Privacy policy
Protecting your personal data is important to me. This privacy policy explains how I process personal data when you visit pascalpausch.com, make contact enquiries, arrange appointments and engage in business relationships with me, the purposes for which the data is used and your rights in this regard. Personal data is information relating to an identified or identifiable natural person.
1. Controller and data protection contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Pascal PauschSole proprietorshipAgnesstraße 46A80798 MunichGermany- Phone:
- +49 176 / 303 481 85
- Email:
- kontakt@pascalpausch.com
You can contact me directly with questions about data protection and to exercise your rights.
2. Accessing the website, hosting and server administration
Technical connection data
When you access this website, the connection data required to deliver it is processed. This includes, in particular, your IP address, the date and time of access, the requested address including any URL parameters transmitted, the HTTP status, the volume of data transferred, and browser and device information. Where your browser transmits this information, the operating system and the previously visited page, known as the referrer URL, may also be recorded.
This processing serves to provide the website, detect and resolve faults, and protect against misuse and attacks. I do not use this data to create advertising profiles or to analyse your browsing behaviour on a personally identifiable basis.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest is in providing a secure, reliable and functional website.
Hetzner
The website is operated on a server provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server used is located in Nuremberg, Germany. Hetzner provides the server infrastructure and may process technical data as part of this service. A data processing agreement pursuant to Article 28 GDPR is in place with Hetzner.
Further information: Hetzner's privacy policy.
Ploi
I use Ploi, Amperestraat 16J, 3861 NC Nijkerk, the Netherlands, to set up, administer and maintain the server. Technical operational data and logs may be processed as part of server administration. Where necessary for the agreed administration or support services, this may also involve access to personal data on the managed server. A data processing agreement pursuant to Article 28 GDPR is in place with Ploi.
Ploi is used as an administration service; merely visiting my website does not embed any Ploi content in your browser.
Further information: Ploi's privacy policy.
IONOS as domain and DNS service provider
The domain and its DNS records are managed by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. DNS resolves the domain name to the server address required to establish a connection. Depending on the DNS service used and its caching, IONOS may process technical DNS query data. This domain administration does not give IONOS access to the content of my contact forms.
The legal basis for the technical provision I arrange is Article 6(1)(f) GDPR. My legitimate interest is in making the website accessible under its domain. A data processing agreement pursuant to Article 28 GDPR is in place with IONOS.
Further information: IONOS's privacy policy.
Storage of server logs
The web server keeps access and error logs for the operational and security purposes mentioned. These may contain, in particular, the connection data described above.
Daily rotation is configured for the NGINX logs. Up to 52 archived log files are retained in addition to the current file; the oldest archives are removed during subsequent rotations. Empty files are not rotated. With regular operation and daily rotations, this corresponds to approximately 52 days of archived logs plus the current file. However, retention depends on the rotations that actually take place and is not a fixed maximum period of 52 calendar days.
Where individual data is necessary to investigate a specific security incident or to establish, exercise or defend legal claims, it may be retained separately for that purpose. The legal basis is Article 6(1)(f) GDPR; my legitimate interest is in investigating the incident and protecting my rights. Such data is deleted as soon as this purpose no longer applies and no statutory retention obligation prevents deletion.
3. Encryption and server backups
The connection to the website is encrypted using HTTPS. This protects transmission between your browser and my server against unauthorised reading and alteration. You can recognise an encrypted connection when the address in your browser changes from "http://" to "https://" and by the padlock symbol in your browser's address bar.
Daily server backups are created at Hetzner to protect against data loss and enable recovery after technical faults. They may contain personal data present on the server at the time of the backup, particularly server logs. Hetzner provides seven rotating backup slots for this purpose. If daily backups are continuously successful, the oldest backup is replaced by the next one.
When data is deleted from the live system, it may remain in a backup until that backup is overwritten. Backups are used for recovery. When restoring a backup, I take account of deletions that have already taken place.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest is in safeguarding website operation and ensuring it can be restored.
4. Cookies, local content and external links
Outside the appointment booking you activate, the website does not use analytics or marketing services, advertising pixels or cookies to track your browsing behaviour. Fonts, images and other directly embedded design elements are served locally. This does not require requests to external font libraries or social networks.
Calendly is only loaded after you expressly activate it. The cookies and similar technologies that may be used in this process are described in section 6.
Links to other websites and social networks are ordinary links. Your browser only connects to the destination when you open such a link. The provider of the linked website is responsible for data processing there, and its own privacy policy applies.
