SchweinfurtFirmen
CategoriesCompaniesSearchAdvertise
List your business
SchweinfurtFirmen

The business directory for Schweinfurt and the district — trades, retail, restaurants and services in one place.

Discover

  • Companies
  • Categories
  • Search

For businesses

  • List your business
  • Advertise on Schweinfurt Firmen

Legal

  • Legal notice
  • Privacy
  • Terms
  • Ranking

All information without warranty · Company data is maintained with care but may change at any time.

© 2026 Schweinfurt FirmenMade in Schweinfurt

Geodata © OpenStreetMap contributors (ODbL)

Privacy Policy

This privacy policy informs you about the nature, scope and purpose of processing personal data on this website. The controller within the meaning of the GDPR (Art. 4 (7)) is:

Oliver Ziegler Consulting UG
Cramerstraße 24D
97421 Schweinfurt
Deutschland
E-Mail: swfirmen@chekaz.dev

1. What data is processed

This site does not set tracking cookies and does not embed any third-party scripts. Without an explicit sign-in, no cookies whatsoever are set for visitors; the language (DE/EN) follows solely from the address of the page you open and is not stored. The editorial administration area additionally uses a strictly necessary session cookie for sign-in — public visitors never encounter it; you likewise receive a strictly necessary session cookie if you sign in to manage a company listing (sections 11 and 21). When a page is loaded, the following technically necessary data is also logged by the web server: date and time, requested URL, HTTP response code, IP address, user agent. These logs serve operational security only and are automatically deleted after 14 days. Anonymous reach measurement is additionally performed via our own self-hosted GoatCounter instance (details in section 8).

2. Legal basis and purpose

Log data is processed under our legitimate interest (Art. 6 (1) (f) GDPR) in the secure and stable operation of the site. No profiling takes place. Data is forwarded to third parties only in the case of a substantiated suspicion of unlawful use as part of an official inquiry.

3. External links and embedded content

Our pages embed no scripts, fonts or other content from third-party servers. Company profiles contain links to external websites (e.g. the company's own website or route planning via Google Maps). When you click such a link you leave our service; the privacy policy of the respective provider then applies. Only upon that click is any data (e.g. your IP address) transmitted to the third party. An exception applies to optional video embeds on Premium company profiles, which are only loaded after your explicit consent — see section 17.

4. Origin of the company data

The company data published in the directory (company name, address, contact details, opening hours, service description, logo) comes from publicly accessible sources — in particular the companies' own websites and legal-notice (Impressum) details — as well as from entries submitted to us via our company-submission form (/eintragen). The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in operating a regional business directory). Where details about sole proprietors constitute personal data, we provide the information required under Art. 14 GDPR by means of this privacy policy; individually notifying every listed company would involve disproportionate effort (Art. 14 (5) (b) GDPR). You may object to the processing at any time (Art. 21 GDPR) — via the "Report data" function on the relevant company profile or by email to the address given in the legal notice; we will then review correction or removal.

5. Automated analysis of company websites

To create and update entries we fetch a company's publicly accessible website server-side and have structured data (e.g. address, opening hours, description) extracted from it by an AI language model. To do so we transmit excerpts of the website content to our service provider Requesty (Requesty LLC, USA) acting as an API router; the processing takes place on Google Vertex AI. For the English translation of German description texts we use DeepL (DeepL SE, Cologne). Only company information is processed, never data about visitors to this website. Automatically generated drafts are editorially reviewed before publication. Legal basis: Art. 6 (1) (f) GDPR. Where providers are based in the US, we base the transfer on Standard Contractual Clauses or the EU-US Data Privacy Framework (depending on the provider).

6. Encryption

This site is served exclusively over encrypted HTTPS connections. We apply appropriate technical and organisational measures to protect your data against unauthorised access (Art. 32 GDPR).

7. Hosting

This site is hosted on servers of DigitalOcean LLC, 101 Avenue of the Americas, 10th Floor, New York, NY 10013, USA — the specific server resides in the EU data centre in Frankfurt am Main. DigitalOcean acts as a processor within the meaning of Art. 28 GDPR; the corresponding Data Processing Agreement is available at https://www.digitalocean.com/legal/data-processing-agreement. A transfer to third countries cannot be fully excluded; such transfers occur on the basis of EU Standard Contractual Clauses (Art. 46 GDPR).

8. Reach measurement with GoatCounter

To improve the site we operate a self-hosted instance of the open-source analytics tool GoatCounter on our own server in Frankfurt am Main. The software sets no cookies, stores no IP addresses in plain text, and transmits no data to third parties. Only anonymous, aggregated metrics are recorded: requested URL, truncated referrer URL, browser family, operating-system family, screen size, language, date. IP addresses are hashed internally for daily deduplication and discarded at end of day. Processing is based on our legitimate interest (Art. 6 (1) (f) GDPR) in privacy-preserving reach measurement. You can opt out at any time via the "Do Not Track" setting in your browser — GoatCounter respects this signal and stops collection.

