Zum Hauptinhalt springen

Stanley Rubyn

Datenschutzhinweis

Allgemeine Informationen

Ich informiere Sie gemäß Art. 13 und 14 DSGVO über die Erhebung, Speicherung und Verarbeitung Ihrer personenbezogenen Daten bei Nutzung meiner Website. Ich behalte mir vor, diese Erklärung bei Bedarf anzupassen, um stets den aktuellen rechtlichen Anforderungen zu entsprechen.

 

Kontaktdaten des Verantwortlichen

Verantwortlich für diese Website ist:

 

Stanley Okoro
Petersburger Str. 39
10249 Berlin
Deutschland

 

E-Mail: info@stanley-rubyn.com
Mobil: +49 (0) 172 755 44 56

 

Datenverarbeitung auf meiner Webseite

Kontaktaufnahme über WhatsApp Business und Superchat

Ich biete die Kontaktaufnahme über den Messenger-Dienst WhatsApp an. Da ich für die geschäftliche Kommunikation die WhatsApp Business Platform (Cloud API) nutze, erfolgt die Datenverarbeitung über die Plattform Superchat (SuperX GmbH, Prenzlauer Allee 242-247, 10405 Berlin).

 

Weitere Informationen finden Sie in der Datenschutzrichtlinie von SuperX GmbH.

 

Wenn Sie mich über WhatsApp kontaktieren, wird Ihre Nachricht Ende-zu-Ende verschlüsselt an die WhatsApp Cloud übermittelt. Die Nachricht wird dort nur vorübergehend gespeichert, bis sie erfolgreich an Superchat weitergeleitet wurde.

Superchat aktiviert für meine Nutzung die Funktion „Local Storage Solution". Das bedeutet, dass der Inhalt Ihrer Nachricht nach der Entschlüsselung durch die Cloud API dauerhaft auf Servern in Deutschland gespeichert wird. Da die Kommunikation über die WhatsApp Cloud API von Meta erfolgt, durchläuft die Nachricht im Rahmen des Transports kurzzeitig auch Server in den USA (oder anderen Ländern), bevor sie bei Superchat in Deutschland ankommt.

 

Diese Daten werden im Transit nicht dauerhaft gespeichert und nach erfolgreicher Weiterleitung automatisch gelöscht (innerhalb von ca. 60 Minuten). Bitte beachten Sie, dass Meta (WhatsApp) als Infrastrukturanbieter unabhängig von Superchat Metadaten (z. B. Zeitpunkt, Häufigkeit, Geräteinformationen) als eigenständiger Verantwortlicher erhebt und verarbeiten kann, auch wenn der Nachrichteninhalt in Deutschland bleibt.

 

Roller der Anbieter

  • Sie(Kunde): Sind der Absender der Nachricht.
  • Ich (Unternehmer): Bin der Verantwortliche für die Kommunikation und nutze Superchat als Auftragsverarbeiter.

Superchat (SuperX GmbH): Ist mein Auftragsverarbeiter und verarbeitet die Daten streng nach meinen Weisungen.

  • Meta (WhatsApp): Ist Unterauftragsverarbeiter, der die Infrastruktur (Cloud API) bereitstellt.

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Beantwortung Ihrer Anfragen und Kontaktaufnahme
  • Bearbeitung von Buchungsanfragen und Vertragsabschluss
  • Technische Sicherstellung der verschlüsselten Kommunikation
  • Verhinderung von Missbrauch und Spam

 

Welche Daten sammle ich?

  • Telefonnummer
  • Name (sofern hinterlegt)
  • Inhalt Ihrer Nachricht
  • Metadaten(Zeitpunkt der Nachricht, Geräteinformationen)

 

Welche technischen Daten werden automatisch erfasst?

  • IP-Adresse (wird von Meta/WhatsApp für die Zustellung genutzt, von mir nicht dauerhaft gespeichert)
  • Zeitstempel der Nachricht
  • Browser- und Betriebssysteminformationen (nur zur Übermittlung notwendig)

 

Die Verarbeitung erfolgt auf Basis Ihrer Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), wenn Sie mich aktiv über WhatsApp kontaktieren, oder zur Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO), wenn die Kommunikation im Rahmen eines Vertragsverhältnisses steht.

 

Die Nachrichten sind Ende-zu-Ende verschlüsselt. Während der Übertragung und im Ruhezustand auf den Servern von Superchat (in Deutschland) sind die Daten zusätzlich verschlüsselt. Im Gegensatz zur normalen WhatsApp-App auf dem Handy wird bei der Nutzung der Cloud API keine Synchronisierung Ihrer gesamten Kontaktliste an Meta durchgeführt. Nur die für die Kommunikation notwendige Telefonnummer wird übermittelt. Superchat verarbeitet die Daten ausschließlich im Auftrag von mir. Ich habe die volle Kontrolle über die Daten und kann deren Löschung veranlassen.

