Last updated: July 2026
Thank you for visiting our website and for your interest in the services provided by Tirum Consulting GmbH. Protecting your personal data is of great importance to us. We process your personal data exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR) and the applicable national data protection laws.
This Privacy Policy explains which personal data is collected when you visit our website, the purposes for which it is processed, and the rights you have as a data subject.
1. Controller
Tirum Consulting GmbH
Düsseldorfer Straße 73
40878 Ratingen
Germany
Email: website@tirum.de
2. Definitions
This Privacy Policy uses the terminology of the General Data Protection Regulation (GDPR). This includes in particular:
- personal data
- data subject
- processing
- controller
- processor
- consent
The definitions set out in Article 4 GDPR apply.
3. General Information on Data Processing
As a general rule, we process personal data only to the extent necessary:
- to provide our website,
- to process your inquiries,
- to carry out pre-contractual measures,
- to comply with legal obligations, or
- on the basis of your consent.
Depending on the specific processing activity, the legal basis is:
- Article 6(1)(a) GDPR (consent),
- Article 6(1)(b) GDPR (contract or pre-contractual measures),
- Article 6(1)(c) GDPR (legal obligation), or
- Article 6(1)(f) GDPR (legitimate interests).
4. Hosting
Our website is hosted by an external hosting service provider.
As part of the hosting services, all data required for the operation of the website is processed. This includes in particular:
- IP address
- date and time of access
- browser type and browser version
- operating system
- referrer URL
- pages accessed
- amount of data transferred
- status codes
The data is processed for the purpose of technically providing the website and ensuring its stability and security.
The legal basis is Article 6(1)(f) GDPR.
5. Server Log Files
When you access our website, information is automatically stored in server log files.
This includes in particular:
- IP address
- browser information
- operating system
- date and time
- requested URL
- referrer
- hostname of the accessing device
This data is used exclusively to ensure the trouble-free operation of the website and to improve our services.
This data is not combined with data from other sources.
The legal basis is Article 6(1)(f) GDPR.
6. SSL/TLS Encryption
For security reasons, this website uses SSL/TLS encryption.
This ensures that all data is transmitted in encrypted form between your browser and our web server.
You can recognize an encrypted connection by the “https://” address in your browser’s address bar and by the padlock symbol.
7. Cookies
Our website uses technically necessary cookies where these are required for the operation of the website.
Should optional cookies be used in the future, for example for convenience functions or external services, they will only be used on the basis of your consent through the consent management system in use.
An overview of the cookies used and their respective storage periods is provided through the consent management system.
8. Contact
When you contact us, for example by email or through a contact form, we process the personal data you provide solely for the purpose of handling your inquiry.
This includes in particular:
- name
- company
- email address
- telephone number, if provided
- content of your message
The legal basis is Article 6(1)(b) GDPR where your inquiry relates to the conclusion or performance of a contract. In all other cases, the processing is based on our legitimate interest in handling your inquiry in accordance with Article 6(1)(f) GDPR.
The data will be deleted once your inquiry has been fully processed, provided that no statutory retention obligations require continued storage.
9. Contact and Application Forms (Fluent Forms)
We use the WordPress plugin Fluent Forms on our website to provide contact, whitepaper, and application forms.
When you use a form, the data you enter is processed. This may include in particular:
- name
- company
- position
- email address
- telephone number
- message
- uploaded application documents
- IP address
- date and time of submission
The data is processed solely for the purpose of handling your inquiry, carrying out pre-contractual measures, or, in the case of an application, conducting the recruitment process.
The legal basis is Article 6(1)(b) GDPR and, where voluntary consent is provided, Article 6(1)(a) GDPR.
10. Whitepaper Downloads
We provide whitepapers for download through our website.
To provide the download link, we collect personal data such as:
- first and last name
- company
- email address
- position within the company, where applicable
Once the form has been successfully submitted, you will receive the download link by email.
Where you have expressly consented, we may contact you at a later date to request feedback on the whitepaper or to inform you about relevant professional content and consulting services.
Consent is voluntary and may be withdrawn at any time with effect for the future.
The legal basis is Article 6(1)(b) GDPR for providing the whitepaper and Article 6(1)(a) GDPR for any further contact.
11. Applications
You may apply for advertised positions through our website or by email.
As part of the recruitment process, we process in particular:
- contact details
- curriculum vitae
- cover letter
- references and certificates
- proof of qualifications
- other information provided voluntarily
The data is processed solely for the purpose of conducting the recruitment process.
