Skip to content

Privacy notice

As at 8 September 2026

This is the English version, and it is our reference version. The same notice is published in German and in Romanian; each version describes the same processing, and you may rely on the version in your language. Where two versions diverge, this English text prevails.

Data protection at a glance

  • The controller is a single person, not a company with employees. Who that is stands in the next section and in the Impressum.
  • Without your consent no analytics and no advertising service is loaded. Refusing is exactly as easy as agreeing on the first level of the banner.
  • We need your email address only where we are to send you something: report, file, confirmation, receipt, newsletter. Everything else is voluntary.
  • When you buy the report at €29, payment data is collected by a payment service provider. Card details do not reach this website.
  • For the analysis, the publicly retrievable content of the website being checked is transmitted to language models. Your email address is not part of it.
  • All recipients are named individually below, with purpose, legal basis, retention and transfer basis.
  • You can request access, rectification, erasure, restriction, portability and objection, informally by email.

1. Controller

Cristian-Stefan Lascu
Kairox Consulting
Glatzer Str. 16
45768 Marl
Germany

Email
[email protected]
Requests about your data
[email protected]

No data protection officer has been appointed, and none is required. § 38 Abs. 1 BDSG requires one where at least twenty persons are constantly engaged in the automated processing of personal data; this service is run by one person, with no employees. The grounds in Art. 37 DSGVO do not apply either: this is not a public body, the core activity is not large-scale regular monitoring, and no special categories of data are processed on a large scale.

2. When you only visit the website

When a page is called, technically necessary data is processed: IP address, date and time, address called, volume of data transferred, browser type and operating system, and the page visited before. Without those details the page cannot be delivered.

All traffic runs through a content delivery network that encrypts the connection and fends off attacks. The servers on which the website and the database sit are at Hetzner Online GmbH in Germany, Nuremberg data centre.

The legal basis is Art. 6 Abs. 1 lit. f DSGVO. The legitimate interest lies in the secure and stable provision of the service.

3. The individual processing operations

Newsletter. We process your email address, on request your name and industry, the time and page of the sign-up and campaign parameters, in order to send you the weekly newsletter. The legal basis is Art. 6 Abs. 1 lit. a DSGVO.

Free short analysis. You give the address of your website. We retrieve the publicly reachable pages, evaluate them and send you the result if you leave an email address. Of your IP address we store only a value that cannot be computed back, in order to limit usage. The legal basis is Art. 6 Abs. 1 lit. b DSGVO for the delivery, otherwise Art. 6 Abs. 1 lit. f DSGVO.

Purchase of the AI Readiness Check. For the purchase at €29, email address, billing address, VAT identification number where applicable and payment data are collected, the details about website and industry are received, the report is produced and receipt and invoice are sent. The legal basis is Art. 6 Abs. 1 lit. b DSGVO, and for retention of the invoice records Art. 6 Abs. 1 lit. c DSGVO in conjunction with § 147 AO.

Enquiries and contact form. We process your name, your email address, your message and the page the enquiry came from, in order to reply. The legal basis is Art. 6 Abs. 1 lit. b DSGVO, and for general enquiries Art. 6 Abs. 1 lit. f DSGVO.

Booking a call. If you book a call, we process the details reported back about person, time and time zone, and your answers in the booking form, in order to prepare the call and send reminders. The legal basis is Art. 6 Abs. 1 lit. b DSGVO.

Reach and product analytics, and advertising measurement. These operations take place only after your consent and are described in the section on consent and access to your device.

Error logs and operational security. Program errors on the server are recorded in order to fix faults. The legal basis is Art. 6 Abs. 1 lit. f DSGVO.

4. Which details are necessary

You are not obliged to give us personal data. There is no statutory or contractual obligation to do so.

Without an email address, however, we can send you neither the report nor a file, a confirmation, a receipt or the newsletter. Without the address of your website no analysis can be produced. Without a billing address no purchase can be completed. All other details, such as name, industry or free text, are voluntary, and their absence has no disadvantage other than a less precise result.

5. Automated evaluation and language models

The analysis is produced by machine. Language models assess the publicly retrievable content of the website being checked and generate findings, suggestions and a rough placement into a band. That placement describes the website being checked, not you as a person, and it leads to no decision about you: it merely controls which text blocks appear in the report.

