Privacy Policy
Collection and processing of personal data
1. General information
This privacy policy explains which personal data is processed when you visit and use this website. Personal data means any data that can be used to identify you personally or that relates to an identifiable person.
This privacy policy applies to the website alexbellon.com.
2. Controller
The controller for data processing on this website is:
Alexander Bellon
Galgenbergstraße 15
93053 Regensburg, Germany
Email: kontakt@alexbellon.de
3. Hosting and provision of the website
This website is hosted by Hetzner Online GmbH. The servers are located in Germany. When you access this website, technically necessary data is processed so that the website can be delivered correctly and operated securely. This may include the following data in particular:
- page or file requested
- date and time of access
- volume of data transferred
- referrer URL
- IP address
This data is processed in order to provide the website technically, to ensure the stability and security of its operation and to be able to trace possible technical faults or attacks.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in providing the website securely, stably and free of technical faults. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
4. Email infrastructure
Emails to kontakt@alexbellon.de are processed via the mail servers of Hetzner. In addition, Mailchimp and Mailchimp Transactional are used for newsletters and certain transactional emails. You will find more information on this in the relevant sections of this privacy policy.
5. SSL/TLS encryption
For security reasons this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser begins with “https://”, among other things. Encryption means that data you transmit via this website cannot readily be read by third parties.
6. Cookies and comparable technologies
This website uses cookies. Cookies are small text files stored on your device. They may be technically necessary in order to provide certain functions of the website, or they may be used for analytics and marketing purposes.
The following cookie categories are currently used on this website:
- Necessary: cookies required for basic functions of the website.
- Analytics: cookies or settings used to analyse how the website is used.
- Marketing: cookies or settings used to measure and optimise marketing activities.
You can set your cookie preferences via the cookie banner. There you can enable or disable analytics and marketing. Cookie preferences can be changed at any time via a link in this privacy policy.
This website uses technically necessary and functional cookies. These include in particular cookies storing the selected light or dark appearance of the website (“light” and “dark”, each with a lifetime of 12 months) and a cookie storing your cookie choice (“cookie_consent”, lifetime 12 months).
In addition, cookies or comparable settings may be used in connection with analytics and marketing. The cookie “analytics_optout” records that analytics has been disabled or should be blocked. Its lifetime is 1 month. The cookie “marketing_optout” records that marketing services have been disabled or should be blocked. Its lifetime is 1 month.
When you open the checkout page, an additional session cookie (“PHPSESSID”) is set. It is used to associate the order process and to protect against form abuse, contains no personal content and is deleted when you close your browser. Stripe may set its own cookies on the checkout page for fraud detection; further details can be found in the section on Stripe. Both are technically necessary in order to provide the payment function you have expressly requested.
Information is stored on your device and accessed in accordance with section 25 TDDDG. Where cookies are technically necessary, they are used on the basis of section 25(2) TDDDG. Where cookies or comparable technologies are not technically necessary, they are used only on the basis of your consent pursuant to section 25(1) TDDDG and Art. 6(1)(a) GDPR.
7. Contacting us through the website
This website offers the option of contacting the operator via an input form. As a rule, the following data is processed:
- first and last name
- email address
- content of the enquiry
- date and time of the enquiry
The data entered is stored in our own database. In addition, the enquiry is sent by email to the controller. Mailchimp Transactional may be used for this.
The processing serves to handle the enquiry and to communicate with the person making it. The legal basis is Art. 6(1)(b) GDPR, insofar as the enquiry relates to pre-contractual measures or a possible collaboration.
In all other cases the processing takes place on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in handling incoming enquiries efficiently. Contact enquiries are stored for a maximum of 12 months, unless statutory retention obligations or legitimate reasons require longer storage.
8. Intro call and Launchpad enquiries
On the subpages /launchpad and /call you can get in touch via an application or enquiry form. The following data in particular may be processed:
- first name
- last name
- email address
- website or social media profile
- business goals or challenges
- message
The data is stored in our own database. In addition, an automatic email notification may be sent to the controller.
