Legal
Privacy Policy
Last updated: August 2026
This is a translation of the German privacy policy, provided for convenience. In the event of any discrepancy, the German version prevails.
1. Controller
The controller for the processing of personal data within the meaning of Art. 4(7) GDPR is:
RawsBau GmbHWilly-Brandt-Platz 2
12529 Schönefeld
Deutschland
Represented by its managing director: Ercan Çelik
Email: info@rawsbau.de
Data protection enquiries: datenschutz@rawsbau.de
2. Data protection officer
Whether we are required to appoint a data protection officer is being reviewed internally. The relevant provisions are § 38 BDSG (a threshold of, as a rule, 20 persons constantly engaged in the automated processing of personal data) and Art. 37(1)(b) and (c) GDPR (large-scale regular monitoring, or processing of special categories of data). Should an appointment be required, or should one be made voluntarily, the person responsible will be named here. Until then you can reach us with data protection matters using the contact details above.
3. Competent supervisory authority
The supervisory authority competent for the processing of personal data in connection with this website is the data protection authority of the federal state in which the controller has its registered office. You have the right to lodge a complaint with the competent supervisory authority at any time (Art. 77 GDPR). The German Federal Commissioner for Data Protection and Freedom of Information (BfDI) publishes an overview of the German supervisory authorities.
4. Terms and legal bases
This privacy policy uses the terms defined in Art. 4 GDPR. Personal data means any information relating to an identified or identifiable natural person.
We process personal data on the legal bases set out in Art. 6 GDPR, in particular:
- Art. 6(1)(a) GDPR — consent
- Art. 6(1)(b) GDPR — performance of a contract and pre-contractual measures
- Art. 6(1)(c) GDPR — compliance with a legal obligation
- Art. 6(1)(f) GDPR — legitimate interests, following a balancing test
For access to information stored in terminal equipment (cookies, local storage, fingerprinting), § 25 TDDDG applies in addition: beyond what is strictly technically necessary (§ 25(2) TDDDG), your prior consent is required.
5. Hosting and server log files
This website is delivered via the infrastructure of Cloudflare, Inc. (registered office: USA). Cloudflare handles domain name resolution, the delivery of all content as an upstream intermediary server, and the mitigation of automated access. In doing so, Cloudflare processes the technical connection data of every page request, in particular the IP address. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the secure, stable and attack-resistant delivery of the website. For the transfer to the USA, see section 15.
Every request automatically records technical information in server log files, in particular the IP address, date and time, the URL requested, the referrer URL and a browser or device identifier.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the secure and stable delivery of the website and in defending against attacks.
Origin server
Behind the upstream intermediary server, the website runs on a rented server operated by the following provider:
Hetzner Online GmbHIndustriestr. 25
91710 Gunzenhausen
Germany
The server location is in Germany. Hosting itself involves no transfer of personal data to a third country. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the reliable provision of the website.
Retention period for access logs
Access logs arising on the origin server are deleted after seven days, unless they are needed longer in an individual case to investigate or defend against a specific security incident. In that case the data concerned is stored until the incident has been conclusively resolved. The website application itself keeps no access log of its own. The provider’s retention periods apply to log data arising at Cloudflare.
6. Cookies and consent management
Cookies and comparable storage techniques are small data items placed in your browser. We distinguish between:
- Strictly necessary cookies (Art. 6(1)(f) GDPR, § 25(2) TDDDG) — required to operate the website (session, basket, language choice, security functions).
- Consent-based cookies (Art. 6(1)(a) GDPR, § 25(1) TDDDG) — analytics, marketing and third-party cookies; these are set only after your active consent.
6.1 Consent management
This website uses strictly necessary cookies only. Consent-based cookies within the meaning of § 25(1) TDDDG are not used; no analytics, marketing or audience measurement services are embedded. A consent banner is therefore neither required nor in use. Should consent-based services be embedded in future, a consent tool will be set up beforehand, allowing you to make your choices and change them at any time with effect for the future.
Independently of this, you can delete cookies or restrict their storage at any time via your browser settings. In that case your language choice will be requested again on every visit.
6.2 Cookies in use
NEXT_LOCALE
- Provider
- This website (first party)
- Category
- Strictly necessary
- Purpose
- Stores the language version you have chosen (German or English) so that the website appears in the same language on subsequent visits
- Duration
- 1 year
- Consent required?
- No — § 25(2) no. 2 TDDDG
cf_clearance
- Provider
- Cloudflare, Inc. (registered office: USA)
- Category
- Strictly necessary (security)
- Purpose
- Stores the result of an automated check for automated access so that the check does not have to be repeated on subsequent requests; serves to defend against abusive access
- Duration
- 1 year
- Consent required?
- No — § 25(2) no. 2 TDDDG
7. Web analytics
No web analytics take place on this website. No analytics, statistics or audience measurement services are embedded; no usage profiles are created and no visitor identifiers are assigned. Server-side or cookie-free audience measurement is not used either.
