Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to briefly as "data") we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as "online services").

The terms used are not gender-specific.

Last updated: 8 September 2026

Table of contents

Controller

Cleo Walker
Oderstrasse 11, 10247 Berlin, Germany
Email address: cleo@arecordofyou.com

Should the company be transferred to a successor entity (e.g. in the course of a conversion from a sole proprietorship into an Unternehmergesellschaft (haftungsbeschränkt), i.e. a UG (limited liability)), responsibility for the data processing described in this privacy policy shall transfer to that successor entity. We will inform data subjects of any such change.

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of data processed

  • Inventory data.
  • Payment data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication and procedural data.
  • Log data.

Categories of data subjects

  • Service recipients and clients.
  • Prospective clients.
  • Communication partners.
  • Users.
  • Business and contractual partners.
  • Third parties.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement (analytics).
  • Office and organisational procedures.
  • Organisational and administrative procedures.
  • Feedback.
  • Profiles containing user-related information.
  • Provision of our online services and user-friendliness.
  • Information technology infrastructure.
  • Public relations.
  • Business processes and business management procedures.

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations in your or our country of residence or registered office may apply. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.

  • Consent (Art. 6 (1) sentence 1 (a) GDPR) – The data subject has given their consent to the processing of personal data concerning them for one or more specific purposes.
  • Performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6 (1) sentence 1 (c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject which require protection of personal data. National data protection provisions in Germany: In addition to the provisions of the GDPR, national data protection regulations apply in Germany. This includes, in particular, the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains, among other things, special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. In addition, the data protection laws of the individual federal states may apply. Note on the applicability of the GDPR and the Swiss FADP: This privacy notice serves to provide information under both the Swiss Federal Act on Data Protection (FADP) and the GDPR. For this reason, and given the broader territorial scope and comprehensibility, GDPR terminology is used throughout. In particular, instead of the terms used under the Swiss FADP — "processing" of "personal data," "overriding interest," and "particularly sensitive personal data" — the terms used under the GDPR are applied: "processing" of "personal data," "legitimate interest," and "special categories of data." However, the legal meaning of these terms continues to be determined under the Swiss FADP insofar as it applies.

Security measures

In accordance with legal requirements, and taking into account the state of the art, implementation costs, and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to data, as well as access to, input of, disclosure of, and the securing and separation of data. We have also established procedures to ensure the exercise of data subject rights, the erasure of data, and appropriate responses to threats to data. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection through technology design and privacy-friendly default settings.

Securing online connections through TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between a website or app and the user's browser (or between two servers), protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. Where a website is secured by an SSL/TLS certificate, this is indicated by "HTTPS" appearing in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.

Disclosure of personal data

In the course of our processing of personal data, it may occur that such data is transmitted to, or disclosed to, other bodies, companies, legally independent organisational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded within a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.

International data transfers

Data processing in third countries: Where we transfer data to a third country (i.e. a country outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transmission of data to other persons, bodies or companies (which becomes apparent from the postal address of the respective provider, or where the privacy policy expressly refers to the transfer of data to third countries), this always takes place in accordance with legal requirements. For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognised as a safe legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded Standard Contractual Clauses with the respective providers, which comply with the requirements of the EU Commission and establish contractual obligations to protect your data.

This two-fold safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, while the Standard Contractual Clauses serve as an additional safeguard. Should changes occur within the framework of the DPF, the Standard Contractual Clauses serve as a reliable fallback. This ensures that your data remains adequately protected even in the event of political or legal changes. We inform you, for each individual service provider, whether it is certified under the DPF and whether Standard Contractual Clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). For data transfers to other third countries, corresponding safeguards apply, in particular Standard Contractual Clauses, explicit consent, or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found on the EU Commission's website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.

General information on data storage and erasure

We erase personal data that we process in accordance with legal requirements as soon as the underlying consent is withdrawn or no further legal basis for processing exists. This applies to cases in which the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule apply where legal obligations or particular interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the pursuit of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.

