Privacy Policy
We take the protection of your personal data seriously. This privacy policy informs you about which data is processed when you visit this website, for what purpose and on what legal basis. The relevant law is the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for data processing on this website is:
weooo GmbH
Nagelpötchen 19
44269 Dortmund, Germany
Phone: +49 1516 1463283
Email: hello@weooo.de
For questions about data protection, you can reach us using the contact details above. A data protection officer is not required by law and has not been appointed.
2. Hosting
We host this website with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Germany. When you access our website, Hetzner, as a technical service provider acting on our behalf, processes various data that your browser transmits (see “Server log files”).
The legal basis is our legitimate interest in the secure and efficient provision of our online services (Art. 6(1)(f) GDPR). A data processing agreement (Art. 28 GDPR) is in place with Hetzner, ensuring data-protection-compliant processing.
3. Server log files
When this website is accessed, the server automatically collects and stores information in so-called server log files, which your browser transmits automatically. These are generally:
- the anonymised or shortened IP address,
- the date and time of access,
- the page or file accessed,
- the browser and operating system used,
- the previously visited page (referrer), if transmitted.
This data is not merged with other data sources and serves exclusively the technical operation, security and stability of the website. The legal basis is Art. 6(1)(f) GDPR. The log files are stored for as long as they are technically required and then deleted.
4. Self-hosted fonts
This website uses exclusively self-hosted fonts (Montserrat as WOFF2). The fonts are loaded directly from our server. No connection to third-party servers — such as Google Fonts — is established, and no personal data is transmitted to third parties in the process.
5. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” in your browser’s address bar and the padlock symbol. When encryption is active, the data you transmit to us cannot be read by third parties.
6. Cookies and consent
Cookies are small text files stored on your device. Technically necessary cookies are required for the operation of the website; in particular, this includes a cookie that stores your choice in the cookie banner (named cc_cookie) so that you do not have to decide again on every visit. No consent is required for these technically necessary processes; the legal basis is Art. 6(1)(f) GDPR.
All non-essential services — in particular the web analytics described below — are loaded exclusively after your explicit consent. On your first visit, a consent banner appears in which you can enable or decline individual categories. Before consent is given, no analytics script is loaded and no associated cookies are set. You can withdraw or change your consent at any time with effect for the future by clicking “Cookie settings” in the footer.
7. Web analytics with Google Analytics 4
If you consent, we use Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. GA4 helps us evaluate the use of our website statistically and in pseudonymised form (e.g. pages visited, approximate origin, devices used) in order to improve our offering.
We use GA4 together with Google Consent Mode v2. This means: before your consent, storage for analytics purposes is disabled by default (analytics_storage: denied) and no Google Analytics script is loaded. Only once you consent to the “Analytics” category is the script loaded, your consent transmitted to Google (granted) and cookies (including _ga, _ga_*) set. IP anonymisation is enabled.
The legal basis for this processing is your consent pursuant to Art. 6(1)(a) GDPR, and Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act) for the storage of, or access to, information on your device.
Data transfer to the USA: When using GA4, personal data may be transferred to Google servers, including in the USA. Google LLC is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023); standard contractual clauses additionally apply. Nevertheless, a level of data protection equivalent to that within the EU cannot be guaranteed in all cases; in particular, access by US authorities cannot be entirely ruled out.
Retention period: The information stored in the GA4 cookies has a limited lifetime (the _ga cookie by default up to two years). Data collected at user and event level is automatically deleted by Google in accordance with the retention period we have selected.
Withdrawal/opt-out: You can withdraw your consent at any time via “Cookie settings” in the footer. After withdrawal, no further analytics is carried out, storage is set to denied and the associated cookies are deleted. For more information, see Google’s privacy policy: https://policies.google.com/privacy.
8. Contact form
If you send us an enquiry via the contact form, we process the data you provide in order to handle your enquiry. We collect:
- name,
- email address,
- mobile/phone number (optional),
- your message.
Processing takes place on the basis of Art. 6(1)(b) GDPR insofar as your enquiry is aimed at concluding or performing a contract, and otherwise on the basis of our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR) and your consent (Art. 6(1)(a) GDPR), which you give via the data protection checkbox.
Your message is delivered to a weooo email account via an encrypted SMTP connection. To protect against automated misuse (spam), we use an invisible honeypot field and a time-token check; a captcha service such as Google reCAPTCHA is not used, so no data is transmitted to third parties for this purpose.
We store your enquiry and the associated data until processing is complete and no statutory retention obligations conflict with deletion. You can object to the processing at any time and request deletion; an objection does not affect the lawfulness of the processing carried out up to that point.
9. Contact via WhatsApp Business
On our contact page we optionally offer you a link to get in touch via WhatsApp. Only when you actively click this link is a connection to WhatsApp established and data transmitted to the operator of WhatsApp, WhatsApp Ireland Limited or Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). For details on which data is processed, please refer to the WhatsApp Business privacy notice: https://www.whatsapp.com/legal/business-policy/.
Data is transmitted to WhatsApp/Meta only if you use this communication channel on your own initiative. The legal basis is your consent through active use (Art. 6(1)(a) GDPR) and our legitimate interest in providing an easy way to get in touch (Art. 6(1)(f) GDPR). If you do not wish to transmit any data to WhatsApp/Meta, please use the contact form, email or phone.
10. Your rights as a data subject
With regard to your personal data, you have the following rights:
- right of access (Art. 15 GDPR),
- right to rectification (Art. 16 GDPR),
- right to erasure (Art. 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to object to processing (Art. 21 GDPR),
- right to withdraw a given consent with effect for the future (Art. 7(3) GDPR).
To exercise your rights, an informal message to the contact details listed under “Controller” is sufficient.
11. Right to lodge a complaint with a supervisory authority
Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. The supervisory authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW)
Kavalleriestr. 2–4, 40213 Düsseldorf, Germany
https://www.ldi.nrw.de/
12. Currency of this privacy policy
This privacy policy reflects the current status. As our website develops further, or due to changed legal or regulatory requirements, it may become necessary to amend this policy. You can access the current version at any time on this page.