At a Glance how your personal data is collected and processed...
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is all data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.
The data processing on this website is carried out by the website operator. You can find their contact details in the "Notice on the Responsible Entity" section of this privacy policy.
Your data is collected firstly when you provide it to us. This can be, for example, data you enter into a contact form. Other data is automatically collected or collected with your consent by our IT systems when you visit the website. These are mainly technical data (e.g., internet browser, operating system, or time of page view). The collection of this data occurs automatically as soon as you enter this website.
Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze your user behavior.
You have the right at any time to obtain information about the origin, recipient, and purpose of your stored personal data free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. In addition, under certain circumstances, you have the right to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. For this, as well as for further questions on the topic of data protection, you can contact us at any time.
When visiting this website, your surfing behavior can be statistically analyzed. This is done primarily with so-called analysis programs. Detailed information about these analysis programs can be found in the following privacy policy.
We are committed to ensuring the security of your personal data. To prevent unauthorized access, maintain data accuracy, and ensure the correct use of information, we have put in place appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect online.
Our security measures include, but are not limited to:
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
We restrict access to personal data to employees, contractors, and agents who need to know that information in order to process it for us. They are subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations.
We conduct security assessments and penetration testing to identify and mitigate vulnerabilities within our website and its underlying infrastructure.
We adhere to the principle of data minimization, ensuring that we collect only the data necessary for the purposes for which it is processed.
Personal data is stored on secure servers with access limited to authorized personnel only. Measures are in place to protect against data loss, misuse, or alteration.
Our security measures are continuously reviewed and updated in response to new threats and developments in technology. We are committed to using best practices and industry-standard security measures to protect your personal data.
While we strive to protect your personal data, the security of information transmitted over the Internet cannot be guaranteed. We encourage users to take their own precautions, such as keeping software up to date and using complex passwords, to further enhance their online security.
If you have any questions or concerns about our security measures, please do not hesitate to contact us at hello[at]lennart-westendorf.com
We host the contents of our website with two different providers:
- Webflow (Servers located in the US)
- TrafficPlex (Servers located in Germany)
We host the general contents of our website with Webflow Inc.
We utilize the services of Webflow, Inc., located at 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (hereinafter referred to as "Webflow"), for hosting the general contents of our website. Webflow is a comprehensive tool for creating and hosting websites, providing us with the necessary infrastructure to ensure our website is accessible to our users efficiently and reliably.
When you visit our website, Webflow collects various types of data through log files, including your IP addresses. This data collection is essential for delivering our website content, ensuring website functionality, and maintaining the security of our services. Additionally, Webflow uses cookies or other recognition technologies necessary for the presentation of the page, providing certain website functions, and ensuring security (necessary cookies).
The use of Webflow for hosting our website is based on Art. 6 Para. 1 lit. f GDPR, indicating our legitimate interest in a reliable presentation of our website. If consent has been obtained for processing activities that require it (e.g., storage of cookies or access to information on the user's end device), such processing is carried out exclusively based on Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TTDSG. This consent can be revoked at any time.
Data transfer to the USA is conducted under the standard contractual clauses of the EU Commission, ensuring compliance with European data protection standards. For more details on these clauses and Webflow's data processing practices, please refer to Webflow's privacy policy: https://webflow.com/legal/eu-privacy-policy.Webflow has obtained certification under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA designed to ensure that data processing by companies in the USA adheres to European data protection standards. Companies certified under the DPF commit to upholding these standards.
We have entered into a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the service provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.
For more information on Webflow's data protection practices and the EU-US Data Privacy Framework certification, please visit the following link: Data Privacy Framework Participant Search.
We use TrafficPlex GmbH for Video Hosting.
We utilize the services of TrafficPlex GmbH, located at Konsul-Smidt-Str. 90, 28217 Bremen, for hosting our video files. Our videos are hosted on a separate website, www.video-hosting.eu, to ensure optimized delivery and enhanced security of our video content.
In the course of hosting on www.video-hosting.eu, TrafficPlex GmbH collects log data of page accesses. This data collection serves security purposes, such as the detection and prevention of DDoS attacks, access control, and the identification of brute-force attacks, in accordance with Art. 6 Para. 1 lit. f GDPR in conjunction with Art. 28 GDPR. The collected log data may include or constitute personal data.The retention of this log data by TrafficPlex GmbH is currently set for a period of 7 days, to enable effective security analysis and intervention.
