Privacy Policy

Preamble

With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). The terms used are not gender-specific. Last updated: 4 February 2026

Table of contents

Responsible

Maibach Digital GmbH
Beimoorweg 3
22927 Großhansdorf
Authorised representatives:
Paul Maibach, Sebastian Schmidt
Email address:
info@maibach.digital

Applicable legal bases

Applicable legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in an individual case, we will inform you of these in this privacy policy.
  • Consent (Article 6(1)(a) GDPR) – The data subject has given consent to the processing of personal data concerning them for one or more specific purposes.
  • Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legitimate interests (Article 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection rules apply in Germany. These include in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transfer, as well as automated decision-making in individual cases including profiling. State data protection acts of the individual federal states may also apply. Note on the applicability of the GDPR and the Swiss FADP: This privacy notice serves to provide information both under the Swiss Federal Act on Data Protection (Swiss FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that the terminology of the GDPR is used because of its broader geographical application and general familiarity. In particular, instead of the terms “processing” of “personal data”, “overriding interest” and “particularly sensitive personal data” used in the Swiss FADP, the GDPR terms “processing” of “personal data”, “legitimate interest” and “special categories of data” are used. The legal meaning of these terms continues, however, to be determined by the Swiss FADP where that act applies.

Overview of processing operations

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of data processed

  • Contact data.
  • Content data.
  • Usage data.
  • Meta, communication and procedural data.

Categories of data subjects

  • Communication partners.
  • Users.

Purposes of processing

  • Contact enquiries and communication.
  • Security measures.
  • Management and response to enquiries.
  • Feedback.
  • Provision of our online offering and user-friendliness.
  • Information technology infrastructure.

Security measures

In accordance with the legal requirements, and taking into account the state of the art, the cost of implementation and the nature, scope, circumstances and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk. These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, availability and separation relating to it. We have also established procedures that ensure the exercise of data subject rights, the erasure of data and responses to data breaches. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in line with the principle of data protection by design and by default. TLS encryption (https): To protect the data you transmit via our online offering, we use TLS encryption. You can recognise such encrypted connections by the prefix https:// in the address bar of your browser.

Transfer of personal data

In the course of our processing of personal data, it may happen that the data is transferred to, or disclosed to, other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases we observe the legal requirements and in particular conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.

International data transfers

Data processing in third countries: Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where processing takes place in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies, this is done only in accordance with the legal requirements. Subject to express consent or a transfer required by contract or law (see Article 49 GDPR), we process the data, or allow it to be processed, only in third countries with a recognised level of data protection (Article 45 GDPR), where contractual obligations under the European Commission’s standard contractual clauses exist and are complied with (Article 46 GDPR), or where certifications or binding corporate rules are in place (see Articles 44 to 49 GDPR, European Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en). EU-US Trans-Atlantic Data Privacy Framework: Under the so-called Data Privacy Framework (DPF), the European Commission has also recognised the level of data protection as adequate for certain companies in the USA by way of the adequacy decision of 10 July 2023. The list of certified companies and further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English). We inform you within this privacy notice which of the service providers we use are certified under the Data Privacy Framework.

Erasure of data

The data processed by us is erased in accordance with the legal requirements as soon as the consents permitting its processing are withdrawn or other permissions cease to apply (for example, where the purpose of processing this data no longer applies or the data is not necessary for that purpose). Where the data is not erased because it is required for other, legally permissible purposes, its processing is restricted to those purposes. That is, the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary for the establishment, exercise or defence of legal claims or to protect the rights of another natural or legal person. Within our privacy notice we may provide users with further information on the erasure and retention of data that applies specifically to the respective processing operations.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw consent you have given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to obtain information about that data, as well as further information and a copy of the data in accordance with the legal requirements.
  • Right to rectification: In accordance with the legal requirements, you have the right to request that data concerning you be completed or that inaccurate data concerning you be rectified.
  • Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to request that data concerning you be erased without undue delay, or alternatively to request a restriction of the processing of the data in accordance with the legal requirements.
  • Right to data portability: You have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
  • Complaint to a supervisory authority: In accordance with the legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.

