STRATEGY. COMMUNICATIONS. TECHNOLOGY.For B2B SMEs · 20 to 2,000 employees
Legal information

Privacy Policy

English version of the revised German text, dated 4 October 2026. View the German version.

Privacy Policy

Last updated: 4 October 2026

1. Controller

Claas Hansen Marketingberatung
trading under the brand lightparc
Owner: Claas Hansen
Münzplatz 10
56068 Koblenz
Germany

Phone: +49 261 – 287 318 66
Email: service-expert@lightparc.de

2. General information

Personal data is processed only to the extent necessary and on the basis of the applicable statutory provisions.

This Privacy Policy explains the processing of personal data when you visit this website, make enquiries or enter into business relationships with us. Specific projects or separate applications may require supplementary privacy notices. The controller is Claas Hansen, owner of Claas Hansen Marketingberatung, trading as lightparc.

3. Website visits and server logs

When you access this website, the hosting provider automatically processes technical access data. This may include:

  • IP address of the accessing device
  • Date and time of access
  • Pages and files accessed
  • Volume of data transferred and access status
  • Browser type and version
  • Operating system
  • Referrer URL, where transmitted
  • Hostname of the accessing computer

This data is processed to provide the website technically, ensure secure and stable operation, analyse errors and prevent abusive access. The legal basis is Article 6(1)(f) GDPR.

Server log data is stored only for as long as necessary for secure operation. Longer retention may be necessary to investigate a security incident or comply with statutory retention requirements.

4. Contact via the form

A contact form is available on this website. Data entered by the user and data technically necessary for transmission are processed.

This includes, in particular:

  • Name
  • Email address
  • Company
  • Phone number, if provided voluntarily
  • Selected area of interest
  • Description of the situation and desired outcome
  • Acknowledgement of the Privacy Policy
  • Technical submission timestamp
  • Technical information for spam and abuse prevention

The data is processed to review and answer the enquiry personally and, where appropriate, prepare a proposal or a pre-contractual recommendation.

Article 6(1)(b) GDPR is the legal basis where you personally are the prospective contracting party and processing is necessary for pre-contractual steps at your request or contract performance. For contacts acting on behalf of a company or institution, and for general enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is appropriate handling of business enquiries and communications. Acknowledging this policy is not consent to advertising.

Data submitted through the form is made available only to those responsible for handling the enquiry and to processors required for technical purposes.

Enquiries alone are deleted after final handling once no further related communication is expected and no retention duty or specific need to defend legal claims requires continued storage. Contract and accounting records are retained according to the criteria in section 8. Enquiries are not retained indefinitely as a matter of course.

4a. Required information and technical abuse prevention

Required fields are needed to identify and answer your enquiry. There is no general legal obligation to use the form. Without these details, an enquiry cannot be submitted through it; you can alternatively contact us by email or phone. Providing a phone number is voluntary. Please do not submit passwords, payment details or special categories of personal data through the form.

To protect the form, the IP address, timestamps, browser identifier (user agent), input patterns, email domain and message characteristics are checked automatically. Checks include a hidden field, timing, repeated-request limits, email-domain DNS checks and risk-based spam assessment. DNS queries concern the domain, not your message content. No external CAPTCHA is used. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protection against spam, abuse and overload.

For request limits, a pseudonymous identifier derived from the IP address is stored server-side with request timestamps. A one-hour window is evaluated. This is not an automatic deletion deadline: residual technical files may remain until the temporary server directory is cleaned. For forwarded enquiries, the notification email also contains the IP address, browser identifier and spam assessment; the enquiry retention rules apply to these details.

Submissions classified as abusive may be rejected automatically. This does not decide whether a consulting or service contract is concluded. If your enquiry does not arrive, you can request personal review by email or phone.

5. Contact by email or telephone

If you contact us by email or telephone, the personal data you provide is processed to handle your enquiry.

Article 6(1)(b) GDPR applies to enquiries about a contract to which you personally are or may become a party. For general enquiries and communications with company or institutional contacts, Article 6(1)(f) GDPR applies; the legitimate interest is handling and documenting business communications.

6. Hosting and technical provision

Domain management is provided by http.net Internet GmbH.

The website is hosted by Jolt, a company of the Freethought Group. The servers used for this website are located in the United Kingdom. Transfers of personal data to the United Kingdom are covered by an adequacy decision of the European Commission pursuant to Article 45 GDPR.

Data processing agreements pursuant to Article 28 GDPR are in place with the service providers used, where required.

7. Collaboration and exchange platform

For secure document exchange, project organisation and collaboration, the controller may use a self-operated or contractually provided collaboration and exchange platform.

This may involve processing contact details, project data, documents, filenames, access times and technical log data.

Processing takes place for pre-contractual measures and contract performance pursuant to Article 6(1)(b) GDPR and on the basis of the legitimate interest in secure project organisation pursuant to Article 6(1)(f) GDPR.

