Privacy Policy
Effective date: 1 January 2026 · Last updated: 20 August 2026
1. Data Controller
The data controller responsible for the processing of personal data on this website within the meaning of Article 4(7) of Regulation (EU) 2016/679 (hereinafter referred to as "GDPR") is Alfred Rumm Import +Export -Consultancy, Gronauer Weg 37, 67125 Dannstadt-Schauernheim, Germany, reachable via email at info@rumm-impexcon.com. The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data. Any data subject may direct all questions and requests concerning the processing of personal data to the above-mentioned controller at any time, and the controller's identity may be confirmed by contacting the email address provided. The controller has appointed no external data protection officer, as the undertaking falls below the threshold requiring mandatory appointment under Article 37 GDPR in conjunction with Section 38 of the German Federal Data Protection Act (Bundesdatenschutzgesetz, hereinafter "BDSG"). Nevertheless, all inquiries related to this privacy policy and the processing of personal data shall be reviewed and responded to by the controller within a reasonable timeframe not exceeding thirty (30) calendar days from receipt of the inquiry.
2. Scope and Purpose of Personal Data Processing
This website collects and processes personal data of users in order to provide its services and ensure the technical functionality and security of the web presence. The categories of personal data processed include, but are not limited to, the following: when a user submits an inquiry via the contact form, the data provided therein, which typically includes the user's name, email address, the target market of interest, and the content of the message, is collected and stored for the purpose of processing and responding to the inquiry; in addition, when any page of this website is accessed, the server automatically logs certain technical information, including the user's IP address (truncated where possible), browser type and version, operating system, the pages visited and the time and date of each request, the referring URL from which the user navigated to the website, and the amount of data transferred, all of which constitutes server log data. Furthermore, this website uses cookies, which are small text files placed on the user's device, in order to maintain session state, manage user consent preferences, and ensure security through anti-forgery tokens. The legal basis for processing data submitted through the contact form is Article 6(1)(b) GDPR, as the processing is necessary for the performance of pre-contractual measures taken at the data subject's request. The legal basis for the automatic collection of server log data is Article 6(1)(f) GDPR, as the processing is necessary for the legitimate interests of the controller, namely ensuring the security, stability, and proper operation of the website and protecting against unauthorized access and misuse. This website does not intentionally collect or process special categories of personal data as defined under Article 9 GDPR, including but not limited to data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a person, health data, or data concerning a person's sex life or sexual orientation. Server log data is retained for a period of ninety (90) days from the date of collection, after which it is automatically deleted or irreversibly anonymized.
3. Legal Bases for Data Processing
The processing of personal data on this website is conducted in accordance with the provisions of Article 6(1) GDPR, which sets forth the lawful bases for data processing. Article 6(1)(a) GDPR permits processing where the data subject has given consent to the processing of their personal data for one or more specific purposes, and such consent may be withdrawn at any time with future effect. Article 6(1)(b) GDPR permits processing where the processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. Article 6(1)(c) GDPR permits processing where the processing is necessary for compliance with a legal obligation to which the controller is subject under European Union or Member State law. Article 6(1)(d) GDPR permits processing where the processing is necessary in order to protect the vital interests of the data subject or of another natural person. Article 6(1)(e) GDPR permits processing where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. Article 6(1)(f) GDPR permits processing where the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. On this website, the contact form data is processed under Article 6(1)(b) GDPR, as the controller must process the information provided in order to respond to the inquiry and take pre-contractual measures as requested by the data subject. The collection of server log data and the operation of essential cookies are processed under Article 6(1)(f) GDPR, as the controller has a legitimate interest in ensuring the secure and stable operation of the website, preventing abuse, and maintaining the integrity of its systems, and these interests are not overridden by the rights of the data subject given the limited and technical nature of the data collected. Where consent-based processing is required, such as for non-essential analytics or marketing cookies, Article 6(1)(a) GDPR provides the applicable legal basis, and such consent will be sought through the cookie consent mechanism prior to any such processing. The controller may also be subject to legal obligations under German law, including but not limited to the commercial record-keeping requirements of Section 257 of the German Commercial Code (Handelsgesetzbuch, "HGB") and the tax-related retention obligations of Section 147 of the German Fiscal Code (Abgabenordnung, "AO"), which may necessitate the retention of certain personal data for specified periods.
