Legal
Privacy policy
Information on the processing of personal data pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR). This is a translation for convenience; the German version is the legally binding one.
1. Controller
The controller for data processing on this website within the meaning of Article 4 (7) GDPR is:
Feidt Consulting
Jean-Paul Feidt
Neuer Wall 80
20354 Hamburg
Germany
Phone: +49 170 24 17 279
Email: jean-paul.feidt@feidt-consulting.de
There is no legal obligation to appoint a data protection officer, as the conditions of Article 37 GDPR in conjunction with section 38 of the German Federal Data Protection Act are not met. For any questions about data protection you can reach me at the contact details above.
2. General
Protecting your personal data matters to me, not least because careful handling of data is part of my profession. Personal data is any information relating to an identified or identifiable natural person: for example name, address, email address, telephone number or IP address.
This website presents my professional work. There is no contact form, no registration and no user account. No cookies are set, no social media plugins are embedded, and no external resources are loaded when the pages are opened. The typeface used is served from this site's own server.
For audience measurement I use a service provided by my hosting provider. It works without cookies, stores nothing on your device and anonymises the IP address; details in section 6. That is why there is no consent banner on this website: no information is stored on or read from your device for which consent would need to be obtained.
The appointment booking service is included as an ordinary link and is not embedded into this website. Data is only transmitted to the provider once you deliberately click the link. Details in section 9.
3. Legal bases for processing
Where I obtain consent for processing operations, Article 6 (1) (a) GDPR is the legal basis. Where processing is necessary for the performance of a contract or for pre-contractual measures, Article 6 (1) (b) GDPR applies. Where processing is necessary for compliance with a legal obligation, for example to observe retention periods under tax and commercial law, Article 6 (1) (c) GDPR applies. In all other cases I base the processing on a legitimate interest pursuant to Article 6 (1) (f) GDPR; the interest in question is stated with each individual processing activity.
4. Visiting the website and server log files
When this website is accessed, the hosting provider automatically stores information transmitted by your browser in what are known as server log files. These are:
- the IP address of the accessing device
- the date and time of access
- the name and URL of the file retrieved
- the volume of data transferred and a message confirming successful retrieval
- the website from which access took place (referrer URL)
- the browser used, including version, and the operating system
Processing this data is technically necessary in order to deliver the website. It takes place on the basis of Article 6 (1) (f) GDPR. My legitimate interest lies in the technically faultless operation of the website, in ensuring system security and in investigating abusive access.
The log files are automatically deleted after seven days at the latest. This data is not combined with other data sources; it is not evaluated for marketing purposes.
5. Hosting
This website is hosted by:
IONOS SE
Elgendorfer Strasse 57
56410 Montabaur
Germany
IONOS processes the data arising when the website is accessed exclusively on my behalf and according to my instructions. A data processing agreement pursuant to Article 28 GDPR is in place with IONOS. The data is processed on servers within the European Union. The legal basis for using the provider is Article 6 (1) (f) GDPR; my legitimate interest lies in the secure and reliable operation of this website.
6. Audience measurement with IONOS WebAnalytics Plus
This website uses WebAnalytics Plus, an analytics service provided by my hosting provider IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany. I use it to evaluate how the website is used, in order to improve it technically and in terms of content.
The following is recorded:
- the page visited previously (referrer)
- the page or file requested
- browser type and browser version
- operating system and device type
- the time of access
- the IP address in anonymised form, used solely for a rough location estimate
Collection takes place through log files and a counting pixel. No cookies are set and no information is stored on your device. The IP address is anonymised immediately after transmission; drawing conclusions about individual visitors is not possible. The data is not passed on to third parties.
The legal basis is Article 6 (1) (f) GDPR. My legitimate interest lies in the statistical evaluation and improvement of my website. A data processing agreement pursuant to Article 28 GDPR is in place with IONOS.
As neither cookies are set nor information stored on or read from your device, consent under section 25 of the German Digital Services Data Protection Act (TDDDG) is not required. You can object to this processing at any time pursuant to Article 21 GDPR; how to do so is set out in section 20.
