Welf GmbH
Privacy policy.
This notice explains the personal data processed through Welf GmbH's website, the purposes of processing and your rights.
Draft · Details pending
The company name Welf GmbH is confirmed. Address, representatives, registration and contact details, and the actual operating environment still need to be completed. This version is not yet a complete publication notice.
Controller and privacy contact
Welf GmbH is the controller for processing associated with this website.
To be completed: the full business address and public contact email. Confirm whether a data protection officer has been appointed and, if so, add their contact details. These outstanding company details also appear in the legal notice.
Website delivery and security
Visiting the site transmits an IP address and the connection information required to deliver the page. Depending on the hosting configuration, access or security logs may contain the request time, URL, HTTP status, browser information and referring page.
The purpose is to serve the website and detect or resolve errors and abuse. The proposed legal basis is Article 6(1)(f) GDPR: the interest in operating a secure, reliable website.
To be completed: the hosting provider and contracting entity, processing locations, actual log fields and deletion periods. The final hosting and logging configuration must be checked before publication.
Contact inquiries
The form processes your name, company, email address and message, together with the selected language and a technical request identifier. These details are used to handle your inquiry, reply and confirm submission. Please do not submit especially sensitive information or confidential client data through the form.
Contacting us is voluntary. Fields marked required are needed to process a form submission; the form cannot be submitted without them. An inquiry does not subscribe you to a newsletter or give marketing consent.
Where the inquiry concerns a contract with you or steps requested by you before a contract, the proposed basis is Article 6(1)(b) GDPR. For business contacts and other correspondence, Article 6(1)(f) may apply, based on the interest in handling relevant communications. The operator must confirm the applicable basis for its actual processing.
Email delivery through Resend
When live delivery is enabled, the system sends your inquiry to Resend for delivery to Welf's configured mailbox. A confirmation containing a reference is sent to your email address. It does not repeat your message, submitted name or company.
Resend and the involved email providers process email addresses, message content and delivery information. The application does not separately store your message in Redis or write it to application logs. Error logs may include technical request identifiers and error categories.
To be confirmed: the Resend contracting entity, mailbox provider, processing agreements, locations, email deletion periods and technical log retention.
Abuse prevention and reliable delivery
The live contact form uses Cloudflare Turnstile. Technical browser and connection information is transmitted to Cloudflare to detect automated or abusive submissions, and the application verifies the resulting token on its server. Cloudflare's Turnstile notice explains its own processing.
Upstash Redis supports submission limits, recognition of accepted requests and handling of delivery events. Data includes cryptographically protected, pseudonymous derivatives of email addresses or inquiries, technical identifiers and timing information. Pseudonymous data is not automatically anonymous.
The proposed basis for these security and reliability functions is Article 6(1)(f) GDPR. The balancing assessment, necessity, provider roles, device access and any required consent implementation must be confirmed before live operation.
Retention
Data is processed for the relevant purpose and then deleted unless further retention is necessary. Different systems have different retention periods.
- Redis submission receipts
- Seven days after storage. Records contain technical identifiers, a pseudonymous fingerprint and delivery identifiers, not the message body.
- Redis delivery events
- 30 days after storage. Records contain event type, email identifier and event time; no recipient address or subject.
- Submission limits
- The application uses one-hour checking windows. Confirm the actual deletion timing of the underlying provider counters before publication.
- Emails and business correspondence
- To be set: a concrete deletion policy for closed inquiries and applicable statutory retention periods. Redis retention does not apply to mailboxes or Resend.
- Hosting and error logs
- To be confirmed: provider, configuration and actual deletion periods.
Recipients and international transfers
Access is available to the Welf personnel handling the inquiry and the service providers used for the relevant functions. Hosting, email and security providers may use subprocessors.
Processing outside the European Economic Area depends on the contracted provider regions and subprocessors. The actual recipients, countries and applicable transfer mechanisms under Articles 44 onwards GDPR must be documented. No exclusive EU processing or particular certification is promised.
Where standard contractual clauses or other safeguards are used, information about them and a way to obtain a copy must be available through the privacy contact that remains to be added.
Cookies, local resources and measurement
The current application has no advertising trackers, connected external analytics service or analytics cookies set by its own code. Fonts and editorial images are served through this website.
Local measurement events contain only an event name and page path and are not currently sent to an analytics service. The separate cookies and technologies notice explains form state, Turnstile and possible hosting technologies.
Your rights
Subject to the applicable legal conditions, you have rights of access, rectification, erasure, restriction and data portability. You may withdraw consent at any time with effect for the future.
You may object to processing based on legitimate interests for reasons relating to your particular situation. You have an unconditional right to object to direct marketing. This contact function does not subscribe you to direct marketing.
Address requests to Welf GmbH's privacy contact, which remains to be supplied. You may also complain to a data protection authority, particularly where you habitually reside, work or believe an infringement occurred. The authority for the company's establishment will be identified once its address is confirmed.
Automated decisions and scope
The contact form does not make solely automated decisions about you that have legal or similarly significant effects. Technical validation may limit submission when errors or abuse are detected.
This notice covers the website and contact function. Processing of client data in later AI projects is addressed separately for the relevant engagement. In local preview mode, the application handles test inputs without sending email or calling the external contact services described above.