Skip to main content
4TrustConsulting GmbH

Privacy policy

Last updated: 30 September 2026

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

4Trust Consulting GmbH
Adeline-Jöster-Weg 10
59425 Unna, Germany
Telephone: +49 2303 538740
Email: info@4trust-consulting.com

We are not required by law to appoint a data protection officer. For any questions about data protection, please contact us using the details above.

2. Overview: what this website does not do

We deliberately keep data processing on this website to a minimum. In practice, this means:

  • We use no third-party analytics or advertising tools (no Google Analytics, no tracking pixels, no remarketing). We do, however, carry out our own cookieless audience measurement, see section 8.
  • We do not load any external fonts. Only the system fonts already present on your device are used.
  • We do not embed any third-party content (no maps, no videos, no social media buttons, no external scripts).
  • There are input fields in two forms only: the request form on the ‘Consultant placement’ page (section 6) and the form for an initial SAP consultation on the SAP pages (section 7). All other pages require no input; there you can reach us using the email address or telephone number given.
  • We use no cookies that require consent, only the two technically necessary ones described in section 4. For this reason, this website does not need a cookie banner.

3. Hosting and server log files

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (‘Vercel’). Vercel delivers static page content via a globally distributed network of servers so that the page reaches you from a nearby location. The processing of your form entries and of the audience measurement (sections 6 to 8) takes place on Vercel servers in the Frankfurt am Main region.

When you access this website, Vercel, as our technical service provider, automatically collects information transmitted by your browser and stores it in what are known as server log files. These are usually:

  • IP address of the requesting device
  • date and time of access
  • name and URL of the file retrieved
  • browser and operating system used
  • amount of data transferred and notification of whether the retrieval was successful

This data is technically necessary to deliver the website, to ensure its stability and security and to fend off attacks. It is not combined with other data sources or evaluated for marketing purposes. From the IP address, Vercel also derives the country of the network connection and makes it available to our application; we use it only for the audience measurement described in section 8.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website in a technically error-free and secure manner.

Retention period: According to Vercel, runtime logs are kept only briefly – between one hour and a few days, depending on the plan; we have not booked longer retention. Data is kept beyond this only if a specific security incident requires it; the data concerned is then retained until the incident has been fully resolved.

We have concluded a data processing agreement with Vercel in accordance with Art. 28 GDPR. Where personal data is transferred to the USA in this context, the transfer is based on the European Commission’s standard contractual clauses and on Vercel’s certification under the EU-U.S. Data Privacy Framework.

4. Cookies

The public part of this website uses two cookies. The second is only created if you actually submit the request form on the ‘Consultant placement’ page:

NEXT_LOCALE

Purpose: stores the language you selected so that the website appears in the same language the next time you open a page.
Content: only the language code (e.g. ‘de’ or ‘en’).
Retention period: for the duration of the browser session.

staffing_request

Purpose: links the optional additions in the second step of the request form to the request you have already submitted and prevents third parties from adding to other people’s requests.
Content: only the reference number of your request.
Retention period: one hour at most; it is deleted immediately once the second step has been submitted, and if you skip that step it expires after the hour has passed. It cannot be read by scripts in the browser and is sent only to the form endpoint.

Both cookies are strictly necessary to provide the services you have expressly requested – displaying the website in the language you selected and submitting your request. Storing them is therefore permitted without consent under Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). No other cookies are set and no data is stored in your browser’s storage. The cookies of the administration area, which is accessible only to us, are described in section 9.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functional, user-friendly website).

5. Contacting us

If you contact us by email or telephone, we process the information you provide (in particular your name, contact details and the content of your enquiry) in order to deal with your request and answer any follow-up questions. We do not pass this data on to third parties without your consent.

Legal basis: Art. 6(1)(b) GDPR, where your enquiry relates to the conclusion or performance of a contract; otherwise Art. 6(1)(f) GDPR on the basis of our legitimate interest in responding to enquiries.

Retention period: We delete your enquiry once it has been fully dealt with, provided that no statutory retention obligations prevent deletion. Retention periods under commercial and tax law (generally six or ten years) remain unaffected.

6. Requests via the ‘Consultant placement’ form

On the ‘Consultant placement’ page you can describe your requirements to us using a form. It has two steps. In the first step we collect only what we need in order to get back to you: the type of requirement (placement into a permanent position, introduction of a freelance specialist or still open), the professional profile sought, your company, and the name and email address of the contact person; the telephone number is optional. In the second step you can optionally add: number of people sought, level of experience, specialist focus, industry, scope, project duration, preferred start date, budget or salary range, languages, project location, remote working options and a free-text description. If you abandon the second step, only the information from the first step is kept.