7. Fonts
The typeface used, “Mulish”, is served locally from this website's own server. There is no connection to Google Fonts or any other external provider; your IP address is not transmitted to third parties in this context.
8. Getting in touch by email or telephone
If you contact me by email or telephone, I process the data you provide, such as name, contact details, company and the content of your enquiry, in order to deal with your request and in case of follow-up questions.
The legal basis is Article 6 (1) (b) GDPR where the enquiry is directed at concluding or performing a contract. Otherwise I base the processing on Article 6 (1) (f) GDPR; my legitimate interest lies in answering enquiries addressed to me.
The data is deleted once the underlying matter has been concluded and no statutory retention periods prevent this. A matter is considered concluded when the circumstances indicate that the request has been dealt with conclusively.
Please note: an unencrypted email can be read by unauthorised parties while in transit. For confidential content I recommend postal mail or arranging a secure channel in advance.
9. Appointment booking and video calls via Zoom
9.1 Appointment booking
On the contact page I offer you the option of scheduling an intro call yourself. A link to the “Zoom Scheduler” booking tool is provided for this. The service is not embedded into this website: as long as you do not click the link, no data is transmitted to the provider.
If you click the link, you leave this website and are forwarded to a page belonging to the following provider:
Zoom Communications, Inc.
55 Almaden Blvd, Suite 600
San Jose, CA 95113
USA
The representative in the European Union pursuant to Article 27 GDPR is Workvivo Limited, 4th Floor, City Quarter, Lapps Quay, Cork T12 W832, Ireland.
When you book, Zoom processes the data you enter, as a rule your name, email address, the slot chosen including time zone, and any information you voluntarily provide about your request. Technically, connection data also arises, in particular the IP address, the date and time of access and information about the browser and operating system. The booking data is then passed on to me so that I can attend the appointment.
The legal basis is Article 6 (1) (b) GDPR: the processing takes place at your initiative for the purpose of pre-contractual measures. You are not obliged to use the booking tool. You can equally reach me by email or telephone without any data being transmitted to Zoom.
9.2 Conducting the conversation
If the conversation takes place as a video call, Zoom processes the data required for it: display name, meeting metadata such as start, duration and participants, technical connection data and, depending on what you enable, image, audio and chat content during the conversation.
Conversations are not recorded. Should a recording be wanted in an individual case, I will obtain your express consent beforehand; the legal basis would then be Article 6 (1) (a) GDPR, revocable with effect for the future.
You can also take part in a conversation without a camera, or join by phone instead. That is expressly fine and needs no justification.
9.3 Data processing agreement and transfer to the USA
A data processing agreement pursuant to Article 28 GDPR is in place with Zoom. Zoom processes the data on my behalf and according to my instructions.
Processing in the United States cannot be ruled out in this context. Zoom Communications, Inc. is certified under the EU-U.S. Data Privacy Framework. By adequacy decision of 10 July 2023, the European Commission determined that certified companies provide an adequate level of data protection. The European Commission's standard contractual clauses apply in addition.
The booking data is deleted once the appointment has been dealt with and no statutory retention periods prevent this. For processing carried out by Zoom under its own responsibility, the provider's privacy policy applies in addition: zoom.com/en/trust/privacy/privacy-statement.
10. Initiating and carrying out advisory engagements
If we work together, I process the data of your contacts that is necessary to carry out the engagement, in particular name, role, business contact details and the correspondence exchanged in the course of the collaboration.
The legal basis is Article 6 (1) (b) GDPR, and for data of my clients' employees Article 6 (1) (f) GDPR; the legitimate interest lies in performing the contractual relationship with the company concerned.
Once the engagement has ended, the data is deleted unless statutory retention periods apply. Retention obligations arise in particular from section 147 of the German Fiscal Code and section 257 of the German Commercial Code, with periods of six to ten years.
Where I process personal data on behalf of my clients as part of an engagement, this takes place on the basis of a separate data processing agreement pursuant to Article 28 GDPR. In that case the client concerned remains the controller for that data.
11. Presence on LinkedIn
I maintain a personal profile on the LinkedIn network as well as a company page for Feidt Consulting, and I link to them from this website. The reference is an ordinary link. No buttons, profile previews or other LinkedIn content are embedded; as long as you do not click the link, no data is transmitted to LinkedIn when this website is accessed.
