CSR Tools

Privacy Policy

Privacy Policy of CSR Tools: how we process personal data, which third-party services we use and what rights you have under the GDPR.

Thank you for your interest in our website. Protecting your personal data is important to us. Below we inform you in detail about how we handle your data in accordance with the General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

1. Controller

The controller within the meaning of the GDPR is:

CSR Tools – Spahn Sustainability Services, Alexander Spahn, Hohenlinde 2, 73547 Lorch, Germany

Email: info@csr-tools.com

VAT ID: DE453631336

2. General information on data processing

As a rule, we only process our users' personal data to the extent necessary to provide a functioning website along with our content and services. Processing generally takes place only with the user's consent or where a legal basis permits it.

The main legal bases are:

  • Art. 6(1)(a) GDPR (consent), e.g. for statistics services and for loading external media & services;
  • Art. 6(1)(b) GDPR (contract / pre-contractual measures), e.g. for appointment bookings and enquiries;
  • Art. 6(1)(f) GDPR (legitimate interest), e.g. for the secure and stable operation of the website.

You may withdraw any consent given at any time with effect for the future. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.

3. Provision of the website and server log files

Each time our website is accessed, our system automatically collects data and information from the accessing device. The following data is recorded in so-called server log files:

  • the IP address of the requesting device,
  • the date and time of access,
  • the page or file requested,
  • the referrer URL (the previously visited page),
  • the browser type and operating system used.

This processing serves to deliver the website, ensure system security and stability, and analyse errors. The legal basis is Art. 6(1)(f) GDPR. Log files are deleted after a short period unless they are required to investigate security incidents.

4. Hosting (Hetzner)

Our website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany ("Hetzner"). The servers are located in data centres within the European Union. Hetzner processes the log data described above solely on our behalf and on the basis of a data processing agreement (Art. 28 GDPR). No personal data is transferred to a third country outside the EU/EEA as part of the hosting. The legal basis is Art. 6(1)(f) GDPR (reliable and secure provision of the website).

We use technically necessary cookies and comparable technologies (e.g. localStorage) as well as optional ones subject to your consent.

  • Necessary storage: Required to operate the website. This includes in particular storing your cookie choice in your browser's localStorage so that we can respect your decision. This storage contains no advertising or tracking identifiers.
  • Optional services: Statistics (Google Analytics) and external media & services (Crisp chat, YouTube, the Substack newsletter, Microsoft Bookings) are loaded only after your explicit consent.

On your first visit you are shown a cookie banner where you can accept or decline the optional services. You can change or withdraw your choice at any time via the "Cookie settings" link in the website footer. The legal basis for optional cookies is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG; for necessary storage it is Art. 6(1)(f) GDPR and Section 25(2) TDDDG.

6. Google Analytics 4

Subject to your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses cookies and similar technologies that enable an analysis of how the website is used (e.g. pages visited, time spent, approximate location, device used). The information generated is generally transmitted to and stored by Google.

The measurement ID of our property is G-ZV8KP6QHEE. IP addresses are truncated or processed only in anonymised form by Google Analytics 4. A transfer of data to Google LLC in the USA cannot be excluded; Google is certified under the EU-US Data Privacy Framework, and Standard Contractual Clauses (Art. 46 GDPR) are used in addition.

The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time via the cookie settings. For more information, see Google's Privacy Policy.

7. Crisp live chat

Subject to your consent, we use the live chat of Crisp IM SARL, 2 boulevard de Launay, 44100 Nantes, France ("Crisp"), so that we can answer your questions directly. When the chat is loaded, data such as your messages, browser and device information and a session identifier may be processed. Crisp processes this data within the EU.

The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG; for the communication itself, additionally Art. 6(1)(b) and (f) GDPR (handling your enquiry). Without consent, the chat is not loaded. For more information, see Crisp's Privacy Policy.

8. YouTube videos

On individual pages we embed videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We use the extended data protection mode ("youtube-nocookie"), under which, according to YouTube, no cookies for personalised advertising are set as long as you do not play the video. In addition, we load YouTube videos only after you have consented to external media & services. Only then is a connection to YouTube's servers established and data (including your IP address) may be transmitted.

The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. A transfer to the USA may occur; Google is certified under the EU-US Data Privacy Framework. For more information, see Google's Privacy Policy.

9. Newsletter (Substack)

We send our "CSRD Compass" newsletter via the Substack service of Substack Inc., 548 Market Street PMB 72296, San Francisco, CA 94104, USA ("Substack"). For this purpose we embed a Substack sign-up form on our website. This form is loaded only after you have consented to external media & services; only then is a connection to Substack established.

Signing up for the newsletter requires you to provide your email address. Sign-up and delivery take place via Substack, which may process technical data (e.g. IP address, time of sign-up) as well as information about the opening of and clicks within the newsletter. You can unsubscribe from the newsletter at any time using the unsubscribe link in every email.

The legal basis for sending the newsletter is your consent under Art. 6(1)(a) GDPR; for embedding the form, additionally Section 25(1) TDDDG. A transfer to the USA is based on Standard Contractual Clauses (Art. 46 GDPR). For more information, see Substack's Privacy Policy.

10. Appointment booking (Microsoft Bookings)

To arrange consulting and demo appointments, we embed a booking calendar from Microsoft Bookings (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland). The booking calendar is loaded only when you actively open or click it. When you make a booking, Microsoft processes the data you provide (e.g. name, email address, requested appointment) as well as technical connection data.

The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual measures) and your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG for loading the external content. A transfer to the USA may occur; Microsoft is certified under the EU-US Data Privacy Framework. For more information, see Microsoft's Privacy Statement.

11. Contact by email

If you contact us by email, we process the data you provide (e.g. name, email address, content of the message) in order to handle your request. The legal basis is Art. 6(1)(b) GDPR where your request relates to the initiation or performance of a contract, otherwise Art. 6(1)(f) GDPR (responding to enquiries). The data is deleted once it is no longer required to achieve the purpose and no statutory retention obligations apply.

12. Fonts

We embed fonts (Inter and Roboto) locally from our own server. When the website is accessed, no connection to Google's servers is therefore established and no data is transmitted to Google for this purpose.

Our website and individual blog articles contain links to external websites (e.g. LinkedIn, Spotify, Calendly or providers of ESG software). When you click such links, you leave our website; the respective provider is responsible for data processing on the target pages. Occasionally, articles embed external images; when this content loads, your IP address may be transmitted to the respective provider.

14. Recipients and transfers to third countries

Your data is shared with third parties only within the scope of the services described above and only on the basis of the legal basis stated in each case. Where data is transferred to providers established or processing in the USA (Google, Substack, Microsoft), this is done on the basis of a certification under the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses pursuant to Art. 46 GDPR. The hosting of our website takes place within the EU (see section 4).

15. Your rights

You have the following rights vis-à-vis the controller with regard to your personal data:

  • Access (Art. 15 GDPR),
  • Rectification (Art. 16 GDPR),
  • Erasure (Art. 17 GDPR),
  • Restriction of processing (Art. 18 GDPR),
  • Data portability (Art. 20 GDPR),
  • Objection to processing (Art. 21 GDPR),
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).

To exercise your rights, an informal message to info@csr-tools.com is sufficient.

16. Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany. Website: baden-wuerttemberg.datenschutz.de

17. Validity and changes to this Privacy Policy

This Privacy Policy is dated June 2026. As our website develops or due to changes in legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version can be accessed at any time on this page.