Privacy Policy

1. Privacy at a glance

General information

The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. You will find detailed information on data protection in the privacy policy below.

Data collection on this website

Who is responsible for data collection on this website?

Data on this website is processed by the website operator. You will find the operator's contact details in the section "Controller" in this privacy policy.

How is your data collected?

Some of your data is collected because you provide it to me. This may be, for example, data you enter in a contact form or when you book an appointment.

Other data is collected automatically, or after you have given your consent, by IT systems when you visit the website. This is mainly technical data (e.g. web browser, operating system or time of the page visit). This data is collected automatically as soon as you enter this website.

What is your data used for?

Some of the data is collected to make sure the website works without errors. Where contracts can be concluded or initiated via the website, the data you submit is also processed for offers, orders or other service requests.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact me at any time about this and any other questions on data protection.

2. Hosting

I host the content of this website with the following provider:

External hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the host. This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data and other data generated via a website.

External hosting is used to fulfill contracts with my potential and existing clients (Art. 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of my online services by a professional provider (Art. 6(1)(f) GDPR). Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act), insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

My host will process your data only to the extent necessary to fulfill its service obligations and will follow my instructions regarding this data.

I use the following host:

Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA

Netlify is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to complying with these standards. Netlify also relies on the European Commission's Standard Contractual Clauses. For more information, see Netlify's privacy policy: https://www.netlify.com/privacy/

Data processing agreement

I have concluded a data processing agreement (DPA) with Netlify for the use of the service described above. This is a contract required by data protection law, which ensures that Netlify processes the personal data of my website visitors only on my instructions and in compliance with the GDPR.

3. General information and mandatory information

Data protection

I take the protection of your personal data very seriously. I treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data I collect and what I use it for. It also explains how and for what purpose this happens.

Please note that data transmission over the internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.

Controller

The controller responsible for data processing on this website is:

Elisaveta Gomann
Scharnhorststr. 15
10115 Berlin
Germany

Phone: +49 171 9952228
Email: elli.gomann@tealpath.com

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses or similar).

Storage period

Unless a more specific storage period is stated in this privacy policy, your personal data will remain with me until the purpose for processing it no longer applies. If you make a justified request for deletion or withdraw your consent to data processing, your data will be deleted unless I have other legally permissible reasons for storing it (e.g. retention periods under tax or commercial law). In the latter case, the data will be deleted once these reasons no longer apply.

General information on the legal bases for data processing on this website

If you have consented to data processing, I process your personal data on the basis of Art. 6(1)(a) GDPR or, where special categories of data under Art. 9(1) GDPR are processed, Art. 9(2)(a) GDPR. If you have expressly consented to the transfer of personal data to third countries, processing is also based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), processing is additionally based on Section 25(1) TDDDG. Consent can be withdrawn at any time. If your data is required to fulfill a contract or to carry out pre-contractual measures, I process your data on the basis of Art. 6(1)(b) GDPR. I also process your data where this is necessary to fulfill a legal obligation, on the basis of Art. 6(1)(c) GDPR. Processing may also be based on my legitimate interest under Art. 6(1)(f) GDPR. The legal bases relevant in each individual case are set out in the following sections of this privacy policy.

Recipients of personal data

In the course of my business, I work with various external parties. In some cases, this requires the transfer of personal data to these external parties. I only pass personal data on to external parties if this is necessary to fulfill a contract, if I am legally obliged to do so (e.g. passing data on to tax authorities), if I have a legitimate interest in the transfer under Art. 6(1)(f) GDPR, or if another legal basis permits the transfer. When using processors, I only pass on my clients' personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out up to the withdrawal remains unaffected.

Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE LEGAL BASIS ON WHICH EACH PROCESSING OPERATION IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, I WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS I CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ESTABLISH, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ART. 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged violation. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.

Right to data portability

You have the right to have data that I process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done where technically feasible.

Access, rectification and erasure

Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to rectification or erasure of this data. You can contact me at any time about this and any other questions on personal data.