In our assessment there is no automated decision in an individual case, including profiling, within the meaning of Art. 22 DSGVO. The assessment is of a website, not of you; it produces no legal effect and denies you nothing; and its only consequence is which text appears in a report you asked for.

Because that assessment is ours and not a court’s, we do not rely on it to withhold anything from you. If you think a band is wrong, write to us: we will look at it by hand, tell you how it was arrived at, and correct the report where the objection is good. You need give no reason and there is no form.

Which providers are involved is stated in the list of recipients.

6. Recipients

Art. 13 Abs. 1 lit. e DSGVO requires the recipients or the categories of recipients. Since all recipients are determined, they are named individually. The list below states, for each service, the provider, purpose, data categories, legal basis, retention, transfer basis, processing agreement, the provider’s own privacy policy and the route to object.

Beyond that, data may be transmitted to authorities where a statutory obligation to do so exists, and to the tax adviser in the course of bookkeeping. Data is not sold.

Hetzner (hosting)

Provider
Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany
Purpose
Running the servers on which this website, the database and the generated reports sit.
Data categories
All data arising on this website, plus server and access logs with IP address, time, address requested, browser type and referrer.
Legal basis
Art. 6 Abs. 1 lit. f DSGVO (providing a functioning service), and for contract data additionally Art. 6 Abs. 1 lit. b DSGVO.
Retention
Log data for the duration of technical operation. Content data according to the table in the retention section.
Third-country transfer
No third-country transfer. The servers are in Germany, and the provider states that the technical and customer support for every server location is provided within the EU. The provider does list subcontractors in the USA and in Singapore; those apply to server locations we do not use.
Processing agreement
A processing agreement under Art. 28 DSGVO was concluded with the provider on 26 August 2026. The provider has an appointed data protection officer, reachable at [email protected].
How to object
Cannot be switched off. Without hosting the website is unreachable.
In use
Permanently active.
Privacy policy
www.hetzner.com/de/legal/privacy-policy

Cloudflare (CDN, TLS and Turnstile)

Provider
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
Purpose
Delivery of the website through a content delivery network, TLS encryption of the connection, and Turnstile as abuse protection in front of the forms. From the IP address the provider additionally derives the country code and passes it to this website, which uses it on a first visit to suggest a language version and for nothing else.
Data categories
IP address, browser identifier and requested address of every call, because all traffic runs through Cloudflare. For Turnstile additionally a verification token and the IP address during the server-side check.
Legal basis
Art. 6 Abs. 1 lit. f DSGVO (secure and available provision, defence against automated attacks). For the Turnstile component loaded in the browser additionally § 25 Abs. 2 Nr. 2 TDDDG.
Retention
According to the provider’s periods. We do not store the Turnstile tokens.
Third-country transfer
Transfer to the USA. According to its own statement the provider is certified under the EU-US Data Privacy Framework, supplemented by standard contractual clauses.
Processing agreement
The Cloudflare Data Processing Addendum is incorporated into the Self-Serve Subscription Agreement under which this account is held, so it applies without a separate signature. It incorporates the standard contractual clauses for restricted transfers.
How to object
Cannot be switched off for as long as the website is delivered through this network.
In use
CDN and TLS permanently. Turnstile only where the credentials are configured. If Turnstile fails, the request is let through.
Privacy policy
www.cloudflare.com/privacypolicy/

Stripe (payment and invoice)

Provider
Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, and Stripe, Inc., South San Francisco, CA, USA
Purpose
Handling the purchase of the AI Readiness Check at €29, producing the invoice and showing the VAT.
Data categories
Email address, billing address, VAT identification number where applicable, payment data, amount and payment identifiers. In addition three details asked for on the payment page: website address, industry and a free description of the industry. Flowing back to us are the email address, country, tax numbers, amounts and the identifier and address of the invoice.
Legal basis
Art. 6 Abs. 1 lit. b DSGVO (performance of the purchase contract) and Art. 6 Abs. 1 lit. c DSGVO in conjunction with § 147 AO for retention of the invoice records.
Retention
Order and invoice data for ten years under § 147 Abs. 3 AO. That period applies even after a deletion request.
Third-country transfer
The contracting party is the Irish company. Onward transfer to the USA on the basis of standard contractual clauses and certification under the EU-US Data Privacy Framework.
Processing agreement
A processing agreement under Art. 28 DSGVO is in place through Stripe’s terms of service.
How to object
Cannot be switched off if you buy. Without a payment service provider no purchase is possible.
In use
Active as soon as a purchase is started. Card details never reach this website.
Privacy policy
stripe.com/de/privacy