4. Data Sharing and Third-Party Service Providers
The controller does not sell, rent, or otherwise commercially distribute personal data of users to third parties for their own purposes. Personal data is shared with third-party service providers only to the extent necessary for the operation of this website and the fulfillment of the purposes described in this privacy policy, and all such third-party service providers act as data processors within the meaning of Article 28 GDPR. The controller has entered into data processing agreements (Auftragsverarbeitungsverträge) with each processor in accordance with Article 28(3) GDPR, ensuring that the processor provides sufficient guarantees to implement appropriate technical and organizational measures such that the processing complies with the requirements of the GDPR and protects the rights of the data subjects. The current processors engaged by the controller are as follows: Hostinger, which provides web hosting services and server infrastructure, is based in India and processes server log data and website content on behalf of the controller; Microsoft Office 365 SMTP services, which provide email relay functionality for the contact form and general correspondence, are operated within the European Economic Area (EEA) and process the data contained in email communications on behalf of the controller; and Cookiebot A/S, which provides consent management platform services, is based in Denmark (EEA) and processes cookie consent records and related technical data on behalf of the controller. The controller does not transfer personal data to recipients in countries outside the European Economic Area unless adequate safeguards have been implemented in accordance with Chapter V GDPR, including but not limited to standard contractual clauses approved by the European Commission under Article 46(2)(c) GDPR or an adequacy decision adopted by the European Commission under Article 45 GDPR. In the event that personal data is transferred to a third country, the data subject has the right to request information about the specific safeguards in place, including a copy of the relevant contractual arrangements, by contacting the controller at the email address provided in this privacy policy.
5. Cookies and Similar Tracking Technologies
This website uses cookies and similar technologies as defined by the ePrivacy Directive (Directive 2002/58/EC) as implemented in German law by the Telecommunications and Telemedia Data Protection Act (Telekommunikation-Telemedien-Datenschutz-Gesetz, "TTDSG"). Cookies are small text files that are stored on the user's end device when visiting the website and contain information that allows the recognition of the user's device during subsequent visits or enables specific functions and analyses. The controller distinguishes between three categories of cookies: (1) strictly necessary cookies, which are essential for the basic operation of the website and do not require consent under Section 25(2) TTDSG and the ePrivacy Directive, as they serve purposes that are strictly necessary for the provision of the telemedia service explicitly requested by the user; these include the session identifier cookie (session_id), which maintains the user's session state across page loads, the CookieConsent cookie, which stores the user's cookie consent preferences and is required to demonstrate compliance with the consent requirement under Article 7(1) GDPR, and anti-forgery token cookies (CSRF tokens), which protect against cross-site request forgery attacks and are essential for the security of the website; the legal basis for strictly necessary cookies is Article 6(1)(f) GDPR, as the processing is necessary for the legitimate interests of ensuring website functionality and security, and no consent is required under Section 25(2) TTDSG; (2) analytics cookies, which are not currently active on this website, but if implemented in the future, would require the explicit prior consent of the user under Article 6(1)(a) GDPR and Section 25(1) TTDSG before any such cookies are placed or read on the user's device; and (3) marketing cookies, which are also not currently active on this website and would similarly require explicit prior consent. Strictly necessary cookies are retained for the duration of the user's browsing session or for a maximum period of twelve (12) months from the date of placement, after which they are automatically deleted. Users may manage their cookie preferences at any time by accessing the cookie settings dialog, which is accessible via the "Cookie Settings" link in the footer of each page of this website, and through which they may grant, refuse, or withdraw consent for non-essential cookies.