 

Die Speicherung der Nachrichteninhalte erfolgt in Deutschland. Eine Übermittlung in die USA findet nur im transienten Transport (Cache/Queues) statt, wo die Daten nach 60 Minuten automatisch gelöscht werden. Diese Übermittlung ist durch das EU-US Data Privacy Framework und Standardvertragsklauseln abgesichert.

 

Die Nachrichten werden so lange gespeichert, wie es für die Beantwortung Ihrer Anfrage oder die Vertragserfüllung notwendig ist. Danach werden sie gelöscht, es sei denn, gesetzliche Aufbewahrungspflichten (z. B. für geschäftliche Korrespondenz) stehen entgegen.

Meta Platforms Ireland Limited ist als Unterauftragsverarbeiter für die Bereitstellung der Infrastruktur verantwortlich. Meta erhebt eigene Metadaten (z. B. Zeitpunkt, Häufigkeit der Nutzung) als eigenständiger Verantwortlicher für den Betrieb des Dienstes.

 

Weitere Informationen finden Sie in der Datenschutzrichtlinie von WhatsApp.

 

Zwischen mir und SuperX GmbH besteht ein Vertrag über die Auftragsverarbeitung (AVV) gemäß Art. 28 DSGVO. Dieser stellt sicher, dass Superchat die Daten nur nach meinen Weisungen verarbeitet und angemessene technische und organisatorische Maßnahmen (z. B. Verschlüsselung, Zugriffskontrolle) trifft.

 

Contact Form (Fluent Forms)

For creating contact forms or other forms, I use the plugin “Fluent Forms”. Your entries are stored directly in my database. Since I use the server of my German web host, no content is forwarded to external cloud services.

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Beantwortung Ihrer Anfragen und Kontaktaufnahme
  • Bearbeitung von Buchungsanfragen und Vertragsabschluss
  • Technically ensuring email delivery
  • Verhinderung von Missbrauch und Spam

 

Welche Daten sammle ich?

  • Name
  • Email address and phone number (if provided)
  • Inhalt Ihrer Nachricht
  • Possibly other information you provide

 

Welche technischen Daten werden automatisch erfasst?

  • IP address
  • Timestamp
  • Browser and operating system information and the referrer URL

 

These data are protected by SSL/TLS encryption during transmission. The collection of technical data serves exclusively to technically secure email delivery, filter spam, and ensure message management. No evaluation for profiling purposes or marketing takes place.

 

Processing is carried out for the performance of pre-contractual measures or contract fulfillment (Art. 6 Para. 1 lit. b GDPR), especially for booking requests. For general information inquiries, processing is based on my legitimate interest to effectively answer your inquiries and prevent abuse (Art. 6 Para. 1 lit. f GDPR). If you have given explicit consent (e.g., for the newsletter), I use this as an additional legal basis (Art. 6 Para. 1 lit. a GDPR).

 

Appointment Booking (FluentBooking)

For appointment bookings, I use the plugin “FluentBooking”, a locally hosted service that writes booking entries directly into my database (i.e., data is not forwarded to external cloud services or the plugin provider’s servers).

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Arranging initial telephone consultations
  • Booking sessions in my home studio (e.g., audio recordings)
  • Communication regarding appointment confirmation and changes
  • Managing and billing booked services

 

Welche Daten sammle ich?

  • Name, email address, and phone number
  • Desired appointment and duration of the booking
  • Type of service (phone call or studio session)
  • Possibly additional messages or special requests

 

Welche technischen Daten werden automatisch erfasst?

  • IP address, timestamp, browser and operating system information
  • Email header data for reliable delivery
  • Cookie data for session management

 

These data are protected by SSL/TLS encryption during transmission. The collection of technical data serves exclusively to technically secure email delivery, filter spam, and ensure message management. No evaluation for profiling purposes or marketing takes place.

 

Processing is carried out for the performance of pre-contractual measures or contract fulfillment (Art. 6 Para. 1 lit. b GDPR), especially for appointment bookings. The collection of technical data is based on my legitimate interest to ensure the security and functionality of the booking system and prevent abuse (Art. 6 Para. 1 lit. f GDPR). If you have given explicit consent, I use this as an additional legal basis (Art. 6 Para. 1 lit. a GDPR).

