XP360

Legal Notice & Privacy Policy

Legal notice under § 5 DDG and privacy policy under the GDPR. The legally binding version is the German original.

Legal Notice (Impressum)

Information in accordance with § 5 DDG (German law)

Rudi Zeilhofer — XP360

Irschenhauser Str. 90

82057 Icking, Germany

Email:

Responsible for content pursuant to § 18 (2) MStV: Rudi Zeilhofer (address as above)

Privacy Policy

1. Data controller

The controller for data processing on this website is Rudi Zeilhofer — XP360, Irschenhauser Str. 90, 82057 Icking, Germany. You can reach us by email at the address given in the legal notice above.

2. Principles

Protecting your personal data matters to us. We process personal data only within the framework of the applicable rules (GDPR, German Federal Data Protection Act, TDDDG). This website is deliberately data-minimising and works without analytics tools, tracking, or marketing cookies.

3. Hosting and server log files

This website is hosted by Netlify (Netlify, Inc., San Francisco, California, USA). When the site is accessed, information transmitted by your browser is automatically processed in server log files: IP address, date and time of access, the file requested, the amount of data transferred, the referrer URL, and your browser type, version, and operating system. This processing is technically necessary to deliver the website and to ensure its stability and security.

The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in secure, functional delivery). As Netlify is based in the USA, a transfer to a third country takes place. Netlify, Inc. is certified under the EU-U.S. Data Privacy Framework; for data transferred to the USA on this basis, an EU Commission adequacy decision applies (Art. 45 GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with Netlify.

4. Encryption (SSL/TLS)

For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in your browser's address bar.

5. Contact by email

If you contact us by email, we process the data you provide (email address, name where given, and the content of your message) in order to handle your enquiry. The legal basis is Art. 6 (1)(b) GDPR where your enquiry is aimed at concluding a contract, and otherwise Art. 6 (1)(f) GDPR (legitimate interest in responding to your enquiry). The data is deleted once it is no longer required and no statutory retention obligations prevent this.

6. Appointment booking via Calendly

To schedule appointments we offer a booking tool provided by Calendly LLC (Atlanta, Georgia, USA). Calendly content is loaded only after you actively click the “Book a free call” button. Only then is a connection to Calendly's servers established and data (including your IP address) transmitted. If you book an appointment, Calendly processes the data you enter (e.g. name, email address, preferred time) on our behalf.

The legal basis for loading the tool is your consent (Art. 6 (1)(a) GDPR), which you give by clicking and can withdraw at any time with effect for the future. Processing in connection with a specific booking is carried out to take pre-contractual steps (Art. 6 (1)(b) GDPR). Calendly LLC is certified under the EU-U.S. Data Privacy Framework; the transfer to the USA is safeguarded by the EU Commission's adequacy decision. A data processing agreement is in place with Calendly. Further information:calendly.com/legal/privacy-notice.

To carry out the booked appointment, we share data with further services: the booking request, including name, email address, and the date and time, is added to our Google Calendar (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA). To provide the video meeting, the date and time are transmitted to Zoom (Zoom Communications, Inc., San Jose, California, USA), which generates the meeting link. Both providers process the data on our behalf; for transfers to the USA, Google LLC and Zoom Communications, Inc. are certified under the EU-U.S. Data Privacy Framework. The legal basis is Art. 6 (1)(b) GDPR (carrying out the agreed appointment).

7. Cookies and analytics

This website sets no cookies for analytics or marketing purposes and uses no tracking or web analytics services. Any cookies set by Calendly during a booking serve solely the function of the booking tool.

8. Fonts and email display

The fonts used are served locally from our server; there is no connection to third-party servers (e.g. Google Fonts). Our email address is only shown after a click, to protect it from automated harvesting; no personal data is transmitted to third parties in the process.

9. Your rights

Under the GDPR you have the right to

  • access (Art. 15), rectification (Art. 16), and erasure (Art. 17),
  • restriction of processing (Art. 18) and data portability (Art. 20),
  • object to processing based on Art. 6 (1)(f) GDPR (Art. 21),
  • withdraw consent given, with effect for the future (Art. 7 (3)).

An informal message to the contact details in the legal notice is sufficient to exercise these rights.

10. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.

11. Further notes

No automated decision-making, including profiling, takes place. Providing your data is neither legally nor contractually required; however, without the data needed to contact us or book an appointment, we cannot process your request.

Last updated: 20 July 2026 · The legally binding version is the German original.