GDPR

Privacy policy

This privacy policy informs you about the nature, scope and purpose of the processing of personal data on this website in accordance with the General Data Protection Regulation (GDPR).

This English version is a convenience translation. The German version is legally binding.

1. Controller

Jan Otte
Rheingutstraße 4
78462 Konstanz
Deutschland
USt-IdNr.: DE340429114

2. Types of data processed

  • Master data (e.g. names, addresses)
  • Contact data (e.g. email, phone numbers)
  • Content data (e.g. text entered in enquiries)
  • Usage data (e.g. pages visited, access times)
  • Meta / communication data (e.g. device information, IP addresses)
  • Quick-check data (answers to the future check, everyday check and outside check, where you complete them)

Data subjects are the visitors and users of this online service (hereinafter collectively “users”).

3. Purpose of processing

  • Provision of the online service, its functions and content
  • Answering contact enquiries and communicating with users
  • Analysis of anonymised quick-check answers to improve the service
  • Security measures to protect the website

4. Relevant legal bases

In accordance with Art. 13 GDPR, the legal bases for the data processing are set out here:

  • Art. 6(1)(a) GDPR — consent
  • Art. 6(1)(b) GDPR — performance of a contract and pre-contractual enquiries
  • Art. 6(1)(c) GDPR — compliance with legal obligations
  • Art. 6(1)(f) GDPR — protection of legitimate interests

5. Security measures

Appropriate technical and organisational measures are taken in accordance with Art. 32 GDPR to ensure a level of protection appropriate to the risk. These include in particular the confidentiality, integrity and availability of data through control of physical access, transfer, securing of availability and separation. Transmission is SSL/TLS-encrypted.

6. Rights of data subjects

You have the following rights vis-à-vis us:

  • Right of access (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Withdrawal of consent given (Art. 7(3) GDPR)
  • Right to object (Art. 21 GDPR)
  • Complaint to a supervisory authority (Art. 77 GDPR) — competent in Baden-Württemberg: the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg

7. Server log files

On the basis of legitimate interests (Art. 6(1)(f) GDPR), the hosting provider collects data about every access to the server (so-called server log files). This data includes:

  • Name of the file and web page retrieved
  • Date and time of the retrieval
  • Volume of data transferred
  • Notification of successful retrieval
  • Browser type and version
  • User's operating system
  • Referrer URL (previously visited page)
  • IP address and the requesting provider

For security reasons (e.g. to investigate misuse or fraud), log file information is stored for a maximum of 7 days and then deleted. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified.

8. Google Fonts

To display fonts consistently, this website uses so-called web fonts provided by Google (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). “Schibsted Grotesk” and “Hanken Grotesk” are used. When you call up a page, your browser loads the required web fonts into the browser cache in order to display text and fonts correctly.

For this purpose, the browser you use must connect to Google's servers. This means Google becomes aware that this website was accessed via your IP address. Google Fonts is used in the interest of a consistent and appealing presentation of the online service. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.

Further information: developers.google.com/fonts/faq · Google's privacy policy: policies.google.com/privacy

9. Calendly (online appointment booking)

To arrange initial and quick-check appointments, we use the Calendly service from Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. When you book an appointment, Calendly processes the data you provide (e.g. name, email address, preferred time and technical connection data) on our behalf in order to carry out the booking and send reminders.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (efficient appointment organisation). The Calendly booking widget is only loaded when you actively call it up. Cookies may be set in the process. A transfer to the USA may occur; Calendly relies on the EU standard contractual clauses. A data processing agreement is in place with Calendly.

Further information: calendly.com/privacy

10. Form submission (n8n) & email delivery (Brevo)

To transmit our forms (e.g. direct application, practice checks), we use the workflow platform n8n (n8n GmbH, Berlin). The data you enter (e.g. name, practice, email address, phone number, message and your check answers) is transmitted to our n8n instance and processed there to handle your request and to create and deliver your evaluation. Only the data you actively enter is processed.

To deliver emails (e.g. evaluation report, confirmation emails), we use Brevo (Sendinblue GmbH, Berlin). Every such email contains an unsubscribe option; after unsubscribing you will not receive any further emails from us.

The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual measures) or Art. 6(1)(a) GDPR (consent, e.g. for check delivery). Data processing agreements are in place with both providers; processing takes place within the EU.

Further information: n8n.io/legal/privacy · brevo.com/legal/privacypolicy

11. Google Workspace & Google Meet

For internal collaboration, email communication, document storage and video calls, we use Google Workspace and Google Meet from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). Where you contact us by email or hold a video call with us (e.g. for the quick check), the resulting content and connection data is processed via Google.

The legal basis is Art. 6(1)(b) GDPR (performance of pre-contractual measures and communication) and Art. 6(1)(f) GDPR (legitimate interest in an efficient, secure working environment); for video calls, additionally your consent under Art. 6(1)(a) GDPR through participation. A transfer to the USA is possible; Google is certified under the EU-US Data Privacy Framework, and the EU standard contractual clauses apply in addition. A data processing agreement is in place with Google.

Further information: policies.google.com/privacy

12. Cookies & localStorage

This website itself sets no cookies for tracking, analysis or advertising. Nor are any third-party services integrated that store cookies on your device (no Google Analytics, no social-media tracking, no advertising networks).

This website only uses browserlocalStorage to store your preferences locally (e.g. the chosen colour scheme “light/dark” and the splash status). This information remains exclusively in your browser and is not transferred to our servers.

14. Contact

When you contact the provider (by email, phone or via the quick-check and direct-application forms), your details are processed to handle the enquiry and in case of follow-up questions pursuant to Art. 6(1)(b) GDPR. We delete enquiries once they are no longer required. The necessity is reviewed every two years; statutory archiving obligations remain unaffected.

On this and other matters, you can contact us at any time using the contact options listed in the imprint.