[SCAFFOLD — placeholder structure only.] The headings below are the sections a German company’s privacy policy normally needs. The actual binding wording must be supplied/validated by a lawyer or a reputable German generator (e.g. eRecht24, Dr. Schwenke’s Datenschutz-Generator) and reflect the real tools in use.
1. Controller (Verantwortlicher)
Lab IV Berlin GmbH
Fehrbelliner Str. 27
10119 Berlin, Germany
E-Mail: ilya@lab4.berlin
[Add data-protection contact / phone if one is designated. Telephone is available on request.]
2. Overview
[Short plain-language summary of what data is processed and why, and a note that the site is operated from Germany under the GDPR / BDSG / TTDSG.]
3. Data we process
[Describe each: server log files (IP address, timestamp, user agent, referrer) created automatically by the host; data from any contact by e-mail; and the booking link (meet2.lab4.berlin) if a scheduling tool is embedded or linked.]
4. Legal bases for processing
[Map each purpose to its Art. 6(1) GDPR basis — e.g. legitimate interest (f) for secure operation/logs, consent (a) for analytics cookies, contract/pre-contract (b) for enquiries.]
5. Cookies and consent
[State that only strictly necessary cookies are set without consent; that any analytics/optional cookies load only after “Accept” in the cookie banner; how the choice is stored; and how to withdraw or change consent at any time (the “Cookie settings” link in the footer re-opens the banner). List the concrete cookies, their purpose, provider, and lifetime.]
6. Analytics and third-party services
[Name each tool actually used — e.g. a privacy-friendly analytics provider — with provider, purpose, data transferred, location, and legal basis. If none is used, state that explicitly.]
7. Hosting and data processors
[Name the hosting provider and any processors, and reference the data-processing agreements (AVV) in place. Note any transfers to third countries and the safeguards used.]
8. External links and embedded content
[Cover outbound links and any embeds — the booking scheduler, LinkedIn, YouTube videos on the blog — including whether embeds load only on interaction.]
9. Data retention
[State how long each category is kept and the deletion criteria.]
10. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object. You may also withdraw consent at any time with future effect.
[Add the right to lodge a complaint with the competent supervisory authority — for Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit — with its address.]
11. Changes to this policy
[Note that the policy may be updated and show a “last updated” date.]
Last updated: [DATE]