Please note: This is a translation of our German privacy policy, provided for your convenience. In the event of any discrepancy or ambiguity, the German version at smartfabrik.de is authoritative and legally binding.
This policy describes what happens to your data when you visit our website or send us an enquiry through one of our forms. It has deliberately been written so that you can understand, without any legal background, what data is generated, why we process it, who besides us gets to see it and how long we keep it.
The controller for the processing of personal data on this website within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR) is:
We plan smart home, KNX, electrical and lighting installations on a manufacturer-independent basis. Implementation is generally carried out by our sister company elektrofabrik GmbH, Reisholzer Werftstraße 31A, 40589 Düsseldorf.
We have not appointed a data protection officer. Having reviewed the matter, we are under no obligation to do so, either under Article 37 GDPR or under Section 38 of the Bundesdatenschutzgesetz (BDSG, German Federal Data Protection Act), because our company does not permanently employ at least twenty people on the automated processing of personal data, and because we are neither required to carry out a data protection impact assessment nor do we process personal data on a commercial basis for the purpose of transfer or for market and opinion research.
For all questions concerning data protection and for exercising your rights, please contact us directly at the address given above or at info@smartfabrik.de.
You have the following rights in relation to us. You can exercise them informally, no reasons need to be given, and you incur no costs in doing so.
The authority responsible for us is:
We answer requests concerning your rights without undue delay, and at the latest within one month of receipt. If a request is particularly extensive or complex, we may extend this period by up to two further months; we will inform you of this within one month of receipt, stating the reasons (Article 12(3) GDPR). To prevent anyone from obtaining information about you under your name, we may in cases of doubt request additional information to confirm your identity (Article 12(6) GDPR).
This section concerns all processing operations that we base on a legitimate interest under Article 6(1)(f) GDPR. In this policy, these are:
You have the right to object at any time, on grounds relating to your particular situation, to these processing operations. If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
Where your data is processed for direct marketing purposes, you have the right to object at any time and without giving reasons; this also applies to profiling connected with such marketing. Following your objection, we will no longer process your data for that purpose (Article 21(2) and (3) GDPR).
An objection is not subject to any particular form. An email to info@smartfabrik.de is sufficient.
To be distinguished from this are the processing operations that are based on your consent: the attribution of your enquiry to an advertising campaign via the sf_attr cookie (sections 7.2, 8.5 and 8.6) as well as all measurement, advertising and embedding services in sections 9 to 11. There, no right to object applies; instead, you may withdraw your consent at any time via the cookie settings (section 6.4).
When you access our website, your browser transmits technically necessary information to our server. This is recorded in what are known as server log files. This happens irrespective of any consent, because without this data no connection can be established.
We process this data in order to deliver the website, to ensure its stability and speed, to isolate faults and to detect and repel attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and fault-free operation of this website.
This data is not merged with other data sources. We do not use the log files to identify you as a person and do not evaluate them for advertising or reach measurement purposes.
The log files are deleted after seven days. If a specific incident — an attempted attack, for instance — requires longer retention, we store the entries concerned until the incident has been conclusively resolved.
The security software Wordfence is installed on this website. It checks incoming requests for known attack patterns and blocks suspicious access. In doing so, the IP address, time and type of request are evaluated and, in so far as a request has been classified as suspicious, logged in the database on our server. The processing takes place exclusively on our server in Germany; no transfer to the manufacturer occurs in this context. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in repelling attacks on our website. Security logs are deleted after 30 days.
We use the Borlabs Cookie consent management tool. It runs entirely on our own server; no data is transmitted to the manufacturer in the process.
The first time you access our website, you will be shown a notice allowing you to permit or refuse individual services or groups of services. Until you give your consent, the services described in sections 9 and 11 are blocked. Until then, no script from these providers is loaded and no connection to their servers is established.
The podcast player (section 10.1) is not controlled via the consent management tool. It is loaded by a separate solution only once you click the play area.
This information is stored in a cookie in your browser. This means we do not have to ask you again on every page view and can demonstrate that, and to what extent, you have given consent.
In addition, we log your decision on our server in Germany, with the same details: consent identifier, time, services selected and version of the banner. This log serves exclusively to demonstrate consent and is deleted after three years.