The processing serves to handle the enquiry, to assess a possible collaboration and to carry out pre-contractual measures. The legal basis is Art. 6(1)(b) GDPR. Insofar as the processing is additionally necessary to organise, document and follow up on the enquiry, it takes place on the basis of Art. 6(1)(f) GDPR.
Enquiries are stored until deletion is requested, unless statutory retention obligations or legitimate reasons require further storage.
9. Newsletter / Webletter
This website offers the option of subscribing to a newsletter (called the “Webletter”). The following data is processed for this purpose:
- first name
- email address
- date and time of sign-up
Delivery takes place via Mailchimp. Sign-up uses the double opt-in procedure. This means that you must first confirm your sign-up via a confirmation link in an email. The data is stored in our own database on the Hetzner server and additionally transferred to Mailchimp in order to add you to what is known there as an “audience” or list.
The Webletter contains in particular personal newsletters, updates, offers and content on business, marketing and creator topics.
The legal basis for delivery is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw this consent at any time with effect for the future by using the unsubscribe link in every newsletter email. The data is stored until you unsubscribe from the newsletter, unless statutory retention obligations or legitimate reasons require further storage.
10. Newsletter analysis, open and click tracking
When the newsletter is sent via Mailchimp, opens and clicks can be evaluated. This makes it possible to see whether a newsletter was opened and which links were clicked. This evaluation serves to understand content better, improve it and make it more relevant.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You can unsubscribe from the newsletter at any time via the unsubscribe link in every email.
Newsletter contacts can be organised in Mailchimp using tags or segments. These tags and segments serve only the broad organisation of the newsletter and not profiling within the meaning of automated individual decision-making.
11. Downloads and lead magnets
This website offers the option of requesting downloads, free content or so-called “lead magnets”. The following data in particular may be requested in order to receive such content:
- first name
- email address
The data is stored in our own database and transferred to Mailchimp via an interface in order to add the person to the newsletter or Webletter list. The processing takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future, for example via the unsubscribe link in every email.
12. Mailchimp
Mailchimp is used to send the newsletter or Webletter. The provider is The Rocket Science Group LLC, a company of the Intuit group. When Mailchimp is used, personal data may be processed, in particular email address, first name, subscription status, opens, clicks and technical delivery data.
A data processing agreement or data processing addendum is in place with Mailchimp. Processing of data in the USA or other third countries cannot be ruled out. According to its own statements, Mailchimp uses appropriate data protection safeguards for this, in particular standard contractual clauses.
Mailchimp is used for the purpose of sending the newsletter, managing recipients, organising tags and segments and evaluating opens and clicks. The legal basis is Art. 6(1)(a) GDPR.
13. Transactional emails
Mailchimp Transactional (also referred to as “Mandrill”) may be used for transactional emails. These include, for example:
- confirmations after contact enquiries
- double opt-in emails
- technical notifications
- system emails
The processing serves the reliable delivery of such emails. The legal basis is Art. 6(1)(b) GDPR, insofar as the email is necessary to carry out pre-contractual or contractual measures. Otherwise the processing takes place on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in secure and reliable communication with users. Transactional emails are not actively logged or tracked by the controller for analysis purposes.
14. Purchases and payment processing
When you purchase digital products or services through this website, the following data is processed: first and last name, email address, billing address (street, postal code, city, country), for business customers also the company name and, where provided, the VAT identification number, optionally a telephone number, the selected payment method, the ordered items including price and tax rate, as well as the IP address and browser identification at the time of the order.
This data is required in order to perform the contract. The legal basis is Art. 6(1)(b) GDPR. The IP address and browser identification are stored so that orders remain traceable and to prevent abusive use; the legal basis for this is Art. 6(1)(f) GDPR.
No customer account is created. Only the data required for the order and for statutory retention obligations is stored.
Payment data in the narrower sense, meaning card numbers, security codes or bank access credentials, is never collected, processed or stored by the provider. Details on card payments, on PayPal and on Klarna can be found in the following sections.
