoft 365 and Exchange Online.
Processing is based on Art. 6(1)(b) GDPR where the enquiry relates to steps taken at your request before entering into a contract or to the performance of a contract. In all other cases, processing is based on our legitimate interest in the efficient handling of incoming enquiries under Art. 6(1)(f) GDPR. Where express consent is obtained, processing is based on Art. 6(1)(a) GDPR.
Data is disclosed to service providers or other recipients only where this is necessary to handle your enquiry, where we are legally required to do so, or where another legal basis permits the disclosure. Where service providers process personal data on our behalf, they are engaged in accordance with Art. 28 GDPR.
The information identified as mandatory fields is required in order for us to handle your enquiry properly. Without this information, we may be unable to process your enquiry or may be able to do so only to a limited extent. Any additional information is provided voluntarily.
The data is erased once your enquiry has been fully resolved, unless statutory retention obligations, contractual requirements or other lawful grounds require further storage. A valid request for erasure or the withdrawal of consent remains unaffected.
Enquiries by email or telephone
When you contact us by email or telephone, we process your enquiry and the associated personal data, in particular your name, contact details and the content of the communication, in order to handle your request.
Processing is based on Art. 6(1)(b) GDPR where the communication relates to steps taken at your request before entering into a contract or to the performance of a contract. In all other cases, processing is based on our legitimate interest in efficient business communication under Art. 6(1)(f) GDPR. Where express consent is obtained, processing is based on Art. 6(1)(a) GDPR.
Data is disclosed to service providers or other recipients only where this is necessary to handle your enquiry, where we are legally required to do so, or where another legal basis permits the disclosure. Where service providers process personal data on our behalf, they are engaged in accordance with Art. 28 GDPR.
The data is erased once your request has been fully handled, unless statutory retention obligations, contractual requirements or other lawful grounds require further storage.
Business communication through Microsoft 365 and Exchange Online
We use Microsoft 365 and Exchange Online to process our business email communications, including enquiries submitted through the contact form to `info@securbit.de`.
The provider for customers in the European Economic Area is generally:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
D18 P521
Ireland
The following data may be processed in connection with the service:
- sender and recipient data
- email addresses
- subject lines
- communication content
- date, time and delivery information
- IP addresses
- technical log and diagnostic data
- transmitted attachments
Processing is based on Art. 6(1)(b) GDPR where the communication relates to steps taken at your request before entering into a contract or to the performance of a contract. In all other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in secure, reliable and efficient business communication. Where consent is obtained, processing is based on Art. 6(1)(a) GDPR.
Microsoft processes customer data under the contractual terms applicable to Microsoft 365 and the Microsoft Products and Services Data Protection Addendum. Where Microsoft processes personal data on our behalf, the processing is carried out in accordance with Art. 28 GDPR.
Microsoft may process data outside the European Economic Area. Where required, such transfers are based on an adequacy decision under Art. 45 GDPR or appropriate safeguards under Art. 46 GDPR, including the European Commission's Standard Contractual Clauses.
The data is erased once it is no longer required to handle the relevant enquiry or for further business communication, unless statutory retention obligations or other legitimate grounds require longer storage. Communications relevant under contract, tax or commercial law may be retained for longer in accordance with statutory retention obligations.
Further information can be found in the Microsoft Privacy Statement and Microsoft Trust Center.
5. Processing of customer and contract data
We process personal data relating to prospective customers, customers and contractual partners where this is necessary to initiate, establish, structure, perform or amend a contractual relationship. This may include, in particular:
- identification and contact data
- company and organisational data
- communication content
- information concerning project or support requirements
- quotation, order and billing data
Processing is based on Art. 6(1)(b) GDPR where it is necessary to take steps at your request before entering into a contract or for the performance of a contract. Where statutory retention and documentation obligations apply, processing is additionally based on Art. 6(1)(c) GDPR. In individual cases, processing may be based on Art. 6(1)(f) GDPR, in particular for orderly customer communication, IT security, prevention of misuse, and the establishment, exercise or defence of legal claims.
The provision of data required for pre-contractual steps and contract performance is necessary in order to prepare quotations, enter into contracts and provide the agreed services. Without this data, a contractual relationship may not be established or performed.
The data is erased once it is no longer required for the above purposes and no statutory retention obligations or other legal grounds prevent erasure.
6. Consent management for optional services
Through our consent banner, you can choose between Necessary Cookies and the optional categories Analytics Cookies, Marketing Cookies and External Media.
Necessary Cookies are always active. Analytics Cookies, Marketing Cookies and External Media are disabled by default and are activated only after your express consent. Analytics and Marketing Cookies are not currently used. The dynamic ProvenExpert rating seal is currently available under the External Media category.
You may enable external ProvenExpert content either by activating the “External Media” category in the Cookie Settings or by selecting the “Load ProvenExpert” button. Without your consent, the rating seal is not loaded and no connection is established to ProvenExpert's servers.
Where information is stored on or accessed from your terminal equipment, the legal basis is, where applicable, Section 25(1) TDDDG. The associated processing of personal data is based on Art. 6(1)(a) GDPR.
A technically necessary record of your consent choice is stored in order to respect and document your selection. This storage is based on Section 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. Our legitimate interest lies in complying with and demonstrating your privacy choice.
The consent record is stored for the duration of the relevant selection and thereafter only for as long as necessary to comply with statutory accountability and evidentiary obligations or to defend against possible legal claims. It is then erased unless statutory requirements justify longer storage.
You may withdraw or change your consent at any time with effect for the future through the permanent “Cookie Settings” link provided in the footer.