Beehiiv (newsletter)

Provider
Beehiiv, Inc., 228 Park Avenue #2329976, New York, NY 10003, USA
Purpose
Sending and managing the weekly newsletter.
Data categories
Email address, first and last name, industry, sign-up source, campaign parameters, the address of the page the sign-up happened on, and the usual delivery signals such as delivery, open and click.
Legal basis
Art. 6 Abs. 1 lit. a DSGVO (consent).
Retention
Until withdrawal. After unsubscribing, the entry in our own database is kept marked as unsubscribed so that the address is not written to again by mistake.
Third-country transfer
Transfer to the USA on the basis of the standard contractual clauses. For subscriber profile data the provider incorporates the controller-to-controller module of those clauses, which means it processes part of that data on its own responsibility rather than solely on ours.
Processing agreement
The provider’s data protection addendum is incorporated into its terms of use by reference and applies to this account.
How to object
Unsubscribe link at the end of every issue, or informally by email to us.
In use
Active as soon as the credentials are configured. Sign-up currently happens without a confirmation mail, that is in one step.
Privacy policy
www.beehiiv.com/privacy

Loops (transactional and follow-up mail)

Provider
Astrodon Corporation, trading as Loops, 9450 SW Gemini Dr, PMB 22902, Beaverton, OR 97008-7105, USA
Purpose
Sending the mail this website itself produces: the analysis report, a requested file, confirmation and reminder for a booking, the purchase receipt, and the short follow-up sequences after them.
Data categories
Email address, first name, industry, size band, score band, source, the website address from the analysis, the report’s key figures, addresses for report, file and invoice, time and time zone of a booking, and a signed unsubscribe link.
Legal basis
Art. 6 Abs. 1 lit. b DSGVO for the delivery you asked for, Art. 6 Abs. 1 lit. a DSGVO for the follow-up sequences after it.
Retention
Until consent is withdrawn or the purpose ceases.
Third-country transfer
Transfer to the USA. The provider is certified under the EU-US Data Privacy Framework, actively since 16 May 2025 and with recertification due by 4 May 2027; the standard contractual clauses apply in addition, so the transfer does not stand on the framework alone.
Processing agreement
The provider’s data processing agreement takes effect through use of the service and applies to this account. The provider publishes its own list of subprocessors at loops.so/subprocessors.
How to object
Unsubscribe link in every one of these mails. It stops all mail of this kind, but not the newsletter, which is a separate list.
In use
Active as soon as the credentials and the respective template identifier are configured.
Privacy policy
loops.so/privacy

Zeeg (booking)

Provider
Zeeg GmbH, Friedrichstr. 155, 10117 Berlin, Germany (Amtsgericht Berlin (Charlottenburg), HRB 253807, VAT ID DE362883687)
Purpose
Booking the call through an external booking page.
Data categories
When you click through to the booking page from our contact form, we pass your name and your email address in the link, so that the form arrives with those two fields already filled in. Everything else you enter there yourself. Zeeg reports back to us your email address, your name, the start and time zone of the call, the booking identifiers and the answers to the booking form’s questions, including the data-protection consent given there.
Legal basis
Art. 6 Abs. 1 lit. b DSGVO (carrying out the call you asked for). For the processing on the booking page, Zeeg is itself the controller towards you.
Retention
The booking data reported back stays in the lead record until the purpose ceases or you object.
Third-country transfer
No third-country transfer. The provider is established in Germany and hosts on European servers, in Deutsche Telekom’s Open Telekom Cloud.
Processing agreement
A processing agreement under Art. 28 DSGVO forms part of the provider’s business terms and applies to this account.
How to object
Do not book, or write us an email instead.
In use
The link to the booking page is always visible. We process what is reported back to us only where the corresponding key is configured.
Privacy policy
zeeg.me/en/legal/privacy

