Privacy Policy
1. General Information
The protection of personal data is important to us. This Privacy Policy explains which personal data is processed when you visit our website, for what purposes this data is processed, on which legal basis the processing takes place, and which rights data subjects have.
Personal data means any information relating to an identified or identifiable natural person, such as a name, email address, IP address, communication data or image data. This Privacy Policy is intended to fulfil our information obligations under Article 13 GDPR.
2. Controller
The controller responsible for data processing on this website is:
Rollsberg GmbH Siemensstrasse 53b 25462 Rellingen Deutschland
E-Mail: sales@rollsberg.de Telefon: +49 (0)4101 519978 -0
3. No Data Protection Officer Appointed
We are not legally required to appoint a Data Protection Officer. For any questions regarding data protection, you may contact us at any time:
Rollsberg GmbH Siemensstrasse 53b E-Mail: sales@rollsberg.de
4. Hosting and Technical Provision of the Website
Our website is hosted by Hetzner and operated technically via a Docker/Node.js environment. The website is based on Next.js/React and is generally designed as a presentational website. There are no user accounts, no authentication and no login function. We do not operate a general server-side database for storing user data.
The hosting provider is Hetzner Online GmbH, Germany. Where required, a data processing agreement pursuant to Article 28 GDPR is concluded and managed via the Hetzner account.
When the website is accessed, technically necessary connection data is processed so that the website can be displayed in your browser. This may include IP address, date and time of access, requested URL, referrer URL, amount of data transferred, browser type and version, operating system, user agent and HTTP status codes.
No server access log files are written at application level. The Next.js application only logs error messages to stdout; personal access data is not recorded there. Where access data is logged at server or web server level, in particular on the Hetzner host or in Caddy access logs, this is done for technical provision, security, error analysis and abuse prevention.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our website.
Storage period: No personal access data is permanently stored at application level. Any server or web server logs on the Hetzner host are stored only for as long as necessary for technical security, error analysis and documentation purposes and are then deleted or anonymised. Specifically, the web server’s access and error logs are retained for 7 days by default, mail server logs for 7 days, and backups are kept in encrypted form for 14 days.
5. Data Storage and Data Collection on the Website
As a general rule, our website does not store user data server-side in a database. There are no user accounts and no login function.
Users may send us enquiries via the contact form. The personal data entered there is transmitted exclusively by email via our standard Microsoft 365/Outlook mailboxes to the responsible recipients. The contents of the contact form are not otherwise stored on the website, in a website database, queue or form backend. Incoming contact form emails are subsequently stored, processed and, after processing, archived or deleted in the Microsoft 365/Outlook mailbox like regular business emails, unless statutory retention obligations apply.
For abuse and spam prevention, the IP address is processed when the contact form is used only transiently in the application server’s memory for rate-limit checks. The rate limit is a maximum of 5 requests per 60 seconds per IP address. The IP address is not stored permanently and is automatically discarded after the time window has expired or, at the latest, when the container is restarted.
No personal data is stored in localStorage or sessionStorage.
6. Contact Form
We provide a contact form on our website through which you can send us specific enquiries regarding products, engines, spare parts, services or other matters.
When you use the contact form, we process the data you enter in order to handle your enquiry. This includes in particular name/contact person, company, email address, area of application, IMO number, engine manufacturer, engine type, serial number, the content of your enquiry, date and time of the enquiry and technical metadata where necessary.
The data entered in the contact form is sent directly via Rollsberg’s standard Microsoft 365/Outlook environment by SMTP. Transmission takes place with TLS encryption via smtp.hve.mx.microsoft, port 587, from contactform@rollsberg.de. Depending on the selected area of application, the recipients include sales@rollsberg.de or lorange@rollsberg.de. No additional external sending service provider such as SendGrid, Mailgun or a comparable service is involved.
The contents of the contact form are not stored on the website, in a website database, queue or form backend. The IP address is processed only transiently in memory for rate-limit checks and is not permanently stored.
Purpose of processing: The purpose is to receive, review, technically classify and respond to your enquiry and, where applicable, to prepare or perform a contractual relationship. The rate-limit check serves technical security and abuse prevention.
Legal basis: Article 6(1)(b) GDPR where your enquiry is aimed at entering into or performing a contract. In all other cases, Article 6(1)(f) GDPR.
