Privacy Policy
Cybervize Consulting GmbH
Last updated: August 2026
1. Controller
Cybervize Consulting GmbH
Graf-Adolf-Str. 41
40210 Düsseldorf
Germany
Phone: +49 211 1587 4349
Email: contact@cybervize.de
Managing Director: Alexander Busse
Commercial register: District Court Düsseldorf, HRB 101465
VAT ID: DE347501488
Scope of this policy
This policy covers www.cybervize.de and the appointment booking at book.cybervize.de. Two links on our website lead to separate offerings governed by their own terms:
- app.cybervize.de — OdySecure. Access is reserved for customers. For the data our customers process in the platform we act as a processor; the respective contract and its data processing agreement govern that. Alongside this, we process data there as a controller in our own right, for example for user accounts, sign-in and access and security logs. Users receive the information required under Art. 13 and 14 GDPR for that within the application itself. Clicking the login link opens the application; this transmits your IP address and browser information to our server.
- community.cybervize.de — the community area with its own sign-in. The privacy notices published there apply.
2. Overview of Data Processing
The following overview summarizes the types of data processed and the purposes of their processing.
Types of Data Processed
- Inventory data (e.g., names, addresses)
- Contact data (e.g., email, phone numbers)
- Content data (e.g., form inputs, messages)
- Usage data (e.g., pages visited, access times)
- Meta/communication data (e.g., IP addresses, device information)
Categories of Data Subjects
- Visitors and users of the website
- Communication partners (contact form, email, support chat)
Purposes of Processing
- Provision of the website and its content
- Responding to contact inquiries
- Appointment scheduling
- Reach measurement and web analytics
- Security measures
- Consent management
3. Legal Bases
Below you will find an overview of the legal bases of the GDPR on which we process personal data.
- Consent (Art. 6(1)(a) GDPR): The data subject has given consent to the processing of their personal data for one or more specific purposes (e.g., analytics cookies, marketing cookies).
- Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR): Processing is necessary for the performance of a contract or for pre-contractual measures (e.g., contact inquiries, appointment bookings).
- Legitimate interests (Art. 6(1)(f) GDPR): Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party (e.g., technically necessary cookies, security measures, server logs).
4. Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing to ensure a level of protection appropriate to the risk.
These measures include securing the confidentiality, integrity, and availability of data by controlling access to data, as well as encrypting transmission via SSL/TLS (recognizable by the lock icon in your browser and the address line with "https://"). TLS protects the transport path between your device and our server. It protects neither the endpoints themselves nor the subsequent processing: on the server the data is present in the clear, and authorised recipients such as processors see it in the clear. How we secure that processing is set out in the sections on the individual services.
5. Rights of Data Subjects
As a data subject, you are entitled to various rights under the GDPR:
- Right to object (Art. 21 GDPR): You have the right to object at any time to the processing of your personal data based on Art. 6(1)(f) GDPR for reasons arising from your particular situation.
- Right to withdraw consent: You have the right to withdraw any consent given at any time. The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
- Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether personal data concerning you is being processed and to obtain access to that data.
- Right to rectification (Art. 16 GDPR): You have the right to request the completion or correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You have the right to request the immediate deletion of data concerning you.
- Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of processing.
- Right to data portability (Art. 20 GDPR): You have the right to receive your data in a structured, commonly used, and machine-readable format.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2-4, 40213 Düsseldorf.
6. Website Hosting
Vercel
Our website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). Each time you access our website, Vercel automatically collects information in server log files that your browser transmits. This includes:
- IP address of the requesting device
- Date and time of the request
- Requested URL and referrer URL
- Browser type and operating system
- Amount of data transferred
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Our legitimate interest lies in the stable and secure provision of the website.
Third country transfer: Vercel processes data in the USA. The transfer is based on the EU-U.S. Data Privacy Framework. Further information: Vercel Privacy Policy.
7. Consent Management
Cookie banner
To obtain and manage your cookie consent, we use a self-hosted open-source solution. No data is transmitted to an external service provider and no IP address is processed.
Your consent decision is stored exclusively locally in your browser, in a cookie named "cc_cookie" that contains your cookie preferences (necessary / statistics / marketing) and the time of the decision. Your consent is not logged server-side.
The cookie has a storage duration of 12 months. You can adjust or withdraw your consent at any time via the "Cookie settings" link (e.g. in our cookie policy).
Legal basis: Storing or reading the information required for consent on your device is based on Section 25(2)(2) TDDDG; the management of consent is based on our legitimate interest in legally compliant consent documentation (Art. 6(1)(f) GDPR).
8. Web Analytics
Google Tag Manager and Google Analytics
We use Google Tag Manager (GTM) and Google Analytics by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Tag Manager itself does not store personal data but serves as a tool for managing tags and tracking services.
Google Analytics is integrated via the Tag Manager and uses cookies to enable analysis of website usage. The information generated by the cookie about your use of this website is usually transmitted to a Google server.
We use Google Consent Mode v2. The Tag Manager container is only loaded after you have consented to the statistics category in our cookie banner. As long as you have not, no Google script runs, no tracking cookies are set and no data reaches Google. If you withdraw consent later, we immediately set storage access to denied via Consent Mode. The container already loaded stays in the document for the current page view and is not loaded again on the next one.
Data processed: Usage data (pages visited, dwell time, click behavior), device information and your IP address. The IP address is processed when the connection is established and for coarse geolocation, and is discarded by Google before Google Analytics logs it; it is not stored. The transmission to Google servers does take place.
Storage duration: Session to 2 years, depending on the cookie type.