Google Analytics 4

Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, Mountain View, CA, USA
Purpose
Reach measurement, to see which content is read.
Data categories
Pages called, event names and simple event parameters, truncated IP address, browser identifier, referrer. Email addresses are not transmitted.
Legal basis
Art. 6 Abs. 1 lit. a DSGVO in conjunction with § 25 Abs. 1 TDDDG (consent through the banner, Analytics category).
Retention
Event data and user-related data: 14 months (event data raised from two to 14 months on 15 August 2026; user-related data was already at 14 months). Aggregated reports are unaffected.
Third-country transfer
The contracting party is the Irish company. Onward transfer to the USA on the basis of certification under the EU-US Data Privacy Framework, supplemented by standard contractual clauses.
Processing agreement
Processing agreement under Art. 28 DSGVO through the Google terms.
How to object
Deselect the Analytics category in the banner, or simply close it without agreeing. Without that consent the provider’s library is not loaded at all, so nothing is measured and nothing is stored.
In use
Loaded exclusively after consent to the Analytics category has been given, and only where the measurement id is configured.
Privacy policy
policies.google.com/privacy

PostHog (product analytics, EU instance)

Provider
PostHog, Inc., 2261 Market Street, San Francisco, CA 94114, USA, EU instance in the European Union
Purpose
Understanding at which point of a flow people drop out, and evaluating the funnels for analysis, purchase and sign-up.
Data categories
After consent to the Analytics category: page views, clicks, persistent identifiers in the browser, and session recordings in which input fields are masked, together with IP address and browser identifier. Without that consent the provider’s library is not loaded and nothing is sent to it. Server-side, and independently of the browser, a purchase is reported through the payment identifier and a booking through the email address.
Legal basis
Art. 6 Abs. 1 lit. a DSGVO in conjunction with § 25 Abs. 1 TDDDG for everything measured in the browser. For the two server-side reports of a purchase and a booking, Art. 6 Abs. 1 lit. b DSGVO.
Retention
Event data: one year, the period of the plan in use; a shorter project-wide period cannot be set on that plan. Session recordings: up to 30 days. Provider information as at 15 August 2026.
Third-country transfer
Processing on the provider’s EU instance. This is enforced in the software rather than merely configured: an address that is not an EU host of this provider is refused when the site starts. The provider itself is seated in the USA; the standard contractual clauses apply in addition for maintenance access, and the provider is certified under the EU-US Data Privacy Framework, actively since 8 May 2024 and with recertification due by 10 March 2027.
Processing agreement
A data processing agreement under Art. 28 DSGVO was concluded with the provider on 26 August 2026. It incorporates the EU standard contractual clauses under Commission Implementing Decision (EU) 2021/914.
How to object
Deselect the Analytics category in the banner, or close it without agreeing. The library is then not loaded at all. Withdrawing a consent already given stops the session recording and drops the persistent identifiers for the rest of the visit.
In use
Loaded exclusively after consent to the Analytics category has been given, and only where the project key is configured.
Privacy policy
posthog.com/privacy

Microsoft Clarity (session recording)

Provider
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Purpose
Recording sessions and heatmaps, to spot usability problems.
Data categories
Addresses called, clicks, scrolling and mouse movement, snapshots of the page structure, IP address, browser identifier, and the provider’s own identifiers in the browser.
Legal basis
Art. 6 Abs. 1 lit. a DSGVO in conjunction with § 25 Abs. 1 TDDDG (Analytics category).
Retention
According to the provider’s periods.
Third-country transfer
The contracting party is the Irish company. Onward transfer to the USA on the basis of certification under the EU-US Data Privacy Framework, supplemented by standard contractual clauses.
Processing agreement
There is no processing agreement under Art. 28 DSGVO here, and none is possible. For the data collected through this service Microsoft acts as a controller in its own right: it decides for itself about the purposes and the means, including using the data to improve its own services. Your data reaches Microsoft Ireland Operations Limited in that capacity, under Microsoft’s own privacy statement, which is linked below. That is why this service is loaded only after you have consented.
How to object
Deselect the Analytics category in the banner. The component is then not loaded at all. A withdrawal during a running session is reported to the provider.
In use
Loaded exclusively after consent to the Analytics category has been given, and only where the project id is configured. The provider’s masking of input fields is set to its strictest setting, so what you type into a form is not part of a recording.
Privacy policy
privacy.microsoft.com/de-de/privacystatement

