Privacy Notice
Below we explain, in accordance with Articles 13 and 14 GDPR, which personal data we process when you visit this website and when you contact us. This website deliberately does without analytics, tracking and advertising technologies. The German version of this notice is the legally binding one.
Last updated: 5 September 2026
1. Controller
The controller for data processing on this website within the meaning of Article 4(7) GDPR is:
Dimitar Kuzumski
trading as ProperIT Consulting
Wiedbachstraße 49
65307 Bad Schwalbach
Germany
Email: info@properit-consulting.de
For data protection matters and to exercise your rights, please write to the address above or to info@properit-consulting.de.
2. Hosting
This website is hosted with an external service provider. The personal data collected on this website is processed on that provider’s servers. The provider processes the data exclusively on our instructions.
The hosting provider is Microsoft, contracting through Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The website application runs on Azure App Service in the Microsoft Azure “West Europe” region, whose data centre location is the Netherlands.
Data processing by Microsoft is governed by the Microsoft Products and Services Data Protection Addendum (DPA) in the version applicable to the relevant contractual relationship.
Microsoft also processes data in the course of the Azure and Microsoft 365 services we use, under the contractual product and data protection terms applicable to them. We make no assurance about the EU Data Boundary beyond those services whose specific tenant and service configuration confirms it.
3. Server log files and logging
When you access this website, your browser transmits the following information for technical reasons, which may be processed at the hosting provider’s platform level:
- IP address of the requesting device
- date and time of access
- name and URL of the file retrieved
- volume of data transferred and confirmation of successful retrieval
- browser type and version, and the operating system used
- previously visited page (referrer URL), if transmitted
We have not enabled application-level HTTP access logging for website visits. Our website server’s diagnostic logs do not contain contact-form content and are deleted after seven days. Microsoft also processes system-generated operational, security and administrative logs. Their retention depends on the type and purpose of the log and the applicable Microsoft contractual and service terms. Azure Activity Log events relating to management operations are retained for 90 days by default; they are not visitor access logs. We do not merge this data with other data sources.
4. Cookies, tracking and audience measurement
This website sets no analytics, tracking or advertising cookies. Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Microsoft Clarity and comparable services are not embedded. There is no audience measurement, no profiling and no remarketing.
No cookie is set for language selection either: the language follows solely from the URL you open (/de/… or /en/…). The first time you open the home page, you are simply redirected to the matching language version based on the language preference your browser sends; nothing is stored on your device in the process.
Fonts are served locally from our own server. Opening the website therefore establishes no connection to external font servers.
Because we do not store or read any information on your device beyond what is strictly necessary to provide the service you have expressly requested, your visit to this website requires no consent under section 25 TDDDG, which is why we deliberately show no cookie banner.
If analytics or marketing technology is ever added, we will reassess the requirements of section 25 TDDDG and update this privacy notice before that technology is used.
5. Contact form and enquiries
If you contact us via the contact form or by email, we process the information you provide in order to handle and answer your enquiry. The form collects the following data:
- name (mandatory)
- email address (mandatory)
- subject of the enquiry (mandatory)
- message (mandatory)
- company (optional)
- telephone number (optional)
- confirmation that you have read this privacy notice
Mandatory fields are marked as such; you may leave optional fields blank without any disadvantage. Form content is not stored in a database on this website — it is only delivered as an email. Please do not use the form to send special categories of personal data within the meaning of Article 9 GDPR, or confidential credentials.
6. Protection against automated submissions
To protect the contact form against automated submissions we use two mechanisms, neither of which involves a third party: an additional field that is invisible to humans (a “honeypot”), and a limit on the number of submissions within a given period. For that limit, your IP address is held only as a non-reversible hash in the server’s memory; it is not permanently stored, logged or written to disk.
No external captcha or bot-protection service is embedded. Neither opening the page nor submitting the form loads a third-party script or transmits data to a third party.
7. Email delivery
Your form enquiry is delivered by our server as an email to info@properit-consulting.de. No additional external SMTP provider is involved: the message is sent directly from our own mailbox system.
