Privacy Policy

Last updated:

This policy describes what happens to your data when you visit nexilon.de.

Hosting customers are covered by a separate document. What happens to data arising under a hosting contract - account data, billing, server operations - is described in the Hosting Privacy Policy. The present policy covers this website only.

1. Controller

The controller within the meaning of the GDPR is the German entity named in the imprint. For data protection enquiries, a message to the address given there is sufficient.

No data protection officer has been appointed; the conditions of § 38 BDSG are not met.

2. Visiting the website

This website is served by Cloudflare (Cloudflare Pages). On every request, Cloudflare processes technically necessary connection data as a processor:

  • IP address of the requesting device
  • date and time of access
  • requested address and volume of data transferred
  • delivery status code
  • browser and operating system identification transmitted
  • where applicable, the previously visited page (referrer)

Without this processing a website cannot technically be delivered. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in delivering the site and defending against attacks.

We do not operate our own web server and keep no access logs of our own. We have no access to Cloudflare’s raw logs; only aggregated, non-personal statistics are available to us. We can therefore neither inspect nor delete those logs. Their retention is governed by the data processing agreement named below and by Cloudflare’s documentation.

The processing is based on the Cloudflare Customer Data Processing Addendum as amended from time to time.

3. Transfers to the United States

Cloudflare is a company headquartered in the United States. Even where delivery takes place via European data centres, processing by the US parent company cannot be excluded. This concerns delivery of this website (section 2), the contact form’s spam protection (section 5), and its receipt (section 4).

The United States does not provide a level of data protection equivalent to European law; in particular, authorities may under certain conditions access data without a remedy meeting European standards being available.

The transfer rests on the Cloudflare Customer Data Processing Addendum linked above, with the safeguards agreed therein.

4. Contact form

When you submit the form on the contact page, only the fields you have filled in are transmitted:

FieldRequired
Nameyes
Email addressyes
Messageyes
Companyno
Phoneno
Subject (selection)no

The path the data takes, step by step:

  1. Your entries go to a Cloudflare Worker that receives the request. Your IP address is processed in doing so.
  2. The Worker has Cloudflare’s spam protection verify the submission and transmits your IP address for that purpose (section 5).
  3. It then creates a case in our ticket system (Zammad) from your entries. A contact record is created from your email address, or an existing one is matched. The connection to it also runs through Cloudflare; the server itself is not directly reachable from the internet.
  4. Your enquiry is then handled within that ticket system. It runs on a virtual server operated by us at Webdock ApS in the European Union; a data processing agreement is in place with the provider.

The purpose is to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry is directed at a contract, and otherwise Art. 6(1)(f) GDPR.

Processing by the Worker produces technical log entries that may contain your email address and your IP address.

Your enquiry remains in the ticket system for as long as it is needed to handle it and to keep our business relationship traceable. We have not yet set a fixed deletion period for this. You may request erasure at any time (section 10); only statutory retention obligations can stand in the way.

5. Spam protection on the contact form (Cloudflare Turnstile)

On the contact page and its German counterpart - and only there - Cloudflare Turnstile is embedded to fend off automated submissions. This loads a script from challenges.cloudflare.com; Cloudflare processes your IP address along with characteristics of your browser and device to assess whether the input comes from a human. On submission, the verification result together with your IP address is transmitted to Cloudflare a second time for confirmation.

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in preventing abusive submissions. Without such protection, a publicly reachable contact form is not realistically operable.

Turnstile is not loaded on any other page of this website.

6. Audience measurement

Cloudflare Web Analytics

A measurement script is loaded from static.cloudflareinsights.com on every page. It reports to Cloudflare which page was requested, how quickly it loaded, which country the request came from, and the browser and device category. No cookies are set and nothing is stored on or read from your device (verified on 17 August 2026).

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in being able to assess this website’s loading times and reach. For Cloudflare, the statements in sections 2 and 3 apply.

Counterscale

We additionally measure reach using Counterscale. This is not a third-party service: the software runs in our own Cloudflare account, the measurement script is served from our own domain, and the data does not leave our infrastructure. No further recipient is involved; for Cloudflare, sections 2 and 3 apply.

Recorded are the timestamp, the page requested, the referrer, the country of origin, and the browser and device category. No cookies are set and nothing is stored on or read from your device (measured in a browser on 18 August 2026). No recognition takes place - not even within a single day: every page view is counted on its own, and a returning visit cannot be told apart from a first one.

Individual records are deleted automatically after 90 days. Daily totals derived from them without personal reference - such as “this page was requested this many times on this day” - may be kept beyond that.

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in being able to assess this website’s reach.

7. Storage on your device

This website itself sets no cookies. It stores two values in your browser’s local storage, and both only if you use the corresponding function yourself:

KeyContentSet when
nexilon-themelight or darkyou switch the view between light and dark
nexilon-lang-nudge-to-…-dismissed1you dismiss the notice about the other language version

Neither contains personal data, neither is transmitted, and both serve solely to preserve a choice you made for your next visit. Under § 25(2) no. 2 TDDDG no consent is required for this. You can delete the values at any time through your browser settings.

For storage by the audience measurement, see section 6.

In a few places this website links to third-party offerings - for instance Stripe payment pages, the App Store, and product pages. These are ordinary links: no data is transmitted as long as you do not click them. Once you do, the privacy policy of the respective provider applies, over whose processing we have no influence.

9. Recipients

RecipientFor whatRole
Cloudflare, Inc.website delivery, audience measurement, receipt of the contact form, Turnstileprocessor
Webdock ApSvirtual server on which the ticket system runsprocessor

No data is passed on for advertising purposes, and no data is sold.

10. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20).

You also have the right to object (Art. 21 GDPR) where processing rests on a legitimate interest - this concerns sections 2, 5, and 6.

An informal message to the address given in the imprint is sufficient to exercise these rights.

11. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority, in particular the authority of your habitual residence or the one responsible for us.

The authority responsible for us is that of the German state in which we are established - given the Mannheim registry court, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.

12. Changes

This policy will be adapted when the processing described here changes. The version published here, bearing the date given above, is the authoritative one.