Legal

Privacy policy

How we handle your data on this website – explained clearly and in line with what the website actually does technically.

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Fahrschule DEVAM
Fahrschule Devam GmbH
Ulmenstr. 2
90443 Nürnberg

Phone: 0176 41693949
Email: [email protected]

You will find further information in our legal notice.

2. Hosting and server log files

When you open a page, your browser automatically transmits technical information to our web server. This includes in particular:

  • IP address
  • Date and time of access
  • page or file requested
  • HTTP status code and amount of data transferred
  • previously visited page (referrer), if your browser transmits it
  • browser type, browser version and operating system

This data is technically necessary to deliver the website to you. Depending on the server configuration, it is stored in log files so that errors can be detected and attacks averted. It is not combined with other data sources or analysed for advertising purposes.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing the website securely, stably and without errors.

Date, time and weather: The line showing the date, the time and the current weather in Nuremberg is displayed in your browser. Our server retrieves the weather data from the German Meteorological Service (Deutscher Wetterdienst, DWD, open data service, Nuremberg weather station) and caches it briefly. No data about you is transmitted to the German Meteorological Service in the process.

3. Cookies and storage in your browser

Under § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG), information may generally only be stored on or read from your device with your consent – unless this is strictly necessary for a service you have expressly requested.

Public pages: We store language, appearance and your consent decision locally in your browser as necessary settings. Statistics are off on the first visit, and the consent banner gives equal access to “Accept all”, “Necessary only” and “Settings”. A random session ID is created in sessionStorage for the current browser session only after your explicit statistics consent. You can withdraw consent at any time through “Cookie settings” in the footer; collection then stops immediately and the optional session ID is deleted.

Independently of this, your browser keeps files it has already loaded, such as images or the font, in its cache so that pages load faster. You can clear this cache at any time in your browser settings.

Admin area: Only people who log in to the driving school's protected admin area receive technically necessary cookies: a session cookie and a cookie that identifies the browser as a known device, so that attacks on the login can be slowed down without locking out authorised people. Visitors to the website are not affected.

We do not use tracking pixels or third-party analytics or marketing services. We perform no canvas, audio, font, WebGL or other device fingerprinting of our own. Cloudflare Turnstile is loaded only when form protection is enabled and fully configured on the server; details are in section 11.

Our own consent-based visitor statistics: After your consent, our own server records visit time and the internal page viewed, website and browser language, approximate country and city (only where the server supplies a local or trusted GeoIP source), the referrer domain alone or a direct visit, only utm_source, utm_medium and utm_campaign, plus device class, browser family and operating-system family. External referrer paths and query strings are not stored. The full IP address and full user agent are not stored in the statistics database or sent to a geolocation service. A random session ID is processed server-side only as a day-bound HMAC and deleted by the next day at the latest. Only aggregated daily values remain. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).

“Open today” indicator: Whether we are currently open is calculated by your browser directly on the page, based on your device's time and the published opening hours. Nothing is stored and nothing is transmitted to us or third parties.

4. Contact form and handling of your enquiry

When you write to us using the contact or price request form, we process the details you enter there. Only the details without which we cannot assign and answer your enquiry are required:

  • Type of enquiry (for example price / cost request, general question or callback)
  • First and last name
  • Email address or phone number (at least one of them; for a callback, the phone number)
  • desired licence class or topic of the enquiry
  • Message – optional for price requests, registration enquiries and callbacks
  • Confirmation that you have read this privacy notice (with time stamp)

You can also optionally state when you would like to start your training and add a subject. We also store the language in which you used the website so that we can reply appropriately. The form does not involve any consent to advertising or a newsletter.

Purpose and legal basis: We use the details exclusively to handle your enquiry. If your enquiry concerns training with us, the legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). In all other cases we base the processing on Art. 6(1)(f) GDPR; our legitimate interest is answering enquiries addressed to us. The confirmation box merely documents that you have read this notice; it is not consent within the meaning of Art. 6(1)(a) GDPR.

Process: Your details are transmitted to our web server in encrypted form and stored there as a contact enquiry in a database outside the publicly accessible web directory. We also send a notification to the driving school's mailbox. If you gave an email address, you receive an automatic confirmation of receipt in the language in which you used the website – a pure confirmation, no advertising. If this confirmation cannot be sent, your enquiry is still stored.

