Privacy Policy

I take the protection of your personal data seriously. This privacy policy explains which personal data is processed when you visit this website, for what purpose, and on what legal basis.

1. Controller

The controller responsible for data processing on this website is:

Thimo Hofner — Clicks in Mind
Lahntalstr. 15
80995 Munich
Germany

Email: thimo.hofner@clicksinmind.com

2. General information on data processing

I process personal data only to the extent necessary to provide a functioning website along with my content and services. Depending on the case, the legal basis is Art. 6 (1) (a) GDPR (consent), (b) (contract or pre-contractual measures) or (f) (legitimate interest). Personal data is deleted as soon as the purpose for storing it no longer applies and no statutory retention obligations stand in the way.

3. Provision of the website and server log files

When you access this website, the hosting provider automatically records information that your browser transmits. This includes:

  • IP address of the requesting device
  • date and time of access
  • page or file accessed
  • volume of data transferred
  • browser type and operating system used
  • referrer URL (the previously visited page)

This data is processed to enable the connection, to ensure the stability and security of the website, and to guarantee smooth operation. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a technically error-free presentation and in security).

4. Hosting

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel processes the server log data named under section 3 on my behalf as a processor. For the transfer of data to the USA, the provider relies on appropriate safeguards pursuant to Art. 44 et seq. GDPR (EU Commission standard contractual clauses or the EU-US Data Privacy Framework). The legal basis for its use is Art. 6 (1) (f) GDPR.

[NOTE: If the domain runs through Cloudflare, add Cloudflare here as an additional service provider.]

5. Contact form and contact by email

When you send me an enquiry via the contact form or by email, your details (in particular name, email address, company and message) are processed for the purpose of handling the enquiry. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in responding to enquiries). This data is deleted as soon as the enquiry has been fully dealt with and no statutory retention obligations exist.

The data submitted via the contact form is processed through a dedicated server function on the hosting platform (Vercel, see section 4) and stored in a database of the service Notion (Notion Labs, Inc., USA) in order to handle your enquiry. Notion processes this data as a processor; for the transfer to the USA, the provider relies on appropriate safeguards pursuant to Art. 44 et seq. GDPR (standard contractual clauses or the EU-US Data Privacy Framework). In addition, a notification may be sent via the email service Resend (Resend, Inc., USA). The legal basis is Art. 6 (1) (b) or (f) GDPR.

6. Cookies

This website uses only technically necessary cookies that are required to operate the site (e.g. to store your language selection). These cookies do not require consent. There is currently no tracking and no analysis of your usage behavior for marketing or statistical purposes.

[NOTE: As soon as GA4 / Google Tag Manager or other tracking/marketing cookies are added, this section must be expanded and a cookie consent banner (opt-in) is required.]

7. Fonts (web fonts)

The fonts used on this website are delivered locally from my own server (self-hosted). No data is transferred to third parties (e.g. Google Fonts) in the process.

8. Review seal (ProvenExpert)

This website embeds a review seal from the service ProvenExpert (Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin) that displays my customer reviews. To do so, a script is loaded from a ProvenExpert server when the page is accessed, which for technical reasons transmits your IP address to the provider. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in presenting trust-building customer reviews). You’ll find more information in the ProvenExpert privacy policy.

This website links to my profiles on LinkedIn and YouTube. Only when you actively click one of these links are you forwarded to the respective provider. The respective provider is responsible for data processing on the linked platforms. Merely visiting my website does not transfer your data to these providers.

10. Your rights as a data subject

With regard to the personal data concerning you, you have the following rights:

  • right of access (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to object to processing (Art. 21 GDPR)
  • right to withdraw a given consent with effect for the future (Art. 7 (3) GDPR)

To exercise your rights, an informal message to the email address named above is sufficient.

11. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority. The competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

12. Validity and changes to this privacy policy

This privacy policy is currently valid. As the website develops further, or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy.