Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Privacy information

1. Controller

In short

This company decides on the processing and is your point of contact for anything concerning data protection. An email is enough.

The controller for the processing of your personal data within the meaning of Article 4(7) GDPR is:

lexICT GmbH

Eichenbrink 5
30453 Hannover
Germany
Fax
+49 511 47 55 58 19

We have not appointed a data protection officer. Please address questions about data protection to [email protected].

2. Processing when you visit this website

In short

Your visit generates technical connection data. On our own server it is processed only for delivery and never logged. It also arises at the upstream protection service, where it is analysed to fend off attacks.

When you open our website, your browser automatically sends information to the server hosting it. The connection data technically required for the transfer is processed: your IP address, the date and time of the request, the address requested, the volume of data transferred, the server status message and the identification string sent by your browser with details of browser and operating system.

This connection data arises in two places, and it is treated differently in each.

On our own server it is processed solely for the duration of delivery. We keep no access logs of it and do not store the data afterwards.

At the upstream network service the position is different. It can identify malicious traffic only by analysing the connection data, and it retains that data for a limited time in order to do so. This processing is the purpose of the service, not a side effect; details are in section 2.2. Our statement that no access logs are kept therefore relates to our own server and not to that upstream layer.

In both cases the legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the secure and uninterrupted operation of the website. The data is not evaluated for any other purpose, and in particular not to analyse your behaviour.

2.1 Hosting

In short

The website sits with Hetzner in a data centre in Germany, on our behalf and on our instructions.

The website is operated for us by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in a data centre in Germany. Hetzner processes the data named above solely on our behalf and on our instructions. We have concluded a data processing agreement with Hetzner under Article 28 GDPR.

2.2 Delivery through Cloudflare

In short

Every request passes through Cloudflare first, processed in data centres in the EU. The content of the form is briefly in clear text there as well.

We use the service of Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany, as an upstream network service. All requests to our website first pass through Cloudflare's servers and only then reach our server. Cloudflare filters malicious traffic, defends against denial of service attacks and delivers static content more quickly.

For that purpose Cloudflare processes your IP address and the details of the request and retains them for a limited time in order to recognise recurring attack patterns. We have configured the service so that processing takes place in data centres inside the European Union.

So that Cloudflare can perform this task, the encrypted connection terminates at Cloudflare and is established anew from there. The content of your requests, including the details from the contact form, is therefore present there in clear text for the duration of processing.

The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the security and availability of the website. A data processing agreement under Article 28 GDPR is in place with Cloudflare.

Cloudflare Germany GmbH belongs to Cloudflare, Inc., which is based in the United States. Where data is transferred there, the transfer relies on the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework, under which Cloudflare, Inc. is certified. In addition, the standard contractual clauses of the European Commission have been agreed and apply should the certification lapse. Further details are set out in Cloudflare's privacy policy at cloudflare.com/privacypolicy.

3. Cookies and local storage

In short

Three things can sit on your device, and each only where there is a reason: your choice of colour scheme, if you make one, a marker from Cloudflare, if you pass a security challenge, and your decision about services that need consent, once you have made one. No advertising tracking, no profiling.

3.1 Your choice of colour scheme

The website appears in a light colour scheme. Using the control in the service row at the top you can switch to a dark scheme.

What is stored. So that the choice still applies on your next visit, we store it in your browser's local storage, in localStorage under the key schema. The content is a single word, dark. No name, no identifier, no timestamp and no address.

Where the value goes. Nowhere. It does not leave your device, it is not transmitted to us or to third parties, and it appears in no server log.

When nothing is stored at all. As long as you stay with the light scheme, which is the normal case. The entry is created only when you switch to dark.

Legal basis. For the associated processing, Article 6(1)(f) GDPR. Our legitimate interest lies in not asking you for a setting again on every visit. Storing it on your device is strictly necessary within the meaning of section 25(2) no. 2 TDDDG in order to provide a service you have expressly requested; no consent is required for it.

Duration and deletion. The entry remains until you delete it. You can do so using the same control, by switching back to the light scheme, or through your browser's settings for deleting website data.

3.2 Marker for a passed security challenge

Cloudflare sits in front of the website as an upstream network service, see section 2.2. The service fends off attacks and classifies every request in order to do so. Where it presents a security challenge, it sets a cookie.

