Privacy policy

Last updated: October 2026

Thank you for your interest in kabeltrommelsicherung.de. Below we explain, in accordance with the EU General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG), which personal data we process when you visit our website or contact us, for what purposes, and what rights you have. The German version of this policy is legally binding.

Our offer is aimed at business customers. Business contacts also involve personal data, in particular names and business contact details of contact persons.

1. Controller

AAAgiler GmbH
DEDE Industrieausstattung division
Heinrich-Hertz-Str. 6
64295 Darmstadt
Germany

Managing Director: Martin Thöle
Register court: Amtsgericht Darmstadt, HRB 98505

Phone: +49 6151 787 7805
E-mail: info@kabeltrommelsicherung.de

No data protection officer has been appointed. For all data protection questions and to exercise your rights, please use the e-mail address above.

2. Hosting and server log files

Our website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, on servers in Germany. STRATO provides the technical infrastructure for the website, database and e-mail delivery and processes personal data on our behalf under Art. 28 GDPR.

When you access the website, the following data in particular are processed for technical reasons: IP address, date and time of access, page or file requested, amount of data transferred and HTTP status code, browser type and version, operating system and referrer URL (if transmitted). This serves to provide the website, ensure stability and security, analyse errors and fend off attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation). Access logs are kept by the host for no more than six weeks and then deleted automatically, unless individual data are needed to investigate a specific security incident.

3. Enquiries and contact

If you use our enquiry form, we process your details to handle your enquiry, check the suitable cable drum protection, advise you and prepare and follow up a quotation: name and company, e-mail and phone, industry, number, diameter, flange rim width and weight of the drums, ground conditions, requested products, delivery location and date, and your message. Required fields are marked; without them we cannot process your enquiry, or only to a limited extent.

Where the enquiry relates to a contract with you, the legal basis is Art. 6(1)(b) GDPR. For contact persons of business customers, processing is based on Art. 6(1)(f) GDPR (legitimate interest in handling business enquiries).

The form uses the WordPress plugin Contact Form 7. Enquiries are additionally stored in the WordPress database on our web server using the Flamingo plugin so that no enquiry is lost if e-mail delivery fails. E-mails are sent via WP Mail SMTP and STRATO’s mail server. Only staff handling the enquiry have access.

Enquiries that do not lead to an order are deleted from the database and our mailbox no later than six months after the last business contact. If a business transaction results, correspondence is retained in line with statutory obligations (business letters six years, accounting records eight years, certain other documents up to ten years; Section 257 German Commercial Code, Section 147 German Fiscal Code; Art. 6(1)(c) GDPR). The same applies to contact by e-mail or phone.

4. Protection against spam and attacks

Antispam Bee checks form submissions locally on our server for spam; no data are sent to third parties (Art. 6(1)(f) GDPR).

Wordfence Security (Defiant, Inc., 1700 Westlake Ave N, Suite 200, Seattle, WA 98109, USA) protects the website against attacks, malware and unauthorised logins. It processes IP addresses, time and type of access, URLs, browser and connection data and information on failed logins and detected attacks on our server. Logging is limited to security-relevant events; these logs are deleted after 30 days. To update firewall rules and compare against known attackers, IP addresses of suspicious or blocked requests are transmitted to Defiant, which may involve a transfer to the USA. Defiant provides a Data Processing Addendum with EU Standard Contractual Clauses under Art. 46(2)(c) GDPR (wordfence.com/data-processing-addendum); you can request a copy from us. Legal basis: Art. 6(1)(f) GDPR.

5. Cookies

Storing information on your device and accessing it is governed by Section 25 TDDDG. We only use cookies that are strictly necessary for functions you request (Section 25(2) no. 2 TDDDG); we do not use advertising, analytics or tracking cookies. Any related processing of personal data is based on Art. 6(1)(f) GDPR.

  • pll_language (Polylang): stores the selected language version, content: language code, lifetime: one year.
  • WordPress and Wordfence login cookies: only set for logged-in administrators, not for regular visitors.

We use the Complianz plugin to maintain this policy. Should a privacy settings dialog be shown in future, Complianz stores your choice in cookies prefixed cmplz_ for up to twelve months. You can delete or block cookies in your browser at any time.

6. Product images from dede-industrieausstattung.de

Some product images are loaded directly from the server of our online shop www.dede-industrieausstattung.de, which is also operated by AAAgiler GmbH (same controller). Your browser transmits technically necessary connection data, in particular your IP address, the requested file and possibly the referrer URL. Purpose: display of our products; legal basis: Art. 6(1)(f) GDPR.

7. WordPress, local fonts and technical plugins

The website runs on WordPress with the Kadence theme. Fonts are served locally from our server; no connection to Google Fonts or other font servers is made. The plugins WP Super Cache (page caching), Yoast SEO (search engine information), a WebP converter (image optimisation) and Polylang (language versions) work on the server side only and are not used for tracking (Art. 6(1)(f) GDPR).

8. Backups

We use UpdraftPlus for backups. Backups contain the WordPress database including stored enquiries and are kept on our web space at STRATO in Germany; no external cloud storage is used. The two most recent backups are kept; older ones are deleted automatically (Art. 6(1)(f) GDPR).

9. Recipients and transfers to third countries

Within our company, only persons who need the data for their tasks have access. External recipients: STRATO GmbH (hosting and e-mail, processor), Defiant, Inc. (Wordfence, see section 4) and, where necessary in individual cases to check technical requirements or prepare a quotation, manufacturers and suppliers, to whom we disclose only the data required. Transfers outside the EU/EEA occur only in connection with Wordfence.

10. No analytics or advertising services

We do not use analytics, tracking or advertising services – no Google Analytics, no advertising pixels, no social media plugins and no newsletter.

11. Your rights

Subject to the legal requirements, you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21, see section 12), withdrawal of consent with effect for the future (Art. 7(3)) and to lodge a complaint with a supervisory authority (Art. 77). Under Art. 19 GDPR you may also ask to be informed about recipients. An e-mail to info@kabeltrommelsicherung.de is sufficient.

12. Right to object under Art. 21 GDPR

Where we process your personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where your data are processed for direct marketing, you may object at any time without giving reasons; your data will then no longer be used for this purpose.

13. Supervisory authority

You may lodge a complaint with any supervisory authority, in particular in your country of residence or work. The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7
65185 Wiesbaden, Germany
Phone: +49 611 1408-0
E-mail: poststelle@datenschutz.hessen.de

14. No automated decision-making

We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR. The product selection tool runs entirely in your browser, stores no input and is for guidance only.

15. Data security and changes

Connections to our website are encrypted using TLS (HTTPS). We protect personal data with appropriate technical and organisational measures. We will update this policy if our processing or the legal situation changes; the version published here applies.