Skip to content
Services
  • Custom softwareDigital solutions that fit your workflows exactly — from the first idea to a production system.
  • AI applicationsAI that takes load off the everyday: securely integrated, measurably effective and aligned to real business processes.
  • SaaS solutionsProven platforms for core business processes — scalable, maintainable and in production for years.
All services at a glance
ApproachSolutionsAboutContactBlog
  • DEDeutsch
  • ENEnglish
Book an intro callBook a call
01Services
Custom softwareAI applicationsSaaS solutions
02Approach03Solutions04About05Contact06Blog
EN/DEBook an intro call

Privacy policy

Last updated: August 2026

1. Controller

The controller within the meaning of the GDPR is:

t-next GmbH
Heidenkampsweg 58, 20097 Hamburg, Germany
Email: info@t-next.de
Phone: +49 40 / 6077 6172

2. Principle & overview of processing

Protecting your personal data matters to us. We process data solely on the basis of the applicable law (GDPR, BDSG, TDDDG). This website is a largely static company presentation designed around data minimisation. We essentially process:

  • Usage and meta data (e.g. IP address, time, page requested) when the site is accessed,
  • Contact data (e.g. name, email, phone number) when you contact us,
  • Statistics data for web analytics — only after your consent.

3. Legal bases

  • Art. 6(1)(a) GDPR (consent) — e.g. for web analytics,
  • Art. 6(1)(b) GDPR (contract / pre-contract) — e.g. for a project enquiry,
  • Art. 6(1)(f) GDPR (legitimate interest) — e.g. for secure, stable operation,
  • for storing or reading information on your device, additionally § 25 TDDDG.

4. Hosting & server logs (Amazon Web Services)

This website is hosted with Amazon Web Services. The provider is Amazon Web Services EMEA SARL with its registered address at 38 Avenue John F. Kennedy, L-1855 Luxemburg (“AWS”). Content is delivered via the Amazon CloudFront content delivery network and the Amazon S3 storage service; the origin server location is Frankfurt am Main (Region eu-central-1).

When the site is accessed, AWS processes technically necessary access data on our behalf (including IP address, date and time, requested URL, volume of data transferred, referrer, and browser/operating system identifiers). The purpose is the secure, stable and performant delivery of the website. The legal basis is our legitimate interest in a reliable web presence (Art. 6(1)(f) GDPR). Where access data is logged, we keep it only for as long as necessary to deliver the site, analyse security or investigate a specific fault. It is then deleted or anonymised; a security incident may require longer storage until the incident has been conclusively resolved.

A data processing agreement under Art. 28 GDPR is in place with AWS. Where data may be transferred to the parent company Amazon.com, Inc. in the USA, it is certified under the EU-US Data Privacy Framework; the EU Commission’s standard contractual clauses apply in addition.

5. SSL/TLS encryption

For security reasons this website uses TLS encryption. You can recognise an encrypted connection by “https://” in the address bar and the padlock symbol in your browser.

6. Fonts

Web fonts are served locally from our own server. There is no connection to third-party servers (e.g. Google Fonts); no data is transferred to third parties for this purpose when the page is loaded.

7. Cookies, local storage & consent

No analytics cookies are set before consent. The website uses your browser's local storage for necessary settings. This is required to retain a display option requested by you or your privacy choice (§ 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR). Google Analytics cookies are set only after your explicit consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR).

NameTechnologyPurposeRetention
themeLocal storageStores the light or dark appearance selected by you.Until you change the choice or delete local site data.
tn-consentLocal storageRecords your choice for necessary settings and statistics.Up to 6 months.
_ga, _ga_<ID>CookiesPseudonymous recognition for Google Analytics 4.Up to 2 years; only after consent.

You can change or withdraw your choice at any time with effect for the future. On withdrawal, the Google Analytics cookies accessible to this website are deleted and further measurement stops:

8. Web analytics with Google Analytics 4

If you consent, we use Google Analytics 4 (“GA4”), a web analytics service provided byGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Its purpose is pseudonymous audience and usage analysis so that we can improve content, navigation and contact paths. Data processed may include the page address and title, referrer, time and session details, approximate region, browser, operating system, device type and interactions. Interactions collected by us include, for example, starting and completing the AI self-check, its broad result category, and clicks on booking or contact options. We do not knowingly transmit names, email addresses, form contents or individual self-check answers to GA4.

After consent, GA4 sets the cookies listed above and assigns usage events to a pseudonymous identifier. Google states that IP addresses from EU traffic are discarded before logging or storage; approximate location information may first be derived from the IP address. This does not make the entire processing anonymous. Advertising features, Google Signals and personalised advertising are disabled in our implementation. Before your consent, the Google library is not loaded and no analytics events are sent to Google (Basic Consent Mode).

