Legal
Privacy Policy
This policy explains, pursuant to Art. 12 to 14 GDPR, which personal data we process, for what purpose, on what legal basis, for how long we store it, and what rights you have.
18 August 2026
Controller and contact details
The controller within the meaning of Art. 4 no. 7 GDPR is Christian M. Irmler, sole proprietor (autónomo, Spain), trading under the name ZELLGIPFEL, Calle del Bisbe Jaume 10, 07015 Palma, Baleares, Spain. Tax number/NIF: ESY3735632D.
Contact: hello@zellgipfel.com, phone +34 641 20 88 33. For privacy-related matters and to withdraw consent: privacy@zellgipfel.com.
This policy applies to the website zellgipfel.de, including all subpages, and to the communication that takes place via the contact channels offered there.
Data protection officer
No data protection officer has been appointed. The requirements for a mandatory appointment under Art. 37(1) GDPR are not met: there is no large-scale regular and systematic monitoring of data subjects and no large-scale processing of special categories of personal data under Art. 9 GDPR.
Please direct all privacy-related enquiries to privacy@zellgipfel.com. We will respond within the period set out in Art. 12(3) GDPR, generally within one month.
Principles, legal bases and definitions
We process personal data only to the extent necessary to provide a functioning website, to handle your enquiry, or on the basis of your consent. In doing so, we comply with the principles of data minimisation, purpose limitation, storage limitation, accuracy, and integrity and confidentiality under Art. 5 GDPR.
Depending on the processing activity, the legal bases are: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract and pre-contractual measures), Art. 6(1)(c) GDPR (legal obligation, e.g. commercial and tax retention periods) and Art. 6(1)(f) GDPR (legitimate interests, in particular secure operation, abuse prevention and communication).
Storing information on your device and reading information already stored there are additionally governed by § 25 TDDDG (German Telecommunications-Digital-Services-Data-Protection Act); beyond technically necessary operations, this takes place only with your consent.
We do not collect special categories of personal data under Art. 9 GDPR — in particular health data — via this website. Please do not enter information about illnesses, diagnoses or medication in free-text fields. If you voluntarily provide such information, we will process it solely on the basis of your explicit consent under Art. 9(2)(a) GDPR in order to answer your enquiry.
Recipients, processors and third-country transfers
We only disclose personal data to recipients required to operate the website and handle your enquiry. Categories of recipients are: hosting and infrastructure providers, database and backend service providers, providers used to prevent spam and abuse, email delivery service providers, and — where legally required — authorities, tax advisers and legal advisers.
We have data processing agreements under Art. 28 GDPR with all service providers who process data on our behalf. Processing takes place only on our instructions and with appropriate technical and organisational measures.
Transfers to third countries outside the EEA take place only where one of the safeguards under Art. 44 et seq. GDPR applies: an adequacy decision by the European Commission (such as the EU-U.S. Data Privacy Framework for certified companies) or the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, supplemented by additional safeguards such as transport encryption and data minimisation.
We do not sell data. We do not pass on data to third parties for advertising purposes.
Hosting, delivery and server log files
This website is operated on a managed cloud platform and delivered via a content delivery network that routes requests to the nearest location. Delivery and storage of website data preferentially take place via data centres in the European Union; data processing agreements under Art. 28 GDPR are in place with the providers.
When you access the site, server log files are automatically processed: the IP address of the requesting device, the date and time of access, the resource accessed and the amount of data transferred, the HTTP status code, the referrer URL, and the browser type, operating system and language (user agent).
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional operation of the website and in detecting and defending against attacks. Log data is deleted after 30 days at the latest, unless it is needed for longer to investigate a specific security incident.
Transmission is consistently encrypted in transit via TLS (recognisable by https in the address bar).
Contact and lead form
Through the form we process the data you provide: name, email address, optionally phone number, chosen mode of use (private individual or institution), and — for institutions — the name and type of institution, location and time horizon, selected focus topics, your preferred method of contact, and your message.
For technical purposes we additionally process a salted hash of your IP address, the user agent, the time of submission, and — where present — campaign parameters of the requested URL (UTM parameters) and referrer information.
The purposes are handling your enquiry, preparing and conducting a free initial consultation, preventing spam and automated submissions, and documenting consents given.
The legal bases are Art. 6(1)(b) GDPR for pre-contractual measures and handling your enquiry, Art. 6(1)(a) GDPR for voluntary additional information and the consent given, and Art. 6(1)(f) GDPR for abuse prevention and documentation.
Mandatory fields are only those without which we could not call or write back to you; they are marked in the form. Without this information, the enquiry cannot be processed. All other information is voluntary.
Retention period: we delete form data 24 months after the last contact, unless statutory retention obligations (in particular commercial and tax law periods of six or ten years) prevent this, or the data is still required to assert, exercise or defend legal claims. We retain evidence of consents given for the duration of the applicable limitation periods.
Contact by email and phone
If you contact us by email or phone, we process your contact details and the content of your message to handle the matter. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract or its initiation, and otherwise Art. 6(1)(f) GDPR based on our interest in responding to enquiries effectively.
Please note that unencrypted emails could be intercepted by third parties in transit. For confidential matters, we recommend contacting us by phone or using a secure transmission method.
We delete correspondence once the matter has been fully resolved and no retention obligations apply.
Spam prevention (Cloudflare Turnstile)
To prevent automated abuse of our forms, we use Cloudflare Turnstile whenever this feature is enabled. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, and its European establishment.
This processes technical characteristics of your browser and device as well as your IP address in order to distinguish human from automated access. According to the provider, Turnstile does not track users or evaluate personal profiles.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting our forms against spam and abuse. For processing in the USA, the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR apply. Further information: cloudflare.com/privacypolicy.
