5BLUE IT Management
Owner: Armin Gütlich
Germany
E-mail: datenschutz-gg(-@-)5blue.de
As an IT consulting and management service provider, we process personal data in particular in the context of:
Implementation of IT and consulting projects
Communication with customers, partners and interested parties
Contract initiation and execution
Operation and security of our IT systems
Fulfilment of legal obligations
Legal basis (Art. 6 GDPR):
lit. b – Performance of the contract
lit. c – legal obligations
lit. f – legitimate interest (e.g. IT security, business operations)
Contact details (name, email, phone number)
Company and project data
Communication data
Contract and billing data
Technical data (IP address, log files, system accesses)
We use the following IT service providers:
Hosting
DomainFactory GmbH (Germany)
→ Hosting of the website and technical infrastructure
→ Processing on the basis of a data processing agreement (Art. 28 GDPR)
Cloud and IT services
Microsoft Corporation ( Microsoft 365)
→ Email, Collaboration, Identity & Access Management
→ Data processing within the EU (EU Data Boundary, where available)
→ Standard Contractual Clauses (SCCs) for third country references
A transfer to third countries (e.g. USA) will only take place:
based on EU Standard Contractual Clauses (SCC)
taking into account additional protective measures
in accordance with Art. 44 et seq. GDPR
.
Personal data is stored:
as long as they are necessary for the respective purpose
in accordance with statutory retention obligations (e.g. HGB, AO)
After that, they will be deleted or anonymized
As an IT consulting company, we implement comprehensive security measures in accordance with Art. 32 GDPR:
Access control
Multi-factor authentication (MFA)
Access Protection / Network Security
Firewalls and Network Segmentation
VPN access for remote access
Monitoring and logging
Data security
Encryption (TLS/HTTPS, at-rest if necessary)
Backup and recovery concepts
Protection against data loss and manipulation
System hardening
Patch and vulnerability management
Endpoint Security
Regular updates
Organizational measures
Non-Disclosure Agreements
With all external service providers who process personal data, there are:
Data processing agreements in accordance with Art. 28 GDPR
clear regulations on:
Safety measures
Our security and privacy measures are based on:
ISO/IEC 27001 (Information Security)
TISAX (Trusted Information Security Assessment Exchange) – if relevant in the project context
IT governance and security best practices
When using the contact form:
Processing exclusively for the purpose of processing the enquiry
No disclosure to third parties
no automated decision-making
You have the right to:
Information (Art. 15 GDPR)
Erasure (Art. 17 GDPR)
Objection (Art. 21 GDPR)
Version 01/2026