Privacy

Privacy policy

This privacy policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter “data”) in the course of providing our services and within our online offering and the websites, functions and content connected with it, as well as external online presences such as our social media profiles (hereinafter jointly referred to as the “online offering”). Regarding the terms used, such as “processing” or “controller”, we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR). Informational translation — the German version is legally binding.

Controller

VELVET DOTS LIMITED
Unit 2, 2 Bridge Street
Athlone
Co. Westmeath, N37 V8N7, Ireland
Authorized director: Kirsten Biema
Registration number (CRO Ireland): 822393
Email: team@velvetdotscreativeminds.com

Types of data processed

- Inventory data (e.g. master data, names or addresses).
- Contact data (e.g. email, phone numbers).
- Content data (e.g. text input, photographs, videos).
- Usage data (e.g. websites visited, interest in content, access times).
- Meta/communication data (e.g. device information, IP addresses).

Categories of data subjects

Visitors and users of the online offering (hereinafter we also refer to the data subjects collectively as “users”).

Purpose of processing

Providing the online offering, its functions and content. - Responding to contact requests and communicating with users. - Security measures. - Reach measurement/marketing.

Terms used

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. “Processing” means any operation performed on personal data, whether or not by automated means. The term is broad and covers practically every handling of data. “Pseudonymization” means processing personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures ensuring non-attribution. “Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movements. “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. “Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. Relevant legal bases: in accordance with Art. 13 GDPR, we inform you of the legal bases of our data processing. For users within the scope of the GDPR (EU and EEA), unless the legal basis is stated in this privacy policy, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; the legal basis for processing to perform our services, carry out contractual measures and respond to inquiries is Art. 6(1)(b) GDPR; the legal basis for processing to comply with our legal obligations is Art. 6(1)(c) GDPR; where vital interests of the data subject or another natural person require processing, Art. 6(1)(d) GDPR serves as the legal basis; the legal basis for processing necessary for the performance of a task in the public interest or in the exercise of official authority is Art. 6(1)(e) GDPR; the legal basis for processing to protect our legitimate interests is Art. 6(1)(f) GDPR. Processing for purposes other than those for which the data were collected is governed by Art. 6(4) GDPR. Processing of special categories of data (per Art. 9(1) GDPR) is governed by Art. 9(2) GDPR.

Security measures

In accordance with statutory requirements — taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons — we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk. The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, entry of, disclosure of, availability of and separation of the data. Furthermore, we have established procedures ensuring the exercise of data subject rights, the deletion of data and responses to data threats. We also take the protection of personal data into account in the development and selection of hardware, software and processes, in line with the principles of data protection by design and by default.

Cooperation with processors, joint controllers and third parties

Where, in the course of our processing, we disclose data to other persons and companies (processors, joint controllers or third parties), transmit data to them or otherwise grant them access, this occurs only on the basis of legal permission (e.g. where transmission to third parties such as payment service providers is necessary for contract performance), user consent, a legal obligation, or our legitimate interests (e.g. when using agents, web hosts, etc.). Where we disclose, transmit or otherwise grant access to data to other companies in our group, this is done in particular for administrative purposes as a legitimate interest and otherwise on a basis compliant with statutory requirements.

Transfers to third countries

Where we process data in a third country (i.e. outside the European Union (EU), the European Economic Area (EEA) or the Swiss Confederation), or where this occurs through the use of third-party services or the disclosure or transmission of data to other persons or companies, it only takes place to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to statutory or contractual permissions, we process or have data processed in a third country only where the statutory conditions are met — for example on the basis of specific safeguards such as an officially recognized adequacy decision (for the USA, in particular the “EU-U.S. Data Privacy Framework”) or compliance with officially recognized contractual obligations (standard contractual clauses per Art. 46 GDPR).

Rights of data subjects

You have the right to request confirmation as to whether data concerning you are being processed, information about those data, further information and a copy of the data in accordance with statutory requirements. You have the right, in accordance with statutory requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you. You have the right, in accordance with statutory requirements, to request that data concerning you be deleted without undue delay or, alternatively, that processing be restricted. You have the right to receive the data concerning you that you provided to us and to request their transmission to other controllers, in accordance with statutory requirements. You also have the right to lodge a complaint with the competent supervisory authority. Right of revocation: you have the right to revoke consent once given, with effect for the future.