Storing the consent on your terminal equipment is strictly necessary under Section 25(2) no. 2 of the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG, German Telecommunications Digital Services Data Protection Act) in order to give effect to your decision, and therefore does not itself require consent. We base the documentation of your decision on Article 6(1)(c) GDPR in conjunction with Article 5(2) and Article 7(1) GDPR — we are legally required to be able to demonstrate consent. The consent cookie has a lifetime of one year; after that, we ask again.
In the footer of every page you will find the item Cookie settings. Through it you can review your selection at any time, subsequently permit individual services or withdraw your consent with effect for the future. Independently of this, you can delete cookies in your browser or restrict their storage from the outset; however, the technically necessary cookies described in section 7.1 are then affected as well, which may impair the usability of the website.
The following overview lists the cookies and comparable entries that are set by our own website. What is set by third parties only after your consent is described under the relevant service in sections 9 to 11.
The caching tool we use (WP Rocket) and the image optimisation tool (Imagify) speed up the delivery of pages and do not set any cookies for visitors who are not logged in. The security software described in section 5.4 likewise does not set any cookies during your visit.
You can delete the cookie at any time via your browser's cookie management; without this cookie, the website continues to function in full and unchanged. You can also request at any time at info@smartfabrik.de that we delete the source and advertising parameters stored with your enquiry.
Several forms are available on this website through which you can reach us — including the general contact form, the appointment request for our Basalte showroom, several forms relating to KNX reconstruction and the takeover of existing installations, as well as a form that appears when you are about to leave the page. All forms work on the same pattern.
Depending on the form, we ask for: name or first and last name, email address, telephone number, company, town or city, type of project or property, project phase, whether a project file for your existing installation is available, and your message. Mandatory fields are marked as such; everything else is voluntary and serves only to enable us to reply to you more quickly and more appropriately. In addition, we record the time of submission and the page from which you sent the form.
No files can be uploaded through the forms; we merely ask whether a project file exists and then arrange its transmission with you separately.
Please do not send us any special categories of personal data within the meaning of Article 9 GDPR through the forms — such as information on health, religion or trade union membership. We do not need such data for our planning services.
We process your details in order to handle your enquiry, to reply to you, to ask follow-up questions and, where appropriate, to submit an offer to you.
Providing this data is neither legally nor contractually required. Without it, however, we cannot deal with your enquiry; it is therefore necessary in order to contact us via the form.
To prevent our forms from being misused in an automated manner for advertising and fraudulent messages, we use two procedures that run entirely on our own server. No third-party service is involved; in particular, we do not use any CAPTCHA procedure such as Google reCAPTCHA.
The legal basis for both procedures is Article 6(1)(f) GDPR; our legitimate interest lies in protecting our forms and our mailbox against abusive automated use. No transfer to third parties or to a third country takes place.
Your enquiry is delivered as an email from our mailbox anfrage@smartfabrik.de to our address info@smartfabrik.de. The technical transmission takes place via the Microsoft Graph interface. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, acting for us as a processor on the basis of a contract under Article 28 GDPR.
Your enquiry is then held in two mailboxes: as a sent message in the mailbox anfrage@smartfabrik.de and as an incoming message under info@smartfabrik.de. info@smartfabrik.de is a shared mailbox accessed by several employees of our company who deal with enquiries. The remaining email traffic from this website is also sent via the same interface, for example system messages from the website administration.
Our mailboxes are operated with Microsoft 365. The data location is set to the European Union. Access from the USA — for maintenance and fault resolution, for instance — cannot nevertheless be ruled out; the legal grounds for this are set out in section 14.
In parallel with sending it by email, we store every enquiry in a dedicated table (sf_leads) in the database of our website. This database is located on our server in Germany (see section 12). The following are stored:
This storage serves three purposes. First, we do not lose any enquiry if an email is lost in transit or ends up in a spam folder. Second, we can keep track of the processing status and evaluate internally how many enquiries of what type we receive. To that extent, the legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR as set out in section 8.2. Third, we can see through which advertising routes enquiries reach us; in so far as the parameters from the sf_attr cookie are used for this, that processing is based on your consent under Article 6(1)(a) GDPR.
