Privacy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Monaco Solutions GmbH
Schmaedelstr. 2
81245 München
E-mail: contact@monaco-solutions.com

Authorised representative: Dr. Michael Huber

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

2. General Information

We take the protection of your personal data seriously and treat it confidentially and in accordance with statutory provisions and this policy. Personal data is any data by which you can be personally identified.

4. Legal Bases for Processing

We process personal data on the following legal bases:

  • Art. 6(1)(a) GDPR (consent)
  • Art. 6(1)(b) GDPR (contract / pre-contractual measures)
  • Art. 6(1)(c) GDPR (legal obligation)
  • Art. 6(1)(f) GDPR (legitimate interest)

Where you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), processing is additionally based on § 25(1) TDDDG. Consent may be withdrawn at any time with effect for the future. The specific legal basis is stated for each processing activity.

5. Retention Period

Unless a more specific retention period is stated in this policy, your personal data remains with us until the purpose of processing no longer applies. Upon a legitimate request for erasure or withdrawal of consent, your data will be deleted unless there are legally permissible grounds for further storage (e.g. tax or commercial retention obligations).

6. Hosting and Server Log Files

We host this website with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany ("Hetzner"). For details, please see Hetzner's privacy policy.

On each visit, the system automatically collects data from the accessing device (server log files):

  • IP address
  • Date and time of access
  • Page / file requested
  • Volume of data transferred, HTTP status code
  • Referrer URL
  • Browser type and operating system

Purpose: technical provision, stability and security of the website. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the reliable and trouble-free presentation of the website. Retention period: {{e.g. 7 days}}, after which the data are deleted or anonymised.

7. Processing on Our Behalf

We have concluded data processing agreements pursuant to Art. 28 GDPR with Hetzner and other service providers who process personal data on our behalf. These ensure that data is processed only on our instructions and in compliance with the GDPR.

8. Recipients of Personal Data

We disclose personal data to external parties only where necessary for the performance of a contract, where we are legally obliged to do so, where we have a legitimate interest under Art. 6(1)(f) GDPR, or where another legal basis permits disclosure. Processors receive data only on the basis of an agreement under Art. 28 GDPR.

9. Transfer to Third Countries

A transfer to countries outside the EU/EEA does not take place.

10. Contacting Us and Contact Form

If you contact us by email or contact form, we process your details in order to handle your request and any follow-up questions. Legal basis: Art. 6(1)(b) GDPR where the request relates to a contract or pre-contractual measures; otherwise Art. 6(1)(f) GDPR (effective handling of enquiries) or Art. 6(1)(a) GDPR (consent), where requested. Retention period: until your request has been dealt with; statutory retention obligations remain unaffected.

11. Fonts and Icons

Fonts and icons are served locally from our own server. No connection to third-party servers takes place.

12. Plausible Analytics

We operate the web analytics software Plausible Analytics on our own servers (hosted with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany).

We are the sole provider and controller within the meaning of the GDPR. Plausible allows us to analyse visitor behaviour on our website in a privacy-friendly way. The software records only the following information:

  • The page URL requested
  • The HTTP referrer (the page you previously visited)
  • Technical browser and device data (browser type and version, operating system, device category)

To recognise returning visitors within a single day, Plausible generates a non-reversible hash from your IP address, the user agent and the domain, combined with a daily rotating random value (salt). Your IP address itself is never stored; it serves solely as an input for this hash and is discarded immediately. Because the salt changes daily, recognition across days is not possible. Identification of your person is not possible. Plausible does not use cookies and does not store any information on your device.

Legal basis: Processing is based on our legitimate interest under Art. 6(1)(f) GDPR in a privacy-friendly analysis of visitor behaviour. As Plausible neither stores nor accesses information on your device, no consent under § 25 TDDDG is required.

13. Your Rights

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing (Art. 21 GDPR)
  • Withdraw consent with effect for the future (Art. 7(3) GDPR)

Withdrawal of Consent

Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.

Objection (Art. 21(1) GDPR)

Where we process data on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object at any time on grounds relating to your particular situation; this also applies to any profiling based on these provisions.

Objection to Direct Advertising (Art. 21(2) GDPR)

Where your data are processed for direct advertising, you have the right to object at any time. Following your objection, your data will no longer be used for direct advertising.

Right to Restriction of Processing

You may request restriction of processing if you contest the accuracy of your data (for the duration of verification), if processing is unlawful, if you need the data for legal claims although we no longer require them, or while your objection under Art. 21(1) GDPR is being reviewed.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

14. Data Security and SSL/TLS Encryption

For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the "https://" in the address bar and the lock symbol in your browser. When encryption is active, the data you transmit to us cannot be read by third parties.

15. Note on Data Transmission over the Internet

Data transmission over the internet (e.g. communication by email) may have security gaps. Complete protection against access by third parties is not possible.

16. Currency of This Policy

Last updated: 07/2026. We will amend this policy whenever the legal situation or the services we use change.