Privacy Policy
Controller
Philip Isenmann, Ulmer Straße 64, 89143 Blaubeuren, Germany
E‑mail: [email protected]
Data Collected
We collect the following types of personal data: email addresses (for contact and scheduling), names (for communication), IP addresses (for website operation and analytics), browser information, device information, and usage data (pages visited, time spent, interactions).
Purposes of Processing
Website operation, contact handling, call scheduling (Calendly), payment processing (Stripe), and website analytics (Google Analytics).
Legal Bases
Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(f) GDPR (legitimate interests), and Art. 6(1)(a) GDPR (consent for cookies and tracking).
Recipients and Third‑Party Services
Hosting: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Data is processed on servers located in the EU and USA.
Calendly: Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA (scheduling).
Stripe: Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA (payment processing via payment links).
Google Analytics: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (website analytics). We use Google Analytics 4 with consent mode. Data processing is based on standard contractual clauses.
Cookies and Tracking
This website uses cookies for website analytics. We use Google Analytics 4, which sets the following cookies:
- _ga: Used to distinguish users (expires after 2 years)
- _ga_[ID]: Used to persist session state (expires after 2 years)
These cookies are only set after you provide explicit consent via our cookie banner. Google Analytics uses these cookies to analyze your use of the website. The information is usually transferred to a Google server in the USA and stored there. We use Google Consent Mode to ensure analytics cookies are only activated after you consent.
Managing Cookies: You can withdraw your consent at any time by clearing your browser cookies and refreshing the page to reset your choice via the cookie banner. Most browsers allow you to refuse cookies entirely through settings.
Data Retention
We retain personal data according to the following schedules:
- Contact inquiries: 6 months after last correspondence
- Calendly scheduling data: Until appointment completion, then deleted within 30 days
- Payment records (Stripe): 10 years (German tax law requirement per AO §147)
- Analytics data (Google Analytics): 14 months (Google's default retention for GA4)
- Cookie consent records: Stored locally in your browser until cleared
Data Subject Rights
Under GDPR, you have the following rights:
- Right to access (Art. 15 GDPR): Request information about your stored personal data
- Right to rectification (Art. 16 GDPR): Request correction of inaccurate data
- Right to erasure (Art. 17 GDPR): Request deletion of your data
- Right to restriction (Art. 18 GDPR): Request limitation of data processing
- Right to object (Art. 21 GDPR): Object to data processing
- Right to data portability (Art. 20 GDPR): Receive your data in a structured format
- Right to withdraw consent (Art. 7(3) GDPR): Withdraw your consent at any time
Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority, particularly in your country of residence, workplace, or where the alleged infringement occurred. For Baden‑Württemberg (Germany), the competent authority is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden‑Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany. Website: www.baden-wuerttemberg.datenschutz.de
Third‑Country Transfers
Some of our service providers (Vercel, Calendly, Stripe, Google) are located in the USA. Data transfers to the USA are secured through standard contractual clauses (Art. 46 GDPR) and, where applicable, the EU‑US Data Privacy Framework. Google, Stripe, and other providers maintain GDPR‑compliant data processing agreements.
Security and Encryption
This website uses SSL/TLS encryption to protect data transmission. You can recognize an encrypted connection by the "https://" in your browser's address bar and the lock icon.
Automated Decision‑Making
We do not use automated decision‑making or profiling as defined in Art. 22 GDPR.
Contact for Privacy Inquiries
For any privacy‑related questions or to exercise your rights, please contact us at: [email protected]