Access to this table is limited to those people in our company who deal with enquiries, as well as the technical support staff for our website within the scope of their duties.
If an enquiry has reached us via a Google advertisement and we have classified it internally as qualified, we report this outcome back to Google Ads. To do so, we create a file from the enquiry database and upload it to our Google Ads account. The process is initiated in each case by a person in our company, not automatically.
Only the following are transmitted:
Your name, your email address, your telephone number and the content of your message are not transmitted. Google can, however, attribute the click identifier to the same ad click, and thus to the same person, as we can. The purpose is to align our advertisements with those that lead to actual projects and not merely to form clicks.
The legal basis is your consent under Article 6(1)(a) GDPR, because the underlying click identifier may only be collected with your consent (section 7.2). The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; a transfer to the USA is possible, and the legal grounds are set out in section 14. You can object to the inclusion of your enquiry in this feedback, or withdraw your consent, at any time at info@smartfabrik.de.
If you write to us directly by email or call us, the same applies to the information arising in that context as to the forms: we process it exclusively in order to deal with your matter, on the same legal bases and with the same storage periods. All our email traffic runs via Microsoft 365 (section 8.4). Please note that an email sent unencrypted could be read by third parties on its way through the internet. For confidential information, we will gladly agree a secure means of transmission with you.
All services described in this section are loaded exclusively after your express consent. As long as you have not given consent, the consent management tool (section 6) blocks their integration; no script is loaded and no connection to the provider's servers is established.
The legal basis throughout is your consent under Article 6(1)(a) GDPR and — for the storage of and access to information on your terminal equipment — Section 25(1) TDDDG. You can withdraw this consent at any time with effect for the future via the Cookie settings in the footer.
The provider of all of the following services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A transfer to the USA to Google LLC is possible in this context; the legal grounds are set out in section 14. Google's privacy information: policies.google.com/privacy.
We use Google Tag Manager (container ID GTM-K793MB5G). The Tag Manager is not itself a measurement tool and does not store any cookies with personal content. It is the technical framework through which we deliver and control the services listed below.
The Tag Manager is loaded only after you have given consent: for as long as you have consented to neither the „Statistics" nor the „Marketing" category in the consent banner, the container file is not requested. No connection to Google arises and no IP address is transmitted. Only once you consent is the container file loaded from a Google server; your IP address is transmitted to Google in the process.
Which of the services listed below the container actually starts depends on your selection: consent to „Statistics" releases Google Analytics 4 only, consent to „Marketing" releases the advertising services only — Google Ads under section 9.3 and the Meta Pixel under section 11.
We use Google Analytics 4 with the measurement ID G-VQM16GNMBK in order to understand how our website is used: which pages are accessed, how long visitors stay, by which route they come to us and at which point they leave. We evaluate these figures in order to improve our content.
The following in particular are processed:
Enhanced conversions. If you submit one of our contact forms and have previously consented to the „Marketing" category, we additionally transmit your email address and telephone number in encrypted form (SHA-256 hash). The conversion takes place in your browser; the details never leave your device in plain text. Google matches these hashes against the hashes of signed-in Google accounts in order to attribute an enquiry to a preceding advertisement. Without consent to the „Marketing" category these hashes are neither generated nor transmitted. A hash is not an anonymous value but personal data in encrypted form — we treat it accordingly.
According to Google, Google Analytics 4 generally processes IP addresses only in truncated form and does not store them permanently. We have concluded a data processing agreement with Google under Article 28 GDPR. The retention period for user-level data in Google Analytics is set to 14 months; aggregated reports are retained beyond that but do not allow any conclusions to be drawn about individual persons.
The Google Signals feature and data sharing with Google advertising services are deactivated in our property. No cross-device linking of your visits with your Google account therefore takes place via Google Analytics.
We advertise with Google Ads. So that we can identify which advertisement actually led to an enquiry, we use Google Ads conversion measurement with the conversion ID AW-759401620.
