PRIVACY.
Information about the collection, processing and use of personal data by TGiGA in accordance with the GDPR and the German Federal Data Protection Act (BDSG).
1. Data Controller
TGiGA — Creative Digital Agency
Sole proprietorship (Einzelunternehmen)
Represented by: M. Al-haddi
Straße der Solidarität 8
39418 Staßfurt
Germany
Email: info@tgiga.com
Phone / WhatsApp: +49 176 57772123
A data protection officer has not been appointed, as this is not legally required for this business under Art. 37 GDPR. If you have any questions about data protection, please contact us directly at info@tgiga.com.
2. General Information on Data Processing
We process personal data only to the extent permitted by law. The legal framework is formed by the EU General Data Protection Regulation (GDPR / DSGVO), the German Federal Data Protection Act (BDSG), and the German Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (TDDDG). This policy describes which data we process, for which purposes, and on which legal basis.
3. Collection of Data when Visiting the Website (Server Log Files)
When you access our website, the hosting provider automatically stores information in server log files that your browser transmits. These are:
- IP address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status / HTTP status code
- Amount of data transferred
- Website from which the request originates (referrer)
- Browser, operating system and its interface
- Language and version of the browser software
This data is required to deliver the website, to ensure the stability and security of the systems (e.g., defence against attacks), and for troubleshooting. The data is not merged with other data sources and is not assigned to specific individuals. Server log files are stored for a maximum of 7 days and then deleted or anonymised. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in the secure and stable operation of the website).
4. Hosting and Content Delivery Network
Our website is hosted by an external service provider and delivered through a content delivery network (CDN). The provider processes personal data (in particular IP addresses and server logs) on our behalf as a processor in accordance with Art. 28 GDPR, on the basis of a data processing agreement. This is necessary to provide the website securely and quickly and to defend against attacks. The legal basis is Art. 6 (1) lit. f GDPR. Where data is transferred to service providers in the USA, this is based on the EU-US Data Privacy Framework (adequacy decision of 10 July 2023).
5. External Fonts (Google Fonts)
This website uses Google Fonts (provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) for the uniform display of fonts. When the page is loaded, fonts are retrieved from the servers of Google; for this purpose, your IP address and technical browser data are transmitted to Google. Google is certified under the EU-US Data Privacy Framework. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in a uniform and attractive presentation of the website). Further information can be found in Google's privacy policy: https://policies.google.com/privacy
6. Contact by Email
If you contact us by email, the data you provide (in particular your email address, your name and the content of your message) will be stored by us solely to process your enquiry and for possible follow-up questions. This data will not be passed on to third parties without your consent. The legal basis is Art. 6 (1) lit. b GDPR (processing for the performance of a contract or pre-contractual measures) and Art. 6 (1) lit. f GDPR (legitimate interest in answering enquiries).
7. Contact via WhatsApp
You can contact us via our WhatsApp link. When you do so, you will be directed to the messaging service of WhatsApp Ireland Ltd / Meta Platforms Inc. (USA). The message content and associated metadata (e.g., phone number, time) are processed by the provider in accordance with its own privacy policy. We process the data received in this way exclusively to answer your enquiry. The legal basis is Art. 6 (1) lit. b GDPR and Art. 6 (1) lit. f GDPR. Transfers to the USA are based on the EU-US Data Privacy Framework. Please also note the privacy policy of WhatsApp: https://www.whatsapp.com/legal/privacy-policy
8. Contact Form
Should we provide a contact form on this website, the data entered there (e.g., name, email address and message) will be used exclusively to process your enquiry and for possible follow-up questions. This data will be deleted once the enquiry has been conclusively processed and no statutory retention obligations conflict with the deletion. The legal basis is Art. 6 (1) lit. b GDPR.
