LEGAL
Privacy policy
Last updated: 26 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection legislation is:
AlphaCom Solutions UG (haftungsbeschränkt)
Hindenburgstraße 6a–10a
42853 Remscheid
Germany
Represented by the managing director:
Benjamin Getschmann
Email: info@dppdesk.io
Website: https://dppdesk.io
DPPdesk is a brand and service offered by AlphaCom Solutions UG (haftungsbeschränkt).
2. General information on data processing
We process personal data only to the extent necessary to provide our website, respond to enquiries, send our newsletter or take steps prior to entering into a contract.
Depending on the processing activity, we rely in particular on the following legal bases:
- Art. 6(1)(a) GDPR where you have given us your consent,
- Art. 6(1)(b) GDPR where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract,
- Art. 6(1)(c) GDPR where we are subject to a legal obligation,
- Art. 6(1)(f) GDPR where processing is necessary for the purposes of our legitimate interests or those of a third party and your interests or fundamental rights do not override those interests.
We disclose personal data only where this is necessary for the stated purposes, where a legal obligation applies or where you have given your consent. Where required, service providers are engaged on the basis of a data processing agreement pursuant to Art. 28 GDPR.
3. Provision of the website and server log data
When you access our website, your browser automatically sends information to our technical infrastructure. In particular, the following data may be processed:
- IP address of the accessing device,
- date and time of access,
- page or file accessed,
- previously visited page (referrer URL), where transmitted by the browser,
- browser type and browser version,
- operating system used,
- volume of data transferred,
- HTTP status code,
- hostname of the accessing device.
This processing is carried out to provide the website technically, ensure its stability and security, detect attacks and abusive access, and analyse technical errors.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional operation of our website.
Server log data is generally deleted no later than 14 days after collection, unless a security-related investigation, preservation of evidence or a legal obligation requires longer storage. Data needed to investigate a specific security incident may be stored until the relevant matter has been concluded.
4. Hosting by Hetzner
Our website and the associated data are hosted on servers operated by:
Hetzner Online GmbH
Industriestraße 25
91710 Gunzenhausen
Germany
Hetzner processes data generated during the operation of the website on our behalf. Processing generally takes place within the European Union or the European Economic Area.
We use Hetzner to provide our website securely, quickly and reliably. The legal basis is Art. 6(1)(f) GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
Further information is available in Hetzner’s privacy policy.
5. Cloudflare
We use services provided by the following company to deliver our website securely and quickly:
Cloudflare, Inc.
101 Townsend Street
San Francisco, California 94107
USA
Cloudflare provides, in particular, a content delivery network (CDN) and security functions. Traffic between your device and our website is routed through Cloudflare’s global network. Cloudflare may process IP addresses, connection data, device and browser information, and technical log data. This processing serves, among other things, to defend against DDoS attacks and malicious traffic, improve loading times and securely deliver our website.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, efficient and reliable provision of our website.
Cloudflare processes data as our processor. A data processing agreement pursuant to Art. 28 GDPR is in place. Processing may also take place outside the European Union or the European Economic Area, in particular in the United States.
Cloudflare is certified under the EU–US Data Privacy Framework. Where a transfer cannot be based on an adequacy decision, the agreement with Cloudflare provides for the use of the standard contractual clauses approved by the European Commission and supplementary safeguards.
Cloudflare stores personal data only for as long as is necessary to provide and secure the services used or for as long as legal obligations apply. The specific period depends on the type of security and log data and on the settings we have selected.
Further information is available in Cloudflare’s privacy policy and the Cloudflare Data Processing Addendum.
6. Server-side baseline measurement and optional Matomo analytics
6.1 Privacy-friendly baseline measurement
To measure actual reach and technical quality, we perform server-side baseline measurement for all page requests. It operates independently of the choice made in the consent banner and uses no browser-side analytics JavaScript, analytics cookies, local storage or device fingerprinting.
The following information is derived in particular from web-server requests that are technically generated in any event:
- requested URL path and landing page,
- time of access, HTTP status code and response time,
- referring page reduced to its domain,
- approved campaign parameters such as
utm_source,utm_mediumandutm_campaign, - the mere presence of an advertising click identifier such as
gclid, used only to classify the request as campaign traffic; the actual identifier is discarded.
To associate page requests belonging to a short visit, the IP address is reduced to a coarse network prefix before the analytics log is written and the browser user agent is replaced with a one-way hash. The server combines both values with a secret key to generate a pseudonymous identifier that changes no later than each calendar day. Neither the reduced input values nor the key are transferred to Matomo. The identifier permits an estimate of active browsers and short visits, but no recognition across days or devices. People behind the same network prefix may be combined and changing connections may be counted separately.
