Deecke Financial Solutions

Privacy Policy

1.Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to our privacy policy listed below this text.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. Their contact details can be found in the section “Information on the Responsible Party” in this privacy policy.

How do we collect your data?

Your data is collected, on the one hand, by you providing it to us. This may, for example, be data you enter into a contact form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g., internet browser, operating system, or time of page access). Such data is collected automatically as soon as you enter this website.

What do we use your data for?

Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.

For this and other questions on the subject of data protection, you can contact us at any time.

2.Hosting

We host the content of our website with the following provider:

External Hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the host(s). This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated through a website.

External hosting is carried out for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6 para. 1 lit. f GDPR). Where consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s end device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

Our host(s) will only process your data to the extent necessary to fulfill its performance obligations and will follow our instructions regarding this data.

We use the following host(s):

united-domains GmbHGautinger Straße 1082319 StarnbergGermany

Order Processing

We have concluded a data processing agreement (DPA) for the use of the service mentioned above. This is a contract required under data protection law that ensures that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.

3.General Information and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We point out that data transmission over the internet (e.g., when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.

Information on the Responsible Party

The responsible party for data processing on this website is:

DEECKE Insurance Broker GmbHAugustaanlage 3268165 MannheimGermany

Legal form: Gesellschaft mit beschränkter Haftung (GmbH). Represented by its managing director Jochen Deecke. Registered in the commercial register under HRB 309997. This website is operated under the brand “Deecke Financial Solutions”.

DEECKE Insurance Broker GmbH is also the holder of the permit under § 34f para. 1 GewO (German Trade Regulation Act), the holder of the Meta advertising account through which the advertisements on Facebook and Instagram are placed, and the owner of the domain under which this website is operated. All processing described in this privacy policy is therefore carried out by one and the same responsible party.

The responsible party is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a more specific storage period has been mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a justified request for deletion or revoke consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., retention periods under tax or commercial law); in the latter case, deletion will take place after these reasons have ceased to apply.

General Information on the Legal Bases for Data Processing on This Website

If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, insofar as special data categories under Art. 9 para. 1 GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also based on Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or to access to information on your end device (e.g., via device fingerprinting), data processing is additionally based on § 25 para. 1 TDDDG. Consent can be revoked at any time. If your data is required for the fulfillment of a contract or for pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if it is necessary to fulfill a legal obligation, on the basis of Art. 6 para. 1 lit. c GDPR. Data processing may also be based on our legitimate interest under Art. 6 para. 1 lit. f GDPR. Information on the legal bases applicable in each individual case is provided in the following paragraphs of this privacy policy.

Information on Data Transfer to Third Countries Not Considered Safe Under Data Protection Law and Transfer to Non-DPF-Certified US Companies

Among other things, we use tools from companies based in third countries that are not considered safe under data protection law, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. We point out that no level of data protection comparable to that in the EU can be guaranteed in third countries that are not considered safe under data protection law.

We point out that the USA, as a safe third country, generally has a level of data protection comparable to that of the EU. Data transfer to the USA is therefore permissible if the recipient holds a certification under the “EU-US Data Privacy Framework” (DPF) or has appropriate additional safeguards. Information on transfers to third countries, including the data recipients, can be found in this privacy policy.

Recipients of Personal Data

In the course of our business activities, we work with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only pass on personal data to external parties if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g., transfer of data to tax authorities), if we have a legitimate interest under Art. 6 para. 1 lit. f GDPR in the transfer, or if another legal basis permits the data transfer. When using order processors, we only pass on personal data of our customers on the basis of a valid order processing agreement. In the case of joint processing, a joint processing agreement is concluded.

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ART. 21 PARA. 2 GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged violation. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible.

Information, Correction, and Deletion

Within the scope of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of data processing and, if applicable, a right to correction or deletion of this data. For this and other questions on the subject of personal data, you can contact us at any time.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is carried out unlawfully, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need it for the exercise, defense, or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
  • If you have lodged an objection under Art. 21 para. 1 GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data — apart from being stored — may only be processed with your consent or for the assertion, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.

SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

4.Data Collection on This Website

Cookies

Our internet pages use so-called “cookies.” Cookies are small data packets and do not cause any damage to your end device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your end device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or your web browser automatically deletes them.

Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for handling payment services).

Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.

Cookies that are necessary for the implementation of the electronic communication process, for the provision of certain functions you have requested (e.g., for the shopping cart function), or for the optimization of the website (e.g., cookies for measuring the web audience) (necessary cookies) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG); consent can be revoked at any time.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when the browser is closed. If cookies are deactivated, the functionality of this website may be limited.

You can find out which cookies and services are used on this website in this privacy policy.

Inquiry Form for the Personal Initial Consultation

If you contact us via the inquiry form on this website, we process the details you enter there. We collect: first name, last name, email address, telephone number including the country code you select, your answer to the question about your intended investment volume, and your confirmation that you have taken note of this privacy policy. We additionally store the language version of this website you used and the time of submission.

The purpose of the processing is to handle your inquiry and to prepare and carry out the personal initial consultation you requested. The legal basis is Art. 6 para. 1 lit. b GDPR, as the processing serves to carry out pre-contractual measures taken at your request.

Providing your first name, last name, email address, telephone number, and investment volume is necessary for us to process your inquiry; without this information we cannot offer you an initial consultation. The form can also only be submitted if you confirm that you have taken note of this privacy policy. There is no obligation to provide any data beyond this.

The data remains with us until you ask us to delete it, revoke a consent you have given, or the purpose for storage no longer applies. We review inquiries that have not led to a business relationship after three years at the latest and delete them, unless retention obligations prevent this. Mandatory statutory provisions — in particular retention periods under commercial and tax law, as well as the retention obligations for financial investment brokers under § 34f GewO in conjunction with the German Financial Investment Brokerage Ordinance — remain unaffected.

Question on the Intended Investment Volume

The form contains one qualifying question: “Would you like to invest from €100,000?” We transmit your answer (“Yes” or “No”) together with your contact details to our customer relationship management system and store it there in the field for the intended investment volume. We use the answer solely to assign your inquiry to the appropriate advisor and to assess whether our offering — which is aimed at an investment volume of €100,000 and above — is a possible fit for you.

No automated decision-making in individual cases, including profiling within the meaning of Art. 22 GDPR, takes place in this context: a human being always decides whether and how we contact you. The legal basis is Art. 6 para. 1 lit. b GDPR. Your answer does not determine the outcome of your inquiry in any automated way and in particular does not lead to an automatic rejection.

Consent to Marketing Emails

The form contains an additional, non-pre-ticked checkbox with which you can consent to occasionally receiving news and market analyses from us by email. This consent is separate from the handling of your inquiry: you can request the initial consultation even if you do not tick the box, and you suffer no disadvantage as a result.

The legal basis for sending these marketing emails is exclusively your consent under Art. 6 para. 1 lit. a GDPR in conjunction with § 7 para. 2 no. 2 UWG (German Act Against Unfair Competition). Your consent is documented together with your inquiry and the time it was given so that we are able to demonstrate it (Art. 7 para. 1 GDPR).

You can revoke this consent at any time with effect for the future, without this affecting your inquiry or an existing business relationship. Revocation is possible informally, for example via the unsubscribe link in every marketing email or by sending a message to service@deecke-financialsolutions.com. The legality of the processing carried out until the revocation remains unaffected. Following a revocation we store your email address on a suppression list to ensure that you receive no further marketing emails; the legal basis for this is our legitimate interest under Art. 6 para. 1 lit. f GDPR.

Arranging the Initial Consultation Appointment

The “Book Now” and “Request Initial Consultation” buttons take you to the inquiry form described above within this website. We do not use an external calendar or booking tool to arrange appointments, nor do we embed any third-party booking calendar in this website; no connection to any further provider is established in the process.

Once your inquiry has reached us, one of our advisors will contact you personally by email or telephone to agree on an appointment. The resulting correspondence and the agreed appointment are documented in your record in our customer relationship management system. The legal basis is Art. 6 para. 1 lit. b GDPR.

5.Analytics Tools and Advertising

Google Ads

The website operator uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads enables us to display advertisements in the Google search engine or on third-party websites when the user enters certain search terms on Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available to Google (e.g., location data and interests) (audience targeting). As the website operator, we can quantitatively evaluate this data by, for example, analyzing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards in data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

Meta Pixel and Conversions API

This website uses the Meta visitor action pixel (“Meta Pixel”) to measure conversions. The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”).