The operator of the network for users in the European Economic Area is:
LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland
11.1 Processing by LinkedIn
If you open my profile or my company page, LinkedIn processes your data under its own responsibility. This concerns in particular your profile and usage data, technical connection data and information about which content you access. LinkedIn also uses cookies in this context and can build usage profiles from them. I have no influence over the nature and extent of this processing, nor am I aware of it in detail.
If you do not want LinkedIn to associate your visit with your account, log out of LinkedIn beforehand. Details and your settings options can be found in the provider's privacy policy: linkedin.com/legal/privacy-policy.
11.2 Joint controllership for the company page
For the company page, LinkedIn provides me with statistics known as page insights. They show how often posts were seen and clicked, how the number of followers is developing and roughly how the audience is composed, for example by industry, role, company size and region. I receive this information in aggregated form only. I cannot attribute it to any individual person and, through the page, I have no access to your profile unless you contact me yourself.
For the processing underlying these statistics, LinkedIn Ireland and I are joint controllers within the meaning of Article 26 GDPR. The legal basis is Article 6 (1) (f) GDPR. My legitimate interest lies in presenting my work publicly and in seeing whether my posts reach their audience.
The essence of the arrangement between LinkedIn and operators of company pages can be summarised as follows:
- LinkedIn has assumed primary responsibility for the processing of page insights data under the GDPR, including fulfilling your rights as a data subject.
- LinkedIn itself provides the information required under Articles 13 and 14 GDPR, in the provider's privacy policy.
- The lead supervisory authority for LinkedIn Ireland is the Irish Data Protection Commission.
- You can exercise your rights both against LinkedIn and against me. If you approach me, I will forward your request to LinkedIn where LinkedIn is responsible for it.
LinkedIn provides the full text in the “Page Insights Joint Controller Addendum”: legal.linkedin.com/pages-joint-controller-addendum.
This does not apply to my personal profile: the statistics function is not available there, and there is no joint controllership in that respect.
11.3 Messages and connection requests
If you send me a message or a connection request via LinkedIn, I process the data transmitted, that is your name, the publicly visible information in your profile and the content of your message, in order to deal with your request. The legal basis is Article 6 (1) (b) GDPR where it concerns initiating or performing a contract, otherwise Article 6 (1) (f) GDPR. My legitimate interest lies in answering enquiries addressed to me and in presenting my professional work.
LinkedIn is not the right channel for confidential matters. Please use the contact details given in section 1 for those.
11.4 Transfer of data to the USA
LinkedIn is part of the Microsoft group of companies; processing in the United States cannot be ruled out. Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework, and the European Commission's standard contractual clauses apply in addition.
12. Handling of postal mail
For receiving, handling and forwarding postal items sent to my business address I use a service provider. In doing so, the data on the item is processed, in particular sender, recipient and address, and depending on the scope of service chosen also the content of the item, for example where letters are scanned and made available to me digitally.
The legal basis is Article 6 (1) (f) GDPR. My legitimate interest lies in the reliable handling of business post independently of location. Where the item serves to initiate or perform a contract, Article 6 (1) (b) GDPR applies in addition.
A data processing agreement pursuant to Article 28 GDPR is in place with the service provider; it processes the data exclusively on my behalf and according to my instructions. Processing takes place within the European Union. The data is deleted once the underlying matter has been concluded and no statutory retention periods prevent this.
13. Office and communication software
For day-to-day work, that is correspondence, calendar management, documents and notes, I use Microsoft 365. Personal data contained in those documents and messages is processed to the extent necessary for the matter in question.
The provider for customers in the European Economic Area is:
Microsoft Ireland Operations Limited
Dublin
Ireland
The legal basis is Article 6 (1) (b) GDPR where processing serves to initiate or perform a contract, otherwise Article 6 (1) (f) GDPR. My legitimate interest lies in a secure, available and economically reasonable office setup.
