Skip to content

// Legal

Privacy Policy

We take the protection of your personal data seriously — and have built this website so that as little of it as possible arises in the first place. Below we inform you in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR) about the data we process when you visit this website and when you contact us. This is the English rendering of our German privacy policy; the German version remains authoritative.

1. Controller

The controller within the meaning of Article 4 (7) GDPR for the processing of data on this website is:

CaNo Solutions GmbH
Niederstr. 41
40789 Monheim am Rhein
Germany

Represented by Managing Director Mirko Novkovic
Phone: +49 (2173) 993046-0
Email: info@cano-sol.de

For questions about data protection and to exercise your rights, please use the contact details above.

2. Principle: a deliberately data-frugal website

This is a static website. The pages are generated in advance and delivered unchanged. There are no user accounts, no personalised content and no profiles.

In concrete terms, that means the following for you as a visitor:

Because no cookies or comparable techniques are used, this website also needs no consent banner. Our cookie policy covers this in more detail.

3. Hosting

This website is hosted by Hetzner Online GmbH. The servers used are located in Nuremberg, Germany. All data arising when a page is requested is processed exclusively on this infrastructure within the European Union.

Hetzner Online GmbH processes the data on our behalf and solely on our instructions, on the basis of a data processing agreement pursuant to Article 28 GDPR. The legal basis for using a hosting provider is our legitimate interest in the secure and reliable operation of this website (Article 6 (1) (f) GDPR).

4. Server log files

Each time a page is requested, the web server automatically stores access data in what are known as server log files. This transmission is technically necessary for the page to be delivered to your browser at all. The data recorded includes in particular:

This data is not merged with other data sources and is not used to identify individuals or to evaluate their behaviour. No evaluation for marketing or statistical purposes takes place.

The legal basis is Article 6 (1) (f) GDPR. Our legitimate interest lies in the technical provision of the website, in ensuring system security and in investigating and defending against attacks and misuse.

Log data is retained only for as long as is necessary for these purposes and is then deleted. Where data is exceptionally kept longer because it is needed to investigate a specific security incident, it is deleted once that matter has been resolved.

5. Encrypted transmission (TLS)

For security reasons this website uses TLS encryption, recognisable by “https://” in your browser’s address bar. Data you transmit to us is thereby protected in transit against access by third parties. The certificate in use is issued by the certificate authority Let’s Encrypt.

6. Contact by email and telephone

If you contact us by email or by telephone, we process the details you provide — usually your name, contact details, company and the content of your enquiry. We use this data solely to deal with your request and for any follow-up questions arising from it.

The legal basis is Article 6 (1) (b) GDPR where your enquiry is directed at concluding or performing a contract, and otherwise Article 6 (1) (f) GDPR based on our legitimate interest in responding to business enquiries.

Please note that email may be transmitted unencrypted over the internet. If you need to send us particularly confidential information, please contact us in advance so that we can agree a suitable route.

7. Contact form

A contact form is present on this website. For as long as the associated form processing is not yet in operation, please reach us by telephone or email using the contact details above.

Once the contact form is active, the following applies to the processing: we process the data you enter into the form — in particular name, email address, where applicable telephone number and company, and your message — for the purpose of handling your enquiry. Mandatory fields are marked as such in the form; any further details are voluntary.

The legal basis is Article 6 (1) (b) GDPR for pre-contractual or contractual enquiries, and otherwise Article 6 (1) (f) GDPR based on our legitimate interest in responding. Transmission is encrypted. Data is not passed to third parties, apart from technical service providers engaged as processors under Article 28 GDPR and named in this policy.

We delete enquiry data once your matter has been dealt with conclusively and no statutory retention obligations prevent deletion. Where a contractual relationship arises from the enquiry, retention follows the requirements of commercial and tax law.

As soon as form processing goes live, we will update this policy and name the service providers then in use.

8. Recipients and transfers to third countries

Your data is passed on to third parties only where this is necessary to perform a contract, where we are legally obliged to do so, where you have consented, or where we can rely on an overriding legitimate interest. In connection with operating this website, only our hosting provider is currently involved as a processor (see section 3).

No personal data is transferred to countries outside the European Union or the European Economic Area in connection with the operation of this website.

9. Retention and deletion

We process personal data only for as long as is necessary for the relevant purpose. After that the data is deleted or its processing is restricted. Where statutory retention obligations exist — in particular under commercial and tax law — the data concerned is kept for the duration of those obligations and blocked for other purposes.

10. No automated decision-making

Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place. We do not evaluate your behaviour on this website and build no usage profiles.

11. Your rights as a data subject

In relation to your personal data you have the following rights against us:

Access (Article 15 GDPR)

You may request information about whether and which personal data we process about you, for which purposes, to which recipients we pass it on where applicable, and how long we store it.

Rectification (Article 16 GDPR)

You may request the correction of inaccurate data and the completion of incomplete data.

Erasure (Article 17 GDPR)

You may request the erasure of your data where the statutory conditions are met and no retention obligations stand in the way.

Restriction of processing (Article 18 GDPR)

You may request that we restrict the processing of your data, for instance while its accuracy is being verified.

Data portability (Article 20 GDPR)

You may request that we provide the data you supplied to us in a structured, commonly used and machine-readable format, or — where technically feasible — transmit it directly to another controller.

Objection (Article 21 GDPR)

Where we process data on the basis of a legitimate interest under Article 6 (1) (f) GDPR, you may object to that processing on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Withdrawal of consent (Article 7 (3) GDPR)

Where you have given us consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.

An informal message to the contact details in section 1 is sufficient to exercise these rights. Doing so costs you nothing.

12. Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, Article 77 GDPR gives you the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. You may contact the authority of your habitual residence, your place of work or the place of the alleged infringement.

The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Düsseldorf

LDI NRW is the data protection supervisory authority of the German federal state of North Rhine-Westphalia, in which our registered office is located.

13. Data security

We take technical and organisational measures in accordance with Article 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. These include encrypted delivery of the website, a group of authorised persons limited to what is necessary, and continuous updating of the systems in use. Our measures are reviewed and adjusted on an ongoing basis in line with technical developments.

14. Changes to this privacy policy

We will adapt this privacy policy whenever the legal situation, our services or the technical make-up of this website change — for example when the contact form goes into operation or further functions are added. The version available at the time of your visit applies.

Further legal texts

As of August 2026. Under legal review.