Right to object

You may object to the future processing of data concerning you at any time in accordance with statutory requirements. The objection may in particular be made against processing for direct marketing purposes.

Cookies and the right to object to direct marketing

“Cookies” are small files stored on users’ devices. Various information can be stored in cookies. A cookie primarily serves to store information about a user (or the device on which it is stored) during or after their visit to an online offering. Temporary cookies (“session cookies” or “transient cookies”) are deleted after a user leaves an online offering and closes the browser — such a cookie may store, for example, the contents of a shopping cart or a login status. “Permanent” or “persistent” cookies remain stored even after the browser is closed — for example, the login status or user interests used for reach measurement or marketing. “Third-party cookies” are cookies offered by providers other than the controller operating the online offering (otherwise, they are “first-party cookies”). We may use temporary and permanent cookies and explain this in our privacy policy. If users do not want cookies stored on their device, they are asked to disable the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Excluding cookies may limit the functionality of this online offering. A general objection to the use of cookies for online marketing purposes can be declared for a large number of services, especially in the case of tracking, via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. Furthermore, cookies can be prevented by disabling them in the browser settings; note that not all functions of this online offering may then be available.

Deletion of data

The data we process are deleted or their processing restricted in accordance with statutory requirements. Unless expressly stated in this privacy policy, data stored by us are deleted as soon as they are no longer required for their intended purpose and no statutory retention obligations prevent deletion. Where data are not deleted because they are required for other legally permissible purposes, their processing is restricted — i.e. the data are blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax reasons.

Changes and updates to this privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to our data processing make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.

Business-related processing

Additionally we process — contract data (e.g. subject of the contract, term, customer category) — payment data (e.g. bank details, payment history) of our customers, prospects and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.

Contractual services

We process the data of our contractual partners and prospects as well as other clients, customers or contractual partners (uniformly referred to as “contractual partners”) in accordance with Art. 6(1)(b) GDPR in order to provide our contractual or pre-contractual services to them. The data processed, and the nature, scope, purpose and necessity of their processing, are determined by the underlying contractual relationship. The data processed include the master data of our contractual partners (e.g. names and addresses), contact data (e.g. email addresses and phone numbers) as well as contract data (e.g. services used, contract content, contractual communication, names of contact persons) and payment data (e.g. bank details, payment history). We generally do not process special categories of personal data, unless they are part of commissioned or contractual processing. We process data required to establish and perform the contractual services and indicate the necessity of their disclosure where this is not evident to the contractual partners. Disclosure to external persons or companies takes place only where required under a contract. When processing data entrusted to us within an engagement, we act in accordance with the instructions of the client and the statutory requirements. When using our online services, we may store the IP address and the time of the respective user action. Storage is based on our legitimate interests and the users’ interests in protection against misuse and other unauthorized use. These data are generally not passed on to third parties, unless required to pursue our claims per Art. 6(1)(f) GDPR or there is a legal obligation per Art. 6(1)(c) GDPR. Data are deleted when they are no longer required for the performance of contractual or statutory duties of care or for handling any warranty or comparable obligations; the necessity of retaining the data is reviewed every three years; otherwise, the statutory retention obligations apply.

External payment service providers

Depending on the offer we use different routes for order and payment processing: via our checkout pages with ThriveCart (see the dedicated section “Order and purchase processing with ThriveCart” below), via the community platform Skool (see the dedicated section “Community platform and purchase processing with Skool” below) and, in individual cases, by invoice in a direct contractual relationship with us. For payment by invoice, your data are processed by us and, within our tax obligations, by our tax office; no external checkout service is involved. Where a checkout service is used, this happens in conjunction with external payment service providers, in particular Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; https://stripe.com/de/privacy) and PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg; https://www.paypal.com/de/webapps/mpp/ua/privacy-full). In the context of contract performance we use the payment service providers on the basis of Art. 6(1)(b) GDPR. Otherwise we use external payment service providers on the basis of our legitimate interests per Art. 6(1)(f) GDPR to offer our users effective and secure payment options. The data processed by the payment service providers include inventory data (e.g. name and address), bank data (e.g. account numbers or credit card numbers), passwords, TANs and checksums, as well as contract, amount and recipient-related information. This information is required to carry out the transactions. However, the data entered are processed and stored only by the payment service providers; we receive no account or credit-card-related information, only confirmation or rejection of the payment. The terms and privacy notices of the respective payment service providers apply to the payment transactions; we refer to them for further information and for asserting revocation, access and other data subject rights.