 

Email Sending (FluentSMTP)

For secure and reliable email sending, I use the plugin “FluentSMTP”. It ensures that your inquiry or message reaches my email inbox directly. Since I use the SMTP server of my German web host, no content is forwarded to external cloud services.

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Secure and reliable delivery of your emails, contact form messages, and notifications
  • Improving deliverability (avoiding spam)
  • Technically ensuring sending and analyzing errors in case of delivery problems

Preventing abuse and spam by logging sending attempts

 

Welche Daten sammle ich?

  • Email address of the sender (and possibly the recipient)
  • Name, content of your message, and subject line

 

Welche technischen Daten werden automatisch erfasst?

  • IP address of the sender (for identification and spam prevention)
  • Sending timestamp and delivery status (successful, failed)
  • Browser and operating system information and server headers

 

The sender’s IP address is stored only as long as necessary for technically securing the sending and spam prevention (usually max. 7 days) and is then deleted unless legal reasons require longer retention.

These data are protected by SSL/TLS encryption during transmission. The collection of technical data serves exclusively to technically secure sending, filter spam, and manage messages. No evaluation for profiling purposes or marketing takes place.

 

Processing is carried out for the performance of pre-contractual measures or contract fulfillment (Art. 6 Para. 1 lit. b GDPR), especially for inquiries via contact forms. For purely technical processes of email sending (e.g., system messages), processing is based on my legitimate interest to ensure the functionality of website communication and prevent abuse (Art. 6 Para. 1 lit. f GDPR).

 

Newsletter (FluentCRM)

I use the plugin FluentCRM” for creating newsletters and managing my subscribers, a locally hosted service that stores data directly in my database (i.e., data is not forwarded to external cloud services or the plugin provider’s servers).

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Regular information about current news, offers, and relevant content
  • Direct communication with my subscribers
  • Providing exclusive content or special offers

 

Welche Daten sammle ich?

  • Email address
  • Name
  • Date and time of subscription
  • IP address at the time of subscription
  • Confirmation status
  • Unsubscribe date and time
  • Possibly other information

 

Welche technischen Daten werden automatisch erfasst?

  • IP address with every retrieval or click
  • Timestamp of opening the email or clicking links (open and click tracking)
  • Browser and operating system information
  • Referrer URL
  • Delivery status and technical error messages

 

This data is used to analyze whether and when you open my emails and which links you click. This serves to optimize my content and technically ensure sending. This tracking constitutes a form of profiling according to Art. 4 No. 4 GDPR, as conclusions about your interests can be drawn from your interactions. However, I do not create comprehensive personality profiles for purposes outside this newsletter (e.g., no sharing with third parties or combination with other data sources). The processing of this tracking data is based on the same consent (Art. 6 Para. 1 lit. a GDPR) you gave for receiving the newsletter. You can object to tracking by unsubscribing from the newsletter.

 

After a period of 30 days, the tracking data (open and click statistics) is fully anonymized. This means the data can no longer be assigned to a specific email address or person but is only available as aggregated statistical values (e.g., open rate in percent). Once anonymization occurs, this data no longer falls under the scope of the GDPR and can be used for long-term analysis to optimize my content.

 

The processing of your email address and data for the newsletter is based exclusively on your explicit consent in accordance with Art. 6 Para. 1 lit. a GDPR. Since the newsletter does not constitute a contractual service, Art. 6 Para. 1 lit. b GDPR is not applicable here. For general information inquiries (e.g., via contact form) not related to the newsletter, processing is based on my legitimate interest to effectively answer your inquiries and prevent abuse (Art. 6 Para. 1 lit. f GDPR).

 

You can revoke your consent at any time by unsubscribing from the newsletter or sending a message to info@stanley-rubyn.com. With the revocation, the legal basis for further processing of your data for the newsletter ceases to exist.

 

Cookies and Other Embedded Services (Plugins)

Consent Tool (Real Cookie Banner)

On my website, I use the plugin “Real Cookie Banner”. With this, I obtain your consent for cookies before they are set. The plugin blocks external content such as embedded YouTube videos by default until you give your consent. The plugin runs on my own server. All data is stored directly in my database or as small files (cookies) on your device. Data is not sent to external companies or the manufacturer’s servers, as my website is hosted on a German server.

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • To obtain consent for cookies
  • To store which cookies you allowed or rejected
  • To save consent as proof
  • To ensure my website functions legally

 

Welche Daten sammle ich?

  • Consent status (accepted/rejected for various cookie categories)
  • Date and time of consent
  • Version number of cookie settings (for update proofs)
  • Session ID to assign the consent

 

Welche technischen Daten werden automatisch erfasst?