OpenRouter and the model providers behind it

Provider
OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016, USA
Purpose
Producing the analysis: the publicly retrievable content of the website being checked is evaluated and findings and suggested actions are generated from it.
Data categories
The address of the website being checked, its publicly retrievable page content, the industry selected and the free industry description, plus the search queries generated from them. The name, email address and IP address of the requesting person are not transmitted.
Legal basis
Art. 6 Abs. 1 lit. b DSGVO for the paid report, Art. 6 Abs. 1 lit. f DSGVO for the free short analysis.
Retention
We store the models’ answers in our database. Free text from them is removed automatically after 90 days, see the retention section.
Third-country transfer
Transfer to the USA and, depending on the model, to further countries, on the basis of standard contractual clauses.
Processing agreement
The provider’s data processing agreement is incorporated by reference into its terms for commercial use and applies to this account.
How to object
Do not start an analysis. Without model evaluation no report is produced.
In use
Active as soon as the access key is configured. Without a key the evaluation does not happen and the report stays purely rule-based. Models from the following providers are currently addressed through OpenRouter: OpenAI, Google, Anthropic, xAI, DeepSeek and Perplexity. Models offered at no charge that may use inputs for training are excluded technically. Every provider that can be reached is named here rather than described as a category, so that Art. 13 Abs. 1 lit. e DSGVO is satisfied whichever of the two readings of that provision is right; if the list ever changes, this row changes with it.
Privacy policy
openrouter.ai/privacy

DataForSEO (search result data)

Provider
DataForSEO OÜ, Vesivärava tn 50-201, 10152 Tallinn, Estonia
Purpose
Retrieving public search results for a query, in order to place the visibility of the website being checked.
Data categories
A search query derived from the website being checked, language and country. Neither email address nor IP address nor any identifier of the requesting person is transmitted.
Legal basis
Art. 6 Abs. 1 lit. b DSGVO for the paid report, otherwise Art. 6 Abs. 1 lit. f DSGVO.
Retention
The results go into the report and are subject to its periods.
Third-country transfer
The contracting party is established in the European Union, so the contract itself gives rise to no third-country transfer. The provider states that it uses Google and Microsoft Azure infrastructure alongside a German data centre, so onward transfers may occur at the level of its own subcontractors, under that provider’s safeguards.
Processing agreement
The provider’s data processing agreement is incorporated into its privacy policy where the GDPR applies, and applies to this account.
How to object
Do not start an analysis.
In use
Active as soon as the credentials are configured.
Privacy policy
dataforseo.com/privacy-policy

7. Transfers to third countries

Some of the providers named are seated outside the European Union or process there. The basis relied on in each case is stated in that provider’s row: no transfer, certification under the EU-US Data Privacy Framework, or standard contractual clauses under Art. 46 Abs. 2 lit. c DSGVO.

The European Commission’s adequacy decision on the EU-US Data Privacy Framework of 10 July 2023 remains in force. An action against the decision was dismissed by the General Court of the European Union on 3 September 2025; the appeal against that is pending before the Court of Justice. We are watching the outcome and will adjust the bases if it requires that.

We do not claim that your data enjoys the same level of protection outside the EU as within it. We name the basis the transfer rests on and leave the assessment to you.

8. Consent and access to your device (§ 25 TDDDG)

Storing information on your device and accessing information already stored there require your consent in principle under § 25 Abs. 1 TDDDG. Exempt under § 25 Abs. 2 Nr. 2 TDDDG is what is strictly necessary for the service you expressly requested. That rule applies alongside the GDPR, not instead of it.

On a first visit a banner with two categories appears. Agreeing and refusing sit on the same level: the button for the necessary services only sits directly beside the one for all services. Before your decision, no measurement service and no advertising service is loaded at all · not in a reduced mode, and not without cookies. Until you agree to a category, nothing about your visit is sent to any of those providers, and nothing is counted, not even anonymously. Everything the Analytics category describes · page views, clicks, persistent identifiers, session recordings · begins with your consent and not before.

Your decision is not stored in a cookie but in your browser’s local storage, under the names cookiePreferences and cookiesAccepted, and it stays there for twelve months, unless you change it or clear your browser’s data first. After twelve months both entries are deleted and the banner asks again. No statute fixes an interval at which a consent must be sought afresh; twelve months is the period the German supervisory authorities treat as the outer edge of a still current decision. With consent to the Analytics category, the entry st_ai_referral is added in session storage, recording which AI answer engine sent you; it is read and written only with that consent, ends with the session, and is removed immediately on withdrawal.

