Data protection

Privacy notice

Last updated: 20 September 2026

This notice explains how personal data is processed when you visit this website or contact Bridgeforge.

1. Controller

Lisa Niestroj, trading as Bridgeforge

Dieblicher Str. 40
56232 Waldesch
Germany

Email: lisa@bridgeforge.eu

2. Website hosting

This website is hosted by Hostinger. When you access the website, Hostinger's infrastructure may process technical connection data such as your IP address, date and time of access, requested resource, referrer, browser, operating system, and response status. This processing is necessary to deliver the website, maintain security, diagnose technical faults, and prevent misuse.

The legal basis is Article 6(1)(f) GDPR. The legitimate interests are the secure, reliable, and efficient operation of the website. Hostinger processes website-visitor data on my behalf under a data-processing agreement. Hostinger may use subprocessors and, depending on the selected services and infrastructure, may process data outside the European Economic Area. According to Hostinger, transfers requiring safeguards are covered in particular by the European Commission's Standard Contractual Clauses.

Technical data is retained only for as long as required to provide and secure the service, meet contractual or statutory requirements, and handle security incidents. Hostinger states that customer data is ordinarily deleted within 30 days after termination of the covered services, subject to service-specific and legal exceptions.

More information: Hostinger privacy policy and Hostinger data-processing addendum.

3. Contact form and email enquiries

If you contact me through the form, I process the information you provide, including your name, email address, company, selected area of interest, and message. The purpose is to review and respond to your enquiry and, where relevant, to take steps before entering into a business relationship.

The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a potential contract or pre-contractual steps. For other business enquiries, the legal basis is Article 6(1)(f) GDPR, based on the legitimate interest in receiving and responding to professional communications.

The website code sends the message to the Hostinger-hosted business mailbox at lisa@bridgeforge.eu and does not intentionally save a separate database copy. Hostinger and its email-delivery subprocessors may process message and connection data for transmission, spam prevention, security, and mailbox operation. Email systems and backups may retain operational copies.

Enquiry data is deleted when it is no longer required for the conversation or business relationship, unless statutory retention duties or the establishment, exercise, or defence of legal claims require longer storage. The information about Hostinger, its subprocessors, and possible international transfers in section 2 also applies to email processing.

4. Recipients and partner introductions

Your contact-form information is not automatically sent to iotasol or another business partner. If an introduction appears appropriate, I will explain the intended recipient and purpose before forwarding personal contact information, unless the forwarding is already clearly requested by you or otherwise legally permitted.

5. Language selection and cookies

When you first visit the website, the language is selected automatically. If the hosting or content-delivery infrastructure supplies a country code, visitors from Germany and Austria are directed to the German version and other visitors to the English version. If no country code is available, the website uses the browser's time-zone setting as a privacy-friendly approximation: Europe/Berlin, Europe/Vienna, and Europe/Busingen lead to the German version; other or unavailable time zones lead to English. No additional external geolocation service is contacted.

If you select a language manually, a technically necessary cookie named bf_lang stores “de” or “en” for up to one year. The cookie prevents your choice from being overwritten by the automatic selection. The legal basis is § 25(2)(2) TDDDG and Article 6(1)(f) GDPR. The legitimate interest is providing the website in the language chosen by the visitor.

6. Analytics and external media

The supplied website does not use analytics, advertising technologies, external web fonts, embedded social-media content, or nonessential cookies. It therefore does not display a consent banner. If any of those technologies are added later, their legal basis, consent requirements, recipients, and retention periods must be assessed and this notice must be updated before deployment.

7. Data security

Technical and organizational measures are used to protect information against accidental loss, unauthorized access, alteration, and disclosure. The website should be served exclusively over HTTPS. No internet transmission can be guaranteed to be completely secure.

8. Your rights

Subject to the applicable legal requirements, you may have the right to:

Where processing is based on consent, you may withdraw that consent at any time for future processing. The current website contact form does not rely on consent as its primary legal basis.

9. Supervisory authority

The competent supervisory authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34
55116 Mainz
Germany
Email: poststelle@datenschutz.rlp.de
www.datenschutz.rlp.de

10. Changes to this notice

This notice should be reviewed whenever the website, hosting arrangement, contact process, third-party integrations, or applicable legal requirements change.