Our privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.

Where multiple retention periods or erasure deadlines apply to a given piece of data, the longest applicable period shall prevail. Data that is retained not for its originally intended purpose, but on the basis of legal requirements or other grounds, is processed exclusively for the purposes that justify its retention.

Retention and erasure of data: The following general periods apply to retention and archiving under German law:

  • 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the working instructions and other organisational documents required to understand them (§ 147 (1) no. 1 in conjunction with (3) AO, § 14b (1) UStG, § 257 (1) no. 1 in conjunction with (4) HGB).
  • 8 years – Accounting documents, such as invoices and expense receipts (§ 147 (1) nos. 4 and 4a in conjunction with (3) sentence 1 AO, and § 257 (1) no. 4 in conjunction with (4) HGB).
  • 6 years – Other business documents: received commercial or business correspondence, copies of sent commercial or business correspondence, and other documents relevant for tax purposes, e.g. hourly wage records, cost accounting sheets, calculation documents, price labelling, as well as payroll records (where not already accounting documents) and cash register tapes (§ 147 (1) nos. 2, 3, 5 in conjunction with (3) AO, § 257 (1) nos. 2 and 3 in conjunction with (4) HGB).
  • 3 years – Data required to take into account potential warranty and damages claims, or similar contractual claims and rights, and to process related enquiries, based on past business experience and standard industry practice, is stored for the duration of the standard statutory limitation period of three years (§§ 195, 199 BGB). Commencement of periods at year-end: Where a period does not expressly begin on a specific date and is at least one year in duration, it commences automatically at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in the course of which data is stored, the triggering event is the point at which the termination or other conclusion of the legal relationship takes effect.

Retention periods for memory contributions and orders:

  • Contact data of contributors collected solely for the purpose of coordinating the collection of contributions is deleted no later than 6 months after completion of the respective order, unless separate consent has been given for further purposes (e.g. the newsletter).
  • Submitted content (texts, photos, other contributions) and the Record created from it is stored as follows: where provision takes the form of a website with an agreed access period (e.g. 6 months, 3 years, 10 years, lifetime), we store the data for the duration of that period plus an additional 6 months following the last activity. Where provision takes another form (e.g. as a PDF document), we store the underlying data for a period of 6 months following delivery of the completed Record. Upon expiry of the relevant period, we delete the data, unless the client requests an extension or statutory retention obligations prevent deletion. Upon completion, the client is provided with a permanently usable copy of the Record for their own retention.
  • If an order is discontinued prematurely, or if the client ceases communication, we will make up to three documented attempts to make contact within a period of up to 6 months. Should these attempts be unsuccessful, we will provide the client with the contributions submitted up to that point in the form of a downloadable document (e.g. as a PDF and/or as a ZIP file containing photos) and treat the order as completed. From that point onward, the retention period described above for delivery in another form applies (6 months following delivery). In total, therefore, up to 12 months may elapse between the client's last contact and the erasure of the data. Should the client wish to resume the order before expiry of these periods, the order will be continued. This does not affect a contributor's right to request deletion of their own submitted content at any time, independent of the status of the overall order.
  • Should A RECORD OF YOU cease business operations, clients will be notified with at least 90 days' notice and will receive a complete export of their Record before any hosted web access is discontinued.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to that data as well as further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: You have the right, in accordance with legal requirements, to request the completion of data concerning you or the correction of inaccurate data concerning you.
  • Right to erasure and restriction of processing: You have the right, in accordance with legal requirements, to request that data concerning you be erased without delay, or alternatively to request restriction of the processing of such data in accordance with legal requirements.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us, in accordance with legal requirements, in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.
  • Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

Business services

We process the personal data of our contractual and business partners — such as customers, clients, prospective clients, suppliers and other cooperation partners (collectively "contractual partners") — for the purpose of initiating, carrying out and concluding contractual relationships and comparable legal relationships. This also includes pre-contractual measures carried out upon request, as well as communication in connection with the relevant contractual relationship.

