Privacy Policy
Last updated: 15 July 2026The protection of personal data matters to me. In line with Art. 13 GDPR, this policy explains which data I collect when you visit www.buengener-software.de, for what purpose and on what legal basis. It applies regardless of the chosen language version (German/English) and to all sub-pages of this domain.1. Controller
Controller within the meaning of Art. 4 No. 7 GDPR:David BüngenerBüngener Software — Security Architect · Backend & Embedded
c/o POSTFLEX PFX-403-328
Emsdettener Straße 10
48268 Greven
GermanyPhone: +49 160 93126091
Email: info@buengener-software.deA data protection officer is not legally required given the size of the business. The contact address above is responsible for all data-protection matters.
2. General information on data processing
Personal data is only processed to the extent necessary to provide the website, its functions and my services, or where you have given your explicit consent. Depending on the processing, the legal basis is Art. 6(1)(a) (consent), (b) (contract/pre-contractual), (c) (legal obligation) or (f) (legitimate interest) GDPR.Data is only stored for as long as it is required for the respective purposes and is then deleted, unless statutory retention obligations (e.g. under commercial or tax law, typically 6–10 years) apply.3. Server log files
When you access the website, your browser transmits technically necessary data that the server records in what are known as log files:· IP address of the requesting device· date and time of access
· requested URL and HTTP status code
· volume of data transferred
· referrer URL (referring page)
· user agent (browser, operating system, version)This data is technically necessary to deliver the page and to ensure system security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation). Log files are deleted or anonymised after 14 days at the latest.
4. Cookies
This website uses cookies — small text files stored in your browser — only to the extent strictly necessary. A cookie consent banner obtains your consent for all non-essential categories.Strictly necessary cookies
· cc-consent — stores your choice from the cookie banner (functional, analytics: on/off). Lifetime: 12 months. Attributes: SameSite=Lax, plus Secure over HTTPS.· NEXT_LOCALE — stores the selected language version (German/English), set by the next-intl framework. Lifetime: 1 year (SameSite=Lax).
· theme (localStorage) — stores your chosen colour-mode preference (light/dark/system). Remains in browser storage until manually deleted. No server-side access.The legal basis for these cookies is Sec. 25(2) No. 2 TDDDG (technically necessary) or Art. 6(1)(f) GDPR. No consent is required for them.
Functional and analytics cookies
No functional or consent-requiring cookies and no analytics, tracking or marketing cookies are currently used. Should this change, the relevant category will be activated in the cookie banner and processing will only take place after your explicit consent (Art. 6(1)(a) GDPR). Optionally subscribing to the newsletter is not a cookie consent; it is dealt with exclusively in Section 7.5. Contact forms
If you send me a message via a form on this website, the data you enter (name, email address, and where applicable company, project timeframe and the description of your request) is transmitted to an email address operated by me. The purpose is to process your enquiry and, where applicable, to initiate a contractual relationship.The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (answering general enquiries). Enquiries that do not lead to a contract are generally deleted no later than 6 months after the correspondence has ended. If a contract is initiated or concluded, the commercial and tax retention periods apply (typically 6–10 years); the data is deleted once these have expired.The forms include server-side spam and rate-limiting protection (honeypot, minimum input time, IP-based limiting). The IP address is processed briefly in memory only and is not stored permanently. Legal basis: Art. 6(1)(f) GDPR (protection against misuse).6. Appointment booking (Proton Calendar)
To arrange initial calls I use the booking service Proton Calendar (Proton AG, Switzerland). Clicking “Book appointment” opens the booking page at Proton. From that point on, Proton processes the data you enter there (including name, email and any further details in the booking form) under its own responsibility.Switzerland is covered by an adequacy decision of the EU Commission (pursuant to Art. 45 GDPR), so a data transfer is generally permissible. Details on data processing at Proton are available at proton.me/legal/privacy. Legal basis for the transfer: Art. 6(1)(b) GDPR (pre-contractual measure at your request).7. Newsletter (Brevo)
You can optionally subscribe to my newsletter. For sending and management I use the service Brevo (Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, HRB 133191 B; parent company: Sendinblue SAS, Paris, France). By subscribing you consent to the storage and processing of your email address by Brevo for the purpose of sending professional news and practical reports.Your email address is transmitted to Brevo in encrypted form via a server-side API call — the address never leaves the client sphere via the browser. Brevo processes the data primarily on servers within the EU; details (including the data processing agreement and any sub-processors) are available at brevo.com/de/legal/privacypolicy/.The legal basis is Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time with effect for the future — an unsubscribe link is included at the end of every newsletter email. After withdrawal your address is removed from the active distribution list. It may remain on a suppression list in order to reliably exclude you from advertising emails in future and to document the withdrawal; the legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in observing your withdrawal). Such storage only occurs for as long as this interest exists and is reviewed regularly.The subscription form is also protected against misuse on the server side (honeypot and IP-based rate limiting). The IP address is only processed briefly for this purpose and is not stored permanently. Legal basis: Art. 6(1)(f) GDPR (protection against misuse).8. NIS2 self-check tool
On the sub-page /nis2-check I provide an interactive self-assessment that gives you a technically sound initial estimate, in four questions, of whether your organisation is likely to be classified as an essential, important or indirectly affected entity under NIS2. The purpose of processing is to provide this estimate and — at your request — to send a personalised PDF report by email.Which data is processed?
