Privacy Policy

Table of Contents

  • Preamble
  • Data Controller
  • Data Protection Officer
  • Rights of the data subject
  • General information about cookies on this website
  • Data processing when visiting our website
  • Processing of cookie data based on your cookie preferences
  • Cookie settings/opt-out options
  • Web analytics, monitoring and optimisation
  • Restricted content on our website for customers
  • Contacting us
  • Privacy notice for whistleblowers

Preamble

The following privacy policy is intended to inform you about which of your personal data (hereinafter also referred to simply as ‘data’) we process, for what purposes and to what extent. This policy applies to all processing of personal data carried out by us when you visit our website or contact us.
The terms used are gender-neutral.

Date: 18 June 2026

Data Controller

The controller responsible for the processing of personal data on this website is

Holmberg GmbH & Co. KG
Ohlauer Str. 5–11
10999 Berlin
Germany

Authorised representatives: Lutz-Michael Pöppel, Thorsten Pöppel
Email address: info@holmco.de
Telephone: +49 30 617 80-0

Contact the Data Protection Officer

If you have any questions, suggestions or complaints, you can also contact our external Data Protection Officer, Mr. Freyer.
Email address: datenschutz@freyer-berater.de

freyer consultants management systems

Berliner Straße 100
13189 Berlin
Germany

Rights of Data Subjects

Rights of data subjects under the GDPR (General Data Protection Regulation): As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time, with effect for the future, by notifying the controller.
  • Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to this data, as well as further information and a copy of the data in accordance with the legal requirements.
  • Right to rectification: In accordance with the legal provisions, you have the right to request that data relating to you be completed or that any inaccurate data relating to you be rectified.
  • Right to erasure and restriction of processing: In accordance with the legal provisions, you have the right to request that data relating to you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of the data.
  • Right to data portability: You have the right, in accordance with the statutory provisions, to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller.
  • Complaints to a supervisory authority: In accordance with the legal provisions and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State in which you habitually reside, the supervisory authority for your place of work or the location of the alleged infringement, should you consider that the processing of your personal data infringes the GDPR. Contact details can be found at

    https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html

General information about cookies on this website

Personal data may be processed by so-called ‘cookies’ or other “third-party services”. Cookies are text files that are stored on your device.

  • “Technically necessary” cookies are used solely to ensure the functioning of our website and do not require your consent. They serve to recognise and store temporary data relating to website visitors. We use these technical cookies only to the extent necessary to enable the website to communicate with your device. The use of technical cookies is justified on the basis of our overriding legitimate interest in the functionality of our website (Article 6(1)(f) GDPR).
  • In addition to these technically necessary cookies, we may also use so-called “third-party services” (e.g. “marketing cookies”, “analytics cookies”, “non-essential cookies”, “pixels”, “local/session storage” or similar technologies). These services enable us to better understand and analyse your interests. With the help of these services, we can combine your “browsing behaviour” beyond the boundaries of our website with data from other websites. Our aim is to gain a better understanding of the interests of our website visitors so that we can target them more effectively. For this purpose, the relevant categories of your personal data required for this purpose are also transferred to the respective service provider. We respect that not every visitor to our website wishes this. We therefore only process your data via these third-party services if you give us your consent to do so (Article 6(1)(a) GDPR). Third-party services are only activated once you have given your consent via our cookie banner (the pop-up window that appears when you first visit our website).

Data processing when visiting our website

For technical reasons, personal data is logged each time you access our website and each time a page is viewed, in order to enable you to visit and navigate our website.

  • Types of data processed: name of the file accessed, meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, data volume, operating system used, notification of successful access).
  • Data subjects: Website visitors.
  • Purposes of processing: We wish to ensure that your visit to our website is technically sound and secure.
  • Retention and deletion: As a rule, data and cookies are deleted as follows:

Session cookies: at the end of your visit to our website.
Persistent cookies (for security functions): after 45 days.
IP addresses and login attempts (to prevent malicious login attempts): after 24 hours.
Language settings: after one year.

  • Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
  • Data processors: To provide our online services, we use storage space, computing capacity and software which we lease or otherwise obtain from a relevant server provider or data processor:
  • Hosting, maintenance, backups and data recovery are carried out by LAUDO Designagentur GmbH, Erkelenzdamm 59–61, 10999 Berlin, Germany. Hosting takes place exclusively on German servers.
  • Plug-ins: For language settings, we use Polylang from the provider WP SYNT (Polylang), 28 rue Jean Bart, 31100 Toulouse, France. Polylang is a WordPress plug-in that enables us to make our website available in multiple languages. The data is stored locally for a period of 1 year.

