Imprint & Privacy

Imprint

IT-Service-Commander
Tom Commander
c/o Online-Impressum.de #2172
Europaring 90
53757 Sankt Augustin
Germany

Economic Identification Number:
DE436306120

Imprint Notice
To protect privacy, an external imprint service is used.
The residence as well as the address for issuing and sending invoices are located in 50181 Bedburg.

Member of the Chamber of Industry and Commerce (IHK) in Germany:


Liability for Content

The contents of these pages were created with the utmost care. However, I cannot guarantee the accuracy, completeness, or timeliness of the content. As a service provider, I am responsible for my own content in accordance with the general laws and pursuant to the German Telemedia Act (Telemediengesetz).

However, I am not obligated to monitor transmitted or stored third-party information or to investigate circumstances indicating illegal activity. Obligations to remove or block the use of information under general laws remain unaffected. Liability is only possible once a concrete legal infringement becomes known. Upon becoming aware of such infringements, I will remove the content immediately.

Liability for Links

My website contains links to external third-party websites over whose content I have no control. Therefore, I cannot assume any liability for such external content. The respective provider or operator of the linked websites is always responsible for their content.

At the time of linking, the pages were checked for possible legal violations; unlawful content was not recognizable. Permanent monitoring of the linked pages is unreasonable without specific indications of a legal violation. Upon becoming aware of such violations, I will remove the links immediately.

Copyright

I always strive to respect the copyrights of others or to use self-created or license-free works.

All content and works created by me on this website are subject to German copyright law. Third-party contributions are marked as such. Any use outside the limits of copyright law requires your written consent or that of the respective rights holder.

Downloads and copies of this page are permitted for private, non-commercial use only.


Privacy Policy (Date: 2026-07-29)

1. General Information

The protection of your personal data is important to me. I process personal data exclusively in accordance with the legal requirements of the GDPR and the BDSG.

This statement explains which data I process, for what purpose, and on which legal basis.

2. Controller

IT-Service-Commander
Tom Commander
Europaring 90
53757 Sankt Augustin
Residential address: 50181 Bedburg
Contact information: see above

3. Principle: No storage of personal data by my own services

For all services I operate myself, the following applies:

  • no server logs are kept
  • no IP addresses are stored
  • no timestamps, device information, or usage data are stored
  • no analysis or profiling takes place
  • connection data is processed only temporarily in RAM and discarded immediately after the connection ends

Thus, no permanent processing of personal data takes place.

4. Data Processing When Visiting This Website

I have configured my website so that no personal data is stored, as far as technically and legally possible.

In particular, no permanent storage of:

  • IP addresses
  • browser data
  • referrer data
  • access times

occurs.

Connection data is processed only temporarily for the duration of technical provision.

5. Contacting Me

If you contact me by email or via a contact form, I process your details solely for handling your request.

Legal basis: Art. 6(1)(b) GDPR.

After your request has been processed, your data will be deleted.

6. WordPress-Related Data Processing

Since this website is based on WordPress, the following processing may occur:

Comments
If you write a comment:

  • your comment is stored
  • WordPress may process your IP address and user agent for security purposes
  • Gravatar may receive a hash of your email address

Cookies
Cookies are only set if technically necessary or if you consent (e.g., when logging in or commenting).

Embedded content
For embedded content (e.g., YouTube, maps, social media), the data protection rules of the respective provider apply.

Cloudflare Turnstile (spam protection)

To protect my forms against abusive automated use (spam, bots), I use the service Cloudflare Turnstile. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.

Turnstile checks in the background whether a form entry is made by a human or generated automatically. For this purpose, Turnstile evaluates technical information about the device and browser used (e.g. IP address, browser information, time spent on the page and interaction behaviour) and transmits this data to Cloudflare. This processing is technically necessary in order to provide the protective function; it therefore constitutes an exception to the principle of data minimisation described above and is limited to spam protection of the forms.

I use Turnstile in invisible mode. No visible security check is therefore displayed. Further information on data processing by Cloudflare in connection with Turnstile can be found in the Turnstile Privacy Addendum: https://www.cloudflare.com/turnstile-privacy-policy/ and in Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/

The legal basis is my legitimate interest in preventing spam and ensuring the security of my forms (Art. 6(1)(f) GDPR).

Transfer to third countries: When using Turnstile, a transfer of personal data to the USA cannot be ruled out. To safeguard such transfers, Cloudflare uses appropriate safeguards pursuant to Art. 46 GDPR, in particular the standard contractual clauses approved by the European Commission.

Rybbit (website analytics)
To improve usability and optimize my website, I use the analytics service Rybbit. This service allows me to understand which areas are frequently visited and how users interact with individual pages.

Evaluation occurs exclusively in aggregated form and without storing personal data such as IP addresses or device identifiers. The analysis helps me improve my website technically and in content.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

7. Security

To protect your data, I use various measures, including:

  • regular server and system updates
  • TLS/SSL encryption of the entire website
  • secure password and key management
  • firewall and access restrictions
  • data minimization: only data technically necessary is processed

Forms are transmitted exclusively in encrypted form.

8. Your Rights

Under the GDPR, you have the following rights:

  • right of access
  • right to rectification
  • right to erasure
  • right to restriction
  • right to data portability
  • right to object
  • right to withdraw consent

Contact for data protection matters: see above (legal notice).

