Privacy
Privacy notice
Updated: 7 August 2026
1. Controller
Office
Josef Str. 10
51377 Leverkusen, Deutschland
Telephone: 0221 29120505
Mobile: 0174 9855999
Email: info@gutachtermirahki.de
2. Hosting and server logs
This website is hosted on a server provided by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. When you access the site, the server processes technically necessary connection data, which may include your IP address, date and time, requested resource, data volume, referrer, browser and operating system.
Processing is necessary to deliver the website securely and reliably, analyse errors and prevent attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure website operation. Standard access logs are erased after 14 days. Security data concerning failed logins and form abuse is erased within 24 hours unless a specific incident requires longer retention.
3. Appointment requests and contact
When you request an appointment, we process your name, email address, telephone number, vehicle details, requested service, date, location, language and any voluntary notes. Required fields allow us to assign and review your request and contact you; without them, we cannot process it.
The legal basis is Article 6(1)(b) GDPR for steps prior to entering into a contract and contract performance. Article 6(1)(f) GDPR may additionally apply to other enquiries, based on our interest in handling them properly. An online request is non-binding until we personally confirm the appointment.
4. Email delivery via STRATO
We use STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, for receipt, appointment, invitation and password emails. This involves processing sender and recipient addresses, subject, necessary appointment data, time and technical delivery information. Automated appointment emails do not include free-text damage notes, reports or sensitive attachments.
Processing is based on Article 6(1)(b) GDPR for pre-contractual steps and contract performance and Article 6(1)(f) GDPR for reliable, secure delivery. Failed messages may temporarily remain in an outbox for another delivery attempt.
5. Client portal, accounts and reports
Client accounts are created by invitation only. We process identity and contact details, hashed credentials, vehicle and appointment data, and assignment-related reports and documents to perform the contract and provide protected file access. The legal bases are Article 6(1)(b) and, where retention is required by law, Article 6(1)(c) GDPR.
Invitation and password-reset links contain one-time tokens; only cryptographic hashes are stored. Invitations expire after 24 hours and reset links after 30 minutes. Access is limited to authorised personnel and the client assigned to the data.
6. Cookies and external content
This website uses no analytics, marketing or tracking cookies and does not load external maps, videos, review widgets or social-media plugins. No consent banner is therefore displayed.
Signing in sets a technically necessary secure session cookie. It is required for the protected access you requested to the client or administration portal and is not used for advertising. Subsequent processing is based on Article 6(1)(b) GDPR; storage on your device is permitted without consent under Section 25(2)(2) TDDDG. You can review the current status through “Cookie settings” in the footer.
7. Recipients, processors and backups
IONOS receives the data necessary for hosting and STRATO the data necessary for email delivery as technical processors. Depending on your assignment, data may also be sent to insurers, legal representatives or repair shops that you identify. The website does not automatically disclose data to those parties.
Encrypted or access-controlled backups support service recovery. Daily backups are routinely overwritten after 30 days. Service providers acting as processors are bound by agreements under Article 28 GDPR.
8. Retention
Enquiries that do not lead to an assignment are erased once no longer required and no claims are expected. Contract, report and billing records are kept for the assignment and then for applicable commercial and tax retention periods or potential legal claims. They are subsequently erased or restricted.
A client account is erased when it is no longer needed for active assignments, document access, legal retention or claims. Backup data disappears through the scheduled overwrite cycle.
9. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection to processing based on legitimate interests. You may withdraw consent at any time for the future.
You may lodge a complaint with a data protection authority. The competent authority in North Rhine-Westphalia is the State Commissioner for Data Protection and Freedom of Information NRW, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
10. Security and updates
We use appropriate technical and organisational measures, including encrypted transmission, role-based access, hashed passwords, time-limited tokens, secure sessions and regular backups.
We update this notice when functions, providers or legal requirements change. The current version is always available on this page.