9. Submissions via the company-submission form

Via our company-submission form (/eintragen) you send us company data, your email address for follow-up questions and, optionally, your name and a message to the editorial team. We store the email address in plain text for as long as the submission is being processed; additionally we store a cryptographic hash of the email address and of the IP address to prevent abuse (rate limiting, duplicate detection). We do not store the IP address itself. Submissions that are not accepted are deleted automatically no later than 180 days after the decision, unreviewed submissions no later than 90 days after receipt; any uploaded logo is removed at the moment of rejection. If a submission is published, we remove your email address, your name and your message from our system no later than 180 days after the decision. On publication the company data becomes part of the directory (see section 12); your contact details do not appear publicly. Legal basis: Art. 6 (1) (b) and (f) GDPR.

10. Reports about directory entries ("Report data")

On every company profile you can use the "Report data" button to send a note to our editors — for example if information is incorrect or you object to the listing. We process the reason text you write (stored in plain text), optionally your email address — kept exclusively as a cryptographic hash, never in plain text — and a hash of your IP address to prevent abuse. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in editorial quality assurance of the directory data). Reports are retained only as long as needed for follow-up; you may request deletion or anonymisation of your report at any time (see section 18).

11. Cookies

We ourselves set no cookies for visitors of this site — in particular no marketing or tracking cookies. Excluded from this is the strictly necessary admin session cookie used in the editorial administration area, which public visitors never encounter. Likewise strictly necessary is the session cookie of the listing-management area (section 21): it is only set when you actively sign in there with a verification code, is valid for 30 days and is deleted on sign-out; for visitors who do not use this feature it is never set. Our GoatCounter reach measurement (section 8) likewise works entirely without cookies. Your language choice (DE/EN) is not stored in a cookie but follows from the address you open. There is exactly one case in which cookies requiring consent can be set, and they are set by a third party: when you explicitly start a video in a Premium company profile (section 17). We obtain your consent there at the moment of the click. As no cookies requiring consent under § 25 TDDDG (the German ePrivacy implementation) are therefore used without your consent, we deliberately do not display a cookie-consent banner.

12. Company data in the directory

At its core, this site is a regional business directory for the city of Schweinfurt and the surrounding Landkreis Schweinfurt. For the companies listed there we process and publish, where available, the following categories of data: company name (with legal form where applicable), address, contact details (phone, email, website, social media profiles), opening hours, category assignment, a short description of the business, logo and cover image, commercial-register entry and VAT ID. For sole proprietors and freelancers this information can constitute personal data within the meaning of the GDPR, for example where the company name is the person's own name.

For the origin of this data, the legal basis for publication, and your right to object and to have data corrected — in particular via the "Report data" function on the relevant company profile or by email to the address given in the legal notice — see section 4 ("Origin of the company data").

13. Payment processing (Stripe)

For the purchase of paid featured placements (see /werbung, "advertise") we use the payment provider Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland ("Stripe"). The payment itself takes place on a checkout page hosted by Stripe; you enter payment data (e.g. card numbers) exclusively there — we ourselves never receive or store complete payment data.

As part of the order process we transmit to Stripe: the name and email address of the purchasing person or company, the booked product, and the amount payable. On the Stripe payment page we additionally collect your billing address (required for a proper invoice under § 14 UStG) and — where VAT is calculated — optionally your VAT identification number; you enter these directly with Stripe. The payment data you enter at Stripe is processed by Stripe as an independent controller. The legal basis is Art. 6 (1) (b) GDPR (performance of the contract concluded with you for the featured placement). Stripe processes data partly outside the EU (in particular in the US); this occurs on the basis of Standard Contractual Clauses (Art. 46 GDPR). Further information is available in Stripe's privacy policy at https://stripe.com/privacy.

14. Order data and retention

For every order we store the associated order and invoice data (including the product booked, period, amount, payment status). The billing address and, where given, the VAT identification number are not stored in our own database but only in the invoice Stripe creates and keeps for us, which we access via the invoice number stored on our side. This data is subject to German commercial and tax-law retention obligations (in particular § 147 of the Fiscal Code (AO) and the GoBD principles) of currently up to ten years, and is retained for that period — even where a right to erasure under Art. 17 GDPR would otherwise apply, the statutory retention obligation takes precedence (Art. 17(3)(b) GDPR). The legal basis is Art. 6 (1) (c) GDPR in conjunction with Art. 6 (1) (b) GDPR.

15. Geodata (OpenStreetMap / Nominatim)

Company profile coordinates are geocoded once, server-side, from public company addresses via OpenStreetMap's Nominatim service. Only public company addresses are transmitted — never any visitor data. Geodata is provided by OpenStreetMap contributors under the Open Database License (ODbL); see openstreetmap.org/copyright.

16. Email verification for company updates

When you update a company's details you may optionally verify your email address. We send a one-time code only to the address you entered yourself (never to a stored company address). The legal bases are Art. 6(1)(b) GDPR (carrying out the step you requested) and Art. 6(1)(f) GDPR (legitimate interest in the accuracy of the directory data, Art. 5(1)(d) GDPR). Codes are stored only as a hash, are valid for 15 minutes, and are deleted no later than 24 hours after they expire. We use a processor to send them — see section 20. The same code delivery is also used for signing in to the listing-management area (section 21), where confirmation is a prerequisite for signing in.

