Privacy Policy
BayPass Information about the processing of personal data on the BayPass website.
1. General Information
Protecting your personal data is important to us. In this privacy policy, we explain which personal data we process when you visit our website, use our forms or contact us, for what purposes this happens, on which legal basis the processing takes place and which rights you have.
Personal data means any information that can identify you personally, for example your name, e-mail address, phone number, IP address, company details or the content of an enquiry.
2. Controller
The controller responsible for data processing on this website is:
BayPass
Owner: Mehmet Sakir BAYINDIR
55122
Mainz
Germany
E-mail: kontakt@baypass.net
Phone: +4915121631920
Website: https://baypass.net
3. Hosting and Server Log Files
This website is operated by an external hosting provider. When you visit the website, the hosting provider automatically processes technical access data that is required for the secure, stable and error-free provision of the website.
This may include in particular the following data:
- IP address
- date and time of access
- requested URL
- referrer URL
- browser used
- operating system used
- HTTP status code
- amount of data transferred
- hostname of the accessing computer
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and error-free provision of our website and in the prevention of misuse, attacks and technical disruptions.
Server log files are stored only for as long as necessary for the purposes mentioned and are then deleted or anonymised, unless statutory retention obligations or legitimate security interests require longer storage.
Hosting provider: ionos.de
Server location: Germany
Where the hosting provider processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR, where such an agreement is legally required.
4. SSL or TLS Encryption
This website uses SSL or TLS encryption for security reasons. You can recognise an encrypted connection by the fact that the address line of the browser begins with “https://” and a lock symbol is displayed.
Encryption helps prevent data that you transmit to us from being easily read by third parties.
5. Contact by E-mail, Phone or Contact Form
If you contact us by e-mail, phone or via a contact form, we process the data you provide in order to handle your enquiry.
This may include in particular the following data:
- name
- e-mail address
- phone number
- company
- website
- content of your message
- requested service or project description
The processing is based on Art. 6(1)(b) GDPR if your enquiry is related to pre-contractual measures or a contract. In all other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in handling and responding to your enquiry.
The data you submit remains with us until the purpose of storage no longer applies, you request deletion or statutory retention obligations prevent deletion.
6. Project Enquiries, Website Check and Other Forms
You can use various forms on our website, for example for project enquiries, the free website check, maintenance and support, AI automation or partner enquiries.
Depending on the form, the following data may be processed in particular:
- name
- e-mail address
- phone number
- company
- website URL
- requested service
- budget or timing information
- project description
- content of your enquiry
The processing is based on Art. 6(1)(b) GDPR where the enquiry serves the preparation or performance of a contract. In addition, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in professionally handling your enquiry, preparing a suitable assessment and communicating with you.
If you request a free website check, we may technically and editorially review the website you provide. Only publicly accessible information from the specified website is taken into account.
7. Technical Spam Checks for Forms
Our forms use simple technical measures to protect against automated spam and misuse. These may include hidden form fields, time checks and technical form information.
This data is not used for profiling. The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, communication channels and technical systems from misuse and automated spam requests.
8. Communication via WhatsApp
Our website may include links or buttons that allow you to contact us via WhatsApp. If you use this function, you leave our website and communicate via the WhatsApp service.
The provider of WhatsApp is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
If you contact us via WhatsApp, we process the data you transmit in order to handle your enquiry. This may include in particular your phone number, profile name, message and any files you transmit.
Please do not send us sensitive data, passwords, access credentials or confidential documents via WhatsApp.
Processing by us is based, depending on the content of the enquiry, on Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR. WhatsApp itself is responsible for the data processing carried out by WhatsApp.
When using WhatsApp, personal data may also be transferred to companies of the Meta group or to countries outside the European Union or the European Economic Area. We have no influence over this data processing by WhatsApp.
9. Cookies, Local Storage and Similar Technologies
Our website uses technically necessary cookies and comparable technologies where these are required for the operation of the website or for functions expressly requested by you.
This may include in particular:
- session cookies for the technical provision of the website
- CSRF protection cookies to secure forms
- local storage of display or operating states, for example theme settings or dismissed notices
The processing of technically necessary cookies and comparable technologies is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, technically error-free and user-friendly provision of our website.
Where information is stored in or accessed from the user’s terminal equipment, this is done for technically necessary functions on the basis of Section 25(2) TDDDG. For non-essential cookies, analytics tools, marketing tools or comparable services, we obtain prior consent where legally required.
