Last updated: 9 October 2026
1. Controller
The controller responsible for data processing on this website is:
Stolz und Müller GmbH
represented by Jürgen Müller and Martin Stolz
Bismarckstrasse 9
76761 Rülzheim
Germany
Telephone: +49 (0)6321 189 04 04
E-mail: info@lieht.com
The contact person for data protection enquiries is Martin Stolz, who can be reached using the contact details above. Further information can be found in the Imprint.
2. At a glance
| What happens | Without your consent | With your consent |
|---|---|---|
| Page view, server log | yes | yes |
| Audience measurement with Umami (our own server, no cookies) | yes | yes |
| Storage of your cookie selection | – | yes, according to your selection |
| Google reCAPTCHA, Google Maps, images from our Facebook posts, YouTube videos | no, you see a placeholder | yes |
Before you give your consent, this website does not set any cookies and does not connect to any other providers.
3. Hosting and server logs
This website is operated on our behalf by our technical service provider Ackermann-Online (processing on our behalf under Art. 28 GDPR). The servers are located in a data centre of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. A data processing agreement is in place with Hetzner.
Each time the website is accessed, the web server stores a log containing:
- IP address
- date and time
- requested address and response code
- amount of data transferred and processing time
- previously visited page (referrer)
- browser and operating system (user agent)
The purpose is to deliver the pages, to troubleshoot errors and to defend against attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure and stable operation of the website.
The logs are rotated daily and automatically deleted after 180 days.
Further systems process IP addresses to defend against attacks:
- Attack detection (CrowdSec): automatically analyses the server logs, blocks suspicious IP addresses for 4 hours and deletes their reports after 7 days at the most. Reports on detected attacks (the attacker’s IP address, type of attack) are also sent to the manufacturer, CrowdSec.
- Firewall log (ModSecurity): retains requests that trigger a protection rule for 30 days.
- Login protection for the website administration: The security plug-in “Limit Login Attempts Reloaded” stores the IP address and the user name entered in failed login attempts in the database. No automatic deletion period has been set up for this.
- Activity log (Simple History): records logins, failed login attempts and changes in the administration area, together with user name and IP address. The entries are deleted after 180 days.
- Backups: Database backups are retained on a staggered basis for up to 12 months. The web server’s log files are not included in them.
The legal basis in each case is Art. 6(1)(f) GDPR; our legitimate interest lies in the security of the website.
4. Cookies and consent management
4.1 Consent dialog (Borlabs Cookie)
On your first visit we show a dialog in which you decide which services may be loaded. Until you have made your decision, we do not load any of the services that require consent. In their place you see a placeholder.
We store your selection in the cookie borlabs-cookie in your browser. In addition, we record in our database when you made which selection; a random identifier with no link to your name is used for this. This allows us to demonstrate that consent has been given (Art. 7(1) GDPR).
The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR. Storing the cookie is permitted without consent under Section 25(2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act), because otherwise we could not remember your decision. We run the software on our own server; no data is passed on to the manufacturer.
The cookie and the log entry are deleted after 365 days. We then ask you again.
4.2 Changing or withdrawing your consent
You can change your selection or withdraw your consent with effect for the future at any time. To do so, click “Cookie settings” at the foot of every page or here: Change cookie settings. In the dialog, select “Deselect all” and “Save”. After that, none of the services that require consent will be loaded any more.
Cookies that another provider has stored under its own address (such as _GRECAPTCHA from Google) cannot be deleted by us from our website. After withdrawal they are no longer retrieved, but they remain in the browser until they expire. You can delete them yourself in your browser settings.
4.3 Cookies and browser storage in detail
| Name | Stored by | Purpose | Duration | When |
|---|---|---|---|---|
borlabs-cookie | lieht.com | Your selection in the consent dialog | 365 days | after you have made a selection |
wpEmojiSettingsSupports (session storage) | lieht.com | checks whether your browser can display emoji | until the browser tab is closed | on every page view |
_GRECAPTCHA | www.google.com | Google reCAPTCHA, protection against automated input | 180 days | after consent, on the home page with the contact form |
_grecaptcha (local storage) | lieht.com, by Google reCAPTCHA | Google reCAPTCHA | until deleted in the browser | after consent, on the home page with the contact form |
After you have given your consent, Google (Google Maps, YouTube) and Meta may set further cookies under their own addresses when loading their content; the type and duration of these cookies are determined by those providers. The audience measurement tool Umami does not set any cookies.
