Privacy Policy
Working draft dated 10 October 2026. Actual hosting services, data flows and retention periods must be verified before publication.
1. Controller
Brechel Electronic – Industrial Interface Systems (BE-IIS), Philipp Brechel, Hindenburgstraße 100/1, 73207 Plochingen, Germany. Email: contact@be-iis.eu. See Imprint.
2. Website access and technical logs
The web server processes connection data as necessary to deliver the website, potentially including IP addresses, requested URLs, access times and browser characteristics. Purposes include availability and security (normally GDPR Article 6(1)(f)). To verify: Synology/Web Station, reverse proxy, router and any additional logs and retention periods.
3. Local basket and currency selection
The basket currently uses browser localStorage to retain product identifiers, quantities and selected currency across visits. The visitor can delete local data using their browser. The legal classification of technically necessary local storage must be checked against the actual implementation.
4. Optional CSV export and import
Visitors may download a CSV containing basket items and import it later. They can optionally include contact details. CSV files are not encrypted and are saved on the visitor’s device. Product records can be checked against current published offers when a file is imported.
5. Order and quote inquiries
The intended inquiry process handles customer type, name, email, optional business name and VAT ID, billing and shipping address, selected products and quantities, currency and inquiry type. The purpose is to answer pre-contractual requests and, where relevant, administer a contract (GDPR Article 6(1)(b)). Legal recordkeeping may additionally require Article 6(1)(c) and other lawful grounds.
Technical implementation: Quotation inquiries can be transmitted through PHP as one email to BE-IIS with an XML attachment once SMTP has been configured. No payment is initiated and no automatic customer email is sent. Temporary server-side hashed request fingerprints and rate-limit data are used to help prevent duplicates and abuse. Before production, verify recipients, SMTP provider, retention/deletion periods and access controls.
6. Email and processors
Messages are processed to respond to inquiries. To verify: email provider, any data processing agreements under GDPR Article 28 and international transfers.
7. Anti-abuse measures
Rate limiting and bot protection are envisaged. Should a third-party verification provider such as Cloudflare Turnstile be deployed, the processing, legal basis and any transfers must be explained prior to activation.
8. Retention periods
Personal data is retained only for as long as necessary to process requests and meet legal requirements. Specific schedules remain to be defined for unconverted inquiries and for legally relevant business documents.
9. Data subject rights
Subject to the applicable GDPR conditions, data subjects have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to a supervisory authority. Contact: contact@be-iis.eu.
10. Other services
Before publication: inventory the actual analytics tooling (e.g. Umami), embedded third-party content, cookies, fonts, security services and international data transfers. This draft does not claim that no other tools are in use.