This is a courtesy translation. In case of doubt, the German version applies.
1. Controller
Markus Geretshauser & Partner
An der Felsplatte 1
93333 Neustadt an der Donau, OT Bad Gögging
Deutschland
E-Mail: info@markus-geretshauser.de
Telefon: +49 9445 205160
2. Your rights
You have the right to obtain information about the origin, recipients and purpose of your stored personal data free of charge at any time (Art. 15 GDPR). You also have the right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR). Consent once given can be withdrawn at any time with effect for the future. You have the right to lodge a complaint with a supervisory authority.
3. Hosting
This website is hosted by an external service provider:
ALL-INKL.COM – Neue Medien Münnich, Inhaber René Münnich, Hauptstraße 68, 02742 Friedersdorf, Deutschland
The provider processes the data collected via this website on our behalf, in particular server log files. The legal basis is our legitimate interest in the secure and efficient provision of our website (Art. 6 (1) (f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place.
4. Server log files
When you access this website, your browser automatically transmits browser type and version, operating system, referrer URL, hostname, time of the request and IP address. This data is not merged with other sources and is deleted after seven days at the latest. Legal basis: Art. 6 (1) (f) GDPR.
5. Cookies and consent
We use the Complianz software to manage your consent. It runs entirely on our own server; no data is transmitted to its maker.
Before you give consent, no third-party content is loaded and no cookies are set beyond those that are technically necessary.
Once you make a choice in the notice, the following cookies are stored on your device: cmplz_banner-status, cmplz_consented_services, cmplz_policy_id, cmplz_functional, cmplz_preferences, cmplz_statistics and cmplz_marketing. They hold nothing but your choice and no identifier that would allow you to be recognised. Storage period is 365 days. This website additionally stores your decision about the Spotify player in the cookie sadsyn_consent, with the same lifetime.
The legal basis for storing your consent decision is § 25 (2) no. 2 TDDDG, as it is strictly necessary to provide the service you explicitly requested. External content is loaded on the basis of your consent under § 25 (1) TDDDG and Art. 6 (1) (a) GDPR.
You can change or withdraw your decision at any time via the “Cookie settings” link in the footer. An overview of the cookies in use can be found in our cookie policy.
6. Spotify player
A player from the music service Spotify is embedded on this website. Provider: Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden.
The player does not load automatically. It is only activated after you explicitly click it. Until you consent, no connection to Spotify is established and no data is transmitted.
If you load the player, a connection to Spotify servers is established. Spotify learns your IP address and the page you are on, and may process further data such as browser and device information. If you are logged into your Spotify account at the same time, Spotify can associate the visit with your account. Transfer to third countries cannot be excluded. Legal basis: your consent under Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG, revocable at any time.
7. Fonts
This website uses the typefaces Archivo, Archivo Black, Inter, Bebas Neue, Rajdhani and Barlow. They are served exclusively from our own server. There is no connection to Google Fonts or any other external font provider, and no data is transmitted to third parties when the fonts load.
8. Links to social networks
This website links to our profiles on Instagram, TikTok, YouTube, X and Facebook. These are plain text links, not embedded content or social plugins. Simply visiting our site transmits no data to these providers. Only when you click a link do you leave our website, at which point the respective provider’s privacy policy applies.
9. Comments
If you leave a comment, the comment, the time of creation, the name and email address you provide and your IP address are stored. Legal basis: Art. 6 (1) (a) GDPR. The data remains with us until the comment is deleted or you request its deletion.
Every incoming comment additionally passes through the spam check described in section 12.
10. Contact
If you contact us by email, your details are stored in order to process the enquiry and for any follow-up questions. Legal basis: Art. 6 (1) (f) or (b) GDPR. The data is deleted once it is no longer required and no statutory retention periods apply.