Further handling in the admin area: Authorised staff of the driving school can see your enquiry in the internal admin area, record its status there (for example “new”, “contacted”, “appointment arranged”) and add internal notes and a consultation appointment. If your enquiry leads to training, we create a customer record for it. Access and changes are logged (see section 10).

Storage period: We delete your enquiry as soon as it has been dealt with conclusively, provided no statutory retention obligations apply. If your enquiry results in a training relationship, we keep the details for as long as is necessary to carry it out and to meet legal obligations.

To protect against spam, the form contains a field that is invisible to people and a short-lived technical check token; we also limit the number of enquiries (see Protection against misuse).

4a. Appointment notices and acceptance evidence

When we schedule an appointment for a customer, we process the appointment and contact data required to carry it out. This may include the customer number, date and time, meeting point, instructor, vehicle, registration plate, transmission and licence class. The customer receives a transactional email with a random, time-limited confirmation link and one appointment PDF containing German, Turkish, Russian, English and Arabic. The instructor receives only information needed for the appointment; confidential internal notes are not sent.

The confirmation link provides the appointment details, the version of the cancellation terms applicable to that appointment and the associated PDF. Acceptance is recorded only after an explicit choice. As evidence, we store in particular the appointment reference and snapshot, version and text of the terms, document identifier and version, the PDF's SHA-256 digest, language and time. Privacy-preserving one-way request hashes may be stored to prevent abuse. The link itself is stored only as a hash and may expire or be revoked.

An appointment cannot be cancelled or changed through the confirmation link; notice may be given by telephone or in text form, especially by email, as described in the cancellation terms. An attempt to cancel through the link is only recorded. The legal basis for appointment handling, notices and evidence is Article 6(1)(b) GDPR insofar as this is necessary to prepare or perform the training relationship; security records additionally rely on Article 6(1)(f) GDPR. Evidence is protected against later alteration and retained only as long as necessary for contract handling, establishing or defending claims and statutory obligations.

5. Contact by email, phone or WhatsApp

If you contact us by email or phone, we process the data you give us (for example name, phone number, email address and the content of your message) in order to deal with your request. The legal basis is Art. 6(1)(b) GDPR where training is concerned, otherwise Art. 6(1)(f) GDPR (answering enquiries). The storage period is the same as for the contact form.

Email correspondence: Our web server fetches emails sent to our mailbox from the email provider over an encrypted connection and stores them – together with our replies – in the protected administration area, separately from the other data. We link an email to your enquiry or customer record if the sender address matches; otherwise it remains unlinked. A new email may be followed by an automatic confirmation of receipt (not for automatically generated messages and at most once within a waiting period). External images contained in emails are not loaded automatically. We do not send newsletters or advertising emails; email communication serves solely to handle your request or your training. The legal basis is Art. 6(1)(b) GDPR where training is concerned, otherwise Art. 6(1)(f) GDPR.

WhatsApp: No WhatsApp function is embedded in our website; there are only links to WhatsApp. Only when you click such a link does WhatsApp or the WhatsApp (Meta) website open, and WhatsApp's privacy terms apply. If you write to us via WhatsApp, WhatsApp also processes your data under its own responsibility, possibly also outside the EU. If you do not want this, you can reach us by phone, by email, via the contact form or in person at the driving school.

6. Google reviews

On the home page we can display reviews from our Google Business Profile. If this function has not been set up, you will only see a link to Google there.

  • Retrieval via our server: Our web server retrieves the reviews via the Google Places API when you open that section. In doing so, our server only transmits a technical access key, the ID of our Google listing and the language of the page you are viewing to Google – no data about you. Your browser does not connect to Google for this; the authors' profile pictures are also loaded via our server.
  • No permanent storage: The content of the reviews is not stored on our server. We only store an identifier (hash value) of reviews that have been hidden in the admin area.
  • Authors' data: We display the name, profile picture, star rating, text and time information that the authors have published themselves on Google (source: Google). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to make other learner drivers' experiences available to interested people. If an author edits or deletes their review on Google, it is updated here accordingly or no longer shown.
  • Links to Google: If you click on a name, on “View on Google Maps” or on “All reviews”, Google opens in a new tab. Google's privacy terms apply there.

Authenticity of the reviews: We display the reviews as Google provides them via its interface (a maximum of five, selected by Google). We do not check whether the authors actually trained with us. Individual reviews can be hidden on this website in the admin area.