Use of cookies

Cookies are small text files, or other forms of storage, that store information on end devices and read information from those devices. For example, to store the login status in a user account, the contents of a shopping basket in an online shop, the content accessed or the functions used within an online offering. Cookies can also be used for various purposes, for example for the functionality, security and convenience of online offerings as well as for producing analyses of visitor flows. Notes on consent: We use cookies in accordance with the legal requirements. We therefore obtain prior consent from users unless this is not required by law. In particular, consent is not necessary where the storage and reading of information, including cookies, is strictly necessary in order to provide users with a telemedia service (i.e. our online offering) that they have expressly requested. Strictly necessary cookies generally include cookies with functions relating to the display and operability of the online offering, load balancing, security, the storage of users’ preferences and choices, or similar purposes connected with the provision of the main and ancillary functions of the online offering requested by users. Consent, which can be withdrawn, is clearly communicated to users and contains the information on the respective use of cookies. Notes on the legal bases under data protection law: The legal basis under data protection law on which we process users’ personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the consent given. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (for example, in the commercial operation of our online offering and the improvement of its usability) or, where this takes place in the performance of our contractual obligations, where the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which we process cookies in the course of this privacy policy or as part of our consent and processing procedures. Storage period: With regard to the storage period, the following types of cookies are distinguished:
  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest once a user has left an online offering and closed their end device (e.g. browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the end device has been closed. This makes it possible, for example, to store the login status or to display preferred content directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information about the type and storage period of cookies (e.g. when obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.
General information on withdrawal and objection (so-called “opt-out”): Users can withdraw the consent they have given at any time and object to processing in accordance with the legal requirements. Among other things, users can restrict the use of cookies in their browser settings (although this may also limit the functionality of our online offering). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/ .
  • Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and user-friendliness.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR). Consent (Article 6(1)(a) GDPR).
Further information on processing operations, procedures and services:
  • Processing of cookie data on the basis of consent: We use a cookie consent management procedure through which users’ consent to the use of cookies, or to the processing operations and providers named within the cookie consent management procedure, can be obtained, managed and withdrawn by users. The declaration of consent is stored so that the request does not have to be repeated and so that consent can be evidenced in accordance with the legal obligation. Storage may take place server-side and/or in a cookie (a so-called opt-in cookie, or using comparable technologies) in order to be able to attribute the consent to a user or their device. Subject to individual information about the providers of cookie management services, the following applies: consent may be stored for up to two years. A pseudonymous user identifier is created and stored together with the time of consent, information on the scope of the consent (e.g. which categories of cookies and/or service providers) and the browser, system and end device used; Legal bases: Consent (Article 6(1)(a) GDPR).
  • Real Cookie Banner: Cookie consent management; Service provider: devowl.io GmbH, Tannet 12, 94539 Grafling, Germany; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://devowl.io/wordpress-real-cookie-banner/. Privacy policy: https://devowl.io/privacy-policy/.

Provision of the online offering and web hosting

We process users’ data in order to be able to provide them with our online services. For this purpose we process the user’s IP address, which is necessary in order to transmit the content and functions of our online services to the user’s browser or end device.
  • Types of data processed: Usage data (e.g. websites visited, interest in content, access times). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
Further information on processing operations, procedures and services:
  • Provision of the online offering on rented storage space: To provide our online offering we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a “web host”); Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
  • Collection of access data and log files: Access to our online offering is logged in the form of so-called server log files. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used firstly for security purposes, for example to avoid server overload (in particular in the event of abusive attacks, so-called DDoS attacks), and secondly to ensure server utilisation and stability; Legal bases: Legitimate interests (Article 6(1)(f) GDPR). Erasure of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is necessary for evidentiary purposes is exempt from erasure until the respective incident has been finally resolved.
  • STRATO: Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: STRATO AG, Pascalstrasse 10, 10587 Berlin, Germany; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.strato.de; Privacy policy: https://www.strato.de/datenschutz. Data processing agreement: Provided by the service provider.

Contact and enquiry management

When you contact us (e.g. by post, contact form, email, telephone or via social media) and within existing user and business relationships, the details of the enquiring person are processed insofar as this is necessary to respond to the contact enquiry and any requested measures. The same applies to the use of online appointment booking tools for arranging meetings.
  • Types of data processed: Contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); appointment and organisational data (e.g. selected appointment, time zone, occasion). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
  • Data subjects: Communication partners; persons who arrange appointments with us.
  • Purposes of processing: Contact enquiries and communication; management and response to enquiries; appointment scheduling and organisation; feedback (e.g. collecting feedback via an online form). Provision of our online offering and user-friendliness.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR). Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
Further information on processing operations, procedures and services:
  • Contact form: When users contact us via our contact form, by email or by other means of communication, we process the data provided to us in this context in order to deal with the matter raised; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).
  • Contact Form 7: Form. Website: https://contactform7.com/.
  • Calendly: We use the Calendly service for online appointment scheduling. The provider is Calendly LLC, 1315 Peachtree St NE, Atlanta, GA 30309, USA. The data processing serves the planning and holding of appointments. Information on data processing by Calendly can be found at: https://calendly.com/privacy. Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).

Amendment and updating of this privacy policy

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification. Where we state addresses and contact details of companies and organisations in this privacy policy, please note that addresses may change over time and we ask you to verify the details before making contact.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Where the terms are defined by law, the statutory definitions apply. The following explanations are intended primarily to aid understanding.
  • Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Controller: “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: “Processing” means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, be it collection, analysis, storage, transfer or erasure.

This is a translation of our German privacy policy. In the event of any discrepancy, the German version shall prevail.

©️ 2026 Maibach Digital GmbH