Skip to content
Welling Immobilien

Privacy statement

As at: 5 September 2026 · Version 1

At a glance

This website is deliberately built to collect as little data as possible. It consists of files generated in advance and delivered by a single server in Germany. No third-party services are embedded.

When a page is opened, only the HTML document with a few lines of JavaScript for the menu, the filter and the image display, one stylesheet, up to three font files and the images of that page are transmitted. All of it comes from the same server. The JavaScript runs solely in your browser and sends nothing back.

  • no audience measurement, no statistics, no profiling
  • no maps, no embedded videos, no social network buttons
  • no fonts from third-party servers — they are held in our own directory
  • no advertising networks, no disclosure to third parties for advertising purposes
  • no cookies; nothing is stored on your device
  • no transfer to countries outside the European Union

Controller

The controller for the processing of personal data within the meaning of Art. 4(7) GDPR is:

Anton Welling Nachf. Oliver Welling e.K.
Weseler Straße 480
48163 Münster
Deutschland

T. 0251 – 609 68 7-0
F. 0251 – 609 68 7-127
freecall 0800-welling
info@welling-immo.com

HRA 3073 · Registergericht Münster
VAT ID DE 126096614

Second office

AREO-Turm, 25. Etage
Bonner Straße 211
50968 Köln
Deutschland

Data protection officer

Whether a data protection officer has to be appointed is currently being examined. As long as no appointment has been published, please address data protection enquiries to the postal address or the e-mail address given above. The matter is listed as an open point at the end of this statement.

What this statement covers

This statement applies to the website at the internet address given above. Personal data are all details relating to an identified or identifiable natural person (Art. 4(1) GDPR) — this includes in particular the IP address of your connection.

It does not apply to websites of other providers linked from here. Their content and their data processing are the sole responsibility of the respective provider.

Opening the pages, hosting and server logs

The website is operated on a rented server. The provider, and thus the processor within the meaning of Art. 28 GDPR, is:

Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Deutschland
HRB 6089, Amtsgericht Ansbach

The server is located in the Nuremberg data centre in Germany. It is named “welling-sites”, runs on Debian 13 and delivers the pages through the Caddy web server. The data do not leave the Federal Republic of Germany.

Connection data

As with every request on the internet, the delivering server has to process technically necessary connection data. These regularly include:

  • the IP address of the requesting connection
  • the time and time zone of the request
  • the address requested and the transfer protocol used
  • the server’s response (status code) and the volume of data transferred
  • the identifier of the browser and the operating system (user agent)
  • the page from which the request was made (referrer), where the browser transmits it

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to provide the website free of technical faults, to detect malfunctions and to defend the server against attacks. These data are not combined with other sources, and no usage profile is created from them.

Which of these details are in fact written to a log file, whether the IP address is truncated, and after what period the entries are deleted, depends on the configuration of the web server. That decision is still outstanding; it will be added here once it has been made. Until then the point is listed as open at the end of this statement.

Processing on our behalf

A data processing agreement under Art. 28 GDPR is to be concluded with the server provider, in so far as this has not already happened. Its conclusion is listed as an open point at the end of this statement. This statement expressly does not assert that the agreement is already in place.

Cookies, comparable techniques and your consent

Under section 25(1) TDDDG, storing information on your end device and accessing information stored there is permitted only with your consent. Strictly necessary operations are excepted under section 25(2) TDDDG.

At present neither takes place: this website sets no cookies, stores nothing in your browser and reads nothing from your browser. Consent is therefore not required, and none is requested.

The website nevertheless carries a complete consent management system. It is built in but switched off: it appears only at the moment a service actually requiring consent is set up. Showing a consent banner when there is nothing to consent to would be misleading — it would assert data processing that does not take place.

As soon as such a service is set up, the following applies: you are asked before anything is loaded or stored. Nothing is pre-ticked. “Necessary only” is just as easy to reach as “Accept all”. Without your decision, only what is strictly necessary happens.

The categories in detail

Strictly necessary

These operations are required for the pages to be delivered and used at all. They cannot be switched off, because without them no page could be opened. Under section 25(2) TDDDG no consent is required for them.