Database and backend
Form data is stored in a managed PostgreSQL database operated by our backend service provider; the server region chosen is the European Union (Frankfurt am Main, eu-central-1). Operation takes place under a data processing agreement pursuant to Art. 28 GDPR.
Access to the data is restricted by database-level access rules, encrypted connections and a permissions concept. Write access from the form takes place exclusively via a server-side function; there is no direct read access from the browser.
The legal basis is Art. 6(1)(b) and (f) GDPR.
Email delivery and notifications
For notification and confirmation emails relating to your enquiry, we use an email delivery service provider under a data processing agreement pursuant to Art. 28 GDPR. This processes the email address, the content of the message, and technical delivery information.
The legal basis is Art. 6(1)(b) GDPR, and otherwise Art. 6(1)(f) GDPR based on our interest in reliable delivery. Any third-country transfer takes place only on the basis of the EU Standard Contractual Clauses or an adequacy decision.
We do not currently send a promotional newsletter. Should a newsletter be offered in future, it will be sent only after explicit consent via a double opt-in process with the option to unsubscribe at any time.
Cookies and similar technologies
We distinguish between the categories Necessary, Statistics and Marketing. Necessary technologies are strictly required to operate the website, store your choices and protect the forms; under § 25(2) no. 2 TDDDG they do not require consent, and any subsequent processing is based on Art. 6(1)(f) GDPR.
We use Statistics and Marketing technologies only with your consent under § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. No such technologies are loaded without consent.
We store your decision locally in your browser's local storage under the key zg_consent_v1, together with a timestamp and version, for six months; after that we ask again. This is not technically a cookie, but functionally comparable.
You can change or fully withdraw your choice at any time, with effect for the future, via the “Cookie settings” link in the footer. Clearing your browser data also resets your choice.
Web analytics and reach measurement
If web analytics are used, we prefer a cookie-free solution hosted in the EU that truncates or anonymises the IP address and does not enable cross-device recognition. The purpose is to measure reach and improve content and user guidance.
Only aggregated metrics are collected, such as pages viewed, time spent, approximate region of origin, device category and referrer. Data is not combined with form data, and no profiling takes place.
Specifically, we use the analytics service Metricool (Metricool Software SL, Calle Serrano 240, 28016 Madrid, Spain). Once you have given consent, a script is loaded from tracker.metricool.com. It processes your IP address (shortened or used only to derive an approximate region), date and time, the URL requested, the referrer, and browser and device information. The service may set cookies or comparable identifiers in your browser for this purpose. Servers are located in the EU, and the cooperation is governed by a data processing agreement under Art. 28 GDPR.
The purpose is reach and campaign measurement and improving our content. Metricool acts solely on our instructions as a processor; the data is not passed on to third parties for their own purposes, not sold, and not combined with form or customer data. Any third-country transfer takes place only on the basis of the EU standard contractual clauses.
Retention: cookies or identifiers set by Metricool have a lifetime of up to 12 months; aggregated statistics are kept for up to 24 months and then deleted or anonymised. You can withdraw your consent at any time via “Cookie settings” in the footer: the script is then removed immediately and the associated cookies and storage entries are deleted.
Execution only takes place after you have given consent to the Statistics category (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Until then, events are held locally and discarded without consent. Google Analytics or comparable US services are not used without prior separate consent.
Self-hosted fonts and media
The fonts used are delivered from our own server. When you visit the website, no connection is established to Google Fonts servers, and no data is transmitted to Google.
Images, icons and other media are likewise delivered from our own offering. We do not use embedded third-party content such as video platforms, maps or social media plug-ins. The only exception is the analytics script described in section 12, which is loaded solely after your consent.
Data security
We take technical and organisational measures under Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. These include TLS encryption in transit, encryption of data at rest at the service provider, restrictive access rights, separation of read and write paths, logging, and regular updates of the software used.
Our measures are continuously reviewed and adapted in line with technical developments.
Your rights as a data subject
You have the right to obtain information about the data processed about you (Art. 15 GDPR), to rectify inaccurate data (Art. 16 GDPR), to erasure (Art. 17 GDPR), to restrict processing (Art. 18 GDPR), and to data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR).
Right to object under Art. 21 GDPR: for reasons arising from your particular situation, you have the right to object at any time to the processing of data concerning you carried out on the basis of Art. 6(1)(f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. Where data is processed for direct marketing purposes, you may object at any time without giving reasons.
You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out prior to withdrawal remains unaffected. An informal message to privacy@zellgipfel.com is sufficient to exercise your rights or withdraw consent. To prevent misuse, we may request additional information to verify your identity where there are reasonable doubts (Art. 12(6) GDPR).
Right to lodge a complaint under Art. 77 GDPR: you may lodge a complaint with a data protection supervisory authority. The authority competent at the controller's place of establishment is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain, www.aepd.es. Independently of this, you may also contact the supervisory authority of your habitual residence or place of work — in Germany, for example, the data protection authority responsible for your federal state.
No automated decision-making
No decision-making based solely on automated processing, including profiling, takes place under Art. 22 GDPR. Enquiries are reviewed and answered exclusively by humans.
Protection of minors
Our offering is aimed at adults as well as professionals and institutions. Persons under the age of 16 should not transmit any personal data to us without the consent of a parent or legal guardian. If we become aware that we have inadvertently received such data, we will delete it without delay.
Currency and amendment of this policy
This privacy policy is dated 18 August 2026. Further development of our website and offering, or changes to statutory or regulatory requirements, may make an update necessary.
The current version can always be accessed on this page. Unless otherwise required by law, the version in force at the time of collection applies to ongoing processing activities.
This policy is maintained on an ongoing basis and does not constitute legal advice.