  • IP address (only briefly for the decision)
  • Browser and device information
  • When you opened the settings (timestamp)
  • Which cookie names were set
  • From which page you came (referrer URL)

 

All data is encrypted during transmission (SSL/TLS). Technical data helps only to securely store consent and keep the system functional. No evaluation for profiling purposes or marketing takes place.

Processing is based on your explicit consent in accordance with Art. 6 Para. 1 lit. a GDPR. The plugin stores this consent to prove that you agreed to the data processing. This also serves my legitimate interest to ensure the legal compliance of my website (Art. 6 Para. 1 lit. f GDPR).

You can revoke your consent at any time via the Cookie Banner interface. A subsequent change of your settings is also possible.

 

I store your decision as long as you have consented or as the law requires (usually up to 2 years as proof). If you revoke or the time expires, I delete the data.

A detailed overview of all cookies used, their duration, and purpose can be found in my separate Cookie Richtlinie.

 

Online Shop (WooCommerce and WooCommerce Germanized)

For operating my online shop, I use the plugins “WooCommerce” and “WooCommerce Germanized”. WooCommerce enables the display of products, the shopping cart, and the checkout process. WooCommerce Germanized adds legally required functions according to German law, including the right of withdrawal notice, terms and conditions integration, mandatory information on prices and delivery times, and a double-opt-in procedure for order confirmation. Both plugins run on the server of my German web host. Personal data is stored directly in my database and not forwarded to external cloud services or the plugin providers’ servers.

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Executing orders and fulfilling contracts
  • Providing the shopping cart and checkout functionality
  • Sending order confirmations and status updates (via double-opt-in)
  • Obtaining legally required consents (e.g., terms and conditions, right of withdrawal)
  • Processing payments and shipping arrangements
  • Providing a customer account (if you create one)
  • Complying with legal obligations (e.g., accounting, retention obligations)

 

Welche Daten sammle ich?

  • First and last name
  • Billing and possibly shipping address
  • Email address and phone number (if provided)
  • Order data (products, quantities, prices, shipping method, payment method)
  • Payment data (depending on the chosen payment method — Note: Credit card data is not stored by me but processed directly by the payment service provider)
  • Customer account data (username, password — stored encrypted) if you create an account
  • Consents (terms and conditions, right of withdrawal, possibly newsletter) with timestamp

 

Welche technischen Daten werden automatisch erfasst?

  • IP address
  • Timestamp of the order and individual order steps
  • Browser and operating system information and the referrer URL
  • Cookie data to maintain the session and shopping cart (session cookie and possibly a permanent shopping cart cookie if you are logged in)

 

These data are protected by SSL/TLS encryption during transmission. The cookies serve exclusively the technical functionality of the shop (cart, login, checkout process) and are not used for profiling or marketing. A detailed overview of the cookies used can be found in my Cookie Richtlinie.

 

The processing of your order and customer data is carried out for contract fulfillment or the performance of pre-contractual measures (Art. 6 Para. 1 lit. b GDPR). The storage of consents (terms and conditions, right of withdrawal) is based on my legal obligation to document (Art. 6 Para. 1 lit. c GDPR) and my legitimate interest to be able to prove legal claims (Art. 6 Para. 1 lit. f GDPR). If you create a customer account, processing is based on contract fulfillment (Art. 6 Para. 1 lit. b GDPR). No further evaluation for profiling purposes or marketing takes place.

 

As part of WooCommerce Germanized, your email address is confirmed via a double-opt-in procedure during the checkout process. This means: After your order, you receive an email with a confirmation link. Only by clicking this link is your order finally processed and you receive the order confirmation. This ensures that the order actually comes from you and prevents abuse. The data collected here (email address, IP address, and timestamp of confirmation) is processed on the same legal basis as the order data.

 

Order data is stored for the duration of statutory retention obligations (10 years for invoices according to § 147 AO and § 257 HGB). Customer account data (e.g., username, password, profile information) is deleted as soon as you delete your account or upon a corresponding request. Regardless of deleting your customer account, we are legally obliged to retain invoice data (name, address, order date, amount, items) for 10 years (§ 147 AO, § 257 HGB). After deleting the account, this data is stored in a separate, purely accounting database and is no longer linked to your active customer account. After the statutory period expires, this data is also deleted. Session cookies are deleted after closing the browser; the shopping cart cookie loses validity after 48 hours or after logout.

