Privacy Policy
Language notice
The German version is the source version of the central privacy information. This English version is provided for information. Mandatory rights under the GDPR and other data protection law remain unaffected.
1. Scope
This privacy policy applies to digital offers, online presences, technical endpoints, media and communication channels and external profiles operated or controlled by Michael Scheibl where the relevant offer links to this policy.
It is designed as a central privacy framework. Only functions and processing operations actually used by a specific offer result in corresponding processing. Additional or more specific privacy notices for a particular offer take precedence within their scope.
2. Controller
Michael Scheibl
Sole proprietor
Vogelherd 5
96224 Burgkunstadt
Germany
Email: contact365@sigruppe.com
Domain, project, product, channel, brand, website, service and system names are used for assignment and are not separate controllers or legal entities unless expressly stated otherwise for a specific offer.
3. Principles and legal bases
Personal data is processed only where a legal basis exists and the processing is necessary for a defined purpose. Depending on the circumstances, relevant legal bases may in particular include consent under Article 6(1)(a) GDPR; pre-contractual steps and performance of a contract under Article 6(1)(b) GDPR; compliance with legal obligations under Article 6(1)(c) GDPR; and legitimate interests under Article 6(1)(f) GDPR.
Legitimate interests may in particular include the secure, stable and economical operation of technical systems, prevention of misuse and attacks, error analysis, business-related communications, organisation of business processes, and establishment, exercise or defence of legal claims. Where special categories of personal data are concerned, processing takes place only where an additional legal basis under Article 9 GDPR applies.
4. Categories and sources of personal data
Depending on use, the data processed may include technical connection and log data, device and browser information, contact and communication data, content data, contractual and offer data, billing and transaction data, support and case data, usage and consent data, and publicly available professional or business information.
Data may be obtained directly from the data subject, automatically through the use of a technical offer, from an existing contractual or communication relationship, from commissioned service providers or platforms, and, where permitted, from publicly available or customary business sources. Where Article 14 GDPR applies, the additional information required by that provision will be provided.
5. Delivery of websites, digital offers and server logs
When a web-based or other network-based offer is accessed, data such as IP address, date and time, requested resource, referrer, browser, device and operating-system information, transfer status, and security or error data may be processed.
The processing serves technical delivery, stability, IT security, error analysis and prevention of misuse. The legal basis is generally Article 6(1)(f) GDPR; where processing is directly necessary to provide a requested contractual digital service, Article 6(1)(b) GDPR may also apply.
6. Technical administration, security and prevention of misuse
For administration, backups, system monitoring, security analysis, access control, update, licence, download, ticket, API or comparable technical functions, necessary access, version, device, event, communication and log data may be processed.
Purposes include integrity, availability, confidentiality, traceability, troubleshooting and the detection and prevention of abusive or unauthorised use. The legal basis is generally Article 6(1)(f) GDPR.
7. Contact, enquiries, offers and pre-contractual communications
When contact is made, the contact, communication and content data provided is processed in order to handle the enquiry, answer questions, prepare offers, conduct pre-contractual communications or manage an existing business relationship.
The legal basis is Article 6(1)(b) GDPR where communication serves the initiation or performance of a contract, and otherwise Article 6(1)(f) GDPR for business-related and administrative communications. Making contact does not automatically conclude a contract; statutory pre-contractual duties remain unaffected.
8. Contracts, services, billing, support and sponsorship
Where a specific offer involves contracts, paid services, digital products, voluntary support, cooperation or sponsorship, identification, contact, contract, performance, billing, payment and transaction data may be processed.
Legal bases include in particular Article 6(1)(b) GDPR for contract performance and pre-contractual steps, Article 6(1)(c) GDPR for statutory retention, tax or evidentiary obligations, and Article 6(1)(f) GDPR for proper business organisation and legal defence. Payment, support or other service providers are involved only where necessary; specific providers are identified where required for transparency or consent.
9. Cookies, local storage and similar technologies
Access to information stored on terminal equipment or the storage of information on terminal equipment is governed by Section 25 TDDDG. Strictly necessary operations may be carried out without consent where the conditions of Section 25(2) TDDDG are met. Non-essential operations are used only after valid consent where consent is legally required.
Where a consent-based technology also processes personal data, the legal basis is generally Article 6(1)(a) GDPR. Consent can be withdrawn or changed at any time with effect for the future through the settings provided. Details are available in the Cookie Settings.