10. No Analytics or Marketing Tools
We currently do not use our own analytics or marketing tools such as Google Analytics, Meta Pixel, Hotjar or comparable tracking technologies.
If we use analytics or marketing tools in the future, this privacy policy will be updated accordingly and, where required, prior consent will be obtained.
11. Google Search Console
We use Google Search Console to monitor the technical visibility of our website in Google Search and to identify possible indexing or display issues.
Google Search Console is not embedded as a tracking tool on our website and does not set cookies on our website. Through Search Console, we receive aggregated information about how our website is found in Google Search. This information is used for technical and content-related optimisation of our website.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
12. Local Fonts
Fonts on this website are embedded locally from our own server. When you access our website, no connection is established to external font provider servers, in particular not to Google Fonts.
If external font providers are used in the future, this privacy policy will be updated accordingly.
13. OpenStreetMap
A map from OpenStreetMap may be embedded on our contact page. The map is not loaded automatically when the page is opened. Only when you actively load the map using the corresponding button is a connection established to OpenStreetMap servers or to technical services used for map display.
The provider is the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom.
When loading the map, technical data such as your IP address, browser information, date and time of access and the page accessed may be transmitted.
Processing only takes place after your active decision to load the map. The legal basis is Art. 6(1)(a) GDPR where consent is required. Where the integration serves the user-friendly display of our location, processing may also be based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the user-friendly display of our location.
If the map is not loaded, no data transmission takes place via the map.
14. E-mail Delivery and E-mail Provider
If you contact us via a form, your enquiry is transmitted to us by e-mail. The data you enter may be processed via our e-mail provider.
E-mail provider: brevo.com
Server location: Germany
The processing is based on Art. 6(1)(b) GDPR if the communication is related to pre-contractual measures or a contract, and otherwise on Art. 6(1)(f) GDPR. Our legitimate interest lies in reliably handling incoming enquiries.
Where the e-mail provider processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR, where such an agreement is legally required.
15. Recipients of Personal Data
Personal data is only passed on to third parties if this is necessary to handle your enquiry, fulfil a contract, operate the website, comply with legal obligations or on the basis of a legitimate interest.
Possible recipients may include:
- hosting provider
- e-mail provider
- technical service providers
- tax advisors or accounting, where required
- authorities, where legally required
Your data is not passed on for advertising purposes.
16. Transfers to Third Countries
Personal data is transferred to countries outside the European Union or the European Economic Area only where this is necessary for the use of individual services, there is a legal basis, appropriate safeguards are in place or you have consented.
This may be relevant in particular when using WhatsApp or actively loading external services. Where required, a third-country transfer is based on an adequacy decision of the European Commission, standard contractual clauses or explicit consent.
17. Storage Period
We store personal data only for as long as necessary for the respective purposes or as long as statutory retention periods apply.
Enquiries by e-mail or contact form are deleted once processing has been completed and no statutory retention obligations or legitimate interests in further storage apply.
If an enquiry results in an order, offer, invoice or other business relationship, business documents and contract-related communication may be stored for longer due to statutory retention obligations.
18. Provision of Personal Data
Providing personal data is generally voluntary. However, if you want to contact us, submit a form or make a project enquiry, we need certain information in order to process your enquiry.
Without the required information, we may not be able to process your enquiry or may only be able to process it to a limited extent.
19. Your Rights
Within the scope of the statutory provisions, you have the following rights:
- right of access to your stored personal data
- right to rectification of inaccurate data
- right to erasure of your data
- right to restriction of processing
- right to data portability
- right to object to certain processing
- right to withdraw consent with effect for the future
- right to lodge a complaint with a data protection supervisory authority
If you would like to exercise any of these rights, you can contact us at any time.
20. Right to Object under Art. 21 GDPR
If we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing or the processing serves the establishment, exercise or defence of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to processing for such marketing.
21. Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
The competent supervisory authority for Rhineland-Palatinate is:
The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate
Hintere Bleiche 34
55116 Mainz
Website: https://www.datenschutz.rlp.de
22. No Automated Decision-Making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place on this website.
23. Objection to Advertising E-mails
We object to the use of contact details published in the imprint or on this website for sending unsolicited advertising. We reserve the right to take legal action in the event of unsolicited advertising, for example spam e-mails.
24. Current Status of this Privacy Policy
This privacy policy is currently valid and was last updated in June 2026.
We reserve the right to update this privacy policy if our website, technical systems or legal requirements change.