What is stored. Only the fact that the challenge was passed. The marker saves you from having to repeat it on every further page.

When this happens. Not routinely, but not only during an ongoing attack either. The service presents the challenge as soon as it considers a request suspicious. That may be a wave of attacks, but equally a single request that strikes it as unusual, for instance from an anonymisation service, over a conspicuous network address or from an unusually configured browser. Which characteristics it judges this by is for the service to determine, and it does not disclose them to us. On an ordinary visit you will as a rule see no challenge. We cannot rule it out.

Legal basis. Storing it is strictly necessary for operation within the meaning of section 25(2) no. 2 TDDDG; no consent is required for it. For the associated processing, Article 6(1)(f) GDPR, with the legitimate interest in fending off attacks. Who Cloudflare is, where processing takes place and what arises in the course of it is set out in section 2.2.

3.3 Your decision about services that need consent

On your first visit we ask you whether we may measure the reach of this website. What is measured is set out in section 4. Where a page carries embedded content, we ask you separately at that point, see section 5.2.

What is stored. Your decision, in a cookie named lexict-einwilligung. The content is the name of the service and whether you agreed or declined. No identifier, no name, no address.

Where the value goes. Nowhere. It is sent to our server with every request, because that is how cookies work, and it is not evaluated there. The decision is applied in the browser.

When nothing is stored at all. As long as you do not decide. Without a decision no service is loaded and the cookie is not created. If you dismiss the question without agreeing, you are not measured. If you load embedded content once only, you do not receive the cookie either.

Legal basis. Storing it is strictly necessary within the meaning of section 25(2) no. 2 TDDDG in order not to ask you for the decision again on every visit. For the associated processing, Article 6(1)(c) GDPR, since consent has to be demonstrable under Article 7(1) GDPR.

Duration and deletion. The cookie expires after 180 days. After that we ask again. You can delete it at any time through your browser's settings, or withdraw your decision using Change consent in the footer.

3.4 No analysis of your behaviour beyond this

Beyond the measurement of reach under section 4 we use no analytics services. There are no counting pixels, no profiling and no disclosure to advertising networks.

4. Measurement of reach

In short

Only with your consent. The software does not run at a provider from the advertising industry but on a server we operate ourselves. No cookie is set for the measurement, and without your consent the script is not executed.

With your consent we measure the reach of this website using Umami. We operate the instance ourselves. No service provider is involved, and no transfer to a third country takes place.

What is recorded. The page visited, the referring page, the country, the screen size as well as the browser and the operating system. From these details and your IP address an identifier is derived that changes daily. The IP address itself is not stored, and no cookie is set for the measurement.

For what purpose. We want to know which topics are being read in order to decide which of them to go into more deeply. Recognising individual people is neither intended nor possible with the details recorded.

Legal basis. Your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Whether section 25(1) TDDDG applies at all to a measurement without a cookie is judged differently by different authors. We obtain consent without deciding that question.

Withdrawal. You can withdraw your consent at any time with effect for the future, using Change consent in the footer. The withdrawal takes effect immediately. Without consent the counting script is not executed; it is present in the document, but in a form the browser does not execute.

Duration and deletion. We keep the details recorded for one year. They are deleted after that. A longer period would add nothing to the question of which topics to go into more deeply.

5. Fonts and third-party content

In short

Fonts and icons come from our own server. A video and the appointment booking come from third parties and load only once you allow it at that point.

5.1 Fonts and icons

All fonts are loaded from our own server. There is no connection to Google Fonts or any comparable service. The icons are inserted when the pages are built and are not loaded afterwards. We embed no maps and no social media buttons.

5.2 Embedded content

In a few places we embed content that comes from another provider. That is videos from YouTube, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and the appointment booking, operated by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

This content does not load by itself. In its place there is a panel asking whether you wish to load it. Only once you answer does a connection to the provider arise, and only then does it receive your IP address and details of your device. With the appointment booking, your entries in the booking form are sent to Microsoft in addition.

You have two options. Load once loads the content for this one visit, and we store nothing for it. On your next visit the question appears again. Always load and remember stores your decision, and the content then loads without asking again.

The legal basis is your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. You can withdraw it at any time with effect for the future. For arranging an appointment the telephone and email remain open to you, and we make no appointment dependent on consent.