Order and purchase processing with ThriveCart

For part of our digital products and programs — such as the Claude Sprint — we use the order and checkout service ThriveCart (https://thrivecart.com). Orders are placed via our checkout pages (sales.kirstenbiema.com). The AI Business Community is not sold via this route; the section “Community platform and purchase processing with Skool” applies to it. When you order, the data required (e.g. name, email address, billing address, product ordered, payment information) are processed by ThriveCart and the payment service provider you choose (see above). Processing takes place to perform the contract per Art. 6(1)(b) GDPR. Transfers to third countries (in particular the USA) may occur, based on standard contractual clauses per Art. 46 GDPR. Further information is available in ThriveCart’s privacy policy: https://thrivecart.com/privacy/.

Community platform and purchase processing with Skool

We run our AI Business Community and our free community “KI — aber richtig” on the platform Skool (skool.com), a service of Skool, Inc., 111 Main Street, Los Angeles, California, USA (email: help@skool.com). When you join the community, you create your own user account there; the processing of your data initially takes place in the relationship between you and Skool under their privacy terms. The data processed include, in particular, inventory data (e.g. name or display name, email address, optional profile picture), usage and connection data (e.g. IP address, time and extent of use) and the content you post yourself (e.g. posts, comments, messages). As operator of the community we can additionally see the details of your membership.

You book the paid membership in the AI Business Community directly with Skool. Ordering, billing and renewal of the subscription therefore run via Skool and the payment service providers integrated there; we do not receive complete payment data, only the details required to manage the membership. The legal basis for processing is the performance of the contract per Art. 6(1)(b) GDPR and, otherwise, our legitimate interest in operating a functioning community platform per Art. 6(1)(f) GDPR.

Skool processes data in the USA. Transfers to third countries take place on the basis of suitable safeguards per Art. 44 et seq. GDPR, in particular standard contractual clauses per Art. 46 GDPR. Please note that content you post in the community is visible to the other members — consider which personal data and which details about your own clients you share there. You can end your membership at any time in your Skool account; the deletion of your user account and the data stored there is governed by Skool’s terms. Further information is available in Skool’s privacy policy: https://www.skool.com/legal?t=privacy.

Appointment booking with Calendly

For arranging appointments (e.g. the orientation call) we use the service Calendly of Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. When you book an appointment via Calendly, the data you enter (name, email address, chosen slot and any voluntary details about your request) are processed by Calendly. Processing takes place to carry out pre-contractual measures or to perform the contract per Art. 6(1)(b) GDPR and on the basis of our legitimate interests in efficient appointment organization per Art. 6(1)(f) GDPR. Calendly processes data in the USA and is certified under the EU-U.S. Data Privacy Framework. Further information is available in Calendly’s privacy policy: https://calendly.com/privacy.

Video conferencing and recordings with Zoom

For video calls, live sessions and consultations (e.g. in our sprints, programs and the community) we use Zoom, a service of Zoom Communications, Inc., 55 Almaden Blvd., Suite 600, San Jose, CA 95113, USA. When participating in a Zoom session, the following are processed in particular: personal details (e.g. display name, possibly email address, optional profile picture), connection and metadata (e.g. IP address, device information, time) as well as audio, video and chat content where you use microphone, camera or chat. Please note: our Zoom calls are recorded by default — above all so that participants can catch up on missed sessions. Before each call, Zoom actively informs you of the recording and asks for your consent: on joining, a notice appears that the call is being recorded, and you can consent — or decline and in that case not participate (we provide missed content via the recording or on request). If you participate but want to appear in the recording as little as possible, you can additionally keep camera and microphone off, use an alias as display name, and ask questions beforehand or afterwards. Legal bases: performance of our contractual services per Art. 6(1)(b) GDPR; for recordings, your consent per Art. 6(1)(a) GDPR, granted via the prompt in the Zoom client before joining and revocable at any time with effect for the future. We make recordings available exclusively to the respective participants or members of the associated programs and delete them once no longer required for this purpose. Zoom also processes data in the USA and is certified under the EU-U.S. Data Privacy Framework; a data processing agreement per Art. 28 GDPR is in place with Zoom. Further information: https://explore.zoom.us/de/privacy/.