The recipients of the data are the internally responsible employees. The technical recipient in connection with email sending and receiving is Microsoft Ireland Operations Ltd. or Microsoft Corporation for the Microsoft 365 infrastructure. Data is only passed on to further external third parties if this is necessary to process your enquiry, if you have given your consent, or if there is a legal obligation to do so.
Storage period: Contact form enquiries are not stored on the website, but are processed in the standard Microsoft 365/Outlook mailbox like regular incoming business emails. They are stored there, processed and, after processing, archived or deleted unless statutory retention obligations apply. Business-related or contract-related communication may be stored for a longer period due to commercial or tax law retention obligations. SMTP sending logs are processed according to Microsoft’s standard retention periods in the respective tenant.
7. Contact by Email or Telephone
If you contact us outside the contact form by email or telephone, we process the personal data you provide, such as your name, email address, telephone number, company, the content of your enquiry and communication metadata. The purpose is to process and respond to your enquiry. The legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. The data will be deleted as soon as it is no longer required, unless statutory retention obligations apply.
8. Cookies and Similar Technologies
Our website uses cookies and similar technologies only where they are technically necessary or where users have given prior consent. You can give, refuse or later change your consent via our consent management tool. Before consent is given, the relevant Consent Mode states for analytics, advertising and personalisation are disabled. security_storage remains enabled; ads_data_redaction is enabled and url_passthrough is disabled.
9. Consent Management with Cookiebot
We use Cookiebot by Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark, to manage consent for cookies and similar technologies. Cookiebot has been acquired by Usercentrics; according to the information available to us, the contractual relationship relevant for the data processing agreement continues to run via Cybot A/S.
The Cookiebot ID currently integrated in production is: bce156aa-6461-49cf-b890-ec06dd1e9327.
Cookiebot processes information about the consent status and anonymised browser information. The purpose is to obtain, manage and document consent and to legally control services that require consent. The legal basis is Article 6(1)(c) GDPR and Article 6(1)(f) GDPR. No consent is required for Cookiebot itself.
Storage period: Cookiebot consent logs are stored for 12 months according to the Cookiebot standard.
10. Google Analytics 4
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us understand how visitors use our website so that we can improve our content and user experience.
Google Analytics 4 is activated only after prior consent has been given via Cookiebot. The measurement ID used is G-4YCSV6NC55. The retention period for event and user data in Google Analytics is set to 2 months.
Google Consent Mode v2 is implemented in the code with a defensive default state. ad_storage, ad_user_data, ad_personalization and analytics_storage are set to “denied” by default until consent is given. ads_data_redaction is enabled and url_passthrough is disabled.
No ads, remarketing, retargeting, conversion or Google Ads functions are activated in the code. Google Analytics is used exclusively for reach measurement and usage analysis.
As part of Google Analytics 4, page views, click events, navigation clicks, contact button clicks, language switch events, legal link clicks, PDF downloads, external link clicks, technical browser and device information and usage data may be processed.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and, where cookies or similar technologies are involved, Section 25(1) TDDDG. Data may be transferred to Google LLC in the United States on the basis of the applicable data protection instruments, in particular the EU-US Data Privacy Framework and/or standard contractual clauses.
11. Locally Provided Draco Decoder
Our website uses the Draco Decoder to decompress 3D model data. The Draco Decoder is not loaded from Google servers but is stored locally in the repository under /draco/ and delivered as static files from the same origin as the website. This includes draco_decoder.js, draco_decoder.wasm and draco_wasm_wrapper.js. No connection to Google servers via www.gstatic.com takes place for the Draco Decoder.
12. BunnyCDN
We use BunnyCDN, a service of BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia, as a pull zone in front of the origin server for the fast and secure delivery of static website content. BunnyCDN delivers images, JavaScript, CSS, the locally provided Draco Decoder, GLB models and KTX2 textures.
When content is retrieved, BunnyCDN processes IP address, user agent, referrer, requested URL, timestamp, HTTP status and transfer volume. The purpose is the delivery of website content, performance optimisation and technical security. The legal basis is Article 6(1)(f) GDPR. No consent is required for the technically necessary delivery of content via BunnyCDN.
Storage period: The log file retention period at BunnyCDN is 3 days by default.
13. Self-Hosted Fonts
The fonts Manrope and JetBrains Mono are self-hosted on our website. No external font services are integrated.
14. External Links
Our website may contain links to external websites or services, such as Google Maps, email addresses or telephone numbers. Google Maps is not used as an embedded map service, but only as an external link. When you click on an external link, you leave our website.