9. Measures in Case of Data Breaches

In the event of a data breach, I will:

  • investigate the incident immediately
  • inform affected individuals (if legally required)
  • initiate protective measures
  • document the incident internally
10. EU Dispute Resolution

The European Commission provides a platform for online dispute resolution (ODR):
http://ec.europa.eu/consumers/odr/

11. Consumer Dispute Resolution

I am not obligated to participate in dispute resolution procedures before a consumer arbitration board.

12. Changes to This Statement

I reserve the right to update this privacy policy in the future.
The current version will always be available on this page.


Some icons on this website were created by Freepik and are subject to the Freepik licence.


AI-powered chatbot

This website provides an AI-powered chatbot that answers questions about my services automatically.

Use of the chatbot is voluntary. The data submitted is used solely to answer the respective enquiry. No automated decision-making producing legal effects within the meaning of Article 22 GDPR takes place.

Purpose of processing

The processing serves to answer visitors’ questions, to provide automated information and to improve the information offered.

Legal basis

The processing is based on my legitimate interest pursuant to Article 6(1)(f) GDPR in answering enquiries efficiently.

Where the chatbot is used in connection with the initiation or performance of a contract, Article 6(1)(b) GDPR applies as an additional legal basis.

What data is processed

The content you enter into the chat window is processed. This primarily means your questions, as well as any further information you choose to provide.

Please do not submit sensitive data through the chatbot, in particular no health data, bank details, access credentials or passwords.

Recipients of the data

An external AI service is used to generate the answers. Your input is transmitted to this service together with an extract of the stored information and processed there to produce an answer. Only what is necessary to generate the answer is transmitted.

The application programming interface (API) of the following provider is used:

OpenAI Ireland Limited
1st Floor, The Liffey Trust Centre
117–126 Sheriff Street Upper
Dublin 1, D01 YC43, Ireland

If this service is temporarily unavailable, the API of the following provider is used instead so that enquiries can still be answered:

Anthropic Ireland, Limited
6th Floor, South Bank House
Barrow Street
Dublin 4, D04 TR29, Ireland

Both providers process the data as processors, acting solely on my instructions. Under the respective terms applicable to the programming interface, the transmitted content is not used to train the AI models.

Transfers to third countries

In both cases the contracting party is a company established in Ireland and therefore within the European Union. In the course of providing the service, the providers may pass data on to affiliated companies outside the European Economic Area, in particular in the United States. In the case of Anthropic, enquiries are processed on infrastructure located in the United States.

For such transfers, the providers rely – in accordance with their data processing terms – on appropriate safeguards pursuant to Article 46 GDPR, in particular the standard contractual clauses adopted by the European Commission, or on an adequacy decision pursuant to Article 45 GDPR.

Record of questions asked

In order to improve the stored information, the questions asked are recorded on the server of this website. The following is stored:

  • the time of the enquiry
  • the wording of the question
  • the language of the enquiry
  • the address of the page on which the chatbot was opened
  • whether an answer was found
  • which AI service generated the answer

No IP address is stored in this process. The record cannot be attributed to a specific person unless you enter personal information into the question yourself.

The records are deleted automatically after 90 days.

If you rate an answer as helpful or not helpful using the buttons provided, this rating is stored together with the question. No further data is collected in this process.

Limiting the number of enquiries

To prevent excessive use, the number of enquiries per visitor is limited. For this purpose your IP address is stored briefly in a form that cannot be reversed (as a checksum). The IP address is not stored permanently.

Storage in your browser

The chatbot stores the following information locally in your browser so that the chat window remains usable as you navigate the site:

  • whether the chat window was open and whether sounds are enabled – stored permanently in local storage until you clear your browser storage
  • the conversation so far in the current browser tab – stored in session storage, which is discarded when the tab is closed

This information remains in your browser and is not transmitted to me. It constitutes storage that is strictly necessary for the function you have expressly requested (Section 25(2) no. 2 TDDDG, the German Telecommunications Digital Services Data Protection Act).

Enquiry via the chat

You can submit an enquiry in the chat window. The following details are requested:

  • your enquiry
  • your name
  • your email address
  • optionally your telephone number

These details are sent to me by email together with the conversation so far, so that your enquiry can be dealt with in context. The message is only sent after you have confirmed the summary.

The legal basis is Article 6(1)(b) GDPR where the enquiry serves the initiation or performance of a contract, and otherwise Article 6(1)(f) GDPR.

On request you will receive a copy of the enquiry at the email address you provided.

Retention periods

Enquiries you have submitted via the chat are retained for as long as is necessary to deal with them or as required by statutory retention obligations.

The record of questions asked is deleted automatically after 90 days.

To reduce the load on the AI services, generated answers are cached on the server of this website for a limited time so that identical questions do not have to be transmitted again.

Notes on use

The chatbot’s answers are generated automatically by artificial intelligence. Despite careful configuration they may be incomplete or incorrect and do not constitute binding information.

Your rights

You have the right to obtain information about the personal data stored about you, as well as the right to rectification, erasure, restriction of processing and data portability in accordance with the statutory provisions.

Where processing is based on a legitimate interest pursuant to Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.

You also have the right to lodge a complaint with a data protection supervisory authority.