Privacy policy
1. Controller
Timo Wevelsiep
Max-Liersch-Anger 13, 59457 Werl, Germany
Email: [email protected]
2. Hosting and delivery through Cloudflare
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on servers located in Germany.
Cloudflare is used to deliver the website securely and efficiently (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare processes technically necessary connection data, in particular the IP address, requested URL, time, referrer, and browser and system information. The processing serves delivery, stability, and protection of the website, especially against abusive access. The legal basis is Article 6(1)(f) GDPR; my legitimate interest is the secure and reliable operation of the website.
Where data is transferred to the United States, Cloudflare states that it relies in particular on the EU-US Data Privacy Framework and, where necessary, the EU Standard Contractual Clauses.
The connection between your browser and this website is encrypted using TLS.
3. Server logs
When you access the website, server logs may process the IP address, date and time, requested resource, referrer, browser type, and operating system. This processing supports error analysis, stability, and IT security and is based on Article 6(1)(f) GDPR. Logs held by the hosting provider are generally deleted after seven days unless longer retention is required to investigate a security incident.
4. Audience measurement with Umami
This website uses a self-hosted Umami instance at analytics.merkaio.com. The data collected includes page views, referrers, approximate country of origin, and browser, operating-system, and device type. Umami does not use cookies or track users across websites. To recognize a session, a non-reversible session value is generated from the IP address, user agent, and website ID; the IP address itself is not stored. The processing is based on Article 6(1)(f) GDPR. My legitimate interest is the privacy-friendly analysis and improvement of this website.
5. Cookies and local storage
The website itself does not set tracking or advertising cookies. Technically necessary storage access may occur through the booking application after you deliberately open the appointment scheduler. The legal basis is Section 25(2)(2) TDDDG where access is strictly necessary to provide the appointment-booking service you explicitly requested.
6. Appointment booking
Appointment booking is provided through a self-hosted Cal.com instance at schedule.merkaio.com. The required content is loaded only when you open the triage page or activate a booking button. This initially processes technically necessary connection data such as your IP address, access time, and browser information. If you book an appointment, your entries—particularly your name, email address, time zone, and any message—are also processed to arrange the appointment. The legal basis for booking is Article 6(1)(b) GDPR; Article 6(1)(f) GDPR additionally applies to the secure provision of the application.
7. Contacting me
If you contact me by email, I process the information you provide to handle your request and any follow-up questions. The legal basis is Article 6(1)(b) GDPR where pre-contractual steps are concerned, and otherwise Article 6(1)(f) GDPR. The data is not disclosed to third parties without a legal basis.
8. Retention periods
Personal data is deleted when the purpose of processing no longer applies and no statutory retention obligation or legitimate reason for continued storage remains. Depending on the type of document, retention periods of six, eight or ten years may apply under German commercial and tax law.
9. Your rights
Subject to the applicable statutory requirements, you have the right to access, rectification, erasure, restriction of processing, and data portability. You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. You may withdraw any consent at any time with effect for the future. To exercise your rights, send a message to [email protected].
10. Right to lodge a complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The competent authority in North Rhine-Westphalia is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
Last updated: September 2026