9. Cookies and Similar Technologies (§ 25 TDDDG)
This website uses local storage and, in individual cases, cookies. Technically necessary storage and access (e.g., saving your language preference, load balancing) are carried out without your consent in accordance with § 25 (2) TDDDG, as they are strictly necessary for the operation of the website. Cookies or similar technologies for marketing, tracking or analysis purposes are only used with your prior consent, which you grant via a consent banner, in accordance with § 25 (1) TDDDG and Art. 6 (1) lit. a GDPR. You can withdraw your consent at any time with effect for the future. The website does not currently use tracking or advertising cookies.
10. Newsletter
If you subscribe to our newsletter, we use your email address (and, if you provide it, your name) to send you information about our services. Registration takes place using the double opt-in procedure: after registration you will receive a confirmation email with a link that you must confirm. The legal basis is Art. 6 (1) lit. a GDPR (consent). You can revoke your consent and unsubscribe at any time, e.g., via the unsubscribe link in the newsletter or by email. If an email marketing service provider is used, it processes the data on our behalf in accordance with Art. 28 GDPR.
11. Marketing and Legitimate Interests
As an agency offering web design, graphic design, web development and digital marketing, we may process the business contact details of clients and prospects (e.g., business email addresses) for direct marketing purposes within the scope of our legitimate interests, in accordance with Art. 6 (1) lit. f GDPR and § 7 of the German Act against Unfair Competition (UWG). You may object to this processing at any time with effect for the future.
12. Overview of Legal Bases
- Art. 6 (1) lit. a GDPR — consent (e.g., newsletter, marketing cookies)
- Art. 6 (1) lit. b GDPR — performance of a contract or pre-contractual measures (e.g., enquiries, project work)
- Art. 6 (1) lit. c GDPR — legal obligations (e.g., tax and commercial retention obligations)
- Art. 6 (1) lit. f GDPR — legitimate interests (e.g., website operation, hosting, fonts, security)
13. Storage Periods
- Server log files: max. 7 days, then deletion or anonymisation.
- Enquiries (email, WhatsApp, forms): until the enquiry is conclusively processed, then in accordance with the statutory retention obligations.
- Business and commercial documents: in accordance with § 257 of the German Commercial Code (HGB) and § 147 of the German Fiscal Code (AO) — up to 6 or 10 years.
- Consent-based data (e.g., newsletter): until consent is withdrawn.
14. Recipients and Disclosure of Data
We do not sell your data. Your data is only passed on to service providers who support us in operating the website and providing our services (in particular hosting, content delivery network and email marketing providers), and only to the extent necessary. These providers process your data exclusively on our behalf as processors in accordance with Art. 28 GDPR. In addition, data is only passed on where we are legally obliged to do so (e.g., to tax or law enforcement authorities).
15. Transfers to Third Countries
In individual cases, data may be transferred to service providers located outside the EU/EEA, in particular to the USA (Google Fonts, Cloudflare, WhatsApp/Meta). Such transfers are based on the adequacy decision of the European Commission for the EU-US Data Privacy Framework (10 July 2023) and, insofar as this is not applicable, on standard contractual clauses and supplementary measures. You can obtain a copy of the appropriate safeguards from us at any time.
16. Your Rights as a Data Subject
You have the following rights under the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure ("right to be forgotten", Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
17. Supervisory Authority
If you believe that the processing of your personal data infringes data protection law, you may lodge a complaint with the competent supervisory authority. The authority responsible for our business is:
Landesbeauftragter für Datenschutz und Informationsfreiheit Sachsen-Anhalt
Leiterstraße 9
39104 Magdeburg
Germany
Website: https://datenschutz.sachsen-anhalt.de
18. Data Security
We use appropriate technical and organisational measures to protect your data against manipulation, loss, destruction or unauthorised access, in accordance with Art. 32 GDPR. Our website is transmitted using TLS/HTTPS encryption. Please note that email and messaging communication can generally not be completely protected from access by third parties.
19. Automated Decision-Making / Profiling
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
20. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy from time to time to reflect current legal requirements, technical developments or changes to our services. This version is current as of August 2026.