 

Payment Processing (Mollie)

For secure payment processing in the shop, I use the services of Mollie. I do not store sensitive payment data (such as full credit card numbers or bank details) on my own servers. Instead, this data is transmitted directly and encrypted to Mollie, which acts as an independent controller:

 

Mollie B.V.
Keizersgracht 126
1015 CW Amsterdam
Netherlands

 

If you choose a payment method via Mollie (e.g., credit card, PayPal, Sofortüberweisung, Giropay, Apple Pay, or other available methods), your order data and the information required for the payment are transmitted to Mollie. Mollie forwards the payment to the respective payment provider and executes the transaction.

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Executing online payments
  • Authorizing and processing the chosen payment method
  • Fraud prevention and ensuring payment security
  • Fulfilling legal obligations
  • Documenting and proving transactions
  • Customer service for payment questions

 

Welche Daten sammle ich?

  • First and last name
  • Billing address
  • Email address and possibly phone number
  • Order data (digital products, quantities, prices, payment method)
  • Payment data (depending on the chosen payment method)
  • Information about the purchased digital product

 

Welche technischen Daten werden automatisch erfasst?

  • IP address (for fraud prevention and transaction security)
  • Internet browser and device type (User-Agent)
  • Transaction timestamp
  • Location data (if transmitted by the browser)

 

The processing of your data is based on several legal grounds: Firstly, it is necessary for contract fulfillment (Art. 6 Para. 1 lit. b GDPR) as you are buying something from me and the payment must be processed. Secondly, it is based on my legitimate interest in secure payment processing and fraud prevention (Art. 6 Para. 1 lit. f GDPR). Finally, there are legal obligations that Mollie, as a financial institution, must comply with, e.g., for anti-money laundering (Art. 6 Para. 1 lit. c GDPR).

 

These data are protected by SSL/TLS encryption during transmission. The collection of technical data by Mollie serves exclusively payment processing, fraud prevention, and ensuring system integrity. No evaluation for profiling purposes or marketing by me takes place. Mollie may, however, use automated procedures to detect and prevent financial crime.

 

  • Mollie is a European company based in the Netherlands and processes data primarily within the EU. In some cases, data may be processed outside the European Economic Area (EEA), e.g., if an international payment provider is involved for the chosen payment method. In such cases, Mollie ensures an adequate level of data protection through legal guarantees (EU Standard Contractual Clauses).

 

  • Mollie may pass data to commissioned service providers and audit partners, e.g., for identity verification and fraud prevention. Additionally, Mollie may be legally obliged to pass data to government authorities (e.g., law enforcement or tax authorities).

 

  • You cannot object to data processing by Mollie, as it is strictly necessary for the purchase. Without processing, the payment cannot be executed.

 

Further information: Mollie Privacy Policy

 

If a payment is unsuccessful, I reserve the right to store the necessary data (name, address, email, transaction ID) for processing or legal enforcement of claims. The storage duration is determined by statutory retention obligations (usually 10 years for tax-relevant documents according to § 147 AO and § 257 HGB) or Mollie’s guidelines. As a financial institution, Mollie is legally obliged to retain transaction data for a specific period.

 

Embedded YouTube Videos

I have embedded videos from YouTube on my website. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. To protect your data, embedded YouTube videos are not loaded automatically. Instead, the video is blocked by my Cookie Banner (Real Cookie Banner) until you give your explicit consent. Only after your consent is a connection established to the YouTube servers and the video loaded.

 

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Displaying and playing the YouTube video
  • Connection between browser and YouTube servers
  • Analysis to improve YouTube functionality
  • Recording interactions (playback time, pausing) for statistics
  • Displaying personalized ads by Google
  • Assignment to Google account if logged in (settings, history)

 

Welche Daten sammle ich?

  • No direct data collection by me — all data is transmitted to YouTube and processed by Google

 

Welche technischen Daten werden automatisch erfasst?

  • IP address
  • Browser and operating system information
  • Referrer URL
  • Language settings
  • Timestamp
  • Device information (resolution, hardware capabilities)

 

This data is transmitted to YouTube only after active consent in the Cookie Banner. Without consent, no transmission occurs. If you are logged in to Google, the data can be assigned to your account.

Data processing is based on your consent (Art. 6 Para. 1 lit. a GDPR). You can refuse consent by not agreeing in the Cookie Banner. You can revoke an already granted consent at any time via the Cookie Banner interface. The storage duration of data transmitted to YouTube is determined by Google’s privacy policy. I point out that I have no influence on the storage duration.

 

Further information can be found in the Google Privacy Policy.

 

Embedded Bandcamp Audio Player

I have embedded audio tracks from Bandcamp on my website. The operator is Bandcamp, Inc., 1948 Harrison Street, Oakland, CA, USA.

