GDPR · BDSG · TDDDG

Privacy Policy

Last updated: 1 September 2026

This is a translation provided for convenience. The German version is the legally binding text; in case of any discrepancy, the German wording prevails. References to statutes are to German law.

With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to as „data“) we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the „online offering“).

The terms used are not gender-specific.

Table of contents

Controller

Kai Hackbarth, Hagener Straße 67, 58285 Gevelsberg, Germany

Email address: kai@kaihackbarth.com

Telephone: +49 176 45151099

Legal notice: kaihackbarth.com/imprint

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of data processed

Categories of data subjects

Purposes of processing

Relevant legal bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in an individual case, we will inform you of these in this privacy policy.

National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection rules apply in Germany. These include in particular the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). The BDSG contains special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transfer, as well as automated decision-making in individual cases including profiling. Data protection acts of the individual federal states may also apply.

Security measures

In accordance with the statutory requirements and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input of, disclosure of, assurance of availability of and separation of the data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the erasure of data and responses to threats to data. We also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.

Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services against unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data against unauthorised access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator to users that their data is transmitted securely and in encrypted form.

Transfer of personal data

In the course of our processing of personal data, it may happen that such data is transferred to, or disclosed to, other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content that are integrated into a website. In such cases we observe the statutory requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.

International data transfers

Data processing in third countries: Insofar as we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or this occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies (which is apparent from the postal address of the respective provider or where the privacy policy expressly refers to a data transfer to third countries), this is always done in accordance with the statutory requirements.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission of 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers which comply with the requirements of the EU Commission and set out contractual obligations to protect your data.

This twofold safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, while the standard contractual clauses serve as additional security. Should changes arise in the context of the DPF, the standard contractual clauses take effect as a reliable fallback. In this way we ensure that your data remains adequately protected even in the event of political or legal changes.

For each individual service provider we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.

For data transfers to other third countries, appropriate safeguards apply, in particular standard contractual clauses, explicit consent or transfers required by law. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: European Commission, international dimension of data protection.

General information on data storage and erasure

We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consent is withdrawn or no further legal bases for the processing exist. This concerns cases in which the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply where statutory obligations or particular interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.

Where there are several specifications regarding the retention period or erasure deadlines for a data item, the longest period is always decisive. Data that is no longer retained for the originally intended purpose but on account of statutory requirements or other reasons is processed by us exclusively for the reasons that justify its retention.

Retention and erasure of data: The following general periods apply to retention and archiving under German law:

Start of the period at the end of the year: If a period does not expressly begin on a specific date and is at least one year, it starts automatically at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the context of which data is stored, the event triggering the period is the point in time at which the termination or other ending of the legal relationship takes effect.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

Reach measurement (Vercel Web Analytics)

We measure the reach of our online offering using Vercel Web Analytics, a service provided by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.

The data recorded comprises the pages accessed, the referring source, the approximate region of origin at country level, and device type, operating system and browser. Evaluation is carried out exclusively in aggregate form.

The service operates without cookies and does not store or read any information on your device. No user profiles are created, no returning visitors are recognised and no data is combined across different websites. Identification of individual persons is neither intended nor possible. We do not use A/B testing or comparable testing procedures.

As no access to your device takes place, consent under Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act) is not required. The legal basis is our legitimate interest in the statistical evaluation of usage and the improvement of our offering pursuant to Art. 6(1)(f) GDPR.

Purpose: reach measurement. Types of data processed: usage data as well as meta and communication data. Data subjects: users. Retention: no individual personal records are kept; the evaluations are aggregated.

Transfer to the USA takes place on the basis of standard contractual clauses. Data processing agreement: vercel.com/legal/dpa — provider's privacy policy: vercel.com/legal/privacy-policy

Embedded videos (YouTube)

On our „Speaking“ page, a video hosted on YouTube is embedded. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The video is only loaded once you expressly start playback by clicking. Before this click, no data is transmitted to YouTube and no connection to Google is established.

We use the extended data protection mode (youtube-nocookie.com). In this mode, according to YouTube's own statements, no cookies are set for advertising purposes as long as no video is played. When playback starts, your IP address and information about your device and browser are transmitted to Google; if you are logged in to Google, the usage may be associated with your account.

The legal basis is our legitimate interest in an appealing presentation of our offering pursuant to Art. 6(1)(f) GDPR.

Provider's privacy policy: business.safety.google/privacy

Language preference in browser storage

This website remembers your language selection in an entry in your browser's local storage (localStorage) under the name kh-lang. The entry is set exclusively by your own use of the language switch, contains no personal data, is not transmitted and does not enable recognition.