If you pay by advance bank transfer, you will receive the provider’s bank details by email. You carry out the transfer through your own bank; the details arising from it, in particular your IBAN, the account holder’s name and the payment reference, become known to the provider through the bank statement issued by the provider’s bank.
An invoice is created and archived for every paid order. Invoices and the data they contain are subject to the statutory retention obligations under sections 147 AO and 257 HGB (German fiscal and commercial law) and are kept for ten years. To that extent, deletion before the end of that period is not possible.
A personal access link is generated in order to deliver purchased files. The link is limited in time and in the number of retrievals; the values that apply in each case are stated in the confirmation email. The time and IP address of the last retrieval are stored in order to detect unauthorised sharing. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in protecting the content offered.
15. Stripe
Stripe is used to process card payments. For customers in the European Economic Area, the provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. In order to provide the service, Stripe may involve further companies of the Stripe group, in particular Stripe, Inc., based in the United States.
A script provided by Stripe (js.stripe.com) is loaded on the checkout page. Your IP address is transmitted to Stripe in the process. The input fields for card details are provided by Stripe within a separate area of the page that the provider cannot access. Card numbers and security codes are therefore transmitted directly to Stripe and never reach the provider’s server. The provider only receives a response about the status of the payment, together with the card brand and the last four digits of the card used.
Stripe is also given the payment amount, the currency, the order number as well as the name, email address and billing address, insofar as these are required in order to carry out and verify the payment.
Stripe processes this data in order to carry out the payment and to detect and prevent fraud. For this purpose, Stripe may set its own cookies and evaluate information about your device. The legal basis is Art. 6(1)(b) GDPR insofar as the processing is necessary to perform the contract; for fraud prevention the legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in protection against abusive payment transactions. Loading the script and the cookies set in the process are technically necessary in order to provide the payment function you have expressly requested; to that extent, storage takes place on the basis of section 25(2)(2) TDDDG. Stripe is only loaded once you open the checkout page; no connection to Stripe is established on the other pages of this website.
In the case of card payments, confirmation by your bank may be required as part of the statutory strong customer authentication (“3-D Secure”). This authentication takes place between you and your bank; the provider only receives the result.
Stripe processes part of the data on the provider’s instructions and a further part, in particular for fraud prevention and in order to meet its own regulatory, anti-money-laundering and tax obligations, as an independent controller. For the part processed on instructions, the data processing agreement forms part of the Stripe Services Agreement; it takes effect when those terms are accepted and is not concluded separately. Insofar as data is transferred to the United States, Stripe states that it relies on appropriate safeguards, in particular standard contractual clauses and certification under the EU-U.S. Data Privacy Framework.
Further information about data processing by Stripe can be found at https://stripe.com/privacy.
16. PayPal
If PayPal is selected as the payment method, the payment is likewise processed through Stripe (see the preceding section). PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg is additionally involved.
After selecting PayPal and completing your order, you are redirected to PayPal and sign in to your PayPal account there. No PayPal script is loaded and no PayPal cookie is set on this website – signing in and confirming the payment take place exclusively on PayPal’s pages. You are then redirected back to the order completion page.
The payment amount, the currency, the order number as well as your name, email address and billing address are transmitted, insofar as they are required in order to carry out the payment. You enter your PayPal credentials exclusively at PayPal; they are never accessible to the provider.
Of the payment result, the provider stores only the transaction number issued by PayPal. It is needed in order to assign a payment to an order in the event of a query or a payment dispute. Further details made available by PayPal – in particular the email address held in the PayPal account and the name kept there – are expressly not stored.
The legal basis is Art. 6(1)(b) GDPR insofar as the processing is necessary to perform the contract. The legal basis for storing the transaction number is Art. 6(1)(f) GDPR; the legitimate interest lies in keeping payments traceable and in handling payment disputes.
PayPal additionally processes your data under its own responsibility, in particular in order to operate your PayPal account, to prevent fraud and to meet its own statutory obligations. The provider has no influence over this processing. A transfer to countries outside the European Economic Area, in particular to PayPal, Inc. in the United States, cannot be ruled out in this context.