Right to restriction of processing

You have the right to request that the processing of your personal data be restricted. You can contact me about this at any time. The right to restriction of processing applies in the following cases:

  • If you dispute the accuracy of your personal data stored by me, I usually need time to verify this. For the duration of the verification, you have the right to request that the processing of your personal data be restricted.
  • If the processing of your personal data was or is unlawful, you can request restriction of processing instead of erasure.
  • If I no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request restriction of processing instead of erasure.
  • If you have lodged an objection under Art. 21(1) GDPR, your interests and mine must be weighed against each other. As long as it has not yet been determined whose interests prevail, you have the right to request that the processing of your personal data be restricted.

If you have restricted the processing of your personal data, this data may, apart from being stored, only be processed with your consent, to establish, exercise or defend legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, such as requests you send to me as the site operator, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the browser's address bar changing from "http://" to "https://" and by the lock symbol in your browser bar.

If SSL/TLS encryption is activated, the data you send to me cannot be read by third parties.

4. Data collection on this website

Contact form

If you send me enquiries via the contact form, your details from the form, including the contact details you provide there, will be stored by me for the purpose of processing the enquiry and in case of follow-up questions. I will not pass this data on without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your enquiry is related to the fulfilment of a contract or is necessary to carry out pre-contractual measures. In all other cases, processing is based on my legitimate interest in the effective handling of enquiries sent to me (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be withdrawn at any time.

The data you enter in the contact form will remain with me until you ask me to delete it, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. after your enquiry has been dealt with). Mandatory statutory provisions, in particular retention periods, remain unaffected.

The contact form is provided by Netlify Forms, a service of the host named in section 2. Your entries are stored on Netlify’s servers and forwarded to me by email. The information in section 2 on Netlify, the Data Privacy Framework and the data processing agreement applies accordingly.

Enquiries by email or phone

If you contact me by email or phone, your enquiry, including all personal data resulting from it (name, enquiry), will be stored and processed by me for the purpose of handling your request. I will not pass this data on without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your enquiry is related to the fulfilment of a contract or is necessary to carry out pre-contractual measures. In all other cases, processing is based on my legitimate interest in the effective handling of enquiries sent to me (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent can be withdrawn at any time.

The data you send me via contact requests will remain with me until you ask me to delete it, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. after your request has been dealt with). Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.

Email provider: Google Workspace

I use Google Workspace to send and receive emails. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). When you write to me, or when I receive your answers from the contact form, your email and the personal data it contains are processed on Google’s servers.

The data is processed on the basis of my legitimate interest in reliable and secure email communication (Art. 6(1)(f) GDPR) and, where your enquiry concerns a contract, Art. 6(1)(b) GDPR.

Data may also be transferred to Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF), and Google also relies on the European Commission’s Standard Contractual Clauses. I have concluded a data processing agreement with Google. For more information, see Google’s privacy policy: https://policies.google.com/privacy

5. Appointment booking with Calendly

You can book appointments with me on this website, for example the free first session. I use the tool Calendly for this. The provider is Calendly, LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA ("Calendly").

When you book an appointment, you enter your details in Calendly's booking form. These are usually your name, your email address, the date and time you choose, and your answers to the questions in the booking form. Calendly stores this data and sends it to me so that I can confirm and prepare the appointment. Calendly also receives technical data such as your IP address.

When you click on a booking button on this website, you are taken to Calendly's website. Calendly only receives your data once you open its booking page.

If you fill in the contact form first, your name and email address are passed on to Calendly when you are redirected, so that you don’t have to enter them again. Your other answers from the contact form are not passed on to Calendly.

The data is processed to arrange and prepare our appointment, i.e. to take steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR). I also have a legitimate interest in scheduling appointments with interested parties as simply as possible (Art. 6(1)(f) GDPR). Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on your device. Consent can be withdrawn at any time.

Please do not enter any special categories of personal data in the booking form, in particular no health information. We can talk about anything personal in the conversation itself.

The data you enter will remain with me and with Calendly until you ask me to delete it or the purpose for storing it no longer applies (e.g. after our appointment has taken place and there is no follow-up). Mandatory statutory provisions, in particular retention periods, remain unaffected.

Calendly is certified under the EU-U.S. Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to complying with these standards. Calendly also relies on the European Commission's Standard Contractual Clauses. For more information, see Calendly's privacy notice: https://calendly.com/legal/privacy-notice