7. ProvenExpert rating seal
We embed a dynamic rating seal provided by ProvenExpert on our website.
The provider is:
Expert Systems AG
Quedlinburger Straße 1
10589 Berlin
Germany
The rating seal displays current information from our publicly accessible ProvenExpert profile, in particular the overall rating and other rating information. The displayed content is loaded directly from ProvenExpert and may be updated automatically.
When the rating seal is loaded, a connection is established to ProvenExpert's servers. ProvenExpert may process, in particular:
- your IP address
- browser and device information
- the page accessed
- the referrer URL
- date and time of access
Depending on the technical implementation, ProvenExpert may also store information on your terminal equipment or access information already stored there.
The rating seal is loaded as optional External Media only after you activate the “External Media” category in the Cookie Settings or select the “Load ProvenExpert” button and thereby give your express consent. Without consent, the rating seal is not loaded and no connection is established to ProvenExpert's servers.
Where information is stored on or accessed from your terminal equipment, the legal basis is Section 25(1) TDDDG. The associated processing of personal data is based on Art. 6(1)(a) GDPR.
You may withdraw or change your consent at any time with effect for the future through the “Cookie Settings” link provided in the footer.
When you select the rating seal, you will be redirected to our publicly accessible ProvenExpert profile. From that point onward, the further processing of personal data is governed by ProvenExpert's privacy policy.
The retention period for data processed by ProvenExpert under its own responsibility is determined by ProvenExpert's privacy policy. We retain the record of your consent in accordance with the criteria described in the section on consent management.
Further information can be found in the ProvenExpert Privacy Policy.
8. Audio and video conferences with Microsoft Teams
We use Microsoft Teams for online meetings, consultations and communication with prospective customers, customers, business partners and staff.
The provider for customers in the European Economic Area is generally:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
D18 P521
Ireland
Depending on the functions used, the following data may be processed:
- name and contact details
- account and authentication data
- meeting title, meeting ID and other metadata
- IP address
- device, operating-system and diagnostic data
- chat messages
- audio and video data
- shared-screen content
- files and other content shared during the meeting
You generally decide whether to activate your camera and microphone, unless the requirements of a particular meeting provide otherwise.
Meetings are not recorded without prior clear notice and an appropriate legal basis. Where consent is required for a recording, it is obtained before the recording begins.
Processing is based on Art. 6(1)(b) GDPR where the meeting is necessary to take steps at your request before entering into a contract or for the performance of a contract. In all other cases, processing is based on our legitimate interest in efficient and location-independent communication under Art. 6(1)(f) GDPR. Where consent is obtained, processing is based on Art. 6(1)(a) GDPR.
Microsoft processes customer data under the contractual terms applicable to Microsoft 365 and the Microsoft Products and Services Data Protection Addendum. Where Microsoft processes personal data on our behalf, the processing is carried out in accordance with Art. 28 GDPR. Microsoft may act as an independent controller for certain business-operation, security or billing purposes of its own.
Microsoft may process data outside the European Economic Area. Where required, such transfers are based on an adequacy decision under Art. 45 GDPR or appropriate safeguards under Art. 46 GDPR, including the European Commission's Standard Contractual Clauses.
The data is erased once it is no longer required for the conduct and follow-up of the meeting and no statutory retention obligations, contractual requirements or other legitimate grounds require further storage. Chat messages, files and other content are subject to the retention rules configured in our Microsoft 365 environment. Content relevant under contract or commercial law may be retained for longer in accordance with statutory retention obligations.
Further information can be found in the Microsoft Privacy Statement and the Microsoft Trust Center.
9. Remote maintenance and remote support with TeamViewer
We may use TeamViewer to provide technical support and remote-maintenance services.
The provider is:
TeamViewer Germany GmbH
Bahnhofsplatz 2
73033 Göppingen
Germany
A remote-support session is generally started only after prior coordination and through an active connection established by the customer or with the customer's express authorisation.
Depending on the functions used, the following data may be processed:
- connection, session and device identifiers, including the TeamViewer ID
- IP address, MAC address and device-related system information
- operating-system, diagnostic and log data
- date, time and duration of the session
- account, authentication, authorisation and licence information
- chat and support content
- visible screen content
- files and other content expressly shared or transferred
- technical error, security and crash information
Permanent unattended access is configured only where expressly agreed, necessary for the agreed service and protected by appropriate technical and organisational measures. Session content is not recorded without prior clear notice and an appropriate legal basis. Access is limited to authorised persons and to the extent necessary to provide the agreed support service.
Processing is based on Art. 6(1)(b) GDPR where remote support is necessary to take steps at your request before entering into a contract or for the performance of a contract. In all other cases, processing is based on our legitimate interest in secure and efficient technical support under Art. 6(1)(f) GDPR. Where consent is required, processing is based on Art. 6(1)(a) GDPR.
Where TeamViewer processes personal data on our behalf, processing is governed by the applicable Data Processing Agreement and Art. 28 GDPR. TeamViewer may act as an independent controller for certain purposes of its own, in particular product, security, licensing or billing purposes.
TeamViewer and its subprocessors may process data outside the European Economic Area. Where required, such transfers are based on an adequacy decision under Art. 45 GDPR or appropriate safeguards under Art. 46 GDPR, including the European Commission's Standard Contractual Clauses.
Session, connection and log data is retained only for as long as necessary to provide and document the support service, maintain IT security, carry out billing, or establish, exercise or defend legal claims. Longer retention takes place only where required by statutory retention obligations or other legal grounds.
Further information can be found in the TeamViewer Privacy and Cookies Policy.

