AnvaCode AnvaCodeDigital for businesses
  • Solutions
  • Preise
    • Online-AbosMonatlich · ab 19 €
  • Industries
  • Why us
  • Process
  • Contact
Client login
AnvaCode AnvaCode
  • Online-Abos
  • Solutions
  • Industries
  • Why us
  • Process
  • Contact
info@anvacode.de +49 (0) 221 96267727 Client login Send inquiry
Home / Privacy
GDPR · Art. 13 & 14

Privacy Policy

Last updated · May 2026

This translation is for informational purposes only. The German version is legally binding.
Contents
  • 1. Introduction
  • 2. Data Controller
  • 3. Data categories
  • 4. Processing purposes
  • 5. Legal bases
  • 6. Hosting (Hetzner)
  • 7. Server logs
  • 8. Cookies
  • 9. Contact form
  • 10. Third-party services
  • 11. Retention period
  • 12. Your rights
  • 13. Right to lodge a complaint
  • 14. Right to object
  • 15. Security
  • 16. Changes

1. Introduction

We are pleased about your visit to anvacode.de. The protection of your personal data is a central concern for us. In this privacy policy, we inform you comprehensively about the nature, scope and purpose of the collection and use of personal data pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR) and supplementary German regulations (BDSG).

Personal data is all information that relates to an identified or identifiable natural person — e.g. name, email address, IP address, telephone number.

2. Data Controller within the meaning of the GDPR

The data controller responsible for the processing of personal data on this website is:

CompanyAnvaCode
Managing DirectorGünay Turgut
AddressVochemer Str. 5, 50969 Köln, Deutschland
Phone+49 221 96267728 · +49 221 96267727
Emaildatenschutz@anvacode.de

For data protection enquiries, please contact our data protection address directly: datenschutz@anvacode.de

3. What data we process

Depending on the context, we process the following categories of personal data:

  • Master data — name, address, company, role
  • Contact data — telephone number, email address
  • Content data — texts, inquiries from contact forms
  • Contract data — subject of the contract, term, conditions
  • Usage data — pages visited, time spent, click paths (anonymised)
  • Meta / communication data — IP address (truncated), user agent, referrer URL

4. For what purposes

We process personal data for the following purposes:

  • Provision of this website (technically necessary)
  • Answering contact inquiries via the form or by email
  • Handling of contractual relationships (offer, order, invoice)
  • Fulfilment of statutory retention obligations (e.g. § 147 AO, § 257 HGB)
  • Security and stability of the website (protection against attacks)

5. Legal bases

The processing of personal data takes place on the basis of the following provisions of the GDPR:

Art. GDPRProcessing reasonApplication
Art. 6 Abs. 1 lit. aConsentNewsletter, cookies (optional)
Art. 6 Abs. 1 lit. bContract / pre-contractual measuresInquiry, offer, contract
Art. 6 Abs. 1 lit. cLegal obligationRetention obligations
Art. 6 Abs. 1 lit. fLegitimate interestsWebsite security, statistics

6. Hosting at Hetzner (Germany)

This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (Hetzner privacy policy). The servers are located in the data centres Falkenstein and Nuremberg — exclusively in Germany.

Important: There is no data transfer to third countries outside the EU/EEA. Hetzner is ISO 27001-certified. We have concluded a data processing agreement (DPA) with Hetzner pursuant to Art. 28 GDPR.

7. Server log files

Each time this website is accessed, information is automatically transmitted from the browser to our server and temporarily stored in log files:

  • IP address (anonymised after 7 days)
  • date and time of the request
  • URL accessed
  • HTTP status code
  • browser type and version (user agent)
  • referring URL (referrer)

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a technically error-free and secure website). Retention period: max. 30 days. This data is not merged with other data sources.

8. Cookies, localStorage & consent

On this website we use technically necessary and consent-requiring cookies and storage entries. Before setting consent-requiring cookies, we ask for your consent via a banner (Google Consent Mode v2, default: all tracking storage denied).

Technically necessary storage entries

NameTypePurposeRetention
ac_sessionCookieSession management (login)Session
anvacode_consent_v1localStorageStorage of your consent decision12 months

Legal basis: § 25 (2) no. 2 TTDSG (technically required); Art. 6 (1) (f) GDPR.

Consent-requiring cookies (only after agreement)

The following cookies are only set if you select „Accept all“ in the cookie banner. If you refuse, or before consent, these cookies are not loaded.

NameProviderPurposeRetention
_gcl_auGoogle Ireland Ltd.Google Ads Conversion Linker90 days
_gcl_awGoogle Ireland Ltd.Google Ads click tracking90 days
_gcl_dcGoogle Ireland Ltd.Google Ads Conversion Tracking90 days

Legal basis: § 25 (1) TTDSG (consent); Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by clicking „Cookie settings“ in the footer or by deleting the entries in your browser settings.

9. Contact form & email

If you send us an inquiry via the contact form or by email (info@anvacode.de), your details from the form, including the contact data you provide there, will be stored by us for processing the inquiry and in the event of follow-up questions.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in answering inquiries). Retention period: until the inquiry is completed plus 12 months. In case of an order: statutory retention periods (6/10 years pursuant to HGB/AO).