The legal basis is Section 26 of the German Federal Data Protection Act (BDSG) and Article 6(1)(b) GDPR.
If your application is unsuccessful, your application documents will be deleted no later than six months after the recruitment process has been completed, unless statutory retention obligations require otherwise or you have expressly consented to a longer storage period.
12. Microsoft 365 and FluentSMTP
We use Microsoft 365 (Exchange Online) to send form notifications and whitepaper links.
The technical delivery is carried out using the WordPress plugin FluentSMTP.
The following data in particular may be processed:
- name
- email address
- subject
- message content
- technical delivery information
Microsoft processes data partly on servers located within the European Union. In individual cases, data may also be processed outside the European Economic Area.
Further information is available in Microsoft’s privacy policy.
The legal basis is Article 6(1)(b) GDPR.
13. Wordfence
We use the Wordfence security plugin to protect our website.
Wordfence is used in particular to detect and prevent cyberattacks and to ensure the integrity and availability of our website.
The following data may be processed:
- IP address
- browser information
- URLs accessed
- security events
- date and time of access
The processing is based on our legitimate interest in ensuring IT security in accordance with Article 6(1)(f) GDPR.
14. Google Fonts
Google Fonts are used on this website.
The fonts are currently loaded directly from servers operated by Google Ireland Limited. In particular, this results in your IP address being transmitted to Google.
The fonts are used to ensure a consistent and visually appealing presentation of our website.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR, provided that consent has been given through the consent management system in use.
15. OpenStreetMap
We use map material from OpenStreetMap to display the location of our company.
The integration is designed to be privacy-friendly. No personal data is automatically transmitted to OpenStreetMap through our website.
Technically necessary data may only be processed when you actively use the map function.
The legal basis is Article 6(1)(f) GDPR.
16. Polylang
We use the Polylang plugin to provide multilingual content.
Polylang stores only technically necessary information in order to remember the language selected by the visitor.
No personal profiles are created.
The legal basis is Article 6(1)(f) GDPR.
17. Draw Attention
We use the Draw Attention plugin for interactive graphics.
The plugin is used exclusively to display interactive content on our website.
To the best of our knowledge, Draw Attention does not independently process personal data.
The legal basis is Article 6(1)(f) GDPR.
18. Team Members
We use the Team Members plugin to present our employees and team members.
Only information provided by us is published.
The plugin does not carry out any automated processing of visitors’ personal data.
The legal basis is Article 6(1)(f) GDPR.
19. Smart Slider 3
We use Smart Slider 3 to display image and content sliders.
The plugin is used exclusively for the visual presentation of content.
No personal data is transmitted to the plugin provider.
The legal basis is Article 6(1)(f) GDPR.
20. LinkedIn
Our website contains links to our company profile on LinkedIn.
No personal data is initially transmitted to LinkedIn when you visit our website.
Only when you click on the relevant link will you leave our website and be redirected to the LinkedIn platform.
The relevant platform operator is solely responsible for the processing of personal data on LinkedIn.
21. Storage Period
We store personal data only for as long as is necessary for the respective processing purposes or for as long as statutory retention obligations apply.
The following storage periods apply in particular:
- contact inquiries: until the inquiry has been fully processed
- whitepaper requests: until the purpose of providing the whitepaper has been fulfilled; where additional consent has been given, until the consent is withdrawn or the purpose no longer applies
- applications: for a maximum of six months after completion of the recruitment process
- statutory retention obligations remain unaffected
Once the relevant retention periods have expired, the data will be deleted or anonymized.
22. Your Rights as a Data Subject
Under the General Data Protection Regulation, you have the following rights in particular:
- right of access pursuant to Article 15 GDPR
- right to rectification pursuant to Article 16 GDPR
- right to erasure pursuant to Article 17 GDPR
- right to restriction of processing pursuant to Article 18 GDPR
- right to data portability pursuant to Article 20 GDPR
- right to object pursuant to Article 21 GDPR
- right to withdraw consent with effect for the future
- right to lodge a complaint with a competent data protection supervisory authority
To exercise your rights, you may contact us at any time using the contact details provided above.
23. Transfers to Third Countries
Where personal data is transferred to countries outside the European Economic Area as part of individual services, such transfers will only take place in compliance with the requirements of Articles 44 et seq. GDPR.
Where necessary, appropriate safeguards are used, in particular the European Commission’s Standard Contractual Clauses or certification under the EU-US Data Privacy Framework.
Further information on the respective data transfers can be found in the privacy notices of the relevant service providers.