For enquiries sent through the contact form we use Contact Form 7 (provider: Takayuki Miyoshi). The details you enter – name, email address and your message – are forwarded by email to our own mailbox and are not additionally stored within the website. No transfer to third parties takes place. The legal basis is your consent under Art. 6(1)(a) GDPR, which you give by submitting the form and may withdraw at any time with effect for the future.
11. SSL / TLS encryption
For security reasons this website uses SSL/TLS encryption, recognisable by “https://” in the address bar.
12. Security and spam protection
To protect this website against attacks we use the web application firewall NinjaFirewall (WP Edition) (provider: The Ninja Technologies Network). The firewall inspects every request to this website before it is processed. In doing so it evaluates your IP address, the requested path, the user agent string sent by your browser, and the time and type of the request. Suspicious events – such as repeated failed login attempts or recognisable attack patterns – are recorded in a log on our own server and deleted after 30 days at the latest. No data is transmitted to the plugin provider or any other third party.
To prevent comment and trackback spam we use Antispam Bee (provider: pluginkollektiv). The plugin assesses incoming comments based on features such as the comment text, timing behaviour, language and IP address. The check runs exclusively on our own server; no external spam databases are queried in our configuration. Comments classified as spam are filtered out automatically and deleted after 14 days at the latest.
The legal basis for both measures is our legitimate interest in the secure and undisturbed operation of this website (Art. 6 (1) (f) GDPR).
In addition, the files of this website are checked regularly with NinjaScanner (provider: The Ninja Technologies Network) for unexpected changes and malicious code. The comparison runs entirely on our own server. No visitor data is processed in the process and no data is transmitted to third parties.
Forms on this website are additionally protected by WP Armour – Honeypot Anti Spam (provider: Dnesscarkey). The plugin adds a field to every form that is invisible to you. If this field is filled in – which only automated programs do – the submission is discarded. No cookies are set and no personal data is transmitted to third parties.
13. Performance and caching
To speed up page delivery we use the plugins WP-Optimize and Autoptimize. WP-Optimize stores pre-rendered copies of our pages as files on our own server; Autoptimize combines stylesheets and scripts into fewer files. These files contain no personal data and nothing is transmitted to the plugin authors. The legal basis is our legitimate interest in a fast and reliable website (Art. 6 (1) (f) GDPR).
We also use Rank Math SEO to generate meta tags and the sitemap — its analytics module is deliberately switched off, so no Google code is loaded — and Easy Updates Manager to control updates, which we install manually only. Neither processes personal data of visitors nor transmits data to its authors.
14. AI assistants
ChatGPT
We use ChatGPT for customer communication and content creation. The provider is OpenAI, 3180 18th St, San Francisco, CA 94110, USA.
If you start a conversation with us via our website and ChatGPT is activated, your input including metadata is transferred to OpenAI servers and processed there in order to generate a suitable response. Personal data is transferred to the USA in this process. We have configured ChatGPT so that the personal data entered is not used to train the algorithm.
Use is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in efficient customer communication using modern technical solutions. Where consent has been requested, processing is based solely on Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. Consent may be withdrawn at any time. Further information: openai.com/policies/privacy-policy.
Claude
We use Claude for customer communication and content creation. The provider is Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA.
If you start a conversation with us via our website and Claude is activated, your input including metadata is transferred to Anthropic servers and processed there in order to generate a suitable response. Personal data is transferred to the USA in this process. We have configured Claude so that the personal data entered is not used to train Anthropic models.
Use of Claude is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in efficient customer communication using modern technical solutions. Where consent has been requested, processing is based solely on Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. Consent may be withdrawn at any time. Further information: anthropic.com/legal/privacy.
This privacy policy was created by Freyberg Consulting (Felix Freyberg) for Markus Geretshauser & Partner (Markus Geretshauser) to the best of their knowledge and belief.
Freyberg Consulting (Felix Freyberg) has granted Markus Geretshauser & Partner unrestricted use and distribution of this policy. It was also adapted for Saddle & Synth (Markus Geretshauser) and released for single use on saddleandsynth.com.