For more detailed information on the processing of your personal data by TrafficPlex GmbH and your rights as a data subject, please consult the privacy policy of TrafficPlex GmbH. We recommend reviewing their privacy policy to gain a complete understanding of their data processing practices:
TrafficPlex GmbH Privacy Policy.
To ensure data protection-compliant processing of all data, we have entered into a data processing agreement with TrafficPlex GmbH in accordance with Art. 28 GDPR. This agreement regulates the processing of personal data on our behalf and ensures that processing is carried out in compliance with data protection laws and that the rights of the data subjects are protected.
As already mentioned above, the operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the Internet (e.g. communication by email) can have security gaps. A complete protection of data against access by third parties is not possible.
The responsible entity for data processing on this website is:
Lennart Westendorf
Am Sonnenhügel 9
73525 Schwäbisch Gmünd
Email: hello[at]lennart-westendorf.com
Contact form: www.lennart-westendorf.com/contact
Phone: [Upon request]
The responsible entity is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.
If you have given your consent to data processing, we process your personal data based on Article 6 (1) a GDPR or Article 9 (2) a GDPR if special categories of data are processed according to Article 9 (1) GDPR. In the event of explicit consent to the transfer of personal data to third countries, data processing is also carried out based on Article 49 (1) a GDPR. If you have consented to the storage of cookies or to access information in your end device (e.g., device fingerprinting), data processing is additionally carried out based on § 25 (1) TTDSG. The consent can be revoked at any time. If your data is required for contract fulfillment or for carrying out pre-contractual measures, we process your data based on Article 6 (1) b GDPR. Furthermore, we process your data if it is necessary to fulfill a legal obligation based on Article 6 (1) c GDPR. Data processing may also be based on our legitimate interest according to Article 6 (1) f GDPR. The respective legal basis in individual cases is informed in the following paragraphs of this privacy policy.
In the course of our business activities, we collaborate with various external parties. In some cases, this also involves the transfer of personal data to these external parties. We only transfer personal data to external parties if this is necessary for the fulfillment of a contract, if we are legally obliged to do so (e.g., transfer of data to tax authorities), if we have a legitimate interest according to Article 6 (1) f GDPR in the transfer, or if another legal basis allows the data transfer. In the case of using data processors, we only pass on personal data of our customers based on a valid contract for data processing. In the case of joint processing, a contract for joint processing is concluded.
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.
IF DATA PROCESSING IS CARRIED OUT BASED ON ARTICLE 6 (1) E OR F GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR IF THE PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION ACCORDING TO ARTICLE 21 (1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION ACCORDING TO ARTICLE 21 (2) GDPR).
In the event of violations of the GDPR, the data subjects have a right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, their place of work, or the place of the alleged violation. This right to lodge a complaint is without prejudice to other administrative or judicial remedies.
You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract handed over to yourself or to a third party in a standard, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient, and the purpose of data processing, and, if necessary, a right to rectification or erasure of this data. For this as well as for further questions on the subject of personal data, you can contact us at any time.
You have the right to request the restriction of processing of your personal data. For this purpose, you can contact us at any time. The right to restriction of processing exists in the following cases:
If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the duration of the examination, you have the right to request the restriction of processing of your personal data.
If the processing of your personal data was/is carried out unlawfully, you can request the restriction of data processing instead of deletion.
If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of processing of your personal data instead of deletion.
If you have lodged an objection according to Article 21 (1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data - apart from its storage - may only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us.
These are:
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
- Browser type and browser version
- Browser Language
A combination of this data with other data sources is not carried out. The collection of this data is based on Article 6 (1) f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of his website - for this purpose, the server log files must be recorded.
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not share this information without your consent.
The processing of these data is based on Article 6 (1) b GDPR if your request is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of requests addressed to us (Article 6 (1) f GDPR) or on your consent (Article 6 (1) a GDPR) if this has been requested; the consent can be revoked at any time.
The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after the completion of your request). Mandatory statutory provisions - in particular retention periods - remain unaffected.
If you contact us by email, contact form, or telephone, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of processing your request. We do not share this information without your consent.
The processing of these data is based on Article 6 (1) b GDPR if your request is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of requests addressed to us (Article 6 (1) f GDPR) or on your consent (Article 6 (1) a GDPR) if this has been requested; the consent can be revoked at any time.
The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after the completion of your request). Mandatory statutory provisions - in particular statutory retention periods - remain unaffected.