For each request we also store the time of receipt, the website language you selected, the time at which you confirmed the notice referring to this privacy policy and, for handling purposes, a status, the member of our management who is handling the request and an internal note on its progress.

Purpose: handling your request, searching for suitable consultants and contacting you about it.

Legal basis: Art. 6(1)(b) GDPR, as the processing is carried out at your request to take steps prior to entering into a contract; otherwise Art. 6(1)(f) GDPR on the basis of our legitimate interest in responding to business enquiries.

Recipient: The information is stored in a database operated by the service provider Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 (‘Supabase’), which acts for us as a processor under Art. 28 GDPR. The data is physically held in an Amazon Web Services data centre in Ireland; Supabase uses this hosting provider as a sub-processor. The data is not passed on to third parties for their own purposes.

Transfers to third countries: Supabase is based in Singapore; access from there – for example in the course of maintenance and support – cannot be ruled out. Such transfers are based on the European Commission’s standard contractual clauses under Implementing Decision (EU) 2021/914 (Module 2, controller to processor), which form part of our data processing agreement with Supabase. Data is transmitted in encrypted form.

In addition, when a request comes in, we receive a notification by email to our mailbox. The notification contains no name, no email address, no telephone number and no message text of the person making the request, but only the type of requirement, the reference number of the request, the language selected and the time of receipt – that is, no information about you or your company. It is sent in encrypted form from our own mailbox via the Microsoft 365 interface; no other mail provider is involved, and no copy is kept in the ‘Sent’ folder. Our mailbox is operated by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Microsoft 365 / Exchange Online) as a processor under Art. 28 GDPR; the data is stored in data centres within the EU. Where access from the USA is possible, this is based on the European Commission’s standard contractual clauses and the adequacy decision for the EU-U.S. Data Privacy Framework. Once the record of the request has been deleted, the notification can no longer be linked to anyone.

Retention period: We delete your request automatically twelve months after it was received. If we go on to work together, we transfer the information required for this into our contract records; the retention periods under commercial and tax law (generally six or ten years) apply there.

Protection against misuse: To fend off automated mass submissions, we evaluate a form field that is invisible to you and the time between opening and submitting the form, and we limit the number of submissions per sender. For this purpose, a non-reversible hash value is derived from your IP address; it is held only in our server’s memory and discarded after 15 minutes at the latest. Your IP address is not stored.

7. Initial SAP consultation via the form

At the end of the SAP topic pages and on the SAP overview page, you can contact us via a form to arrange an initial consultation. We collect your name, email address and message; your company, telephone number and the SAP topic concerned are optional.

For each request we also store the time of receipt, the website language you selected, the time at which you confirmed the notice referring to this privacy policy and, for handling purposes, a status, the member of our management who is handling the request and an internal note on its progress.

Purpose: handling your request and contacting you about it.

Legal basis: Art. 6(1)(b) GDPR, as the processing is carried out at your request to take steps prior to entering into a contract; otherwise Art. 6(1)(f) GDPR on the basis of our legitimate interest in responding to business enquiries.

Recipient: The information is stored in a database operated by the service provider Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 (‘Supabase’), which acts for us as a processor under Art. 28 GDPR. The data is physically held in an Amazon Web Services data centre in Ireland; Supabase uses this hosting provider as a sub-processor. The data is not passed on to third parties for their own purposes.

Transfers to third countries: Supabase is based in Singapore; access from there – for example in the course of maintenance and support – cannot be ruled out. Such transfers are based on the European Commission’s standard contractual clauses under Implementing Decision (EU) 2021/914 (Module 2, controller to processor), which form part of our data processing agreement with Supabase. Data is transmitted in encrypted form.

In addition, when a request comes in, we receive a notification by email to our mailbox. The notification contains no name, no email address, no telephone number and no message text of the person making the request, but only the topic selected, the reference number of the request, the language selected and the time of receipt – that is, no information about you or your company. It is sent in encrypted form from our own mailbox via the Microsoft 365 interface; no other mail provider is involved, and no copy is kept in the ‘Sent’ folder. Our mailbox is operated by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Microsoft 365 / Exchange Online) as a processor under Art. 28 GDPR; the data is stored in data centres within the EU. Where access from the USA is possible, this is based on the European Commission’s standard contractual clauses and the adequacy decision for the EU-U.S. Data Privacy Framework. Once the record of the request has been deleted, the notification can no longer be linked to anyone.

