Skip to content
Monthly long-form articles on service, vendor management and outbound Subscribe free of charge (German) Berlin · aleksander@agrosz.de
Home · Privacy policy

Privacy policy

Please note: this is a courtesy translation. The legally binding version is the German Datenschutzerklärung. Statutory references are given in their original German form, since German and EU law applies.

A) Privacy policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Aleksander Grosz
Edmonton-Platz 16
14513 Teltow
Germany
Telephone: +49 (0) 163 641 80 90
Email: aleksander@agrosz.de

2. General information on data processing

I process personal data only where this is necessary in order to provide a functioning website and my content and services, or where you have given your consent.

Legal bases

  • Article 6(1)(b) GDPR (contract or pre-contractual measures)
  • Article 6(1)(f) GDPR (legitimate interests, e.g. security and operation)
  • Article 6(1)(a) GDPR (consent)

Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) applies in addition to access to terminal equipment (cookies and local storage).

No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place.

3. Hosting and content delivery network (CDN) via Netlify

This website is provided via Netlify (hosting and delivery through a CDN).

Service provider: Netlify, Inc. (USA)

Each time the website is accessed, Netlify processes technically necessary data in server log files, in particular:

  • IP address
  • date and time of the request
  • page or URL accessed
  • referrer URL
  • browser type and version, operating system
  • where applicable, status codes and volume of data transferred

Purpose: technical delivery of the website, stability and security (e.g. error analysis and defense against attacks).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in secure, stable operation).

4. Forms (contact and appointment requests): sending via Resend

If you contact me through forms on this website or request an appointment, the data you enter is transmitted to me by email. I use the Resend service to send these emails, an offering of Plus Five Five, Inc. (“Resend”), San Francisco, USA (resend.com).

Data processed (depending on the form and your entries)

  • name
  • email address
  • optional: company or organization
  • optional: preferred appointment, time, preferred type of contact, message text and any further information you enter
  • technical metadata (e.g. time of transmission, delivery information)

Form data is technically received through the hosting at Netlify (see section 3). For the purpose of sending email, the data is transferred to servers operated by Resend in the USA and processed there on my behalf.

Purpose: handling your inquiry, communicating with you, delivering the form message, and protection against misuse (spam and attacks).
Legal basis: Article 6(1)(b) GDPR (pre-contractual measures and inquiries); otherwise Article 6(1)(f) GDPR (legitimate interest in handling inquiries effectively, operational security and prevention of misuse).

I have concluded a data processing agreement (Data Processing Addendum) with Resend pursuant to Article 28 GDPR. Resend is certified under the EU-US Data Privacy Framework (DPF) including the UK Extension; to that extent the transfer to the USA is covered by the adequacy decision of the European Commission (Article 45 GDPR). In addition, the data processing agreement contains the European Commission's standard contractual clauses (Article 46(2)(c) GDPR). Further information: resend.com/legal/privacy-policy

5. External resources

This website does without externally embedded resources: scripts, stylesheets, fonts and images are delivered entirely locally from this website (delivered through the hosting described in section 3). When the pages are accessed, no data is therefore transmitted to third-party content providers beyond the processing described in section 3.

Links to external offerings (e.g. LinkedIn, or the newsletter site at newsletter.agrosz.de operated by beehiiv) only result in data processing by the respective provider once you click on them.

6. Fonts (hosted locally)

To display fonts consistently, the fonts used on this website are provided locally. No data is transmitted to Google in connection with font delivery. This applies to agrosz.de. The newsletter at newsletter.agrosz.de is operated by beehiiv; when those pages are accessed, fonts are loaded from Google servers (fonts.googleapis.com, fonts.gstatic.com), in the course of which your IP address is transmitted to Google. This behavior is part of the platform and cannot be switched off by us.

7. Storage on your device

This website stores nothing on your device. No cookies are set, and no access to local storage or session storage takes place. A consent banner is therefore not required.

This also applies to the language switch between the German and the English version: it is an ordinary link to a separate address, and your choice is not stored.

8. Processing on behalf and transfers to third countries

Data processing agreements within the meaning of Article 28 GDPR are in place with the following service providers:

  • Netlify, Inc. (USA): hosting and CDN (section 3). Netlify is certified under the EU-US Data Privacy Framework (DPF) including the UK Extension and the Swiss-US DPF; to that extent, data transfers to the USA are covered by the adequacy decision of the European Commission (Article 45 GDPR). In addition, Netlify uses the European Commission's standard contractual clauses (Article 46(2)(c) GDPR).
  • Resend (Plus Five Five, Inc., USA): sending form inquiries by email (section 4). Resend is certified under the EU-US DPF including the UK Extension; the standard contractual clauses contained in the data processing agreement apply in addition.
  • beehiiv Inc. (USA): newsletter delivery (see the section “Newsletter / delivery via beehiiv”). The transfer to the USA takes place on the basis of the European Commission's standard contractual clauses contained in the data processing agreement (Article 46(2)(c) GDPR).

You may request a copy of the applicable safeguards from the providers named or from me (contact details in section 1).

9. Cookies and similar technologies (brief overview)

I use cookies and comparable technologies only where this is technically necessary in order to provide or protect the website, or to provide functions you have requested.

Technically necessary storage access: section 25(2) TDDDG.
Further processing: Article 6(1)(f) GDPR.

