Terson Consulting
Legal

Privacy policy

Protecting your personal data matters to us. We process your data exclusively on the basis of the applicable law (GDPR, BDSG, TDDDG). This privacy policy informs you about the nature, scope and purpose of the processing of personal data on this website.

The controller for data processing on this website is:

Terson Consulting UG (haftungsbeschränkt)
Annaberger Straße 2a
04159 Leipzig
Deutschland

Phone: +49 341 92709981
Email: kontakt@terson-consulting.de

1. Privacy at a glance

The following notes provide a straightforward overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information can be found in the sections of this policy below.

The controller for data processing on this website is the website operator named above. Some of your data is collected because you provide it to us — for example when you fill in the contact form or write to us. Other data is recorded automatically by our systems when you access the website; this is primarily technical data such as browser type, operating system or the time of the page request.

Part of this data is collected in order to provide the website free of errors and securely. Where contracts are initiated via the website, we also process the data submitted in order to handle your enquiry. No statistical evaluation of your browsing behaviour takes place on this website: we use no analytics, tracking or marketing tools and embed no advertising networks.

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data, as well as a right to rectification or erasure of that data. You may withdraw any consent given at any time with effect for the future. You also have the right to lodge a complaint with the competent supervisory authority. You are welcome to contact us at any time regarding this and any other data protection matter.

2. General information and definitions

This privacy policy uses the terminology of the General Data Protection Regulation (GDPR). “Personal data” means any information relating to an identified or identifiable natural person. “Processing” means any operation performed on personal data, such as collection, storage, use, transmission or erasure.

As a rule, we process personal data only insofar as this is necessary to provide a functioning website together with our content and services, or where a legal basis permits the processing. We are currently not required to appoint a data protection officer; for any data protection questions you can reach us using the contact details stated in the imprint.

Please note that data transmission over the internet — for example when communicating by email — can have security vulnerabilities. Complete protection of data against access by third parties is not possible.

3. Legal bases for processing

Where we obtain consent for processing operations or rely on other legal bases, the following legal bases of the GDPR apply:

  • Art. 6 (1) (a) GDPR (consent): where you have given us consent for a specific processing purpose. Where the consent concerns the storage of information on your device or access to it, § 25 (1) TDDDG applies in addition. Consent can be withdrawn at any time.
  • Art. 6 (1) (b) GDPR (contract): to perform a contract with you or to take steps prior to entering into a contract, for example when handling an enquiry.
  • Art. 6 (1) (c) GDPR (legal obligation): to comply with statutory obligations, such as retention periods under commercial or tax law.
  • Art. 6 (1) (f) GDPR (legitimate interest): to safeguard our legitimate interests, provided your interests or fundamental rights do not override them, for example for the secure and stable operation of the website.
  • Art. 49 (1) (a) GDPR: in the event of your explicit consent to the transfer of personal data to third countries.

4. Your rights as a data subject

With regard to the personal data concerning you, you have the following rights. An informal message to the contact details stated in the imprint is sufficient to exercise them:

  • Access (Art. 15 GDPR): you may request confirmation of whether and which personal data concerning you we process.
  • Rectification (Art. 16 GDPR): you may request the rectification of inaccurate data or the completion of data concerning you.
  • Erasure (Art. 17 GDPR): you may request the erasure of your data, unless statutory retention obligations prevent this.
  • Restriction (Art. 18 GDPR): you may request the restriction of processing — for example while we verify the accuracy of contested data, instead of erasure in the case of unlawful processing, where you need the data to pursue legal claims, or while an objection under Art. 21 (1) GDPR is still being weighed.
  • Data portability (Art. 20 GDPR): you may request the data you provided to us in a structured, commonly used and machine-readable format. Direct transmission to another controller takes place where technically feasible.
  • Objection (Art. 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on Art. 6 (1) (e) or (f) GDPR. See the following section for details.
  • Withdrawal of consent (Art. 7 (3) GDPR): you may withdraw consent given at any time with effect for the future. The lawfulness of processing carried out until withdrawal remains unaffected.

5. Right to object in particular situations and to direct marketing (Art. 21 GDPR)

Where data processing is based on Art. 6 (1) (e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data; this also applies to profiling based on those provisions. The respective legal basis on which processing is founded can be found in this privacy policy.

If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims (objection pursuant to Art. 21 (1) GDPR).

Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will no longer be used for direct marketing purposes (objection pursuant to Art. 21 (2) GDPR).

An informal message to the contact details stated in the imprint is sufficient to object.

6. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.

The competent authority for us is the supervisory authority of our registered seat: the Saxon Data Protection Commissioner (Die Sächsische Datenschutzbeauftragte), Dresden. Contact details and the complaint form are available at www.saechsdsb.de. You may also contact the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.