8. Customer, prospect and business partner data

In connection with pre-contractual measures, proposals, projects, managed services, IT infrastructure and consulting assignments, the controller processes, in particular, master and contact data, communications, proposal, contract and billing data, and project-related information.

Personal data of individuals who are themselves contracting parties is processed under Article 6(1)(b) GDPR where necessary to enter into or perform the contract. Contact persons’ data and additional project, documentation and security data are processed under Article 6(1)(f) GDPR for business relationships, project management, evidence and IT security. Processing required by law is based on Article 6(1)(c) GDPR.

Where lightparc processes personal data solely on a client’s instructions as part of hosting, cloud, support, infrastructure or consulting services, this takes place under a separate data processing agreement pursuant to Article 28 GDPR.

8a. Retention and deletion

Retention depends on the purpose, contract status, specific evidential and legal-defence interests and statutory retention duties. Where applicable, commercial and business correspondence is generally retained for six years, accounting vouchers for eight years, and books or annual accounts for ten years (section 257 HGB and section 147 AO). The statutory period generally starts at the end of the relevant calendar year. Not every enquiry is subject to these periods.

Records needed to pursue or defend specific claims may be kept until the relevant limitation period expires or proceedings conclude. Access and use are restricted to that purpose. Data is deleted once its purpose and applicable retention duties cease. Backup data is overwritten as part of the relevant backup rotation and is not reused for ongoing business operations.

9. Lexware Office

For proposal, contract, invoicing and accounting processes, Lexware Office is used.

This may involve processing names, companies, addresses, email addresses, proposal and contract data, invoice data and payment information.

Processing is based on Article 6(1)(b), Article 6(1)(c) and Article 6(1)(f) GDPR.

A data processing agreement pursuant to Article 28 GDPR is in place with the provider, where required.

10. Cookies and tracking

Page display, language switching, the reference strip and contact-form processing do not use analytics, marketing or tracking cookies. These functions also do not require local storage or session storage. Analytics or advertising services such as Google Analytics, Google Tag Manager, Meta Pixel and LinkedIn Insight Tag are not embedded. Spam prevention operates server-side rather than through a tracking cookie. Any future integration of technologies requiring consent will take place only after prior information and consent under section 25 TDDDG and, where required, the GDPR.

11. External links

This website contains links to external websites, for example LinkedIn or websites of technology and cooperation partners. After an external link is opened, the respective operator is responsible for processing personal data.

12. Recipients and processors

Personal data may be transferred to technical service providers where necessary for hosting, domain management, email communications, cloud operations, project organisation, accounting or delivery of a requested service.

External specialists or cooperation partners receive personal data only where their involvement is necessary to handle an enquiry or carry out an engagement and a data protection basis exists for doing so.

Depending on the agreed scope, recipients may include hosting and cloud providers, data centres, domain registrars, software providers, distributors, manufacturers, technical specialists, payment and accounting service providers, and advisers subject to professional confidentiality obligations.

12a. Transfers outside the European Economic Area

The UK hosting described in section 6 relies on the relevant European Commission adequacy decision under Article 45 GDPR. Transfers to other third countries require the applicable conditions of Articles 44 et seq. GDPR. Where standard contractual clauses or other safeguards are used, data subjects receive the relevant information for that processing; a copy may be requested using the contact details above.

12b. Project-specific analytics, AI and social media monitoring

Where a separate engagement involves processing personal data for analytics, AI applications or social media monitoring, the purpose, allocation of roles, sources, recipients and deletion rules are established for that project. Public availability alone does not remove data protection requirements for public posts. Additional information required under Articles 13 or 14 GDPR is provided for the respective processing. This general website policy does not replace project-specific information.

13. Data security

This website uses SSL/TLS encryption. Appropriate technical and organisational measures are also used to protect personal data against loss, manipulation, unauthorised access and other misuse.

14. Rights of data subjects

Data subjects have, in particular, the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing

Right to object: You may object to processing under Article 6(1)(f) GDPR on grounds relating to your particular situation. We will stop that processing unless we demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims. You may object to processing for direct marketing at any time without giving reasons.

Data subjects also have the right to lodge a complaint with a data protection supervisory authority.

Where processing is based on consent, consent may be withdrawn with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal.

The relevant authority includes:

The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate
Hintere Bleiche 34
55116 Mainz
www.datenschutz.rlp.de

To exercise your rights, contact service-expert@lightparc.de. Rights are subject to their respective statutory conditions. You may lodge a complaint, in particular, with a supervisory authority in your place of habitual residence, workplace or the location of the alleged infringement.

15. Changes to this Privacy Policy

This Privacy Policy is updated where technical, organisational or legal changes make this necessary. The current version published on this website applies.