Privacy

Privacy notice for IT consulting business. Translation only for your Convenience

1. Controller

5BLUE IT Management
Owner: Armin Gütlich
Germany
E-mail: datenschutz-gg(-@-)5blue.de

2. Type and scope of processing

As an IT consulting and management service provider, we process personal data in particular in the context of:

Implementation of IT and consulting projects

Communication with customers, partners and interested parties

Contract initiation and execution

Operation and security of our IT systems

Fulfilment of legal obligations

 

Legal basis (Art. 6 GDPR):

lit. b – Performance of the contract

lit. c – legal obligations

lit. f – legitimate interest (e.g. IT security, business operations)

3. Categories of personal data

Contact details (name, email, phone number)

Company and project data

Communication data

Contract and billing data

Technical data (IP address, log files, system accesses)

4. Recipients and Service Providers

We use the following IT service providers:

Hosting

DomainFactory GmbH (Germany)
→ Hosting of the website and technical infrastructure
→ Processing on the basis of a data processing agreement (Art. 28 GDPR)

Cloud and IT services

Microsoft Corporation ( Microsoft 365)
→ Email, Collaboration, Identity & Access Management
→ Data processing within the EU (EU Data Boundary, where available)
→ Standard Contractual Clauses (SCCs) for third country references

5. Data transfer to third countries

A transfer to third countries (e.g. USA) will only take place:

based on EU Standard Contractual Clauses (SCC)

taking into account additional protective measures

in accordance with Art. 44 et seq. GDPR

.

6. Storage period

Personal data is stored:

as long as they are necessary for the respective purpose

in accordance with statutory retention obligations (e.g. HGB, AO)

After that, they will be deleted or anonymized

7. Technical and Organizational Measures (TOMs)

As an IT consulting company, we implement comprehensive security measures in accordance with Art. 32 GDPR:

Access control

Multi-factor authentication (MFA)

 

Access Protection / Network Security

Firewalls and Network Segmentation

VPN access for remote access

Monitoring and logging

 

Data security

Encryption (TLS/HTTPS, at-rest if necessary)

Backup and recovery concepts

Protection against data loss and manipulation

 

System hardening

Patch and vulnerability management

Endpoint Security

Regular updates

 

Organizational measures

Non-Disclosure Agreements

8. Order Processing (DPA)

With all external service providers who process personal data, there are:

Data processing agreements in accordance with Art. 28 GDPR

clear regulations on:

Safety measures

9. Compliance / Standards

Our security and privacy measures are based on:

ISO/IEC 27001 (Information Security)

TISAX (Trusted Information Security Assessment Exchange) – if relevant in the project context

IT governance and security best practices

 

10. Contact form (suspended)

When using the contact form:

Processing exclusively for the purpose of processing the enquiry

No disclosure to third parties

no automated decision-making

 

11. Rights of Data Subjects

You have the right to:

Information (Art. 15 GDPR)

Erasure (Art. 17 GDPR)

Objection (Art. 21 GDPR)

12. Version

Version 01/2026

English version for convenience only. German version prevails.