Collaboration tools in the client context (Notion, ClickUp)

As part of our consulting and program services we work with project and knowledge management tools, in particular Notion (Notion Labs, Inc., 2300 Harrison Street, San Francisco, CA 94110, USA; privacy policy: https://www.notion.com/privacy) and ClickUp (Mango Technologies, Inc. d/b/a ClickUp, San Diego, CA, USA; privacy policy: https://clickup.com/terms/privacy). Personal data of our clients may be processed in these tools — e.g. names, contact details, project content, notes and shared working documents from the collaboration. Processing takes place to provide our contractual services per Art. 6(1)(b) GDPR and on the basis of our legitimate interests in efficient, structured collaboration per Art. 6(1)(f) GDPR. Both providers may process data in the USA; transfers take place on the basis of the EU-U.S. Data Privacy Framework or standard contractual clauses per Art. 46 GDPR. We store in these tools only the data required for the respective collaboration and delete them when no longer needed.

CRM and customer management with HighLevel

To manage customer and prospect relationships (CRM) we use HighLevel, a service of HighLevel Inc., Dallas, Texas, USA (privacy policy: https://www.gohighlevel.com/privacy-policy). In particular, contact data (e.g. name, email address, phone number), details of the customer relationship and the communication history may be stored there. Processing takes place to provide our contractual services and respond to inquiries per Art. 6(1)(b) GDPR and on the basis of our legitimate interests in efficient customer management per Art. 6(1)(f) GDPR. HighLevel may process data in the USA; transfers take place on the basis of standard contractual clauses per Art. 46 GDPR; a data processing agreement per Art. 28 GDPR is in place with the provider.

Email and office software: Google Workspace

For our business email communication and for documents, calendars and file storage we use Google Workspace, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (privacy policy: https://policies.google.com/privacy). When you write us an email, for example, your message and contact details are processed and stored via Google Workspace. Processing takes place for communication and contract handling per Art. 6(1)(b) GDPR and on the basis of our legitimate interests in a secure, efficient office infrastructure per Art. 6(1)(f) GDPR. A data processing agreement per Art. 28 GDPR is in place with Google; where data are transferred to the USA, this takes place on the basis of the EU-U.S. Data Privacy Framework or standard contractual clauses per Art. 46 GDPR.

Accounting with QuickBooks

For invoicing and accounting we use QuickBooks, a service of Intuit Inc. (privacy policy: https://www.intuit.com/privacy/statement/). There we process billing and payment data of our customers (e.g. name, address, services used, amounts). Processing takes place for contract handling per Art. 6(1)(b) GDPR and to comply with statutory retention obligations per Art. 6(1)(c) GDPR.

Automation services (Make, Zapier, n8n)

To connect our work tools with each other we use automation services, in particular Make (Celonis/make.com, EU; https://www.make.com/en/privacy-notice), Zapier (Zapier Inc., San Francisco, CA, USA; https://zapier.com/legal/data-privacy) and n8n. Personal data (e.g. name and email address from a form signup) may be transferred automatically between the services named in this privacy policy; the automation services only transport the data and do not use them for their own purposes. The legal bases are those of the respective originating processing and our legitimate interests in efficient workflows per Art. 6(1)(f) GDPR. Where data are transferred to the USA, this takes place on the basis of the EU-U.S. Data Privacy Framework or standard contractual clauses per Art. 46 GDPR.

Dictation software Wispr Flow

For our own work we use the dictation software Wispr Flow (Wispr AI, San Francisco, CA, USA; privacy policy: https://wisprflow.ai/privacy), which converts spoken language into text. Dictated content may contain personal data (e.g. names from customer communication). Processing takes place on the basis of our legitimate interests in an efficient way of working per Art. 6(1)(f) GDPR. We dictate only the content required for the respective task. Where data are transferred to the USA, this takes place on the basis of standard contractual clauses per Art. 46 GDPR.