You can change your decision at any time. At the foot of every page there is an entry for the privacy settings, which reopens the banner. A withdrawal takes effect for the future and leaves the lawfulness of processing carried out up to that point unaffected.

This website sets cookies of its own in four places. All four are strictly necessary for the service you expressly requested within the meaning of § 25 Abs. 2 Nr. 2 TDDDG and therefore need no consent. None of them measures reach, none serves advertising, and none is passed to a third party.

st_exit_seen remembers that a notice window has already been shown and expires after 14 days. st_locale holds the language you chose yourself and expires after a year. The entry is created when you use the language selector that sits in the header and in the footer of every page, and it is updated when you deliberately move into another language version with a choice already made; without it we could not know your choice on your next visit. st_locale_suggested records that a language version was once suggested to you and expires after twelve hours; without that entry the same suggestion would be made on every visit.

st_warm is written when you open a scan report of your own, and expires after a year. It holds that report’s own link code, which is the same code in the link we emailed you and which opens nothing else. It exists so that a booking link on this site can open the appointment calendar with the details you gave us for the scan already filled in, instead of putting a form in front of you that asks for them a second time; without it every such link would ask again.

The three cookies above contain only a language code, the digit 1, or a report link code. None can be read by JavaScript in the browser, and all are sent only when a page of this website is called. They contain no identifier by which a person could be recognised beyond the one report the code belongs to.

The table below is the complete list of what is written to your device: by this website itself, and by the three measurement services, which write nothing until you have agreed to the Analytics category. Local storage and session storage are not cookies, and are named as what they are. Session storage ends when you close the tab.

The banner’s categories

Essential (always on)necessary

Your own decision about this banner, and the abuse protection in front of the forms. Nothing else. No measurement service and no advertising service is loaded before you have decided · not in a reduced mode either, and not without cookies. Until you agree to a category, nothing about your visit is sent to any of the providers named below.

Legal basis: § 25 Abs. 2 Nr. 2 TDDDG, Art. 6 Abs. 1 lit. f DSGVO.

Analyticsanalytics

Google Analytics 4, PostHog’s persistent recording including session recording, and Microsoft Clarity, each where the service is configured. This consent additionally allows reading which page you arrived from; where the visit comes from one of the known AI answer engines, its name is stored in your browser’s session storage under st_ai_referral and attached to the measurement events. Without this consent nothing is read or stored for that purpose.

Legal basis: § 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO.

