Privacy
This website needs no cookie banner, because it runs without tracking, without recognition, and without loading anything from anyone else’s servers. The only cookie is a technically necessary session cookie. What is processed anyway is listed here — in full, in plain language. The German Datenschutzerklärung is the legally binding version.
Controller
Tree IT Systems, owner Maximilian Jung
Altremda 27, 07407 Rudolstadt, Germany
Phone +49 36744 204750
E-mail
We are not legally required to appoint a data protection officer. Questions about data protection are answered by the owner.
In short
- No cookies for analytics, advertising or recognition, no recognition across websites, no advertising networks, and no analytics script in your browser. The only cookie is a technically necessary session cookie.
- Visitor statistics are produced solely on our own server from the log files — no cookie, no script, no third party. Details under “Website statistics”.
- No fonts, scripts, maps, videos or icons from other servers — the page loads files from tree.systems only, so your IP address is not passed to anyone.
- No profiles, no automated decision-making, no profiling.
- What is processed: server logs and the statistics our own server produces from them, the enquiries you send us — by e-mail, by phone or through the contact form — and, only if you choose it yourself, one display setting stored in your browser.
Server logs
Every request creates a log entry on the web server. It serves security and the investigation of unauthorised access only, not the analysis of visitor behaviour.
Logged are:
- the IP address of the requesting machine
- date and time of the request
- the access method and the file or URL requested
- the server's response status (served, not found, refused …)
- referrer, browser type and operating system, as far as the browser sends them
The legal basis is our legitimate interest in operating the site securely (Art. 6 (1) (f) GDPR). The logs serve that purpose only: secure operation, detecting faults, and investigating unauthorised access.
Entries are deleted automatically by the server's log rotation. The period is governed by that purpose alone: we keep them only as long as they are needed for the security of the service, and entries relating to a specific incident until that incident is resolved. They are not combined with any other data and no profile is built.
Website statistics
From the log files described above, our server produces visitor statistics (AWStats). They show summary figures — page views, referring pages, browser and country groups — and serve to improve the operation and the content of this website.
The analysis runs entirely on our own server. No script is executed in your browser for it, no cookie is set, and nothing is stored on or read from your device — so no consent under § 25 TDDDG is required and there is nothing here to consent to. There is no recognition across websites, no profiles are built, and no data is passed to third parties. The legal basis is our legitimate interest in operating and improving this website in a way that suits its visitors (Art. 6 (1) (f) GDPR). You may object to this processing under Art. 21 GDPR.
The analysis is password-protected and accessible only to us. The monthly report files stay on the server so that periods remain comparable; they are produced solely from the log data described above.
Hosting
The website runs on cloud servers that we administer ourselves. The infrastructure is provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in its data centres in Falkenstein and Nuremberg (Germany) and Helsinki (Finland). All of these are in the European Union, so no data is transferred to a third country for the operation of this website. A data processing agreement under Art. 28 GDPR is in place with Hetzner. Operating, configuring and maintaining the servers is our own responsibility.
Contact by e-mail or phone
If you write or call, we process what you send — name, e-mail address or phone number and the content of your enquiry — solely in order to answer it. The legal basis is Art. 6 (1) (b) GDPR for contractual or pre-contractual matters, otherwise Art. 6 (1) (f) GDPR.
Enquiries are deleted once they are settled, unless statutory retention periods apply; business correspondence is subject to commercial and tax retention periods of up to ten years.
E-mail is an open channel. If you want to send us something confidential, ask for a key first — we are happy to encrypt.
Contact form
The form on Contact asks for four things: your name, your e-mail address, a subject and your message. All four are required — without them we cannot answer you. You may additionally ask for a copy of your message to be sent to your own address, and you have to confirm that you have read this notice before the form can be sent.
The form does not write anything into a database on this website. Your entries are sent to us as an e-mail and are handled from then on exactly like an e-mail you write yourself, including the retention described in the section above. The legal basis is Art. 6 (1) (b) GDPR where the message concerns a contract or its preparation, and otherwise our legitimate interest in answering enquiries, Art. 6 (1) (f) GDPR.