A data processing agreement is in place with Microsoft. Where data is transferred to the parent companies in the United States, the transfer relies for both providers on the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework; the standard contractual clauses apply in addition.

6. Mini games and best score of the week

In short

The small games run in your browser. Some of them keep a best score of the week. Your result is only transmitted if you submit it yourself, and it is stored without any identifier.

Some pages carry a small game. It starts only when you click and runs entirely in your browser.

Some of these games keep a best score for the current calendar week. Where they do and a round ends with a result that would beat that score, a button appears. Only a click on it sends the result to our server. Without that click the number does not leave your device. Submitting is voluntary and has no effect whatsoever on your use of the website. The remaining games have neither a best score nor a button for one, and their result does not leave your device under any circumstances.

For the transmission itself your IP address and the usual connection data are processed, as with every visit to this website. They are not stored together with the result. What is stored is the number alone, the game it belongs to and the calendar week. The best score is therefore anonymous, and we cannot trace it back to you.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in an engaging presence and in making a result comparable with others.

The best score is deleted at the end of the calendar week. It is stored on our own server.

7. Processing when you contact us

In short

Three routes lead to us: the form, email and the telephone. What arises on the way is used to answer your request and for nothing else.

7.1 Contact form and call-back request

In short

Your details are sent as an email to our mailbox, not into a database. The protective measures run entirely on our server. The confirmation email does not repeat your text.

Through our contact form we collect your name, your email address and your message, and optionally your company and your telephone number. For the call-back request, name, telephone number and message are the required entries. We also process the language of the page you were on and the time of submission.

The details are processed in order to answer your enquiry. The legal basis is Article 6(1)(b) GDPR where your enquiry is directed at entering into a contract, and otherwise Article 6(1)(f) GDPR; our legitimate interest lies in answering your request.

Your details are not stored in any database of the website. They are transmitted solely as an email to our mailbox. We delete the data once the purpose of the processing has ceased. That is the case at the latest by the end of the following calendar year, unless a statutory retention obligation applies.

Technical protective measures. The form is secured against automated submissions. To that end we check several technical characteristics of the request when it is sent, and we process your IP address in order to limit the number of requests. In addition, your browser solves a small computational task before sending; we use ALTCHA for this.

All checks are purely local processing on our own server. Nothing is loaded from external servers, no data is transferred to third parties, and no cookies are set. ALTCHA too runs entirely with us; the task is generated and verified on our own server. Your IP address is held in memory for no more than fifteen minutes, is not written to any storage medium, and is not transmitted to our mailbox with your message. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in preventing misuse.

The task is sized so that you will not notice it; it merely makes automated bulk submission more expensive. The form therefore requires JavaScript. Without JavaScript you can reach us using the contact details on the same page.

The route your message takes. Every leg of that route is encrypted:

  1. Your browser hands the form over HTTPS to the network service named in section 2.2.
  2. From there the request travels to our server over a connection that is encrypted again.
  3. Our server hands the message to the delivery service named in section 7.3 over an SMTP connection that is encrypted from the outset, with TLS 1.2 or above.
  4. From there it is delivered to our mailbox.
  5. We access that mailbox over encrypted connections only.

Two qualifications belong with this, because “encrypted throughout” would otherwise promise more than the route delivers. The encryption ends at each handover point and begins anew; the network service in section 2.2 and the providers in section 7.3 therefore each see the content in clear text. And on our server the message sits in memory for the moment of processing before it is passed on; it is not written to any storage medium in the process.

The form does not provide end-to-end encryption, where only you and we could read the content. For documents that need that protection, please speak to us and we will agree another route.

After submitting you receive an automatic confirmation at the address you gave. It states that the enquiry arrived and when, but not the text of your message. We deliberately do not send the text back, so that a typing error in the address cannot deliver it to an uninvolved third party. What happens to that confirmation afterwards is no longer in our hands. Whether delivery to your provider is encrypted is decided by their configuration, not ours.

7.2 Email, telephone and fax

In short

The same applies to the direct routes, so only to deal with your request, erased once the purpose has ceased.

If you contact us by one of these routes, we process the details arising in order to deal with your request. The legal bases are Article 6(1)(b) and (f) GDPR. Here too we delete the data once the purpose has ceased, at the latest by the end of the following calendar year, unless a statutory retention obligation applies.

