1. An overview of data protection
General information
The following information provides an easy overview of what happens to your personal data when you visit this website. "Personal data" comprises all data that can be used to identify you personally. For detailed information, please consult the declaration below.
Data recording on this website
Who is responsible for the recording of data on this website?
The data on this website is processed by the operator of the website, whose contact details appear under "Information about the responsible party" below.
How do we record your data?
We collect data that you share with us — for instance information you enter into the booking form. Other data is recorded automatically by our IT systems when you visit the website. This is primarily technical information such as your web browser, operating system, or the time the page was accessed.
What do we use your data for?
Part of the information is collected to ensure error-free provision of the website. Other data may be used to analyse how the site is used.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipients and purpose of your stored personal data at any time, free of charge. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you may revoke it at any time with effect for the future. You further have the right to request restriction of processing under certain circumstances, and to lodge a complaint with the competent supervisory authority.
Please contact us at any time if you have questions about this or any other data protection matter.
2. Hosting
External hosting
This website is hosted externally. Personal data collected on this website is stored on the servers of the host. This may include IP addresses, contact requests, metadata and communications, contract information, contact details, names, page access data and other data generated through a website.
External hosting serves the purpose of fulfilling our contract with potential and existing customers (Art. 6(1)(b) GDPR) and the interest of secure, fast and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR). Where consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on your device. This consent may be revoked at any time.
Our host processes your data only to the extent necessary to fulfil its performance obligations and follows our instructions with respect to that data.
Current host: Contabo GmbH · Aschauer Straße 32a · 81549 München · Germany
3. General information and mandatory disclosures
Data protection
The operator of this website takes the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
We point out that data transmission over the internet — for example when communicating by e-mail — can have security gaps. Complete protection of data against access by third parties is not possible.
Information about the responsible party
The controller for data processing on this website is:
Sven Rogge c/o Impressumservice Dein-Impressum.de Stettiner Str. 41 35410 Hungen, Germany [email protected]
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
Storage duration
Unless a more specific storage period is stated in this privacy policy, your personal data remains with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent, your data will be deleted unless we have other legally permissible grounds for storing it, such as retention periods under tax or commercial law. In the latter case, deletion takes place once those grounds cease to apply.
Legal bases for processing
If you have consented to processing, we process your personal data on the basis of Art. 6(1)(a) GDPR, or Art. 9(2)(a) GDPR where special categories of data are processed. Where you have consented to the storage of cookies or access to information on your device, processing is additionally based on § 25(1) TDDDG. Consent may be revoked at any time. Where your data is required to perform a contract or to carry out pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. Where processing is necessary to fulfil a legal obligation, we rely on Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Recipients of personal data
In the course of our business we work with various external parties, which sometimes requires transferring personal data to them. We only disclose personal data to external parties where this is required to perform a contract, where we are legally obliged to do so, where we have a legitimate interest pursuant to Art. 6(1)(f) GDPR, or where another legal basis permits it. Where processors are used, we disclose personal data only on the basis of a valid data processing agreement.
4. Booking a call
When you request a call, we process your name, e-mail address, selected time, optional project description and survey interests in order to arrange the requested pre-contractual service (Art. 6(1)(b) GDPR). The booking is stored in our database and a calendar invitation is created through Google Calendar. Depending on your choice it contains a Google Meet link or a private browser-video link to our MiroTalk P2P instance. Google receives the attendee e-mail address and appointment details as a processor. MiroTalk processes signalling and connection metadata; call media is exchanged directly between participants where the network permits.
A browser-video link contains a signed access token generated by our booking backend. The MiroTalk API key is never sent to your browser. Access tokens expire when the scheduled call ends; expired links cannot create or join the room.
Cloudflare Turnstile is loaded only as a managed, interaction-only abuse check. Cloudflare receives its verification token and limited technical data in order to prevent automated submissions. We retain peppered hashes of IP addresses and normalised e-mail addresses only in short-lived rate-limit buckets. We do not log tokens, calendar response bodies or credentials.
Booking records, signed room links and related survey data are deleted 90 days after the call, and the corresponding Google event is deleted where possible. Only anonymous aggregate booking-status metrics remain. Retention by providers is governed by Google's, MiroTalk's and Cloudflare's own terms.
5. Your rights
Revocation of your consent
Many data processing operations are possible only with your express consent. You may revoke consent you have already given at any time. The lawfulness of processing carried out before the revocation remains unaffected.
Right to object (Art. 21 GDPR)
Where data is processed on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object at any time to the processing of your personal data on grounds relating to your particular situation. This also applies to profiling based on those provisions. If you object, we will no longer process the affected personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or where processing serves to establish, exercise or defend legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time. If you object, your personal data will no longer be used for direct marketing.
Right to lodge a complaint
In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work, or the place of the alleged breach.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. Direct transfer to another controller will be carried out only where technically feasible.
Information, correction and deletion
Within the scope of applicable law, you have the right at any time to information about your stored personal data, its origin and recipients, and the purpose of processing, as well as a right to correction or deletion of that data.
Right to restriction of processing
You have the right to request restriction of the processing of your personal data. This right applies in the following cases:
- If you dispute the accuracy of your data stored by us, we usually need time to verify this. For the duration of the review, you have the right to request restriction of processing.
- If the processing of your personal data was or is unlawful, you may request restriction of processing instead of deletion.
- If we no longer need your personal data but you need it to exercise, defend or establish legal claims, you have the right to request restriction instead of deletion.
- If you have objected pursuant to Art. 21(1) GDPR, your interests and ours must be weighed. For as long as it is not clear whose interests prevail, you have the right to request restriction of processing.
If you have restricted processing, the data — apart from being stored — may be processed only with your consent, or to establish, exercise or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest.
6. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the address bar changing from "http://" to "https://" and by the lock icon in your browser. When encryption is active, the data you transmit to us cannot be read by third parties.