Privacy Policy
Protecting your personal data matters to us. This website is built on a “privacy by design” principle: we process as little data as possible, avoid tracking and set no cookies that require consent. Below we inform you about the nature, scope and purpose of the processing of personal data on this website.
1. Controller
The controller for data processing on this website is:
SECURITYSQUAD GmbH
Lerchenweg 6
88699 Frickingen, Germany
Phone: +49 7554 2109910
Email: info@securitysquad.de
2. Data Protection Officer
We have appointed a data protection officer:
Daniel Oppe
SECURITYSQUAD GmbH
Lerchenweg 6, 88699 Frickingen, Germany
Email: dataprivacy@securitysquad.de
3. Hosting
This website is hosted on a server operated by us in a data centre in Germany. The provider of the server infrastructure is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Processing takes place to fulfil our contractual and pre-contractual obligations (Art. 6(1)(b) GDPR) and in the interest of the secure and efficient provision of our online offering (Art. 6(1)(f) GDPR). A data processing agreement (DPA) is in place with the provider.
4. Server log files
When this website is accessed, information transmitted by your browser is automatically stored in server log files:
- browser type and version
- operating system used
- referrer URL
- host name of the accessing device
- time of the server request
- IP address
This is collected on the basis of Art. 6(1)(f) GDPR for the technically flawless and secure provision of the website. This data is not merged with other data sources and is deleted after a short time.
5. Contacting us
You can contact us by email (e.g. info@ or support@securitysquad.de) or by phone. We do not operate a contact form with data storage on the website. We process the information you provide when contacting us solely to handle your request and in case of follow-up questions.
The legal basis is Art. 6(1)(b) GDPR (pre-contractual or contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in effectively handling your enquiry). The technical processing of your email communication takes place via Microsoft 365 (see section 8). Your information remains with us until your request has been fully dealt with or you ask us to delete it; mandatory statutory retention periods remain unaffected.
6. Reach measurement with Umami
To analyse the use of this website statistically, we use Umami – self-hosted, cookieless analytics software operated on our server in Germany. Umami records anonymised usage data in a data-minimising way (e.g. pages visited, approximate origin, browser type used) as well as individual interaction events – such as an appointment link being opened or the quick check being started. Only the fact that the action occurred is recorded; input such as the domain tested is not transmitted. This happens without setting cookies, without building cross-device profiles and without passing data to third parties or third countries. No personal reference is established. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in data-minimising reach measurement). As no cookies or comparable techniques are used, no consent is required for this.
7. Appointment booking (Microsoft Bookings) and Microsoft Teams
For online appointment scheduling we link to Microsoft Bookings; online appointments are usually conducted via Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The data you provide when booking or during the appointment is used to plan and hold the appointment. The legal basis is Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR and your consent (Art. 6(1)(a) GDPR). Processing in third countries (USA) is possible; Microsoft is certified under the EU-US Data Privacy Framework. Details: Microsoft privacy statement (opens in a new window).
8. Email communication (Microsoft 365)
We operate our email mailboxes (including info@ and career@securitysquad.de) and email delivery via Microsoft 365 (Exchange Online). The provider is Microsoft Ireland Operations Limited (address as in section 7). When you contact us by email or we send you emails, Microsoft processes the content and metadata of this communication on our behalf. Processing in third countries (USA) is possible; Microsoft is certified under the EU-US Data Privacy Framework, and a data processing agreement is in place. The legal basis is Art. 6(1)(f) GDPR (efficient and secure communication) or Art. 6(1)(b) GDPR for contract-related communication.
9. Job applications
Please send applications by email to career@securitysquad.de. We process the applicant data submitted solely to carry out the application process. The legal basis is Section 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR (initiation of an employment relationship). After the process is concluded, we delete your documents in compliance with statutory periods, unless you have consented to longer storage (e.g. for future positions).
10. Cookies
This website sets no tracking or marketing cookies and currently no cookies that require consent; a cookie consent banner is therefore not required. Details can be found in our cookie policy.
11. Social media and external links
We maintain profiles on social networks (LinkedIn, Facebook, Instagram) and link in the footer to our location on Google Maps. On our website this content is merely linked and not embedded – data is therefore only transmitted to the respective providers once you actively click one of these links. From that point, the privacy terms of the respective provider apply (LinkedIn: Microsoft; Facebook/Instagram: Meta; Google Maps: Google), who may also process data in the USA. We have no influence on this processing.
12. SSL / TLS encryption
For security reasons, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in the address bar and the padlock symbol in your browser.
13. Your rights
Within the scope of the statutory provisions, you have the right at any time to:
- information about your stored personal data (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing (Art. 21 GDPR)
- withdrawal of consent given, with effect for the future
You also have the right to lodge a complaint with the competent supervisory authority. For data protection matters, please contact dataprivacy@securitysquad.de.
14. Security Score Check
On our vulnerability management page we offer a free quick check. You enter a domain and we retrieve publicly published data about it only: DNS records, the TLS certificate, the home page and standardised well-known paths. Technically this is no different from a browser visit. For the quick check itself we collect no personal data from you – neither a sign-in nor contact details. We process the domain tested and the result in order to perform the check; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in operating the service and preventing its misuse).
If you would like the full report, you request it via the form below the result. First name, last name, business email address, telephone number and company are mandatory there. We process these details for two purposes:
- Delivery of the report you requested. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).
- Contacting you about this result and about services that fit it, by email and telephone. The legal basis is your consent under Art. 6(1)(a) GDPR, which you give expressly when submitting the form. Without that consent the full report cannot be requested; the quick check remains available to you anonymously regardless.
You may withdraw your consent at any time with effect for the future, informally to dataprivacy@securitysquad.de. This does not affect the lawfulness of processing carried out before the withdrawal. After a withdrawal we no longer use your details to contact you.
The details are stored in the testing system that performs the check and produces the report; we operate it in Germany. They are not stored in the database of this website, and they are not passed to third parties for advertising purposes. We delete the details once the purpose ceases to apply – at the latest after withdrawal of your consent and completion of any related matter – unless statutory retention periods require otherwise.
We do not carry out an active in-depth test that interacts with systems via this form. Such testing takes place solely after verification of authorisation and written engagement.
15. Currency of this privacy policy
We update this privacy policy as soon as the legal situation or our services change. The version published on this page applies.