Delivery goes through Microsoft Exchange Online (Microsoft 365) in our own Microsoft 365 tenant. The contracting party is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The website authenticates without any stored password, using a managed identity technically restricted to the sending mailbox alone.
Your email address is only ever set as the reply-to address; the sender is always an address on our own domain. Transport to the mail server is encrypted. If delivery fails, we log only the type of error, never the content of your message.
Microsoft 365 is likewise covered by the Microsoft Products and Services Data Protection Addendum (DPA) in the version applicable to the relevant contractual relationship.
For mailbox data we make no assurance about the EU Data Boundary beyond the Microsoft contractual and service terms applicable at the time. Please also note that the transmission of email over the internet can have security gaps in principle, and complete protection against access by third parties cannot be guaranteed.
8. Legal bases
If you contact us to take steps prior to entering into a contract or in connection with the performance of a contract and you are the contracting party, we process your data on the basis of Article 6(1)(b) GDPR.
For other business enquiries – in particular where you act as an employee, contact person or representative of an organisation or public body – processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to respond to business enquiries, initiate services and organise communication with prospects, customers and business partners.
The secure, stable and abuse-resistant operation of the website, limited error diagnostics and protection of the contact form against spam are also based on Article 6(1)(f) GDPR. Our legitimate interest is the security and proper functioning of the website and the prevention of misuse.
Where data must be retained to comply with statutory commercial or tax-law obligations, processing is based on Article 6(1)(c) GDPR in conjunction with the applicable statutory provisions.
In the balancing test under Article 6(1)(f) GDPR, the following reduce the impact on you: this website uses no tracking, advertising or profiling; it sets no cookies; form enquiries are not stored in a database; contact-form content is never logged; the IP address used for rate limiting is held only as a salted hash in memory; no HTTP access logging is enabled; the website server’s diagnostic logs are deleted after seven days; and ordinary enquiries are deleted after twelve months. Additional processing by the optional AI assistant is described in sections 15 and 16. Your data subject rights, including the right to object, remain unaffected.
9. Recipients and processors
Within our company, your data is only passed to those people involved in handling your enquiry. Beyond that, the following recipients may have access to personal data:
- Microsoft Ireland Operations Limited, as the processor for hosting this website (Azure App Service) and for email delivery (Microsoft Exchange Online)
- tax advisers as well as IT and legal service providers, where required in an individual case
For Microsoft, the Microsoft Products and Services Data Protection Addendum (DPA) applies. Where Microsoft processes data outside the European Union in the course of the services we use, this is governed by the contractual product and data protection terms applicable at the time, including the DPA. Additional recipients involved in the optional AI assistant are described in sections 15 and 16. We do not pass your data on for advertising purposes and we do not sell data.
10. Retention periods
We retain contact enquiries only for as long as necessary to process them and for any subsequent business relationship. General enquiries that do not result in a contractual relationship and are not subject to further evidentiary or statutory retention requirements are deleted no later than twelve months after final processing.
Where correspondence forms part of business or tax records subject to statutory retention, the applicable statutory periods apply. Longer retention may also be necessary while a contract, audit or legal dispute is ongoing or where data is required to establish, exercise or defend legal claims.
For the technical data of this website, the following also applies:
- the website server’s diagnostic logs: deleted after seven days
- data used for the form’s abuse detection: held only transiently in memory, at most for the duration of the respective time window
- platform-level logs at Microsoft: according to the type and purpose of the log and the Microsoft contractual and service terms applicable at the time
11. Your rights as a data subject
You have the following rights in relation to your personal data:
- right of access (Article 15 GDPR)
- right to rectification (Article 16 GDPR)
- right to erasure (Article 17 GDPR)
- right to restriction of processing (Article 18 GDPR)
- right to data portability (Article 20 GDPR)
- right to object to processing (Article 21 GDPR)
- right to withdraw consent at any time with effect for the future (Article 7(3) GDPR)
- right to lodge a complaint with a supervisory authority (Article 77 GDPR)
An informal message to info@properit-consulting.de is enough to exercise these rights. Right to object under Article 21 GDPR: where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation.