It is therefore strictly necessary for the service expressly requested by you within the meaning of Section 25(2) no. 2 TDDDG; consent is not required. You can delete it at any time via your browser settings. We do not use any other cookies or comparable storage technologies.

Business services

We process personal data of our contractual and business partners, such as customers, clients, prospective clients, suppliers and other cooperation partners (collectively „contractual partners“), for the initiation, performance and settlement of contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken upon request as well as communication in connection with the respective contractual relationship.

The processing serves in particular to fulfil our primary and ancillary contractual obligations. These include the provision of the agreed services, any update and information obligations, the handling of warranty claims and other performance issues, the processing of withdrawals, terminations of continuing obligations, reversals and refunds, as well as the handling of other contract-related declarations and enquiries. This covers both one-off contracts and ongoing contractual relationships.

The data processed includes in particular master data such as name, address and, where applicable, company; contact data such as email address and telephone number; contract and service data such as subject matter of the contract, contract term, order or transaction number; usage and service data; payment and billing data; as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of carrying out an assignment.

In addition, we process the data to safeguard our rights and to comply with legal obligations. This includes in particular commercial and tax law retention obligations, documentation obligations and, where applicable, obligations of proof and accountability. Processing also takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners against misuse, endangerment of data, trade secrets and other legally protected interests. This may also involve engaging external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisers or other vicarious agents, insofar as this is necessary for the performance of the contract or to comply with legal obligations.

Personal data is only passed on to third parties where this is necessary for the performance of the contract, for pre-contractual measures, to safeguard legitimate interests or to comply with legal obligations. We provide separate information within this privacy policy about any processing that goes beyond this, in particular for marketing purposes.

We inform contractual partners which data is required in an individual case at the time of collection, for example through corresponding labelling in online forms or in personal contact.

Data is erased as soon as it is no longer required for the aforementioned purposes and no statutory retention obligations conflict with erasure. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the context of a specific assignment is erased by us after completion of the assignment and expiry of any retention periods, provided that no further statutory or contractual storage obligations exist.

The legal basis for the processing is Art. 6(1)(b) GDPR for carrying out pre-contractual measures and performing the respective contractual relationship, and Art. 6(1)(c) GDPR for compliance with legal obligations. Insofar as the processing is based on legitimate interests, it takes place on the basis of Art. 6(1)(f) GDPR. Where processing is based on Art. 6(1)(f) GDPR, it serves our legitimate interests in proper and efficient business organisation, the internal administration and documentation of business transactions, the assertion and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, and the commercial management and further development of our business operations. These interests consist in particular in ensuring secure and legally compliant business operations and in preserving our entrepreneurial capacity to act.

Further information on processing operations, procedures and services:

Business processes and procedures

Personal data of recipients of services and principals — including customers, clients or, in specific cases, mandators, patients or business partners as well as further third parties — is processed in the context of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates commercial procedures in areas such as customer management, sales, payment transactions, accounting and project management.

The data collected serves to fulfil contractual obligations and to design operational processes efficiently. This includes the handling of business transactions, the management of customer relationships, the optimisation of sales strategies and the assurance of internal invoicing and financial processes. In addition, the data supports the safeguarding of the controller's rights and promotes administrative tasks and the organisation of the business.

Personal data may be passed on to third parties insofar as this is necessary to fulfil the stated purposes or legal obligations. Once statutory retention periods have expired or the purpose of processing ceases to apply, the data is erased. This also includes data that must be stored for longer due to tax law and statutory evidence obligations.

Further information on processing operations, procedures and services:

Provision of the online offering and web hosting

We process users' data in order to be able to provide them with our online services. For this purpose we process the user's IP address, which is necessary in order to transmit the content and functions of our online services to the user's browser or device.

Further information on processing operations, procedures and services:

Contact and enquiry management

When you contact us (e.g. by post, contact form, email, telephone or via social media) as well as in the context of existing user and business relationships, the details of the enquiring person are processed insofar as this is necessary to respond to the contact enquiries and any measures requested.

Further information on processing operations, procedures and services:

Artificial intelligence (AI)

We use artificial intelligence (AI), in the course of which personal data is processed. The specific purposes and our interest in using AI are set out below. By AI we mean, in accordance with the concept of an „AI system“ under Article 3(1) of the AI Act, a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.

Our AI systems are used in strict compliance with the statutory requirements. These comprise both specific rules for artificial intelligence and data protection requirements. In doing so, we observe in particular the principles of lawfulness, transparency, fairness, human oversight, purpose limitation, data minimisation and integrity and confidentiality. We ensure that the processing of personal data always takes place on a legal basis. This may be either the consent of the data subjects or a statutory permission.

