Privacy policy
1. Controller
Feinwerktechnik-Bender
Owner: Julian Bender
Bergstraße 5
67806 Rockenhausen
Germany
Email: info@feinwerktechnik-bender.de
2. Hosting
This website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. When the website is accessed, technically necessary access data is processed. This may include the IP address, date and time of access, requested files, browser and operating system information and referrer information. Processing serves the secure and reliable provision of the website and is based on Art. 6(1)(f) GDPR.
STRATO processes personal data as a processor in connection with its hosting services. Where required, a data processing agreement pursuant to Art. 28 GDPR is in place.
3. Contact and project requests
If you use the contact or project form, the data you enter and any project files voluntarily submitted are transmitted to Feinwerktechnik-Bender and processed to handle your request. This may include your name, company, email address, telephone number, requested deadline, quantity, application, message and uploaded files.
The legal basis is Art. 6(1)(b) GDPR where the request serves to initiate or perform a contract. Other business enquiries are processed on the basis of Art. 6(1)(f) GDPR. Data is deleted once it is no longer required for processing and no statutory retention obligations apply.
4. File uploads
Technical files and, depending on the request type, documents or images can be submitted through the project form. Uploaded files are stored for processing in an area of the STRATO webspace that is technically separated from the publicly accessible website directory. They cannot be accessed through a freely available web address.
Please submit only data necessary to process the request and remove unnecessary personal or confidential information. Project files are deleted when they are no longer required for processing the request or any resulting business relationship and no statutory or contractual reason for further storage applies.
5. Email communication
When contacting us by email, the information provided is processed to handle the request and possible follow-up questions. The legal basis depends on the content of the communication and is generally Art. 6(1)(b) or (f) GDPR.
6. First-party website statistics, cookies and external services
For internal reach measurement we use our own server-side statistics to estimate unique browsers/devices. Repeated page views from the same recognised browser are not counted repeatedly as visitors within the selected reporting period. Technical request data such as the IP address, User-Agent, language and, where supplied by the browser, platform indicators are used only momentarily to create a pseudonymous HMAC identifier with a random server-side key. The raw IP address and User-Agent are not stored by this statistics function. No additional analytics cookie or Local Storage entry is used for this counter.
The pseudonymous identifier is used only to display aggregated visitor figures for today and the previous 7, 30 and 365 days. The result is an approximation because changing IP addresses, browser updates or privacy relays may cause a device to be recognised as new. Processing is based on our legitimate interest in evaluating and improving the use of our business website in a data-minimising manner (Art. 6(1)(f) GDPR).
7. Customer portal and security measures
Technically necessary session cookies are used for the protected customer portal. They are used exclusively for login, access control and security of the customer and administration areas. Session cookies are marked Secure and HttpOnly and use a SameSite restriction.
Cloudflare Turnstile is used on login and code-request pages to defend against automated access and abuse attempts. This establishes a connection to Cloudflare and processes technical information from the browser or device required for the security check. Turnstile does not receive the content of your project request or uploaded project files. Server-side access restrictions and rate limits are also used.
8. Customer account and login codes
The customer portal is not freely registered; it is only available to email addresses associated with an actual project request. A time-limited one-time code is sent to the stored email address for login. Login codes are stored only as cryptographic hashes and become invalid after use or expiry.
9. Retention period
Personal data is stored only for as long as necessary for the respective purpose. Statutory commercial and tax retention obligations remain unaffected.
10. Your rights
Subject to the applicable legal requirements, you have in particular the right of access, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with a data protection supervisory authority.
11. Version
Version: August 2026