Last updated: August 2026
Protecting your personal data is important to us. The following Privacy Policy explains which personal data is processed when you use our website, the purposes for which it is processed, the legal bases on which the processing is carried out and the rights you have as a data subject.
Personal data is processed in particular in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG) and the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG).
1. Controller
The controller responsible for data processing on this website is:
Tirum Consulting GmbH
Düsseldorfer Str. 73
40878 Ratingen
Germany
Phone: +49 30 233272790
Email: info@tirum.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
2. General Principles of Data Processing
We process personal data only to the extent necessary to provide and securely operate our website, handle inquiries, perform pre-contractual or contractual measures, comply with legal obligations or on the basis of consent you have provided.
Depending on the processing activity, the following legal bases in particular may apply:
- Article 6(1)(a) GDPR – consent,
- Article 6(1)(b) GDPR – contract or pre-contractual measures,
- Article 6(1)(c) GDPR – legal obligation,
- Article 6(1)(f) GDPR – legitimate interests.
3. Hosting
Our website is hosted by GoDaddy. The provider is in particular GoDaddy.com, LLC, USA.
As part of the hosting services, data required to provide, operate and secure the website may be processed. This may include in particular:
- IP address,
- date and time of access,
- URL accessed,
- referrer URL,
- browser type and browser version,
- operating system,
- hostname of the accessing device,
- amount of data transferred,
- HTTP status codes.
The data is processed for the technical provision of the website, troubleshooting and the prevention and detection of attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and economically efficient operation of our website.
Where GoDaddy processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement pursuant to Article 28 GDPR.
Data may also be processed outside the European Economic Area. Where required, such transfers are based on appropriate safeguards pursuant to Articles 44 et seq. GDPR, in particular the European Commission’s Standard Contractual Clauses or an applicable adequacy decision.
4. Server Log Files
When you access our website, technical information is automatically recorded in server log files.
This data is required in particular to:
- technically provide the website,
- identify and analyse errors,
- identify unauthorised access and attacks,
- ensure the security and functionality of the website.
We do not combine this data with other data sources for the purpose of creating personal usage profiles.
The legal basis is Article 6(1)(f) GDPR.
Server log data is retained only for as long as necessary for technical operation, troubleshooting and IT security. In the event of a security-related incident, data may be retained until the respective incident has been fully investigated.
5. SSL/TLS Encryption
Our website uses SSL/TLS encryption.
This means that data you transmit to us is generally transmitted in encrypted form between your browser and our web server.
An encrypted connection can be identified in particular by “https://” in your browser’s address bar.
6. Cookies and Technically Necessary Storage Access
Our website only uses cookies or comparable storage mechanisms where these are required for the technical operation of the website or for functions expressly requested by you.
This may include, for example, technically necessary information relating to your language selection.
Where information is stored on your terminal device or information already stored there is accessed, this is carried out – where the relevant requirements are met – on the basis of Section 25(2) TDDDG.
Where the information processed in this context constitutes personal data, the processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the technically functional and user-friendly provision of our website.
We currently do not use cookies for advertising, marketing or web analytics purposes.
Should non-essential cookies or comparable technologies be used in the future, they will only be used after prior consent where required by law.
7. Contacting Us
If you contact us by email, telephone or through our website, we process the personal data you provide for the purpose of handling your request.
This may include in particular:
- name,
- company,
- role or position,
- email address,
- telephone number,
- content of your message,
- any other information you provide.
Where your inquiry relates to the conclusion or performance of a contract, the processing is based on Article 6(1)(b) GDPR.
For other inquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the proper handling of business and other inquiries.
Where you have expressly consented to a particular processing activity, Article 6(1)(a) GDPR is the legal basis.
8. Contact, Whitepaper and Application Forms – Fluent Forms
We use the WordPress plugin Fluent Forms to provide forms on our website.
Depending on the form, the following data may be processed in particular:
- first and last name,
- company,
- role or position,
- email address,
- telephone number,
- message,
- uploaded documents,
- IP address,
- date and time of submission,
- technical information relating to the form submission.
The data is processed solely for the purpose associated with the respective form.
For general contact inquiries, Article 6(1)(b) or Article 6(1)(f) GDPR applies depending on the nature of the inquiry.
For applications, the legal bases stated in the “Applications” section apply.
Where voluntary consent is obtained, processing is based on Article 6(1)(a) GDPR.
9. Whitepaper Downloads
We provide professional information and whitepapers for download through our website.
To provide the download link, the following personal data may be collected in particular:
- first and last name,
- company,
- email address,
- role or position within the company, where applicable.
After submitting the form, the download link may be provided by email.
