1. Controller

Cystrat Services GmbH, Zwingerstraße 17c, 63477 Maintal, Germany
Phone: +49 6109 500 32 41 · Email: [email protected]

For data protection requests please contact [email protected] (subject: “Data protection”).

2. Principles

We process personal data exclusively in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This website uses cookies and comparable technologies, including statistics, tracking and marketing technologies. Anything that is not strictly necessary is loaded only after your explicit consent, managed and blocked in advance by our consent management platform (see section 4).

3. Hosting and server log files

When you access this website your browser transmits technically necessary data which is stored in log files:

  • truncated or processed IP address
  • date and time of access
  • page requested, volume of data transferred, HTTP status code
  • referrer URL as well as browser, device and operating system identifiers
  • Accept-Language header (used to select the language version)

Purpose: delivery, stability and security of the website. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure operation). Retention: usually 7 days, no longer than 30 days; in case of security incidents until the matter is resolved. Our hosting provider acts as a processor under Art. 28 GDPR.

4. Cookies and local storage

We use Cookiebot CMP, a consent management platform of Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, as our processor under Art. 28 GDPR. Until you decide, scripts and cookies that require consent are blocked (“prior blocking”). Cookiebot processes your anonymised IP address, browser and device data, the URL visited, the time of your decision, a random consent ID (cookie CookieConsent, up to 12 months) and the consent state per category. Legal basis: Sec. 25 (2) no. 2 TDDDG for the strictly necessary consent record and Art. 6 (1) (c)/(f) GDPR (demonstrating consent under Art. 7 (1) GDPR).

Cookies in the categories preferences (e.g. cystrat-lang for your language choice, cookie and localStorage, up to 12 months), statistics (reach measurement, usage analysis) and marketing (cross-page tracking, campaign measurement, advertising, including third-party providers) are set only after your explicit consent — legal basis: Sec. 25 (1) TDDDG together with Art. 6 (1) (a) GDPR. Where a provider processes data outside the EU/EEA, this is based on EU standard contractual clauses and/or the EU-US Data Privacy Framework; residual risks such as access by public authorities cannot be fully excluded. The always up-to-date list of all cookies actually used, including provider, purpose and lifetime, is published in our cookie declaration. You may withdraw your consent at any time with future effect via cookie settings or your browser settings. Details: Cookie Policy.

5. Contact form, email and phone

The contact form on this website does not transmit data to our server: your entries are handed over locally in your browser to your own email client. We only receive your details (name, email address, subject, message and any voluntary information) once you send that email.

Purpose: handling your enquiry and subsequent communication. Legal basis: Art. 6 (1) (b) GDPR (pre-contractual or contractual communication) or Art. 6 (1) (f) GDPR. We delete enquiry data as soon as the purpose ceases to apply, at the latest after 24 months; statutory retention obligations (e.g. Sec. 147 AO, Sec. 257 HGB) remain unaffected.

6. Customer and contract data, incident response

Within Managed SOC, SIEM, incident response and forensic engagements we process customer data on instruction as a processor (Art. 28 GDPR) on the basis of a data processing agreement. Processing takes place in Germany or the EU/EEA; transfers to third countries only occur with appropriate safeguards under Art. 44 et seq. GDPR.

7. Recipients and processors

We only disclose data to hosting and IT service providers, our consent management provider Usercentrics A/S (Cookiebot CMP), the providers of the statistics and marketing services you have consented to, our email provider and tax advisors/authorities where legally required. All service providers are contractually bound under Art. 28 GDPR.

8. Your rights

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR)
  • withdrawal of consent with future effect (Art. 7 (3) GDPR)

You may lodge a complaint with a supervisory authority; the authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.

9. Data security and changes

This website is delivered via TLS encryption (HTTPS). We implement technical and organizational measures in accordance with Art. 32 GDPR. This privacy policy is effective as of August 2026 and will be updated if our processing activities or the legal framework change.

Provider details: Imprint.

10. Further GDPR information

  • No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
  • Providing data is voluntary; without contact details we cannot process your enquiry.
  • Our services are aimed at businesses; we do not knowingly collect data of children under 16.
  • Consents are documented and can be withdrawn at any time (Art. 7 (3) GDPR).
  • Personal data reaching us during incident response is processed strictly on instruction under a DPA.

See also our Cookie Policy.