7. Map preview and route planning

The map on the contact page is an image stored on our server (map data © OpenStreetMap contributors). No connection to a map service is established when it is displayed.

You can open Google Maps in a new tab via “Route in Google Maps” or our linked address. Only then is data – in particular your IP address – transmitted to Google, and Google's privacy terms apply.

8. Links to Instagram and TikTok

We do not embed any content, plug-ins or tracking pixels of social networks. “Instagram” and “TikTok” are simple links on our website. Only when you click them does the respective platform open, and its privacy terms apply.

9. Fonts, icons and images

The font used (Archivo), the icons and all images are loaded from our own server. No data is transmitted to external providers such as Google Fonts or content delivery networks.

10. Internal admin area

The admin area of this website is not public and can only be accessed after logging in. It is used exclusively by the driving school to maintain the website and to handle enquiries, customer data and appointments.

  • User accounts: For each authorised person we store a user name, display name, role, permissions and a password hash, and – if two-factor login is enabled – an encrypted key for the authenticator app. Passwords are never stored in plain text.
  • Log: Logins, changes to content and business data, and changes to enquiries, customer data and appointments are logged with the time, the person acting and the record concerned. The log serves traceability and IT security (Art. 6(1)(f) GDPR, supplemented by § 26 BDSG in the employment context). Passwords, PINs and session IDs are not logged; the IP address is only stored as a hash value.
  • Deletion approval: Important records can only be deleted permanently after approval by an authorised person and entry of an approval PIN. Until then, deleted records are only visible in the recycle bin.

11. Protection against misuse

To protect the contact form and the admin area against automated attacks and spam, we limit the number of requests per sender. For this purpose we store on the web server, for a maximum of 24 hours, a hash value calculated from your IP address and a secret key, which does not contain the IP address in plain text, together with the times of the requests. Failed login and confirmation attempts in the admin area are counted for a maximum of 48 hours. If identical enquiries are sent several times within a few minutes, we store them only once. In addition, the form only accepts requests that originate from this website itself.

Cloudflare Turnstile: If the service is enabled for a form, we load the security check only when that form is opened or used, from Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. According to Cloudflare's documentation, the service processes in particular the IP address, TLS fingerprint, user-agent, sitekey and origin as well as technical browser signals to distinguish people from automated access. Form contents are not sent to Cloudflare. Our server validates the short-lived token produced by Turnstile through the Siteverify interface; invalid, expired or previously used tokens are rejected.

The legal bases are section 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. Our legitimate interest is protecting forms and accounts against bots, spam and automated attacks. Cloudflare provides a Data Processing Addendum including the EU Standard Contractual Clauses for processing on behalf of customers. Further information: Turnstile Privacy Addendum (opens in a new tab) and Cloudflare Data Processing Addendum (opens in a new tab).

Security log: Requests that clearly indicate an attack or automated probing – for example attempts to retrieve protected files or administration addresses that do not exist – are kept in a separate security log. It stores the IP address (for IPv6 the network range), the time, the requested address, the browser identification and technical characteristics of the request, but no form contents, passwords or cookies. After repeated attempts an address may be blocked automatically for a limited time (24 hours at most, never permanently). Ordinary page views are not recorded there.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the security and proper functioning of the website.

12. Recipients and service providers

Google does not receive any data about you in connection with displaying the reviews (see section 6).

13. Transfers to third countries

If Cloudflare Turnstile is enabled, technical security data may be transferred to Cloudflare in the USA and to its subprocessors. For such transfers, Cloudflare's Data Processing Addendum provides in particular for the EU Standard Contractual Clauses.

If you click on links to WhatsApp, Google, Instagram or TikTok, these providers may process data under their own responsibility, including outside the EU.

14. Storage periods at a glance

There is no automated decision-making, including profiling (Art. 22 GDPR).

15. Your rights

Under the GDPR you have the following rights with regard to us:

  • Access to the data we process (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to the processing (Art. 21 GDPR, see next section)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR). This concerns the consent-based visitor statistics: you can withdraw your consent at any time via “Cookie settings” in the footer.

Simply contact us by email at [email protected] or via the contact details given above.

16. Right to object

17. Complaint to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. The competent authority for companies in Bavaria is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Postfach 1349
91504 Ansbach
www.lda.bayern.de (opens in a new tab)

18. Currency of this privacy policy

Last updated: September 2026. We adapt this privacy policy when the website, the services used or the legal requirements change.