Legal basis: Consent (Art. 6(1)(a) GDPR).
Third country transfer: Google may process data in the USA based on the EU-U.S. Data Privacy Framework. Further information: Google Privacy Policy.
Opt-out: You can withdraw your consent at any time via the cookie banner or use the browser plugin to deactivate Google Analytics: https://tools.google.com/dlpage/gaoptout.
9. Contact Form and Email Communication
Contact Form
When you contact us via our contact form, we process the data you provide to handle your inquiry. This includes:
- Name (required)
- Email address (required)
- Company (optional)
- Phone number (optional)
- Subject (required)
- Message (required)
Self-assessments (security check and NIS-2 maturity check)
On the pages “security check” and “NIS-2 maturity check” you can fill in a questionnaire. Answering the questions and evaluating them happens entirely in your browser. Your answers are not transmitted to us and not stored by us.
Only if you explicitly ask for your result to be sent to you at the end do you transmit your contact details together with the completed questionnaire. Delivery happens in two steps (double opt-in):
- You first receive only a short confirmation email without your result. It contains a link valid for seven days. We do not store your details for this: they sit cryptographically signed inside that link.
- Only once you click the link do we send your results with the 90-day roadmap to your address and notify ourselves so that we can respond to it.
Without that click, nothing further happens. We do not process the address, and the link lapses. This means nobody can enter a third party's address and have an email from us sent to them this way. Delivery uses the same provider as the contact form (see “Email delivery” below). This does not enrol you in a newsletter or mailing list.
- Email address (required in order to send the result)
- Company (optional)
- Your complete result: the rating per area, your largest gaps and your individual answers to every question, so that we can follow the result and respond to it
Legal basis: performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR), as the transmission happens at your request. Without that request your answers never leave your browser.
Email Delivery via Brevo
For sending contact form messages, we use the service Brevo (formerly Sendinblue) by Brevo GmbH (Köpenicker Str. 126, 10179 Berlin, Germany). Brevo processes the data entered in the form exclusively for the purpose of delivering the email to us.
Legal basis: Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR). The processing serves to handle your inquiry.
Storage duration: Your data will be deleted as soon as it is no longer required for the purpose for which it was collected. For contact inquiries, this is generally the case when the conversation has ended and the matter has been conclusively resolved.
Further information: Brevo Privacy Policy.
10. Appointment Booking
Cal.com (self-hosted)
For online appointment booking, we use a self-hosted instance of the open-source software Cal.com on our own servers in the EU (available at book.cybervize.de). No external booking service is involved. We integrate the booking in two ways:
- Redirect: Booking links on our website (paths under
/go/) redirect you to book.cybervize.de. A connection is only established once you click the link. - Embedding: On the "Book an appointment" page, the booking form is embedded as an iframe. Your browser connects to book.cybervize.de as soon as the iframe scrolls into view, without you having to click anything. This transmits your IP address and browser information to our own server. No external booking service is involved; OVHcloud acts as a processor for server operations (see the hosting section).
When booking an appointment, we process the data you enter (e.g., name, email address, desired appointment time, answers to booking questions) as well as technical data (IP address, browser information).
Legal basis: Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR). The appointment booking serves to initiate a business relationship.
Recipients: To conduct the appointment, the calendar entry including the video conference link is created via Google Calendar/Google Meet (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland); booking confirmations and reminders are sent via the email service provider Mailgun (EU region, Sinch Sweden AB) acting as a processor. Google may also process data in the USA (EU-U.S. Data Privacy Framework).
Retention: Booking data is deleted once it is no longer required for conducting and following up on the appointment, at the latest when the business purpose ceases and statutory retention periods expire.
11. Podcast Integration
Spotify
On our website, we embed a podcast player from Spotify AB (Regeringsgatan 19, 111 53 Stockholm, Sweden) as an iFrame. When loading the player, Spotify may set cookies and process technical data (IP address, browser information, device ID).
Legal basis: Consent (Art. 6(1)(a) GDPR). The Spotify player is only loaded after your consent via the cookie banner.
Third country transfer: Spotify may process data in countries outside the EU/EEA. Further information: Spotify Privacy Policy.
Podigee
For hosting our podcast, we use Podigee (Podigee GmbH, Germany). When accessing podcast content, Podigee may process technical data such as IP address and browser information to provide the content and create access statistics.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Our legitimate interest lies in providing our podcast content.
Further information: Podigee Privacy Policy.
12. Content Management System
Sanity CMS
For managing our blog content, we use Sanity (Sanity AS, Grønland 32, 0188 Oslo, Norway). Sanity serves as a headless CMS for providing content. When delivering content via the Sanity API, technical data (IP address) may be processed.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Our legitimate interest lies in the efficient management and provision of our website content.
Further information: Sanity Privacy Policy.
13. SSL/TLS Encryption
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content, such as inquiries you send to us as the site operator. An encrypted connection is indicated by the browser address line changing from "http://" to "https://" and by the lock icon in your browser bar.
With SSL/TLS encryption active, the data is protected against being read in transit between your device and our server. The protection ends at the endpoints: on our server the data is present in the clear, and parties we lawfully involve, such as processors, see it in the clear. Which ones those are, and on what basis, is set out in the sections on the individual services.
14. Changes to This Privacy Policy
We reserve the right to adapt this privacy policy to ensure it always complies with current legal requirements or to implement changes to our services. The new privacy policy will apply to your subsequent visits.
15. Cookie Declaration
A detailed list of all cookies used on this website, broken down into necessary, statistics, and marketing cookies, can be found in our cookie policy.