Retention period: We delete your request automatically twelve months after it was received. If we go on to work together, we transfer the information required for this into our contract records; the retention periods under commercial and tax law (generally six or ten years) apply there.

Protection against misuse: To fend off automated mass submissions, we evaluate a form field that is invisible to you and the time between opening and submitting the form, and we limit the number of submissions per sender. For this purpose, a non-reversible hash value is derived from your IP address; it is held only in our server’s memory and discarded after 15 minutes at the latest. Your IP address is not stored.

8. Audience measurement without cookies

To understand which pages are visited and how the website is used overall, we carry out our own cookieless audience measurement. We do not use any third-party provider for this; the measurement runs exclusively via our own server at Vercel.

When a page is opened, a script on our website sends the page opened and the language selected to our server; it does not read anything from your device and stores nothing there. Our server adds your country (roughly derived by Vercel from the network connection, see section 3), your device type (mobile or desktop) and the date and time of the visit. In addition, we create a pseudonymous daily identifier: a hash value derived from your IP address, your browser type and a secret value that changes daily and is held only on our server. We use this identifier to group the page views of a visit within the same day. The identifier cannot be recognised beyond that day, not even if you visit again the following day.

What is not stored: Your IP address and the full browser type (user agent) are not stored; they are used only to create the hash value and are then discarded. No cookies are set and no data is stored in your browser’s storage.

Purpose: We want to understand which content attracts interest and how use of the website develops, so that we can improve it in a targeted way.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in understanding the reach and use of our website without resorting to third-party tools or cookies.

As nothing is stored on or read from your device for this measurement, no consent is required under Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG).

Recipient and storage location: The information is stored in a database operated by the service provider Supabase, as described in section 6.

Retention period: We delete individual page views automatically after 90 days. For year-on-year comparison, we additionally keep daily totals per page, language, country and device type – without the daily identifier, and therefore without any link to individual visitors – for 25 months.

9. Administration area for the management

At the address ‘/admin’ there is an access-protected area in which we handle incoming requests and evaluate the audience measurement. It is intended solely for our management; visitors to the website do not use it. To log in, the email address of the person logging in is transmitted to Supabase (section 6), which manages the login session and creates a single-use login link. We send this link from our mailbox via Microsoft 365, as described in section 6. In the process, the browser of the logged-in person stores a session cookie (name beginning with ‘4trust-admin-auth’) and, temporarily, a technical cookie for the login process; both concern only the logged-in person. Failed login attempts are limited by means of a hash value held briefly in memory, as described in section 6.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure access to the requests we have received).

10. Links

The website contains links to external websites, including the LinkedIn profiles of our managing directors. If you click on such a link, you leave our website. We have no influence over the data processing carried out by the operators of the linked pages; their own privacy policies apply there.

11. Information about our managing directors

On the ‘About us’ pages we publish the names, positions, professional background, portraits and links to the LinkedIn profiles of our two managing directors. We also make the same information available to search engines in machine-readable form (structured data according to schema.org). This information is published with the knowledge and consent of the two persons concerned, who are also the shareholders and representatives of the controller.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in presenting the company to the public).

12. Your rights as a data subject

You have the following rights with regard to us:

  • Access to information on whether and what data we process about you (Art. 15 GDPR)
  • Rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR)
  • Erasure of your data stored by us (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR)
  • Objection to processing that we base on a legitimate interest (Art. 21 GDPR)

To exercise these rights, an informal message to the contact details given above is sufficient.

13. Right to object

Information on your right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest). On this website, this concerns the processing of server log files, the language selection cookie and the cookieless audience measurement (section 8).

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

An informal message to info@4trust-consulting.com is sufficient to object.

14. Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit
Nordrhein-Westfalen
(State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2–4, 40213 Düsseldorf
www.ldi.nrw.de

15. SSL/TLS encryption

For security reasons, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that your browser’s address bar begins with ‘https://’ and displays a padlock symbol. This means that the data you transmit to us cannot be read by third parties.

16. Changes to this privacy policy

We update this privacy policy whenever changes to our website or to the legal framework make this necessary. The version available at the time of your visit applies.