  • Delivery of the pages
    The web server has to deliver the requested page and handle the connection. Nothing is stored on your device for this; only connection data arise on the server.
    Art. 6(1)(f) GDPR (legitimate interest)
  • Record of your privacy settings
    Records which categories you have allowed or refused, so that you are not asked again on every visit and so that we can demonstrate the decision (Art. 7(1) GDPR). The entry is only created once a processing operation requiring consent has been set up and you have made a choice.
    Art. 6(1)(c) GDPR (legal obligation)
Statistics

Audience measurement: records anonymously or pseudonymously which pages are opened how often, how long visitors stay and which route they arrive by. This serves solely to improve the site. Without your consent nothing is measured.

No audience measurement is currently set up.

External media

Content loaded from third-party servers — maps, videos, fonts. When it loads, the third-party server learns your IP address and may set its own cookies. Without your consent nothing is loaded; a notice with a button appears in its place instead.

No content from third-party servers is currently embedded.

Marketing

Advertising and measuring the success of advertisements, where applicable across several websites. Without your consent none of this takes place.

No advertising service is currently set up.

How your decision is recorded

Your decision is stored solely in your browser, in what is called “local storage” and not as a cookie. The reason: a cookie would be sent to the server with every single request — including every image and every font file — and would be visible in the server logs. Yet the server does not need to know your decision at all, because the site is static. The local storage entry never leaves your device. This is the option that collects the least data (Art. 5(1)(c) GDPR).

What is recorded is the time of your decision, the categories chosen, the version number of the consent text and a fingerprint of the list of services. This allows us to demonstrate the consent (Art. 7(1) GDPR). If the list of services changes, the fingerprint no longer matches; the earlier consent then lapses and you are asked again. Consent once given is therefore never silently carried over to a new service.

The entry does not expire by itself. You can delete it at any time through your browser settings; you will then be asked again on your next visit.

  • welling-immo.einwilligung (localStorage) — time, chosen categories, version number and fingerprint of the list of services. until you delete it or change your choice; it does not expire by itself and becomes invalid whenever the list of services changes.

Withdrawal

At present there is nothing to withdraw: no consent is requested and none is given. For the same reason there is currently no “Cookie settings” link at the foot of the pages — it would lead nowhere. As soon as consent is obtained, that link appears on every page; withdrawing is then just as easy as giving consent (Art. 7(3) GDPR) and takes effect for the future, without affecting the lawfulness of processing carried out until then.

Contacting us

Contact form

Current state.

There is a form on the contact page. It is not currently connected to any delivery route. No data are therefore transmitted through this form, none are stored and none reach us. A notice on the contact page says so.

Intended state.

Once the delivery route has been set up, the details you enter — name, e-mail address and message — will be transmitted as an e-mail to our mailbox. Dispatch takes place through Microsoft 365 in the company’s own tenant of Anton Welling Nachf. Oliver Welling e.K.; depending on the matter, the recipients are the mailboxes for acquisitions or for general enquiries.

  • Purpose: handling and answering your enquiry
  • Legal basis: Art. 6(1)(b) GDPR where your enquiry concerns a contract or its initiation; in all other cases Art. 6(1)(f) GDPR, our legitimate interest being to answer enquiries
  • Mandatory details: name, e-mail address and message; without them we cannot reply
  • Retention: until your enquiry has been dealt with conclusively and there is no further reason to keep the matter on file; deletion thereafter, unless statutory retention obligations apply (for example section 257 HGB, section 147 AO)
  • Intended recipients: ankauf@welling-immo.com, info@welling-immo.com

E-mail, telephone and post

If you send us an e-mail, call us or write to us, we process your details in order to deal with your matter. The legal basis is Art. 6(1)(b) GDPR for contract-related matters, otherwise Art. 6(1)(f) GDPR.

Our mailboxes are operated in the company’s own Microsoft 365 tenant of Anton Welling Nachf. Oliver Welling e.K. The details — place of processing, data processing agreement and any third-country aspects — are listed as an open point at the end of this statement and will be added here.

Please note: an unencrypted e-mail is like a postcard. For confidential matters, please use the post or the telephone.

Fonts, images and media

The typeface used, “Open Sans”, is held in our own directory and delivered by the same server as the page. There is no connection to a third-party font service, and no such server learns anything about your visit.

All images are likewise delivered from our own server. No third-party content delivery network is used.

Services not currently in use

The following sections are prepared in advance. None of these services is set up; none processes any data today. They appear here so that it is clear what would have to be added before such a service may be switched on.

These sections and the consent management system are fed from the same configuration file. If a service is switched on, this statement changes with it — and consent is requested from that moment.

Audience measurement

Not currently in use. Category: Statistics.

Audience measurement would record which pages are opened how often, how long visitors stay, which device and screen width are used and by which route the visit came about.

