Privacy policy
Last updated: 25 September 2026
This is an English translation provided for convenience. Only the German version is legally binding.
In brief
- This website uses no cookies, no tracking, no audience measurement, no advertising and no social media plugins. That is why there is no cookie banner.
- Fonts, images and icons are delivered directly by our hosting. Visiting the site does not open any connections to other providers (such as Google Fonts).
- We only process personal data where this is technically necessary to provide the website, when you contact us via the contact form, by email or by phone, and – only after you click – when you book an appointment via Calendly.
Controller
The controller responsible for data processing on this website is:
Andreas Rothmann – AROCO
Straßburger Weg 3
77975 Ringsheim
Germany
Email: info@aroco.de
Phone: +49 176 57603490
We have not appointed a data protection officer, as there is no legal obligation to do so. Please address any questions about data protection directly to the address above.
Hosting and visiting the website
This website is operated on Microsoft Azure (service "Azure Static Web Apps"). Our contractual partner is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Our application is set up in the Microsoft region West Europe (Netherlands); the content is delivered via Microsoft data centres.
When you visit the website, Microsoft processes technically necessary connection data: your IP address, date and time of access, the page or file requested, the amount of data transferred, the previously visited page (referrer) and information about your browser and operating system. This is necessary to deliver the website to you and to ensure its secure and stable operation (e.g. to fend off attacks). We do not analyse this data ourselves and do not create usage profiles.
The legal basis is our legitimate interest in providing a secure and functional website (Art. 6 (1) (f) GDPR) and § 25 (2) no. 2 TDDDG. Microsoft processes the data as a processor on the basis of the Microsoft Products and Services Data Protection Addendum and stores it only for as long as necessary for these purposes.
Processing by Microsoft Corporation in the USA cannot be ruled out. Microsoft is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR); in addition, the EU Standard Contractual Clauses apply. Further information: privacy.microsoft.com.
Contact form
If you write to us using the contact form, we process your name, your email address, your message and – if you provide it – your phone number. We need your name and email address in order to reply; all other information is voluntary.
Your details are transmitted in encrypted form (HTTPS) to our hosting on Microsoft Azure. From there they are delivered by email to our mailbox info@aroco.de via the Azure Communication Services service (data stored in Europe, without open or click tracking) and additionally stored in a non-public data store on Microsoft Azure in the West Europe region. From this store we transfer the enquiry into our internal customer management in order to process and follow up on it. Our email mailbox is operated by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.
The purpose is to process your enquiry and, where applicable, to prepare an engagement. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures); where your enquiry is not aimed at a contract, our legitimate interest in answering enquiries (Art. 6 (1) (f) GDPR).
We delete your data as soon as your enquiry has been fully processed and no further communication is expected, at the latest 24 months after our last contact. If an engagement results, the statutory retention periods apply (e.g. six or ten years under German commercial and tax law).
Contact by email or phone
If you contact us by email or phone, we process your details (e.g. name, contact details, content of your enquiry) in order to handle your request. The legal bases, recipients (email mailbox at IONOS SE) and storage period are the same as for the contact form.
Appointment booking via Calendly
On our contact page you can book an appointment with us directly. For this we use the Calendly service of Calendly, LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA. The booking calendar is only loaded when you click "Load booking calendar". Before that, no connection to Calendly is established.
After your click, Calendly processes your IP address as well as information about your browser and device and sets its own cookies or similar technologies. If you book an appointment, Calendly additionally processes the details you enter there (in particular name, email address and, where applicable, a message) and sends us the appointment data.
The legal basis for loading the calendar is your consent given by clicking (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG); for carrying out a booked appointment, additionally Art. 6 (1) (b) GDPR. You can withdraw your consent at any time with effect for the future by reloading the page – the calendar will then only be loaded after another click – and deleting cookies set by Calendly in your browser.
Calendly is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and additionally bases transfers on EU Standard Contractual Clauses. Calendly's representative in the EU is DPO Centre Europe, Friedrichstraße 88, 10117 Berlin, Germany (eurep@calendly.com). Further information: calendly.com/legal/privacy-notice. If you use the link "Open Calendly in a new tab", only Calendly's privacy notice applies.
Cookies and consent banner
We do not use cookies on this website and do not store any information in your browser. Your usage behaviour is not analysed. We therefore do not need a consent or cookie banner. Cookies can only be set by Calendly, and only after you have actively loaded the booking calendar (see above).
Recipients of your data
Your data is only received by the service providers named above: Microsoft (hosting, form processing, email delivery, storage), IONOS (email mailbox) and – only after your click – Calendly. Beyond that, we only pass on your data if we are legally obliged to do so. We do not sell data and do not use it for third-party advertising.
Links to other websites
Our pages contain links to websites of other providers (e.g. Calendly, image credits in the legal notice). When you follow these links, you leave our website; the respective provider is responsible for data processing there.
Job applications
If you send us application documents by email, we process them to carry out the application procedure (Art. 6 (1) (b) GDPR). If an employment relationship results, we store the data for its performance in compliance with the statutory provisions. Otherwise we delete the documents two months after notification of the rejection, unless legitimate interests prevent deletion, for example evidence in proceedings under the German General Equal Treatment Act (AGG).
Your rights
You have the following rights with regard to the personal data concerning you:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR)
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6 (1) (f) GDPR, you may object to the processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
To exercise your rights, an informal message to info@aroco.de or to the address above is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
No automated decision-making
No automated decision-making, including profiling (Art. 22 GDPR), takes place.
Data security
All pages of this website and the contact form are transmitted exclusively in encrypted form (HTTPS/TLS). We take appropriate technical and organisational measures to protect your data against loss, manipulation and unauthorised access.
Changes to this privacy policy
We update this privacy policy whenever the website or the services used change. The version published here applies.