The Meta Pixel is only loaded after you have consented to the “Marketing” category in the cookie banner. As long as this consent has not been given, neither is the pixel code executed nor is a connection to Meta’s servers established, and no corresponding cookies are set.

When the pixel is active, Meta can track the behavior of visitors who were forwarded to this website by clicking on a Meta advertisement. This allows the effectiveness of the advertisements to be evaluated for statistical and market research purposes and future advertising measures to be targeted more precisely. In particular, we record page views on this website (the “PageView” event) and the successful submission of the inquiry form (the “Lead” event), in each case together with your IP address, details of your browser and end device, and the cookies set by the pixel (including “_fbp” and “_fbc”).

The data collected in this way is anonymous to us as the operator of this website; we cannot draw any conclusions about the identity of individual users from it. However, the data is stored and processed by Meta and can be linked to the respective user profile. Meta may use it for its own advertising purposes in accordance with the Meta data policy and thereby enable the display of advertisements on Facebook, Instagram, and beyond these platforms. We have no influence over this use.

In addition to collection in the browser, the same events may be transmitted server-side via Meta’s Conversions API. In this case our systems send the event data directly to Meta, even if the browser pixel is prevented from running, for example by an ad blocker. Personal identifiers such as email address and telephone number are transmitted exclusively in hashed form (SHA-256) and are used by Meta only to match them against existing user accounts. Transmission via the Conversions API likewise only takes place if you have previously consented to the “Marketing” category.

The use of the Meta Pixel and the Conversions API is based exclusively on your consent under Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. You can revoke this consent at any time with effect for the future by changing your selection via the “Cookie Settings” button in the footer of this website.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Meta Platforms, Inc. is furthermore certified under the “EU-US Data Privacy Framework” (DPF); you can view the certification in the official list at https://www.dataprivacyframework.gov/list. Details of the processing carried out by Meta can be found in Meta’s privacy policy at https://www.facebook.com/privacy/policy/. Meta explains how you can object to the use of your data for advertising purposes at https://www.facebook.com/settings?tab=ads.

Joint Controllership with Meta (Art. 26 GDPR)

For the collection of data by means of the Meta Pixel and its transfer to Meta, we and Meta Platforms Ireland Limited are joint controllers within the meaning of Art. 26 GDPR. We have concluded a joint processing agreement with Meta on this (the “Controller Addendum”), which you can access at https://www.facebook.com/legal/controller_addendum.

The essence of this agreement is as follows: the joint controllership is expressly limited to the collection of the data on this website and its transfer to Meta. We and Meta are jointly responsible only for this part of the processing. The subsequent processing of the data by Meta — in particular its combination with user accounts, the building of audiences, and the display of advertising — is Meta’s sole responsibility.

In the agreement, Meta has assumed primary responsibility for safeguarding data subject rights under Art. 15 to 22 GDPR. You can therefore assert rights concerning the jointly controlled processing directly against Meta; Meta answers such requests via the channels named in its privacy policy. You are of course also welcome to contact us — we will then forward your request to Meta. We fulfill the information obligations under Art. 13 and 14 GDPR towards you with this section; Meta provides information on its own processing in its privacy policy.

We have further agreed with Meta that Meta is responsible for the security of processing under Art. 32 GDPR and for reporting personal data breaches under Art. 33 GDPR, insofar as the data is processed at Meta. The agreement also provides that Meta processes the data exclusively on servers for which appropriate safeguards for transfers to third countries are in place.

Facebook and Instagram Lead Ads (Instant Forms)

We place advertisements with a so-called instant form (Meta “Lead Ads”) on Facebook and Instagram. If you click on such an advertisement, the form opens directly within the Facebook or Instagram app. You do not leave the platform in the process; the collection initially takes place entirely on Meta’s systems and not on this website.

The instant form collects the details you enter or confirm there — as a rule first name, last name, email address, and telephone number, as well as your answer to the question about your intended investment volume. Meta pre-fills individual fields from the details stored in your user profile; you can change or delete these before submitting. The data is only transmitted to us once you submit the form.