6. Data Retention Periods
Personal data collected through this website is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The specific retention periods applicable to each category of data are as follows: data submitted through the contact form or via email correspondence, including the sender's name, email address, and message content, is retained for a period of up to twenty-four (24) months from the date of the last communication, in order to enable the controller to maintain a complete record of the inquiry and any follow-up communications, and to demonstrate compliance with the data subject's request in the event of a dispute; server log data, including IP addresses, browser information, and access timestamps, is retained for a period of ninety (90) days from the date of collection, after which it is automatically and irreversibly deleted, and this short retention period is sufficient to enable the detection and investigation of security incidents, access anomalies, and technical faults; records of cookie consent, including the timestamp of consent, the specific consents granted or refused, and the version of the consent text presented to the user, are retained for a period of twelve (12) months from the date of the consent action, in order to allow the controller to demonstrate to the competent supervisory authority, upon request, that valid and informed consent was obtained from the data subject, in compliance with the accountability obligation under Article 5(2) GDPR; where personal data is processed in connection with the establishment, exercise, or defense of legal claims or is subject to statutory retention obligations, such data may be retained for the duration of the applicable limitation period or the statutory retention period, which under Section 257 HGB and Section 147 AO may extend up to ten (10) years for certain commercial and tax-related records. Upon expiry of the applicable retention period, personal data is either irreversibly deleted using secure deletion methods or anonymized in such a manner that it can no longer be associated with an identifiable natural person.
7. Rights of the Data Subject
Data subjects whose personal data is processed on this website are entitled to exercise the rights conferred upon them by Chapter III of the GDPR, subject to the conditions and limitations set forth therein. The data subject has the right of access under Article 15 GDPR to obtain from the controller confirmation as to whether personal data concerning them is being processed, and where that is the case, to access the personal data and supplementary information including the purposes of processing, the categories of data concerned, the recipients, the retention periods, and the existence of the right to lodge a complaint. The data subject has the right to rectification under Article 16 GDPR to obtain from the controller without undue delay the correction of inaccurate personal data and the completion of incomplete personal data. The data subject has the right to erasure ("right to be forgotten") under Article 17 GDPR to obtain from the controller the deletion of personal data without undue delay where one of the grounds enumerated therein applies, including where the data is no longer necessary for the purposes for which it was collected, where the data subject withdraws consent and there is no other legal ground for the processing, or where the data subject objects to the processing and there are no overriding legitimate grounds, provided that erasure is not required for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims. The data subject has the right to restriction of processing under Article 18 GDPR where one of the following grounds applies: the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy; the processing is unlawful and the data subject opposes erasure and requests restriction instead; the controller no longer needs the personal data for the purposes of the processing, but the data subject requires it for the establishment, exercise, or defense of legal claims; or the data subject has objected to processing pursuant to Article 21(1) GDPR pending the verification whether the legitimate grounds of the controller override those of the data subject. The data subject has the right to data portability under Article 20 GDPR to receive the personal data concerning them, which they have provided to the controller, in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance where the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) or on a contract pursuant to Article 6(1)(b) and is carried out by automated means. The data subject has the right to object under Article 21 GDPR to the processing of personal data concerning them on grounds relating to their particular situation, where the processing is based on Article 6(1)(e) or Article 6(1)(f), including profiling based on those provisions, and the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing is necessary for the establishment, exercise, or defense of legal claims. Where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to such processing, and the personal data shall no longer be processed for such purposes. The data subject has the right to withdraw consent under Article 7(3) GDPR at any time, without affecting the lawfulness of processing based on consent before its withdrawal. All requests and exercises of rights may be directed to the controller at info@rumm-impexcon.com, and the controller shall respond to legitimate inquiries within thirty (30) calendar days. The data subject also has the right to lodge a complaint with a supervisory authority under Article 77 GDPR, as further described in Section 10 of this privacy policy.
8. Automated Decision-Making and Profiling
This website does not employ any form of automated decision-making within the meaning of Article 22(1) GDPR that produces legal effects concerning the data subject or similarly significantly affects them, nor does it carry out any profiling as defined in Article 4(4) GDPR that results in decisions with legal or similarly significant effects. Automated decision-making refers to a decision made solely by automated means, without any human involvement, which produces legal effects on the data subject or similarly significantly affects them, such as the automatic refusal of an online credit application or the automatic assessment of insurance risks without human intervention. Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. While the website collects limited technical data such as server logs and cookie preferences for operational purposes, none of this data is used to make decisions that produce legal effects or similarly significant effects on the data subject, nor is any automated profiling conducted. In the event that the controller introduces automated decision-making or profiling functionality in the future, the data subject will be informed thereof in a timely manner and in accordance with Articles 13(2)(f) and 14(2)(g) GDPR, including clear information about the logic involved, as well as the significance and envisaged consequences of such processing, and the data subject will be afforded the right to obtain human intervention, to express their point of view, and to contest the decision, as provided under Article 22(3) GDPR.
