Privacy Policy
Last updated: July 23, 2026
The protection of your personal data is important to me. In the following, I inform you comprehensively, in accordance with Art. 13 and Art. 14 of the General Data Protection Regulation (GDPR), about the nature, scope, and purpose of the processing of personal data within the scope of this online offering and in the course of existing business relationships.
1. Data Controller
The controller within the meaning of the GDPR is Oskar Seeberger, Adalbert-Stifter-Straße 5, 82031 Grünwald, Germany, reachable at o.seeberger@outlook.com. Due to the size of the business, the appointment of a data protection officer is not legally required.
2. Categories of Data Processed
In connection with the use of this website and the business relationship, the following categories of personal data are processed:
- Contact data from inquiries (name, email address, phone number, message content)
- Billing and payment data in connection with contract fulfillment (processed via Stripe)
- Usage and log data for the provision and security of the website (server log files)
- Pseudonymized usage data for the analysis and improvement of the service (PostHog)
- Business correspondence and contact management within the scope of the client relationship (Attio, Resend)
3. Legal Basis for Processing
Personal data is processed on the basis of the following legal grounds under the GDPR:
- Art. 6 (1) (b) GDPR – for the performance of pre-contractual measures and the execution of consulting service agreements
- Art. 6 (1) (f) GDPR – to safeguard legitimate interests, in particular ensuring IT security, fraud prevention, and the needs-based further development of the service
- Art. 6 (1) (c) GDPR – to comply with legal obligations, such as commercial and tax retention requirements
4. Data Processors and Recipients
The following carefully selected data processors and service providers are engaged to operate this website and manage the business relationship. Data processing agreements pursuant to Art. 28 GDPR are in place with all processors where legally required:
- Vercel Inc. (hosting and infrastructure, data center location: Frankfurt am Main, Germany): processes server log files, IP addresses, and technically necessary session information. The data processing agreement includes EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR.
- Stripe Payments Europe, Ltd. (payment processing, headquarters: Dublin, Ireland): processes payment, invoicing, and subscription data in connection with the performance of the contract. Stripe is PCI-DSS certified and is subject to its own statutory retention obligations for payment records.
- PostHog Inc. (web analytics, headquarters: San Francisco, USA): collects pseudonymized usage data to further develop the service as needed. Data is not combined with other sources. The transfer to the USA is based on EU Standard Contractual Clauses.
- Attio (customer relationship management): used for the internal management of business contacts and project information within existing or prospective business relationships.
- Resend (email delivery): used to send transaction-related emails, such as order confirmations and notifications.
5. Cookies and Similar Technologies
This website uses only technically necessary cookies and pseudonymized analytics technology; no third-party marketing or tracking cookies are used.
- Technically necessary cookies: maintaining the session and ensuring the basic functionality of the website (legal basis: Art. 6 (1) (f) GDPR, § 25 (2) No. 2 TTDSG)
- PostHog analytics: pseudonymized collection of page views and interactions for reach measurement (legal basis: Art. 6 (1) (f) GDPR)
As these are exclusively technically necessary processing activities that safeguard legitimate interests, separate consent is not required.
6. Data Retention
Personal data is stored only for as long as necessary to achieve the respective processing purpose or as required by statutory retention periods:
- Contact inquiries: deleted upon completion of processing, at the latest after 12 months
- Billing and payment data: retained in accordance with commercial and tax law retention periods (§ 147 AO, § 257 HGB), generally up to 10 years
- Analytics data (PostHog): automatically deleted after 12 months
7. Your Rights as a Data Subject
You have the following rights with respect to your personal data:
- Right of access to the processed data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure, insofar as no statutory retention obligations apply (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on legitimate interests (Art. 21 GDPR)
- Right to withdraw any consent given, with effect for the future (Art. 7 (3) GDPR)
To exercise these rights, an informal message to o.seeberger@outlook.com is sufficient.
8. International Data Transfers
Some of the data processors named above are headquartered outside the European Union, in particular in the USA. The transfer of personal data to these third countries takes place exclusively on the basis of appropriate safeguards within the meaning of Art. 44 to 49 GDPR, in particular through the use of the Standard Contractual Clauses adopted by the European Commission.
9. Data Security
Appropriate technical and organizational measures are taken to protect personal data against accidental or intentional manipulation, loss, destruction, or unauthorized access by third parties, including end-to-end transport encryption (TLS) for all data transmissions.
10. Changes to This Privacy Policy
This privacy policy is updated as necessary to continue to meet current legal requirements or to reflect changes to the services described herein. The version published on this website shall apply at any given time.
11. Contact and Right to Lodge a Complaint
For questions regarding the processing of your personal data or to exercise your rights, Oskar Seeberger is available at o.seeberger@outlook.com. Without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany (www.lda.bayern.de).