You can choose the website's light or dark appearance yourself. Without a manual selection, the appearance follows your browser or system setting. Only after you make a manual selection is the value “light” or “dark” stored under the key “appearance” in your browser's sessionStorage, so that your selection is retained when navigating between pages in the same tab. The stored entry remains in your browser and is not used for tracking. If you expressly load Calendly, matching colour values are transmitted to Calendly to display appointment booking in the selected appearance; this allows Calendly to recognise the light or dark appearance. Storage is tied to the tab session; when restoring a session, your browser may retain the selection. Selecting “System setting” removes the stored selection. Storage and access take place pursuant to Section 25(2), no. 2 TDDDG to provide the appearance you have expressly selected during the session.
5. Contact form, email and telephone
Handling your enquiry
If you send me an enquiry using the contact form, by email or by telephone, I process the details it contains to review and respond to your request and, where appropriate, prepare a proposal or collaboration.
The contact form requires you to select the nature of your enquiry and provide your email address and message. Depending on the selected enquiry, you can additionally provide your name, organisation, a project URL, details of your starting situation and the desired timeframe. Technical form information about the selected language and protection against automated submissions is also processed.
The form is processed on my own server. The enquiry is delivered to me as an email; the form contents are not additionally stored permanently in a website database.
For email, I process in particular your email address, your name where provided, the message content, attachments and technical transmission data. For a telephone call, your telephone number, the information you provide and necessary call notes may be processed. I do not record telephone calls.
If your enquiry serves to enter into or perform a contract with you as a natural person, Article 6(1)(b) GDPR is the legal basis. For enquiries from a company's contact persons and other enquiries, processing is based on Article 6(1)(f) GDPR. My legitimate interest is in handling and responding to enquiries and in business communication.
Contacting me is voluntary. Without a suitable way to reply and the information required to handle your enquiry, I may be unable to respond. Details not marked as required in the form are voluntary.
Email service provider IONOS
I use IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, to send, receive and store my business correspondence at kontakt@pascalpausch.com and other "@pascalpausch.com" email addresses. In particular, IONOS processes email addresses, messages, attachments and technical delivery data for this purpose. A data processing agreement pursuant to Article 28 GDPR is in place with IONOS.
Further information: IONOS's privacy policy.
Calendly is additionally used for appointment confirmations and reminders from Calendly bookings; section 6 applies to this.
Protecting the contact form
To protect against spam, automated requests and immediate duplicate submissions, the frequency and technical characteristics of submissions are checked. For this purpose, the IP address determined on the server is used in hashed form. A hash is also generated from technical association data and the form content to detect immediately repeated submissions. These hashes are pseudonymised protection data, not anonymous data.
The protection data is held exclusively in the memory of the running website process. The frequency check uses assessment windows of one minute and 15 minutes; identical submissions are detected within 60 seconds. Expired entries are cleared during subsequent form requests or discarded when the process ends. This protection data is not permanently stored in a database or a dedicated log file.
For form handling, the application logs only technical events, statuses and error categories. Message text, email addresses and IP addresses are not written to the application log. The separate web server logs are described in section 2.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest is in keeping the contact function available, preventing misuse and avoiding unintended multiple deliveries.
Retention of contact enquiries
Contact enquiries and the associated correspondence are retained for as long as necessary to handle them and any subsequent collaboration. I review completed enquiries regularly. Non-binding enquiries and associated messages that are no longer needed are deleted, unless statutory retention obligations or specific reasons for protecting legal claims prevent this.
Business records subject to retention obligations are governed by the rules described in section 10. Merely making contact does not mean that every message is stored for the duration of a statutory retention period.
6. Appointment scheduling with Calendly
Voluntary activation of the appointment view
For online appointment scheduling, I use Calendly LLC, USA. The postal address published by Calendly for privacy enquiries is: 115 E Main St., Ste A1B, Buford, GA 30518, USA.
The embedded appointment view is only loaded when you expressly activate the designated button. Before that, this embed makes no connections to Calendly. Alternatively, you can reach me using the contact form, by email or by telephone.
When the appointment view is loaded, Calendly receives in particular your IP address, browser and device information, the time of access and, where applicable, information about the referring page. The activation I arrange is based on your consent pursuant to Article 6(1)(a) GDPR.
Your activation on my website is not stored permanently in a cookie or in browser storage. You can end the embed by reloading the page. After reloading, you must activate it again. This does not delete any data already transmitted to Calendly or revoke a cookie preference stored by Calendly. You can also withdraw your consent at any time by contacting kontakt@pascalpausch.com.
Calendly cookies and other technologies
Calendly may use technically necessary cookies and similar technologies for the appointment booking you expressly request.
According to its notices, Calendly may use technologies for purposes including analytics, personalisation and marketing. This may also include recording clicks, mouse movements and interactions within the booking view. By activating the appointment view on my website, you accept this.