5. Audience measurement with Umami
To understand which pages are used, we use the open-source software Umami. It runs on our own server at the address lieht.com/analytics/ and is operated on our behalf by our technical service provider. No data is passed on to other providers or to third countries.
Umami does not set any cookies and stores nothing in your browser’s storage. The following is transmitted with every page view:
- requested page and previously visited page
- browser and browser language, operating system, device type, screen size
- approximate origin (country, region, city), derived from the IP address
- campaign details in the requested address (such as
utm_sourceorgclid) if you arrive via an advertisement or a referral - date and time
- page load time measurements (how quickly content appears and responds)
Your IP address is not stored. It is used only briefly, together with the browser identifier, to form an irreversible check value. This check value changes at the beginning of each calendar month. Within a month we can therefore recognise the same browser behind the same IP address, but we do not link it to names or account data.
In addition, we count four events: the successful submission of the contact form, clicks on e-mail addresses, clicks on telephone numbers and the switch to our online shop. Only the fact that the event took place is recorded and, for clicks, also the target (our own e-mail address, telephone number or shop page), but no form content.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in improving our offering without passing data on to third parties. We do not obtain consent for this: no information is stored on your device, and only details that your browser makes available anyway for displaying the page are read (Section 25(2) No. 2 TDDDG). You can object to the processing at any time (Art. 21 GDPR), for example by e-mail to info@lieht.com.
The analytics data is stored for 36 months. A daily deletion run removes older data.
6. Contacting us
You can reach us by e-mail, by telephone and via the contact form on the home page (section “Contact”). The form asks for your name, e-mail address, subject and your message. We process the information you provide to us in order to answer your enquiry.
The legal basis is Art. 6(1)(b) GDPR if your enquiry is aimed at a contract (such as lighting design or a purchase), otherwise Art. 6(1)(f) GDPR; our legitimate interest lies in answering your enquiry. We delete the information once the enquiry has been dealt with and there are no statutory retention obligations.
Our e-mail mailboxes are hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. The website sends the message from the contact form to our mailbox via the IONOS e-mail server. The form does not store your details in the website’s database.
The contact form is protected by Google reCAPTCHA (Section 7). Without your consent to reCAPTCHA, the form cannot be submitted; you can then reach us by e-mail or telephone.
You book appointments for a consultation in the showroom in our online shop lieht-shop.com; its privacy policy applies there.
7. Google reCAPTCHA
Purpose: protecting the contact form against automated input (spam). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When loaded: only after your consent. Until then the page shows a placeholder, and no connection to Google is made. reCAPTCHA is loaded only on the home page, where the contact form is located.
Which data: reCAPTCHA analyses your behaviour on the page in order to distinguish humans from programs. In the process, your IP address, details of your browser, operating system and screen, the time spent on the page and mouse and keyboard input, among other things, are sent to Google. Connections are made to www.google.com and www.gstatic.com; Google also loads font files from fonts.gstatic.com.
Cookies: _GRECAPTCHA (180 days) and the storage entry _grecaptcha, see Section 4.3.
Legal basis: your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Third country: A transfer to Google LLC in the USA is possible; see Section 12.
Google’s privacy policy: https://policies.google.com/privacy
8. Google Maps
Purpose: We show maps so that you can find us and our retailers. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Where: on the home page in the section “Contact”, on the “Opening hours” page and on the “Retailers” page (there a map from Google My Maps).
When loaded: only after your consent, then when the page is accessed. Until then you see a placeholder, and no connection to Google is made.