If you click on one of our advertisements, a cookie is placed in your browser (including _gcl_au, lifetime 90 days). If you then reach a point that is relevant to us — in particular the submission of an enquiry form or a click on our telephone number or email address — Google reports to us that a conversion has taken place. In doing so, we learn the total number of users who clicked on an advertisement and subsequently made an enquiry; we do not receive any information from Google that would allow us to identify you as a person. In addition, we report back to Google which of these enquiries led to a project (section 8.6).
Google may also use the data arising in this context for its own purposes, in particular to deliver advertising and to combine it with data from your Google account if you are logged in there. To that extent, Google is an independent controller; the processing within your Google account is governed by the settings you can make at myadcenter.google.com.
We use Google Consent Mode in version 2. It ensures that your decision from the consent banner is passed on to the Google services and that these behave accordingly — measurement and ad delivery only take place to the extent that you have consented.
In our configuration, the Google services are additionally blocked by the consent management tool as long as no consent is present. Without your consent, none of the services named in this section is therefore loaded, and no consent signals are transmitted to Google either.
A distinction must be drawn here: embedded content is displayed on our page and is loaded for that purpose from another provider's server — in the process, that provider learns at least your IP address. A link, by contrast, only takes you to another provider once you click it; nothing is transmitted beforehand.
Our podcast episodes are delivered via the podcast host Podigee, operated by Podigee GmbH, Berlin, Germany.
The player is not loaded when the page is accessed. Initially you only see a preview image. Only when you click the play area is the player loaded from Podigee's servers and playback started (two-click solution). This integration is not controlled via the cookie settings described in section 6.4, but solely through your click.
What is transmitted in the process is your IP address, information on browser and operating system, and the episode retrieved and the playback duration. Podigee operates its servers in Germany; according to the provider, no transfer to a third country takes place. The legal basis is your consent, declared by clicking the play area, under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Privacy information: podigee.com/de/about/privacy.
On some pages we link to our profiles and content with other providers — in particular to our podcast on Spotify, to our Instagram profile and individual posts there, to our YouTube channel and to the professional profiles of our managing directors on LinkedIn.
These are ordinary links, not embedded content. As long as you do not click such a link, nothing is transmitted to the provider concerned; no scripts are loaded and no cookies are set for this purpose. By clicking, you leave our website. From that point on, the provider concerned is solely responsible for the processing of your data; if you are logged in there, it can attribute the visit to your account. Please refer to the privacy information of the respective provider for details.
The Meta Pixel with the ID 205747504548371 is integrated on this website. The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. The pixel is delivered through Google Tag Manager (section 9.1) and is loaded only after you have consented to the „Marketing" category.
The Meta Pixel records which of our pages you access and whether you carry out an action that is relevant to us, such as submitting an enquiry form. What is processed in the course of this is your IP address, information on browser and device, the page accessed and an identifier that Meta places in a cookie (_fbp, lifetime 90 days). The purpose is to measure the success of our advertising on Facebook and Instagram and to enable relevant advertisements to be delivered to you there. If you are logged in to Facebook or Instagram, Meta can attribute the recorded events to your account there.
For the collection and transfer of this data, we and Meta are joint controllers within the meaning of Article 26 GDPR. The essence of the arrangement made in this regard is as follows: Meta is responsible for the security of the processing and for giving effect to your rights under Articles 15 to 20 GDPR in respect of the data stored at Meta; we are responsible for the information required under Articles 13 and 14 GDPR and for obtaining your consent. You can exercise your data subject rights both against us and against Meta. The full arrangement is available at facebook.com/legal/controller_addendum. For the subsequent processing in its own systems, Meta is solely responsible.
Advanced matching. If you submit one of our contact forms, we additionally transmit your email address and telephone number to Meta as a SHA-256 hash. Here too the conversion takes place in your browser, and here too the details are never transmitted in plain text. Meta matches the hashes against the hashes of its user accounts in order to attribute the enquiry to an advertisement shown previously.
The pixel is loaded after your express consent. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time via the Cookie settings in the footer. A transfer to the USA to Meta Platforms, Inc. is possible; the legal grounds are set out in section 14. Privacy information: facebook.com/privacy/policy.
This website is operated at Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The servers are located in the Falkenstein data centre in Saxony, Germany. The server is administered using the Plesk software.
