LEGAL
Privacy policy
Version of 24 August 2026
This is an English translation, provided for convenience. The processing described here is governed by the General Data Protection Regulation (GDPR) and German federal law.
1. Controller
The controller within the meaning of the GDPR is:
Erhardt Systems UG (haftungsbeschränkt)
Gehegestraße 5
39646 Oebisfelde-Weferlingen
Germany
Email: info@erhardt.systems
Represented by managing director Lars Peter Werner Erhardt. Registered at the local court (Amtsgericht) of Stendal under HRB 37973. No data protection officer has been appointed; the statutory conditions of Art. 37 GDPR and § 38 BDSG are not met.
2. General information on data processing
We process personal data only to the extent necessary to provide a functioning website and our content. Processing is carried out on the basis of the GDPR and the German Federal Data Protection Act (BDSG).
3. Hosting and domain name resolution
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, acting as our processor. Hetzner processes data generated when the website is accessed, including server log files. We have concluded a data processing agreement pursuant to Art. 28 GDPR. The legal basis is Art. 6 (1) (f) GDPR.
Name resolution is handled by Amazon Route 53, a service of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. Technical connection data may be generated. Processing in the USA cannot be ruled out; safeguards are described in section 9.
4. Server log files
When the website is accessed, the browser automatically transmits the IP address, date and time, requested file, browser and operating system, referrer URL, transferred data volume, and status message. This is necessary to deliver the page, maintain security and stability, and analyse faults.
Legal basis: Art. 6 (1) (f) GDPR. Log data is generally deleted after seven days unless security-relevant events require longer retention.
5. SSL/TLS encryption
For security reasons and to protect confidential content, this website uses SSL/TLS encryption. An encrypted connection is identifiable by the “https://” prefix in the browser address bar.
6. Contacting us from the home page
The home page contains no contact form. It shows an email address as a mailto link. Selecting it opens the email program configured on your device; no data is transmitted to us by the website and no enquiry database is operated.
7. Contacting us by email
If you contact us by email, the details you provide are stored to process your enquiry and follow-up questions. The legal basis is Art. 6 (1) (f) GDPR, or Art. 6 (1) (b) GDPR where the enquiry concerns a contract. Data is deleted when it is no longer required and no statutory retention obligation applies.
Business email communication uses Microsoft 365, operated by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place. Processing in the USA cannot be ruled out.
8. Web analytics
This website uses the open-source software Rybbit for statistical analysis. We operate Rybbit ourselves at analytics.erhardt.systems. Data is processed on our infrastructure within the European Union and is not transmitted to the software manufacturer or another third party.
Rybbit sets no cookies and stores no information in your browser. It does not record sessions, mouse movements, keystrokes, or form content; it performs no cross-site tracking, profiling, advertising disclosure, or data sale.
Processed data includes the page and title, referrer, entry and exit page, visit duration, browser and operating system, device type, screen resolution, country and region derived from the IP address, campaign parameters, and clicks to other websites. The IP address is handled transiently to derive country and region and is not stored. A daily salted identifier expires within 24 hours.
Legal basis: Art. 6 (1) (f) GDPR. Retention: 14 months. You may object at any time by emailing info@erhardt.systems or blocking the script from analytics.erhardt.systems.
9. Recipients and transfers to third countries
Personal data is disclosed only to the processors named above and is not sold or disclosed for advertising. Where data is processed in the USA, transfers rely on an adequacy decision pursuant to Art. 45 GDPR where the recipient is certified under the EU-US Data Privacy Framework, and otherwise on standard contractual clauses pursuant to Art. 46 (2) (c) GDPR. The USA does not offer a level of protection equivalent to European law and access by state authorities cannot be entirely ruled out.
10. No automated decision-making
Automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR does not take place.
11. Your rights
You have rights of access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent with effect for the future. To exercise these rights, an informal message to info@erhardt.systems is sufficient.
12. Right to object
Where we process data on the basis of Art. 6 (1) (f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop processing unless compelling legitimate grounds override your interests or the processing serves legal claims.
13. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Landesbeauftragter für den Datenschutz Sachsen-Anhalt, Leiterstraße 9, 39104 Magdeburg, Germany.
14. Changes to this privacy policy
We will adapt this policy when processing operations or legal requirements change. The version published here applies in each case.