Processing of cookie data based on your cookie preferences

We use a consent management solution to obtain users’ consent to the use of cookies. This process is used to obtain, log, manage and withdraw consent, in particular with regard to the use of cookies and similar technologies used to store, read and process information on users’ devices. A pseudonymous user identifier is created, which is stored together with the time of consent, details of the scope of consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, the system and the end device used:

  • Types of data processed: meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, operating system used).
  • Data subjects: Website visitors.
  • Purposes of processing: Consent management for website visitors regarding optional cookies.
  • Retention and deletion: Data is deleted after 2 years.
  • Legal basis: Legitimate interest (Article 6(1)(f) GDPR).
  • Further information and data processors:

We use the service provider Borlabs GmbH, Hamburger Str. 112, 2083 Hamburg, Germany, for consent management. An individual user ID, language, types of consent and the time at which consent was given are stored on the server and in a cookie on the user’s device.

We use Google LLC, Gordon House, Barrow Street, Dublin 4, Ireland, as a second provider, utilising Google reCAPTCHA to store a website visitor’s status regarding their cookie preferences. The data is processed within the EU and the USA. For the transfer of personal data to the USA, there is an adequacy decision by the European Commission pursuant to Article 45 GDPR in the form of the EU-US Data Privacy Framework (DPF). Google LLC is certified under the Data Privacy Framework, ensuring an adequate level of data protection for data transfers. In addition, Google has entered into so-called Standard Contractual Clauses (SCCs) in accordance with Article 46 GDPR to safeguard data transfers. These oblige the recipient in the USA to comply with European data protection standards. Further information on data processing by Google can be found at:
https://policies.google.com/privacy

Cookie settings/opt-out option:

You may withdraw all your consents regarding the use of non-essential cookies at any time by deleting the enabled services from your device’s browser, although data processing carried out up to the time of withdrawal remains justified, or by managing them here:

Web analytics, monitoring and optimisation

Web analytics (also known as ‘reach measurement’) is used to analyse visitor traffic to our online offering and may include behaviour and interests in pseudonymous form. With the help of reach analysis, we can, for example, identify at what times our online offering, its functions or content are most frequently used, or encourage repeat visits. It also enables us to identify which areas require optimisation.

In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. Generally speaking, no personally identifiable user data (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.

  • Types of data processed: usage data (IP address (anonymised)), pages accessed (URL), referrer URL, date and time of access, duration of visit, device and browser information, screen resolution).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: To optimise our website in terms of user-friendliness and content, we analyse the behaviour of website visitors (e.g. access statistics, identification of returning visitors, audience measurement). Information regarding website usage is transmitted exclusively to our servers and aggregated into pseudonymous usage profiles.
  • Retention and deletion: 6 months.
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal basis: Consent (Article 6(1)(a) GDPR).
  • Further information and data processors: We use Matomo cookies for web analytics and audience measurement. Matomo is a product of InnoCraft, 7 Waterloo Quay, PO Box 625, 6140 Wellington, New Zealand (Company Register No. NZBN 6106769). Cookies are generated and stored on users’ devices and hosted on the servers of LAUDO Designagentur GmbH, Erkelenzdamm 59–61, 10999 Berlin (data processor) within Germany.
  • Withdrawal: You may withdraw your consent at any time with future effect, as specified above under ‘Cookie settings/opt-out option’.

Restricted content on our website for customers

On our website, you will find documents that are password-protected and therefore only accessible to registered customers.

  • Types of data processed: Log-in details (email address, password), log data, company affiliation, contact details.
  • Data subjects: Users of this service.
  • Purposes of processing: Provision of restricted content.
  • Retention and deletion: Upon termination or at the end of the contract term, your login details and contact details will be deleted. Log data will be deleted after a period of 30 days.
  • Legal basis: Performance of a contract (Article 6(1)(b) GDPR).

Contacting us

You can contact us by email, telephone, post or via the contact form on our website.

  • Types of data processed: Contact details, email address, telephone number, order details, correspondence details, IP address, device information, metadata (type and version of the browser or device, system information relating to the processing software).
  • Data subjects: Individuals who contact us.
  • Purposes of processing: Handling customer inquiries and general inquiries; customer support.
  • Retention and deletion: Your data will be deleted from our active systems once your inquiry has been fully processed, provided that no statutory retention obligations (for example, commercial or tax law provisions: 6–10 years) require it to be stored for a longer period. In this case, the data will be blocked until the expiry of the retention period and permanently deleted once the retention obligation ceases to apply. Inquiries arising from existing or prospective business relationships may be stored in our CRM system and will be deleted upon termination of the business relationship, in accordance with statutory retention obligations.
  • Legal basis: Where your inquiry is aimed at concluding or performing a contract, or relates to an existing contractual relationship, processing is carried out on the basis of Article 6(1)(b) GDPR. For other inquiries, processing is carried out on the basis of our legitimate interest pursuant to Article 6(1)(f) GDPR, for the purpose of responding to your inquiry and maintaining potential business relationships.
  • Further information and data processors: To provide our online contact form, we use Gravity Forms by Gravity SMTP. This is a WordPress plugin that enables emails to be sent via external SMTP services and ensures the reliable delivery of form and system emails. The plugin itself does not process any personal data. We use Microsoft 365/Outlook as our email service provider and data processor. Emails are sent via Microsoft’s servers. This may involve the processing of personal data on servers operated by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

