privacy policy
This translation is provided for information only. The German version is legally binding.
Protecting your personal data matters to me. This website works without external fonts and without content delivery networks. Advertising performance is only measured if you have expressly consented beforehand.
1. Controller
Can Yildiz Security ConsultingDietrich-Bonhoeffer-Str. 23
61440 Oberursel (Taunus)
Email: kontakt@cyi-consulting.de
2. Server log files
The hosting provider automatically collects and stores information in so-called server log files, which your browser transmits: browser type and version, operating system used, referrer URL, hostname of the accessing computer, time of the server request and IP address. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the technically error-free and secure operation of the website. The data is deleted after seven days at the latest.
3. Contact form and email contact
If you send me enquiries via the contact form or by email, your details including the contact data you provide are stored in order to process the enquiry and in case of follow-up questions.
The legal basis is Art. 6 (1) (b) GDPR where your enquiry relates to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on my legitimate interest in effectively handling the enquiries addressed to me (Art. 6 (1) (f) GDPR). The data remains with me until you ask me to delete it, withdraw your consent or the purpose ceases to apply; mandatory statutory retention periods remain unaffected.
To protect against automated requests, technical characteristics are evaluated on submission (an invisible additional field, timing measurement and a shortened, hashed form of the IP address to limit submission frequency). These characteristics are used solely for spam protection and are deleted automatically after a short time.
4. Cookies and local storage
This website sets a technically necessary session cookie that serves solely to secure the contact form (protection against cross-site request forgery). It is deleted when you close your browser and requires no consent (§ 25 (2) no. 2 TDDDG).
Optional services (see section 5) are only loaded after your explicit consent via the consent notice. Your decision is stored locally in your browser for this purpose (localStorage, key “cyi-consent”) and is not transmitted to the server. You can withdraw it at any time by clearing the site data in your browser; the notice will then appear again.
5. Google Ads (conversion measurement)
This website uses the Google Ads tag (gtag.js) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It makes it possible to see whether a visit originates from a Google advert and has led to an enquiry (conversion measurement). In doing so, cookies or comparable identifiers are stored on and read from your device, and data is transmitted to Google, in particular your IP address, device and browser information, the pages you visit, the time of access and the click identifier of the advert.
The legal basis for storing and reading information on your device is § 25 (1) TDDDG, and for the subsequent processing of your personal data Art. 6 (1) (a) GDPR – in each case your consent. Without consent the script is not loaded; until then no connection to Google whatsoever is established. Your consent is voluntary and can be withdrawn at any time with effect for the future (see section 4).
Google also processes the data in the USA. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is additionally based on the European Commission’s standard contractual clauses. Despite these safeguards, protection equivalent to the European level cannot be fully guaranteed, in particular with regard to access by government authorities.
Further information: Google’s privacy policy at policies.google.com/privacy and the ad settings at adssettings.google.com.
6. External content
The contact form is protected against automated requests exclusively by server-side, data-minimising measures (including checksum tokens as well as time and frequency limits); no data is transmitted to third parties in the process.
Apart from the consent-based Google Ads tag described in section 5, no external fonts, maps, video platforms, captcha or analytics services are embedded. All other resources are delivered from my own server. Links to external profiles (e.g. LinkedIn) only become active when you click them.
7. Your rights
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR)
The competent supervisory authority is the Hessian Commissioner for Data Protection and Freedom of Information.
8. SSL/TLS encryption
For security reasons this site uses TLS encryption. You can recognise an encrypted connection by the prefix “https://” in your browser’s address bar.
Last updated: Version 1.2