Legal / English
Privacy Policy
Last updated: 20 August 2026
This Privacy Policy explains how CCI Services GmbH ("CCI", "we", "us" or "our") processes personal data when you visit https://cciservices.de, contact us, submit information through our solution configurator, enter into or perform a business relationship with us, or use our invite-only backoffice as an authorised user.
We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the Telecommunications Digital Services Data Protection Act (TDDDG) and other applicable law.
This Policy covers processing for CCI's website and its own business administration. It does not describe processing that CCI performs solely on a client's documented instructions as a processor; that processing is governed by the client's privacy information and the applicable data processing agreement. If CCI obtains lead or contact data from public or third-party sources for its own purposes, CCI must provide the separate information required by Article 14 GDPR within the applicable time limits; a passive website page alone is not sufficient.
1. Controller
The controller responsible for the processing described in this Privacy Policy is:
CCI Services GmbH
Kurfürstendamm 11
10719 Berlin
Germany
Email: info@cciservices.de
2. General principles
We process personal data only for specified and legitimate purposes, collect only the data reasonably necessary for those purposes and retain it only for as long as required. Access is restricted to authorised personnel and service providers who need the data for their work.
3. Visiting our website and server logs
When you access our website, our hosting and security systems may process technical information including:
- IP address;
- date and time of access;
- requested page or file;
- referrer URL, where transmitted;
- browser, device and operating-system information;
- HTTP response status; and
- diagnostic and security-event data.
We process these data to deliver the website, maintain stability and security, identify misuse, investigate technical faults, security incidents or fraud and protect our systems. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of our website and IT systems and, where an incident or claim arises, investigating it and establishing, exercising or defending legal claims.
As a default, ordinary access logs are deleted or irreversibly anonymised after 7 days. If a specific security incident, fraud attempt or legal claim is identified, a restricted extract may be retained for as long as reasonably necessary to investigate, remedy or establish, exercise or defend claims.
4. Essential cookies and device storage
We use only technologies that are necessary to provide an expressly requested function, maintain security or authenticate authorised backoffice users.
Under Section 25(2) TDDDG, consent is not required only where storage of or access to information on a device has the sole purpose of transmitting a communication or is strictly necessary to provide a digital service expressly requested by the user. Where those operations involve personal data, subsequent processing is based on Article 6(1)(f) GDPR for secure and reliable operation and access control, Section 26 BDSG where applicable to employee use, or Article 6(1)(b) GDPR only where the user personally requests a contractual function.
The invite-only backoffice uses Supabase Auth and only strictly necessary authentication and security storage. Authentication data are used solely to maintain secure access, refresh an authorised session and enforce backoffice permissions.
CCI does not use analytics, advertising, behavioural profiling, social-media pixels or other non-essential tracking technologies. Those features must not be enabled without updating this Policy and, where required, obtaining consent.
5. Contact requests and business communications
If you contact us by form, email, telephone or another channel, we process the data you provide, such as your name, company, job title, contact details, message, requested service and related correspondence. We use these data to respond, assess your request, prepare a proposal and manage follow-up communication.
Where you personally request steps before entering into a contract, the legal basis is Article 6(1)(b) GDPR. For general business enquiries or where you act on behalf of a company, the legal basis is Article 6(1)(f) GDPR. Our legitimate interests are responding to enquiries, developing business relationships and documenting professional communications.
If no contract or continuing business relationship results, we delete ordinary enquiry data 6 months after the matter is finally closed, unless the data are needed for a legal claim, a documented objection or a statutory record. Necessary data that become part of a client matter are retained under Section 7 below.
6. Solution configurator
Our solution configurator helps business visitors identify potentially relevant CCI capabilities. It may process your selected objectives, service interests, project context and any contact details or message you submit.
Before submission, configurator inputs are held only in page memory and are discarded when the page or browser session ends. They are not written to server storage, cookies, localStorage or sessionStorage. Data are sent to CCI only when you submit the configurator.
Submitted configurator enquiries are processed on the same legal bases and for the same periods as contact requests under Section 5. The recommendation is non-binding and rule-based. It does not constitute a solely automated decision that produces legal or similarly significant effects within the meaning of Article 22 GDPR.
7. Clients, contracts and invoices
When we prepare or perform a contract, support a client or issue an invoice, we may process:
- names, roles and business contact details;
- company and billing details;
- proposals, Orders, Statements of Work and approvals;
- project communications, tickets and delivery records;
- invoice, payment and transaction information;
- VAT and accounting information; and
- information needed to establish, exercise or defend legal claims.
The legal bases are Article 6(1)(b) GDPR where the data subject is a contractual party or requests pre-contractual steps, Article 6(1)(f) GDPR for B2B contract administration and communication, and Article 6(1)(c) GDPR for legal, tax and accounting obligations, in particular Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB) and Section 14b of the German VAT Act (UStG), as applicable.
