Privacy policy
Last updated: 02.10.2026
This translation is provided for your information only. The German version alone is legally binding. Open the German version
We are very pleased that you have shown an interest in our company. Use of the MDEPARTMENT website is, in principle, possible without providing any personal data. However, if a data subject wishes to use special services offered by our company via our website, the processing of personal data could become necessary. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain the consent of the data subject.
The processing of personal data, such as the name, address, email address or telephone number of a data subject, is always carried out in line with the General Data Protection Regulation and in accordance with the country-specific data protection provisions applicable to MDEPARTMENT. By means of this privacy policy, our company wishes to inform the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, this privacy policy informs data subjects of the rights to which they are entitled.
As the controller, MDEPARTMENT has implemented numerous technical and organisational measures to ensure the most complete protection possible of the personal data processed through this website. Nevertheless, internet-based data transmissions may, in principle, have security vulnerabilities, so that absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.
1. Definitions
The MDEPARTMENT privacy policy is based on the terms used by the European legislator in adopting the General Data Protection Regulation (GDPR). Our privacy policy is intended to be easy to read and understand for the general public as well as for our customers and business partners. To ensure this, we would like to begin by explaining the terminology used.
a) Personal data means any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more specific factors.
b) Data subject means any identified or identifiable natural person whose personal data are processed by the controller.
c) Processing means any operation performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure or destruction.
d) Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.
e) Profiling means any form of automated processing of personal data consisting of the use of those data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
f) Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures.
g) Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
h) Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
i) Recipient means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not.
j) Third party means a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or processor, are authorised to process the personal data.
k) Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, in the form of a statement or other clear affirmative action, by which the data subject signifies agreement to the processing of personal data relating to him or her.
2. Name and address of the controller
The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and other provisions of a data protection nature is:
KRUPKA Concept GmbH (MDEPARTMENT brand) Grabenstraße 18 40789 Monheim am Rhein Germany Tel.: +49 176 100 11 000 Email: office@mdepartment.de Website: https://mdepartment.de
3. Cookies and consent management
The MDEPARTMENT website uses cookies. Cookies are text files that are placed and stored on a computer system via an internet browser. Many cookies contain a so-called cookie ID — a unique identifier consisting of a string of characters, by means of which websites and servers can be assigned to the specific internet browser.
In this regard, we distinguish between technically necessary cookies, which are required for the operation of the site (e.g. language setting, storage of your consent), and optional cookies for statistics/audience measurement, marketing and external content. We use optional cookies and comparable technologies exclusively on the basis of your consent pursuant to Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act) and Art. 6(1)(a) GDPR.
When you first visit our website, our consent banner gives you the option to consent to or reject the individual categories separately. Your selection is stored and taken into account on subsequent visits. You can withdraw or adjust your consent at any time with effect for the future — via the “Cookie settings” link in the footer of this website.
In addition, you can prevent our website from setting cookies at any time by means of a corresponding setting in the internet browser used, and thereby permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via an internet browser or other software programs. If you deactivate the setting of cookies, it may not be possible to use all functions of our website to their full extent.
4. Collection of general data and information
The MDEPARTMENT website collects a series of general data and information each time it is accessed by a data subject or an automated system. These are stored in the server’s log files. The following may be collected: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (referrer), (4) the sub-pages accessed, (5) the date and time of access, (6) an Internet Protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data that serve to avert threats in the event of attacks on our information technology systems.
When using these general data and information, MDEPARTMENT does not draw any conclusions about the data subject. Rather, this information is needed in order to (1) deliver the content of our website correctly, (2) optimise the content and the advertising for it, (3) ensure the long-term functionality of our systems and technology and (4) provide law enforcement authorities with the necessary information in the event of a cyberattack. The legal basis is Art. 6(1)(f) GDPR. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.
5. Contacting us, enquiry forms and appointment booking
If you contact us via a form on this website, via the project configurator, the booking form or by email, we process the data you provide (e.g. name, company, email address, telephone number, project details, message) exclusively for the purpose of handling your enquiry and in the event of follow-up questions. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or, as applicable, Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
In order to determine the geographical context of an enquiry (handling by the geographically appropriate team, identification of obviously misdirected messages), we enrich incoming messages with an approximate geolocation based on the IP address. For this purpose, the IP address is transmitted to the ipinfo.io service (ipinfo.io LLC, United States). The legal basis is Art. 6(1)(f) GDPR; according to the provider’s statement, the IP address is not stored there in a manner permanently linked to the enquiry after the lookup. You may object to this processing at any time using the contact address given above.
The data are deleted as soon as they are no longer required to achieve the purpose for which they were collected and no statutory retention periods preclude deletion.
5b. Free website check
On our website, you can have a website address checked. For this purpose, we process the website address entered, your email address and, optionally, your name and your company. Our server retrieves the specified website once and evaluates publicly visible technical characteristics (e.g. response time, encryption, page title). The result is displayed to you directly and sent to us by email. The legal basis is Art. 6(1)(b) GDPR (performance of the service you requested).
We will only contact you regarding the results if you have expressly consented to this (Art. 6(1)(a) GDPR). Consent is voluntary and may be withdrawn at any time with effect for the future, e.g. by email to the address given in section 2.
To protect against misuse, we limit the number of checks per IP address; for this purpose, the IP address is held exclusively in the server’s working memory for a maximum of one hour and is not stored permanently. We do not store the check results in a database; they exist only in the email sent to us.
5c. Cookie-free counting of page actions
In order to identify which pages lead to enquiries, we count certain actions (e.g. clicking “Book an initial consultation”, submitting a form). Only the name of the action, the path of the page accessed and the time are recorded in our server’s logs. No cookies are set, and no identifiers, IP addresses or other personal data are stored; it is not possible to draw conclusions about individual visitors.
