+49 151 7392 6848

Legal · Datenschutzerklärung

Privacy Policy

What happens to your personal data when you visit this website or get in touch with Krüger GmbH, explained in the order you are likely to ask.

In force since 7 October 2026

The short version

  • We use your details to answer you and to carry out projects, nothing else.
  • We do not sell data and we do not run advertising trackers.
  • You can ask to see, correct or delete your data at any time.

Who is responsible

The controller within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:

Krüger GmbH
In der Schwarzerde 5-7
65549 Limburg, Germany
Phone: +49 151 7392 6848

This policy applies to visitors of this website and to anyone who contacts us through the brief form, by phone or by email.

What we collect

When you send the brief form or contact us
Name, company, phone number, email address (optional), the service you are interested in and the text of your message.
When you become a client
Contact details of the people involved, project correspondence, contract and invoicing records.
When you simply browse
Our hosting provider records technical data such as IP address, date and time, requested page, browser type and referrer, in server logs.

The wheel on our home page and the other interactive elements work only inside your browser. What you do with them is not sent to us.

Why we may

  • Answering enquiries and preparing proposals: Art. 6(1)(b) GDPR (steps before a contract) and, for the form, Art. 6(1)(a) (your consent).
  • Carrying out projects: Art. 6(1)(b) GDPR.
  • Bookkeeping and tax duties: Art. 6(1)(c) GDPR.
  • Running and securing the website: Art. 6(1)(f) GDPR, our legitimate interest in a stable and attack-resistant site.

You are not obliged to give us your data, but without it we cannot answer your request.

Who receives it

Nobody gets your data to use for their own purposes. We pass it only to service providers who work on our instructions under a data processing agreement (Art. 28 GDPR):

  • the hosting and content-delivery provider, including its protection against attacks;
  • the service that receives the brief form and forwards it to us;
  • the email and project-management tools our team works with;
  • our tax adviser, and public authorities where the law requires disclosure.

Transfers abroad

Some providers operate servers outside the European Economic Area. Where data is sent there, we rely on an adequacy decision by the European Commission or on the Standard Contractual Clauses under Art. 46 GDPR, supplemented by technical safeguards where needed.

Cookies

This site only uses storage that is strictly necessary for it to work. Under § 25(2) of the Telecommunications Digital Services Data Protection Act (TDDDG) this needs no consent. If we ever add analytics or other optional tools, they stay off until you agree, and this page is updated first.

How long we keep it

  • Enquiries that do not lead to a project: deleted after 12 months at the latest.
  • Client records: for the duration of the project, then for as long as statutory retention applies, generally six years for business correspondence (§ 257 HGB) and up to ten years for accounting records (§ 147 AO).
  • Server logs: kept for a short period only and not combined with other data.

Your rights

  • Access (Art. 15): confirmation and a copy of your data.
  • Rectification (Art. 16): correction of inaccurate data.
  • Erasure (Art. 17): deletion once there is no reason to keep it.
  • Restriction (Art. 18): limited use while a dispute is being clarified.
  • Portability (Art. 20): your data in a structured, machine-readable format.
  • Objection (Art. 21): against processing based on our legitimate interest.
  • Withdrawal of consent (Art. 7(3)): at any time, with effect for the future.

To use any of these, write or call us using the details in section 01.

Complaints

You may complain to any data protection supervisory authority. For us, the competent authority is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Wiesbaden.

Security

Connections to this site are encrypted with TLS. Access to enquiries is limited to the people who need it, and the systems we run are kept up to date in line with Art. 32 GDPR. No transmission over the internet is entirely risk-free, and we do not claim otherwise.

Children

Our services are aimed at businesses. We do not knowingly collect data from anyone under 16.

Changes

If our practices or the law change, we update this page. The date at the top always shows which version is current.