Use of artificial intelligence (AI)

In our company, AI-supported tools are regularly used for analysis and evaluation — e.g. for evaluating surveys and feedback, preparing transcripts and recordings of our calls, analyzing business and usage data, and within our consulting and program services. In particular, we use Claude, an AI service of Anthropic PBC, San Francisco, CA, USA (privacy policy: https://www.anthropic.com/legal/privacy). Where personal data are processed (e.g. names, posts or content from the collaboration), this takes place to provide our contractual services per Art. 6(1)(b) GDPR or on the basis of our legitimate interests in efficient analysis, evaluation and quality assurance per Art. 6(1)(f) GDPR. We enter into AI systems only the data required for the respective purpose and pseudonymize data where possible. Transfers to the USA take place on the basis of standard contractual clauses per Art. 46 GDPR. No exclusively automated decision-making with legal effect within the meaning of Art. 22 GDPR takes place — we make decisions ourselves.

Communities: Skool

We run our paid premium community (AI Business Community) and our free community (“KI — aber richtig”) on the platform Skool (skool.com, USA; privacy policy: https://www.skool.com/legal?t=privacy). When you join one of our communities, you create a user account directly with Skool; the platform provider’s privacy terms apply additionally. Within the communities we process the profile data you provide (e.g. name, email address, profile picture) and your posts, comments and course progress in order to provide the community services (Art. 6(1)(b) GDPR). Skool processes data in the USA; transfers take place on the basis of the EU-U.S. Data Privacy Framework or standard contractual clauses per Art. 46 GDPR.

Testimonials with Senja

On our website we embed testimonials via the service Senja (senja.io; privacy policy: https://senja.io/privacy). When you open a page with embedded Senja content, your browser connects to Senja’s servers; your IP address and device information are transmitted for technical reasons. The embedding takes place on the basis of our legitimate interests in displaying genuine customer feedback per Art. 6(1)(f) GDPR. In addition, we process via Senja the reviews customers voluntarily give us (e.g. name, possibly photo, text or video testimonial) — the basis for this is the reviewer’s consent per Art. 6(1)(a) GDPR, revocable at any time with effect for the future. Where data are transferred to third countries, this takes place on the basis of standard contractual clauses per Art. 46 GDPR.

Video embedding with Wistia

On individual pages (e.g. “About me”) we embed videos via the service Wistia (Wistia, Inc., 17 Tudor Street, Cambridge, MA 02139, USA; privacy policy: https://wistia.com/privacy). When you open a page with an embedded Wistia video, your browser connects to Wistia’s servers; your IP address and device information are transmitted for technical reasons. The embedding takes place on the basis of our legitimate interests in an appealing presentation of our content per Art. 6(1)(f) GDPR. Where data are transferred to the USA, this takes place on the basis of standard contractual clauses per Art. 46 GDPR.

Administration, financial accounting, office organization, contact management

We process data in the context of administrative tasks, organization of our business, financial accounting and compliance with legal obligations such as archiving. In doing so, we process the same data we process in the course of providing our contractual services. The processing bases are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Customers, prospects, business partners and website visitors are affected by the processing. The purpose and our interest in the processing lie in administration, financial accounting, office organization and archiving of data — tasks that serve the maintenance of our business activities, performance of our tasks and provision of our services. We disclose or transmit data to the tax authorities, advisers such as tax consultants or auditors, and payment service providers.

Participation in affiliate partner programs

Within our online offering, on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offering) per Art. 6(1)(f) GDPR, we use industry-standard tracking measures where required for the operation of the affiliate system. Below we explain the technical background. The services offered by our contractual partners may also be advertised and linked on other websites (affiliate links or after-buy systems, e.g. where links or third-party services are offered after a contract is concluded). The operators of the respective websites receive a commission when users follow the affiliate links and then take up the offers. In summary, it is necessary for our online offering that we can track whether users who are interested in affiliate links and/or the offers available with us subsequently take up the offers at the prompting of the affiliate links or our online platform. For this purpose the affiliate links and our offers are supplemented with certain values that can be set as part of the link or elsewhere, e.g. in a cookie. The values include, in particular, the originating website (referrer), the time, an online identifier of the operator of the website hosting the affiliate link, an online identifier of the respective offer, an online identifier of the user, and tracking-specific values such as ad-material ID, partner ID and categorizations. The user online identifiers we use are pseudonymous values — they contain no personal data such as names or email addresses. They only help us determine whether the same user who clicked an affiliate link or showed interest in an offer via our online platform took up the offer, i.e. concluded a contract with the provider. The online identifier is, however, personal insofar as the partner company and we hold it together with other user data — only in this way can the partner company tell us whether the user took up the offer and we can pay out the bonus, for example.

