Legal

Privacy Policy

Last updated: March 2026

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Norbert Steinhauser
Vallenstone LLC
E-Mail: norbert@vallenstone.de

If you have any questions about data protection on this website, please contact us at the address above.

2. Hosting

This website is hosted by Netlify. When you visit our website, Netlify automatically records server log data, which may include:

  • Your IP address
  • Browser type and version
  • Operating system
  • Referring URL
  • Date and time of access
  • Pages accessed

This processing is based on our legitimate interest in the technically secure and stable operation of the website (Art. 6(1)(f) GDPR). This data is not merged with other data sources and is deleted after a short retention period set by Netlify.

Netlify, Inc.

512 2nd Street, Suite 200, San Francisco, CA 94107, USA
Privacy policy: netlify.com/privacy
Data transfer basis: EU Standard Contractual Clauses (SCC)

3. Contact Form and Website Analytics (HubSpot)

This website uses HubSpot for two purposes: (a) to process submissions from the contact form, and (b) to collect aggregated website analytics via a tracking script loaded on every page.

Contact form: If you contact us via the form on this website, the information you provide — including your name, email address, type of request, and message — will be transmitted to and processed by HubSpot and stored in our HubSpot CRM. We process this data for the purpose of responding to your inquiry. The legal basis is Art. 6(1)(b) GDPR (processing necessary for the performance of a contract or to take steps prior to entering into a contract) or, where no contractual relationship exists, Art. 6(1)(f) GDPR (legitimate interest in handling correspondence). The contact form works without cookie consent: it does not set tracking cookies and loads from a different endpoint (hsforms.net) than the analytics script. The form provider's CDN (Cloudflare) may set a session cookie (_cfuvid) for bot protection; this is a technically necessary cookie and does not require consent.

Website analytics: HubSpot also provides an analytics script that sets cookies (including __hstc, hubspotutk, and __hssc) to help us understand how visitors use our website in aggregate — e.g. which pages are visited, referral sources, and session duration. This script is not loaded until you give your consent via the cookie banner. The legal basis is Art. 6(1)(a) GDPR (consent), which you may withdraw at any time via the "Cookie settings" link in the footer.

Your data will be retained only for as long as necessary to process your inquiry and any follow-up, or as required by applicable retention obligations.

HubSpot, Inc.

2 Canal Park, Cambridge, MA 02141, USA
EU representative: HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, D01 K2C5, Ireland
Privacy policy: legal.hubspot.com/privacy-policy
Data transfer basis: EU Standard Contractual Clauses (SCC) and EU-U.S. Data Privacy Framework (DPF)

4. Google Analytics 4

This website uses Google Analytics 4 (Measurement ID G-GVD65LPG7E), a web analytics service provided by Google Ireland Limited. Google Analytics uses cookies (including _ga and _ga_GVD65LPG7E) to distinguish users and sessions and to collect aggregated statistics about how visitors use this site — for example, which pages are viewed, for how long, and from which referral sources. IP addresses are anonymised before processing.

The analytics script is not loaded and no cookies are set until you give your consent via the cookie banner. The legal basis is Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time via the "Cookie settings" link in the footer; after withdrawal the existing analytics cookies are deleted automatically and the script is no longer loaded on subsequent page views.

Google may transfer the collected data to servers in the United States. The transfer is based on EU Standard Contractual Clauses (SCC) and Google's certification under the EU-U.S. Data Privacy Framework (DPF). Default GA4 data retention is set to the shortest period offered (2 months for event data).

Google Ireland Limited

Gordon House, Barrow Street, Dublin 4, Ireland
Parent: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Privacy policy: policies.google.com/privacy
Data transfer basis: EU Standard Contractual Clauses (SCC) and EU-U.S. Data Privacy Framework (DPF)

6. Newsletter Subscription

This website offers a newsletter signup form on multiple pages. If you subscribe, your email address is transmitted to and stored by HubSpot (see section 3 above for provider details). We use your email address solely to send you occasional updates about new content, book news, and strategy insights.

The legal basis is Art. 6(1)(a) GDPR (consent). You provide your consent by filling out the subscription form and confirming via double opt-in email. You can withdraw your consent at any time by clicking the unsubscribe link included in every email, or by contacting us at norbert@vallenstone.de. After withdrawal your email address will be removed from the mailing list.

7. Google Fonts

This website uses Google Fonts, a web font service provided by Google LLC. When you load a page on this site, your browser establishes a direct connection to Google's servers to download the fonts. In doing so, Google receives your IP address and information about which page you visited on our site.

The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in the uniform and attractive display of the website). We have no influence over what Google does with the data collected in this way.

Google LLC

1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Privacy policy: policies.google.com/privacy
Data transfer basis: EU Standard Contractual Clauses (SCC) / EU-U.S. Data Privacy Framework

8. Your Rights

Under the GDPR, you have the following rights with respect to your personal data:

  • Right of access (Art. 15 GDPR): You have the right to obtain confirmation as to whether personal data concerning you is being processed, and if so, to access that data.
  • Right to rectification (Art. 16 GDPR): You have the right to have inaccurate personal data rectified without undue delay.
  • Right to erasure (Art. 17 GDPR): You have the right to have your personal data erased under certain circumstances.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of processing of your personal data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21 GDPR): You have the right to object to the processing of your personal data on grounds relating to your particular situation, insofar as the processing is based on our legitimate interests.

To exercise any of these rights, please contact us at norbert@vallenstone.de.

9. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data by us. The supervisory authority in Germany competent for us is:

The Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Husarenstraße 30, 53117 Bonn, Germany
www.bfdi.bund.de

Alternatively, you may contact the data protection authority of your country of residence.

10. Changes to This Policy

We reserve the right to update this privacy policy to reflect changes in our website, legal requirements, or data processing practices. The current version is always available at this URL. We recommend checking this page periodically.