Privacy
Privacy Policy
The protection of your personal data is important to us. This policy explains which data are processed when you visit our website or contact us.
1. Privacy at a glance
General information
Personal data are any information relating to an identified or identifiable natural person, for example a name, email address, IP address or information voluntarily provided in a message.
When you visit this website, technically necessary access data may be processed. If you use our contact form or send us an email, we additionally process the information you provide in order to respond to your enquiry and, where applicable, to take steps prior to entering into a contract or to perform a contract.
2. Controller
The controller responsible for data processing on this website is:
HEIDEL I & E e.K.
Owner: My Linh Heidel
Moltkestraße 33
58332 Schwelm
Germany
Email: info@heidelie.de
3. Hosting and server log files
This website is hosted through united-domains. In the course of providing the website, the hosting provider may process technical data in server log files. These may include the requested page or file, date and time of access, amount of data transferred, referrer URL, browser type and version, operating system, IP address and the requesting provider.
The processing is necessary to deliver the website securely and reliably, to detect technical errors and to prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient operation of our website.
Further information on the provider's processing can be found in the privacy information made available by united-domains.
4. SSL/TLS encryption
This website uses SSL or TLS encryption to protect the transmission of confidential content. You can recognise an encrypted connection by the address line beginning with “https://” and, depending on your browser, by a lock symbol.
Please note that data transmission over the internet can never be guaranteed to be completely secure.
5. Contact form via FormSubmit
Our contact form is technically processed through FormSubmit. When you submit the form, the data entered by you, such as your name, company, email address, subject, selected business area and message, are transmitted for the purpose of forwarding the enquiry to us.
The processing is based on Article 6(1)(b) GDPR where your enquiry relates to a possible or existing business relationship. In other cases, it is based on Article 6(1)(f) GDPR. Our legitimate interest is the efficient handling of enquiries addressed to us.
FormSubmit may process technical information required to provide and secure the service. Depending on the technical routing and the service provider used, data may also be processed outside the European Economic Area. In such cases, the requirements of Articles 44 et seq. GDPR apply.
Please do not transmit particularly sensitive information through the contact form unless this is necessary and has been agreed with us in advance.
6. Contact by email
If you contact us by email, we process the data contained in your message, including contact details and any attachments, in order to respond to your enquiry. The same legal bases apply as for contact form enquiries.
Email communication may involve unavoidable technical risks. For confidential information, please contact us first so that a suitable transmission method can be agreed.
7. Legal bases for processing
Depending on the purpose, we process personal data on the following legal bases:
- Article 6(1)(a) GDPR: consent;
- Article 6(1)(b) GDPR: steps prior to entering into a contract and performance of a contract;
- Article 6(1)(c) GDPR: compliance with legal obligations;
- Article 6(1)(f) GDPR: legitimate interests, in particular secure website operation, communication and the assertion or defence of legal claims.
8. Recipients, processors and international transfers
Personal data are only disclosed where this is necessary, legally permitted or required. Potential recipients include hosting and IT service providers, email providers, FormSubmit, professional advisers and public authorities where legally required.
Where service providers process data on our behalf, they are engaged in accordance with Article 28 GDPR where applicable. Transfers to countries outside the European Economic Area take place only if the requirements of Articles 44 et seq. GDPR are met, for example on the basis of an adequacy decision, standard contractual clauses or another legally recognised safeguard.
9. Retention periods
We store personal data only for as long as required for the relevant purpose or for as long as statutory retention obligations apply. Contact enquiries are generally deleted after final processing unless a business relationship, statutory retention obligation, limitation period or need for legal defence requires longer storage.
Commercial and tax documents may be subject to statutory retention periods. Technical log data are normally retained only for the period required for security, error analysis and abuse prevention.
11. Your rights
Subject to the statutory requirements, you have the following rights:
- right of access under Article 15 GDPR;
- right to rectification under Article 16 GDPR;
- right to erasure under Article 17 GDPR;
- right to restriction of processing under Article 18 GDPR;
- right to data portability under Article 20 GDPR;
- right to object under Article 21 GDPR;
- right to withdraw consent at any time with effect for the future under Article 7(3) GDPR.
To exercise your rights, contact us at info@heidelie.de. We may request appropriate proof of identity to prevent unauthorised disclosure.
Right to object
Where processing is based on Article 6(1)(e) or (f) GDPR, you may object at any time on grounds relating to your particular situation. We will then cease the processing unless compelling legitimate grounds override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
12. Right to lodge a complaint
If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority. The supervisory authority responsible for our registered office is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
www.ldi.nrw.de
13. Updates and changes
We may update this privacy policy if legal requirements, technical functions, service providers or our processing activities change. The version published on this website at the time of your visit applies.
Last updated: July 2026
Our legal notice is available on the contact page.