Privacy Policy
1. Controller
The controller responsible for processing personal data on this website is:
Terwey Research & Advisory UG (haftungsbeschränkt)
Düvelsbeker Weg 16
24105 Kiel
Germany
Represented by: Prof. Dr.-Ing. Torben Terwey
Email: mail@terwey.de
Telephone: +49 173 3616 404
2. General Information
We process personal data only where this is necessary to provide a functional and secure website, respond to enquiries, perform contracts or take steps prior to entering into a contract, or comply with legal obligations.
Personal data means any information relating to an identified or identifiable natural person. Relevant data may include IP addresses, technical connection data, contact details and the content of messages sent to us.
The legal bases referred to in this Privacy Policy are those of the General Data Protection Regulation (“GDPR”).
3. Hosting and Server Log Files
This website and the associated email services are hosted by:
Host Europe GmbH
Hansestrasse 111
51149 Cologne
Germany
When you access this website, the hosting infrastructure processes technical connection and usage data. This may include:
- IP address
- date and time of access
- requested page or file
- amount of data transferred
- referrer URL
- browser type and version
- operating system
- access status and error messages
This processing is necessary to deliver the website, maintain its stability and security, identify technical problems and defend against misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of the website and the protection of our systems.
Log data is deleted when it is no longer required for these purposes, unless continued retention is necessary to investigate a security incident or comply with a legal obligation.
Host Europe processes data on our behalf in accordance with Article 28 GDPR.
4. Content Delivery and Security through Cloudflare
The website uses infrastructure and security services provided through Cloudflare. The provider is:
Cloudflare, Inc.
101 Townsend Street
San Francisco, CA 94107
USA
Cloudflare operates a content delivery network and provides security functions. Connections to this website may therefore be routed through Cloudflare’s network. In this context, Cloudflare may process technical data such as IP addresses, request data, browser and device information, timestamps and security-related identifiers.
The purposes of this processing are the secure and efficient delivery of the website, protection against automated attacks and misuse, and improvement of the website’s availability.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the security, reliability and performance of our website.
Cloudflare may process data outside the European Economic Area, particularly in the United States. Where required, such transfers are based on an applicable adequacy decision or appropriate safeguards under Articles 44 et seq. GDPR, including the EU Standard Contractual Clauses.
Further information is available in Cloudflare’s Privacy Policy:
https://www.cloudflare.com/privacypolicy/
5. Technically Necessary Cookies
This website does not currently use analytics, advertising or marketing cookies.
Cloudflare may set the technically necessary cookie __cf_bm. This cookie is used to distinguish legitimate access from automated or abusive traffic and to protect the website against attacks. It does not serve advertising purposes and generally expires after approximately 30 minutes.
The storage of or access to information on your device is based on Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG), as this is necessary to securely provide the website requested by you. The associated processing of personal data is based on Article 6(1)(f) GDPR.
If optional services or cookies are added in the future, they will only be activated after consent where consent is legally required.
6. Local Web Fonts
This website uses the Montserrat font. The required font files are hosted locally on our own web space.
When these fonts are displayed, no connection is established to Google Fonts or other external font providers.
The local provision of fonts is based on Article 6(1)(f) GDPR. Our legitimate interest is the consistent, efficient and privacy-friendly presentation of the website.
7. Contact by Email and Contact Form
You can contact us by email or through the contact form provided on this website.
When you contact us, we process the information you provide. This may include:
- your name, if provided
- your email address
- the content of your message
- the date and time of submission
- technical connection data necessary to transmit the form
The contact form is implemented using WordPress and the CoBlocks plugin. Submitted information is processed by the website’s hosting infrastructure and forwarded to our email account hosted by Host Europe.
We process this information solely to handle and respond to your enquiry and, where applicable, to take steps prior to entering into a contract.
For contractual or pre-contractual enquiries, the legal basis is Article 6(1)(b) GDPR. For other enquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the effective handling of communications addressed to our company.
The information is deleted when the enquiry has been conclusively dealt with and there is no further legal or contractual reason to retain it. Statutory retention obligations and the retention of information required for the establishment, exercise or defence of legal claims remain unaffected.
You are not legally or contractually required to contact us or provide optional information. However, we require a valid email address and the content of your enquiry in order to respond.
8. Links to External Websites and Social Networks
This website contains links to external websites and profiles, including LinkedIn, ResearchGate, Instagram and university websites.
No data is transmitted to these providers merely because the links are displayed on our website. A connection to the respective provider is established only when you select a link. The provider may then process personal data independently and may set cookies. The privacy policy of the respective provider applies.
We have no control over data processing carried out by the operators of external websites.
9. Recipients of Personal Data
Within our company, personal data is accessible only to persons who require it for the relevant purpose.
External recipients may include:
- hosting and email service providers
- content delivery and security providers
- technical service providers
- professional advisers or public authorities where disclosure is legally required
Service providers acting on our behalf process personal data only in accordance with our instructions and applicable data protection law.
10. Storage Periods
Unless a more specific storage period is stated in this Privacy Policy, personal data is retained only for as long as necessary for the respective processing purpose.
Data may be retained for a longer period where this is required by statutory commercial or tax retention obligations or where it is necessary for the establishment, exercise or defence of legal claims. Once the relevant reason for retention no longer applies, the data is deleted or anonymised.
11. Your Rights
Subject to the applicable legal requirements, you have the following rights:
- the right of access under Article 15 GDPR
- the right to rectification under Article 16 GDPR
- the right to erasure under Article 17 GDPR
- the right to restriction of processing under Article 18 GDPR
- the right to data portability under Article 20 GDPR
- the right to object under Article 21 GDPR
- the right to withdraw consent under Article 7(3) GDPR
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
12. Right to Object
Where personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.
We will then cease processing the relevant personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
13. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
The supervisory authority responsible for private organisations based in Schleswig-Holstein is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
Holstenstrasse 98
24103 Kiel
Germany
Telephone: +49 431 988-1200
Email: mail@datenschutzzentrum.de
Website: https://www.datenschutzzentrum.de/
You may also contact another competent supervisory authority, particularly in the EU Member State of your habitual residence or place of work.
14. Security
This website uses encrypted HTTPS connections. We also take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Internet-based data transmission cannot, however, be guaranteed to be completely secure.
15. Automated Decision-Making
We do not use personal data collected through this website for automated decision-making or profiling within the meaning of Article 22 GDPR.
16. Changes to this Privacy Policy
We may update this Privacy Policy if the website, the services used or the applicable legal requirements change.
Last updated: August 2026
