Privacy Policy
Your Privacy Settings
You can revoke and re-grant your cookie consent at any time here.
No cookie consent given yet.
1. Data Protection at a Glance
Protecting your personal data is important to us. This privacy policy informs you about what personal data is processed when you visit our website and what rights you have.
2. Controller
IT Munich GmbH
Leopoldstr. 31
80802 Munich
Germany
Email: info@itmunich.com
Managing Director: Ahmed Noor
The controller within the meaning of the General Data Protection Regulation (GDPR) is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
3. Hosting and Data Processing
This website is technically operated on the Base44 platform. In this respect, Base44 acts as a processor in accordance with Art. 28 GDPR. The data required for delivery, security and stability is processed in order to operate the website.
Our current Builder workspace uses US data residency. Personal data may therefore be processed and stored in the United States. For such transfers to third countries outside the EU/EEA, appropriate safeguards are provided within the framework of the Data Processing Agreement between us and the provider, in particular the Standard Contractual Clauses adopted by the European Commission and/or other legally recognized transfer mechanisms. The provider may in turn engage further subprocessors in third countries. It cannot be ruled out that personal data is processed in the USA or other third countries.
The legal basis for processing carried out as part of hosting is Art. 6 para. 1 lit. f GDPR, based on our legitimate interest in the secure and stable provision of this website.
4. Server Log Files
When our website is accessed, technical server and log data required for secure and stable operation is processed automatically. This may include:
- IP address (truncated/anonymized where technically possible)
- Date and time of access
- Status code and data volume transferred
- Requested resource/URL
- Referrer URL
- Browser type used and, if applicable, operating system
This data is processed exclusively for the purpose of technical delivery, the detection and prevention of disruptions, and ensuring security. The legal basis is Art. 6 para. 1 lit. f GDPR.
5. Cookies and Consent Management
By default, our website only uses technically necessary cookies that are required for secure operation and correct display of the website. These cannot be deactivated.
On your first visit, a cookie banner offers the following options:
- Accept all – Consents to all categories
- Reject all – Only technically necessary cookies remain active
- Manage settings – Granular selection by category
Your consent is stored with a timestamp exclusively locally in your browser (local storage). No server-side consent cookie is set. You can revoke and re-grant your consent at any time via the "Your Privacy Settings" section at the top of this page.
6. Cookie Categories
Technically necessary (always active)
Strictly required for proper operation of the website. Legal basis: Art. 6 para. 1 lit. f GDPR.
Statistics / Analytics
Available, but disabled by default. Only activated with explicit consent (see section 7). Legal basis: Art. 6 para. 1 lit. a GDPR.
Marketing
Currently not active and not implemented (no Google Ads, Meta Pixel, LinkedIn Insight Tag). Legal basis for future use: Art. 6 para. 1 lit. a GDPR.
External media / third parties
Currently not active and not implemented. Legal basis for future use: Art. 6 para. 1 lit. a GDPR.
7. Statistics / Analytics
An integrated statistics/analytics function is available on this website. However, this function is disabled by default. No analytics event whatsoever is transmitted before explicit consent.
Analytics is only activated when you consent to the "Statistics / Analytics" category – either by selecting this category in the settings or by choosing "Accept all". If you reject, analytics remains permanently disabled.
After consent has been given, the following technical event information may be processed:
- page URL accessed
- session identifier
- timestamp
- event information (e.g. type of event)
- referrer, where available
This processing is based on Art. 6 para. 1 lit. a GDPR (consent). Consent is voluntary and can be withdrawn at any time.
8. Marketing
Currently, no marketing or advertising tracking services are active or implemented. No Google Ads, no Google Tag Manager, no Meta Pixel (Facebook), no LinkedIn Insight Tag and no other marketing service is used. Marketing remains disabled unless explicitly implemented at a later date with prior consent.
9. External Media
No external media is embedded. In particular, no OpenStreetMap map, no YouTube video and no other third-party content is loaded. Should external media be added in the future, this will only be done with prior consent.
10. Fonts
This website uses exclusively locally hosted or system fonts. There is no connection to Google Fonts servers (fonts.googleapis.com / fonts.gstatic.com) or any other external font provider. No IP address is transmitted to a font provider.
11. Contact
Contact is made via the email address displayed on the website. A contact form that collects form data via the website is not offered. If you contact us by email, we process the details you provide (in particular name, email address and the content of your message) in order to handle and answer your inquiry.
The legal basis is Art. 6 para. 1 lit. b GDPR for pre-contractual or contract-related inquiries and Art. 6 para. 1 lit. f GDPR for general inquiries. The data is deleted once the inquiry has been conclusively processed, unless statutory retention obligations apply.
12. International Data Transfers
As described in section 3, our website currently uses US data residency of the platform provider. This may result in transfers of personal data to the USA and to further subprocessors in third countries outside the EU/EEA. For such transfers, appropriate safeguards are provided, in particular Standard Contractual Clauses of the European Commission and/or other legally recognized transfer mechanisms within the framework of the Data Processing Agreement with the provider. However, it cannot be guaranteed that all processing operations take place exclusively within the EU/EEA.
13. SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the browser address bar showing "https://" and the lock icon in your browser bar.
14. Retention Period
Personal data is stored only as long as necessary for the respective processing purpose or as required by statutory retention obligations. Inquiry data transmitted by email is deleted after conclusively being processed.
15. No Automated Decision-Making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on this website.
16. Your Rights
You have the right at any time to:
- Access to your stored personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdraw consent (without affecting the lawfulness of processing carried out prior to withdrawal)
- Lodge a complaint with a supervisory authority
To exercise your rights, please contact: info@itmunich.com
17. Competent Supervisory Authority
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
18. Currency of This Privacy Policy
As of: September 2026. This privacy policy will be updated as required by technical or legal changes.