 

To protect your data, the embedded audio player is not loaded automatically. Instead, the player is blocked by my Cookie Banner (Real Cookie Banner) until you give your explicit consent. Only after your consent is a connection established to the Bandcamp servers and the player loaded.

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Playing audio tracks directly on the website
  • Connection between browser and Bandcamp servers
  • Analysis to improve Bandcamp functionality
  • Recording interactions (playback time, pausing) for statistics
  • Personalization and advertising by Bandcamp

 

Welche Daten sammle ich?

  • No direct data collection by me — all data is transmitted to Bandcamp and processed by Bandcamp

 

Welche technischen Daten werden automatisch erfasst?

  • IP address
  • Browser and operating system information
  • Referrer URL
  • Language settings
  • Timestamp
  • Device information (resolution, hardware capabilities)

 

This data is transmitted to Bandcamp only after active consent in the Cookie Banner. Without consent, no transmission occurs. Data processing is based on your consent (Art. 6 Para. 1 lit. a GDPR). You can refuse consent by not agreeing in the Cookie Banner. You can revoke an already granted consent at any time via the Cookie Banner interface. The storage duration of data transmitted to Bandcamp is determined by Bandcamp’s privacy policy. I point out that I have no influence on the storage duration.

 

Bandcamp is based in the USA. Data transmission is based on the EU-US Data Privacy Framework. However, please note that this may be legally controversial and the level of data protection does not always correspond to that of the EU. If you do not want data transmission to servers in the USA, do not agree to the embedding of the player in the Cookie Banner.

 

Further information can be found in the Bandcamp Privacy Policy.

 

Website Builder (Elementor Pro)

For the design and technology of my website, I use the plugin “Elementor Pro”. It runs completely on my server in Germany. To ensure the page functions correctly (e.g., for previews), the plugin stores only temporary data directly in your browser. Elementor Pro transmits technical data (e.g., domain, license key) to Elementor’s servers to enable license validation and access to template libraries. No further transmission of personal data takes place. Elementor processes this data according to its privacy policy: https://elementor.com/privacy-policy/

 

I process this data only to ensure that my website runs technically flawlessly and looks good on all devices. I do not collect any personal data from you, but only necessary technical information about your browser. The connection is encrypted, and no profile is created about you or used for advertising.

The legal basis is my legitimate interest in a functioning website. The temporary data in the browser is automatically deleted as soon as you close your browser. You can also remove this data at any time by clearing your browser cache.

 

Anti-Spam Protection (WP Armour)

To protect my website from automated spam attacks, malicious comments, and abusive logins, I use the plugin WP Armour — Header Anti-Spam”. The plugin runs locally on my server and analyzes the headers of incoming connections to distinguish human users from automated bots.

Für einen schnellen Überblick fasse ich die Details der Datenverarbeitung hier zusammen:

 

Warum verarbeite ich Daten?

  • Preventing spam comments and spam logins
  • Protecting the website from automated attacks and abuse
  • Ensuring the functionality of contact forms and comment systems
  • Reducing server load from bot traffic

 

Welche Daten sammle ich?

  • No personal content of your message (texts are not stored)
  • Only the technical data necessary for bot detection

 

Welche technischen Daten werden automatisch erfasst?

  • IP address (for identification and blocking of sources)
  • User-Agent (information about browser and operating system)
  • Referrer URL (the page from which the request comes)
  • Timestamp of the request

 

Possibly cookie data (if already set, for session checking)

This data is used exclusively for analysis to filter spam. Storing the data occurs only as long as the request is being processed (usually a few seconds). In case of detected attacks, the IP address can be temporarily stored in a local blacklist to prevent repetitions. No evaluation for profiling purposes or marketing takes place.

 

Processing is based on my legitimate interest to ensure the security and functionality of my website and prevent abuse (Art. 6 Para. 1 lit. f GDPR). Since this is a technically necessary measure to protect the website, no consent in the Cookie Banner is required.

 

WP Armour stores data locally on my server (ALL-INKL.com, Germany). No data is transmitted to external servers of the plugin provider.

 

External Linking to Social Networks or Other Platforms

I use locally embedded social media logos as external hyperlinks. Simply accessing my website does not transmit any data to these services (such as Instagram, TikTok, etc.). Only by actively clicking the links are you redirected in a new browser tab. At this moment, your data (e.g., IP address, time of visit) is transmitted to the respective platform. Furthermore, behavioral data (interests, purchasing behavior) can also be collected to display personalized ads.