Which data: Your browser connects to Google servers (including maps.googleapis.com, maps.gstatic.com, places.googleapis.com, mt.googleapis.com, www.google.com, www.gstatic.com, ssl.gstatic.com, csp.withgoogle.com, fonts.googleapis.com and fonts.gstatic.com). Google thereby receives your IP address, the page accessed and details of your browser and device, even if you do not have a Google account. If you are logged in to Google, Google can assign the access to your account. Google may set cookies in the process.
Legal basis: your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Third country: A transfer to Google LLC in the USA is possible; see Section 12.
Google’s privacy policy: https://policies.google.com/privacy
9. Posts from our Facebook page
Purpose: On the home page we show recent posts from our Facebook page. The texts are delivered by our server; the images are loaded from Meta servers (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland).
When loaded: only after your consent. Until then you see a placeholder, and no connection to Meta is made.
Which data: When the images are loaded (servers at fbcdn.net), Meta learns your IP address and that you have accessed our page, even if you do not have a Facebook account. We do not use a Facebook pixel or “Like” buttons on this website.
Legal basis: your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Third country: A transfer to Meta Platforms, Inc. in the USA is possible; see Section 12.
Meta’s privacy policy: https://www.facebook.com/privacy/policy
10. Videos from YouTube
Purpose: On individual pages, such as project pages and the “About LIEHT” page, we show videos from YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use enhanced privacy mode (youtube-nocookie.com).
When loaded: only after your consent. Until then you see a placeholder, and no connection to YouTube is made. After your consent, the video player is loaded when the page is accessed, even if you do not play the video.
Which data: When the player is loaded, your browser connects to www.youtube-nocookie.com, i.ytimg.com, yt3.ggpht.com, jnn-pa.googleapis.com and fonts.gstatic.com; when a video is played, further Google servers are added. Google thereby receives your IP address, the page accessed and details of your browser and device; the player reports usage events to YouTube. YouTube creates its own entries in the player’s storage (under the address youtube-nocookie.com).
Legal basis: your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Third country: A transfer to Google LLC in the USA is possible; see Section 12.
Google’s privacy policy: https://policies.google.com/privacy
11. Fonts and emoji graphics
We deliver our fonts from our own server. Our website does not itself call up Google Fonts. Font files from Google (fonts.googleapis.com, fonts.gstatic.com) are loaded only by Google itself, if you have consented to reCAPTCHA, Google Maps or YouTube.
When a page is accessed, WordPress checks whether your browser can display emoji and remembers the result for the duration of the session (wpEmojiSettingsSupports). If your device cannot display an emoji that appears on the page, the page loads a replacement graphic from the server s.w.org (WordPress.org); in the process, your IP address is transmitted to this server. On devices with an emoji font, including common Windows, macOS, Android and iOS devices, this retrieval does not take place. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the correct display of the content. Processing in the USA is possible in this context.
12. Transfers to third countries
Google and Meta may transfer data to their parent companies in the USA. For the USA, the adequacy decision of the EU Commission on the EU-US Data Privacy Framework of 10 July 2023 applies. It applies to companies certified under this framework; these include Google LLC and Meta Platforms, Inc. A transfer to these companies is therefore permitted under Art. 45 GDPR.
13. Storage period
We delete personal data as soon as the purpose ceases to apply and there is no statutory retention obligation. The periods for individual data are stated in the sections above. How long other providers store data that they receive after your consent is determined by those providers themselves; their privacy policies provide information.
14. Your rights
You have the following rights in relation to us:
- Access to your data stored by us (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability where processing is based on consent or contract (Art. 20 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR), see Section 4.2
- Objection to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR)
A message to info@lieht.com is sufficient. The lawfulness of processing carried out up to the withdrawal remains unaffected.
15. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate)
Hintere Bleiche 34
55116 Mainz
https://www.datenschutz.rlp.de
You can also contact the supervisory authority of your place of residence or work.
16. Obligation to provide data, no automated decision-making
You are not obliged to provide us with data. However, without the server log we cannot deliver the page, and without your details we cannot answer an enquiry. There is no automated individual decision-making, including profiling, under Art. 22 GDPR.
17. Changes and date
We amend this privacy policy when our website or the legal situation changes. The version published here at any given time applies.
Last updated: 9 October 2026