15. PDF Downloads
PDF documents may be downloaded from our website, for example terms and conditions or AGE documents. When a file is downloaded, technically necessary access data is processed. If you have consented to Google Analytics, the download may also be recorded as an event in Google Analytics.
16. Employee Photos and AI-Assisted Image Editing
Photos of employees may be published on our website. Some employee photos have been visually edited after being taken using AI-assisted image editing processes. The editing may relate to background, clothing, colours, lighting and general visual appearance. The AI-assisted editing is used exclusively for a uniform, professional and brand-consistent presentation on the website.
Data processed: Image data of the employees shown. Purpose: public relations, company presentation and uniform visual design. Legal basis: consent pursuant to Article 6(1)(a) GDPR or, in individual cases, Article 6(1)(f) GDPR. Consent may be withdrawn at any time with effect for the future.
17. Services Not Used
According to the technical specifications, no error tracking or monitoring, newsletter or email marketing services, social media embeds, video embeds, embedded maps, chat widgets, A/B testing, payment processing, device fingerprinting, geolocation detection, session recording, heatmaps, advertising networks or retargeting are used on the website.
18. Security Measures
We implement technical and organisational measures to protect personal data. The website uses in particular HSTS, a strict Content Security Policy with allowlist, Referrer-Policy, Permissions Policy, X-Frame-Options: DENY and X-Content-Type-Options: nosniff.
19. Legal Bases for Processing
Depending on the processing activity, we rely in particular on Article 6(1)(a), Article 6(1)(b), Article 6(1)(c), Article 6(1)(f) GDPR and Section 25 TDDDG.
20. Recipients of Personal Data
Personal data may be transferred, where necessary, to internal employees, Hetzner Online GmbH (Germany) as hosting provider, Cybot A/S / Usercentrics (Denmark) as consent management provider, Google Ireland Limited / Google LLC (Ireland/USA) in connection with Google Analytics 4 after consent, BunnyWay d.o.o. (Slovenia) as CDN provider, Microsoft Ireland Operations Ltd. / Microsoft Corporation (Ireland/USA) in connection with Microsoft 365 email infrastructure, and authorities or other bodies where there is a legal obligation. According to the current production status, no further technical service providers are integrated. In particular, the Draco Decoder is provided locally and is not loaded via Google/gstatic.
21. Transfers to Third Countries
Personal data is transferred to countries outside the EU or EEA only where there is an appropriate legal basis. This may be the case in particular with Google Analytics 4 and Microsoft 365 where data is transferred to affiliated companies or technical infrastructure in the United States. Such transfers take place only on the basis of an adequacy decision, appropriate safeguards, standard contractual clauses or explicit consent.
22. Storage Period
We store personal data only for as long as necessary for the respective purposes or as required by statutory retention obligations.
- Server log files: No personal server access log files are written at application level. Any Caddy access logs or server-side logs are processed on the Hetzner host. The specific retention period must be added in the red-marked section 4.
- Contact form data: No storage on the website, in a website database, queue or form backend. Contact form enquiries are stored and processed in the standard Microsoft 365/Outlook mailbox like regular incoming business emails and, after processing, archived or deleted unless statutory retention obligations apply.
- SMTP sending logs: Processed in Microsoft 365 according to Microsoft’s standard retention periods in the respective tenant.
- Cookiebot consent logs: 12 months according to the Cookiebot standard.
- Google Analytics 4 event and user data: 2 months.
- BunnyCDN logs: 3 days by default.
23. Obligation to Provide Personal Data
The provision of personal data is generally neither legally nor contractually required. However, certain information is required for the contact form so that we can process your enquiry.
24. Automated Decision-Making and Profiling
Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place on our website.
25. Rights of Data Subjects
Data subjects have the rights of access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent and complaint to a supervisory authority under the GDPR. You may contact us at any time to exercise your rights.
26. Right to Object under Article 21 GDPR
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.
27. Withdrawal of Consent
Where processing is based on your consent, you may withdraw this consent at any time with effect for the future. You can change your cookie and tracking settings at any time via the “Cookie Settings” link in the website footer.
28. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
The competent authority may in particular be the data protection supervisory authority of the federal state in which our company has its registered office:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein Holstenstraße 98 24103 Kiel Germany E-Mail: mail@datenschutzzentrum.de
29. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy if legal, technical or organisational changes make this necessary.
Last updated: July 2026