 

do not store any data myself about your clicks on these external links. As soon as you click an external link (e.g., to Facebook, Instagram, YouTube), you are redirected directly to the website of the respective provider. At this moment, your browser automatically transmits data (such as your IP address, the visited page, timestamp, and browser information) to the respective provider. Since I have no influence on the data processing of these external providers, I point out that data transmission takes place immediately as soon as you activate the link. Processing is based on my legitimate interest to provide you with access to these content, but the actual data collection then lies in the responsibility of the respective platform operator.

 

Since I have no influence on how the provider collects and processes your data, I point out that you should check the privacy policies of these providers:

 

Meta Platforms (Facebook, Instagram, WhatsApp) Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland Facebook Privacy Policy Instagram Privacy Policy

WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland WhatsApp Privacy Policy WhatsApp Business App Privacy Policy

 

TikTok TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, Ireland Datenschutzhinweis

 

Google and YouTube Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Datenschutzhinweis

 

Spotify Spotify AB, Regeringsgatan 19, Stockholm, Sweden Datenschutzhinweis

 

Bandcamp (USA) Bandcamp, Inc., 1948 Harrison Street, Oakland, CA, USA Datenschutzhinweis

 

SoundCloud SoundCloud Global Limited & Co. KG, Karl-Marx-Strasse 101, 12043 Berlin, Germany Datenschutzhinweis

 

Pinterest Pinterest Europe Ltd., Palmerston House, Dublin 2, Ireland Datenschutzhinweis

 

If you are logged in to one of the social platforms, the respective provider can assign your visit to your user account. For providers based in the USA (e.g., Bandcamp), data transmission is based on the EU-US Data Privacy Framework. However, please note that this may be legally controversial and the level of data protection does not always correspond to that of the EU. If you do not want data transmission to servers in third countries, do not click the external link. I mark external links with a symbol (e.g., ↗) so you recognize that you are leaving my website.

 

Datenweitergabe an Auftragsverarbeiter und Dritte

Für mein Webhosting habe ich eine Vereinbarung zur Auftragsverarbeitung gemäß Art 28 DS-GVO mit:

 

ALL-INKL.com - Neue Medien Münnich, Inhaber René Münnich, Hauptstraße 68, 02742 Friedersdorf, Deutschland

 

als beauftragten Dienstleister abgeschlossen. Dadurch wird gewährleistet, dass personenbezogene Daten (z. B. IP-Adressen, Webseitenzugriffe) nur nach meinen Weisungen und DSGVO-konform verarbeitet werden. Die beauftragte Dienstleistung behält sich vor, weitere Unterauftragsverarbeiter einzusetzen. Sollte dies der Fall sein, werde ich die entsprechenden Änderungen bzw. Anpassungen meiner Datenschutzerklärung vornehmen.

 

Ich gebe personenbezogene Daten nur dann an Dritte weiter, wenn dies zur Vertragserfüllung notwendig ist, eine Einwilligung vorliegt oder ich gesetzlich dazu verpflichtet bin. Eine Weitergabe erfolgt nur im Rahmen der DSGVO (Art. 6 Abs. 1 DSGVO). Die Verarbeitung in Drittländern außerhalb EU/EWR findet streng nur unter Einhaltung der Art. 44 ff. DSGVO statt.

 

Personenbezogene Daten werden nur so lange gespeichert, wie es für die Erfüllung des Webhosting-Vertrags erforderlich ist oder ich ein berechtigtes Interesse an der Aufbewahrung habe. Bei Beendigung dieses Vertrages erfolgt i.d.R. die sofortige Löschung aller Daten auf den Speichermedien, sofern ALL-INKL.COM nicht aufgrund gesetzlicher Vorschriften (z. B. Steuerrecht) zur Aufbewahrung verpflichtet ist.

 

Widerspruchsrecht

Wenn ich im Rahmen einer Interessenabwägung Ihre personenbezogenen Daten aufgrund meines überwiegenden berechtigten Interesses verarbeite, haben Sie das jederzeitige Recht, aus Gründen, die sich aus Ihrer besonderen Situation ergeben, gegen diese Verarbeitung Widerspruch mit Wirkung für die Zukunft einzulegen.

 

Machen Sie von Ihrem Widerspruchsrecht Gebrauch, beende ich die Verarbeitung der betroffenen Daten. Eine Weiterverarbeitung bleibt aber vorbehalten, wenn ich zwingende schutzwürdige Gründe für die Verarbeitung nachweisen kann, die Ihre Interessen, Grundrechte und Grundfreiheiten überwiegen, oder wenn die Verarbeitung der Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen dient.

