GDPR

Privacy notice.

We deliberately operate this website in a data-economical manner — without cookies, without external tracking services, without advertising networks.

1. Controller

TeslaNow GmbH
Wilhelmstraße 32
51379 Leverkusen
Germany
Telephone: 02191 / 929394
Email: justiz@teslanow.de

2. Hosting

This website is hosted in Germany at Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp. On accessing the website, technically necessary server logs are recorded (IP address, timestamp, user agent, URL accessed). These data are anonymised or deleted in accordance with the Mittwald configuration and used exclusively for ensuring operation. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

3. No cookies, no third parties

This website sets no cookies and embeds no external tracking services (Google Analytics, Facebook pixel or similar). No fonts, scripts or analytics services from third parties are loaded. The fonts used are system fonts of the respective operating system.

4. Own reach measurement (cookieless)

To ensure operation and to detect automated access (bots, scrapers) we operate an own, cookieless reach measurement. On every page view the following information is processed on our servers in Germany:

  • timestamp of the page view
  • URL accessed and, where applicable, referrer URL
  • user agent (browser/bot identifier)
  • device type (desktop, tablet, mobile) and language variant
  • scroll depth and dwell time per page (anonymous, not personalised)
  • Geographical origin: country, region, city and Internet service provider (ISP) are determined on our server based on the IP address using a local GeoIP database (MaxMind GeoLite2 — city-level accuracy ca. ±50 km; updated weekly). No data are transmitted to third parties — the resolution takes place offline using the locally stored database.
  • Pseudonymised IP address: the IP address is processed immediately with a daily-rotating salt into a hash. Re-identification across day boundaries is technically excluded. The raw IP is additionally stored for a maximum of 30 days in a separate server-side cache (purpose: subsequent geo-resolution; recognition of the same connection on repeated anomalies). After 30 days the raw IP is automatically and irrevocably deleted.

No cookies are set, no local storage is used and no cross-device identifiers are formed. No profiling takes place. The data are evaluated exclusively in aggregated form (page-view counts, bot detection, security analysis). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, evaluable operation of the website and defence against automated attacks). Since no end-device information is read out or stored, consent under § 25 TTDSG is not required. Storage period: pseudonymised hits ≤ 30 days, raw IPs ≤ 30 days; aggregated statistics may be retained beyond that.

4a. Anomaly detection (protection against bulk-download / crawling)

For behavioural patterns suggesting an automated bulk download of the content or systematic crawling (in particular: ≥ 14 distinct HTML pages within 10 minutes; more than 50 requests within 5 minutes; more than 200 requests within one hour — each from the same connection), an internal anomaly entry is created. To evaluate the anomaly, a request may in individual cases be sent to the MaxMind GeoIP2 Precision Insights API (MaxMind, Inc., USA). Only the triggering IP is transmitted (processing in the USA on the basis of the EU Standard Contractual Clauses, Art. 46 GDPR; purpose limitation: VPN/proxy/hosting-provider/Tor detection; no profiling). The result is cached locally for 30 days and then deleted. The call to the third-party API takes place exclusively at the anomaly trigger, not in regular operation. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting our intellectual property and in maintaining the availability of the website).

5. Embedded content

On the pages of this website, no videos, scripts, advertising networks or other third-party content are embedded. The explainer videos are delivered entirely on this domain.

6. Press area

The access-protected press area is secured via HTTP basic auth. The credentials submitted are processed exclusively for authentication. Personalised evaluation of accesses does not take place.

7. Contact by email

If you contact us by email (for example via the addresses given in the imprint or the press area), the data submitted are processed for handling your request (Art. 6(1)(b) and (f) GDPR). No transfer to third parties takes place. The data will be deleted as soon as they are no longer necessary for the purpose of processing and no retention obligations conflict.

8. Your rights

You have at any time the right to information, correction, deletion, restriction of processing, data portability and objection (Art. 15–21 GDPR). Furthermore, you can lodge a complaint with a data protection supervisory authority — the competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information, North Rhine-Westphalia).

Status of this notice: 14 May 2026