10. Third-party services used

Google Fonts

This website uses Google Fonts (Geist) for the consistent display of fonts. When the website is accessed, your browser loads the required fonts into the browser cache in order to display texts correctly. In doing so, your IP address is transmitted to Google servers in the USA.

Legal basis: Art. 6 (1) (f) GDPR. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (privacy policy). Transfer to the USA takes place on the basis of the EU Standard Contractual Clauses.

Google Ads & conversion tracking

We use Google Ads (the advertising programme of Google Ireland Limited) to display online ads. If you reach our website via one of our ads, Google sets a conversion tracking cookie on your device. This allows us to measure whether ad clicks have led to inquiries, calls or other interactions. Only anonymised statistics are collected — no identification of your person takes place.

Tracking is implemented via the Google tag AW-18163593902 and is realised within the framework of Google Consent Mode v2. Before your consent, no personal data is transmitted to Google; all storage options (ad_storage, ad_user_data, ad_personalization, analytics_storage) are set to denied by default.

Legal basis: Art. 6 (1) (a) GDPR or § 25 (1) TTDSG (consent). Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing may also be carried out by Google LLC in the USA; the transfer is based on the EU Standard Contractual Clauses. Google LLC is certified under the EU-US Data Privacy Framework (dataprivacyframework.gov). Retention period: up to 90 days (conversion cookies).

Revocation: You can revoke your consent at any time with effect for the future by clicking in the footer and selecting „Only necessary“. Further information: Google privacy policy · Google ad settings.

Three.js / CDN libraries

We load JavaScript libraries (e.g. Three.js for 3D rendering) via content delivery networks. These providers receive your IP address in order to deliver the files. Legal basis: Art. 6 (1) (f) GDPR.

Upon engagement: Stripe, fiskaly, SMS provider

As soon as you engage us as a client and actively use our platform, further service providers come into play, with whom a DPA is in place in each case:

  • Stripe Payments Europe Ltd. (Ireland) — payment processing. Stripe privacy
  • fiskaly GmbH (Austria) — cloud TSE for cash register modules. fiskaly privacy
  • seven.io GmbH (Germany) — SMS dispatch. seven.io privacy
  • Hetzner Online GmbH (Germany) — hosting of application servers

Which services are actually used in your case depends on the modules booked and is regulated contractually.

11. Retention period

We only store personal data for as long as is necessary for the respective purposes or as required by statutory retention obligations:

  • Server logs: max. 30 days
  • Inquiries without business relationship: 12 months after completion
  • Contract data: contract duration + 10 years (§ 257 HGB, § 147 AO)
  • Invoice / accounting data: 10 years (§ 147 AO)
  • Newsletter data: until consent is revoked

12. Your rights as a data subject

You have the following rights vis-à-vis us at any time:

RightContent
Art. 15 DSGVOInformation about the data stored about your person
Art. 16 DSGVORectification of incorrect data
Art. 17 DSGVOErasure of your data („right to be forgotten")
Art. 18 DSGVORestriction of processing
Art. 20 DSGVOData portability (export as CSV/JSON)
Art. 21 DSGVOObjection to processing
Art. 7 Abs. 3 DSGVORevocation of a granted consent

To exercise these rights, an informal message to datenschutz@anvacode.de is sufficient. Processing is free of charge and takes place within 30 days.

13. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. The supervisory authority responsible for us is:

AuthorityState Commissioner for Data Protection and Freedom of Information NRW
AddressKavalleriestr. 2–4, 40213 Düsseldorf
Phone+49 211 38424-0
Webwww.ldi.nrw.de

14. Right to object (Art. 21 GDPR)

Insofar as the processing of your data takes place on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object at any time to the processing for reasons arising from your particular situation. We will then no longer process the personal data, unless we can demonstrate compelling legitimate grounds for the processing.

15. Technical and organisational security

We take appropriate technical and organisational measures to protect your data:

  • Transport encryption: TLS 1.3 (HTTPS) for all connections
  • Server location: exclusively Germany (Hetzner Falkenstein/Nuremberg)
  • Encryption of sensitive fields: AES-256 for IBAN, patient data, personal protection orders
  • Access restriction: two-factor authentication for all internal accesses
  • Data minimisation: we collect only the data necessary for the respective purpose
  • Regular updates: security patches within 24–72 h
  • Backup & recovery: daily encrypted backups, 30 days retention

16. Changes to this privacy policy

We reserve the right to adapt this privacy policy so that it always meets the current legal requirements or to implement changes to our services. The new privacy policy will then apply to your next visit. The current version is always available at https://anvacode.de/datenschutz.

As of: May 2026 · Sources: GDPR, BDSG, TTDSG, TMG · Questions: datenschutz@anvacode.de

AnvaCode AnvaCode

Digital solutions for local businesses in Germany. Tailor-made, fair, personal.

Industries

  • Gastronomie / Food
  • Gesundheit / Medizin
  • Beauty / Wellness
  • Tourismus / Hotellerie
  • All 16 industries →

Modules

  • Bestell-Dashboard
  • Termin-Buchung
  • Webseite & SEO
  • SMS-Marketing
  • All modules →

Company

  • Why us
  • Process
  • Contact
  • Glossary
  • Legal Notice
  • Privacy
  • Terms
© 2026 AnvaCode · Vochemer Str. 5, 50969 Cologne
Legal Notice Privacy Terms