Privacy Policy
pursuant to Art. 13, 14 GDPR, §§ 25 ff. TTDSG, Art. 52 ff. EU AI Act
01Controller pursuant to GDPR
VALENTYR Group GmbH
Ringstraße 1
31319 Sehnde, Germany
Email: info@valentyr.group
Website: www.valentyr.group
Authorized Managing Director: Jessica Michalke
02General Data Processing
We process personal data in compliance with applicable data protection regulations, in particular the GDPR, BDSG, TTDSG and – where applicable – the EU AI Act.
Processing Principles (Art. 5 GDPR):
- Purpose limitation
- Data minimization
- Storage limitation
- Integrity & Confidentiality
- Transparency
- Accountability
Legal Bases pursuant to Art. 6 GDPR:
- lit. a – Consent
- lit. b – Contract or pre-contractual measures
- lit. c – Legal obligation
- lit. f – Legitimate interest
03Hosting
Our website is hosted by:
united-domains AG
Gautinger Straße 10, 82319 Starnberg, Germany
Processing on behalf pursuant to Art. 28 GDPR – Server location: Germany / EU
Data Collected:
- IP address
- Date/time of access
- URL & Referrer URL
- Browser type & version
- Operating system
Legal basis: Art. 6 para. 1 lit. f GDPR
04Cookies & Tracking
When visiting our website, we use cookies and similar technologies. Your consent is obtained transparently through a compliant Consent Management Platform (CMP).
| Category | Description | Legal Basis |
|---|---|---|
| Technically necessary | Ensuring functionality | Art. 6 para. 1 lit. f GDPR |
| Statistics/Analysis | Reach measurement, optimization | Art. 6 para. 1 lit. a GDPR |
| Marketing | Advertising, retargeting | Art. 6 para. 1 lit. a GDPR |
05Google Analytics
This website uses Google Analytics 4 by Google Ireland Limited.
- IP address (truncated)
- User behavior (page views, clicks)
- Device/browser data
- Language, location (approximate)
Legal basis: Art. 6 para. 1 lit. a GDPR
Storage duration: 14 months
06Calendly (Appointment Booking)
For booking appointments, we use Calendly LLC, Atlanta, USA.
- Name
- Appointment time
- Message text (if applicable)
Legal basis: Art. 6 para. 1 lit. b GDPR
07AI Components / AI Act
Where we use AI-powered modules, this is not based on high-risk systems pursuant to Art. 6-9 AI Act.
- Use of transparent, traceable AI
- No automated decisions with legal effect
- No profiling within the meaning of Art. 22 GDPR
08Your Rights (Art. 12-23 GDPR)
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21)
- Withdrawal of consent (Art. 7 para. 3)
- Complaint to supervisory authority (Art. 77)
Competent Supervisory Authority:
State Commissioner for Data Protection Lower Saxony
Prinzenstraße 5, 30159 Hanover
09Data Security
We implement technical and organizational measures (TOMs) pursuant to Art. 32 GDPR:
- SSL/TLS encryption
- Access restrictions
- Logging
- Data processing agreements
- Regular training
10Retention and Deletion
| Data Type | Retention Period |
|---|---|
| Contact inquiries | 6 months after completion |
| Booking data | 1 year after appointment |
| Newsletter subscription | until withdrawal |
| Server logs | 7 days |