Processing serves in particular to fulfil our principal and ancillary contractual obligations. This includes providing the agreed services, fulfilling update and information obligations, handling warranty and other performance issues, processing withdrawals, terminations of continuing obligations, reversals of transactions, refunds, and handling other contract-related declarations and enquiries. This applies both to one-off contracts and ongoing contractual relationships.

We process, in particular, master data such as name, address and, where applicable, company name; contact data such as email address and telephone number; contract and service data such as the subject matter of the contract, contract duration, order or process number; usage and service data; payment and billing data; and communication content and history. Where necessary, we also process data disclosed or transmitted to us in the course of carrying out an order.

We also process this data to protect our rights and to fulfil legal obligations. This includes, in particular, retention obligations under commercial and tax law, documentation obligations, and, where applicable, obligations to provide evidence and accountability. Processing is also carried out on the basis of our legitimate interests in the proper conduct of business, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners from misuse and threats to data, trade secrets and other legal interests. This may involve the engagement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisors, or other agents, insofar as this is necessary for the performance of the contract or for compliance with legal obligations.

Personal data is disclosed to third parties only where necessary for the performance of the contract, for pre-contractual measures, to protect legitimate interests, or to comply with legal obligations. We inform you separately, within this privacy policy, of any processing beyond this scope, in particular for marketing purposes. We inform contractual partners which data is required in each individual case as part of the data collection process, for example through corresponding labelling in online forms or in personal contact. Data is deleted as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations apply. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in connection with a specific order is deleted after the order is completed and any applicable retention periods have expired, unless further legal or contractual obligations to retain the data exist. The legal basis for processing is Art. 6 (1) (b) GDPR for the performance of pre-contractual measures and the respective contractual relationship, and Art. 6 (1) (c) GDPR for compliance with legal obligations. Insofar as processing is based on legitimate interests, it is carried out on the basis of Art. 6 (1) (f) GDPR. Where processing is based on Art. 6 (1) (f) GDPR, it serves to protect our legitimate interests in the proper and efficient organisation of our business, the internal administration and documentation of business processes, the assertion and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, and the economic management and development of our business. These interests lie, in particular, in ensuring secure and legally compliant business operations and preserving our entrepreneurial capacity to act.

  • Types of data processed: Inventory data (e.g. full name, home address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); contract data (e.g. subject matter of contract, duration, customer category); usage data (e.g. page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Service recipients and clients; prospective clients; business and contractual partners.
  • Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; security measures; communication; office and organisational procedures; organisational and administrative procedures; business processes and business management procedures.
  • Retention and erasure: Erasure in accordance with the information provided in the section "General information on data storage and erasure."
  • Legal bases: Performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR); legal obligation (Art. 6 (1) sentence 1 (c) GDPR); legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Online shop, order forms, e-commerce and service fulfilment: We process the data of our customers to enable them to select, purchase or order the chosen products, goods and related services, as well as their payment and provision, delivery or performance. Where necessary for the fulfilment of an order, we engage service providers, in particular postal, freight and shipping companies, to carry out delivery or performance to our customers. For processing payment transactions, we use the services of banks and payment service providers. The required information is identified as such within the ordering or comparable purchasing process and includes the information needed for delivery or provision and billing, as well as contact information for any necessary follow-up; legal bases: performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR).
  • Tally (submission form for contributions): To collect the memories, photos and other content submitted by contributors in connection with the services we provide, we use the form platform Tally. The content entered may, in individual cases, involve special categories of personal data (e.g. health data), where contributors voluntarily share such information; service provider: Tally BV, August Van Lokerenstraat 71, 9050 Ghent, Belgium; legal bases: performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR), and, in the case of special categories of personal data, consent (Art. 9 (2) (a) GDPR); website: https://tally.so; privacy policy: https://tally.so/help/privacy-policy. (No third-country transfer — Tally is a Belgian company, and data storage takes place within the EU.)