7. Provision of the website and server log files (hosting)

This website is hosted externally. The personal data collected on this website is stored on the servers of the host. The provider is Vercel Inc., 440 N Barranca Ave, Covina, California 91723, USA. Vercel provides the infrastructure required to operate the website and processes the resulting data exclusively on our behalf and in accordance with our instructions.

External hosting takes place for the purpose of performing our contracts with prospective and existing customers (Art. 6 (1) (b) GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6 (1) (f) GDPR). We have concluded a data processing agreement with Vercel pursuant to Art. 28 GDPR — a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR. Regarding the transfer to the USA, see the section “Transfer of data to third countries”.

Each time the website is accessed, the server automatically records information transmitted by your browser in what are known as server log files. This processing serves exclusively the technically flawless, secure and stable operation of the website and the prevention of misuse; this data is not merged with other data sources. The log files are stored for a short period only and then deleted, unless further retention is required for security reasons. The following is recorded in particular:

  • IP address of the accessing device
  • date and time of the server request
  • the specific page or file requested
  • browser type and browser version
  • the operating system used
  • the previously visited page (referrer URL)

8. SSL / TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL / TLS encryption. You can recognise an encrypted connection by the address bar of your browser switching from “http://” to “https://” and by the padlock symbol in the browser bar. When encryption is active, the data you transmit to us cannot be read by third parties.

9. Cookies and technically necessary storage

This website uses no tracking, analytics or marketing cookies and embeds no advertising or statistics services (such as Google Analytics or the Meta pixel). For this reason, no consent banner (“cookie banner”) is required.

Cookies are small data packets stored on your device that cause no damage there. They are stored either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are deleted automatically at the end of your visit; persistent cookies remain stored until you delete them yourself or your browser does so automatically.

We use exclusively technically necessary mechanisms, for example to store your language selection (such as a “NEXT_LOCALE” cookie) so that the website is displayed in the language you have chosen. This storage is strictly necessary for the operation you have expressly requested; the legal basis is § 25 (2) no. 2 TDDDG in conjunction with Art. 6 (1) (f) GDPR. No third-party cookies are set.

You can configure your browser to inform you about the setting of cookies, to allow cookies only in individual cases, to exclude them generally, or to delete them automatically when the browser is closed. Disabling cookies may limit the functionality of this website — here this essentially concerns the storage of your language selection.

10. Contact and contact form

If you send us enquiries via the contact form, we process the data you provide in order to handle your enquiry and in case of follow-up questions. Via the contact form we collect: name, company (optional), email address, telephone number (optional), the selected topic and your message. Mandatory fields are marked as such; providing further data is voluntary. We do not pass this data on to third parties without your consent.

The legal basis is Art. 6 (1) (a) GDPR (your consent, which you give expressly before submitting) as well as Art. 6 (1) (b) GDPR insofar as your enquiry relates to the conclusion or performance of a contract. In all other cases, processing is based on our legitimate interest in effectively handling the enquiries addressed to us (Art. 6 (1) (f) GDPR).

To deliver the form message to our mailbox we use the service provider Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as a processor. The data you enter is transmitted to Resend and processed on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place with Resend.

To prevent automated misuse (spam) we use a hidden form field (“honeypot”) and a short-term, IP-based limit on submission frequency. For this limit, the IP address is processed only transiently in memory; the legal basis is Art. 6 (1) (f) GDPR (interest in the security and functionality of our offering).

For every message received via the form we additionally record technical details of the submission: the IP address, the approximate location our hosting provider derives from it (city, region, country, time zone and approximate coordinates), your browser identifier (user agent) and a technical request ID. These details are transmitted to our mailbox together with your message and stored there alongside the enquiry. They serve solely to detect and trace abusive enquiries or enquiries sent under a false identity; they are not evaluated for advertising or analytics purposes. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in preventing abusive contact). They are deleted together with the respective enquiry.

We store your enquiry and the associated data until the purpose of storage no longer applies — for example because your enquiry has been dealt with conclusively —, you ask us to erase it, or you withdraw your consent. Mandatory statutory provisions, in particular retention periods, remain unaffected.

11. Enquiries by email and telephone

If you contact us by email or telephone, your enquiry including all resulting personal data (name, contact details, request) will be stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.

This data is processed on the basis of Art. 6 (1) (b) GDPR where your enquiry relates to the performance of a contract or is necessary to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in effectively handling the enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) where this has been obtained.

The data you send us remains with us until you ask us to erase it, withdraw your consent, or the purpose for storage no longer applies. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.