What is stored on your device

NameWhereWhat it is forHow longLegal basis
cookiePreferences, cookiesAcceptedLocal storageYour decision about the banner, which categories you allowed, and the date you decided. Without it the banner would ask again on every page.Twelve months. After that both are deleted and the banner asks again. Deleted at once if you clear your browser data.§ 25 Abs. 2 Nr. 2 TDDDG. Honouring your decision requires remembering it.
__ph_opt_in_out_<project key>Local storage, set by PostHogThat PostHog has been switched off for you. It is written only if you granted the Analytics category and then withdrew it in the same visit: the provider’s library is loaded by then and a loaded script cannot be removed, so this entry is what tells it to capture nothing further. It holds the digit 0 or 1 and nothing else.One year, the period the provider’s own library sets for it. Deleted at once if you clear your browser data.§ 25 Abs. 2 Nr. 2 TDDDG. Honouring your withdrawal requires remembering it, exactly as the banner decision above does.
tst_capture_shown_session, tst_subscriber, tst_exit_intent_dismissed, tst_drawer_dismissed, tst_sticky_dismissed, newsletter-overlay-dismissedLocal storageWhich newsletter prompt you have already seen, dismissed or answered, so that at most one is shown and a dismissed one stays away. They hold a time or the word true, never an address.Until you clear your browser data. The quiet they buy runs out after seven or thirty days depending on the prompt.§ 25 Abs. 2 Nr. 2 TDDDG. It is what stops the same window reappearing.
bmc_canvas_data, bmc_project_name, bmc_email, bmc_accessLocal storageThe business model canvas you are filling in on this site, its name, the address you gave at its gate and the fact that the gate is open. The canvas stays on your device. We receive it only if you send it to us.Until you clear the canvas in the tool, or clear your browser data.§ 25 Abs. 2 Nr. 2 TDDDG. It is the tool you asked for.
st_scout_input, st_scout_input_<form>Session storageThe address, email address and trade you typed into the free analysis form, so that going back in your browser does not empty it.Ends when you close the tab.§ 25 Abs. 2 Nr. 2 TDDDG. It is your own input, held for the form you are using.
st_first_touchSession storageThe campaign parameters in the address you arrived by, and that first page, so that a form you send later can be attributed to the advertisement that brought you. Read only when you send a form.Ends when you close the tab.§ 25 Abs. 2 Nr. 2 TDDDG. These are parameters you brought with you in our own address, not a read of anything else on your device.
st_exit_route:<page>Session storageThat a notice window has already been shown to you on that page during this visit.Ends when you close the tab.§ 25 Abs. 2 Nr. 2 TDDDG.
check_purchased:<id>, call_booked:<id>, calc_used:<tool>Session storageThat a one off event has already been counted once in this tab, so that reloading a confirmation page does not count it twice.Ends when you close the tab.§ 25 Abs. 2 Nr. 2 TDDDG.
st_ai_referralSession storageWhich AI answer engine sent you, as one of five names. Nothing is written for any other referrer, and no browsing history of any kind is stored.Ends when you close the tab, and is deleted immediately if you withdraw the Analytics category.§ 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO. Analytics category only.
st_exit_seenCookieThat a notice window has already been shown, so it is not shown again site wide.14 days.§ 25 Abs. 2 Nr. 2 TDDDG.
st_localeCookieThe language you chose yourself. Contains a language code and nothing else, and cannot be read by JavaScript.One year.§ 25 Abs. 2 Nr. 2 TDDDG. Without it we could not know your choice on your next visit.
st_locale_suggestedCookieThat a language version was suggested to you once. Contains the digit 1 and nothing else, and cannot be read by JavaScript.Twelve hours.§ 25 Abs. 2 Nr. 2 TDDDG. Without it the same suggestion would be made on every visit.
st_warmCookieThat you have already opened a scan report of your own. Contains the report’s own link code and nothing else, and cannot be read by JavaScript. It is what lets a link to our booking page open the calendar with the answers you have already given us, instead of asking for them again.One year.§ 25 Abs. 2 Nr. 2 TDDDG. Without it every booking link would ask you for your name, your website and your trade a second time.
_ga, _ga_<measurement id>Cookies, set by Google Analytics 4Telling browsers apart and holding a visit together, so that page views can be counted. Written only after you agree to the Analytics category.Up to two years for _ga, shorter for the session entry. Both are expired by this site the moment you withdraw the category.§ 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO.
ph_<project key>_posthogLocal storage and a cookie, set by PostHogPostHog’s own identifier and session state, which is what makes several page views one visit. Written only after you agree to the Analytics category.Up to one year. On a withdrawal the recording stops and nothing further is sent; what is already stored goes when you clear your browser data.§ 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO.
_clck, _clskCookies, set by Microsoft ClarityThe identifier and the session Clarity records against. Written only after you agree to the Analytics category.One year and one day respectively. A withdrawal is reported to the provider with the call that erases them.§ 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO.

9. Retention

We store personal data only as long as is necessary for the respective purpose, or as a statutory retention period requires. The list below states, for each kind of data, the period and what enforces it. Where nothing expires automatically, it says so.

A statutory period takes precedence over a deletion request. If you request erasure although you have bought, the lead record is anonymised and the invoicing transaction is retained for the duration of the retention period under § 147 AO.

