SafeBoxMap

Data protection

Privacy Policy

This privacy policy explains how personal data is processed when this website is provided, when requests are handled, and when privacy-friendly analytics are used.

1. Controller

The controller responsible for data processing on this website is:

Lukas Osterheider
Bahnhofstraße 63
58452 Witten
Germany
[email protected]
+49 (0) 162 - 151 1807

2. General Information on Data Processing

We process personal data only to the extent necessary to provide this website, process requests, fulfil contractual or legal obligations, or safeguard our legitimate interests.

Processing is carried out in particular on the basis of Art. 6(1)(b) GDPR where it is necessary for the implementation of pre-contractual measures or for the performance of a contract, on the basis of Art. 6(1)(c) GDPR where statutory retention or documentation obligations exist, and on the basis of Art. 6(1)(f) GDPR where we have a legitimate interest in the secure, stable, and user-friendly operation of our web offering.

3. Server Log Files

When you access our website, the web server automatically processes information transmitted by your browser. This may include, in particular:

  • IP address
  • Date and time of access
  • Page or file accessed
  • Referrer URL
  • Browser used
  • Operating system
  • Amount of data transferred
  • HTTP status code
  • Requesting internet service provider

The processing of this data is technically necessary in order to deliver the website, ensure the stability and security of the offering, and detect misuse or technical disruptions.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and error-free provision of our website.

This data is not combined with other data sources. Log files are deleted after 30 days unless longer storage is required in an individual case to investigate security incidents.

4. Contacting Us

If you contact us by email or by other means, we process the personal data you transmit, in particular your name, email address, the content of the request, and any further information voluntarily provided.

Processing is carried out to handle your request. The legal basis is Art. 6(1)(b) GDPR if the request relates to a contract or pre-contractual measures. In all other cases, processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in properly responding to requests.

The data is deleted as soon as it is no longer required for processing the request, unless statutory retention obligations prevent deletion.

5. Contract and Business Data

If a contractual relationship is established, performed, or amended, we process the personal data required for this purpose. This may include, in particular, names, contact details, contract data, billing data, and communication content.

The legal basis is Art. 6(1)(b) GDPR. Where statutory retention obligations exist, processing is additionally carried out on the basis of Art. 6(1)(c) GDPR.

We store documents relevant under commercial and tax law in accordance with the statutory retention periods.

6. Web Analytics with Umami Analytics

We use Umami Analytics for privacy-friendly reach measurement and to improve our content. Umami is operated by us ourselves or on our own server infrastructure.

Umami is used on this website without cookies. In particular, page views, click events, referrers, URLs accessed, browser used, operating system, device type, screen size, language setting, approximate location such as country or region, and the time of access are recorded. According to our understanding, the IP address is not stored permanently but is processed at most briefly to derive approximate location information.

We use this information exclusively in aggregated form to understand which content is used, how visitors interact with the website, identify technical problems, and improve our offering. Cross-website tracking, profiling for advertising purposes, or disclosure to advertising networks does not take place.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in privacy-friendly reach measurement and the improvement of our web offering.

Analytics data collected with Umami is deleted or aggregated after 12 months.

Further information can be found in the Umami documentation.

7. Recipients of Personal Data

Personal data is disclosed to third parties only where this is necessary to provide the website, process your request, perform a contract, comply with legal obligations, or on the basis of our legitimate interests.

Recipients may include, in particular:

  • Hosting providers
  • IT service providers
  • Tax or legal advisors, where necessary
  • Authorities, where a legal obligation exists
  • Providers of Umami Analytics, where applicable, if Umami is not self-hosted

Where service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

8. Data Transfers to Third Countries

Personal data is transferred to countries outside the European Union or the European Economic Area only where there is a suitable legal basis for doing so, in particular an adequacy decision by the European Commission or appropriate safeguards pursuant to Art. 46 GDPR.

9. Storage Period

We store personal data only for as long as is necessary for the respective purposes. Statutory retention periods remain unaffected. Once the respective purpose no longer applies or statutory periods have expired, the data is deleted unless further storage is required and legally permissible in an individual case.

10. Your Rights

In accordance with the GDPR, you have the right to information about the data stored about you, to rectification of inaccurate data, to erasure, to restriction of processing, to data portability, and to object to certain processing operations.

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority. In particular, the competent authority may be the data protection supervisory authority of your usual place of residence, your workplace, or the place of the alleged infringement.

11. Security of Data Transmission

We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, and alteration.

Please note that data transmission over the internet, in particular communication by email, may have security vulnerabilities. Complete protection against access by third parties is not possible.

12. Objection to Advertising Emails

We object to the use of contact details published as part of the statutory imprint obligation for sending advertising and informational materials that have not been expressly requested. We reserve the right to take legal action in the event of unsolicited advertising information being sent, for example through spam emails.

Last updated: June 17, 2026