A data processing agreement pursuant to Article 28 GDPR is in place with Microsoft. Content data is stored within the European Union under the EU Data Boundary. Processing in the United States, for example in the context of support or error analysis, nevertheless cannot be entirely ruled out. Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework, and the European Commission's standard contractual clauses apply in addition.
14. Recipients of data
Your data is only passed on to third parties where this is permitted or required by law, where you have consented, or where it is necessary to perform a contract.
The following are engaged as processors pursuant to Article 28 GDPR:
- IONOS SE, Montabaur: hosting of this website, audience measurement and email service
- Zoom Communications, Inc., San Jose (USA): appointment booking and video calls, where you use these options
- Microsoft Ireland Operations Limited, Dublin (Ireland): office and communication software
- A service provider for postal handling established in the European Union: receipt and forwarding of business post
In addition, tax advisers and, in the event of a dispute, legal advisers may become aware of data where this is necessary to fulfil legal obligations or to pursue legal claims.
15. Transfers to third countries
Simply accessing this website does not involve any transfer of personal data to countries outside the European Union or the European Economic Area.
A transfer to the United States may occur in the following cases:
- if you use the booking tool or take part in a video call, see section 9.3
- if you open my profile or my company page on LinkedIn or contact me there, see section 11.4
- to a limited extent when Microsoft 365 is used, for example in the context of support or error analysis, see section 13
The basis is the same in all three cases: certification of the respective provider under the EU-U.S. Data Privacy Framework together with the European Commission's adequacy decision of 10 July 2023, supplemented by the standard contractual clauses.
16. External links
This website contains links to external offerings, for example to podcast platforms and to third-party articles. For the reference to my LinkedIn profile, section 11 applies in addition. All of these links are included as ordinary references; no content from the linked pages is loaded, and no data is transmitted to the linked providers when this website is merely accessed.
Only when you click such a link do you leave this website. From that point on, the privacy provisions of the respective provider apply, over whose processing I have no influence. Please inform yourself there about how your data is handled.
17. No automated decision-making
Automated decision-making, including profiling, within the meaning of Article 22 GDPR does not take place.
18. Whether providing data is required
Providing personal data is neither required by law nor by contract. Processing the server log files is technically necessary in order to access the website. Beyond that, you are free to decide whether and which data you share with me. Without the information needed to get in touch or to book an appointment, however, I cannot deal with your request.
19. Your rights as a data subject
You have the following rights in relation to your personal data:
- Access (Article 15 GDPR): you can request information about whether and which data I process about you, for what purposes, for how long and to which recipients.
- Rectification (Article 16 GDPR): you can request the correction of inaccurate data and the completion of incomplete data.
- Erasure (Article 17 GDPR): you can request the deletion of your data where its processing is no longer necessary and no statutory retention obligations prevent this.
- Restriction of processing (Article 18 GDPR): you can request that your data only be processed in a restricted manner, for example while accuracy you have contested is being verified.
- Data portability (Article 20 GDPR): you can request to receive the data you provided in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
- Withdrawal of consent (Article 7 (3) GDPR): you can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out up to that point remains unaffected.
20. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6 (1) (e) or (f) GDPR (Article 21 GDPR).
If you object, I will no longer process the data concerned unless I can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. An objection can be made informally and should be addressed to the contact details given above.
21. Right to lodge a complaint with a supervisory authority
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your data infringes the GDPR. You may contact the supervisory authority of your place of residence, your place of work or the place of the alleged infringement.
The supervisory authority responsible for me is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
(Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Strasse 22, 7th floor
20459 Hamburg, Germany
datenschutz-hamburg.de
22. Data security
This website is delivered over SSL/TLS encryption. You can recognise an encrypted connection by the fact that your browser's address bar shows “https://”. This means that the data you transmit to this website cannot be read by third parties.
In addition, I use appropriate technical and organisational measures pursuant to Article 32 GDPR to protect your data against accidental or deliberate manipulation, loss, destruction and unauthorised access. These measures are reviewed and adapted on an ongoing basis in line with technological developments.
23. Currency of this privacy policy
This privacy policy will be adapted as soon as the underlying processing activities change or legal requirements make it necessary. The version available on this page applies in each case.
Last updated: September 2026