1. Introduction and general information
Protecting your personal data is important to us. We treat your personal data confidentially and in accordance with statutory data protection provisions and this privacy policy.
This policy applies to the website protexium.de including all sub-pages and the language versions under /en/, /es/ and /ru/, as well as to the forms offered there, the chat assistant and the measurement of reach and advertising performance.
Version of this privacy policy: 16 August 2026.
2. Data controller
The controller responsible for data processing on this website is:
Protexium Security GmbH
Untere Rathausgasse 10
90530 Wendelstein, Germany
VAT ID: DE327683777
Phone: +49 9129-2945775
E-mail: info@protexium.de
Represented by the management:
Oxana Nosenko
Data protection officer: [PLACEHOLDER: state whether a data protection officer has been appointed and, if so, the contact details. If there is no obligation to appoint one under section 38 BDSG, this paragraph can be deleted before publication.]
3. Legal bases for processing
We only collect, use and disclose personal data where this is permitted by law or where you have consented to the processing. We base the individual processing operations on the following legal grounds:
- Art. 6(1)(a) GDPR: your consent, for example for analytics and marketing services. Where information is stored on or read from your device, section 25(1) TDDDG applies in addition.
- Art. 6(1)(b) GDPR: performance of a contract or pre-contractual steps, for example when you send an enquiry via the contact form.
- Art. 6(1)(c) GDPR: compliance with legal obligations, for example commercial and tax retention requirements.
- Art. 6(1)(f) GDPR: our legitimate interests, for example in the secure operation of the website and in preventing abusive requests.
You are under no legal or contractual obligation to provide your data. Without the information marked as mandatory, however, we cannot process an enquiry.
4. Hosting, delivery and server logs
This website is hosted with Cloudflare (Cloudflare Pages). The form, chat and counter functions run through an application we developed ourselves on the Cloudflare Workers platform. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
When you access our pages, Cloudflare processes technically necessary connection data: IP address, date and time of the request, the address requested, the previously visited page (referrer), browser type and operating system, volume of data transferred and status code. This data is required to deliver the pages and to defend against attacks. We do not evaluate it on a personal basis and do not combine it with other data.
Legal basis: Art. 6(1)(f) GDPR. Legitimate interest: secure, stable and efficient provision of the website.
Recipients: Cloudflare as a processor on the basis of a data processing agreement under Art. 28 GDPR. For transfers to the USA see section 16.
Storage period: connection data is retained only briefly in line with the provider's specifications. [PLACEHOLDER: add the specific retention period for Cloudflare logs based on the data processing agreement]
5. Contact form and handling of your enquiry
You can send us enquiries through the forms on our website. The following data is processed: name and e-mail address (mandatory), phone number, region, area of interest or property type and your message. In technical terms, the page language, the form variant and the page from which the enquiry was sent are also transmitted.
Purpose: handling your enquiry, arranging an appointment for the security analysis, preparing a quotation and answering follow-up questions.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps taken at your request). If your enquiry does not relate to a contract, the legal basis is Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Recipients: the enquiry is received by our application at Cloudflare and delivered as an e-mail to our sales mailbox. For delivery we use the Brevo service provided by Sendinblue GmbH, Koepenicker Strasse 126, 10179 Berlin, Germany, acting as a processor. Processing takes place on servers within the European Union.
To limit abuse, your IP address is processed briefly when you submit the form (section 7). It is not stored permanently and is not saved in our enquiry system.
Storage period: we store your enquiry for as long as is necessary to process it. Details in sections 6 and 18.
6. Enquiry and customer management in our own CRM
Incoming enquiries are additionally stored in an enquiry system (CRM) that we operate ourselves. The database runs on the Cloudflare D1 platform and is located within the European Union (Western Europe region).
Purposes: handling and following up your enquiry, preparing quotations and processing orders, internal sales management and, only where you have consented, measuring the performance of our advertising (section 15).
Categories of data processed:
- Contact data: name, e-mail address, phone number
- Enquiry data: your message, language, region, property type
- Sales data: processing status, estimated and actual order value, responsible person, next step and date, reason for a rejection, internal notes on conversations
- Origin data: click identifiers from Google advertising (gclid, wbraid, gbraid), campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content), the first page accessed, the referring page and the source derived from this
- Result of the automated bot check on the form (section 7)
- Log timestamps: creation, last change and, where applicable, the time of a report back to Google Ads
We do not store your IP address or special categories of personal data under Art. 9 GDPR. No profiling and no automated decision-making within the meaning of Art. 22 GDPR takes place.