10. External content, embedded services and interfaces
Where a specific offer actually uses external media, maps, fonts, scripts, APIs, analytics, convenience, communication or other third-party functions, data may be transmitted to the relevant provider. Functions requiring consent are activated only after valid consent.
The specific recipients, purposes, legal bases and, where applicable, third-country transfers are explained with the relevant offer, in the consent settings or in supplementary privacy notices. Services that are not used do not result in corresponding processing.
11. External profiles, platforms and communication channels
When external platforms or profiles are used, the respective platform provider processes data under its own responsibility or, where legally applicable, jointly with the operator. This may include profile, interaction, communication, statistics, project or business data.
Where joint controllership under Article 26 GDPR exists or specific platform information is required, the relevant information will be provided with the respective profile or offer.
12. AI-assisted and automated tools
Local or external automation and AI tools may be used for creation, translation, structuring, technical analysis, organisation, support or other workflows. Personal data is processed in such systems only where necessary for the relevant purpose and legally permitted.
When external systems are used, data is minimised or pseudonymised where possible. Confidential, special-category or otherwise unnecessary personal information should not be transferred to external systems without an appropriate legal basis and safeguards.
13. Recipients and processors
Recipients may, where necessary for the relevant purpose, include hosting, infrastructure, IT, security, email, cloud, communication, platform, support, payment, accounting, legal or other professional service providers and competent authorities.
Where service providers process personal data on behalf of the controller, the statutory requirements for processing on behalf of a controller are observed. Disclosure for an independent purpose takes place only on a separate legal basis. Personal data is not sold.
14. Third-country transfers
Where personal data is transferred to recipients outside the European Union or the European Economic Area, this takes place only in accordance with Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision, appropriate safeguards such as standard contractual clauses, or a legally permitted exception in an individual case.
Where a third-country transfer is relevant to a specific service actually used, any additional information required will be provided with that service, in the consent settings or in supplementary privacy notices.
15. Retention
Personal data is retained only for as long as necessary for the relevant purpose. Relevant criteria include the continuation of an enquiry or contractual relationship, technical security and evidentiary needs, statutory retention duties, limitation periods, and the need to establish, exercise or defend legal claims.
When the purpose and legal basis cease to apply and no statutory or legitimate retention grounds remain, data is deleted or anonymised. Fixed retention periods are stated only where they have actually been defined for the relevant processing operation; they may be specified in supplementary notices.
16. Requirement to provide data
For purely public use, active provision of personal data is generally not required, apart from technically necessary connection data. Certain information may be required for enquiries, offers, contracts, payments or statutory records. Without required data, an enquiry may not be answered, a contract may not be initiated or a service may not be provided.
17. Data subject rights
Subject to the statutory requirements, data subjects have in particular rights of access, rectification, erasure, restriction of processing, data portability and withdrawal of consent with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
18. Right to object under Article 21 GDPR
Where processing is based on Article 6(1)(f) GDPR, data subjects may object to the processing at any time on grounds relating to their particular situation. In the case of direct marketing, there is a right to object at any time without the need to provide special reasons. Following a valid objection, processing is stopped to the extent required by law unless overriding compelling legitimate grounds or legal claims apply.
19. Right to lodge a complaint
Under Article 77 GDPR, data subjects have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement.
For the non-public sector in Bavaria, the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, is generally competent. Information on complaints is available at www.lda.bayern.de.
20. Automated decision-making and profiling
No decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR are made within this central legal offer. If a specific offer were to introduce such processing in the future, the legally required specific information would be provided before the processing takes place.
21. Minors and special data
The central offers are not specifically directed at children unless a specific offer expressly states otherwise. Special categories of personal data, confidential information or time-critical emergency information should not be transmitted without necessity and an appropriate communication channel.
22. Data security
Appropriate technical and organisational measures are used to protect personal data, taking account of the relevant risk, against loss, manipulation, unauthorised access and other unlawful processing. Security measures are reviewed and adapted in line with technical and organisational developments.
23. Changes and supplementary notices
This central privacy policy is updated where the legal framework, technical processes or processing operations actually used change materially. Supplementary notices may be required for specific services. New providers or processing operations are not described merely as a precaution as though they were already in use; they are added transparently when actually introduced.
Last updated: 10 August 2026
