Schäfer +49 151 8374 6798

Datenschutzerklärung

Privacy, in two threads.

Every point below is written twice: once the way we would explain it across a table, and once in the formal terms the law asks for. Read whichever thread suits you; they say the same thing.

Valid from 7 October 2026

01Who we are

Schäfer GmbH in Achern decides what happens to your data, and answers for it.

Controller within the meaning of Art. 4(7) GDPR and the German Federal Data Protection Act (BDSG):

Schäfer GmbH, Oststr. 17, 77855 Achern, Germany. Phone +49 151 8374 6798.

This policy covers visitors to this website and anyone who contacts us via the brief form, by phone or by email.

02What we gather

What you type into the form, what we need for a project, and the bare technical traces any website leaves.

  • Enquiries: name, company, phone, email (optional), selected service and message text.
  • Clients: contact persons, project correspondence, contracts and invoices.
  • Visits: IP address, date and time, page requested, browser and referrer, logged by our hosting provider.

The knitting loom on the home page runs entirely in your browser. Your pattern is never transmitted.

03Why that is allowed

Because you asked us something, because we have a contract, because tax law says so, or because the site has to stay safe.

  • Enquiries and proposals: Art. 6(1)(b) GDPR, and Art. 6(1)(a) for consent given via the form.
  • Project delivery: Art. 6(1)(b) GDPR.
  • Accounting and tax obligations: Art. 6(1)(c) GDPR.
  • Operation and security of the site: Art. 6(1)(f) GDPR, our legitimate interest in a stable service protected from attacks.

Providing data is voluntary, but without it we cannot respond.

04Who else touches it

Only the few services we need to run the business, and only on our instructions. Nobody buys it.

We do not sell personal data or use it for third-party advertising. Processors acting under Art. 28 GDPR agreements:

  • hosting and content delivery, including attack protection;
  • the service that receives form submissions and forwards them;
  • email and project-management tools used by our team;
  • our tax adviser; public authorities where disclosure is legally required.

05Outside the EU

Some tools have servers abroad. When data goes there, it travels with legal protection attached.

Transfers to countries outside the European Economic Area rely on a European Commission adequacy decision or on Standard Contractual Clauses under Art. 46 GDPR, with additional technical measures where appropriate.

06Cookies

Only the ones the site cannot work without. No trackers, no ads.

We use only strictly necessary storage, which does not require consent under § 25(2) of the Telecommunications Digital Services Data Protection Act (TDDDG). Any optional tool added later will stay disabled until you consent, and this page will be updated beforehand.

07How long

A year at most for an enquiry that goes nowhere. Longer for clients, because German tax law requires it.

  • Enquiries without a resulting project: erased no later than 12 months after the last contact.
  • Client data: for the duration of the project, then for the statutory retention periods, generally 6 years for business letters (§ 257 HGB) and up to 10 years for accounting documents (§ 147 AO).
  • Server logs: retained briefly and not merged with other data.

08What you can demand

See it, fix it, delete it, pause it, take it with you, object, or change your mind. Just ask.

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing based on legitimate interest (Art. 21)
  • Withdrawal of consent at any time, with effect for the future (Art. 7(3))

Requests go to the contact details in point 01.

09If you are unhappy

You can always go over our heads to a data protection authority.

You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Stuttgart.

10Keeping it safe

Encrypted connections, few people with access, updated systems. Not perfect, because nothing online is.

Technical and organisational measures under Art. 32 GDPR include TLS encryption, role-based access to enquiries and regular updates. No method of transmission over the internet is completely secure.

11Children

This site is for businesses, not for kids.

We do not knowingly process personal data of persons under 16.

12Updates

If anything changes, this page changes first.

We amend this policy when our processing or the legal framework changes. The date at the top identifies the current version.