Legal basis: Art. 6(1)(b) GDPR for handling the enquiry and processing the order; Art. 6(1)(f) GDPR for internal sales management (legitimate interest in orderly and traceable quotation processing); Art. 6(1)(a) GDPR for using the origin data to measure advertising performance.
Recipients: Cloudflare as a processor operating the database. Access to the system is limited to named employees and requires a separate login using a one-time code.
Storage period: enquiries that did not lead to an order and are marked as closed without success are deleted automatically twelve months after the last change, together with the associated notes. We review the remaining enquiries without an order regularly and generally delete them after 24 months without activity. Where an order was placed, the statutory retention periods of six and ten years apply (section 257 HGB, section 147 AO).
7. Protection against automated requests (Cloudflare Turnstile)
To protect our forms against automated submissions and spam we use Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
Turnstile checks in the background whether the input comes from a human. In doing so, your IP address and technical characteristics of your browser and device (including browser version, language setting, screen and device properties and interaction patterns on the page) are transmitted to Cloudflare and evaluated there. According to the provider, Turnstile does not set cookies for advertising purposes and is not used to recognise users across websites.
We store the result of the check (passed, no token supplied, rejected or check not possible) together with your enquiry so that we can assess doubtful submissions manually. An enquiry is not discarded automatically on the basis of this result alone.
In addition we use methods that do not involve any transfer to third parties: a field that is invisible to you and is only completed by automated scripts, and a measurement of the time between the form being displayed and submitted. We also limit the number of submissions per IP address (currently five enquiries per hour). The counter required for this is deleted automatically after one hour.
Legal basis: Art. 6(1)(f) GDPR. Legitimate interest: protecting our systems against abuse, spam and automated attacks. You may object to this processing under Art. 21 GDPR; in that case we will be happy to accept your enquiry by phone or e-mail.
Third country transfer: see section 16. Further information in the Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/
8. Chat assistant
A chat assistant is available on our website to answer questions about our services. We operate it ourselves; no external live chat service is used.
Your entries are transmitted to our application at Cloudflare and from there to OpenAI, Inc., 1455 3rd Street, San Francisco, CA 94158, USA, where they are processed by a language model. Only the content of your message and the current conversation history, limited to the last ten contributions, are transmitted. The history is kept in your browser; we do not store the chat content permanently.
Please do not enter particularly sensitive information in the chat, such as health data, access credentials or details of specific security weaknesses at your property. For personal advice please use the contact form or call us.
To limit abuse, your IP address is processed briefly in a counter; this counter is deleted automatically after 15 minutes.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in answering questions directly); where you make a specific enquiry about our services in the chat, additionally Art. 6(1)(b) GDPR.
Storage period at the provider: according to OpenAI, content transmitted via the programming interface is not used to train the models and is retained for up to 30 days for abuse monitoring. [PLACEHOLDER: confirm this statement against the OpenAI terms in force at the time of publication]
Third country transfer: see section 16.
9. Cookie-free visitor counter
In order to see which pages are accessed and how often, we operate a very simple counter of our own. Only the path of the page accessed and a rough indication of the origin of the visit are transmitted. No cookies are set and no identifiers are assigned that could be used to recognise you. Only daily totals per page are stored.
Your IP address is used only transiently to limit abuse, is deleted after one hour and is not linked to the counter values.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimising reach measurement). Storage period: two years for the aggregated counter values.
10. Cookies, local storage and consent management
Our website uses cookies and comparable technologies such as your browser local storage. Technically necessary storage is based on section 25(2) TDDDG and Art. 6(1)(f) GDPR. All services requiring consent are only started once you have agreed.
We use the consent tool CookieConsent (open source solution, version 3) to obtain and manage your consent. It is delivered from our own server; no data is transferred to third parties in the process. Your decision is stored in the cookie cc_cookie on your device (default lifetime 182 days) and read on each subsequent visit.
We distinguish three categories:
- Strictly necessary: basic functions of the website and storage of your cookie decision. Always active, cannot be deselected.
- Analytics and statistics: Google Analytics 4 (section 12) with the cookies _ga (lifetime two years) and _gid (lifetime 24 hours).
- Marketing and advertising: Google Ads conversion tracking including enhanced conversions and offline conversions (sections 13 to 15) with the cookie _gcl_au (lifetime three months).
Origin data in local storage: independently of cookies, when you access a page we store the origin details of your visit (an advertisement click identifier and campaign parameters from the address called up, the first page accessed and the referring page) for 90 days in your browser local storage under the key px_attr. This allows us to attribute a later enquiry to the correct source. This information is transmitted to us when you submit a form and is stored in our enquiry system (section 6). Transmission to Google only takes place with your consent to the marketing category (sections 13 to 15). Legal basis for our own evaluation: Art. 6(1)(f) GDPR.