The form is protected against automated submissions by a captcha that runs entirely on this server (Joomla's “proof of work” captcha). Your browser performs a small calculation; no puzzle is shown, no cookie is set, you are not tracked and nothing is transmitted to a third party. In addition, a check of your own session and a word filter on our server keep automated submissions out. Joomla sets one technically necessary session cookie here, as it does on every page; see “Session cookie” for details.
Sending e-mail
We use Microsoft 365 (Microsoft Ireland Operations Limited) for system notifications and business correspondence. Microsoft processes your e-mail address and the message content as a processor; an Art. 28 GDPR agreement is in place, processing in the USA cannot be excluded, and it relies on the standard contractual clauses and the EU-US Data Privacy Framework.
Map
The contact page shows a map of where we are. It is an image on this server, like every other picture on the site: opening the page requests nothing from a map provider, no map service sees your IP address, and there is nothing here to consent to. There is no script behind it and nothing is stored on your device.
The map is our own drawing. It is based on published coordinates and distances; no map service's rendering is reproduced and no third-party map material is embedded. The image was made once and is not refreshed while you browse.
Under the map are three links that open our location in Google Maps, Apple Maps or OpenStreetMap. They open in a new window and they are ordinary links: nothing is loaded from those providers while you are on this page, and nothing is transmitted to them unless you follow a link yourself. The links are marked noreferrer, so the provider is not told which page you came from either. What happens after that is governed by the provider you chose.
Session cookie
Joomla sets a technically necessary session cookie when any page is requested. It contains nothing but a randomly generated session identifier. It stores no personal data, does not recognise you across websites, is not passed to any third party, and expires at the end of the session.
It carries the language version you are viewing and the contact form's protection against abusive submissions. Without it we could not serve the site in the language you chose or with a working form.
Access to your device is therefore exempt from consent under § 25 (2) no. 2 TDDDG: the cookie is strictly necessary to provide the service you expressly requested. No consent and no cookie banner are required for it. The processing rests on our legitimate interest in the secure and functioning operation of this website, Art. 6 (1) (f) GDPR.
Colour scheme / display
By default this website follows your operating system's or browser's light/dark setting. Nothing is stored and nothing is transmitted to us for this; the setting is evaluated entirely inside your browser.
If you manually select “Light” or “Dark”, your browser stores that choice locally in its local storage (key tree-theme, value light or dark). It contains no identifier, is never transmitted to us or to third parties, and serves only to keep the display you asked for on your next visit. The storage is therefore strictly necessary to provide the service you expressly requested (§ 25 (2) No. 2 TDDDG); no consent is required. Selecting “Auto” deletes the stored value; you can also remove it at any time via your browser's site data.
Fonts
The typeface (Montserrat, SIL Open Font License) is served from our own server. There is no connection to Google Fonts or any other font service, and no IP address is passed to a third party.
What this website does not do
- No cookies for analytics, marketing or recognition. The only cookie is the technically necessary session cookie Joomla sets on every page.
- No Google Analytics and no Matomo — no analytics tool that runs in your browser, recognises you, or passes data to third parties.
- No maps, videos or social media buttons embedded from other providers, and no external captcha.
- No newsletter and no advertising e-mail without an explicit sign-up.
Who receives your data
Only the parties needed to operate the site: the data centre operator (hosting) and the e-mail provider, each as a processor. Nothing is passed on for advertising purposes and no data is sold. Authorities receive data only where we are legally obliged to provide it.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Consent, once given, can be withdrawn at any time. A message to
You may also lodge a complaint with a supervisory authority. Ours is the Thuringian Commissioner for Data Protection and Freedom of Information (Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit, Häßlerstraße 8, 99096 Erfurt, the authority’s website).
Security
The site is served over HTTPS only, so the connection is encrypted. Systems and applications are patched regularly, access is limited to what is necessary, and backups are tested.
Version
Version of 23 September 2026. Changes to this statement are published here; the version available at the time of your visit applies.