Booking details and notifications
When booking, you are asked for your first name, last name, email address and the selected date and time. This also includes technically necessary appointment details such as the time zone, and information about bookings, changes and, where applicable, cancellations. I use this data to arrange, organise and conduct the appointment.
Calendly sends appointment confirmations and email reminders. In particular, your email address and the associated appointment details are processed for this purpose. I do not use SMS reminders.
Article 6(1)(b) GDPR applies to appointment handling where it involves entering into or performing a contract with you as a natural person. For appointments with a company's contact persons or other conversations, Article 6(1)(f) GDPR applies. My legitimate interest is in reliable appointment organisation and business communication.
Use of online booking is voluntary. Without the required contact and appointment details, Calendly cannot complete the booking. Appointments can alternatively be arranged using the contact methods stated above.
Appointment confirmation on this website
After a booking, Calendly may redirect you to a confirmation page on this website. Your first name, appointment type and start time are transmitted as URL parameters and processed on my server for the personal confirmation. The website does not store its own booking record for this purpose. The requested address may be contained in your browser history and in the server logs described in section 2. The legal basis is Article 6(1)(b) or (f) GDPR, subject to the conditions for appointment handling described above.
Responsibilities, calendar integration and retention period
Calendly acts as a processor for the booking data processing I arrange. A data processing agreement is in place with Calendly for this purpose. For certain processing it performs for its own purposes, particularly data from cookies and similar technologies in embedded services, Calendly acts as an independent controller under its terms. For this data, Calendly's terms describe separate responsibilities for Calendly and the website operator.
My Google Calendar is connected to Calendly. When a booking is made, contact and appointment details are therefore already transmitted to Google for calendar management and to create the Google Meet appointment. Calendly accesses calendar data within the permissions I have granted to determine availability and create appointments. According to its own information, Calendly also uses limited calendar information to personalise its setup and feature suggestions. Further information about the use of Google is provided in section 7.
I regularly review completed and cancelled bookings and arrange for personal booking and contact data that is no longer needed to be deleted. Contractually required records and statutory retention obligations remain unaffected. According to Calendly, it implements requested deletions within seven days. This is not an automatic deletion period of seven days after the appointment. Calendar copies and email messages are reviewed separately for their continued necessity and deleted where appropriate. Processing carried out by Calendly under its own responsibility is subject to its privacy notices.
Calendly processes data in the USA and potentially in other countries outside the European Economic Area. The bases for transfers are explained in section 9.
Further information:
7. Google Calendar and Google Meet
I use Google Calendar and Google Meet for calendar management and video calls.
The provider of Google services in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The Google group includes, in particular, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The Google Terms of Service and Google Privacy Policy apply to the consumer services used. Google also processes data under its own responsibility as a data controller, particularly to provide, secure and further develop its services.
Calendar management
For agreed appointments, Google Calendar processes in particular names, email addresses, dates, times and participation details, including the Meet link. For Calendly bookings, this transmission takes place during booking, regardless of whether you later participate in a video conference.
Processing serves to manage appointments, avoid overlaps and provide the agreed opportunity for a conversation. Article 6(1)(b) GDPR applies to my appointment organisation where it serves to enter into or perform a contract with you as a natural person. For appointments with a company's contact persons or other conversations, Article 6(1)(f) GDPR applies. My legitimate interest is in organising and conducting the agreed business appointments.
Appointment entries and invitations stored by me that are no longer required are deleted according to the criteria described in sections 6 and 10. Deleting a Calendly record does not replace the separate review of the calendar entry.
Video calls using Google Meet
When you open a Google Meet link or participate in a video call, Google processes the data required to establish the connection and conduct the call. This may include, in particular, the name you provide, Google account information where applicable, your IP address, device and browser information, the time and duration of participation, and technical connection data.
If you use your microphone, camera, screen sharing or chat, the corresponding audio, video, screen and chat content is processed and made available to the other participants. You can switch off your camera and microphone and decide for yourself which content to share.
I do not record conversations or use automatic transcription or AI-assisted recording and summarisation of conversations. The legal bases for appointment organisation stated above apply to the processing I arrange to conduct the conversation.
If you do not wish to use Google Calendar or Google Meet to arrange an appointment or conduct the conversation, please contact me directly by email or telephone. We can agree on an alternative contact method without using Calendly booking.
Google may also process data outside the European Economic Area, particularly in the USA. Information about the bases for transfers is provided in section 9. Retention periods for data processed by Google under its own responsibility depend on Google's privacy notices and the respective features and account settings.
Further information:
8. Establishing and conducting business relationships
If you commission me or work with me in a business relationship, I process the contact, contract, project, service, communication and billing data required for this purpose. This may include names and contact details, company and billing addresses, agreed services, payment information, and details relating to the implementation and support of a project.
