Privacy Policy

Person in Charge

The data controller within the meaning of the General Data Protection Regulation (GDPR) is:

Aris Hägermann 

Email: [email protected]

Address: Nernstweg 14, 22765 Hamburg

General Information on Data Processing

The protection of your personal data is very important to us. We always process personal data in accordance with the General Data Protection Regulation (GDPR) and the relevant national data protection laws.

In this Privacy Policy, we inform you about what personal data we collect and process in connection with your use of our website and our services.

SSL or TLS encryption

This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential information. You can recognize an encrypted connection by the fact that the address bar of your browser changes from „http://“ to „https://“ and by the padlock icon in your browser’s address bar.

Hosting

Our website is hosted by Namecheap, Inc. (EasyWP). When you visit our website, the hosting provider automatically collects information in what are known as server log files. This includes:

  • IP address of the accessing computer
  • Date and time of access
  • Name and URL of the retrieved file
  • Amount of Data Transferred
  • Browser and Operating System Used
  • Referrer URL (the previously visited page)

This data is collected to ensure the smooth operation of the website and to detect and prevent misuse.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the provision and security of our website.

Namecheap, Inc. is headquartered in the United States. Data is transferred to the United States in accordance with the EU-U.S. Data Privacy Framework. For more information, please see Namecheap’s Privacy Policy at https://www.namecheap.com/legal/general/privacy-policy/.

Content Delivery Network (Cloudflare)

We use the Content Delivery Network (CDN) provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare offers a globally distributed content delivery network with DNS. Technically, the transfer of information between your browser and our website is routed through Cloudflare’s network. This enables Cloudflare to analyze the data traffic between users and our website in order, for example, to detect and block attacks on our website.

In addition, Cloudflare may store cookies on your device to ensure the security of the website and to detect bots (see also the „Cookies“ section of this Privacy Policy).

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and efficient operation of our website.

Cloudflare, Inc. is headquartered in the United States. Data is transferred to the United States in accordance with the EU-U.S. Data Privacy Framework. For more information, please see Cloudflare’s Privacy Policy at https://www.cloudflare.com/privacypolicy/.

Cookies and Consent Management

To manage the cookies and similar technologies (tracking pixels, web beacons, etc.) we use, as well as the associated consents, we utilize the consent tool „Real Cookie Banner.“ For details on how „Real Cookie Banner“ works, please visit https://devowl.io/rcb/data-processing/.

The legal basis for the processing of personal data in this context is Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR. Our legitimate interest consists in managing the cookies and similar technologies used, as well as the associated consents.

Providing personal data is neither contractually required nor necessary for entering into a contract. You are not obligated to provide personal data. If you do not provide personal data, we will not be able to manage your consents.

For a detailed overview of the cookies used on this website, please see our Cookie Policy at [insert link to Cookie Policy].

Security Plugin (Wordfence)

To protect our website from unauthorized access and cyberattacks, we use the Wordfence security plugin from Defiant, Inc., 800 5th Avenue, Suite 4100, Seattle, WA 98104, USA. Wordfence uses cookies to, among other things, recognize authenticated users and identify suspicious login activity (see Cookie Policy).

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in protecting our website from misuse and attacks.

For more information, please see Defiant's Privacy Policy at https://www.wordfence.com/privacy-policy/.

Appointment Scheduling (Amelia)

We use the Amelia plugin from TMS Starter d.o.o., Belgrade, Serbia, for online appointment scheduling. When you schedule an appointment, the following personal data is collected:

  • First and Last Name
  • Email address
  • Phone number (if applicable)
  • Selected Date and Service
  • Any additional information you may provide on the booking form

This data is processed solely for the purpose of scheduling and managing appointments.

The legal basis is Article 6(1)(b) of the GDPR (implementation of precontractual measures) and Article 6(1)(f) of the GDPR (legitimate interest in efficient appointment management).

The data is stored on our own server and is not shared with third parties unless it is necessary to fulfill the terms of the contract.

Contacting Us by Email

If you contact us by email, we will store and process the information you provide (e.g., your name, email address, and the content of your message) in order to respond to your inquiry.

The legal basis is Article 6(1)(b) of the GDPR (if your inquiry is related to entering into a contract) or Article 6(1)(f) of the GDPR (legitimate interest in processing inquiries). We will delete the data collected in this context once storage is no longer necessary, or restrict its processing if statutory retention periods apply.

Google Fonts

This website uses Google Fonts, which are stored locally on our server. No connection is made to Google's servers, and no personal data is transmitted to Google.

Data Transfer to Third Countries

Some of the service providers mentioned in this Privacy Policy are based in the United States (Namecheap, Cloudflare, Defiant/Wordfence). The transfer of personal data to the United States is based on the European Commission’s Adequacy Decision regarding the EU-U.S. Data Privacy Framework pursuant to Article 45 of the GDPR, provided that the respective companies are certified under the Data Privacy Framework. In addition, we rely on standard contractual clauses pursuant to Article 46(2)(c) of the GDPR.

Rights of Data Subjects

Under applicable law, you have the following rights:

Right of Access (Art. 15 of the GDPR): You have the right to request confirmation as to whether we are processing your personal data and, if so, to receive information about that data.

Right to Rectification (Art. 16 of the GDPR): You have the right to request the correction of inaccurate personal data or the completion of incomplete personal data.

Right to Erasure (Art. 17 of the GDPR): You have the right to request the deletion of your personal data, provided that the legal requirements are met.

Right to Restriction of Processing (Art. 18 GDPR): You have the right to request that the processing of your data be restricted if certain conditions are met.

Right to Data Portability (Art. 20 of the GDPR): You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format, or to request that it be transferred to another controller.

Right to Object (Art. 21 of the GDPR): If your personal data is processed on the basis of Article 6(1)(f) of the GDPR, you have the right to object to the processing if there are grounds for doing so that arise from your particular situation.

Right to Withdraw Consent (Art. 7(3) of the GDPR): You have the right to withdraw your consent at any time, effective for the future. The lawfulness of the processing carried out on the basis of your consent up until the time of withdrawal remains unaffected.

Right to File a Complaint with a Supervisory Authority (Art. 77 of the GDPR): Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR.

Current Status and Changes to This Privacy Policy

This Privacy Policy is current as of [insert date]. Due to changes in legal or regulatory requirements or further development of our website, it may become necessary to amend this Privacy Policy. The most current version of the Privacy Policy is available on this page at any time.