For essential website functionalities, we utilize the Sygnal Attributes plugin. This plugin is a suite of JavaScript libraries designed to enhance Webflow sites by addressing certain limitations and introducing new capabilities. Notably, the plugin offers:
- Data-Binding: Allows form INPUT and SELECT elements to be dynamically linked to your collection lists.
- Custom Attributes: Enables the addition of custom attributes dynamically to elements within a collection list.
- Tables Support: Integrates tables with data sourced from Google Sheets, enhancing the display and management of data.
- Multilingual Support: Offers language detection and a dynamic content-switcher for creating multilingual sites.
These features are designed to maximize the functionality of Webflow’s native hosting environment, providing advanced capabilities without the need for third-party plugins or additional service fees. The Sygnal Attributes project also represents a practical application of modern web development technologies, such as Javascript ES6 modules and NPM, aimed at enhancing the capabilities of Webflow sites.
This plugin is classified under 'essential' cookies and operates without requiring consent, but we disclose its use for full transparency. Our deployment of this technology aligns with Article 6(1)(f) of the GDPR, which relates to processing necessary for the legitimate interests pursued by us or a third party, provided that these interests do not override the fundamental rights and freedoms of the data subject that require the protection of personal data.Please be informed that while this plugin significantly enhances site functionality, it does so within the framework of our commitment to privacy and data protection. As with all aspects of our site, you have control over your data and can manage your cookie preferences via our GDPR-compliant cookie consent banner.
With your consent, we use Matomo (formerly piwik), an open-source software, for the analysis and statistical evaluation of the use of our website. For this purpose, cookies are used. The information about the use of the website obtained in this way is exclusively transmitted to our servers and summarized in pseudonymous usage profiles. We use the data to evaluate the usage of the website. The collected data is not passed on to third parties.IP addresses are anonymized (IP Masking), making it impossible to associate them with individual users.The processing of data is based on Article 6(1)(a) of the GDPR. With this, we pursue our legitimate interest in optimizing our website for our public presentation.You can revoke your consent at any time by deleting the cookies in your browser or changing your privacy settings. Additionally, our website features a GDPR-compliant cookie consent banner, allowing you to decline or withdraw your consent to cookie use at any time easily.
We use Hotjar to better understand our users' needs and to optimize the service and experience on this website. Hotjar's technology helps us gain a better understanding of our users' experiences (e.g., how much time users spend on which pages, which links they click, what they like and dislike, etc.) and align our offerings based on user feedback. Hotjar uses cookies and other technologies to collect data on our users' behavior and their devices, specifically the device's IP address (collected and stored in anonymized form during your use of the website), screen size, device type (unique device identifiers), browser information, geographic location (country only), and preferred language used to display our website. Hotjar stores this information in a pseudonymized user profile on our behalf. Hotjar is contractually forbidden from selling any data collected on our behalf.In addition to providing your initial consent through our cookie consent banner, you have the right to decline or withdraw your consent at any time. This option is readily accessible and can be exercised with ease, ensuring full compliance with GDPR requirements.
Your participation in these analytics tools is based on your consent, given in accordance with Article 6(1)(a) of the GDPR. If you wish to withdraw your consent, you can do so at any time by changing your cookie settings or managing your privacy preferences on our website. This will not affect the lawfulness of the processing based on consent before its withdrawal.
You have control over your personal data. At any time, you can access your privacy settings to adjust your preferences or opt-out from specific data collection practices. For more detailed instructions on how to adjust your settings or opt-out from Matomo or Hotjar analytics, please visit [Matomo's Opt-Out feature] and [Hotjar's Opt-Out information].
We take your privacy seriously. If you have any questions about how we handle your data or about your rights, please contact our Data Protection Officer at hello[at]lennart-westendorf.com.
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on our website, provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA is implemented to distinguish whether the interaction with our website is conducted by a human or an automated program. This is particularly applied to data entries on our website, such as those made in contact forms.
reCAPTCHA analyzes the behavior of website visitors based on various characteristics. This analysis begins automatically as soon as a visitor enters the site. To conduct this analysis, reCAPTCHA evaluates various information, including the IP address, the duration of the visit on our website, and mouse movements made by the user. All data collected during this analysis is forwarded to Google.The analysis by reCAPTCHA occurs entirely in the background, and visitors are not explicitly notified that such an analysis is taking place.