12. Job applications

If you apply for an advertised position or send us a speculative application, we process the data you submit — such as contact details, CV, references and the information you provide about yourself — exclusively in order to carry out the application procedure. Applications reach us by email at the address stated on our careers page; there is no separate upload function.

The legal basis is § 26 (1) sentence 1 BDSG in conjunction with Art. 88 GDPR (decision on the establishment of an employment relationship) as well as Art. 6 (1) (b) GDPR. Insofar as you voluntarily provide further information, its processing is based on your consent pursuant to Art. 6 (1) (a) GDPR.

If no employment relationship comes about, we delete your documents no later than six months after the procedure has been concluded, unless you have consented to longer storage — for example to be included in a candidate pool — or statutory retention obligations apply. Please do not send us special categories of personal data within the meaning of Art. 9 GDPR (such as information on health, religion or origin) unless it is necessary for the application.

13. AI advisor in the configurator

On the “Configurator” page we offer an AI-supported advisor. It asks you a few questions about your project and compiles a non-binding proposal with indicative figures. Use is voluntary: you can reach the same result via the guided self-build or directly via the contact form.

Only the information you enter yourself in the conversation or select from the answer options offered is processed. Please do not enter special categories of personal data (Art. 9 GDPR) or data relating to third parties there — the contact form is sufficient for getting in touch personally.

To generate the responses, we transmit your input via the Vercel AI Gateway (Vercel Inc., address as above) to the model provider OpenAI (OpenAI, L.L.C., 1455 3rd Street, San Francisco, CA 94158, USA) as a further processor. The models used are GPT-5 mini for the conversation and GPT-5 for creating the proposal.

We do not store the conversation permanently. It exists only in your browser for as long as you keep the page open and is passed to the interface with each round so that the advisor knows the context; closing or reloading the page discards it. According to the providers used, the transmitted content is not used to train the models; short-term storage for misuse and security monitoring at the model provider is possible.

The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in enabling prospective clients to obtain a quick and comprehensible initial assessment — as well as Art. 6 (1) (b) GDPR insofar as use serves to initiate a contract. Regarding the transfer to the USA, see the section “Transfer of data to third countries”.

14. Fonts (locally hosted web fonts)

To display fonts consistently, this website uses web fonts. The fonts used are delivered locally from our host's server and are embedded at the time the website is built. When the website is accessed, no connection is established to third-party servers, in particular not to Google, and no personal data is transmitted to third parties in this context.

15. Recipients of personal data

In the course of our business activities we work with external parties; this sometimes requires the transfer of personal data. We only pass on personal data where this is necessary to handle a contract or enquiry, where we are legally obliged to do so (for example towards tax authorities), where a legitimate interest pursuant to Art. 6 (1) (f) GDPR exists, or where another legal basis permits the disclosure. Your data is never sold.

Where processors are used, we pass on personal data only on the basis of a valid data processing agreement pursuant to Art. 28 GDPR. We currently use the following processors:

  • Vercel Inc., Covina, USA — hosting and delivery of the website as well as routing the requests to the AI advisor.
  • Resend, Inc., San Francisco, USA — delivery of contact form messages to our mailbox.
  • OpenAI, L.L.C., San Francisco, USA — generation of the AI advisor's responses (via the Vercel AI Gateway).

16. Transfer of data to third countries

Some of the service providers we use are based in the United States. Processing of personal data outside the European Union can therefore not be ruled out.

We transfer data only to providers that are certified under the EU-US Data Privacy Framework and with which the European Commission's standard contractual clauses pursuant to Art. 46 (2) (c) GDPR have additionally been agreed. These instruments are intended to ensure that a level of protection equivalent to European requirements also applies to processing in the USA.

Please note that under the current legal situation, access by US authorities to data cannot be entirely ruled out despite these safeguards.

17. Storage period

Unless a more specific storage period is stated within this privacy policy, we process personal data only for as long as this is necessary for the respective purpose or as statutory retention periods require. If you assert a justified request for erasure or withdraw your consent, your data will be deleted unless we have other legally permissible grounds for storing it — such as retention periods under tax or commercial law. In the latter case, erasure takes place once those grounds cease to apply.

18. No automated decision-making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, that produces legal effects concerning you or similarly significantly affects you does not take place. This also applies to the AI advisor: its proposal is non-binding, and every offer is reviewed by us personally and issued under our responsibility.

19. Objection to advertising emails

We hereby object to the use of contact data published within the scope of the imprint obligation for the purpose of sending advertising and information material that has not been expressly requested. We expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam emails.

20. Currency and amendment of this privacy policy

This privacy policy is currently valid and carries the date stated below. Further development of our website or amended legal or regulatory requirements may make it necessary to adapt this privacy policy. The version in force at any given time can be accessed on this page at any time.

Last updated: September 2026