Privacy Policy
How NEXDEN processes your personal data when you visit nexden.de or contact us through the website.
Last updated: July 2026
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Deniz Kaya — NEXDEN Bergstraße 13 46236 Bottrop Germany Email: info@nexden.de Phone: +49 175 5719544
A data protection officer has not been appointed, as the statutory requirements are not met. Please contact the address above for privacy-related requests.
2. Scope
This privacy policy applies to the website nexden.de (including all subpages) and to contact and project inquiry forms offered on this website.
It does not apply to external websites we link to. Their operators are solely responsible for their content and privacy practices.
3. Overview of processing
The following is an overview of data processing on this website:
- Provision of the website and creation of server log files
- Use of technically necessary cookies and local storage (localStorage)
- Processing of inquiries via contact and project forms
- Email notification when new inquiries are received
- Operation of the protected administration area (/admin) for authorised users
4. Provision of the website and server log files
When you access our website, our web server automatically collects information and stores it in server log files. This may include:
Processing takes place to provide the website technically, ensure stability and security, and detect misuse.
- IP address of the requesting device
- Date and time of access
- URL accessed and volume of data transferred
- Browser type and version as well as operating system
- Referrer URL (previously visited page), if transmitted
5. Cookies, localStorage and similar technologies
We do not use marketing or tracking cookies on the public website and do not deploy third-party analytics services (e.g. Google Analytics).
Web fonts are served locally from our server via Next.js; page loads do not connect to Google Fonts or similar providers.
We use the following technologies:
- Cookie NEXT_LOCALE: stores your selected language (de/en). Legal basis: § 25(2) TDDDG in conjunction with Art. 6(1)(f) GDPR (technically required).
- localStorage nexden-cookie-consent: stores your decision regarding the cookie notice. Legal basis: § 25(2) TDDDG in conjunction with Art. 6(1)(f) GDPR.
- Session cookies in the administration area (/admin): for authorised internal users after login only; not intended for website visitors.
6. Contact and project inquiries
If you contact us via a form on the website (e.g. contact page, package inquiry, or project start), we process the data you provide to handle your request and for any follow-up questions.
Data processed may include: name, email address, phone number, company (optional), selected package, project type, budget and timeline information, message text, and technical metadata (language/locale, form source, time of submission).
Transmission takes place via HTTPS to our servers and is stored in our database.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient inquiry handling).
7. Email notifications
When a new form inquiry is submitted, an automatic email notification may be sent to our business address (info@nexden.de) so your request can be processed promptly.
We use the configured SMTP service for email delivery. Personal data contained in the inquiry is processed as part of transmission.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
8. Hosting and processors
This website and related backend services are operated on servers within the European Union. Where required, we have concluded a data processing agreement pursuant to Art. 28 GDPR with our hosting provider.
Personal data is processed solely on our instructions and to provide the technical infrastructure.
9. Retention periods
Server log files are retained only as long as necessary for security, error analysis, and operation, and are then deleted or anonymised (typically within 14 days unless longer retention is required for security reasons).
Inquiry data from forms is stored for the duration of communication and beyond where statutory retention obligations apply or legitimate interests (e.g. proof in business dealings) require longer storage. Commercial and tax retention periods (often up to 10 years) remain unaffected.
Cookie and consent settings remain on your device until you delete them or we remove them for technical reasons.
10. Legal bases at a glance
- Art. 6(1)(a) GDPR — consent, where you have given explicit consent
- Art. 6(1)(b) GDPR — contract performance or pre-contractual measures
- Art. 6(1)(f) GDPR — legitimate interests (e.g. secure website operation, inquiry handling)
- § 25(2) TDDDG — technically necessary storage of information on your device
11. Disclosure of data
We disclose your personal data to third parties only where necessary for contract performance, we are legally obliged to do so, you have consented, or another legal basis applies.
Transfers to countries outside the EU/EEA do not take place with this website unless expressly stated in individual cases.
12. Your rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Right to withdraw consent with future effect (Art. 7(3) GDPR)
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of personal data.
Supervisory authority for North Rhine-Westphalia: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW) Kavalleriestraße 2–4 40213 Düsseldorf Germany Website: https://www.ldi.nrw.de
14. Obligation to provide data
Providing personal data is neither legally nor contractually required, but is necessary to process your inquiry via our forms. Without the required information, we cannot handle your request.
When merely visiting the website, providing data is technically necessary (e.g. IP address) to deliver the page.
15. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
16. Data security
We implement technical and organisational measures to protect your data against accidental or unlawful manipulation, loss, destruction, or unauthorised access. These include HTTPS encryption, access restrictions on systems and databases, and role-based access in the administration area.
Our security measures are updated continuously in line with technical developments.
17. Changes to this privacy policy
We may update this privacy policy when our website, technologies used, or the legal framework change. The current version is available on this page.
Where material changes affect your rights, we will inform you appropriately if required.