After transmission we process the data in the same way as an inquiry received via the inquiry form on this website: it is transferred into our customer relationship management system and used to prepare the initial consultation you requested. The legal basis for this is Art. 6 para. 1 lit. b GDPR (carrying out pre-contractual measures). For the collection within the platform, the consent you declared to Meta is additionally decisive; Meta’s own privacy notices apply to the processing carried out by Meta itself.

We and Meta are also joint controllers within the meaning of Art. 26 GDPR for the data collected via instant forms; the agreement described in the preceding section applies, and you can assert your rights against both us and Meta. Insofar as data is transferred to the USA in this context, the transfer is based on the standard contractual clauses of the EU Commission and on the DPF certification of Meta Platforms, Inc. We delete the data transmitted to us by Meta under the same conditions as the data collected via the inquiry form on this website.

6.Plugins and Tools

Google Fonts (Local Hosting)

This site uses so-called Google Fonts, which are provided by Google, for the uniform display of fonts. The Google Fonts are installed locally. No connection to Google’s servers takes place in the process.

Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=de.

Wordfence

We have integrated Wordfence on this website. The provider is Defiant Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter “Wordfence”).

Wordfence serves to protect our website from unwanted access or malicious cyberattacks. For this purpose, our website establishes a permanent connection to the servers of Wordfence so that Wordfence can compare its databases with the accesses made on our website and block them if necessary.

The use of Wordfence is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its website as effectively as possible from cyberattacks. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s end device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.wordfence.com/help/general-data-protection-regulation/.

Order Processing

We have concluded a data processing agreement (DPA) for the use of the service mentioned above. This is a contract required under data protection law that ensures that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.

HubSpot (Customer Relationship Management)

We use the HubSpot CRM system to manage inquiries and customer relationships. The provider for users in the European Economic Area is HubSpot Ireland Limited, 1 Sir John Rogerson’s Quay, Dublin 2, Ireland; the parent company is HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA (hereinafter “HubSpot”).

All data you transmit to us via the inquiry form on this website or via an instant form on Facebook or Instagram is stored in HubSpot: first name, last name, email address, telephone number, your answer to the question about your intended investment volume, the source of the inquiry, and the responsible advisor. We additionally document the further course of the contact there, such as the correspondence conducted with you and appointments agreed.

We use HubSpot in order to handle inquiries in a structured and traceable manner and to look after prospective clients reliably. The legal basis is Art. 6 para. 1 lit. b GDPR insofar as the processing serves to carry out pre-contractual measures or to perform a contract, and otherwise our legitimate interest in the efficient and traceable management of customer relationships under Art. 6 para. 1 lit. f GDPR.

This website does not embed any HubSpot scripts, tracking codes, or forms. The transfer takes place exclusively server-side after you have submitted the form; HubSpot does not set any cookies on your end device in the process and receives no information about your visit to this website.

A transfer of data to the USA cannot be ruled out. It is based on the standard contractual clauses of the EU Commission; HubSpot, Inc. is furthermore certified under the “EU-US Data Privacy Framework” (DPF). Details can be found in HubSpot’s privacy policy at https://legal.hubspot.com/privacy-policy.

Order Processing

We have concluded a data processing agreement (DPA) for the use of the service mentioned above. This is a contract required under data protection law that ensures that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.

Resend (Email Delivery)

For sending the emails issued in connection with your inquiry — the confirmation of receipt to you and the internal notification to the responsible advisor — we use the Resend service. The provider is Resend, Inc., San Francisco, California, USA (hereinafter “Resend”).

In this context we process your email address, your first and last name, and the content of the respective message, as well as technical delivery data such as the time of dispatch and the delivery status. The legal basis is Art. 6 para. 1 lit. b GDPR, as the confirmation forms part of handling your inquiry, and our legitimate interest in technically reliable email delivery under Art. 6 para. 1 lit. f GDPR.

Resend processes the data on our behalf and in doing so also in the USA. The transfer is based on the standard contractual clauses of the EU Commission. Details can be found in Resend’s privacy policy at https://resend.com/legal/privacy-policy.

Order Processing

We have concluded a data processing agreement (DPA) for the use of the service mentioned above. This is a contract required under data protection law that ensures that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.