We retain only the records required for the applicable purpose:
- contract and claim evidence: until the applicable limitation period expires. The ordinary limitation period is 3 years and generally begins at the end of the year in which the claim arose and the claimant knew or should have known the relevant circumstances; longer periods can apply;
- qualifying commercial or business correspondence: generally 6 years;
- invoices and accounting vouchers: generally 8 years; and
- commercial books, annual financial statements and comparable core accounting records: generally 10 years.
The statutory commercial and tax periods generally begin at the end of the calendar year in which the relevant record was created, the invoice or accounting voucher arose, or the business letter was sent or received. Retention may continue longer while a relevant tax assessment, audit or legal proceeding remains open.
Long-term archives are access-restricted and are not used for unrelated marketing or ordinary CRM activity.
8. Blog and editorial content
Our blog can be read without creating an account. We do not offer public comments under this default configuration. Reading a blog page results only in the website-access processing described in Section 3.
If comments, subscriptions, personalised recommendations or third-party media embeds are introduced, this Policy must be updated before those features are enabled.
9. Invite-only backoffice
Our backoffice is restricted to authorised users. We may process an authorised user's name, work contact details, role, access permissions, authentication metadata, login events and actions recorded in audit logs. We do so to manage access, protect client and financial data, maintain accountability and investigate misuse.
The legal basis is Article 6(1)(f) GDPR, based on our legitimate interests in secure administration, access control and auditability. Where the user is an employee, Section 26 BDSG may also apply. Article 6(1)(b) GDPR applies only where the authorised user personally is party to a contract for which access is required.
Our default retention is:
- account access: disabled promptly upon revocation; the residual profile is deleted or irreversibly anonymised within 30 days;
- authentication and security logs: 90 days;
- ordinary administrative audit records: 12 months; and
- audit records that are actually required as invoice or accounting evidence: for the applicable statutory period.
CCI reviews these retention periods operationally and restricts access throughout the retention lifecycle.
10. Recipients and service providers
We disclose personal data only where necessary. Recipients may include:
- website hosting, content-delivery and infrastructure providers;
- database, authentication, storage, backup and security providers;
- email, communications and document-delivery providers;
- professional advisers, accountants, auditors and insurers;
- payment and banking providers where required for a transaction;
- public authorities, courts or other bodies where disclosure is legally required.
Service providers acting on our instructions are bound by data-processing agreements as required by Article 28 GDPR. They may process data only for documented purposes and must implement appropriate security measures.
The public website runs on CCI's dedicated Sites VPS in Germany. CCI uses Supabase for database, authentication and private file storage, and CCI's SMTP service for contact notifications. Access to these services is restricted to the purposes described in this Policy.
11. International data transfers
Where a service provider processes personal data outside the European Economic Area, CCI requires an applicable transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where required.
12. Retention and deletion
The specific periods stated above are our default schedule. Where no fixed period is stated, we retain personal data only until the relevant purpose has been completed, then delete or irreversibly anonymise it unless a statutory obligation or the establishment, exercise or defence of legal claims requires longer retention.
We process records of privacy-rights requests under Article 6(1)(c) GDPR to meet our GDPR duties and, where necessary, Article 6(1)(f) GDPR for accountability and the establishment, exercise or defence of claims. Those records are normally retained for 3 years after final handling. If consent-based processing is introduced, evidence required to demonstrate consent under Article 7(1) GDPR will normally be retained for 3 years after withdrawal or permanent cessation of the consent-based processing.
If a deleted record remains temporarily in a restricted recovery backup, it is not restored to active use and is removed through the applicable backup lifecycle unless retention is legally required.
13. Security
We use technical and organisational measures appropriate to the risk, which may include encryption in transit, restricted access, role-based permissions, authentication controls, logging, backups, patching and incident-response procedures. No internet transmission or storage system can be guaranteed to be completely secure.
14. Your rights
You have the following rights, subject to the applicable legal conditions:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your data;
- request restriction of processing;
- receive data you provided in a structured, commonly used and machine-readable format and have those data transmitted where technically feasible;
- object to processing based on Article 6(1)(e) or (f) GDPR;
- withdraw consent at any time, without affecting processing carried out before withdrawal; and
- lodge a complaint with a data protection supervisory authority.
To exercise your rights, contact us using the details in Section 1. We may request information reasonably necessary to verify your identity.
15. Right to object
Where we process personal data on the basis of legitimate interests, you have the right to object at any time for reasons arising from your particular situation. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required to establish, exercise or defend legal claims.
16. Supervisory authority
You may complain to any competent data protection authority, including the authority for CCI's registered office:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de/
17. Required information
Fields marked as required in a form are necessary to process the relevant request. Without them, we may be unable to answer an enquiry, prepare a proposal, create an account, perform a contract or issue a compliant invoice. Other fields are voluntary.
18. No solely automated significant decisions
We do not use website or configurator data to make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. If this changes, we will provide the information required by Articles 13 and 22 GDPR before the processing begins.
19. Third-party links
Our website may link to websites operated by third parties. Their processing is governed by their own privacy information. We encourage you to review it before providing personal data.
20. Changes to this Policy
We may update this Policy to reflect changes in our services, technology or legal obligations. The current version and date will always be published on this page. Material changes will be communicated by an appropriate additional method where required.