DataPurposePeriodEnforced by
Orders and invoice dataStatutory retentionTen years under § 147 Abs. 3 AO. A deletion request does not change that.No automatic deletion. The period is mandatory.
Free short analyses with no link to a person, a report or an orderNot needed after a short timeComplete deletion after 90 days.Daily automated job in the background worker.
Free text from the language models’ answersThe key figures are enough for the evaluationAfter 90 days, answer texts, raw answers, text excerpts and named competitors are removed. Counts and key figures remain.The same daily job.
Analysis requests started but never confirmedWithout confirmation no report is producedDeletion after 24 hours.A separate daily job in the background worker.
Analyses belonging to a report, an order or a leadThey evidence a service that was deliveredKept; the free text in them is removed after 90 days. Deletion on request, in so far as no retention period stands in the way.Partly automatic, otherwise on request.
Newsletter sign-upsConsentUntil withdrawal. After that the entry stays marked as unsubscribed, so that the address is not written to again.Unsubscribe link and unsubscribe route, immediate effect.
Consent recordsDuty to demonstrate under Art. 7 Abs. 1 DSGVOFor the duration of that duty. A withdrawal is recorded as a withdrawal; the record itself is not deleted, because deleting it would destroy the evidence of the withdrawal.No automatic expiry.
Leads, enquiries and messages from the contact formHandling the enquiry and initiating businessTwo years after the last contact, then deletion. Earlier at any time on request. The record is held in our own database and nowhere else: there is no customer-management service holding a copy of it.Annual review, no automatic expiry. Statutory retention periods for invoicing transactions remain unaffected: the lead is anonymised in that case.
Inbound interface logs and internal task listsTraceability of technical operations90 days, the same period the free analyses are held to.Reviewed and cleared by hand at present. The automatic job for it is being built; until it exists, the period is kept manually rather than left open.

10. Your rights

This is how you exercise those rights. Write an informal email to the address for data requests named above. We answer within one month. There is no self-service portal: every request is handled by hand. Internally, the data stored for an address is assembled across all the tables concerned and provided as a file, or deleted or anonymised. The procedures for that are recorded in an internal operations manual.

Two routes take effect immediately and need no request. The unsubscribe link at the end of every mail from this service stops all further mail of that kind. The unsubscribe link in the newsletter ends the newsletter. They are separate lists with separate links, and you can end one of them or both.

Unsubscribing through the link in one of our mails takes effect on our own records. It does not simultaneously end the subscription at the newsletter provider, because that is a separate list. If you want to end both, use both links or write to us once and we will do it.

  • Access under Art. 15 DSGVO to the data stored about you.
  • Rectification of inaccurate or incomplete data under Art. 16 DSGVO.
  • Erasure under Art. 17 DSGVO, in so far as no retention period stands in the way.
  • Restriction of processing under Art. 18 DSGVO.
  • Data portability under Art. 20 DSGVO in a common, machine-readable format.
  • Objection under Art. 21 DSGVO to processing based on a legitimate interest, see the separate notice below.
  • Withdrawal of a consent under Art. 7 Abs. 3 DSGVO with effect for the future.
  • Complaint to a supervisory authority under Art. 77 DSGVO.

11. Right to object under Art. 21 DSGVO

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is carried out on the basis of Art. 6 Abs. 1 lit. f DSGVO. We will then no longer process that data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where your data is processed for direct marketing, you have the right to object at any time. After the objection your data will no longer be processed for that purpose.

An objection is informal and subject to no particular form. An email is enough.

12. Objection to advertising emails

The use of the contact details published in the Impressum to send advertising and information material that has not been expressly requested is hereby objected to. We reserve the right to take legal action in the event of unsolicited advertising being sent.

13. Complaint to a supervisory authority

You can complain to a data protection supervisory authority at any time, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement. No particular form is prescribed and there is no deadline.

For us as a private-sector controller, the competent authority is that of the Bundesland in which we are established. The Federal Commissioner for Data Protection and Freedom of Information is not: that body supervises federal authorities and telecommunications and postal undertakings.

14. Data security

The connection to this website is encrypted throughout with TLS. The browser is additionally instructed to call this website only over an encrypted connection. Servers and database are in Germany. The administration area is password-protected and blocked from search engines. Of the IP addresses arising during an analysis, only a value that cannot be computed back is stored.

Nightly backups of the data are produced and the fourteen most recent are kept.

We do not claim encryption of storage media at rest, because we cannot evidence it at this point. No method of transmission over the internet is completely secure.

15. Minors

This service is not directed at persons under 16. We do not knowingly collect data from children. If we learn that data of a person under 16 has been transmitted to us without the required consent, we delete it.

16. Processing for another purpose

If we intend to process your data for a purpose other than the one it was collected for, we will inform you beforehand about that other purpose and about all further necessary information.

17. Changes to this privacy notice

We adapt this notice when the processing operations or the legal position change. The version published on this page, with the date given above, is the one that applies. We point out material changes separately.

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)

Postfach 20 04 44, 40102 Düsseldorf
Visiting address: Kavalleriestraße 2 bis 4, 40213 Düsseldorf

Telephone: 0211 38424-0

[email protected]

www.ldi.nrw.de/beschwerde