8. Contact forms
A contact form is available on this website. If you use it, we process the details you enter there:
- name (mandatory)
- company (mandatory)
- email address (mandatory)
- telephone number (optional)
- the content of your message (mandatory)
The purpose of the processing is to handle and answer your enquiry and to conduct any follow-up communication. The legal basis is Art. 6(1)(b) GDPR where your enquiry is directed at concluding or performing a contract, and otherwise Art. 6(1)(f) GDPR; our legitimate interest lies in answering the enquiries addressed to us. Providing the data marked as mandatory is necessary in order to handle your enquiry; without it we cannot reply to you.
Before submitting, you confirm via a checkbox that you have taken note of this privacy policy. That confirmation documents our information obligations under Art. 13 GDPR; it is not consent within the meaning of Art. 6(1)(a) GDPR and does not constitute a separate legal basis for the processing.
Abuse prevention
When the form is submitted, the IP address of your device is processed temporarily in order to limit how often enquiries can be submitted from the same IP address within a given period. The IP address is not linked to the form data, is not stored in the email sent, and is processed exclusively transiently in memory. It is deleted at the latest when the server process next restarts. The legal basis is Art. 6(1)(f) GDPR.
Email delivery provider
We use the following provider for the technical delivery of messages submitted via the form:
Plus Five Five, Inc., trading as Resend2261 Market Street #5039
San Francisco, CA 94114
USA
The content of your message and the contact details you provide are transmitted to the provider so that the message can be delivered to our email mailbox. The IP address processed for abuse prevention is not transmitted with it. The website does not store the form data permanently in a database of its own.
A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. As the provider is established outside the EU and the EEA, section 15 applies to the transfer.
Retention period for enquiries
Your enquiry and the associated communication are deleted as soon as they are no longer required to achieve the purpose, and at the latest six months after your enquiry has been conclusively handled. Commercial and tax law retention obligations remain unaffected; if the contact leads to a contractual relationship, the retention period follows the statutory periods applicable to it.
9. Newsletter
Not applicable — no processing of this kind. We do not send a newsletter and offer no newsletter sign-up.
10. Appointment booking
Not applicable — no processing of this kind. Online appointment booking is not offered; no external booking or scheduling service is embedded.
11. Webinars and online training
Not applicable — no processing of this kind. No webinars, online training or comparable events are offered or arranged via this website.
12. Job applications
Not applicable — no processing of this kind. No application procedure is offered via this website; there is no application form and no facility for uploading application documents.
13. Social media profiles
Not applicable — no processing of this kind. No social media plugins, buttons or embeds are integrated into this website, and no social media profiles are linked. Accordingly, opening the website involves no transmission to operators of social networks.
14. Processors
We engage the following processors within the meaning of Art. 28 GDPR. Data processing agreements pursuant to Art. 28 GDPR are concluded with these processors; the controller documents the status of each agreement:
Cloudflare, Inc.
- Registered office
- USA
- Purpose of processing
- Domain name resolution, delivery of the website via an upstream intermediary server, mitigation of automated and abusive access, obfuscation of email addresses embedded in the source code
Hetzner Online GmbH
- Registered office
- Germany
- Purpose of processing
- Operation of the origin server on which the website runs, including the access logs arising there
Plus Five Five, Inc. (Resend)
- Registered office
- USA
- Purpose of processing
- Technical delivery of messages submitted via the contact form to our email mailbox
Further processors will be added with the next update of this privacy policy, once confirmed by the controller.
15. Transfers to third countries
Where personal data is transferred to countries outside the EU/EEA (see the overview of processors in section 14), we base the transfer on:
- the Standard Contractual Clauses (SCC) under Implementing Decision (EU) 2021/914 of the European Commission, where no adequacy decision is available;
- the adequacy decision on the EU-US Data Privacy Framework of 10 July 2023, where the recipient is certified accordingly;
- supplementary technical and organisational measures (in particular transport encryption, pseudonymisation, access control) where necessary.
A copy of the safeguards applied in each case can be requested using the contact details given in section 1.
16. Data security (measures under Art. 32 GDPR)
We take technical and organisational measures under Art. 32 GDPR to protect personal data against unauthorised access, loss and manipulation. These include in particular:
- transport encryption (HTTPS/TLS) for all data transmissions over the internet;
- an access and role concept for internal systems, including multi-factor authentication;
- regular security updates of the software and plugins in use;
- a backup concept with encrypted storage and defined recovery objectives;
- an obligation of confidentiality on staff and regular awareness training;
- procedures for detecting, reporting and remedying security incidents (Art. 33, 34 GDPR).
These measures are reviewed regularly and adapted to the state of the art.
17. Rights of the data subject
You have the following rights against us in respect of the personal data relating to you:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object (Art. 21 GDPR)
- right to withdraw consent given (Art. 7(3) GDPR) — the lawfulness of processing carried out up to the point of withdrawal remains unaffected
- right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
An informal message to the contact details given in section 1 is sufficient to exercise your rights.
18. Changes to this privacy policy
We adapt this privacy policy when actual processing activities or the legal framework change. The version currently in force is available on this page.