1
Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Stephan Lachmund, M.Sc.

Engineering practice for contact centre technology · Trading as: CX-Routes

Hansenweg 17, 04838 Doberschütz, Germany

Email: info@cx-routes.com

Phone: +49 3423 6748410

2
Collection and Storage of Personal Data

a) When visiting the website

When you access our website, your browser automatically sends information to our web server. This information is processed only transiently for the purpose of delivering the site. The following information is transmitted automatically:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the requested file
  • Website from which access was made (referrer URL)
  • Browser used and, if applicable, operating system

The data listed above is processed for the following purposes: ensuring a smooth connection to the website, ensuring convenient use of the website, evaluating system security and stability. The legal basis for data processing is Art. 6(1)(f) GDPR.

The website is delivered via the infrastructure of our processor Amazon Web Services (see section 3). Persistent access logging is disabled there: when you merely view the website, the connection data listed above is processed only transiently for technical delivery and is not permanently stored or analysed by us.

This is to be distinguished from the abuse protection of the contact form: only when you submit the form is your IP address processed briefly in pseudonymised form in order to limit the number of submissions. See b) for details.

b) When using the contact form

If you have any questions you can contact us via the form provided on the website. Your name, your company, a valid email address and a project description are required. Further information – phone number, type of enquiry, number of agents and budget range – may be provided voluntarily. Data processing for the purpose of contacting us is carried out pursuant to Art. 6(1)(a) GDPR on the basis of your voluntarily given consent, which you grant explicitly via a checkbox before submitting. You may withdraw this consent at any time with effect for the future; the lawfulness of processing carried out up to the withdrawal remains unaffected.

To protect against automatically generated submissions (spam), the form evaluates three technical details: an additional field that is invisible to you and is only ever filled in by programs, the time at which the page was loaded, and – in order to limit the number of submissions per connection – your IP address. No data is transmitted to third parties and no cookies are set in the process. The legal basis is our legitimate interest in preventing abusive enquiries and in the security of processing pursuant to Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR.

Your IP address is not stored in clear text. Together with a secret additional value it is converted into a string that cannot be reversed (SHA-256); for IPv6 addresses only the network portion is used beforehand. Only this string and a counter are stored – not the content of your enquiry. The entries are deleted automatically no later than 25 hours after they are created (Art. 5(1)(e) GDPR); we are therefore unable to draw any conclusions about your identity. Processing takes place in the Frankfurt am Main region (eu-central-1). If the quota is exceeded, your enquiry is not transmitted and the form displays a corresponding notice; in that case you can always reach us directly by email.

The data you provide will be used exclusively to process your enquiry and will not be used for advertising purposes. Technically, the enquiry is processed by our processor Amazon Web Services and delivered by email to our mailbox, which is operated by our processor ALL-INKL.COM; see section 3 for details on both. No disclosure to third parties within the meaning of Art. 4(10) GDPR takes place.

3
Disclosure of Data

Your personal data will not be transferred to third parties for purposes other than those listed below. We share your personal data with third parties only if:

  • You have given your express consent pursuant to Art. 6(1)(a) GDPR
  • Disclosure is necessary pursuant to Art. 6(1)(f) GDPR for the assertion, exercise or defence of legal claims
  • There is a legal obligation for disclosure pursuant to Art. 6(1)(c) GDPR

Processors and recipients

We use service providers for technical operation who process personal data exclusively on our behalf and on our instructions. Under Art. 4(10) GDPR a processor is not a "third party", but it is a recipient within the meaning of Art. 4(9) GDPR. Data processing agreements pursuant to Art. 28 GDPR are in place with the following providers:

Amazon Web Services (AWS)

Delivery of the website (Amazon S3, Amazon CloudFront) as well as processing and dispatch of enquiries received via the contact form (AWS Lambda, Amazon Simple Email Service) as well as abuse protection for the form (Amazon DynamoDB). Processing of the form data and the email dispatch take place in the Frankfurt am Main region (eu-central-1). Privacy notice: aws.amazon.com/privacy

ALL-INKL.COM – Neue Medien Münnich

Operation of our email mailboxes: receipt, storage and forwarding of messages addressed to us – including enquiries received via the contact form as well as messages sent to info@cx-routes.de, which are forwarded to our mailbox. Provider: owner René Münnich, Hauptstrasse 68, 02742 Friedersdorf, Germany. Privacy notice: all-inkl.com/datenschutzinformationen

Transfers to third countries

Processing of your form data and the email dispatch take place within the European Union; the email mailbox is operated by a provider established in Germany. Amazon CloudFront is a global content delivery network; the purely technical retrieval of static page content may therefore be served from locations outside the EU. Where this involves a transfer to a third country, it takes place on the basis of the Standard Contractual Clauses adopted by the EU Commission pursuant to Art. 46(2)(c) GDPR together with supplementary safeguards. Content submitted via the contact form is not affected by this.

4
Cookies

This website uses no cookies for tracking or advertising purposes. Only technically necessary cookies required for the operation of the website are used (e.g. session management). These cookies are automatically deleted when the browser is closed.

No Google Analytics, no Facebook Pixel, no third-party tracking tools.

5
External Services and CDNs

This website loads the following external resources, which may establish a connection to third-party servers when the page is accessed:

Tailwind CSS CDN (cdn.tailwindcss.com)

CSS framework loaded via the Tailwind CDN. Your IP address may be transmitted in the process.

Font Awesome (cdnjs.cloudflare.com)

Icon library via Cloudflare CDN. Your IP address may be transmitted to Cloudflare when loading. Privacy policy: cloudflare.com/privacypolicy

The font used (Inter) is served from our own server and is not loaded via Google Fonts. No data is therefore transmitted to third parties when the font is loaded.

6
Your Rights as a Data Subject

Under the GDPR you have the following rights regarding your personal data:

Access

Art. 15 GDPR

Rectification

Art. 16 GDPR

Erasure

Art. 17 GDPR

Restriction

Art. 18 GDPR

Data Portability

Art. 20 GDPR

Objection

Art. 21 GDPR

To exercise your rights please contact us by email at: info@cx-routes.com

You also have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. The competent authority is the supervisory authority of the federal state in which you reside.

7
Data Security

We use the widespread SSL procedure (Secure Socket Layer) in conjunction with the highest level of encryption supported by your browser when you visit our website. This is typically 256-bit encryption. Whether an individual page of our website is transmitted in encrypted form can be seen from the closed display of the key or padlock symbol in your browser's status bar.

We also use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties.

8
Currency and Amendments to This Privacy Policy

This privacy policy is currently valid and was last updated in September 2026. The further development of our website and services or changes to legal or regulatory requirements may make it necessary to amend this privacy policy. The current version of the privacy policy can be accessed and printed from the website at any time.

This privacy policy was prepared in accordance with the requirements of GDPR (EU) 2016/679.