The data storage and analysis via reCAPTCHA are grounded on Article 6 (1) f GDPR, indicating the website operator's legitimate interest in protecting its web offerings from abusive automated snooping and SPAM. If consent has been obtained for specific processing activities (e.g., storage of cookies or access to information on the user's end device), such processing is conducted exclusively based on Article 6 (1) a GDPR and § 25 (1) TTDSG. Consent for these activities can be revoked at any time.
For more detailed information about Google reCAPTCHA, including its privacy policy and terms of use, please visit the following links provided by Google:
- Google Privacy Policy
- Google Terms of Use
Google has certification under the "EU-US Data Privacy Framework" (DPF), an agreement between the European Union and the USA designed to ensure compliance with European data protection standards in data processing activities in the USA. Companies certified under the DPF commit to adhering to these data protection standards.For more information about Google's certification or to contact the provider, please visit the following link:
Data Privacy Framework Participant Search.
Our website utilizes Cloudflare as a security measure to protect the video content we host on lima-city, a separate web space hosting provider dedicated to storing our video data. This section explains how Cloudflare processes and protects your data in relation to our video content.
We employ the services of Cloudflare Germany GmbH, located at Rosental 7, c/o Mindspace, 80331 München, Deutschland ("Cloudflare"), to enhance the security and delivery speed of our website. This use is in line with our legitimate interest under Art. 6 Para. 1 lit. f of the GDPR, aiming to optimize our website's performance and security for our users.Cloudflare operates as a Content Delivery Network (CDN), a globally distributed network of servers designed to efficiently deliver web content to users. This network helps in reducing the load times of our videos by storing copies on servers closer to the user, thus improving the overall user experience. In the process of content delivery, personal data may be processed in Cloudflare's server log files, which is necessary for the operation and security of the CDN.
Cloudflare acts as a recipient of your personal data and processes it on our behalf as a data processor. This arrangement is based on our legitimate interest to utilize a third-party CDN for the efficient delivery of content, as outlined in Art. 6 Para. 1 S. 1 lit. f GDPR, without the need to maintain our own CDN infrastructure.
In its role as a security provider, Cloudflare may collect and process certain information that includes, but is not limited to:
- Your IP address, to identify and mitigate potential threats
- Security fingerprints, to prevent unauthorized access and abuse
- DNS log data, for analyzing and securing web traffic
- Website performance data derived from browser activity, to optimize the delivery of video content
The data collected by Cloudflare is primarily used for:
- Enhancing the security of our video hosting infrastructure
- Ensuring the efficient distribution and delivery of videos to our viewers
- Identifying and mitigating potential cyber threats and vulnerabilities
You have the right to object to the processing of your personal data by Cloudflare. The success of such an objection will be determined through a balancing of interests. It's important to note that the processing of certain data is critical for the functionality of our website; without it, we cannot guarantee the full operational capability of our site.
Cloudflare retains your personal data only for as long as necessary to fulfill the purposes outlined in this section.
For more information on how to object to or seek removal of your data processed by Cloudflare, please refer to the Cloudflare Data Processing Addendum (DPA).
Cloudflare has implemented compliance measures for international data transfers, applicable to all its activities involving the processing of personal data from individuals in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs). For further details, please visit:
https://www.cloudflare.com/cloudflare_customer_SCCs-German.pdf.
Our website utilizes the Vidstack library to display videos. This tool enhances video playback and user experience on our website without directly hosting any video content.
While Vidstack is primarily used for displaying videos from our own servers or other hosting solutions, it may still collect and process limited data such as:
- IP address and device information to ensure proper video playback and compatibility.
- Interaction data with the video player (e.g., play, pause, and viewing duration) to improve user experience and functionality.
The purpose of using Vidstack is to provide a seamless and enhanced video viewing experience on our website. The legal basis for processing personal data through Vidstack is our legitimate interest in optimizing our website's video content presentation (Art. 6 Para. 1 lit. f GDPR).
Data collected by Vidstack is used solely for the purpose of improving video playback and user interaction. This data is not shared with third-party advertisers or other platforms. You have the right to access, rectify, or erase any personal data that may be collected through your interaction with the video content displayed by Vidstack on our website.For inquiries or to exercise your rights regarding your personal data, please contact us at:
hello[at]lennart-westendorf.com
We may update this section of our privacy policy to reflect changes in our use of Vidstack or in response to regulatory changes. We encourage users to review this policy periodically.
- Various Legal Artificial Intelligence Services
- Own Research
- https://www.e-recht24.de
- https://datenschutz-generator.de/