Payment procedures

Within the framework of contractual and other legal relationships, on the basis of legal obligations, or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, engage service providers in addition to banks and credit institutions (collectively "payment service providers"). Payment transactions are carried out exclusively via encrypted connections in accordance with the state of the art, so that the data entered is protected from unauthorised access during transmission. Data processed by payment service providers includes inventory data, such as name and address; bank data, such as account or credit card numbers; passwords, TANs and checksums; as well as contract-, amount- and recipient-related information. This information is necessary to carry out the transactions. However, the data entered is processed and stored exclusively by the payment service providers. This means that we do not receive any account- or credit card-related information, but only confirmation or notification of non-payment. Under certain circumstances, payment service providers may transmit data to credit reporting agencies. This transmission serves the purpose of identity and creditworthiness verification. For this purpose, we refer to the terms and conditions and privacy notices of the payment service providers.

The terms and conditions and privacy notices of the respective payment service providers, which are available on their respective websites or transaction applications, apply to payment transactions. We also refer to these for further information and for asserting rights of withdrawal, access and other data subject rights.

  • Types of data processed: Inventory data (e.g. full name, home address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of contract, duration, customer category); usage data; meta, communication and procedural data.
  • Data subjects: Service recipients and clients; business and contractual partners; prospective clients.
  • Purposes of processing and legitimate interests: Performance of contractual services and fulfilment of contractual obligations; business processes and business management procedures.
  • Retention and erasure: Erasure in accordance with the information provided in the section "General information on data storage and erasure."
  • Legal bases: Performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR); legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Stripe: Payment services (technical integration of online payment methods); service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; legal bases: performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR); website: https://stripe.com; privacy policy: https://stripe.com/privacy. Basis for third-country transfer: Data Privacy Framework (DPF).

Provision of online services and web hosting

We process the data of users in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.

  • Types of data processed: Usage data (e.g. page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); log data (e.g. log files relating to logins or the retrieval of data or access times).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.); security measures.
  • Retention and erasure: Erasure in accordance with the information provided in the section "General information on data storage and erasure."
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Provision of online services on rented storage space: For the provision of our online services, we use storage space, computing capacity and software rented or otherwise obtained from a corresponding server provider (also referred to as a "web host"); legal bases: legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • GoDaddy (email hosting): For sending and receiving business emails, we use the services of GoDaddy; service provider: GoDaddy.com, LLC, 14455 N. Hayden Rd., Ste. 226, Scottsdale, AZ 85260, USA; legal bases: legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); website: https://www.godaddy.com; privacy policy: https://www.godaddy.com/legal/agreements/privacy-policy. Basis for third-country transfer: Data Privacy Framework (DPF).
  • Netlify: For the provision of our online services, we use the hosting platform Netlify; service provider: Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA; legal bases: legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); website: https://www.netlify.com; privacy policy: https://www.netlify.com/privacy/. Basis for third-country transfer: Standard Contractual Clauses.
  • The fonts (web fonts) used on this website are hosted locally and are not loaded from external servers (e.g. Google Fonts). Accordingly, no user data is transmitted to third-party providers in connection with the display of fonts.
  • Collection of access data and log files: Access to our online services is logged in the form of so-called "server log files." Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful retrieval, browser type and version, the user's operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes, e.g. to prevent server overload (particularly in the case of malicious attacks, so-called DDoS attacks), and to ensure server utilisation and stability; legal bases: legitimate interests (Art. 6 (1) sentence 1 (f) GDPR). Erasure of data: log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes is excluded from erasure until the relevant incident has been finally resolved.

Use of cookies

The term "cookies" refers to functions that store and read information on users' devices. Cookies may be used for various purposes, including ensuring the functionality, security and user-friendliness of online services, as well as analysing visitor traffic. We use cookies in accordance with legal requirements. Where required, we obtain users' consent in advance. Where consent is not required, we rely on our legitimate interests. This applies where the storage and reading of information is essential to provide expressly requested content and functions. This includes, for example, storing settings and ensuring the functionality and security of our online services. Consent may be withdrawn at any time. We provide clear information on the scope of use and which cookies are used.