To be supplied before switching on:

  • company name and full address of the provider
  • purpose of the processing and the categories of data collected
  • legal basis — for services requiring consent, consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG
  • names, type and lifetime of the entries placed (cookies or comparable techniques)
  • retention period at the provider
  • transfers to third countries and the safeguard relied on under Art. 44 et seq. GDPR
  • data processing agreement under Art. 28 GDPR, or a joint controllership arrangement under Art. 26 GDPR
  • address of the provider’s own privacy statement
  • statement whether the IP address is truncated and whether measurement works without cookies

Maps

Not currently in use. Category: External media.

An embedded map would load data from a third-party server when the page is opened. That server would learn your IP address and the page opened.

To be supplied before switching on:

  • company name and full address of the provider
  • purpose of the processing and the categories of data collected
  • legal basis — for services requiring consent, consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG
  • names, type and lifetime of the entries placed (cookies or comparable techniques)
  • retention period at the provider
  • transfers to third countries and the safeguard relied on under Art. 44 et seq. GDPR
  • data processing agreement under Art. 28 GDPR, or a joint controllership arrangement under Art. 26 GDPR
  • address of the provider’s own privacy statement
  • design of the placeholder shown before the content is loaded

Embedded videos

Not currently in use. Category: External media.

An embedded video would be loaded from a third-party server. Video platforms regularly set their own cookies and link the visit to an account if you are signed in there.

To be supplied before switching on:

  • company name and full address of the provider
  • purpose of the processing and the categories of data collected
  • legal basis — for services requiring consent, consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG
  • names, type and lifetime of the entries placed (cookies or comparable techniques)
  • retention period at the provider
  • transfers to third countries and the safeguard relied on under Art. 44 et seq. GDPR
  • data processing agreement under Art. 28 GDPR, or a joint controllership arrangement under Art. 26 GDPR
  • address of the provider’s own privacy statement
  • statement whether a data-reduced delivery mode of the provider is used

Fonts from third-party servers

Not currently in use. Category: External media.

Fonts are currently delivered from our own directory. If they were loaded from a third-party server, that server would learn your IP address on every page view.

To be supplied before switching on:

  • company name and full address of the provider
  • purpose of the processing and the categories of data collected
  • legal basis — for services requiring consent, consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG
  • names, type and lifetime of the entries placed (cookies or comparable techniques)
  • retention period at the provider
  • transfers to third countries and the safeguard relied on under Art. 44 et seq. GDPR
  • data processing agreement under Art. 28 GDPR, or a joint controllership arrangement under Art. 26 GDPR
  • address of the provider’s own privacy statement
  • reason why delivery from our own directory is being given up

Newsletter

Not currently in use. Category: Marketing.

A newsletter would record the sign-up in a confirmed procedure (double opt-in), log the dispatch and, where applicable, measure whether a message was opened.

To be supplied before switching on:

  • company name and full address of the provider
  • purpose of the processing and the categories of data collected
  • legal basis — for services requiring consent, consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG
  • names, type and lifetime of the entries placed (cookies or comparable techniques)
  • retention period at the provider
  • transfers to third countries and the safeguard relied on under Art. 44 et seq. GDPR
  • data processing agreement under Art. 28 GDPR, or a joint controllership arrangement under Art. 26 GDPR
  • address of the provider’s own privacy statement
  • description of the sign-up procedure and of how consent is logged
  • statement whether open tracking takes place, plus the unsubscribe notice in every message

Application form

Not currently in use. Category: Strictly necessary.

An application form would receive application documents. Special categories of personal data may arise in the process (Art. 9 GDPR), for example information about a severe disability.

To be supplied before switching on:

  • company name and full address of the provider
  • purpose of the processing and the categories of data collected
  • legal basis — for services requiring consent, consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG
  • names, type and lifetime of the entries placed (cookies or comparable techniques)
  • retention period at the provider
  • transfers to third countries and the safeguard relied on under Art. 44 et seq. GDPR
  • data processing agreement under Art. 28 GDPR, or a joint controllership arrangement under Art. 26 GDPR
  • address of the provider’s own privacy statement
  • legal basis section 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR
  • deletion period after the procedure ends, and a rule that inclusion in a talent pool requires separate consent
  • encrypted transmission and access restricted to those involved in the procedure

Recipients of your data

We do not pass on personal data for advertising purposes and we do not sell them. The only recipients are:

  • the server provider as processor, in so far as the processing is technically unavoidable
  • the operator of our e-mail system, in so far as you write to us
  • authorities and courts, in so far as we are required by law to do so
  • our advisers, in so far as they are bound to confidentiality and knowledge is necessary to carry out the engagement

Transfers to third countries

No personal data are transferred to a country outside the European Union or the European Economic Area in connection with opening these pages. The server is in Germany; no third-party services are embedded.