5a. Processors and technical service providers
For the operation of this website and the handling of enquiries, we use the following service providers, with whom a data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded or whose role we set out transparently here:
• Hosting: Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Server location: Germany (EU). Server log files as described in section 4 are processed.
• Email delivery (contact and booking forms): IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. The content of incoming messages is processed for forwarding to our mailboxes.
• Approximate geolocation of incoming messages: ipinfo.io LLC, United States. Transmission of the IP address; no permanent linking within the scope of this service. Legal basis: Art. 6(1)(f) GDPR. For the transfer to a third country, we rely on the standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR).
• Audience measurement: Google Ireland Limited (Google Analytics) — see section 9 of this policy.
6. Routine erasure and blocking of personal data
The controller processes and stores personal data of the data subject only for the period necessary to achieve the purpose of storage, or insofar as this has been provided for by the European legislator or another legislator in laws or regulations.
If the purpose of storage ceases to apply or a prescribed storage period expires, the personal data are routinely blocked or erased in accordance with the statutory provisions.
7. Rights of the data subject
a) Right to confirmation: You have the right to obtain from us confirmation as to whether or not personal data concerning you are being processed.
b) Right of access: You have the right at any time to obtain, free of charge, information about the personal data stored about you and a copy of this information — including information on the purposes of processing, the categories of data, the recipients, the envisaged storage period, the existence of the right to rectification, erasure or restriction, the right to lodge a complaint with a supervisory authority, the source of the data and the existence of automated decision-making.
c) Right to rectification: You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you and the completion of incomplete data.
d) Right to erasure (“right to be forgotten”): You have the right to obtain the erasure of personal data concerning you without undue delay, provided that one of the grounds set out in Art. 17(1) GDPR applies and the processing is not necessary.
e) Right to restriction of processing: You have the right to obtain restriction of processing where one of the conditions set out in Art. 18(1) GDPR is met.
f) Right to data portability: You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit those data to another controller.
g) Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR. Where we process personal data for direct marketing purposes, you have the right to object to such processing at any time; we will then no longer process the data for these purposes.
h) Automated individual decision-making, including profiling: You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you.
i) Right to withdraw consent under data protection law: You have the right to withdraw consent to the processing of personal data at any time with effect for the future.
To exercise your rights, an informal message to office@mdepartment.de is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority.
8. Data protection in applications and the application process
The controller collects and processes the personal data of applicants for the purpose of conducting the application process. Processing may also be carried out electronically, in particular where application documents are submitted by email or via a web form.
If the controller concludes an employment contract with an applicant, the data submitted are stored for the purpose of administering the employment relationship in compliance with the statutory provisions. If no employment contract is concluded, the application documents are automatically deleted two months after notification of the rejection decision, provided that no other legitimate interests preclude deletion — for example, a burden of proof in proceedings under the AGG (German General Equal Treatment Act).
9. Audience measurement and analytics (Google Analytics)
This website uses — exclusively after you have given your consent via the consent banner (“Statistics” category) — Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. Google Analytics is not loaded without your consent.
We use Google Analytics with IP anonymisation activated. As a result, your IP address is first truncated by Google within Member States of the European Union or in other Contracting States to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server and truncated there.
The purpose of the processing is the analysis of visitor flows on our website: Google uses the data obtained to evaluate the use of our website, to compile reports on website activity and to provide other services related to website use. In this context, information such as time of access, place of origin and frequency of visits may be processed.
A transfer of data to the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; in addition, we have concluded the EU standard contractual clauses with Google.
You can withdraw your consent at any time via “Cookie settings” in the footer. In addition, you can prevent collection by Google Analytics by downloading and installing the browser add-on available at tools.google.com/dlpage/gaoptout. Further information can be found in Google’s privacy policy at policies.google.com/privacy.
10. External content and map services
Where we embed external content (e.g. maps, videos or embedded booking services), it is only loaded after you have given your consent (“External content” category). When it is loaded, your IP address and other technical data may be transmitted to the respective provider. The legal basis is Art. 6(1)(a) GDPR.
11. Legal basis for processing
Art. 6(1)(a) GDPR serves as the legal basis for our company for processing operations for which we obtain consent for a specific processing purpose. If the processing is necessary for the performance of a contract, the processing is based on Art. 6(1)(b) GDPR; the same applies to pre-contractual measures. If our company is subject to a legal obligation, the processing is based on Art. 6(1)(c) GDPR. In rare cases, processing may become necessary in order to protect vital interests (Art. 6(1)(d) GDPR). Finally, processing operations may be based on Art. 6(1)(f) GDPR if the processing is necessary to safeguard a legitimate interest and the interests, fundamental rights and fundamental freedoms of the data subject do not override that interest.
12. Legitimate interests pursued by the processing
Where the processing of personal data is based on Art. 6(1)(f) GDPR, our legitimate interest is the conduct of our business activities and the security and functionality of our systems.
13. Storage period
The criterion for the period of storage of personal data is the respective statutory retention period. After expiry of that period, the corresponding data are routinely deleted, provided that they are no longer required for the performance or initiation of a contract.
14. Provision of personal data
The provision of personal data is in part required by law (e.g. tax regulations) or may result from contractual provisions. In some cases, it may be necessary for the conclusion of a contract that a data subject provides us with personal data which must subsequently be processed by us. Failure to provide the data would mean that the contract could not be concluded.
15. Existence of automated decision-making
As a responsible company, we do not use automated decision-making or profiling.