Withdrawal: you can withdraw or change your consent at any time with effect for the future using the Cookies button at the bottom of every page. The lawfulness of processing carried out up to the withdrawal remains unaffected. After a withdrawal the cookies concerned are deleted and no further data is transmitted to the services concerned. You can also delete or block cookies in your browser settings.
11. Google Consent Mode v2
We use Google's consent mode (Consent Mode v2). It ensures that the Google services on this website are set to denied by default when you first access it: ad storage, ad user data, ad personalisation and analytics storage are deactivated. This state is only updated to granted once you agree in the banner. If you withdraw your consent it is immediately set back to denied.
Two additional protective settings are active: without marketing consent Google removes advertising identifiers from the measurement data (ads_data_redaction), and click identifiers are passed on in the address bar instead of in cookies (url_passthrough).
Transparency note: technically, the Google tag is already loaded before your decision. In this state it does not set cookies and does not transmit advertising identifiers; however, retrieving the script from googletagmanager.com does transmit your IP address to Google. Without consent, Google may derive statistical model values from the remaining signals; no evaluation relating to identified persons takes place.
Legal basis: Art. 6(1)(f) GDPR for retrieving the script; for all measurement based on it, your consent under Art. 6(1)(a) GDPR in conjunction with section 25(1) TDDDG.
12. Google Analytics 4
Once you have consented to the analytics and statistics category we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: evaluating the use of our website in order to improve its content, structure and offering.
Data processed: a pseudonymous identifier in the cookies _ga and _gid, pages accessed and time spent, date and time of access, approximate location (derived from the truncated IP address), device type, browser and operating system, referring page and campaign parameters, as well as the following events triggered by us: form submitted successfully (generate_lead), click on a phone number (phone_click), click on a WhatsApp link (whatsapp_click) and opening and use of the chat (chat_open, chat_message). With these events we also transmit the form identifier, the form variant and the page language. The content of your message is not transmitted.
According to Google, your IP address is truncated within the EU and is not logged permanently.
Legal basis: Art. 6(1)(a) GDPR in conjunction with section 25(1) TDDDG (consent).
Recipients: Google Ireland Limited as a processor on the basis of an agreement under Art. 28 GDPR, and affiliated Google companies, including in third countries (section 16).
Storage period: user- and event-related data in Google Analytics is deleted automatically after 14 months. Cookie lifetimes: _ga two years, _gid 24 hours.
Withdrawal: via the Cookies button (section 10). Google also offers a browser add-on for deactivation: https://tools.google.com/dlpage/gaoptout. Further information: https://policies.google.com/privacy
13. Google Ads conversion tracking
Once you have consented to the marketing and advertising category we measure the performance of our advertisements on Google Ads, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: establishing which advertisement or campaign led to an enquiry, and managing our advertising budget.
How it works: if you click on one of our advertisements, Google automatically appends a click identifier to the target address (auto-tagging, parameter gclid, and wbraid or gbraid for certain ad formats). We store this identifier and the campaign parameters for 90 days in your browser local storage (section 10). If a measurable action takes place, the Google tag reports it to Google as a conversion. We measure: a successfully submitted contact form, a click on a phone number and a click on a WhatsApp link. Google Ads sets the cookie _gcl_au with a lifetime of three months.
Data transmitted: click identifier, name of the conversion action, timestamp and a random transaction number to avoid double counting. The content of your message and your other form entries are not transmitted; for the hashed transmission of e-mail address and phone number see section 14.
Legal basis: Art. 6(1)(a) GDPR in conjunction with section 25(1) TDDDG (consent).
Storage period: click identifiers in your browser local storage 90 days, the cookie _gcl_au three months; in the advertising account according to Google specifications.
Withdrawal: via the Cookies button. You can also deactivate ad personalisation in your Google account: https://adssettings.google.com
14. Enhanced conversions for leads
In addition to conversion tracking we use the enhanced conversions for leads function of Google Ads. It attributes an enquiry to the correct advertisement even where cookies are missing, have been deleted or a device has been changed.
Procedure: if you submit a form successfully and have consented to the marketing category, your e-mail address and, if provided, your phone number are first standardised in your browser (lower case, international phone number format) and then converted into a hash value using the SHA-256 cryptographic procedure. Only this hash value is transmitted to Google (sha256_email_address, sha256_phone_number). The plain values do not leave your browser in the direction of Google.
Important to know: such a hash value is not anonymous. Google can compare it with the hash values of accounts held at Google and thereby attribute the enquiry to a Google account. It therefore remains personal data. For this reason this processing takes place exclusively with your express consent.