GA4 cookies are retained for up to 2 years. User and event data in a standard GA4 property is automatically deleted within the available retention period of no more than 14 months; purely aggregated reports without a direct personal reference may remain available for longer. The legal basis is solely your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

Google may also process data in the USA. Google LLC is certified under the EU-US Data Privacy Framework; the EU Commission's Standard Contractual Clauses may apply in addition. Google's data processing terms for advertising products apply. For further information, see theGoogle Privacy Policy andGA4 data-retention information. You may withdraw consent at any time through the cookie settings.

9. Contacting us

If you contact us by email, phone or one of the contact paths offered on the website, we process your details to handle the enquiry and any follow-up questions. The contact form requires your name, email address and message; company is optional. We cannot respond without the required details. An email address is required if you request a checklist.

If your contact is aimed at entering into a contract, the legal basis is Art. 6(1)(b) GDPR; general business communication and the organisation of our processes rely on Art. 6(1)(f) GDPR. Access is limited to responsible staff and the processors used for email and collaboration. Data is disclosed to further recipients only where required to handle the enquiry, initiated by you, or required by law. If no contract is concluded, enquiry data is normally deleted no later than 12 months after the last substantive contact. Contractual relationships and business correspondence subject to retention duties are kept for the applicable statutory periods.

At present, the contact form and checklist request only open a pre-filled draft in your local email application; no form data is transmitted to a form server through the website. Only when you send the message does your email provider process the included data and deliver it to our mailbox.

Our business email is processed in Microsoft 365 / Exchange Online. The provider isMicrosoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft processes the data under our data-processing agreement and the Microsoft Data Protection Addendum.

10. Appointment booking (Microsoft Bookings)

To arrange intro calls, we link to Microsoft Bookings, a service provided by Microsoft Ireland Operations Limited as part of Microsoft 365. You leave our website and connect to Microsoft only after clicking the link. On the external booking page, Microsoft and we may process the details you provide (name, business email address, an optional note on your project, and the selected time) in order to arrange, confirm and hold the appointment; for calls via Microsoft Teams a meeting link is generated automatically. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract). The data is stored in our Microsoft 365 / Exchange Online tenant; Microsoft processes it as a processor (Art. 28 GDPR) under the Microsoft Data Protection Addendum. Any transfers to the USA are safeguarded by the EU-US Data Privacy Framework and supplementary standard contractual clauses. On the booking page, Microsoft may also process technical connection, device and session data for its own necessary purposes under its terms. We normally delete appointment data no later than 12 months after the appointment unless it becomes part of a further business relationship or must be retained by law. For more information, see theMicrosoft Privacy Statement.

11. External links

This website contains links to external services, in particular Microsoft Bookings and LinkedIn. Merely viewing our page does not create a connection to the relevant provider through these links. Only after clicking may the provider process information such as IP address, time, destination page and device details. The relevant provider is responsible for further processing on the destination page under its privacy information.

12. Recipients & third-country transfers

Depending on your use, recipients and processors are Amazon Web Services (hosting/CDN),Microsoft (email, Microsoft 365, appointment booking) and, only after consent,Google (web analytics). Where a provider processes data outside our instructions for its own purposes, its privacy information applies in addition. Further recipients receive data only where required to perform a contract, initiated by you, or required by law. Possible transfers to the USA rely on the EU-US Data Privacy Framework for certified organisations and, in addition, Standard Contractual Clauses.

13. Your rights

You have the right at any time to:

  • access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17),
  • restriction of processing (Art. 18) and data portability (Art. 20),
  • object to processing based on legitimate interests (Art. 21),
  • withdraw a consent given, with effect for the future (Art. 7(3)).

An informal message to info@t-next.de is sufficient to exercise these rights. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany
datenschutz-hamburg.de

14. AI self-check & no automated decision-making

The AI self-check initially processes your answers only locally in your browser and uses fixed rules to provide non-binding technical orientation. It does not make a decision with legal or similarly significant effects and does not replace legal advice or a conclusive legal classification. Only if you request a checklist by email is a summary of your answers inserted into the email draft. No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.

15. Changes

We update this privacy policy whenever changes in the law or in our services require it. The version published here applies at any given time.

Software built to fit.Accelerated by AI.Owned in Hamburg.EU operation on request.

soon
Address

t-next GmbH
Heidenkampsweg 58
20097 Hamburg

Contact

info@t-next.de
+49 40 / 6077 6172

Navigation
  • Services
  • Approach
  • Solutions
  • About
  • Contact
AI made inGermanyPrivacyby designEU hostingon request
© 2026 t-next GmbH
Case studiesBlogLegal noticePrivacy policy