9. Cross-Border Data Transfers
Some of the third-party service providers engaged by the controller are established outside the European Economic Area (EEA), and the processing of personal data by such providers may therefore involve the transfer of personal data to a third country. The controller ensures that any transfer of personal data to a third country is carried out in compliance with the requirements of Chapter V GDPR. In particular, transfers to third countries for which the European Commission has issued an adequacy decision under Article 45 GDPR are deemed to provide an adequate level of protection, and no additional safeguards are required in such cases. Where no adequacy decision exists, the controller relies on standard contractual clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR as the appropriate safeguard for the transfer, and these SCCs are incorporated into the data processing agreements or data transfer agreements with the respective recipients. The controller also ensures that supplementary technical and organizational measures are in place to protect the transferred data, in accordance with the recommendations of the European Data Protection Board. Where transfers are made to recipients in the United Kingdom, the controller may rely on the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the Information Commissioner's Office under Section 119A(1) of the Data Protection Act 2018, where applicable. The data subject has the right to request, pursuant to Article 15(2) and Article 46(3)(a) GDPR, a copy of the contractual safeguards and standard contractual clauses that have been entered into with data recipients in third countries, by directing a request to the controller at info@rumm-impexcon.com. The controller will provide such information within a reasonable timeframe and in a commonly used electronic format.
10. Right to Lodge a Complaint
Without prejudice to any other administrative or judicial remedy, the data subject has the right to lodge a complaint with a supervisory authority under Article 77 GDPR where the data subject considers that the processing of personal data relating to them infringes the GDPR. The supervisory authority with primary jurisdiction over the controller's establishment is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate), who may be contacted in writing at Postfach 3040, 55020 Mainz, Germany, or via the authority's official website. The complaint may be lodged in any EU Member State in which the data subject has their habitual residence, place of work, or the place of the alleged infringement, regardless of whether the controller is established in that Member State, in accordance with Article 56 GDPR. The right to lodge a complaint does not prejudice any other administrative or judicial remedy, and the data subject retains the right to seek an effective judicial remedy under Article 79 GDPR where they consider that their rights under the GDPR have been infringed as a result of the processing of their personal data in non-compliance with the GDPR. The supervisory authority shall inform the complainant of the progress and the outcome of the complaint, including the possibility of a judicial remedy under Article 78 GDPR.
11. Amendment of This Privacy Policy
The controller reserves the right to amend this privacy policy at any time and without prior notice to the extent necessary to reflect changes in the processing of personal data, changes in applicable law or regulatory guidance, or changes in the services offered through this website. Any amended version of this privacy policy shall become effective upon publication on this website and shall apply to all subsequent visits and the processing of personal data occurring after the date of publication, unless the data subject withdraws their consent or exercises their right to object where applicable. The controller shall not be liable for any failure of the data subject to review the current version of this privacy policy, and it is the responsibility of the data subject to consult this page periodically. Where amendments constitute a material change to the purposes or methods of processing, the controller may, at its own discretion and as a matter of good practice, provide additional notification of the changes, such as a prominent notice on the website or an email notification to known data subjects, although no such notification is required under the GDPR. The date of the most recent amendment to this privacy policy shall be indicated at the top of this page or within the version history of the document, and the data subject is encouraged to review this privacy policy regularly to remain informed about how the controller protects their personal data.
12. Contact for Privacy Matters
For all questions, requests, complaints, or exercises of rights related to this privacy policy and the processing of personal data by the controller, data subjects and interested parties may contact the controller at the following address: Alfred Rumm Import +Export -Consultancy, Gronauer Weg 37, 67125 Dannstadt-Schauernheim, Germany, or via email at info@rumm-impexcon.com. The controller undertakes to respond to all legitimate inquiries within thirty (30) calendar days from the date of receipt of the inquiry, unless a shorter or longer period is specified by the applicable provisions of the GDPR or the BDSG, or where the complexity or number of requests requires an extension, in which case the data subject shall be informed of the extension and the reasons therefor within the initial thirty-day period. Requests may be submitted in writing or electronically, and no specific form is required for the exercise of data subject rights under the GDPR. The controller may request additional information from the data subject to verify their identity before responding to a request, in order to prevent the unauthorized disclosure of personal data to third parties, and any such verification shall be proportionate to the nature of the request and the sensitivity of the data involved.