← Back to home

Privacy policy

As of 13 September 2026

1. Controller

The controller under the General Data Protection Regulation (GDPR) is:

Esra Medik
Sole proprietorship
Fährstraße 217
40221 Düsseldorf
Germany

Email: info@hierankommen.de
Telephone: +49 179 1474777
Website: hierankommen.de

No company data protection officer has been appointed, as there is no legal obligation to do so.

2. General information on data processing

Protecting your personal data matters to us. Personal data means information that can identify you. This policy explains what we process when you visit the website or use our services, why we do so and your rights.

3. Legal bases for processing

Where a legal basis is required, we rely on the following as appropriate:

  • Article 6(1)(a) GDPR — your consent.
  • Article 6(1)(b) GDPR — contract performance or pre-contract steps at your request.
  • Article 6(1)(c) GDPR — compliance with a legal obligation.
  • Article 6(1)(f) GDPR — legitimate interests unless your interests override them.

The applicable basis is specified for each processing activity below.

4. Website provision and ALL-INKL hosting

This website and business email mailboxes are hosted by:

ALL-INKL.COM – Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68
02742 Friedersdorf
Germany

Visiting the site may involve necessary connection and log data: IP address, request date/time, page or file, referrer URL, browser, OS, data volume and requesting provider (server logs).

Where a provider processes personal data on our behalf, we conclude an Article 28 GDPR processing agreement if legally required. Such an agreement exists with ALL-INKL.COM – Neue Medien Münnich. Providers acting as independent controllers process under their own privacy policies.

Purposes are secure provision, stability, troubleshooting and preventing abuse. The basis is our legitimate interest in a secure, stable, functional website (Article 6(1)(f) GDPR).

5. Server logs

The logs listed in section 4 are collected automatically solely for secure, stable site provision. They are not combined with other data sources.

ALL-INKL normally deletes server logs within seven days. Longer retention may be necessary, especially to investigate an attack. More information in ALL-INKL's privacy information.

6. SSL or TLS encryption

For security this site uses SSL/TLS encryption. You can recognise an encrypted connection by “https” and the lock icon in your browser bar.

7. Contact by email and telephone

When you contact us, we process details such as name, contact information and message to handle your request. Basis: Article 6(1)(b) GDPR for contractual enquiries, or 6(1)(f) for other requests.

Email processing via Apple iCloud

Business emails to hierankommen.de addresses may be forwarded to or synchronised and stored in an iCloud mailbox we use for central communication management.

This may include name, email address, communication time, technical metadata, message content and attachments.

Service provider:

Apple Distribution International Limited
Hollyhill Industrial Estate
Hollyhill, Cork
Ireland

Processing handles enquiries and organises business communication. Contract initiation/performance uses Article 6(1)(b) GDPR; otherwise our legitimate interest in reliable, efficient communication under 6(1)(f).

Apple may process data through affiliates or providers outside the EEA, particularly in the USA. Apple states that EEA international transfers are safeguarded particularly by European Commission standard contractual clauses.

Email content is deleted once no longer needed for the enquiry, unless statutory retention or other legitimate reasons require longer storage.

Further information: https://www.apple.com/de/legal/privacy/de-ww/

8. Contact form

Private contact forms require name, email and message; business forms require name, company and email. Other details, such as phone, desired offer, staff count or support type, are optional. No file uploads. Your message is emailed to info@hierankommen.de .

Processing is solely to handle your request. Basis: Article 6(1)(b) GDPR for pre-contractual/contractual requests, and 6(1)(f) for other business enquiries.

Forms are sent through Brevo's transactional API (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany; parent Brevo SAS, France). Brevo processes form and technical sending data on our behalf to transmit and handle the request. No newsletter or advertising lists are created. See Brevo's policy for further processing and retention. Basis: Article 6(1)(b) or (f) GDPR, with a legitimate interest in reliable, traceable receipt. More information: https://www.brevo.com/de/legal/privacypolicy/

To prevent automated abuse, we limit sending attempts per access. Your IP address is not stored. Instead, a secret key generates a pseudonymous HMAC-SHA256 value used with a counter for a 15-minute checking window, then regularly deleted automatically. No form content is stored for this. Basis: Article 6(1)(f) GDPR, protection against abuse and overload.

Details are retained only as needed for your request, subject to statutory periods. No newsletter or advertising use without separate consent.

9. Bookings and contract handling

Depending on the booking, we process first/last name, email, optional phone, billing address, course and dates, booking number/time, price, payment status, necessary contractual declarations and the terms/withdrawal versions in force at booking.

Purposes: booking, contracting, payment, organising attendance, communication and statutory evidence/retention duties.

Basis: Article 6(1)(b) GDPR for contract initiation/performance, 6(1)(c) for statutory retention/evidence. Contract and billing records are stored for applicable statutory periods, then deleted unless another legal basis exists.

9a. Accounts and memberships (Supabase)

We use Supabase authentication and database for registration, login, accounts and membership management. Provider: Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Data: email, encrypted stored password or credentials, confirmation/login times, technical session data, membership status and booked plan assignment.

