Deutsche Fassung · English
Privacy Notice
Information on the processing of personal data under Art. 13 GDPR when using the vehicle catalogue at germankos.de.
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
bitte in legal.json ausfüllen: unternehmen.firmabitte in legal.json ausfüllen: unternehmen.strasse
bitte in legal.json ausfüllen: unternehmen.plz bitte in legal.json ausfüllen: unternehmen.ort
Deutschland
Phone: bitte in legal.json ausfüllen: unternehmen.telefon
E-mail: bitte in legal.json ausfüllen: unternehmen.email
3. Processing activities in detail
3.1 Accessing the site (log data)
The catalogue application itself writes only the time, the requested address and the HTTP status code to the server console. No IP address is stored, and the application keeps no persistent log of its own.
Your IP address is held only transiently in memory in order to count failed login attempts for ten minutes and to fend off automated attacks on the access gate (see 3.2). It is discarded afterwards and never stored permanently.
- Purpose
- Delivering the site, operational security, detecting and preventing attacks on the access gate
- Legal basis
- Art. 6 (1) (f) GDPR – legitimate interest in the secure and uninterrupted operation of a restricted-access service holding confidential stock and pricing data
- Retention
- IP addresses for abuse prevention: ten minutes, in memory only
3.2 Signing in with an access code
The catalogue is not public. You sign in with an access code. After a successful sign-in a session cookie keeps you signed in for the duration of the session. It contains the name of the access grant and the expiry time, cryptographically signed. It serves the sign-in only and does not allow recognition beyond this site.
You can end the session at any time via “Sign out” in the header; the cookie is deleted immediately. Confidential content is also served so that the browser does not cache it – nothing is left behind on a shared machine after you sign out.
- Purpose
- Access control, maintaining the signed-in session, abuse prevention
- Legal basis
- Art. 6 (1) (f) GDPR – legitimate interest in access control, the confidentiality of the stock and the functioning of the signed-in catalogue; if you enquire as a sole trader on your own behalf, additionally Art. 6 (1) (b) GDPR. For the storage on your device, § 25 (2) no. 2 TDDDG, as it is strictly necessary to provide the service you expressly requested
- Retention
- 12 hours; deleted immediately when you sign out
3.3 Settings and shortlist in your browser
So that your selection survives to your next visit, the catalogue stores your chosen filters, the language, the net/gross setting, the sort order, your most recent search term and your shortlist in your browser's local storage.
This data never leaves your browser. It is transmitted neither to us nor to third parties and is not accessible to us.
Nothing is stored until you actually use one of these functions – merely opening the page stores nothing. You can remove what is stored at any time using the “Clear stored settings” button at the foot of the catalogue, or by clearing this site's data in your browser.
- Purpose
- Continuing the settings you made yourself
- Legal basis
- § 25 (2) no. 2 TDDDG; no processing by us takes place, as nothing is transmitted
- Retention
- Until you delete it
3.4 Contacting us
The vehicle detail view lets you copy the vehicle data or compose an e-mail. Clicking an e-mail link opens your own mail programme; nothing is transmitted to us at that point. Only when you send the message do we process the details it contains, in order to answer your enquiry.
- Purpose
- Handling your enquiry and initiating business
- Legal basis
- Art. 6 (1) (b) GDPR for enquiries relating to a contract, otherwise Art. 6 (1) (f) GDPR
- Retention
- Until your enquiry has been dealt with; beyond that only where commercial or tax retention periods apply
3.5 Managing access codes
So that access can be granted and withdrawn individually, we store a label for each access grant – usually the name of the company or contact person – together with a cryptographic check value of the access code. The code itself is not stored in plain text and cannot be recovered from that value.
- Purpose
- Issuing, verifying and withdrawing individual access rights
- Legal basis
- Art. 6 (1) (b) and (f) GDPR
- Retention
- Until access is withdrawn, at the latest 12 months after last use or when the catalogue is taken offline; documentation of a block for up to three years
To deliver the access code we use the business contact details given to us for the authorised person, usually their work e-mail address or phone number. We process these solely to issue and administer the access grant.
Where we suspect that an access code is being misused or used contrary to the terms of use, we block the access grant concerned and document that step.
Where the details of an authorised person were provided not by them but by their employer or an intermediary, this notice also serves as information under Art. 14 GDPR: only the categories named above are processed, and the source is the nominating company.
3.6 What expressly does not happen
No per-user activity log is kept. The server logs contain neither the name of the access grant nor an IP address, so it cannot be reconstructed which access grant viewed which vehicles. Vehicles viewed, filters set, search terms and the shortlist are not recorded on the server. There is no audience measurement, no profiling and no analysis of usage behaviour.
4. Cookies and local storage at a glance
| Name | Type | Purpose | Duration |
|---|---|---|---|
fzk_session | Cookie, HttpOnly, SameSite=Strict | Maintaining your sign-in | 12 hours |
fzk.state.v1 | local storage | Filters, language, net/gross, sort order, search term, shortlist | until you delete it |
No other cookies are set. There is no audience measurement, no profiling and no cross-site tracking. Because storage is strictly necessary or initiated by you, consent under § 25 (1) TDDDG is not required – which is why there is no consent banner.
5. Recipients
Your data is not passed to third parties unless this is necessary to perform a contract or we are legally obliged to do so.
6. Transfers to third countries
No personal data is transferred to countries outside the European Union or the European Economic Area.
7. Your rights
- Access to the data held about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure, unless retention obligations apply (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6 (1) (f) GDPR – see the separate notice below (Art. 21 GDPR)
An informal message to the contact details in section 1 is sufficient.
Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where that processing is based on Art. 6 (1) (f) GDPR.
This concerns the processing described in sections 3.1, 3.2 and 3.5. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
An informal message to the contact details in section 1 is sufficient.
8. Right to lodge a complaint
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR).
9. Is provision required?
Processing the connection data and the session cookie is technically necessary to provide the catalogue. Without it the restricted-access service cannot be used. Any further details you provide are voluntary.
10. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
11. Changes to this notice
We update this notice when the functions of the catalogue or the legal situation change.
Version: 14.09.2026