 

Werden Ihre personenbezogenen Daten von mir verarbeitet, um Direktwerbung zu betreiben, haben Sie das Recht, jederzeit Widerspruch gegen die Verarbeitung Sie betreffender personenbezogener Daten zum Zwecke derartiger Werbung einzulegen. Sie können den Widerspruch wie oben beschrieben ausüben.

 

Machen Sie von Ihrem Widerspruchsrecht Gebrauch, beende ich die Verarbeitung der betroffenen Daten zu Direktwerbezwecken.

 

Ihre Rechte als Betroffene Person

Gemäß Art. 15 DSGVO haben Sie das Recht auf Auskunft über den Verarbeitungszweck, die Kategorien der verarbeiteten Daten, die Speicherdauer, die Herkunft der Daten sowie die Empfänger bzw. Empfänger in Drittländern, gegenüber denen Ihre Daten übermittelt worden sind oder noch übermittelt werden.

 

Sie haben das Recht auf Berichtigung unrichtiger oder Vervollständigung unvollständiger personenbezogener Daten gemäß Art. 16 DSGVO. Weiterhin besteht das Recht auf Löschung Ihrer personenbezogenen Daten („Recht auf Vergessenwerden", Art. 17 DSGVO) sowie auf Einschränkung der Verarbeitung gemäß Art. 18 DSGVO.

 

Gemäß Art. 20 DSGVO haben Sie das Recht, die personenbezogenen Daten, die Sie mir bereitgestellt haben, in einem strukturierten, gängigen und maschinenlesbaren Format zu erhalten. Zudem haben Sie das Recht, diese Daten direkt an einen anderen Verantwortlichen übermitteln zu lassen, sofern dies technisch machbar ist, die Verarbeitung auf einer Einwilligung oder einem Vertrag beruht und mithilfe automatisierter Verfahren erfolgt.

 

Um Ihnen die Ausübung dieses Rechts zu erleichtern, stelle ich Ihnen Ihre gespeicherten Daten auf Anfrage in einem gängigen, strukturierten und maschinenlesbaren Format zur Verfügung. Je nach Art der Daten (z. B. aus dem Shop-System oder dem Newsletter-Tool) können wir dies als JSON- oder CSV-Datei bereitstellen. Bitte richten Sie entsprechende Anfragen an unsere unten genannte Kontaktadresse.

 

Ich wende keine automatisierten Entscheidungsfindungsverfahren einschließlich Profiling an, die rechtlichen Wirkungen entfalten oder Sie ähnlich erheblich beeinträchtigen (Art. 22 DSGVO). Zudem steht Ihnen das Recht zu, sich bei einer zuständigen Aufsichtsbehörde über die Verarbeitung Ihrer Daten zu beschweren (Art. 77 DSGVO). Für eine schnelle Bearbeitung von Anfragen zu Ihren Rechten (z. B. Auskunft oder Löschung) nutzen Sie bitte die E-Mail info@stanley-rubyn.com.

 

Speicherdauer

Ich speichere Ihre Daten nur so lange, wie es für den Zweck erforderlich ist oder gesetzliche Aufbewahrungspflichten bestehen.

 

  • Kontaktformular & allgemeine Anfragen: Die Daten werden 6 Monate nach Abschluss der Kommunikation gelöscht, sofern keine gesetzlichen Aufbewahrungspflichten entgegenstehen.

 

  • Terminbuchungen: Buchungsdaten werden 3 Jahre nach dem letzten Termin aufbewahrt (Verjährungsfrist für vertragliche Ansprüche), danach gelöscht.

 

  • Newsletter: Ihre Daten werden unverzüglich nach dem Widerruf Ihres Abos gelöscht. Technische Daten (Öffnungs-/Klickstatistiken) werden 30 Tage nach dem Versand aggregiert gespeichert und danach anonymisiert oder gelöscht.

 

  • Cookie-Einwilligungen: Die Protokolldaten Ihrer Einwilligung werden 2 Jahre aufbewahrt, um den Nachweis gegenüber der Aufsichtsbehörde zu sichern.

 

  • Webserver-Logs (IP-Adressen): Diese werden standardmäßig nach 7 Tagen gelöscht, es sei denn, sie dienen der Aufklärung eines Sicherheitsvorfalls.

 

Sobald der Zweck entfällt oder Sie widerrufen, lösche ich die Daten, es sei denn, das Gesetz verlangt eine längere Aufbewahrung (z. B. 10 Jahre für Rechnungen gemäß § 147 AO und § 257 HGB). Nach Ablauf der Fristen erfolgt die Löschung.

 

Letztes Update: Mai 2026

DSGVO Cookie Consent mit Real Cookie Banner