Back to homepage

    Privacy Policy

    1. Data Controller

    The data controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:

    Dr. Thomas Knoop

    Markobrunner Str. 20

    14197 Berlin

    E-Mail: [email protected]

    Tel. 030 / 84183204

    2. General Information on Data Processing

    The protection of your personal data is important to us. In this privacy policy, we inform you about which personal data we process in connection with the use of our website and our services.

    Personal data is only collected when you voluntarily provide it, e.g. when contacting us by email or via Calendly. Processing is carried out exclusively on the basis of legal provisions (GDPR, BDSG, TTDSG).

    3. Hosting

    This website is hosted via Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Personal data collected on this website is stored on the host's servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data and other data generated via a website.

    External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of secure, fast and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR).

    Cloudflare is certified under the EU-US Data Privacy Framework (DPF), ensuring an adequate level of data protection for data transfers to the USA. In addition, we have entered into a Data Processing Agreement (DPA) with Cloudflare. For more information, see Cloudflare's privacy policy.

    4. Server Log Files

    The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

    • Browser type and version
    • Operating system used
    • Referrer URL
    • Hostname of the accessing computer
    • Time of the server request
    • IP address

    This data is not merged with other data sources. Collection is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of their website – server log files must be collected for this purpose.

    Server log files are deleted after a maximum of 7 days for security and operational reasons.

    5. Contact

    If you contact us by email, your details including the contact data you provide will be stored for the purpose of processing the request and in case of follow-up questions. We will not share this data without your consent.

    This data is processed on the basis of Art. 6(1)(b) GDPR if your request is related to the performance of a contract or pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR).

    The data you send us via contact requests will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions – in particular retention periods – remain unaffected.

    6. Appointment Booking via Calendly

    We use Calendly, provided by Calendly LLC, 3423 Piedmont Road NE, Atlanta, GA 30305, USA, for scheduling appointments. When you book an appointment via our website, the data you enter (e.g. name, email address, desired appointment) is transmitted to and processed by Calendly.

    The use of Calendly is based on Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in efficient scheduling). Calendly LLC is certified under the EU-US Data Privacy Framework (DPF), ensuring an adequate level of data protection for transfers to the USA; in addition, Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR apply. For more information, see Calendly's privacy policy.

    7. LinkedIn

    Our website links to our LinkedIn profile. When you click the link, you will be redirected to the website of LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland). Data is only transmitted to LinkedIn when you click the link. For more information, see LinkedIn's privacy policy.

    7a. YouTube Videos

    Some pages embed videos via YouTube in privacy-enhanced mode (www.youtube-nocookie.com). Provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you play a video, a connection to YouTube's servers may be established. In privacy-enhanced mode, no personal information is initially transmitted to YouTube unless you are simultaneously logged in to your Google account.

    Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an attractive presentation of our online offering). For more information, see Google privacy policy.

    7b. ProvenExpert (Ratings)

    On our website we display the aggregate rating (star value, number of reviews) from our ProvenExpert profile, operated by Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin, Germany. The rating is fetched server-to-server via the official ProvenExpert API by our backend (no third-party requests are triggered from your browser). The retrieved data contains no personal information about visitors and is cached on our backend for up to 24 hours. No cookies are set, no IP addresses are transmitted, and no tracking takes place when the rating is displayed.

    Only when you actively click on the ProvenExpert link or one of the linked individual reviews are you redirected to provenexpert.com, where the privacy policy of Expert Systems AG applies. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in transparent display of trust signals). For more information, see ProvenExpert privacy policy.

    7c. Backend Infrastructure

    For server-side functions (e.g. caching the ProvenExpert rating) we use a managed backend by Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992, with EU data centers (Frankfurt, Germany). Only non-personal data such as the cached aggregate rating is stored. No personal data of visitors is collected, transmitted or stored via this backend. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient and reliable provision of our services).

    8. Web Analytics (Umami)

    This website uses Umami, a privacy-friendly web analytics service by Umami Software, Inc. (US), delivered via Umami Cloud with EU servers (Dublin, Ireland). Umami only collects anonymized usage data such as page views, time on page, referrers and device types. No cookies are set, no IP addresses are stored and no browser fingerprinting is performed. Identifying individual users is not possible. Insofar as data is processed by the US parent company, this is based on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.

    Usage is based on our legitimate interest in statistical analysis of website usage to optimize our services (Art. 6(1)(f) GDPR). For more information, see Umami's privacy policy.

    9. Cookies

    This website does not use tracking cookies. The analytics tool Umami operates entirely without cookies. Only technically necessary data required for the operation of the website is processed.

    10. SSL/TLS Encryption

    This site uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the browser address bar changing from "http://" to "https://" and the lock icon in your browser bar.

    When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.

    11. Your Rights as a Data Subject

    You have the following rights regarding your personal data:

    • Right of access (Art. 15 GDPR)
    • Right to rectification (Art. 16 GDPR)
    • Right to erasure (Art. 17 GDPR)
    • Right to restriction of processing (Art. 18 GDPR)
    • Right to data portability (Art. 20 GDPR)
    • Right to object (Art. 21 GDPR)
    • Right to withdraw consent (Art. 7(3) GDPR)

    You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is:

    Berlin Commissioner for Data Protection and Freedom of Information
    Friedrichstr. 219
    10969 Berlin
    www.datenschutz-berlin.de

    12a. Accessibility (BFSG/EAA)

    This website is designed in accordance with the German Act on Strengthening Accessibility (BFSG) and the European Accessibility Act (EAA). As a microenterprise within the meaning of Section 3 BFSG, we are exempt from the obligation to provide an accessibility statement; we nevertheless strive to make the offering as accessible as possible in accordance with WCAG 2.1 Level AA criteria.

    12. Currency and Changes to this Privacy Policy

    This privacy policy is currently valid as of November 2026. Due to the further development of our website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy.

    Leadership impulses

    Occasionally a short thought on a current leadership question. One impulse whenever a new insight appears.

    Subscribe to the newsletter