Note on legal bases: Whether we process personal data using cookies depends on consent. Where consent has been given, it serves as the legal basis. In the absence of consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and procedures.

Retention period: With regard to retention period, the following types of cookies are distinguished:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left the online service and closed their device (e.g. browser or mobile application).
  • Persistent cookies: Persistent cookies remain stored even after the device has been closed. For example, they may be used to store login status and to display preferred content directly when a user revisits a website. Similarly, user data collected using cookies may be used for reach measurement (analytics). Where we do not provide users with explicit information on the type and storage duration of cookies (e.g. when obtaining consent), users should assume that such cookies are persistent and that the storage period may be up to two years. General information on withdrawal and objection (opt-out): Users may withdraw any consent given at any time and may also object to processing in accordance with legal requirements, including via their browser's privacy settings.
  • Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Contact and inquiry management

When contacting us (e.g. by post, contact form, email, telephone or via social media), and within the context of existing user and business relationships, the information provided by the enquiring party is processed to the extent necessary to respond to the enquiry and any requested action.

  • Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts, together with related information such as authorship or time of creation); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Communication partners.
  • Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form); provision of our online services and user-friendliness.
  • Retention and erasure: Erasure in accordance with the information provided in the section "General information on data storage and erasure."
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR).

Further information on processing operations, procedures and services:

  • Contact form: When contacting us via our contact form, by email, or through other means of communication, we process the personal data transmitted to us in order to respond to and process the relevant enquiry. This generally includes information such as name, contact details, and any further information provided that is necessary for appropriate handling. We use this data exclusively for the stated purpose of establishing contact and communication; legal bases: performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR), legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Cal.com (appointment scheduling): To coordinate consultation appointments with prospective clients and clients, we use the booking platform Cal.com; service provider: Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA; EU representative under Art. 27 GDPR: Felix Kolodziej, contactable via privacy@cal.com; legal bases: performance of a contract and pre-contractual requests (Art. 6 (1) sentence 1 (b) GDPR); website: https://cal.com; privacy policy: https://cal.com/privacy. Basis for third-country transfer: Data Privacy Framework (DPF), Standard Contractual Clauses.

Newsletter and electronic notifications

We send newsletters, emails and other electronic notifications (hereinafter "newsletter") exclusively with the consent of the recipient or on the basis of a legal permission. Where the content of the newsletter is specified as part of the sign-up process, this content is decisive for users' consent. As a rule, providing your email address is sufficient to subscribe to our newsletter. However, in order to provide you with a personalised service, we may ask for your name so that we may address you personally in the newsletter, or for further information where necessary for the purpose of the newsletter.

Erasure and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests, before deleting them, in order to be able to demonstrate that consent was previously given. Processing of this data is limited to the purpose of potential defence against claims. An individual request for erasure is possible at any time, provided that the prior existence of consent is simultaneously confirmed. Where we are subject to an obligation to permanently observe an objection, we reserve the right to retain the email address solely for this purpose on a suppression list (so-called "blocklist"). Logging of the sign-up process is carried out on the basis of our legitimate interests for the purpose of demonstrating that it was conducted properly. Where we engage a service provider to send emails on our behalf, this is done on the basis of our legitimate interest in an efficient and secure delivery system.

Content:

Information about us, our services, promotions and offers.

  • Types of data processed: Inventory data (e.g. full name, home address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Communication partners.
  • Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post).
  • Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR).
  • Right to object (opt-out): You may unsubscribe from our newsletter at any time, i.e. withdraw your consent or object to further receipt. A link to unsubscribe from the newsletter can be found either at the end of each newsletter, or you may otherwise use one of the contact options listed above, preferably email.
  • Brevo (newsletter delivery): To send our newsletter, we use the platform Brevo; service provider: Sendinblue SAS (trading as Brevo), 17 rue Salneuve, 75017 Paris, France; legal bases: consent (Art. 6 (1) sentence 1 (a) GDPR); website: https://www.brevo.com; privacy policy: https://www.brevo.com/legal/privacypolicy/. (No third-country transfer — Brevo is an EU-based company.)