The answers you enter in the wizard (sector, employee band, revenue band, KRITIS status, supply-chain relevance) remain exclusively client-side in your browser as long as you only view the instant result. In this phase no transmission to a server takes place.If you request the detailed PDF report, you actively transmit the following data via an encrypted POST request to the endpoint/api/nis2-report: email address (mandatory), optionally first/last name, company and role (management / CISO / IT lead / other), the answers recorded in the wizard, plus a timestamp and the honeypot field for spam prevention.Categories of recipients
The PDF report is generated on the server (no third-party PDF service) and sent by email to the address you provided and to my internal lead address (info@buengener-software.de). Email delivery is handled via my own SMTP provider within the EU. There is no separate database — your answers are archived in the lead email and are subject to the retention rules stated in Section 5 (contact forms).If you have additionally set the newsletter opt-in “NIS2-Radar”, your email address is also transmitted to Brevo (see Section 7) and added to a separate distribution list. Without this opt-in, no transmission to Brevo takes place.Legal basis and withdrawal
The legal basis for the PDF dispatch and lead handling is Art. 6(1)(b) GDPR (pre-contractual measure at your request). The legal basis for the newsletter opt-in is Art. 6(1)(a) GDPR (consent), which can be withdrawn at any time via the unsubscribe link. The legal basis for the honeypot, minimum input time and IP-based rate limiting is Art. 6(1)(f) GDPR (protection against misuse).Important note: The self-assessment provides technical guidance — not legal advice within the meaning of Sec. 2 RDG. Only an audit or a lawyer specialising in IT law can provide a reliable assessment in an individual case.9. Hosting
The website is delivered from a server operated by me within Germany. The server log data referred to in Section 3 is not passed on to external hosting providers; the data is processed exclusively on infrastructure under my direct control. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation).10. Fonts
This website uses the Geist font (Vercel, Inc.). The font files are delivered locally from my own server (self-hosted via next/font); no connection is made to Google Fonts or any other third-party CDN when the page is loaded.11. Social media profiles
The footer of this website links to my external profiles on GitHub (GitHub, Inc.) and LinkedIn (LinkedIn Ireland Unlimited Company). These are plain hyperlinks — no social media plugins, buttons or scripts from these providers are embedded. Simply visiting this website therefore transfers no data to GitHub or LinkedIn.Only when you actively click one of these links are you redirected to the respective platform, which then handles the processing of your data under its own responsibility. The privacy policy of the respective provider applies.12. Your rights as a data subject
Under the GDPR you have the following rights:· Right of access (Art. 15 GDPR) — you can request information about the data processed about you.· Right to rectification (Art. 16 GDPR) — you can request the correction of inaccurate data or the completion of incomplete data.
· Right to erasure (Art. 17 GDPR) — you can request the deletion of your data, unless statutory retention obligations apply.
· Right to restriction (Art. 18 GDPR) — you can request the restriction of processing.
· Right to data portability (Art. 20 GDPR) — you can receive the data you provided in a structured, commonly used, machine-readable format.
· Right to object (Art. 21 GDPR) — you can object at any time to processing based on a legitimate interest (see the separate notice below).
· Right to withdraw consent (Art. 7(3) GDPR) — you can withdraw any consent given (e.g. for the newsletter) at any time with effect for the future.To exercise your rights, an informal message to the contact address stated in Section 1 is sufficient.
Right to object (Art. 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of a legitimate interest (Art. 6(1)(f) GDPR). If I cannot then demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing does not serve the establishment, exercise or defence of legal claims, I will no longer process the data concerned.Where your data is processed for direct marketing purposes, you have the right to object at any time to such processing; thereafter your data will no longer be used for direct marketing. An informal objection to the contact address stated in Section 1 is sufficient.13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR) — in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The supervisory authority responsible for me is:Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)Kavalleriestraße 2–4, 40213 Düsseldorf
Phone: +49 211 38424-0 · Email: poststelle@ldi.nrw.de
www.ldi.nrw.de