Hetzner processes on our behalf all data arising from the operation of this website — in particular the server log files described in section 5, the content of the website and the database, including the enquiry table described in section 8.5. A data processing agreement under Article 28 GDPR is in place with Hetzner. The legal basis for the hosting is Article 6(1)(f) GDPR; our legitimate interest lies in the secure and reliable provision of this website.
Backup copies of the website and its database are created regularly and are likewise stored in Germany. They serve exclusively for restoration in the event of a malfunction. The legal basis is Article 6(1)(f) GDPR. Backup copies are overwritten after 30 days. If a data record is deleted, it disappears from the live systems immediately and from the backup copies when these are overwritten in the normal cycle.
In addition, people who support us with the operation, maintenance and further development of this website have access to its data. They are contractually bound to confidentiality and, in so far as they process personal data, likewise work on the basis of a data processing agreement.
Your data is only disclosed to other recipients if you have given consent, if we are legally obliged to do so — for example towards tax or law enforcement authorities — or if the disclosure is necessary to establish, exercise or defend legal claims. Your data is not sold.
For the administration and operation of our website we use extensions that do not themselves collect any personal data of our visitors. No consent is required for them; the legal basis is Article 6(1)(f) GDPR, with our legitimate interest in a well-maintained, fast and findable web presence.
In the case of some of the processing operations described, data may reach the USA or be accessible from there. This concerns:
These transfers are based on:
We will provide you with a copy of the standard contractual clauses agreed with the providers named on request; please contact info@smartfabrik.de for this. The clauses adopted by the European Commission are also published in the Official Journal of the European Union (Implementing Decision (EU) 2021/914).
We expressly point out the following: the USA does not have a level of data protection that corresponds to the European level in every respect. In particular, US authorities may under certain conditions access data there without you learning of it, and the legal remedies available against this are more limited than in the European Union. A residual risk can therefore not be entirely ruled out. If you wish to avoid this, please do not consent to the services concerned — the website can be used without restriction without them. To contact us without any involvement of Microsoft, you can reach us at any time by telephone on +49 211 838 66 870 or by post at the address given in section 1.
The adequacy decision on the EU-US Data Privacy Framework is currently subject to judicial review (CJEU, Case C-703/25 P); in addition, the European Data Protection Board asked the EU Commission in July 2026 to review the decision. Should it be annulled or suspended, we will base the transfers concerned on the standard contractual clauses agreed and on your consent, and we will amend this policy accordingly.
We store personal data only for as long as is necessary for the respective purpose or as statutory retention obligations require. In overview:
For the third-party services described in sections 8.6, 10 and 11, the provider concerned determines the storage period in its own systems independently; the privacy information linked in the relevant section is decisive. The lifetimes of the cookies set in your browser in this context are stated with the relevant service.
When a period expires or the purpose ceases to apply, the data is deleted or anonymised in such a way that it can no longer be linked to you. If data is still held solely because of a retention obligation, we restrict its processing: it is then merely stored and no longer used for other purposes.
We take technical and organisational measures in accordance with Article 32 GDPR to protect your data against loss, alteration and unauthorised access. These include in particular:
We continuously adapt these measures to the state of the art. Complete protection against every conceivable form of access is, however, not achievable when data is transmitted over the internet.
We collect your data exclusively from you — through your visit to this website and through your entries. We do not process personal data from external sources, such as address trading or public directories, for this website; the information obligations under Article 14 GDPR are therefore not applicable.
If we intend to process your data for a purpose other than the original one, we will inform you of this beforehand and, where necessary, obtain your consent (Article 13(3) GDPR).
No automated decision-making, including profiling, within the meaning of Article 22 GDPR that produces legal effects concerning you or similarly significantly affects you takes place. Your enquiry is always decided on by a human; the processing status referred to in section 8.5 is likewise assigned by a person in our company and is not calculated automatically.
For the sake of clarity, we record which processing operations do not take place via this website:
We amend this policy when the processing operations on this website change or when a change in the legal situation requires it. The version available here applies in each case. In the case of material changes affecting processing based on your consent, we will obtain your consent again.
Version of this privacy policy: 18 August 2026.
You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More Information