Purposes are a protected account, assigning booked services and secure login. Basis: Article 6(1)(b) GDPR, since accounts are needed for membership services, and 6(1)(f) for access security.

Account data are deleted when the account is deleted, unless statutory retention prevents it.

Primary project data are stored in West EU (Ireland), eu-west-1. This does not promise exclusively European processing; third-country transfers, especially for provider support/operations, are possible. Use is based on Supabase's standard terms, which incorporate the data processing agreement . Section 12 and Schedule 2 contain standard contractual clauses for covered transfers.

Draft note: based on the provider's public standard terms and dashboard region. No individually negotiated or separately signed agreement or independent safeguards review exists. Obtain legal review before publication.

10. Payment processing via Stripe

We use Stripe Checkout hosted by Stripe Payments Europe, Ltd. Stripe is accessed only when you actively continue to payment.

Stripe processes booking, contact, billing, device and payment data needed for payment. Full card/bank details are not stored on our website. Other providers such as PayPal or Klarna may be involved depending on your method.

Purpose: contract/payment processing. Basis: Article 6(1)(b) GDPR, plus 6(1)(c) for accounting/evidence obligations. Stripe may independently process more data for fraud prevention/security, also outside the EEA.

For further details, especially third-country transfers and safeguards, see Stripe's privacy policy.

PayPal and Klarna payment methods

Depending on availability, Stripe Checkout may offer PayPal or Klarna. Only after selecting one may required payment data be sent to that provider.

This may include name, contact/billing data, order/contract data, amount, transaction and technical data, and payment details for the selected method. Transfer performs your chosen payment under Article 6(1)(b) GDPR.

Selecting PayPal may send data to:

PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg

Privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full

Selecting a Klarna method may send data to:

Klarna Bank AB (publ)
Sveavägen 46
111 34 Stockholm
Sweden

Depending on payment type, Klarna may independently conduct identity, fraud or credit checks and process additional data or credit agency information.

Privacy policy: https://www.klarna.com/de/datenschutz/

PayPal/Klarna's own policies additionally govern their further processing. We send no payment-related data to a provider unless you select its method.

11. Scheduling with Cal.com

Currently no online scheduling is embedded and no booking-service data is collected. The following applies only if we activate Cal.com for appointments such as consultations. Cal.com does not load automatically. You first see a notice and a button; the calendar loads only on clicking it. Before loading we explain that data will be sent to Cal.com.

Data may include name, email, optional phone, selected appointment, timezone, booking-form entries, IP and technical connection data.

Purposes: scheduling, avoiding double bookings, organising discussions. Basis: Article 6(1)(b) for pre-contract appointments; if embedded only after explicit consent, 6(1)(a) and where applicable section 25(1) TDDDG. More in the current Cal.com's privacy policy.

12. Connection to Google Calendar

Cal.com may connect to Google Calendar to check availability, avoid double bookings and organise appointments. Event title, date, time, duration, name, email and other necessary details may be transferred to the linked calendar; Google may receive them.

Basis: Article 6(1)(b) for contractual steps/performance or 6(1)(a) where voluntary consent is needed. Appointment data are deleted when no longer needed for scheduling/follow-up unless legal retention or other legitimate reasons apply.

Google may process outside the EEA. This calendar connection uses no other Google services such as Analytics or Ads. More on safeguards and transfers in Google's privacy policy.

13. Online lessons and meetings via Microsoft Teams

Live lessons and one-to-one meetings use Microsoft Teams through a Microsoft 365 Business account. Data may include name/display name, email, meeting metadata, IP, device/connection data and voluntarily transmitted audio, video and chat. Camera/microphone are used only when you activate them.

We do not record or transcribe lessons.

Processing delivers the booked lesson or agreed discussion. Basis: Article 6(1)(b); voluntary features unnecessary for the contract may use 6(1)(a). Microsoft may process outside the EU; more on transfers/safeguards in the Microsoft privacy notice.

14. Contact via WhatsApp

We use only an ordinary WhatsApp link, not an embedded chat widget. Normal page visits do not connect to WhatsApp; clicking opens WhatsApp or WhatsApp Web.

WhatsApp use is voluntary; email and phone are alternatives. Clicking may transfer phone number, profile information, messages, communication metadata, IP and device data to WhatsApp/Meta.

Our handling uses Article 6(1)(b) or (f) depending on content. WhatsApp/Meta's own policies govern further processing, including outside the EEA; see WhatsApp's privacy information.

15. Links to Instagram, TikTok and YouTube

We use ordinary profile links only. No feeds, videos, like buttons or tracking pixels are embedded automatically.

A normal visit does not connect through these links to platforms. Only clicking opens a platform, which then processes data independently. See the policies of Instagram/Meta, TikTok and YouTube/Google.

16. Cookies and similar technologies

We use no analytics, marketing or advertising cookies on this website.