The data is processed to provide the content expressly requested by you on the basis of Article 6(1)(b) GDPR.
Any further promotional or professional contact will only take place where an appropriate legal basis exists. Where you have expressly consented to further contact, such processing is based on Article 6(1)(a) GDPR.
Consent may be withdrawn at any time with effect for the future.
10. Applications
You may apply to us through our website or by email.
As part of a recruitment process, the following data may be processed in particular:
- name and contact details,
- curriculum vitae,
- cover letter,
- references and certificates,
- proof of qualifications,
- information concerning education and professional experience,
- other information voluntarily provided by you.
The data is processed for the purpose of deciding whether to establish an employment relationship.
The legal basis is in particular Section 26(1) of the German Federal Data Protection Act (BDSG).
Where special categories of personal data within the meaning of Article 9 GDPR are processed, such processing will only take place subject to the applicable statutory requirements.
If no employment relationship is established, application data will generally be deleted no later than six months after completion of the recruitment process, unless legal reasons require longer storage.
Longer storage, for example for inclusion in an applicant pool, will only take place on the basis of appropriate consent. Such consent may be withdrawn at any time with effect for the future.
11. Microsoft 365 and Exchange Online
We use Microsoft 365 and Exchange Online for our business email communications and for sending form information and whitepaper links.
The service provider for European corporate customers is in particular:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland
The following data may be processed in particular:
- name,
- email address,
- subject,
- message content,
- attachments,
- technical delivery and transmission information.
Depending on the purpose of the communication, processing is based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
Where communication is based on consent, Article 6(1)(a) GDPR applies.
Microsoft processes data as a processor in connection with Microsoft Online Services on the basis of corresponding data protection agreements.
For certain processing activities, data may also be processed outside the European Economic Area. Microsoft uses, in particular, the European Commission’s Standard Contractual Clauses and additional contractual and technical safeguards for such transfers.
Microsoft Corporation is also certified under the EU-U.S. Data Privacy Framework.
12. FluentSMTP
We use the FluentSMTP plugin to technically connect our WordPress website to Microsoft 365.
FluentSMTP is used to send emails generated by the website through the Microsoft 365 account configured by us.
The information required for the respective email delivery may be processed, including in particular:
- sender and recipient addresses,
- subject,
- message content,
- delivery status,
- technical log information.
The legal basis depends on the purpose of the respective communication and corresponds to the legal bases stated under “Contacting Us”, “Whitepaper Downloads” or “Applications”.
13. Wordfence – Website Security
We use Wordfence to protect our website against unauthorised access, malware, brute-force attacks and other cyberattacks.
The provider is:
Defiant, Inc.
1700 Westlake Ave N, Suite 200
Seattle, WA 98109
USA
As part of security checks, the following data may be processed in particular:
- IP addresses and, where applicable, proxy IP addresses,
- browser and device information,
- HTTP requests and HTTP headers,
- URLs accessed,
- date and time of access,
- security-related events,
- for logged-in users, potentially usernames and email addresses,
- information concerning detected malicious or attempted attacks.
The processing serves to detect and prevent attacks and to ensure the availability, confidentiality and integrity of our website.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is ensuring IT and information security.
Where Defiant processes personal data on our behalf, such processing is carried out on the basis of an agreement pursuant to Article 28 GDPR.
Processing in the United States is possible. For relevant international transfers, the provider uses in particular the European Commission’s Standard Contractual Clauses and additional appropriate safeguards.
Security data is retained only for as long as necessary to detect, analyse and prevent attacks and to document security-related incidents.
14. Locally Hosted Fonts
Our website uses fonts that are hosted locally on our own web server.
The required font files are loaded from our own server when you visit our website.
No connection to Google Fonts servers is established and your IP address is not transmitted to Google solely for the purpose of displaying the fonts used on our website.
15. OpenStreetMap
We may use map material based on OpenStreetMap to display location or map information.
The integration is designed in such a way that external OpenStreetMap services are not automatically loaded merely by accessing the relevant webpage.
Only when you actively use the relevant map function may technically necessary information be transmitted to the respective map service. This may include in particular:
- IP address,
- browser and device information,
- date and time,
- requested map content.
Where personal data is processed in this context, the processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the user-friendly provision of location information.
Where external OpenStreetMap services are used, their own privacy policies may apply.
16. Multilingual Website – Polylang
We use Polylang to provide our website in several languages.
Polylang may store technically necessary information in order to provide or remember the language selected by you.
We do not use this information for advertising or profiling purposes.
Where information is stored on or accessed from your terminal device, this is carried out – where the relevant requirements are met – on the basis of Section 25(2) TDDDG.