Further information about data processing by PayPal can be found at https://www.paypal.com/us/legalhub/privacy-full.
17. Klarna
If Klarna is selected as the payment method, the payment is likewise processed through Stripe (see section 15). Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden is additionally involved.
After selecting Klarna and completing your order, you are redirected to Klarna and choose your preferred payment option there. No Klarna script is loaded and no Klarna cookie is set on this website – choosing and confirming the payment take place exclusively on Klarna’s pages. You are then redirected back to the order completion page.
The payment amount, the currency, the order number as well as your first and last name, your email address and your billing address are transmitted. These details are required because Klarna advances the purchase amount and subsequently settles it directly with you.
Klarna carries out an identity and credit assessment in this context and may obtain information from credit agencies for that purpose. The provider has no influence over the scope, conduct or outcome of that assessment; Klarna decides on it under its own responsibility. If Klarna declines the payment, the provider learns only that the payment did not come about, not the reasons for it.
The legal basis is Art. 6(1)(b) GDPR insofar as the processing is necessary to perform the contract. The legal basis for the credit assessment is Art. 6(1)(f) GDPR; the legitimate interest lies in protection against payment defaults.
Of the payment result, the provider stores no details beyond the payment method itself. In particular, the payment option chosen at Klarna and the data held there are not taken over into the provider’s systems.
Klarna additionally processes your data under its own responsibility, in particular in order to operate your Klarna account, to prevent fraud and to meet its own statutory obligations. The provider has no influence over this processing. Klarna is established within the European Economic Area.
Klarna is available to consumers only and only in certain countries. It is not offered for business orders; in that case no data whatsoever is transmitted to Klarna.
Further information about data processing by Klarna can be found at https://www.klarna.com/international/privacy-policy/.
18. Plausible Analytics
This website uses Plausible Analytics for the statistical evaluation of website usage. The provider is Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible is embedded via a script in the head of the website. The controller uses Plausible Analytics on a processor basis. The provider’s data processing agreement (DPA) has been accepted.
Plausible is designed for privacy-friendly web analytics and processes data without classic tracking cookies. IP addresses are not stored permanently in plain text but are processed in anonymised or aggregated form.
Plausible can evaluate the following information in particular:
- pages visited
- page views
- referring sources
- device and browser types used
- approximate geographic information at an aggregated level
Users can disable Plausible via the analytics setting in the cookie banner or via the analytics opt-out. The cookie “analytics_optout” is set for this purpose.
Insofar as personal data is affected, the processing takes place on the basis of Art. 6(1)(f) GDPR. The legitimate interest lies in the statistical evaluation and improvement of the website. Insofar as consent is required for individual functions, the processing takes place on the basis of Art. 6(1)(a) GDPR.
19. Marketing services and the Meta Pixel
This website uses marketing services to measure and optimise marketing activities. These include the Meta Pixel in particular. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The Meta Pixel makes it possible to trace how users interact with this website after arriving here, for example via an advert.
This allows the effectiveness of adverts to be measured, audiences to be understood better and marketing activities to be optimised. When the Meta Pixel is used, the following data in particular may be processed:
- pages visited
- click and usage behaviour
- technical device and browser information
- referrer information
- IP address
- pseudonymous identifiers
- conversion information
Meta may combine this data with further information, in particular if users are logged in to a Meta service such as Facebook or Instagram. Any further processing by Meta takes place under Meta’s own responsibility.
The Meta Pixel is only loaded on this website if you have consented to the use of marketing services. The legal basis for storing information on your device and accessing such information is section 25(1) TDDDG. The legal basis for the subsequent processing of personal data is your consent pursuant to Art. 6(1)(a) GDPR.
You can disable marketing services via the cookie banner or the cookie settings. The cookie “marketing_optout” is set for this purpose.
20. Vimeo videos
Videos from Vimeo may be embedded on this website. The provider is Vimeo.com, Inc. They are embedded using a two-click solution. This means that simply opening the page does not yet load the Vimeo video. Instead, a locally hosted preview image is shown first. Only when you click the preview image or the play symbol is the Vimeo iframe loaded and a connection to Vimeo established.