Non-essential cookies and tracking (e.g. marketing, third-party tracking) are used only with consent (section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR).

Note: no external content is embedded on this website (see section 5).

10. Recipients and categories of recipients

Depending on use, data may be processed by:

  • Netlify, Inc. (hosting and CDN, technical receipt of form data)
  • Resend / Plus Five Five, Inc. (email delivery of form inquiries)
  • beehiiv Inc. (newsletter delivery, if you have subscribed to the newsletter)

11. Retention period

I store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations. Form data is stored for as long as is necessary in order to handle your inquiry. Server log data is retained in line with the hosting provider's specifications and then deleted.

12. Your rights

You have the right at any time to access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21), and withdrawal of consent given (Article 7(3) GDPR).

A message to the following address is sufficient to exercise these rights: aleksander@agrosz.de

13. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority, for example with the authority competent for my place of business, the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (www.lda.brandenburg.de).

14. Changes to this privacy policy

This privacy policy will be adapted if the website, the services used or legal requirements change.

B) Cookie policy

1. What are cookies?

Cookies are small text files that your browser stores on your device. Similar technologies include local storage and session storage.

2. Which cookies and technologies are used?

2.1 Technically necessary cookies and storage access

This website currently does not use any cookies. Nor does any other access to your device take place (see section 7 of the privacy policy).

Legal basis:
– section 25(2) TDDDG (access to terminal equipment for technically necessary operations)
– Article 6(1)(f) GDPR (legitimate interest in secure, stable operation)

2.2 Optional cookies (analytics and marketing)

I do not currently use any analytics or marketing cookies. Should optional cookies or tracking technologies be used in future, this will only happen with your consent.

Legal basis: section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR (consent).

3. Externally embedded content

External content (e.g. libraries via CDNs or externally hosted images) is not embedded on this website; scripts, fonts and images are provided locally. No data is therefore transmitted to third-party content providers when the pages are merely accessed.

4. Cookie settings and withdrawal

Should optional cookies be used in future, you will be able to withdraw consent you have given at any time with effect for the future via the corresponding cookie settings.

5. Deleting or blocking cookies

You can delete or block cookies in your browser settings. Since this website does not set any cookies, blocking cookies has no effect here. Nor is there any website data that could be deleted.

6. Changes to this cookie policy

This cookie policy will be updated if the use of cookies or legal requirements change.

Newsletter / delivery via beehiiv

Data processed

If you sign up for my newsletter, I process the personal data you provide in the sign-up form, in particular your email address and, where you provide it, your name.

The processing serves the purpose of providing, sending and administering my newsletter, and of analyzing and improving my newsletter offering.

beehiiv as delivery service provider

For sending the newsletter and handling it technically, I use the beehiiv service of beehiiv Inc., based in the USA (beehiiv.com). In doing so, the data you provide during sign-up, together with technical and usage-related information, is processed on beehiiv's systems. I have concluded a data processing agreement (Data Protection Addendum) with beehiiv pursuant to Article 28 GDPR.

Double opt-in procedure

Sign-up to my newsletter uses the double opt-in procedure. This means that after signing up you receive an email in which you must confirm your registration once more by clicking a confirmation link. This ensures that nobody can sign up using someone else's email address.

In this context I process, as evidence of your registration and consent, in particular the time of sign-up, the time of confirmation and, where applicable, technical log data such as the IP address.

Analysis of usage behavior

I also analyze usage behavior in connection with the newsletter. This may record in particular whether a newsletter email was opened, which links were clicked, and how individual recipients interact with my content.

This analysis serves to improve the content, relevance and quality of my newsletter offering.

Legal basis

The legal basis for sending the newsletter and for analyzing usage behavior is your consent under Article 6(1)(a) GDPR.

Insofar as the storage of sign-up and confirmation data serves to document your consent, processing additionally takes place on the basis of my legitimate interest in being able to demonstrate consent in a legally sound manner under Article 6(1)(f) GDPR.

Recipients and transfers to third countries

The recipient of your data is in particular beehiiv, the technical delivery service provider I use. According to beehiiv, publication and subscriber data is stored in AWS regions in the United States of America.

The transfer to the USA takes place on the basis of the European Commission's standard contractual clauses contained in the data processing agreement (Article 46(2)(c) GDPR); you may request a copy from me. beehiiv provides a list of the sub-processors it uses at subprocessors.beehiiv.com.

Retention period

Your data is generally stored for as long as your newsletter registration exists. If you unsubscribe from the newsletter, your email address will no longer be used for active newsletter delivery.

Data that I need in order to demonstrate valid consent may additionally be retained for an appropriate period, insofar as this is necessary in order to fulfill legal obligations or to defend or assert legal claims.

Withdrawal and unsubscribing

You may withdraw your consent at any time with effect for the future. You can unsubscribe in particular via the unsubscribe link at the end of every newsletter email, or by message to aleksander@agrosz.de.

The lawfulness of processing carried out up to the point of withdrawal remains unaffected by the withdrawal.

Your rights

In connection with the processing of your personal data you have the statutory rights of data subjects, in particular to access, rectification, erasure, restriction of processing, data portability, and to lodge a complaint with a data protection supervisory authority.

Obligation to provide data

Providing your email address is necessary in order to be able to send you the newsletter. Without this information, signing up to the newsletter is not possible.