Wirtarin

Privacy

Privacy Policy

Last updated: 16 August 2026

This Privacy Policy describes the processing of personal data when visitors use wirtarin.com or contact Wirtarin.

1. Controller

Controller

Wiktor Karbowski / Wirtarin

sole proprietorship

Address

Sauerbruchstraße 11

67550 Worms

Rhineland-Palatinate, Germany

Contact

w.karbowski@wirtarin.com

+49 176 62426029

2. Hosting

The website can be used without registration and without actively providing personal details. Technically necessary access data is still generated when pages are requested and is described below.

The website is hosted by Vercel Inc.. When the website is accessed, Vercel processes technical access data, in particular IP address, date and time of access, requested URL or resource, HTTP status, transferred data volume, referrer and user-agent data, and technical security or diagnostic data.

The purpose of processing is to deliver the website and keep it secure and stable. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the secure and reliable operation of the website.

Vercel may process personal data outside the EU/EEA, in particular in the United States. Vercel states that safeguards include certification under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Further information is available in Vercel's Privacy Notice and Data Processing Addendum.

3. Contact Enquiries

When someone contacts Wirtarin by form, email or telephone, Wirtarin processes the information required to handle the enquiry. The form processes name, optional company, business email address, optional telephone number, enquiry category, message and language setting.

The required form fields are needed to classify and respond to the enquiry. Without them, the enquiry cannot be handled through the form. There is no statutory obligation to provide this information.

Where the enquiry concerns entering into or preparing a contract or project, processing is based on Article 6(1)(b) GDPR. General business enquiries and related communication are processed on the basis of Article 6(1)(f) GDPR; the legitimate interest is responding to and documenting business communication.

4. Abuse Prevention

To check and prevent abusive form use, Wirtarin temporarily processes technical request data, in particular IP address and time of the request.

The purpose is to protect the contact form and website against spam, excessive requests and other abuse. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the security and functionality of the website.

5. Email Infrastructure

Form and email enquiries are transmitted to and processed in the Wirtarin mailbox at IONOS SE. IONOS processes in particular email addresses, message content, subject or category information, email metadata and technical data required for delivery, security and troubleshooting.

The purpose is the delivery, receipt and handling of business communication. Depending on the content of the enquiry, the legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.

6. Retention

Ordinary enquiries that do not lead to a business relationship are generally deleted no later than six months after the matter has been conclusively handled, unless continued retention is necessary to establish, exercise or defend legal claims, comply with legal obligations or for another lawful reason.

If communication in a specific case becomes part of a business relationship or of records that are subject to statutory commercial or tax retention obligations, the applicable statutory periods apply only to those records. Where statutory retention is required, the legal basis is Article 6(1)(c) GDPR; where retention is required to protect legitimate interests, the legal basis is Article 6(1)(f) GDPR.

Technical access data in hosting and provider-side email logs are retained according to the relevant provider and product settings. Temporary data for abuse prevention is processed only for the period required for that purpose.

7. Data Subject Rights and Right to Lodge a Complaint

Data subjects have the GDPR rights of access, rectification, erasure, restriction of processing, data portability and objection to processing based on Article 6(1)(f) GDPR, subject to the statutory requirements.

Data subjects also have the right to lodge a complaint with a data protection supervisory authority. For Rhineland-Palatinate, the competent authority is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz.