Privacy Policy

Privacy policy and data protection information for BARBANA IT, Cloud & AI-Solutions in accordance with the GDPR.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is: Oussama Barbana BARBANA IT, Cloud & AI-Solutions Ziegelstr. 59 67655 Kaiserslautern Germany Email: contact@barbana.de Phone: +49 156 78611903

2. Scope

This Privacy Policy informs you about the nature, scope, and purposes of the collection and use of personal data on our website https://barbana.de and in connection with our related services.

3. Data Collection When Visiting the Website

When you visit our website for informational purposes only, we collect only the personal data that your browser transmits to our server (server log files). This includes: • IP address of the requesting computer • Date and time of access • Name and URL of the retrieved file • Website from which access was made (referrer URL) • Browser and operating system used • Internet service provider Processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in the security and stability of our offering. The data is deleted or anonymised after 7 days.

4. Contact Form and Email

If you contact us via contact form or email, the data you provide (name, email address, company, phone number, message) will be stored by us to process your enquiry. Processing is carried out in accordance with Art. 6(1)(b) GDPR (contractual measure) or lit. f (legitimate interest in communication). After your enquiry has been fully processed, your data will be deleted unless statutory retention obligations conflict with this.

5. AI Chat Assistant

On our website we offer an AI-powered chat assistant. When using the chat, your messages as well as technical metadata (IP address, browser identifier) are transmitted to our AI service provider to answer your enquiry. After the chat ends, the messages are deleted within 30 days. In case of repeated contact (lead detection after 5 messages), the transcript is forwarded to our CRM for quotation purposes. The legal basis is Art. 6(1)(b) GDPR.

6. Cookies

Our website uses only technically necessary cookies (session cookies) that are required for the operation of the website. These cookies do not store any personal data and are deleted after the end of your visit. We do not use any tracking, analytics, or marketing cookies. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the error-free functioning of the website).

7. Web Hosting

Our website is operated by a professional hosting provider in Germany. The server location is Germany. Processing of server log files takes place exclusively on servers within the European Union, ensuring the GDPR level of data protection at all times. We have concluded a Data Processing Agreement (DPA) with our hosting provider in accordance with Art. 28 GDPR.

8. SSL Encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the address bar of the browser changing from "http://" to "https://" and the padlock icon in your browser bar. When SSL encryption is activated, the data you transmit to us cannot be read by third parties.

9. Third-Party Disclosure

Your personal data is generally not transferred to third parties, unless: • You have given your express consent (Art. 6(1)(a) GDPR) • The disclosure is necessary for the establishment, exercise, or defence of legal claims (Art. 6(1)(f) GDPR) • There is a legal obligation (Art. 6(1)(c) GDPR) • There is a legitimate interest and no overriding legitimate interests on your part We do not sell your data to third parties.

10. Your Rights

Under the GDPR, you have the following rights: • Right of access (Art. 15 GDPR) – You have the right to obtain confirmation as to whether personal data concerning you is being processed. • Right to rectification (Art. 16 GDPR) – You have the right to request the rectification of inaccurate data. • Right to erasure (Art. 17 GDPR) – You have the right to request the deletion of your personal data, unless statutory retention obligations apply. • Right to restriction of processing (Art. 18 GDPR) • Right to data portability (Art. 20 GDPR) • Right to object (Art. 21 GDPR) – You have the right to object to the processing of your data. To exercise your rights, please contact: contact@barbana.de

11. Right to Complain

You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR. The competent supervisory authority for us is: The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate Hintere Bleiche 34 55116 Mainz https://www.datenschutz.rlp.de/

12. Storage Period

We store your personal data only for as long as is necessary to achieve the respective processing purposes or as required by statutory retention periods (e.g. commercial and tax retention periods under the German Commercial Code and Fiscal Code, usually 6–10 years). After the purpose ceases to apply or the retention period expires, the data is deleted.

13. Changes to This Policy

We reserve the right to adapt this Privacy Policy in the event of changes in the legal situation or our services. The current version is always available on our website. Last updated: June 2026