Oscian Consulting
Home
Services
Industries
About us
EN
Contact
Home
Services
Industries
About us
EN
Contact
PRIVACY POLICY
01. March 2026
1) Controller
The controller responsible for processing personal data on this website is:
Oscian Consulting UG (haftungsbeschränkt)
Flurstraße 4
84550 Feichten a. d. Alz
Germany
Phone: +49 159 01097168
E-Mail: maximilian.schuderer@oscian.com
Website: www.oscian-consulting.com
2) Data Protection Officer
No data protection officer has been appointed, as there is no legal obligation to do so under the applicable statutory provisions.
3) Purposes and legal bases of processing
We process personal data only
- to provide this website technically,
- to ensure stability and IT security,
- to handle requests you send to us by email, by phone, or via the contact form.
Legal bases in particular are:
- Art. 6(1)(f) GDPR (legitimate interest in secure, stable website operation),
- Art. 6(1)(b) GDPR (handling pre-contractual/contractual requests),
- Art. 6(1)(f) GDPR (handling other requests / communication).
4) Hosting (Azure Static Web Apps)
This website is operated using “Azure Static Web Apps”. The service provider is:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland
In the course of hosting, Microsoft processes technical data on our behalf that is required to deliver the website and to ensure security and stability (e.g., log data/server logs).
Note: The specific processing operations and safeguards follow from the contractual documents applicable between us and Microsoft (in particular the Data Protection Addendum / processing agreement).
5) Server log files (provision, security)
When you access our website, the hosting infrastructure (Azure Static Web Apps) processes technical data that your browser transmits automatically. This may include in particular:
- IP address
- date and time of access
- accessed page/file (URL)
- referrer URL
- browser type/version, operating system
- status codes and data volume transferred
The purposes of processing are the technical provision of the website, troubleshooting, and ensuring stability and IT security (e.g., detection/analysis of attacks and abuse).
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable website operation).
We do not perform our own additional access analysis and we have not configured any separate export/archiving of HTTP access logs in our Azure tenant (e.g., to Log Analytics/Storage). However, technical log data may still be processed by the hosting provider as part of operating and securing the service.
Retention period: We do not store separate access logs in our own systems. Where technical log data is generated at the hosting provider, retention depends on the operational and security requirements of the hosting service and is limited to what is necessary. In the event of security incidents, longer retention may be required for investigation and mitigation.
6) Contact by email, phone, or contact form
If you contact us by email, by phone, or via a contact form, we process the data you provide or disclose in the course of the communication (e.g., name, email address, phone number, subject, message content and any attachments) in order to handle your request.
When using the contact form, technically necessary metadata that may arise in connection with the transmission can also be processed (e.g., time of submission, IP address) to ensure secure operation and to prevent misuse (e.g., spam).
Mandatory information / necessity:
Where certain fields in the contact form are marked as mandatory, this information is required to process your request and to respond to you. Without it, we may be unable to handle the request.
Legal basis:
- Art. 6(1)(b) GDPR where the communication relates to pre-contractual measures/contract performance (e.g., inquiries about services/quotes),
- otherwise Art. 6(1)(f) GDPR (legitimate interest in handling inquiries, communication, and preventing misuse/spam).
Retention period:
We delete/archive contact requests once they have been fully handled and no statutory retention obligations prevent deletion. If form submissions are only forwarded to our email inbox, the content is not stored separately on the website; further retention then follows the principles stated above for email communication.
Email security note:
Email communication is generally not end-to-end encrypted. If you wish to transmit confidential information, please contact us in advance to agree on a secure transmission method.
7) Cookies / storage of preferences
We do not use cookies for analytics, tracking, or marketing purposes.
We only use functional cookies to store preferences you select:
a) Oscian_UserTheme_V1
Purpose: Stores the website theme you selected (e.g., light/dark).
Retention: 365 days (or until deleted in the browser). If you change the theme, the cookie is set again (the retention period starts anew).
b) Oscian_UserLanguage_V1
Purpose: Stores the language you selected.