12. Competent supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. As we are established in Hesse, the competent authority is:
The Hessian Commissioner for Data Protection and Freedom of Information
P.O. Box 3163
65021 Wiesbaden
Germany
Office: Wilhelmstrasse 7, 65185 Wiesbaden
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
Irrespective of this, you may also contact the supervisory authority of your habitual residence or place of work.
13. Security of transmission
For security reasons and to protect the transmission of confidential content, this website uses TLS encryption. You can recognise an encrypted connection by “https://” in your browser’s address bar and by the padlock symbol. When encryption is active, the data you send us cannot be read by third parties.
14. Changes to this privacy notice
We adapt this privacy notice whenever changes to our website, to the service providers we use, or to legal requirements make that necessary. The version published on this page is the applicable one.
If we introduce further processing in future, we will publish the corresponding information together with its activation and update the date of this notice.
15. Optional AI assistant on the website
Our AI assistant answers questions about ProperIT Consulting and our services. At your request it can check available times, book an appointment or pass on a callback request. You are communicating with an automated system. Its answers may contain errors; please contact us personally for binding information about services and contracts.
Visiting a page, seeing the welcome animation or opening the assistant does not start an AI session. A connection is established only after you explicitly agree following the privacy information and start your chosen mode. Text mode does not use your microphone. Using the assistant is optional; email and the contact form remain available independently.
Our service hosted on Microsoft Azure uses Azure OpenAI (gpt-realtime) to process messages and generate answers. Microsoft processes your inputs, the current session context, replies and the details needed for requested functions. Technical session data includes a random identifier, language, connection time and error status. To limit session starts, the website server holds your IP address only as a salted hash temporarily in memory.
Optional AI processing is based on your consent under Article 6(1)(a) GDPR. You may stop it at any time using “End conversation” or withdraw consent using the contact details above. Minimising the window does not end an active session. Withdrawal does not affect the lawfulness of processing carried out before it.
Conversation context and audio buffers are processed in memory during use; our application does not create a permanent full transcript or a conversation recording. The displayed history may remain in the browser until a new conversation starts or the page is reloaded. Diagnostic logs may contain session identifiers, duration, function calls, errors and a brief outcome summary; recognisable email addresses and telephone numbers are removed from that summary.
If you request an appointment or callback, the necessary details, such as name, contact information, company, enquiry and appointment time, are processed through Microsoft Graph in our Microsoft 365 mailbox or calendar. If email delivery fails, a callback request with contact details and a shortened enquiry may be preserved in an error log so we can handle it. The legal bases and retention periods in sections 8 and 10 apply to these requested contact and appointment processes. The assistant runs as a separate service: the seven-day period stated for the website server’s diagnostic logs is not an assurance about this service’s log retention. Its operational logs are governed by the relevant Azure platform and service configuration.
The absence of permanent conversation storage in our application does not mean that providers retain no data. Microsoft may process and retain content and technical data for service operation and abuse monitoring; suspicious content may be reviewed. Global Azure model deployments may process data outside the EU. The website hosting region is not an assurance about where the AI model processes data. The applicable Microsoft product and data protection terms govern this processing.
Please provide only what is needed for your question, and do not share passwords, other credentials or particularly sensitive personal data. The assistant is not used to assess individuals or make decisions with legal effects about you.
16. Voice mode of the website assistant
In voice mode, after your explicit agreement and browser microphone permission, your microphone audio is transmitted during the active session to our Azure service and Azure OpenAI to understand and transcribe speech and generate replies. You can mute your microphone or end the session at any time.
For spoken replies, our service sends the response text to the ElevenLabs speech-synthesis API. ElevenLabs generates the artificial voice you hear. That text may contain details from your question when the AI includes them in its answer. This integration does not send your microphone audio to ElevenLabs.
ElevenLabs describes the United States as the standard location for storing customer data. Input text, generated audio and technical data may be retained under the applicable service and privacy terms. This integration makes no assurance of EU-only processing or Zero Retention Mode. The Microsoft provider retention described in section 15 also applies in voice mode.
These details concern voice mode in the browser. Starting a website session does not change how our published telephone number is routed.