Ömer CoskunIT Services

Privacy statement

As of 7 October 2026

Translation - not reviewed. Only the German version is legally binding. Deutsche Fassung

1.Controller

Ömer Hüseyin Coskun, Leienbergstr. 1, 53783 Eitorf

Email: mail@oemer-coskun.de

I have not appointed a data protection officer because there is no obligation to do so.

2.Scope of this statement

This privacy statement applies to this website and its forms. The customer portal with the partner and team area has its own privacy statement, linked there.

I process personal data only to the extent required for the respective purpose. The connection to the website is encrypted throughout.

3.Visiting the website and server logs

With every visit the server processes technically necessary data: your IP address, date and time, the address requested, the status of the response, the amount of data transferred and the details of your browser (user agent). These details are recorded in the web server's log. Personal access codes in addresses and everything after a question mark are made unrecognisable there; the previously visited page (referrer) is not logged.

The purpose is secure and stable operation, in particular defence against attacks and troubleshooting; the legal basis is Art. 6(1)(f) GDPR. The logs are deleted as soon as they are no longer required for this purpose.

4.Hosting and backup

I rent the server on which this service and its data are stored from one.com. It is located in a data centre of dogado GmbH in Dortmund, Germany. The provider processes the data as a processor pursuant to Art. 28 GDPR.

Backup with a storage provider outside the server: missing: operator.

5.Delivery via Cloudflare

All requests pass through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare protects the server against attacks and forwards the requests; in doing so, Cloudflare processes the connection data (IP address, requested address, browser details) as a processor. The legal basis is Art. 6(1)(f) GDPR (secure and reliable operation).

Data may be transferred to the USA in the process. Cloudflare is certified under the EU-US Data Privacy Framework; the transfer is based on the adequacy decision of the EU Commission of 10 July 2023 (Art. 45 GDPR).

6.Project inquiry via the form

Companies can describe a project using the 'Request a project' form. Mandatory details are company, contact person, business email address and the description of the project; phone, desired start, duration or scope, place of work and budget range are voluntary. Without the mandatory details I cannot process the inquiry.

After sending, you receive an email with a confirmation link valid for 24 hours. Only after the confirmation do I see the inquiry, and you receive an acknowledgement of receipt. If the address is not confirmed, the inquiry is deleted after the link expires, at the latest during the following night.

The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract at your request). With the tick in the form you also agree to the storage (Art. 6(1)(a) GDPR); you can withdraw this declaration at any time.

If the inquiry leads to an order, I transfer company, contact person, phone and language into my customer data; the privacy statement of the customer portal then applies. I delete an inquiry that does not lead to an order 6 months after it was declined or withdrawn.

I am notified of a confirmed inquiry via Telegram (see 'Notifications to me'). The notification states the number of new inquiries and the company name with the date, but neither your email address nor your phone number nor the description.

To prevent misuse, I store the email address given and your IP address (for IPv6 only the network part) each time the form is sent, and thereby limit the number of inquiries per hour. Entries older than 24 hours are deleted the next time the form is sent (Art. 6(1)(f) GDPR).

7.Project requests from recruiters

Recruiters and agencies can offer me projects through a separate form. First they confirm their email address via a link valid for 7 days. In the form, agency name, contact person, project title and project description are mandatory; voluntary details include phone, end customer, industry, period, workload, place of work, rate, feedback deadline, tender number and a PDF file.

The purpose is to review and answer the request; the legal basis is Art. 6(1)(b) and (f) GDPR. If you name a contact person or an end customer, please inform them about this statement.

I delete an open request 90 days after receipt and a declined one 30 days after the decline, the PDF file already with the decline. If the request leads to an order, it is kept as a record for that order. For statistics on request channels, only the agency name, the month and the outcome remain after deletion.

I am notified of a new request via Telegram, with agency, contact person, project title, end customer, workload, location, rate and feedback deadline; email address, phone, description and PDF file are not sent to Telegram.