Amazon partner program

On the basis of our legitimate interests (i.e. interest in the economic operation of our online offering within the meaning of Art. 6(1)(f) GDPR), we participate in the Amazon EU partner program, designed to provide websites with a medium for earning advertising fees by placing advertisements and links to Amazon.de (an affiliate system). As an Amazon partner, we earn from qualified purchases. Amazon uses cookies to trace the origin of orders — among other things, Amazon can recognize that you clicked the partner link on this website and then purchased a product from Amazon. Further information on Amazon’s data use and objection options is available in the company’s privacy policy: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010. Note: Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or one of its affiliates.

Contacting us

When you contact us (e.g. via contact form, email, phone or social media), the user’s details are processed to handle and process the contact request per Art. 6(1)(b) GDPR (within contractual/pre-contractual relationships) and Art. 6(1)(f) GDPR (other inquiries). Users’ details may be stored in a customer relationship management system (“CRM system”) or comparable inquiry organization. We delete inquiries once no longer required and review the necessity every two years; statutory archiving obligations also apply.

Newsletter

With the following notes we inform you about the content of our newsletter, the signup, dispatch and statistical evaluation procedures, and your rights of objection. By subscribing to our newsletter you agree to its receipt and the procedures described. Content of the newsletter: we send newsletters, emails and other electronic notifications containing promotional information (“newsletter”) only with the recipients’ consent or legal permission. Where the newsletter’s content is specifically described during signup, that description is decisive for the users’ consent. Otherwise our newsletters contain information about our services and us. Double opt-in and logging: signup to our newsletter uses a double opt-in procedure — after signing up you receive an email asking you to confirm your signup. This confirmation is necessary so that nobody can sign up with someone else’s email address. Newsletter signups are logged in order to prove the signup process in line with legal requirements. This includes storing the signup and confirmation times and the IP address; changes to your data stored with the dispatch service provider are also logged. Signup data: to sign up for the newsletter it is sufficient to provide your email address. Optionally, we ask you to provide a name for personal address in the newsletter. Dispatch of the newsletter and the associated performance measurement take place on the basis of the recipients’ consent per Art. 6(1)(a), Art. 7 GDPR in conjunction with Section 7(2) no. 3 UWG, or, where consent is not required, on the basis of our legitimate interests in direct marketing per Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG. Logging of the signup procedure takes place on the basis of our legitimate interests per Art. 6(1)(f) GDPR — our interest lies in a user-friendly, secure newsletter system that serves our business interests, meets users’ expectations and allows us to prove consent. Cancellation/revocation — you can cancel receipt of our newsletter at any time, i.e. revoke your consent. You will find a cancellation link at the end of every newsletter. We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove consent formerly given. The processing of these data is restricted to the purpose of possible defense against claims. An individual deletion request is possible at any time, provided the former existence of consent is confirmed at the same time.

Newsletter — dispatch service provider

The newsletter is dispatched via the dispatch service provider ActiveCampaign, LLC, 1 North Dearborn Street, 5th Floor, Chicago, IL 60602, USA (https://www.activecampaign.com). ActiveCampaign is a service for organizing and analyzing newsletter dispatch. The data you enter for the purpose of receiving the newsletter (e.g. email address, name) are processed on ActiveCampaign’s servers; transfers to the USA may occur. ActiveCampaign is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses per Art. 46(2)(c) GDPR are additionally in place. The dispatch provider’s privacy policy is available at: https://www.activecampaign.com/legal/privacy-policy. The dispatch provider is used on the basis of our legitimate interests per Art. 6(1)(f) GDPR and a data processing agreement per Art. 28(3) sentence 1 GDPR. The dispatch provider may use recipients’ data in pseudonymous form, i.e. without attribution to a user, to optimize or improve its own services, e.g. for technical optimization of dispatch and display of the newsletter or for statistical purposes. However, the dispatch provider does not use our newsletter recipients’ data to write to them itself or to pass the data on to third parties.

