Privacy
Leiber GmbH is fully aware of the relevance of data protection issues on the Internet and sees it as its task to protect your privacy on our websites. Leiber GmbH takes sensible measures to protect all information received from our online visitors from unauthorized access and use. In addition, we regularly review our security measures. We have drawn up the following guidelines, which set out how we make use of the information we receive from visitors to our websites:
Privacy Policy
As of: November 11, 2025
1. Data Controller
Leiber GmbH
Franz-Leiber-Straße 1, 49565 Bramsche, Germany
Phone: +49 (0) 5461 9303-0
Email: ed.hbmgrebiel@ofni
This Privacy Policy applies to all language versions of the website (German, English, Polish).
2. Data Protection Officer
Email: ed.hbmgrebiel@bsd
Phone: +49 (0) 5461 9303-763
3. Supervisory Authority
The competent authority is the State Data Protection Commissioner of Lower Saxony
(Prinzenstraße 5, 30159 Hannover, www.lfd.niedersachsen.de).
4. General Information on Processing
We process personal data only to the extent necessary to provide a functional website, our content and services, and to respond to inquiries.
Legal basis: Art. 6(1)(a), (b), (c), and (f) of the GDPR, as well as § 25 of the TTDSG (for storage and retrieval processes on end devices).
Retention period/deletion: Data is deleted or anonymized as soon as the respective purpose no longer applies and there are no legal retention obligations.
Obligation to provide data: There is no obligation to provide personal data for purely informational use.
No automated decision-making/profiling: Does not take place.
5. Provision of the Website / Server Log Files
Purpose: Technical delivery, stability, IT security, error analysis.
Data: IP address, date/time, time zone, requested content, HTTP status, amount of data transferred, referrer URL, browser/OS.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
Retention period: 14 days; longer retention only for evidentiary purposes.
Recipient/Hosting: netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe – Server location: Nuremberg
Processing on behalf of the controller pursuant to Art. 28 GDPR
6. Contact (Email / Contact Forms)
We offer contact options via email and Contact Form 7; form content is stored via Advanced CF7 DB.
The CFDB7 plugin has been deactivated and will not be used in the future.
Purpose: Processing of inquiries, communication, and, if applicable, initiation of a contract.
Data: Name, company, email/phone, message, timestamp/form page, IP/browser metadata.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) or (f) GDPR (general communication).
Retention period: Form content 12 months, automatic deletion; email correspondence after case closure (6–10 years, if applicable).
Recipients: Authorized employees; data is transmitted to netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe – server location Nuremberg
Note: Please do not submit any sensitive data (e.g., health data) via the form.
7. Cookies, Consent Management (CMP), and § 25 TTDSG
When you visit the site, information may be stored or read, depending on your settings. We only set non-essential cookies with your consent.
Consent Management Tool (CMP): A Consent Management Tool (CMP) is not used, as no external resources are accessed and no cookies are set.
Only the OpenStreetMap service uses a two-click solution that requires active consent.
Currently, no consent management tool is used on the website, as no cookies or comparable technologies requiring consent are used. Accordingly, there are currently no options for objection or adjustment via a CMP.
8. Audience measurement with “WP Statistics” (cookie-free)
Purpose: Anonymous usage statistics for optimization.
Data: truncated IP address (hash), time, pages visited, referrer, browser; no cross-device tracking.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimal analysis); § 25 TTDSG not applicable.
Retention period: Raw data for a maximum of 6 months, then aggregated.
Recipients: No third parties; processing is done locally.
Objection: possible via email to the data protection officer or in the CMP (if selectable).
9. Integration of external content
9.1 OpenStreetMap (maps)
Used on certain subpages (e.g., dealers/distribution partners).
The map loads only after an active click (two-click solution).
Provider: OpenStreetMap Foundation (OSMF), United Kingdom.
Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG (consent).
Third country: UK – Adequacy decision in place.
Note: No map display without consent.
9.2 YouTube
No YouTube videos are embedded.
All films/videos are embedded locally; no data is transferred to third parties.
Legal basis for YouTube does not apply; no transfer to third countries.
10. Backups and Security
10.1 Backups (UpdraftPlus)
Purpose: Data backup for recovery following technical malfunctions.
Content: Backups may contain personal data.
Legal basis: Art. 6(1)(f) GDPR.
Retention period: Rotation principle, max. 90 days.
Storage location: Backups are stored on the server at netcup – netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe – server location Nuremberg
Retention period: Rotation principle, max. 90 days
Legal basis: Art. 6(1)(f) GDPR. Data Processing Agreement in place.
10.2 Security functions (AIOS)
Purpose: Defense against attacks, system integrity.
Data: IP address in case of failed attempts, time, URL.
Legal basis: Art. 6(1)(f) GDPR.
Retention period: Event-based; deletion upon completion.
11. Recipients, Data Processing, and Transfers to Third Countries
Internal recipients: Only authorized employees of Leiber GmbH.
External recipients: PMS Werbeagentur GmbH & Co. KG (Krefeld) for technical support;
netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe – Server location: Nuremberg
Processing on behalf of the controller: in accordance with Art. 28 GDPR.
Transfers to third countries: No transfers to third countries known
12. Retention periods (overview)
Server-Logfiles: 14 days
Form data (CF7 DB): 12 months
Emails: after case closure; 6–10 years if retention obligations apply
WP Statistics: max. 6 months
Backups: max. 90 days
Cookies / consents: according to CMP list
13. Additional Information
Separate privacy notices apply to applicants and business partners; these are available on the website.
14. Rights of data subjects (Art. 15–21 GDPR)
Access, rectification, erasure, restriction, data portability, objection, withdrawal of consent.
Objection to direct marketing: possible at any time.
Withdrawal: via email to ed.hbmgrebiel@BSD.
Complaints: to the LfD Lower Saxony.
15. Up-to-date status
Last content review: November 5, 2025.
This statement is reviewed regularly (every six months to annually) for up-to-date information and updated as needed.