To prevent misuse, I store the email address and your IP address (for IPv6 only the network part) for confirming the address for at most 24 hours. If a submission is rejected as automated, the IP address appears in the server's operating log, which is continuously overwritten.

8.Partner programme for recruiters

Recruiters can sign up for a partnership. To do so they enter email address, company, first and last name and confirm the address via a link. When the partnership agreement is accepted, I store the time, email address, company, name, IP address, browser details and the checksum of the accepted text as proof of the conclusion of the contract.

This is followed by address, contact person, invoice recipient and billing address, desired day rate, monthly target and payment term, and voluntarily VAT ID, billing email and referral code. I also store counter-offers and answers with time, IP address and browser details. You receive the concluded agreement as a PDF by email; on conclusion I add you to my customer data as invoice recipient.

The legal basis is Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR for the proofs (proof of the conclusion of the contract) and Art. 6(1)(c) GDPR for retention.

I am notified of sign-ups, offers and answers via Telegram; these notifications contain company, contact person, email address, day rate, monthly target, payment term, referral and your message.

I keep the details and proofs for as long as the partnership exists, and afterwards until the statutory retention periods expire (8 years for accounting vouchers, 6 years for business letters). If no agreement is reached, I keep the proofs until the end of the regular limitation period (3 years from the end of the calendar year).

9.Reviews

After an order is completed, customers receive a personal link through which they can submit a review; it is valid for 90 days. The number of stars, your text, voluntarily your name, your company and your role are stored, as well as your decision whether these details may be published.

The review itself is published on the basis of Art. 6(1)(f) GDPR (interest in presenting one's own work), and only after I have approved it. Name, company and role are published only with your consent (Art. 6(1)(a) GDPR). Without your consent, name, company and role do not appear, not even abbreviated.

You can withdraw your consent at any time with effect for the future by email to mail@oemer-coskun.de; you can also request that the review be removed. Until then the review remains stored.

10.Protection against misuse of reviews

To limit repeated submission attempts, the IP address (for IPv6 only the network part) is stored each time the review form is submitted. Entries older than one day are deleted with the next submission. The legal basis is Art. 6(1)(f) GDPR.

11.Email contact and sending of emails

If you write me an email, I process your address, your message and its attachments in order to reply (Art. 6(1)(b) or (f) GDPR).

Incoming emails are received by my own mail server, which runs on my server in Germany (hosting as above). No other provider receives them.

On my server I delete spam after 30 days and emails that are not business letters after 90 days; I keep business letters for 6 years from the end of the calendar year (Section 147 AO, Section 257 HGB).

I send emails via Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France) as a processor. Brevo receives your email address and the content of the email. A tracking pixel that reports the opening of an email is switched off.

12.Notifications to me

For notifications to myself I use the messaging service Telegram (Telegram FZ-LLC, Dubai, United Arab Emirates). There is no data processing agreement with Telegram, and the messages are also stored outside the EU. The legal basis is Art. 6(1)(f) GDPR (quick handling). Basis of the transfer to a third country: missing: operator.

Which details a notification contains is stated with the respective form. Reviews do not trigger a notification.

13.Fonts

The fonts of this website are delivered from its own server. Visiting it creates no connection to Google Fonts or any other font provider.

14.No cookies, no audience measurement

This website sets no cookies and stores no data in your browser. It uses no analytics or counting services and no embedded third-party content.

15.Obligation to provide data and automated decisions

You are under no statutory or contractual obligation to provide me with data. Without the mandatory details of a form, however, I cannot process your request. There is no automated decision-making, including profiling (Art. 22 GDPR).

16.Your rights

You have the right of access to your data (Art. 15 GDPR), to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restriction of processing (Art. 18 GDPR) and to data portability (Art. 20 GDPR). An informal email to mail@oemer-coskun.de is sufficient.

You can withdraw a consent at any time with effect for the future (Art. 7(3) GDPR). Processing carried out before the withdrawal remains lawful.

17.Right to object

Where I process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). I will then no longer process the data unless I can demonstrate compelling legitimate grounds which override your interests, or the processing serves the establishment, exercise or defence of legal claims.

18.Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for me is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.