7.3 Delivery and mailboxes

In short

Delivery runs through SMTP2GO inside the European Union, the mailboxes through Microsoft 365. Both act on our behalf, and both see the content in clear text. That is not end to end.

The messages from our forms are sent by SMTP2GO Ltd., 40 Bowen Street, Wellington 6011, New Zealand, through its instance in the European Union located in Amsterdam. SMTP2GO processes the data on our behalf; a data processing agreement under Article 28 GDPR is in place.

Our mailboxes are held with Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft too processes the data on our behalf, on the basis of the Microsoft Data Protection Addendum under Article 28 GDPR. According to Microsoft's commitments for the EU Data Boundary, processing takes place within the European Union.

Where data is transferred to Microsoft Corporation in the United States, the transfer relies on the adequacy decision on the EU-U.S. Data Privacy Framework, under which Microsoft Corporation is certified; the standard contractual clauses apply in addition. Transmission to our mailbox is encrypted in transit. The route through the form does not provide end-to-end encryption.

8. Video conferences and online meetings

In short

We hold meetings over Microsoft Teams on request. We do not record unless everyone involved has agreed beforehand. If you would rather not, we will use the phone or meet you in person.

For meetings we use Microsoft Teams on request. The provider for users in the European Economic Area is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

What data arises. We process the details you need in order to take part and that you supply yourself: your display name, your email address where we invite you, and video, audio and text messages during the meeting. Added to that is technical data about the connection, such as IP address, device and network details, and the start and end of your participation.

Purposes and legal bases. We process this data in order to hold the meeting. The legal basis is Article 6(1)(b) GDPR where the meeting serves to initiate or carry out a contract, and otherwise Article 6(1)(f) GDPR; our legitimate interest lies in coordinating quickly and independently of location.

No recording without agreement. We do not record meetings and produce no automatic transcripts or summaries. Where something else is wanted in an individual case, we obtain the consent of everyone involved beforehand under Article 6(1)(a) GDPR and say so at the start of the meeting. You may withdraw that consent at any time with effect for the future.

Confidentiality. Where we are appointed as your data protection officer, we are bound to secrecy under Article 38(5) GDPR. We have bound Microsoft contractually to confidentiality and chosen the technical options so that content is not disclosed further than necessary. If you would prefer a different route for a meeting, please tell us; the telephone and a meeting at our offices are open at any time.

Processing on our behalf and transfers to third countries. Microsoft processes the data on our behalf on the basis of the Microsoft Data Protection Addendum under Article 28 GDPR. According to Microsoft's commitments for the EU Data Boundary, processing takes place within the European Union. Where data is transferred to Microsoft Corporation in the United States, the transfer relies on the adequacy decision on the EU-U.S. Data Privacy Framework, under which Microsoft Corporation is certified; the standard contractual clauses apply in addition.

Erasure. We delete invitations, participation data and any text messages once the purpose has ceased, at the latest by the end of the following calendar year, unless a statutory retention obligation applies.

Further details from Microsoft are available at microsoft.com/privacystatement.

9. Disclosure of data

In short

Beyond the service providers named above we disclose nothing. Exceptions only with your consent, under a legal obligation, or to defend legal claims.

Beyond the service providers named above, your personal data is not disclosed to third parties. Exceptions may arise where

  • you have given your express consent under Article 6(1)(a) GDPR,
  • disclosure is necessary under Article 6(1)(f) GDPR to establish, exercise or defend legal claims and there is no reason to assume that you have an overriding interest worthy of protection in the data not being disclosed,
  • there is a statutory obligation to disclose under Article 6(1)(c) GDPR,
  • disclosure is legally permissible and necessary under Article 6(1)(b) GDPR for the performance of contractual relationships with you, or
  • disclosure is made to a service provider acting on our behalf and solely on our instructions, selected with care under Article 28(1) GDPR and bound by a data processing agreement under Article 28(3) GDPR.

10. Social media presences

In short

Opening our pages sends nothing to LinkedIn or Instagram. The people pages carry a link to the profile there, and that transfers nothing until you click it. On the platforms themselves their rules apply, not ours.

lexICT maintains presences on LinkedIn and Instagram. Simply opening our pages transfers no data to those platforms. On the people pages, some of our consultants link to their profile there. Such a link is an ordinary link. It transfers nothing until you click it.