Web analytics, monitoring and optimisation

Web analytics (also referred to as "reach measurement") serves to evaluate visitor traffic on our online services and may include behaviour, interests, or demographic information about visitors, such as age or gender, in pseudonymised form. Reach measurement allows us, for example, to identify at what times our online services or their functions and content are used most frequently, or invite repeat use. It also enables us to identify areas that require optimisation.

In addition to web analytics, we may also use testing procedures to test and optimise different versions of our online services or their components. Unless otherwise stated below, profiles — i.e. data compiled in relation to a particular usage process — may be created for these purposes, and information may be stored in and read from a browser or device. Data collected may include, in particular, websites visited and elements used therein, as well as technical information such as the browser used, the computer system used, and information on usage times. Where users have consented to the collection of location data, either to us or to the providers of the services we use, the processing of location data is also possible.

In addition, users' IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation through truncation of the IP address) to protect users. In general, no directly identifying data of users (such as email addresses or names) is stored in the course of web analytics, A/B testing and optimisation, but rather pseudonyms. This means that neither we nor the providers of the software used are aware of the actual identity of users, but only of the information stored in their profiles for the purposes of the respective procedures.

Note on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in efficient, economical and user-friendly services). In this context, we also refer you to the information on the use of cookies contained in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, recognition of returning visitors); profiles containing user-related information (creation of user profiles).
  • Retention and erasure: Erasure in accordance with the information provided in the section "General information on data storage and erasure." Storage of cookies for up to 2 years (unless otherwise specified, cookies and similar storage methods may be stored on users' devices for a period of two years).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6 (1) sentence 1 (a) GDPR); legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).
  • Cloudflare Web Analytics: To analyse visitor numbers and access statistics for our online services, we use Cloudflare Web Analytics. This service does not use cookies, fingerprinting techniques, or persistent identifiers; it is not possible to recognise individual users across multiple visits; service provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA; legal bases: legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); website: https://www.cloudflare.com; privacy policy: https://www.cloudflare.com/privacypolicy/. Basis for third-country transfer: Standard Contractual Clauses. In the case of Cloudflare Web Analytics, no cookies or corresponding retention period apply, as the service operates entirely without cookies.

Presence on social networks (social media)

We maintain online presences within social networks and, in this context, process user data in order to communicate with users active there or to provide information about us.

We would like to point out that, in doing so, user data may be processed outside the European Union. This may present risks to users, as it may, for example, make it more difficult to enforce user rights. Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created based on user behaviour and resulting interests. Such profiles may, in turn, be used to place advertisements within and outside the networks that are presumed to correspond to the interests of users. For this purpose, cookies are generally stored on users' computers, in which the usage behaviour and interests of users are stored. In addition, data may also be stored in usage profiles independently of the devices used by users (in particular, where they are members of the relevant platforms and are logged in there).

For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks. Even in the case of requests for information and the exercise of data subject rights, we would point out that these can be asserted most effectively directly with the providers, since only the providers have access to the relevant user data and can take corresponding measures and provide information directly. Should you nevertheless require assistance, you are welcome to contact us.

  • Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image messages and posts, together with related information such as authorship or time of creation); usage data (e.g. page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Communication; feedback (e.g. collecting feedback via an online form); public relations.
  • Retention and erasure: Erasure in accordance with the information provided in the section "General information on data storage and erasure."
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Further information on processing operations, procedures and services:

  • Instagram: Social network enabling the sharing of photos and videos, commenting on and liking posts, sending messages, and following profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); website: https://www.instagram.com; privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfer: Data Privacy Framework (DPF).

Changes and updates

We ask that you regularly inform yourself of the content of our privacy policy. We will amend the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as such changes require your participation (e.g. consent) or other individual notification.

Where this privacy policy contains addresses and contact information of companies and organisations, please note that this information may change over time, and we ask that you verify it before making contact.