Data Protection Information for Whistleblowers

In this section, you will find information on how we handle data relating to individuals who submit reports (whistleblowers), as well as data relating to affected and involved parties, as part of our whistleblowing procedure. Our aim is to provide a straightforward and secure way to report potential misconduct by us, our employees or service providers, particularly in relation to actions that breach laws or ethical guidelines. We also ensure that reports are processed and handled appropriately.

Types of data processed:

  • Types of data processed: In the course of receiving and processing reports, as well as during the subsequent whistleblowing procedure, we may process various types of data, depending on the information provided to us by the whistleblower.

    This may include: the person’s name, contact details and location; details of the alleged misconduct; further relevant details; a reference number for the report; health data; data relating to a person’s racial or ethnic origin; information about a person’s religious or philosophical beliefs; and details of a person’s sexual orientation.
  • Data subjects: Whistleblowers, witnesses, people against whom the report is directed, other parties involved, employees, job applicants.
  • Purposes of processing: Fulfilment of obligations under the Whistleblower Protection Act.
  • Retention and erasure: Data is generally erased 3 years after the conclusion of the proceedings, provided that the data is not required to defend our legal claims, for ongoing employment law or court proceedings, or to fulfil further statutory retention obligations.
  • Legal basis: Legal obligation (Article 6(1)(c) GDPR).
  • Data processor: We use the whistleblower software reporting channel and the whistleblower system provided by the service provider: Formalize ApS, Kannikegade 4, 1., DK-8000 Aarhus C, Denmark. The data is processed within the EU.

Use of our online forms: Please note that it is possible to submit reports anonymously. To ensure the security of your data when using our online forms, we recommend accessing them in your browser’s ‘incognito mode’. How to open an incognito window: a) On a Windows PC: Open your browser and press Ctrl+Shift+N; b) On a Mac: Open your browser and press Command+Shift+N; c) On mobile devices: Switch to private mode via the tab menu.

When you visit our website in normal mode, your browser automatically sends certain information to our server, such as your browser type and version, and the date and time of your visit. This also includes your device’s IP address. This data is temporarily stored in a log file and automatically deleted after 30 days at the latest.

The processing of the IP address serves technical and administrative purposes relating to establishing a connection to our website. It ensures the security, stability and functionality of the whistleblower form and is an important part of our measures to ensure confidential submission of reports.

The processing of the logged data is based on Article 6(1)(f) GDPR. Our legitimate interest here lies in the need for security and the necessity to ensure the technical requirements for the smooth and trouble-free submission of reports.

Provision of your name: You have the option to submit reports anonymously. However, unless prohibited by national legislation, we recommend that you provide your name and contact details. This enables us to investigate the report more effectively and, if necessary, to contact you directly.

If you provide your name and contact details, your identity will be treated with strict confidence. Exceptions to this confidentiality only apply where we are legally obliged to disclose your identity. This may be necessary to protect or defend our rights or the rights of our employees, customers, suppliers or business partners. A further exception applies if it is determined that the allegations were made with malicious intent.

Disclosure of data to third parties: We will only disclose data relating to the reports submitted to third parties under certain circumstances. This will occur either a) if you have given us your express consent to do so, or b) if there is a legal obligation to disclose the data. Potential third parties include public authorities, government bodies, regulatory bodies or tax authorities, where disclosure is necessary to fulfil a legal or regulatory obligation. Furthermore, we may engage solicitors and other specialist advisers in accordance with legal provisions. They are authorised to investigate alleged misconduct and to take necessary action following an investigation, such as initiating disciplinary or legal proceedings. Furthermore, service providers carefully selected and monitored by us may receive data for these purposes (for example, operators of a web-based reporting system). However, these service providers are contractually obliged, within the framework of data processing on our behalf, to comply with the applicable data protection regulations.

Technical and organisational measures: We have implemented the necessary contractual, technical and organisational measures to ensure the security of all data we process. This data is processed exclusively for the specified purposes. Incoming reports are handled by authorised personnel who are granted access to the relevant reports and carry out the subsequent investigation of the facts. Our staff are specially trained and instructed to carry out fact-finding investigations properly and are bound to maintain the strictest confidentiality.