Controllership. Where we determine the means and purposes of processing, we process your data as controller. In all other cases the platform determines means and purposes and is itself the controller:

  • LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
  • Instagram: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland

Details of the processing on the platforms, of retention periods and of the cookies used are set out in the providers' privacy policies. The platforms transfer personal data to the United States and rely on the adequacy decision of the European Commission or on standard contractual clauses.

Interactions. If you follow our profiles, comment on or share posts, or write to us there, we process the details arising in order to answer your request and to present our company. The legal basis is Article 6(1)(f) GDPR. Before contacting us through a platform, please consider whether you wish to send those details there or whether another route is more suitable.

Statistics. The platforms provide us with aggregated statistics on reach and interactions. We can draw conclusions about individuals only insofar as you interact with our profiles yourself. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in improving our content and how we communicate.

11. Your rights and right to lodge a complaint

In short

Access, rectification, erasure, restriction, portability and a complaint to the supervisory authority. For all of them an email is enough.

As a data subject you have the right

  • under Article 15 GDPR to obtain information about the personal data we process about you, in particular the purposes, the categories of data and of recipients, the intended retention period, the existence of rights to rectification, erasure, restriction and objection, the right to complain, the origin of the data and the existence of automated decision-making;
  • under Article 16 GDPR to obtain without undue delay the rectification of inaccurate data or the completion of your data;
  • under Article 17 GDPR to obtain the erasure of your data, unless processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
  • under Article 18 GDPR to obtain restriction of processing;
  • under Article 20 GDPR to receive your data in a structured, commonly used and machine-readable format, or to have it transmitted to another controller;
  • under Article 77 GDPR to lodge a complaint with a supervisory authority. As a rule you may address the supervisory authority of your habitual residence, your place of work or our registered office. The authority responsible for our registered office is the State Commissioner for Data Protection of Lower Saxony, Denis Lehmkemper, Prinzenstraße 5, 30159 Hanover, Germany.

An email to [email protected] is sufficient to exercise your rights.

12. Right to withdraw consent

In short

Consent once given can be withdrawn at any time, without giving reasons.

Where we process your personal data on the basis of consent under Article 6(1)(a) GDPR, you may withdraw that consent at any time without giving reasons. We may then no longer continue the processing based on it. The lawfulness of processing carried out up to the withdrawal is unaffected.

The route is Change consent in the footer of every page. Withdrawing is therefore as easy as giving consent, as Article 7(3) sentence 4 GDPR requires.

13. Right to object

In short

You may object to processing we base on legitimate interests, on grounds relating to your particular situation.

Where we process your personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you have the right under Article 21 GDPR to object on grounds relating to your particular situation. Where your objection is directed at direct marketing, the right to object applies without further reasons.

An email to [email protected] is sufficient.

14. Data security

In short

Everything is encrypted in transit, but not from end to end. The protection service and the email providers see content in clear text. Genuinely confidential matters are better discussed in person.

Encrypted transmission. This website is reachable over HTTPS only; a request over an unencrypted connection is redirected to the encrypted one. Your browser shows this with the padlock symbol in the address bar. TLS versions 1.2 and 1.3 are used; older versions are switched off.

The connection consists of two legs. Between your browser and the network service named in section 2.2, the certificate issued there applies. Between that service and our server there is a separate, automatically renewed certificate; this second leg is encrypted as well, and the authenticity of our server is verified in the process.

Sending the form. We hand the message from the contact form to the delivery service over an SMTP connection that is encrypted from the outset, likewise with TLS version 1.2 or above.

We deliberately do not state a key length. It is negotiated between browser and server and changes with both; a figure here would be wrong before long.

That encryption secures the transport, not the entire path from end to end. The network service named in section 2.2 and the providers named in section 7.3 each process the content in clear text. Please bear that in mind before describing confidential detail to us through the form.

Beyond that we take appropriate technical and organisational measures to protect your data against loss, destruction, alteration and unauthorised access. We adapt these measures continuously to the state of the art.

15. Currency and amendment of this privacy information

In short

Dated August 2026. Any changes appear on this page.

This privacy information is dated August 2026. As our website develops or legal requirements change, it may become necessary to amend it. The current version is available on this page at any time.