17. Videos in Premium company profiles

Companies with a paid Premium profile may embed a video from YouTube (Google Ireland Limited or Google LLC, USA) or Vimeo (Vimeo.com, Inc., USA) on their own profile page. The video is not loaded automatically: initially only a thumbnail hosted on our own servers is shown, together with a play button, so that simply opening the profile page establishes no connection to the respective provider. Only when you click this button is the provider's player loaded; before that click, no contact with YouTube or Vimeo takes place at all. Clicking transmits data (including your IP address and device/browser information) to the respective provider, which may process it further in the US; this occurs on the basis of Standard Contractual Clauses or, for Google, the EU-US Data Privacy Framework. For YouTube we additionally use the more privacy-friendly youtube-nocookie.com domain; it limits tracking cookies but, despite its name, is not free of device storage: after the click the provider may set and read cookies or other storage on your device. The legal basis for loading the video and for that storage is exclusively your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG), given by clicking; without a click, no processing occurs. Your consent is not stored by us — we set no cookie for it — so it applies only to the current page visit, and reopening the page starts from the thumbnail again. Further information is available in the providers' privacy policies at https://policies.google.com/privacy (YouTube) and https://vimeo.com/privacy (Vimeo).

18. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Requests should be sent to the email address in the legal notice. You may also lodge a complaint with the Bavarian Data Protection Authority: Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.

19. Retention of Premium profile content

A Premium profile's photo gallery, services list, extended description, accent colour and video are only hidden, not deleted, once the associated booking ends, so a follow-on booking restores them instantly and unchanged. If no new booking follows within twelve months of the last booking's end, this content — including uploaded photos — is automatically and permanently deleted. The legal basis is Art. 6(1)(f) GDPR in conjunction with the storage-limitation principle (Art. 5(1)(e) GDPR).

20. Email delivery (Mailjet)

To send individual transactional emails we use Mailjet, a service of the Sinch group (Sinch AB (publ), Sweden), as a processor within the meaning of Art. 28 GDPR. We send exactly two kinds of message through it: the one-time code confirming your email address when you update a company's details or sign in to manage a listing (see sections 16 and 21), and the reminder that a placement or Premium profile you booked is about to expire, roughly 14 days before it ends. We do not send newsletters or circulars.

For this we transmit to Mailjet the recipient's email address as well as the subject and text of the message concerned. Mailjet additionally logs technical delivery data (such as delivery and delivery failures) so that sending remains traceable. The legal basis is Art. 6 (1) (b) GDPR for the confirmation code (carrying out the step you requested) and Art. 6 (1) (f) GDPR for the expiry reminder (legitimate interest in continuing the existing business relationship, § 7 (3) UWG).

You may object at any time to your address being used for the expiry reminder (§ 7 (3) no. 3 UWG, Art. 21 GDPR); an email to the address given in our Impressum is sufficient, and no costs arise beyond basic transmission rates. So that such an objection takes effect permanently and for any future bookings as well, we store your email address in a suppression list solely as a hash value — the address itself is not kept there in plain text.

Depending on the region selected for the account, the Sinch group processes data in the European Union or in the United States; a transfer to the US can therefore not be excluded. It takes place on the basis of the EU Standard Contractual Clauses (Implementing Decision 2021/914/EU, Art. 46 GDPR) and, where the US company involved is certified, the EU-US Data Privacy Framework. The data processing agreement is available at https://sinch.com/legal/terms-and-conditions/other-sinch-terms-conditions/data-protection-agreement/ and Mailjet's privacy policy at https://www.mailjet.com/legal/privacy-policy/. The Sinch group's data protection officer can be reached at dpo@sinch.com.

21. Managing a listing (owner sign-in)

Owners (and staff with an email address on the company's domain) can maintain their company listing under “Manage your listing”. Sign-in is passwordless via a one-time code sent to the address you enter (sections 16 and 20); authorization derives from your address's domain matching the website or email domain stored on the listing — common freemail domains (such as gmail.com or gmx.de) do not confer it. After sign-in, the strictly necessary session cookie described in section 11 is set (§ 25 (2) no. 2 TDDDG); it holds your email address and its validity period in cryptographically signed form. If you claim a listing, we store the association of company, the email address signed in at that moment and the time of the claim; the listing then publicly shows an “Owner-managed” notice and third-party change proposals are locked. Your email address itself is not shown publicly. Legal bases are Art. 6 (1)(b) GDPR (providing the management function you requested) and Art. 6 (1)(f) GDPR (legitimate interest in the accuracy and integrity of the directory data). We store the claim data for as long as the claim stands; on request we revoke it — contact the address given in the legal notice. Proposed changes continue to be editorially reviewed (section 9).

Last updated

This privacy policy was last updated in August 2026.