Cookies, full IP addresses, full referrer URLs and readable browser user agents are not transferred to the baseline system. Security logs and analytics data are processed separately. Baseline measurement is used solely for statistics concerning page views, active browsers, sources, campaigns, errors and performance; it does not create long-term or cross-device user profiles.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are measuring reach, evaluating our own campaigns and improving the content, stability and performance of the website. As no information is stored on or additionally read from the user’s device, baseline measurement is not based on consent under section 25(1) TDDDG. Your right to object under Art. 21 GDPR remains unaffected.
Pseudonymised analytics source logs are deleted after successful processing and no later than 24 hours after creation. Usage statistics stored in the baseline system are deleted or further aggregated after no more than 14 months. Processing takes place on our own infrastructure operated by Hetzner in Germany.
6.2 Full analytics with consent
Only after your express consent do we additionally load our self-hosted Matomo instance at analytics.dppdesk.io. This allows us to analyse detailed sessions, returning visits, time spent, navigation, outbound links, events and campaign attribution. The legal basis is Art. 6(1)(a) GDPR; access to information on your device is based on section 25(1) TDDDG.
After consent, Matomo may set the following first-party cookies in particular; their actual names usually contain an additional website and domain identifier:
_pk_idto recognise returning visits, with a default lifetime of up to 13 months,_pk_sesto associate actions with a visit, with a default lifetime of 30 minutes,_pk_refto attribute the source of a visit, with a default lifetime of up to 6 months,_pk_testcookieas a short-lived technical cookie test that expires almost immediately.
Your choice is stored under dppdesk_analytics_consent_v1 for no more than 90 days in a first-party preference cookie and, as a fallback, in your browser’s local storage. Only the value “analytics allowed” or “analytics not allowed” and its expiry time are stored, not a user identifier. This is necessary to respect your selection on later visits and is carried out pursuant to section 25(2)(2) TDDDG. We ask for your choice again after expiry.
You can withdraw your consent at any time through “Tracking settings” in the footer. Existing Matomo cookies will then be deleted and full analytics stopped for the future. The server-side baseline measurement, which does not require consent, remains unaffected. Withdrawal also does not affect the lawfulness of processing carried out before withdrawal.
Matomo runs on our own infrastructure in Germany; no data is transferred to an independent external analytics provider. Heatmaps, session recordings and advertising profiles are not part of the current integration. Full-analytics data is deleted or anonymised no later than 14 months after collection.
Depending on a specific security situation, Cloudflare security functions may additionally set technically necessary, short-lived cookies. These are used solely for website security and functionality, not for analytics or advertising, pursuant to section 25(2)(2) TDDDG.
7. Contact and contact form
When you use our contact form, we process the information you enter in order to store, assign and handle your enquiry. The following data is collected:
- name and email address,
- company and telephone number, where provided voluntarily,
- selected contact topic and message content,
- your confirmation of the privacy notice,
- the address of the page from which the form was submitted,
- the time elapsed before submission and a spam-protection field that is not visible to human users,
- time of receipt and a reference number,
- the sender’s IP address solely for preventing misuse.
Name, email address, message and confirmation of the privacy notice are required. The enquiry cannot be submitted without them. The spam-protection field and a minimum completion time are checked together with IP-based rate limiting before an enquiry is stored. Rejected enquiries are not stored in the contact database. We do not use a CAPTCHA or an external form provider.
Where your enquiry relates to an existing or potential contractual relationship, the legal basis is Art. 6(1)(b) GDPR. Other enquiries are processed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest is the proper handling and documentation of enquiries and protecting the form against misuse.
Form details, the source page address, time of receipt and reference number are retained for twelve months from receipt and then deleted, unless statutory retention obligations or another legally permissible reason require longer storage. The IP address is processed solely for preventing misuse and deleted after 30 days.
Processing takes place without disclosure to third parties on our own infrastructure hosted by Hetzner in Falkenstein, Germany. The form is transmitted in encrypted form. Once it has been stored successfully, a copy of the enquiry is sent to the email address provided; the technical reference is used only for internal assignment.
If you contact us directly by email, we process the sender address, content, time and any other information you provide in order to handle the message. Such correspondence is generally deleted no later than six months after it has been finally dealt with, unless longer retention is necessary or required by law. Complete confidentiality during transmission cannot be guaranteed for ordinary email communication. Please send particularly confidential information only after prior consultation.
