PreambleWith the following privacy policy, we wish to inform you about the types of personal data (hereinafter also referred to simply as ‘data’) that we process, the purposes for which we do so, and the extent of such processing. This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, on our websites, in mobile applications and within external online platforms, such as our social media profiles (hereinafter collectively referred to as the “online offering”).
The terms used are not gender-specific.
Date: 22 August 2026
Table of Contents- Preamble
- Data controller
- Overview of data processing activities
- Relevant legal bases
- Security measures
- Disclosure of personal data
- International data transfers
- General information on data storage and erasure
- Rights of data subjects
- Business services
- Provision of the online service and web hosting
- Use of cookies
- Contact and enquiry management
- Web analytics, monitoring and optimisation
- Social media presence
- Plug-ins, embedded functions and content
- Amendments and updates
- Definitions
Data Controller
Maxim Heidebrecht
Paderbornerstr 153
32760 Detmold, Germany
Email: maxbreht@gmail.com
Legal notice: https://maxbreht.com/legal-notice
Overview of data processing
The following overview summarises the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of data processed- Master data.
- Employee data.
- Payment data.
- Contact details.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and process data.
- Log data.
Categories of data subjects- Beneficiaries and clients.
- Employees.
- Prospective clients.
- Communication partners.
- Users.
- Business and contractual partners.
- Third parties.
- Whistleblowers.
Purposes of processing- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Audience measurement.
- Tracking.
- Office and organisational procedures.
- Target group identification.
- Organisational and administrative procedures.
- Feedback.
- Marketing.
- Profiles containing user-related information.
- Provision of our online services and user-friendliness.
- IT infrastructure.
- Whistleblower protection.
- Public relations.
- Business processes and operational procedures.
Relevant legal basesRelevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours, depending on where you or we are resident or have our registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
- Consent (Article 6(1), first sentence, point (a) of the GDPR) – The data subject has given their consent to the processing of personal data relating to them for a specific purpose or for several specific purposes.
- Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) - Processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
- Legal obligation (Article 6(1), first sentence, point (c) of the GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject which require the protection of personal data do not override those interests.
National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, data protection laws of the individual federal states may also apply.
Safety measuresIn accordance with statutory requirements, and taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and availability of the data, and ensuring its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and through privacy-friendly default settings.
IP address truncation: Where IP addresses are processed by us or by the service providers and technologies we use, and where the processing of a full IP address is not necessary, the IP address is truncated (also known as ‘IP masking’). In this process, the last two digits, or the last part of the IP address following a full stop, are removed or replaced with placeholders. The purpose of truncating the IP address is to prevent, or make it significantly more difficult, to identify a person on the basis of their IP address.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. If a website is secured by an SSL/TLS certificate, this is indicated by the presence of ‘HTTPS’ in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Transfer of personal dataIn the course of our processing of personal data, such data may be transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
International data transfersData processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to other persons, organisations or companies (which can be identified by the postal address of the relevant provider or where the privacy policy expressly refers to data transfers to third countries), this is always carried out in accordance with the legal requirements.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the European Commission dated 10 July 2023. In addition, we have entered into standard contractual clauses with the relevant providers which comply with the European Commission’s requirements and set out contractual obligations to protect your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, whilst the Standard Contractual Clauses serve as an additional safeguard. Should any changes arise within the framework of the DPF, the Standard Contractual Clauses act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.
For each service provider, we will inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the US Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English).
Appropriate safeguards apply to data transfers to other third countries, in particular standard contractual clauses, explicit consent or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.