Q01Who is responsible for my data here?

The controller within the meaning of Article 4(7) GDPR is:

HOFAL GmbH
Götzenbergstr. 2
70329 Stuttgart, Germany
Phone: +49 151 73829461

These answers apply to anyone visiting this website and to anyone who gets in touch with us through the brief form, by phone or by email.

Q02What do you actually record about me?

Only three kinds of information, and only as much as an enquiry needs:

  • What you type into the brief form — name, company, phone number, an email address if you choose to add one, the service you picked and your description of the project.
  • What your browser sends automatically — the type of device and browser, an IP address from which a rough location can be inferred, and the pages you opened.
  • What you tell us later — anything you share by phone or email while we talk through a possible project.

The floor plan and the sector tabs on the home page are just navigation. Clicking them changes what you see and is not recorded anywhere.

We never take card payments on this site, and the form will never ask you for a password or an ID document.

Q03What is it used for?
  • To reply to you and put together an estimate or proposal.
  • If we end up working together, to run that contract — correspondence, planning and invoicing.
  • To keep the site online, protect it against misuse, and see which parts of it are useful.
  • To meet the record-keeping duties German commercial and tax law places on us.

Your data is not sold, and it is not used for advertising by us or by anyone else.

Q04On what legal ground?

Each use above rests on Article 6(1) GDPR together with the Federal Data Protection Act (BDSG):

  • Consent (point a) — when you send the brief form.
  • Contract (point b) — steps you ask us to take before a contract, and carrying it out afterwards.
  • Legal obligation (point c) — statutory retention of business records.
  • Legitimate interest (point f) — running a secure, working website.
Q05What happens when I simply open a page?

The site is served by an external hosting and content-delivery provider. Its servers automatically note technical details of each request — IP address, date and time, the page requested, the referring page and the browser identifier. Without this the page could not be delivered or defended against attacks, which is why it relies on Article 6(1)(f) GDPR. These logs are kept for a short period only and are not linked with anything else to work out who you are.

Q06How long do you keep it?

If an enquiry doesn't turn into a project, we delete it after at most twelve months — long enough to pick the conversation back up if you return.

If it does become a project, we keep what relates to it while we work together and then for as long as the Commercial Code (HGB) and Fiscal Code (AO) require: six or ten years, depending on the type of record.

Q07Does anyone else get to see it?

Nobody receives your data for their own purposes. A few service providers handle it on our instructions, and only to the extent they need to:

  • the hosting and content-delivery provider, including its protection against attacks;
  • the service that receives the brief form and forwards it to us;
  • the email and project-management tools our team works in;
  • our tax advisers, and authorities where a law obliges us to disclose.

Every one of these providers is bound by a processing agreement under Article 28 GDPR.

Q08Does my data leave the EU?

It can, because some technical providers operate servers outside the European Economic Area. When that happens, the transfer is covered either by an adequacy decision of the European Commission or by Standard Contractual Clauses under Article 46 GDPR, so the protection travels with the data.

Q09Are there cookies?

Only the ones the site cannot work without. Under Section 25(2) TDDDG those need no consent. If we ever add analytics or anything else non-essential, it will stay switched off until you agree to it, and this page will be updated first.

Q10What can I ask of you?

Articles 15 to 21 GDPR give you the right to:

  • ask whether we hold data about you, and get a copy of it;
  • have anything wrong corrected;
  • have data deleted once there is no longer a reason to hold it;
  • limit how we use it, or object to use based on our legitimate interest;
  • receive it in a structured, machine-readable format;
  • withdraw consent at any time — which does not undo the lawfulness of what happened before.

Just contact us using the details under Q01.

Q11Who can I complain to?

You can turn to any data protection supervisory authority, in particular the one where you live or work. The authority responsible for our office is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg), based in Stuttgart.

Q12How is it protected?

We take the measures Article 32 GDPR asks for: every connection is encrypted (TLS/HTTPS), only the people who need enquiries can see them, and the systems we run are kept up to date. We won't pretend any transfer over the internet is perfectly safe — but we do what can reasonably be done.

Q13Is this site meant for children?

No. It is aimed at businesses, and we don't knowingly collect data from anyone under 16.

Q14Will these answers change?

When our processes or the law change, so will this page. The "last revised" date at the top always shows the current version, and any significant change will be pointed out here.