I generally receive this information from you or from contact persons at the company you work for. I use it to prepare proposals, perform contracts, provide services, deliver ongoing support, issue invoices and meet statutory obligations.
The legal bases are Article 6(1)(b) GDPR for contracts with you as a natural person, Article 6(1)(f) GDPR for communication and collaboration with a company's contact persons, and Article 6(1)(c) GDPR for statutory obligations, particularly retention obligations under tax law. My legitimate interest is in establishing and conducting business relationships and protecting legitimate legal claims.
Providing the data is only necessary to the extent that I need it for the respective contract or to fulfil statutory obligations. Without this information, it may not be possible to enter into or perform a contract.
Where I process personal data on behalf of a client as part of a client project, the details are governed by the required data processing agreement. This privacy policy replaces neither such an agreement nor the client's privacy notices for its own website or services.
9. Recipients and transfers to third countries
Recipients
Access to personal data is granted only to parties that need it for the purposes described. These include, in particular, myself as controller and the service providers named in this policy for hosting, server administration, domain operation and email. Where these providers process data on my behalf, the necessary data processing agreements are in place.
When conducting a business relationship, payment service providers or banks may also receive the data required for payments. Further transfers take place where necessary to perform a contract, required by law or necessary to establish, exercise or defend legal claims, for example to competent authorities or, where specifically required, to legal or tax advisers. Depending on the purpose, the legal basis is Article 6(1)(b), (c) or (f) GDPR.
Transfers to third countries
Calendly and Google may process data outside the European Union and the European Economic Area, particularly in the USA. In addition to the legal bases for the respective processing, the requirements of Articles 44 et seq. GDPR apply to these transfers.
For data transfers to the USA, Calendly cites its certification under the EU-US Data Privacy Framework. Its data processing agreement provides for the European Commission's Standard Contractual Clauses if this framework ceases to be a valid basis for transfers. For cookie data from embedded services, the agreement contains separate provisions for transfers between independent controllers.
Google also cites the EU-US Data Privacy Framework and Google LLC's certification, as well as Standard Contractual Clauses, as transfer mechanisms for the data transfers described in its notices.
For transfers to an appropriately certified US recipient, the adequacy decision for the EU-US Data Privacy Framework under Article 45 GDPR may be relied upon. For other transfers, appropriate safeguards under Article 46 GDPR apply where required. You can review the safeguards described in the following provider information. You can also obtain further information through my data protection contact.
Further information:
10. General retention and deletion
I store personal data for as long as necessary for the respective purpose. When the purpose no longer applies, the data is deleted unless statutory retention obligations or legitimate reasons for establishing, exercising or defending specific legal claims exist. The criteria stated in the respective sections additionally apply to contact enquiries, bookings and server logs. Contract and billing data are stored in accordance with statutory retention periods. Temporary security data is regularly cleared automatically.
11. Your rights as a data subject
Subject to the applicable legal requirements, you have the following rights in particular:
- Access to information about the processing of your personal data and receipt of a copy of that data pursuant to Article 15 GDPR.
- Rectification of inaccurate data and completion of incomplete data pursuant to Article 16 GDPR.
- Erasure of your data pursuant to Article 17 GDPR, provided that, in particular, no statutory retention obligations or overriding grounds prevent this.
- Restriction of processing of your data pursuant to Article 18 GDPR.
- Data portability pursuant to Article 20 GDPR, where processing is based on your consent or a contract and is carried out by automated means.
Withdrawing consent
You can withdraw consent you have given at any time with effect for the future pursuant to Article 7(3) GDPR. This does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent, you can reach me using the contact details above. The options for ending the Calendly embed are additionally described in section 6.
Objecting to processing based on legitimate interests
If I process personal data on the basis of Article 6(1)(f) GDPR, you may object to the processing pursuant to Article 21 GDPR on grounds relating to your particular situation. I will then no longer process the data concerned unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Lodging a complaint with a supervisory authority
Under Article 77 GDPR, you may lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence, place of work or the place of the alleged infringement.
The following authority is generally responsible for my business in Bavaria:
Bavarian State Office for Data Protection Supervision (BayLDA)PO Box 134991504 AnsbachGermanyWebsite and further contact options: Bavarian State Office for Data Protection Supervision.
12. Automated decisions and updates to this privacy policy
In connection with this website, I do not make decisions based solely on automated processing, including profiling within the meaning of Article 22 GDPR, that produce legal effects concerning you or similarly significantly affect you. The technical checks protecting the contact form serve exclusively to prevent misuse.
I reserve the right to amend this privacy policy to reflect changes in legislation, the services used or data processing. I recommend that you regularly review the contents of this privacy policy.