8. Newsletter
You can voluntarily subscribe to our newsletter. For this purpose, we process your email address and, where provided voluntarily, your name, company and areas of interest.
We use the double opt-in procedure for subscriptions. After subscribing, you will receive an email asking you to confirm your subscription. Your address is added to the newsletter mailing list only after this confirmation. To document consent, we store the time of subscription and confirmation as well as the IP address used at that time.
The legal basis for sending the newsletter is your consent pursuant to Art. 6(1)(a) GDPR. The subscription process is logged on the basis of Art. 6(1)(f) GDPR, as we have a legitimate interest in demonstrating a proper subscription and the consent given.
If you do not confirm your subscription within seven days, the data collected in connection with the unconfirmed subscription will be deleted.
You can withdraw your consent at any time with effect for the future. You can use the unsubscribe link at the end of each newsletter or send a message to info@dppdesk.io. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
After you unsubscribe, your address will no longer be used to send the newsletter. Where necessary to defend against possible claims or prove prior consent, consent and unsubscribe data may be stored in restricted form for up to three years from the end of the relevant calendar year. Further storage may take place where required by law. You may object to storage for evidentiary purposes if you believe that your interests override our legitimate interest.
The newsletter is sent through our own technical infrastructure hosted by Hetzner. Individual opening or click behaviour is not analysed.
9. Registration and login to the DPPdesk application
The publicly accessible dppdesk.io website does not itself provide user accounts. The “Register” and “Login” buttons lead to the technically separate DPPdesk application.
When you follow such a link, your browser connects to the destination address. The connection and log data required to load the page is processed in the process. The separate privacy information provided there applies to registration, user management, authentication and use of the DPPdesk application. You can review this information before completing a registration.
10. External content and fonts
Apart from the self-hosted Matomo instance described in section 6, we do not embed external analytics tools, maps, videos, social media plugins or comparable marketing services.
Fonts and other static content used are delivered locally or through our own hosting and Cloudflare infrastructure described above. Simply loading the website therefore does not establish a connection to providers such as Google Fonts.
Standard links to external websites transfer data to the respective provider only when you actively open the link. The operator of the linked website is responsible for data processing on that website.
11. Recipients of personal data
Within our company, personal data is accessible only to those persons who need it to fulfil the purposes described.
Data may also be transferred in particular to the following categories of recipients:
- hosting, infrastructure and IT security service providers,
- technical service providers for email communication,
- legal, tax or business advisers where required in an individual case,
- authorities, courts or other public bodies where a legal obligation applies.
Personal data is not disclosed for advertising purposes or sold.
12. Retention periods
Where no specific retention period is stated in this privacy policy, we store personal data only for as long as is necessary for the respective purpose.
The data is then deleted or anonymised unless statutory retention obligations, ongoing contractual relationships, evidentiary obligations or legitimate interests require continued storage. Statutory retention periods may be six or ten years, in particular under commercial and tax law.
13. Data security
Our website is transmitted in encrypted form using HTTPS. We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other unlawful processing. These measures are reviewed and adapted in line with technical developments and the relevant risk situation.
14. Your data protection rights
Subject to the statutory requirements, you have in particular the following rights:
- access to the personal data we process pursuant to Art. 15 GDPR,
- rectification of inaccurate data or completion of incomplete data pursuant to Art. 16 GDPR,
- erasure of your personal data pursuant to Art. 17 GDPR,
- restriction of processing pursuant to Art. 18 GDPR,
- data portability pursuant to Art. 20 GDPR,
- objection to processing pursuant to Art. 21 GDPR,
- withdrawal of consent with effect for the future pursuant to Art. 7(3) GDPR.
Right to object
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation.
Where personal data is processed for direct marketing purposes, you may object to such processing at any time without stating specific reasons.
To exercise your rights, it is sufficient to send an informal message to info@dppdesk.io. To prevent unauthorised disclosure, we may request suitable proof of your identity.
15. Right to lodge a complaint with a supervisory authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. In particular, you may contact the authority responsible for our registered office:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Telephone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de
The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
16. No automated decision-making
No decision based solely on automated processing, including profiling within the meaning of Art. 22 GDPR, takes place in connection with the publicly accessible website.
17. Requirement to provide data
Personal data required to visit the website is provided automatically for technical reasons. When using the contact form, the information marked as required is necessary to process your enquiry.
Newsletter subscription is voluntary. However, a newsletter cannot be sent unless you provide and confirm your email address.
18. Updates to this privacy policy
We update this privacy policy when our website, the services used or the legal requirements change. The version published on this website at the relevant time applies.