Newsletter — performance measurement

The newsletters contain a “web beacon”, i.e. a pixel-sized file retrieved when the newsletter is opened from our server or, where we use a dispatch service provider, from its server. As part of this retrieval, technical information such as browser and system details, your IP address and the time of retrieval are initially collected. This information is used for the technical improvement of the services based on the technical data or the target groups and their reading behavior based on retrieval locations (determinable via IP address) or access times. The statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons this information can be attributed to individual newsletter recipients; however, it is neither our aim nor, where used, that of the dispatch service provider to observe individual users. The evaluations serve us far more to recognize our users’ reading habits and to adapt our content to them or send different content according to our users’ interests. A separate revocation of the performance measurement is unfortunately not possible; in that case, the entire newsletter subscription must be cancelled.

Hosting and email dispatch

This website is hosted by Hostinger (Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus; https://www.hostinger.de). Hostinger’s privacy policy is available at https://www.hostinger.com/legal/privacy-policy. The hosting services we use serve to provide the following: infrastructure and platform services, computing capacity, storage and database services, email dispatch, security services and technical maintenance services we use to operate this online offering. In doing so, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, prospects and visitors of this online offering on the basis of our legitimate interests in efficient and secure provision of this online offering per Art. 6(1)(f) GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement). Collection of access data and log files: we or our hosting provider collect, on the basis of our legitimate interests within the meaning of Art. 6(1)(f) GDPR, data about every access to the server on which this service is located (server log files). Access data include the name of the retrieved web page, file, date and time of retrieval, amount of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider. Log file information is stored for security reasons (e.g. to investigate misuse or fraud) for a maximum of 7 days and then deleted. Data whose further retention is required for evidentiary purposes are exempt from deletion until final clarification of the respective incident.

Google Analytics

We use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). It is used only if you have consented (Art. 6(1)(a) GDPR); you can revoke your consent at any time with effect for the future. Google Analytics uses cookies or comparable recognition technologies that enable an analysis of the use of our online offering. The information generated may be transferred to Google servers — including in the USA — and stored there. Google LLC is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses per Art. 46 GDPR are additionally in place. In Google Analytics 4, IP addresses are by default not logged or stored, only used for rough geographic attribution and truncated or discarded before storage. Google processes the information on our behalf to evaluate the use of our online offering, compile reports on activity and provide us with further related services; pseudonymous usage profiles may be created. Users’ personal data are deleted or anonymized after 14 months. You can additionally prevent collection by Google Analytics by installing the browser add-on available at: https://tools.google.com/dlpage/gaoptout?hl=de. Further information on Google’s data use is available in Google’s privacy policy (https://policies.google.com/privacy) and at https://policies.google.com/technologies/partner-sites.

Umami (reach measurement)

For statistical evaluation of access to this online offering we use Umami, a cookieless, privacy-friendly web analytics software (https://umami.is). We host Umami ourselves on our own server in Germany; no data are transferred to third parties or third countries (e.g. USA). Umami uses no cookies and stores no information on your device. Nor are any personal data stored permanently: from IP address, browser and operating system only an anonymous, irreversible numeric value (hash) is formed to roughly count visits; the IP address itself is not stored, and the value used to form the hash changes daily. Anonymous usage data are collected, such as pages viewed, approximate origin (country), referring page and browser and device type. The legal basis is our legitimate interest in data-minimizing reach measurement to improve our offering per Art. 6(1)(f) GDPR. Since Umami uses no cookies or comparable technologies on your device, no consent is required for this. You have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR); a message to the contact details in the legal notice suffices.

Google Fonts (local embedding)

For a uniform presentation, this website uses the fonts “DM Sans” and “Space Mono” (Google Fonts). The font files are embedded locally on our server. No connection to Google servers is established when this website is accessed; no data are transferred to Google in this respect.

Version of this privacy policy: July 2026