When using external AI systems, we select their providers (hereinafter „AI providers“) carefully. In accordance with our statutory obligations, we ensure that the AI providers comply with the applicable provisions. We likewise observe the obligations incumbent upon us when using or operating the AI services obtained. The processing of personal data by us and the AI providers takes place exclusively on the basis of consent or statutory authorisation. We attach particular importance to transparency, fairness and the preservation of human oversight of AI-supported decision-making processes.

To protect the data processed, we implement appropriate and robust technical and organisational measures. These ensure the integrity and confidentiality of the data processed and minimise potential risks. Through regular reviews of the AI providers and their services, we ensure ongoing compliance with current legal and ethical standards.

Further information on processing operations, procedures and services:

Cloud services

We use software services accessible via the internet and executed on the servers of their providers (so-called „cloud services“, also referred to as „software as a service“) for the storage and management of content (e.g. document storage and management, exchange of documents, content and information with specific recipients, or publication of content and information).

In this context, personal data may be processed and stored on the providers' servers, insofar as such data forms part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include, in particular, master data and contact data of users, data on transactions, contracts, other processes and their content. The providers of the cloud services also process usage data and metadata, which they use for security purposes and service optimisation.

Insofar as we use cloud services to provide forms or other documents and content for other users or publicly accessible websites, the providers may store cookies on users' devices for the purposes of web analysis or in order to remember user settings (e.g. in the case of media controls).

Further information on processing operations, procedures and services:

Newsletter and electronic notifications

We send newsletters, emails and other electronic notifications (hereinafter „newsletter“) exclusively with the consent of the recipients or on a statutory basis. Where the contents of a newsletter are described during sign-up, those contents are decisive for the users' consent. To sign up for our newsletter it is normally sufficient to provide your email address. However, in order to be able to offer you a personalised service, we may ask you to provide your name so that you can be addressed personally in the newsletter, or for further information if this is necessary for the purpose of the newsletter.

Erasure and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to demonstrate consent previously given. The processing of this data is restricted to the purpose of potentially defending against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist.

The sign-up procedure is logged on the basis of our legitimate interests for the purpose of demonstrating that it was carried out properly. Insofar as we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure sending system.

Contents: Information about us, our services, campaigns and offers.

Further information on processing operations, procedures and services:

Presence on social networks (social media)

We maintain online presences within social networks and, in this context, process user data in order to communicate with users active there or to offer information about us.

We point out that user data may be processed outside the European Union in this context. This may give rise to risks for users, because, for example, the enforcement of users' rights could be made more difficult.

Furthermore, users' data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created on the basis of usage behaviour and the resulting interests of users. These profiles may in turn be used to place advertisements inside and outside the networks that are presumed to correspond to users' interests. For this reason, cookies are generally stored on users' computers, in which usage behaviour and users' interests are stored. Moreover, data may also be stored in the usage profiles independently of the devices used by the users (in particular if they are members of the respective platforms and logged in there).

For a detailed description of the respective forms of processing and the options to object (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.

In the case of requests for access and the assertion of data subject rights, we also point out that these can be asserted most effectively with the providers. Only the latter have access to users' data in each case and can take appropriate measures and provide information directly. Should you nevertheless require assistance, you may contact us.

Further information on processing operations, procedures and services:

Management, organisation and support tools

We use services, platforms and software of other providers (hereinafter referred to as „third-party providers“) for the purposes of organisation, administration, planning and the provision of our services. When selecting third-party providers and their services, we observe the statutory requirements.

In this context, personal data may be processed and stored on the servers of the third-party providers. This may affect various types of data that we process in accordance with this privacy policy. Such data may include, in particular, master data and contact data of users, data on transactions, contracts, other processes and their content.

Insofar as users are referred to third-party providers or their software or platforms in the context of communication, business or other relationships with us, the third-party providers may process usage data and metadata for security purposes, service optimisation or marketing purposes. We therefore ask you to observe the privacy notices of the respective third-party providers.

Further information on processing operations, procedures and services:

Amendment and updating

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.

Insofar as we provide addresses and contact information of companies and organisations in this privacy policy, please note that addresses may change over time and we ask you to verify the details before making contact.

Competent supervisory authority

The supervisory authority responsible for us:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
(State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Postfach 20 04 44
40102 Düsseldorf, Germany
Telephone: +49 211 38424-0
Email: poststelle@ldi.nrw.de

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Where the terms are defined by law, the statutory definitions apply. The following explanations are intended primarily to aid understanding.

Legal text created with the privacy policy generator by Dr. Schwenke. English translation provided for convenience; the German version prevails.

← Back to home