Definitions

This section provides an overview of the terms used in this privacy policy. Where terms are defined by law, the statutory definitions apply. The following explanations are intended primarily to aid understanding.

  • Employees: "Employees" refers to persons in an employment relationship, whether as staff, salaried employees, or in similar positions. An employment relationship is a legal relationship between an employer and an employee, established through an employment contract or agreement. It includes the employer's obligation to pay the employee remuneration, while the employee provides their work. The employment relationship encompasses various phases, including its establishment (conclusion of the employment contract), its performance (the employee carries out their work), and its termination (whether by dismissal, mutual agreement, or otherwise). Employee data is any information relating to these persons in the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and bank details, working hours, holiday entitlements, health data, and performance evaluations.
  • Inventory data: "Inventory data" comprises essential information required for the identification and administration of contractual partners, user accounts, profiles and similar assignments. This data may include, among other things, personal and demographic information such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Inventory data forms the basis for any formal interaction between individuals and services, institutions or systems by enabling unambiguous identification and communication.
  • Content data: "Content data" comprises information generated in the course of creating, editing, and publishing content of any kind. This category of data may include text, images, videos, audio files and other multimedia content published across various platforms and media. Content data is not limited to the actual content itself, but also includes metadata providing information about the content, such as tags, descriptions, authorship information, and publication dates.
  • Contact data: "Contact data" is essential information that enables communication with individuals or organisations. This includes, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
  • Meta, communication and procedural data: "Meta, communication and procedural data" are categories comprising information about the manner in which data is processed, transmitted and managed. Metadata, also known as data about data, includes information describing the context, origin and structure of other data. This may include information on file size, date of creation, the author of a document, and revision history. Communication data records the exchange of information between users across various channels, such as email correspondence, call logs, messages within social networks, and chat histories, including the persons involved, timestamps and transmission paths. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, transaction and activity logs, and audit logs used to trace and review processes.
  • Usage data: "Usage data" refers to information that records how users interact with digital products, services or platforms. This data encompasses a broad range of information showing how users use applications, which features they prefer, how long they spend on particular pages, and the paths they take through an application. Usage data may also include frequency of use, timestamps of activity, IP addresses, device information, and location data. It is particularly valuable for analysing user behaviour, optimising user experience, personalising content, and improving products or services. Furthermore, usage data plays a key role in identifying trends, preferences and potential problem areas within digital offerings.
  • Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles containing user-related information: The processing of "profiles containing user-related information," or "profiles" for short, includes any type of automated processing of personal data consisting of the use of such personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may involve different information relating to demographics, behaviour and interests, such as interaction with websites and their content). Cookies and web beacons are frequently used for profiling purposes.
  • Log data: "Log data" is information relating to events or activities recorded within a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system. Log data is often used for the analysis of system problems, security monitoring, or the creation of performance reports.
  • Reach measurement: "Reach measurement" (also referred to as web analytics) serves to evaluate visitor traffic to an online service and may include the behaviour or interests of visitors regarding specific information, such as website content. Reach measurement allows operators of online services to identify, for example, when users visit their websites and which content interests them. This enables them to better tailor website content to the needs of visitors. Pseudonymous cookies and web beacons are frequently used for reach measurement purposes in order to recognise returning visitors and obtain more detailed analyses of the use of an online service.
  • Controller: "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data, including its collection, evaluation, storage, transmission or erasure.
  • Contract data: "Contract data" is specific information relating to the formalisation of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged or sold. This category of data is essential for the management and fulfilment of contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the start and end dates of the contract, the type of services or products agreed upon, pricing arrangements, payment terms, termination rights, renewal options, and any special terms or clauses. It serves as the legal basis for the relationship between the parties and is essential for clarifying rights and obligations, enforcing claims, and resolving disputes.
  • Payment data: "Payment data" comprises all information required to process payment transactions between buyers and sellers. This data is of critical importance for electronic commerce, online banking, and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers, and invoice information. Payment data may also include information relating to payment status, chargebacks, authorisations, and fees.

Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke — English translation prepared for internal use and lawyer review.