Where personal data is processed, the legal basis is Article 6(1)(f) GDPR.
17. Local Display Functions and WordPress Plugins
We use various WordPress extensions for displaying and operating content on our website, including functions for sliders, interactive graphics and the presentation of team members.
These include, for example, Smart Slider 3, Draw Attention and Team Members.
We use these functions in such a way that merely displaying the relevant content does not result in personal data of website visitors being transmitted to the respective plugin provider.
Where personal data is generated as part of local technical processing, the processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the functional and user-friendly presentation of our website.
18. LinkedIn
Our website contains links to our company profile and content on LinkedIn.
These are generally normal external links. Merely visiting our website through such a page does not result in personal data being transmitted to LinkedIn by the link itself.
A connection to the LinkedIn platform is only established when you click on a LinkedIn link.
For users in the European Economic Area, LinkedIn is operated in particular by:
LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland
Once you access LinkedIn, the further processing of your personal data is governed by LinkedIn’s privacy policy.
We currently do not use LinkedIn tracking or analytics technologies such as the LinkedIn Insight Tag on our website.
19. No Web Analytics or Tracking
We currently do not use services such as Google Analytics, Matomo or comparable web analytics or tracking systems on this website for the creation of personal or pseudonymous usage profiles.
We also currently do not use advertising tracking pixels or comparable technologies for behavioural advertising.
20. No Newsletter
We currently do not operate a regular email newsletter through our website.
Where you expressly consent to further contact in connection with a whitepaper or an individual inquiry, such contact will only take place within the scope of the consent provided.
21. Recipients of Personal Data
In connection with the processing activities described above, personal data may in particular be disclosed to the following recipients or categories of recipients:
- hosting and IT service providers,
- Microsoft as provider of our communication and cloud services,
- security service providers such as Defiant/Wordfence,
- other processors engaged by us,
- authorities or other bodies where we are legally required to disclose the data.
Personal data will only be disclosed for other purposes where an appropriate legal basis exists.
22. Transfers to Third Countries
Some of the service providers we use are based or operate technical infrastructure outside the European Economic Area.
Where personal data is transferred to a third country, such transfer is carried out exclusively in compliance with Articles 44 et seq. GDPR.
Depending on the service provider, we rely in particular on:
- adequacy decisions of the European Commission pursuant to Article 45 GDPR,
- Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR,
- additional technical and organisational safeguards.
Where a provider is certified under the EU-U.S. Data Privacy Framework and the relevant requirements are met, the corresponding adequacy decision may also serve as a legal basis for the transfer.
23. Storage Period
We generally retain personal data only for as long as necessary for the respective purpose or for as long as statutory retention obligations apply.
The following principles apply in particular:
- contact inquiries: until the inquiry has been fully processed; business-relevant communications may be retained for longer where statutory retention obligations apply,
- whitepaper requests: until the requested content has been fully provided; where additional consent has been given, until consent is withdrawn or the respective purpose no longer applies,
- applications: generally for a maximum of six months after completion of the recruitment process where no employment relationship is established,
- server and security data: for as long as necessary for technical operation, troubleshooting and IT security,
- contractual and business documents: in accordance with applicable statutory commercial and tax retention periods.
Once the processing purpose no longer applies and any applicable statutory retention periods have expired, personal data will be deleted or anonymised.
24. Your Rights
Subject to the applicable statutory requirements, you have the following rights in particular:
- right of access pursuant to Article 15 GDPR,
- right to rectification pursuant to Article 16 GDPR,
- right to erasure pursuant to Article 17 GDPR,
- right to restriction of processing pursuant to Article 18 GDPR,
- right to data portability pursuant to Article 20 GDPR,
- right to object pursuant to Article 21 GDPR,
- right to withdraw consent pursuant to Article 7(3) GDPR,
- right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent prior to its withdrawal.
To exercise your rights, you may contact:
Tirum Consulting GmbH
Email: info@tirum.de
25. Right to Object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right pursuant to Article 21 GDPR to object to such processing at any time on grounds relating to your particular situation.
Where personal data is processed for direct marketing purposes, you have the right at any time to object to the processing of your personal data for such marketing.
26. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority concerning the processing of your personal data.
The supervisory authority responsible for our registered office is in particular:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
You may generally also contact another supervisory authority competent pursuant to Article 77 GDPR.
27. Automated Decision-Making and Profiling
No decision based solely on automated processing, including profiling, within the meaning of Article 22 GDPR takes place in connection with this website.
28. Amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy where necessary due to changes in legislation, case law or our technical or organisational processes.
The current version published on this website applies.
Last updated: August 2026