Necessary cookies or similar storage solely ensure a secure, working site and your requested account/booking features. Local/Session Storage supports login, passing your selected plan to booking and a password-recovery timestamp. You can delete it in browser settings, which may require logging in or choosing a plan again. Device storage/access is based on section 25(2)(2) TDDDG; related personal data processing on Article 6(1)(f) GDPR.

Optional external content/services, especially any Cal.com calendar, must load only after active consent. No provider connection before consent. Bases: section 25(1) TDDDG and Article 6(1)(a) GDPR.

Consent is voluntary and may be withdrawn or changed for the future at any time, e.g. by email to info@hierankommen.de. Prior lawful processing is unaffected.

16a. External JavaScript libraries

React and ReactDOM load via unpkg.com for site display/interaction. Babel may also load there for embedded scripts. The Supabase account library loads when needed via cdn.jsdelivr.net.

Fetching connects your browser to the delivery service, transmitting IP and technical request data, especially file and HTTP headers. This provides site features; we do not use these libraries for behavioural analytics or advertising.

Service information: UNPKG and jsDelivr privacy information.

17. Google Search Console

We use Google Search Console only to technically monitor visibility and indexing. Its use alone sets no extra analytics cookies; we do not use Google Analytics. Domain verification uses a DNS record.

18. Recipients and processors

We share only as necessary for contracts, legal obligations, consent or lawful legitimate interests. Where legally required, providers processing on our behalf have Article 28 GDPR agreements; one exists with ALL-INKL.COM – Neue Medien Münnich. Independent controllers such as Stripe, Cal.com, Google, Zoom or WhatsApp/Meta process under their own policies.

19. Transfers to third countries

Services such as Stripe, Teams, WhatsApp/Meta or Google may process outside the EEA. Safeguards are described in provider policies linked in the relevant sections.

20. Retention periods

We retain personal data only as needed for stated purposes. Logs are deleted when unnecessary unless security or legal duties require them. Contract/accounting records follow statutory periods, then deletion unless a further basis exists.

21. Obligation to provide personal data

For contracting, you must provide necessary data; without it we may be unable to process enquiries, bookings or payments. Voluntary contact creates no legal obligation to provide data.

22. No automated decision-making

We make no solely automated decisions with legal or significant effects and do no profiling. Do not send health, identity or residence documents through the general contact form; we do not request special-category data under Article 9 GDPR through the website.

We ourselves make no solely automated legally/significantly affecting decisions. Independently, selected payment providers may perform automated security, fraud, identity or credit checks on their own responsibility.

23. Your rights as a data subject

Subject to statutory requirements, you have these rights:

  • Access your stored data (Article 15 GDPR)
  • Correct inaccurate data (Article 16 GDPR)
  • Delete your data (Article 17 GDPR)
  • Restrict processing (Article 18 GDPR)
  • Data portability (Article 20 GDPR)

To exercise these rights, contact info@hierankommen.de at any time.

24. Withdrawing consent

You may withdraw consent for the future at any time (Article 7(3) GDPR), for example by email to info@hierankommen.de. This does not affect the lawfulness of prior processing.

25. Right to object

You may object at any time, for reasons specific to your situation, to processing based on Article 6(1)(f) (Article 21 GDPR). We then stop unless we demonstrate compelling grounds overriding your interests or processing serves the establishment, exercise or defence of legal claims.

26. Complaints to a supervisory authority

You may complain to a data protection authority about our processing (Article 77 GDPR), particularly:

North Rhine-Westphalia Commissioner for Data Protection and Freedom of Information
Kavalleriestraße 2–4
40213 Düsseldorf
Telephone: 0211 38424-0
Website: www.ldi.nrw.de

27. Cloudflare Turnstile

We use Cloudflare Turnstile to protect login/account features. It loads only for registration, login, resending confirmation, password reset, private/business contact forms and cancellation/withdrawal forms.

It distinguishes human access from automated/abusive access and protects accounts, authentication and form sending.

Provider:

Cloudflare, Inc.
101 Townsend St
San Francisco, CA 94107
USA

Data may include IP, TLS fingerprint, user agent, public site key, referring page and technical browser/device signals. Cloudflare states Turnstile does not read, store or transfer form entries, messages or other page content.

Basis: Article 6(1)(f) GDPR, our legitimate interest in service/account security and preventing automated abuse. We do not use Turnstile for advertising/marketing.

US processing cannot be excluded. Cloudflare refers to the EU–US Data Privacy Framework and standard contractual clauses in its Data Processing Addendum, among other safeguards.

For further processing and retention, see Cloudflare's privacy information:

Turnstile privacy information: https://www.cloudflare.com/turnstile-privacy-policy/
General privacy policy: https://www.cloudflare.com/privacypolicy/
Data Processing Addendum: https://www.cloudflare.com/cloudflare-customer-dpa/

28. Updates and changes to this policy

This policy reflects the date above. Site development or changed legal/official requirements may require updates. The current version is always on this page.