Legal
Privacy Policy
Last updated: July 26, 2026
This privacy notice explains which personal data is processed when you visit this website or use the contact form, why it is processed, and which rights data subjects have.
1. Controller
AXA & DBV Versicherung Eduard Scherer
Gänsemarkt 10
97980 Bad Mergentheim
Phone: 07931 4810131
Email: eduard.scherer@axa.de
2. Hosting and server log data
This website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When the website is accessed, the hosting provider processes technically necessary connection data. This may include the IP address, date and time, requested page or file, amount of data transferred, referrer URL, browser type, operating system, and device information.
Processing is necessary to deliver the website securely and reliably, diagnose technical errors, and prevent attacks. The legal basis is Art. 6(1)(f) GDPR. Log data is retained only for as long as required for operation, troubleshooting, and security, unless a security incident or legal obligation requires longer retention.
Vercel may process data in the United States and other countries. Where required, transfers are based on appropriate safeguards, in particular the EU Standard Contractual Clauses.
3. Contact requests and contact form
When you contact us by form, email, or telephone, the information you provide is processed to respond to your request and conduct further communication. Name and email address are required in the form; telephone number, topic, and message are optional. The submission time and technical anti-abuse information are also processed.
Processing for pre-contractual or contract-related requests is based on Art. 6(1)(b) GDPR. Other requests are processed under Art. 6(1)(f) GDPR, based on the legitimate interest in properly handling enquiries. Where consent is given, Art. 6(1)(a) GDPR also applies. Consent can be withdrawn at any time with future effect.
The information is deleted once the request has been fully handled, unless legal retention obligations, an ongoing contractual relationship, or legitimate interests require continued storage.
4. Email delivery via Resend
The email service Resend, provided by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, is used to transmit contact requests. The contact details and content entered in the form are sent to Resend and processed for message delivery.
Resend acts under data processing terms. Data may be processed in the United States. Its Data Processing Addendum provides for safeguards including the EU Standard Contractual Clauses for transfers outside the European Economic Area.
Delivery and log data held by Resend is deleted according to the applicable or contractually agreed retention periods. Messages held by the controller are deleted when no longer required and no legal retention obligation applies.
5. Protection against abusive requests
The contact form uses a hidden field, a timing check, and a locally generated image CAPTCHA with a short validity period. The entered characters are validated on the server against a signed verification token. No biometric analysis, profiling, or external CAPTCHA provider is used.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is protecting the form and technical infrastructure from spam and misuse.
6. Cookies, analytics, and locally hosted fonts
This website currently does not use analytics, marketing, or tracking services. It does not embed social-media plugins or third-party videos and does not use tracking cookies requiring consent.
The website font is served locally. Loading the font therefore does not establish a connection to Google Fonts or another external font provider.
7. Links to social networks
The footer contains ordinary links to Instagram, Facebook, and LinkedIn. No data is transferred to these services merely by visiting this website. Data is processed by the respective provider only after an external link is selected, potentially outside the European Economic Area.
Further information is available in the privacy notices of the respective platforms.
8. Recipients of personal data
Personal data is disclosed only to parties that require it for the stated purposes, including the controller and contracted hosting and email providers. Further disclosure takes place only where legally permitted or required, necessary for contractual performance, or based on consent.
9. Retention period
Personal data is retained only for as long as required for its purpose. It is then deleted unless statutory retention duties, the establishment or defence of legal claims, or another legal reason requires further storage. Commercial correspondence may be subject to commercial and tax-law retention obligations.
10. Data subject rights
Subject to the applicable legal requirements, data subjects have the following rights:
- Access to personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of personal data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR)
- Withdrawal of consent with future effect (Art. 7(3) GDPR)
11. Right to lodge a complaint
Under Art. 77 GDPR, data subjects may lodge a complaint with a supervisory authority, in particular in the country of their habitual residence, place of work, or place of the alleged infringement. The competent authority for the controller is generally the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
12. Encryption and data security
The website is transmitted using HTTPS encryption. Appropriate technical and organisational measures are also used to protect personal data against loss, manipulation, and unauthorised access. Completely risk-free transmission over the internet cannot be guaranteed.
13. Changes to this privacy notice
This privacy notice will be updated when the website, the services used, or legal requirements change. The version published on this page is the applicable version.