Legal

Privacy policy

Last updated:

This English text is the source version, and the German text is a translation of it.

This notice explains what happens to personal data when you visit this website, write to us or book a call. It follows Articles 12 to 14 GDPR. The short version: the site sets no cookies, runs no tracking and only stores what you type into a form yourself.

Controller

The controller for the processing described here, within the meaning of Article 4 (7) GDPR, is:

Ariavor, an independent practice run by Niklas Hoeppener
Email: info@ariavor.com

Data protection officer

We have not appointed a data protection officer, because the thresholds in Article 37 GDPR and § 38 BDSG are not met: the practice is a one-person one, and it neither monitors people systematically nor processes special categories of data as its core activity. Send any question about data protection to the email address above and it reaches the controller directly.

Where we process personal data we rely on one of the following, and each section below names the one that applies:

  • Article 6 (1) (a) GDPR — your consent, which you may withdraw at any time with effect for the future.
  • Article 6 (1) (b) GDPR — performance of a contract, or steps taken at your request before entering into one.
  • Article 6 (1) (c) GDPR — compliance with a legal obligation, such as the retention periods in commercial and tax law.
  • Article 6 (1) (f) GDPR — our legitimate interest in a secure, working and reasonably administered website, weighed against your rights.

Hosting and server log files

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Every time a page is requested your browser necessarily transmits technical data, which the provider records in server log files:

  • the IP address of the requesting device
  • the date and time of the request, the URL requested and the HTTP status code returned
  • browser type and version, operating system and the referring page
  • the volume of data transferred

The legal basis is Article 6 (1) (f) GDPR, our legitimate interest in delivering the site reliably and defending it against attack. This data is never merged with other sources and never used to identify you, and the provider deletes it after a short period, at the latest after 30 days. A data processing agreement under Article 28 GDPR is in place. Because the provider is established in the United States, data may be transferred there on the basis of the EU standard contractual clauses and the EU-US Data Privacy Framework.

Cookies, tracking and fonts

This site sets no cookies, writes nothing to local storage and embeds no analytics, advertising or social media service. There is no consent banner because there is nothing to consent to under § 25 TDDDG. The typefaces are served from our own server rather than a font CDN, so no request about you leaves the site while a page renders. The language you read a page in comes from the URL, not from anything stored on your device.

Contact form

The contact form asks for your name and email address, and optionally your company, what you need help with and a message. We use what you send to answer your enquiry and to prepare the work you are asking about, so the legal basis is Article 6 (1) (b) GDPR where the enquiry concerns a contract, and otherwise Article 6 (1) (f) GDPR, our legitimate interest in replying to people who write to us. The entry is stored in our database, which runs on Turso, operated by Chiselstrike, Inc., USA, under a data processing agreement and again subject to the standard contractual clauses. We keep the entry until your enquiry is settled and there is nothing left to follow up, unless commercial or tax law requires us to keep it longer.

Email correspondence

Mail sent to us is received and stored in Microsoft 365, provided in the EU by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. We process the address you write from and everything you choose to put in the message, on the same legal bases as the contact form. Email leaves our control in transit: it is transported encrypted wherever the receiving server supports it, yet we cannot guarantee end-to-end security, so please do not send anything confidential by email unencrypted.

Booking a call

The buttons that offer a call link to CalendarBridge, a scheduling service operated by CalendarBridge, Inc., USA. Following one of those links takes you to the provider, whose own privacy notice then applies to the booking page; we do not see anything about you until you complete a booking. What reaches us is the name, email address and time you chose, which we process under Article 6 (1) (b) GDPR to hold the meeting you asked for, and which we record alongside contact form entries in the same database.

Journal

Articles in the journal are rendered from our own content store and served from the same domain as the rest of the site. There is no comment function, no newsletter sign-up and no embedded video or social widget, so reading an article involves no processing beyond the server log files described above.

Recipients and processors

We do not sell personal data and we do not pass it on for advertising. Apart from the processors named above, data reaches a third party only where a legal obligation, a court order or the defence of legal claims requires it. The full list of processors is:

  • Vercel Inc., USA — hosting and delivery of the website
  • Chiselstrike, Inc. (Turso), USA — the database holding contact form and booking entries
  • Microsoft Ireland Operations Limited, Ireland — email and office software
  • CalendarBridge, Inc., USA — scheduling for the calls you book

How long we keep data

We delete personal data as soon as the purpose it was collected for no longer applies. Server log files go after 30 days at the latest. An enquiry that leads nowhere is deleted once it is clear that nothing further will come of it, and at the latest after three years counted from the end of the year in which we last heard from you. Where a contract follows, the documents that commercial and tax law require us to keep are retained for six or ten years under § 257 HGB and § 147 AO, and they are blocked for any other use in the meantime.

Your rights

As a data subject you have the following rights, which you can exercise free of charge by writing to the address above. Please describe what you want clearly enough for us to act on it, and expect an answer within one month.

  • Access, Article 15 GDPR — confirmation of whether we process data about you, and a copy of it.
  • Rectification, Article 16 GDPR — correction of inaccurate data and completion of incomplete data.
  • Erasure, Article 17 GDPR — deletion, where no retention obligation stands in the way.
  • Restriction, Article 18 GDPR — processing limited to storage while a dispute about the data is resolved.
  • Portability, Article 20 GDPR — the data you gave us in a structured, machine-readable format.
  • Objection, Article 21 GDPR — see the section below.
  • Withdrawal of consent, Article 7 (3) GDPR — at any time, without affecting what was lawful before.
  • Complaint, Article 77 GDPR — to the supervisory authority of your habitual residence, place of work or of the alleged infringement.

Right to object

Where we process data on the basis of Article 6 (1) (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. If you do, we will stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims. We do not process personal data for direct marketing, so no separate objection is needed for that.

Security

The site is served over TLS throughout, which you can check by the lock in your browser bar, so what you send through a form cannot be read in transit. Beyond that we take appropriate technical and organisational measures under Article 32 GDPR to protect the data we hold, and we review them as the site changes. No method of transmission over the internet is completely secure, and we say so plainly rather than promise otherwise.

Changes to this notice

We update this notice whenever the site changes in a way that affects it, for instance when a processor is added or dropped. The date at the top tells you which version you are reading. Material changes to processing that already concerns you will be flagged to you directly where the law requires it.

Back to the homepage