Privacy Policy (Datenschutzerklärung)
This policy explains what happens to your personal data when you visit zfge.justreporting.eu. It aligns with the parent company policy at justreporting.eu/legal-and-privacy, and is scoped to the services actually running on this subdomain.
1. Data Controller
justReporting GmbH Wirtschaftsprüfungsgesellschaft
Rheinpromenade 2, 40789 Monheim am Rhein, Germany
Phone: +49 211 7407 7093
E-Mail: hello@justreporting.eu
Managing Director: Jannik Hassel
A data protection officer has not been appointed; appointment is not mandatory for our organisation size under Art. 37 GDPR and § 38 BDSG.
2. What Data Is Processed on This Website
We collect only the data strictly necessary to serve the website and, beyond that, only what you enter yourself to book a consultation or write to us.
- Server log files (browser, OS, referrer, IP address, timestamp): collected by our hosting provider for security and technical operation, deleted after 14 days.
- Consent preferences: stored locally in your browser (localStorage, key zfge-consent); never transmitted to us.
- Booking data (name, e-mail, chosen slot): only if you actively use the booking widget.
- E-mail content: only if you contact us at zfge@justreporting.eu.
- cf_clearance cookie: set by Cloudflare once the automated check for program access has been passed; holds nothing but that proof, default lifetime 30 minutes, see section 4.
We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, or any other advertising or retargeting tool. For reach measurement we use Plausible, see section 2a.
2a. Web Analytics (Plausible)
We use Plausible Analytics (Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia) to understand which pages visitors read and how they arrive. Plausible is cookie-free, does not track users across sites and builds no user profiles.
Data collected: URL path, referrer, browser type, operating system, device type and the country derived from the IP address. The IP itself is discarded. No cross-site tracking, no profiles, no fingerprinting.
Legal basis: your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. Plausible works without cookies, but it reads characteristics of your device in order to measure reach: under EDPB Guidelines 2/2023 on Art. 5(3) of the ePrivacy Directive that also counts as access to your terminal equipment. We therefore load the script only once you have agreed. Without your consent no connection to Plausible is made. You can withdraw your consent at any time, see section 5.
Provider privacy policy: plausible.io/privacy
3. Hosting (Hetzner)
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Servers located in the EU. Data processing agreement (Art. 28 GDPR) in place.
Legal basis: Art. 6(1)(f) GDPR, legitimate interest in secure and efficient provision of our website.
Provider privacy policy: hetzner.com/legal/privacy-policy
4. Cloudflare (DNS and delivery)
We use Cloudflare (Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA) for DNS routing and protection against malicious traffic. Cloudflare receives the IP address of visitors and basic connection metadata.
Legal basis: Art. 6(1)(f) GDPR, legitimate interest in a secure, performant and reliably reachable website.
Data transfer to the USA is secured by the EU-US Data Privacy Framework (Cloudflare is certified) and by Standard Contractual Clauses for onward processing. A data processing agreement is in place.
The cf_clearance cookie
To fend off automated access, Cloudflare inserts a script of its own into the pages it delivers (path /cdn-cgi/challenge-platform/…). It runs in your browser, checks whether the request comes from a browser rather than from a program, and reports the result back to Cloudflare. Cloudflare then sets the cookie cf_clearance on this address.
The cookie holds nothing but the proof that this check has been passed, so that it is not repeated on every request. It is not used for reach measurement, not for recognising you across websites and not for advertising. Its default lifetime is 30 minutes.
We state this explicitly because the cookie is set independently of our consent notice: Cloudflare injects the script at the network edge, before our page reaches you. It therefore cannot be governed by the consent choice. You can delete it like any other cookie, or block it for this address, in your browser; the site remains reachable if you do.
Provider privacy policy: cloudflare.com/privacypolicy
6. Appointment scheduling (our own calendar in Germany)
For arranging initial calls we operate our own calendar at meet.justreporting.eu on our server in Germany. The software behind it is Cal.com; the operator is us. There is no third-country transfer, and Cal.com is not a recipient of your data.
Data processed: Your name, e-mail address, the time slot you select and any information you voluntarily enter in the booking form.
Purpose: Scheduling and administration of your consultation request.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request) for the booking itself; Art. 6(1)(a) GDPR together with § 25(1) TDDDG (consent) for loading the embedded calendar. Without your consent it is not loaded and nothing is requested. You can withdraw consent at any time via “Manage cookies” in the footer (section 5).
Data transfer: Booking data is held in our own database on the same server that serves this website (Hetzner, Germany, see section 3). Confirmation and reminder emails are dispatched on our behalf by Scaleway, see section 7. Beyond that, no transfer to third parties takes place.
Retention: Until the booking is completed, and beyond that within statutory retention periods (e.g. § 51b WPO, ten years for audit-related records).
7. Contact by E-Mail
If you write to us at zfge@justreporting.eu, we store your e-mail, name and message solely to respond to your enquiry.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) for engagement-related enquiries; Art. 6(1)(f) GDPR (legitimate interest) for general questions.
Retention: messages are deleted when the purpose is fulfilled, subject to statutory retention periods (e.g. § 51b WPO, ten years for audit-related records).
Dispatch of outgoing messages: booking confirmations and requests for the document package are sent on our behalf by Scaleway SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, France. Recipient address, subject and message content are processed in doing so. The servers are located in France; no transfer to a third country takes place.
8. Self-Hosted Fonts
Plus Jakarta Sans and Inter are served from our own servers. We do not connect to Google Fonts or any external font provider: no visitor IP is sent to third parties merely because of fonts.
9. Professional Secrecy
As a licensed German Wirtschaftsprüfungsgesellschaft we are bound by professional secrecy under § 43 WPO and § 203 StGB. Any information you share with us in the context of a professional engagement is strictly confidential: independent of, and in addition to, GDPR obligations.
10. Your Rights as a Data Subject
You have the following rights at any time, free of charge:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For us the competent authority is LDI NRW: Kavalleriestr. 2–4, 40213 Düsseldorf.
To exercise any of these rights, a message to hello@justreporting.eu.
11. TLS Encryption
All requests to this site are TLS-encrypted. You can recognise this by the “https://” prefix in your address bar and the lock symbol shown by your browser.
12. Updates and Reference to the Full Policy
We keep this policy aligned with the full parent-company privacy policy at justreporting.eu/legal-and-privacy. For services not running on this subdomain, that policy governs.
Last updated: 7 September 2026