If you activate a Vimeo video, data may be transmitted to Vimeo. This may include in particular your IP address, technical device and browser information, the time of access and information about the page accessed. Vimeo may also use cookies or comparable technologies.
A Vimeo video is activated on the basis of your consent pursuant to Art. 6(1)(a) GDPR and section 25(1) TDDDG. You can decide for yourself whether you want to load the video. Vimeo is independently responsible for any further data processing after the video has been activated. You will find more information in Vimeo’s privacy notice.
21. Spam protection
To protect against spam, our own technical measures such as honeypot fields or timing checks, or external captcha services such as Google reCAPTCHA, hCaptcha or Cloudflare Turnstile, may be used. These serve to detect and reduce automated form submissions. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in protecting the website and its communication systems against spam and misuse.
22. Social media links
This website may contain links to social media profiles, in particular to:
- YouTube
- TikTok
These are ordinary links only. No social media feeds, like buttons, share buttons or embedded social media posts are loaded. If you click such a link, you leave this website. The respective providers are responsible for the processing of personal data on the linked platforms.
23. Links to other websites
This website may link to other websites. When you click external links, the privacy policy of the respective target site applies. The respective operator is responsible for content and data processing on external websites.
24. Retention periods
Personal data is only stored for as long as is necessary for the respective purpose or as long as statutory retention obligations require. Unless a more specific retention period is stated in this privacy policy, personal data is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations or legitimate interests prevent deletion.
25. Recipients of personal data
Within the scope of the processing described in this privacy policy, personal data may be transmitted to the following recipients or categories of recipients:
- Hetzner Online GmbH as hosting and email infrastructure provider
- Mailchimp for newsletter/Webletter and recipient lists
- Mailchimp Transactional for transactional emails
- Stripe Payments Europe, Limited for processing card, PayPal and Klarna payments
- PayPal (Europe) S.à r.l. et Cie, S.C.A. where payment is made with PayPal
- Klarna Bank AB (publ) where payment is made with Klarna
- the provider’s bank in the case of payment by advance bank transfer
- the provider’s tax advisor and the tax authorities within the scope of statutory obligations
- Plausible Analytics as a processor for website statistics
- Meta Platforms Ireland Ltd. in connection with the Meta Pixel and marketing measurement
- Vimeo once embedded videos have been actively enabled
- internal systems and databases on our own server
No data is passed on to other service providers with access to website or user data.
26. Transfers to third countries
When services such as Mailchimp, Mailchimp Transactional, Stripe, PayPal, Plausible, Meta or Vimeo are used, a transfer of personal data to countries outside the European Union or the European Economic Area cannot be ruled out. Insofar as such a transfer takes place, it is based on appropriate safeguards, in particular standard contractual clauses, adequacy decisions or other mechanisms provided for by law.
27. Your rights
Under the applicable data protection laws you have the following rights:
- the right to information about the personal data stored
- the right to rectification of inaccurate data
- the right to erasure of personal data
- the right to restriction of processing
- the right to data portability
- the right to object to certain processing
- the right to withdraw consent given
You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.
28. Objection to processing based on legitimate interests
Where personal data is processed on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing.
If you object, the personal data concerned will no longer be processed unless there are compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
29. Withdrawal of consent
Where processing is based on your consent, you can withdraw that consent at any time with effect for the future. Newsletter consent can be withdrawn via the unsubscribe link in every email. Cookie settings can be changed via the corresponding link in this privacy policy.
30. Deletion of contact and enquiries data
If you would like your contact or enquiry data deleted, you can contact us by email at kontakt@alexbellon.de.
31. No automated decision-making
Automated decision-making within the meaning of Art. 22 GDPR does not take place. Tags and segments in Mailchimp are used only for the broad organisation of the newsletter.
32. Changes to this privacy policy
This privacy policy may be adapted if technical, legal or organisational changes arise. The version published on this website at the time applies.