Categories of data: SHA-256 hash of the e-mail address and SHA-256 hash of the phone number, in each case together with the information listed in section 13.
Legal basis: Art. 6(1)(a) GDPR in conjunction with section 25(1) TDDDG. Without consent to the marketing category no hash value is created and nothing is transmitted to Google.
Recipients: Google Ireland Limited and Google LLC. Google processes this data on the basis of the Google Ads customer data terms. For transfers to the USA see section 16.
Withdrawal: at any time via the Cookies button, with effect for the future. On request we will have conversion data already transmitted removed in Google Ads; please contact info@protexium.de.
15. Reporting completed orders to Google Ads (offline conversions)
If an enquiry that originated from a Google advertisement later leads to an order, we report this success back to Google Ads. The purpose is to optimise the delivery of advertisements towards orders actually concluded rather than merely towards submitted forms.
Scope of the transmission: only the click identifier (gclid), the name of the conversion action, the timestamp, the order value and the currency are transmitted. We do not transmit your name, e-mail address, phone number, postal address or the content of your enquiry. The click identifier is already known to Google from the ad click; Google cannot derive contact details from it.
Legal basis: Art. 6(1)(a) GDPR (your consent to the marketing category). Enquiries for which no consent to the marketing category exists do not take part in this reporting.
Recipients: Google Ireland Limited and Google LLC. Each enquiry is reported at most once. Files created for the transmission are deleted immediately after the upload. For transfers to the USA see section 16.
Withdrawal: you can withdraw your consent at any time. We will then remove the advertising identifiers from your record; your enquiry will no longer take part in performance measurement. On request we will have conversions already transmitted removed in Google Ads.
16. Transfers to third countries, in particular to the USA
The services provided by Google, Cloudflare and OpenAI may involve a transfer of personal data to the USA.
By decision of 10 July 2023 the European Commission determined that companies certified under the EU-US Data Privacy Framework ensure an adequate level of data protection in the USA (Art. 45 GDPR). In addition, we have agreed the standard contractual clauses of the European Commission under Art. 46(2)(c) GDPR with the providers and have taken note of their technical and organisational measures.
[PLACEHOLDER: check the certification of the providers used, in particular OpenAI, in the official list at dataprivacyframework.gov before publication and record the status here]
Note on the risk: despite these safeguards it cannot be entirely ruled out that US authorities may access the data on the basis of US law and that you may not have legal remedies comparable to those under European law. Insofar as you consent to the use of the services named, you also consent under Art. 49(1)(a) GDPR to the transfer of your data to the USA. You can withdraw this consent at any time with effect for the future.
17. Fonts and external resources
The Inter typeface used on this website is generally delivered from our own server. No connection to third-party servers is established and no data is transferred to Google.
On individual special pages, including the advertisement and campaign pages, the typeface is currently still loaded via Google Fonts provided by Google Ireland Limited. Your browser then establishes a connection to Google servers and transmits your IP address. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a consistent presentation). [PLACEHOLDER: these pages are scheduled to be switched to local font delivery; this paragraph can then be removed]
Further information: https://developers.google.com/fonts/faq and https://policies.google.com/privacy
18. Storage periods at a glance
- Connection data when a page is accessed: briefly at the hosting provider, see section 4
- Counters used to limit abuse (IP address): one hour for the form and the visitor counter, 15 minutes for the chat
- Aggregated page views from our own counter: two years
- Consent management cookie (cc_cookie): 182 days
- Origin data in local storage (px_attr): 90 days
- Google Analytics cookies: _ga two years, _gid 24 hours; data in the analytics account 14 months
- Google Ads cookie _gcl_au: three months
- Enquiries without an order, marked as unsuccessful: twelve months after the last change, then deleted automatically
- Other enquiries without an order: guideline of 24 months without activity
- Documents relating to orders placed: six or ten years in line with statutory retention periods
19. Your rights
You have the right at any time to:
- information about the data we hold about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing (Art. 21 GDPR)
- withdraw consent you have given (Art. 7(3) GDPR)
Withdrawal of consent: where processing is based on your consent you can withdraw it at any time with effect for the future. For cookies, analytics and advertising measurement a click on the Cookies button at the bottom of every page is sufficient. The lawfulness of processing carried out up to the withdrawal remains unaffected.
Right to object: you have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR.
Right to lodge a complaint: you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 27, 91522 Ansbach, Germany.
To exercise your rights please contact the controller named in section 2.
20. Changes to this privacy policy
We update this privacy policy whenever the processing on our website changes or new services are added. The version published on this page applies in each case.
Version: 16 August 2026.