Retention: 365 days (or until deleted in the browser). If you change the language, the cookie is set again (the retention period starts anew).
c) Oscian_CookieConsent_V1
Purpose: Stores that the cookie notice has already been displayed and/or that a selection has been made, so the notice does not appear again on every visit.
Retention: 365 days (or until deleted in the browser). If you make a new selection, the cookie is set again (the retention period starts anew).
Legal basis:
- Section 25(2) no. 2 TDDDG (Germany) (storage/access is strictly necessary to provide the function expressly requested by the user),
- additionally Art. 6(1)(f) GDPR (legitimate interest in providing a user-friendly experience for the selected settings and in organizing the notice display).
You can delete or block cookies via your browser settings. In that case, stored settings (e.g., language/theme) may be lost.
8) External links to social media profiles (LinkedIn, GitHub, X)
Our website contains links to our profiles on LinkedIn, GitHub and X (formerly Twitter). These are simple hyperlinks. We do not use social media plugins/widgets that transfer data to the respective providers when our website is loaded.
If you click one of these links, you will leave our website. From that point on, the respective provider is responsible for the processing of personal data. In particular, your IP address and potentially information about the page you came from (referrer/redirect information) may be processed. If you are logged in to the respective service, the provider may be able to associate the visit with your user account.
Legal basis for providing the links: Art. 6(1)(f) GDPR (legitimate interest in offering information and communication options via external platforms).
Providers:
- LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Privacy information: linkedin.com/legal/privacy/eu
- GitHub: GitHub B.V., Prins Bernhardplein 200, 1097JB Amsterdam, The Netherlands / GitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA
Privacy information: docs.github.com/site-policy/privacy-policies/github-privacy-statement
- X: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland
Imprint: legal.x.com/de/imprint.html
9) Appointment scheduling via Calendly (external link)
We offer the option to book an appointment via an external link using the service "Calendly". When you click the link, you leave our website and are redirected to Calendly. From that point onward, appointment scheduling takes place on Calendly's pages and Calendly's privacy information applies.
For appointment scheduling, we process the data you enter (e.g., name, email address, potentially phone number, preferred time slot and any additional information you provide) in order to plan, conduct and (if necessary) follow up on the appointment.
The legal basis is Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in efficient appointment organization).
Calendly may also process technical data when you use its pages (e.g., log and device data such as IP address, referrer information, and timestamps) and may set cookies or similar technologies under its own responsibility.
This may involve processing/transfers to third countries (e.g., the United States). Calendly describes the transfer mechanisms used (e.g., the EU-US Data Privacy Framework and Standard Contractual Clauses) in its privacy information.
Provider:
Calendly, Inc.
Attn: Privacy Department
115 E Main St., Ste A1B
Buford, GA 30518
USA
Privacy Notice: https://calendly.com/legal/privacy-notice
Data Processing Addendum (for Calendly customers): https://calendly.com/legal/data-processing-addendum
10) Recipients / processors
We only disclose personal data to the extent necessary, in particular to:
- Microsoft (Azure) as hosting/IT service provider (processor).
- Calendly, Inc., Buford, GA, USA, as service provider for appointment scheduling (processor/recipient, insofar as personal data is processed in the course of scheduling appointments).
11) International data transfers (third countries)
Depending on the setup of the services used and support/operational processes, processing or access from countries outside the EU/EEA cannot be fully excluded in every case.
Where a transfer to a third country takes place, it will only occur in accordance with the requirements of Art. 44 et seq. GDPR (e.g., appropriate safeguards such as Standard Contractual Clauses), as may be provided for in the relevant contractual documents of the service provider.
12) Your rights
Under the GDPR you have the following rights:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
To exercise your rights, simply email: datenschutz@oscian.com.
13) Right to lodge a complaint with a supervisory authority
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
For non-public bodies in Bavaria (Germany), the competent authority is generally:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Website: lda.bayern.de
14) Data security (TLS/SSL)
We implement appropriate technical and organizational measures to protect your data. This website is generally available via TLS encryption (https).
15) Changes to this Privacy Policy
We will update this Privacy Policy if the website, the technologies used, or the legal requirements change.
In the event of any discrepancies or inconsistencies between the German and the English version, the German version shall prevail.