Should a service involving such a transfer be switched on in future, this will be stated here together with the country and the safeguard relied on under Art. 44 et seq. GDPR.

Retention periods

We keep personal data only for as long as is necessary for the respective purpose or as long as a statutory retention obligation applies.

  • Server connection data: the period has not yet been determined and is listed as an open point at the end of this statement.
  • Enquiries by form, e-mail, telephone or post: until they have been dealt with conclusively; deletion thereafter, unless a statutory retention obligation applies (for example section 257 HGB, section 147 AO).
  • Record of your privacy settings: solely in your browser, until you delete it or change your choice. It only comes into existence once consent is obtained at all.

Your rights

As a data subject you have the following rights:

  • Access (Art. 15 GDPR): you may request information as to whether and which data we process about you, for which purposes, to which recipients and for how long.
  • Rectification (Art. 16 GDPR): you may request that inaccurate data be corrected and incomplete data completed.
  • Erasure (Art. 17 GDPR): you may request the erasure of your data, unless a statutory retention obligation applies.
  • Restriction of processing (Art. 18 GDPR): you may request that processing be restricted, for example while we verify the accuracy of contested data.
  • Data portability (Art. 20 GDPR): you may request that we hand over to you, in a common machine-readable format, the data you provided to us on the basis of consent or a contract.
  • Notification obligation (Art. 19 GDPR): we communicate every rectification, erasure or restriction to all recipients to whom the data were disclosed, unless this proves impossible or involves disproportionate effort.

Right to object (Art. 21 GDPR)

In so far as we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR — here principally the server connection data and the handling of enquiries not related to a contract — you have the right to object at any time to that processing on grounds relating to your particular situation.

If you object, we will no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

An informal message to the postal or e-mail address given above is sufficient to object.

Withdrawal of consent (Art. 7(3) GDPR)

If you have consented to processing, you may withdraw that consent at any time with effect for the future. Withdrawing is just as easy as giving consent: as soon as consent to cookies and comparable techniques is obtained, the “Cookie settings” link at the foot of every page suffices for that purpose; otherwise an informal message is enough. The lawfulness of processing carried out until the withdrawal remains unaffected.

Complaint to a supervisory authority (Art. 77 GDPR)

Without prejudice to other remedies, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your data infringes the General Data Protection Regulation. The competent authority is that of your place of residence, your place of work or the place of the alleged infringement. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf
Deutschland

Telephone +49 211 38424-0
poststelle@ldi.nrw.de
ldi.nrw.de

No automated decision-making

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.

Are you obliged to provide data?

You are under no statutory or contractual obligation to provide us with personal data. Without a name and contact details, however, we cannot answer an enquiry. Merely reading these pages requires no details at all.

Data security

The website is delivered over an encrypted connection (HTTPS with TLS); the Caddy web server used sets up the encryption automatically and renews the certificates. You can recognise an encrypted connection by the padlock in your browser’s address bar.

We also take technical and organisational measures under Art. 32 GDPR to protect your data against loss, destruction and unauthorised access. The measures are adapted to the state of the art.

Open points

The following details are not yet available as at the date of this statement. They will be added here once settled. They are shown here rather than asserted without foundation:

  • Data processing agreement under Art. 28 GDPR with the server provider — conclusion not yet confirmed.
  • Scope and deletion period of the server logs, and whether the IP address is truncated — the web server configuration has yet to be settled.
  • Details of the e-mail system: place of processing, data processing agreement and any third-country aspects of the Microsoft 365 tenant used.
  • Recipient address and technical route of the contact form, once it is connected.
  • Appointment of a data protection officer under Art. 37 GDPR — examination not yet concluded.
  • Telephone number of the second office in Cologne — not yet assigned.

Changes to this statement

We amend this statement as soon as the processing operations described change — in particular when a service not previously in use is switched on. The version available here, bearing the date given above, is always the authoritative one.

Note on the status of this text

This statement describes the technical state of the website as at the date given. It is not legal advice. Before the website is published it should be reviewed by a lawyer and completed with the open points listed above.