1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Raon Strohschein
Seelingstraße 37
14059 Berlin
Germany
Phone: +49 30 923 60 697
Email: office@raonstrohschein.de
2. General information
This privacy policy explains which personal data is processed when you visit this website and use its features. Personal data is any information that can identify a person directly or indirectly.
We process personal data only where a legal basis exists. Depending on the processing activity, these include in particular:
- Art. 6(1)(a) GDPR for processing based on consent;
- Art. 6(1)(b) GDPR for steps prior to entering into a contract and for performing a contract;
- Art. 6(1)(c) GDPR for compliance with legal obligations;
- Art. 6(1)(f) GDPR for legitimate interests, provided the interests or fundamental rights of the person concerned do not override them.
Where information is stored on or read from a device, operations that are not strictly necessary take place only with consent under Section 25(1) of the German Telecommunications and Digital Services Data Protection Act (TDDDG). Strictly necessary operations are governed by Section 25(2) TDDDG.
3. Hosting and server logs
This website is hosted by dogado GmbH, Antonio-Segni-Straße 11, 44263 Dortmund, Germany. We use a data processing agreement with the hosting provider under Art. 28 GDPR.
When you access the website, the web server processes in particular:
- IP address;
- date and time of access;
- requested address and amount of data transferred;
- referrer URL;
- browser, operating system and device type;
- HTTP status and technical error information.
This processing provides the website securely, stably and without errors. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website. Access and error logs are deleted after no more than seven days. IP addresses contained in them are anonymized after 24 hours.
The host’s web application firewall is also active. It checks incoming requests for attack patterns, blocks suspicious access and may log security-relevant request data. The processing protects the website and is based on Art. 6(1)(f) GDPR. The retention periods stated for access and error logs are not a guaranteed retention period for firewall logs.
4. Cookies and consent management with Borlabs Cookie
We use Borlabs Cookie to obtain, document and technically implement consent for optional services. The plugin is provided by Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany.
Borlabs Cookie stores your choice in a technically necessary cookie. In particular, consent status, time and a random identifier are processed. This is necessary to document your choice and respect it on subsequent page visits. The legal bases are Art. 6(1)(c) and (f) GDPR and Section 25(2) TDDDG. Our legitimate interest is lawful and user-friendly consent management.
You can change or withdraw your choice at any time using “Cookie Settings” in the website footer or the following button. Withdrawal takes effect for the future. The Borlabs cookie stores your choice for 60 days unless you delete it or change your choice sooner.
5. Google Tag Manager
With your consent, we use Google Tag Manager from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Tag Manager lets us manage website tags centrally. It does not itself create analyses of user behavior. However, its use may transfer technical connection data, particularly your IP address and browser information, to Google.
Google Tag Manager is loaded on this website only after you have allowed Google Analytics 4 in the Statistics category or Google Ads in the Marketing category through Borlabs Cookie. These permissions are handled separately: consent to Statistics alone does not activate the Google Ads tag; consent to Marketing alone does not activate Google Analytics 4. Without consent to at least one of these services, Google Tag Manager is not loaded. The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw consent at any time through Cookie Settings with effect for the future.
Processing by Google companies or subprocessors in the USA cannot be ruled out. According to Google, international transfers rely, among other things, on the EU–US Data Privacy Framework and the European Commission’s standard contractual clauses.
Further information: Google Privacy Policy.
6. Google Analytics 4
With your consent, we use Google Analytics 4, a web analytics service from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It helps us understand how the website is used and which content matters to visitors.
In particular, the following data may be processed:
- pages viewed and interactions;
- time, approximate visit duration and session information;
- referrers and campaign parameters;
- approximate location;
- browser, device and operating system information;
- pseudonymous identifiers such as the Google Analytics client ID.
According to Google, it uses the IP address to derive approximate location information but does not log or store the IP address in Google Analytics. Integration is through Google Tag Manager. Google Analytics and the Tag Manager required for it are loaded only after you give consent.
The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. In our GA4 property, event data retention is set to two months and user data retention to 14 months. The user identifier retention period resets on new activity. These settings concern user-level and event-level data; standard aggregated reports are not affected. Google Signals and collection of user-provided data are disabled. The four optional account-wide data sharing settings for Google products and services, aggregated models and business insights, technical support, and business recommendations are switched off. Separate product links, particularly to Google Ads, must be distinguished from these settings.
This website uses the cookies _ga and _ga_FYZCWJL34Y. They distinguish visitors and store session status. Google’s standard lifetime is two years; browsers may shorten the actual lifetime. Cookie lifetimes differ from retention on Google’s servers. You can withdraw your consent through Cookie Settings at any time with effect for the future.
Processing by Google companies or subprocessors in the USA cannot be ruled out. According to Google, international transfers rely, among other things, on the EU–US Data Privacy Framework and the European Commission’s standard contractual clauses.
Further information: Google Privacy Policy.
6a. Google Ads
After you consent to the Marketing category, we load the Google Ads tag from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It serves advertising measurement and enables retargeting of website visitors with personalized advertising. Integration is through Google Tag Manager.
In particular, your IP address, browser and device information, pages viewed, time, referrer, advertising click information and pseudonymous cookie identifiers may be sent to Google. Google can use this to associate visits and later actions with an advertisement and, depending on your consent and Google settings, to personalize ads. Consent to Statistics alone is not sufficient.
The Google Ads tag uses the _gcl_au cookie, among others. According to Google, cookies with the _gcl_ prefix have a lifetime of 90 days; browsers may limit the actual lifetime. Cookie lifetime should not be equated with the retention period for all data held by Google. Further details about processing and storage are available in the privacy notices linked below.
The legal bases are your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw consent using “Cookie Settings” in the footer or the privacy settings on this page, with effect for the future. After withdrawal, the Google Ads tag will not start on newly loaded pages; the Google Ads cookies used by our integration will be removed. Removing cookies does not automatically erase data already sent to Google.
Processing in the USA is possible. According to Google, Google LLC is certified under the EU–US Data Privacy Framework; a European Commission adequacy decision applies to covered transfers. Google also cites standard contractual clauses as a basis for international data transfers.
Further information: Google Privacy Policy, Google’s use of cookies and Google’s legal grounds for data transfers.
7. Contact form, pricing and fit calculator, and lead management
If you write to us through the contact form or use the pricing and fit calculator, we process your details to handle your inquiry, reply to you and, for the calculator, provide a non-binding price indication and recommendation about a possible engagement.
The contact form may process, in particular:
- name;
- company, if provided voluntarily;
- email address;
- phone number, if provided voluntarily;
- message content;
- page visited, source and UTM parameters;
- timestamps, processing status, notes and follow-up information.
The pricing and fit calculator may additionally process your monthly media budget, number of accounts and markets, requested scope of services, calculated price range and recommendation.
Processing to handle your inquiry and take steps prior to entering into a contract is based on Art. 6(1)(b) GDPR. Where an inquiry does not concern a possible engagement, processing may be based on Art. 6(1)(f) GDPR. Our legitimate interest is to respond appropriately to incoming messages. After submitting the contact form, you receive confirmation that your message arrived. For the calculator, an email address is required if you ask to have the price indication sent to you.
Details from the contact form and calculator are brought together in our internal WordPress lead management system. There, we may store the source, processing status, notes, next follow-ups and a simple activity history so we can handle inquiries consistently and efficiently.
To protect against automated or abusive requests, we create a checksum from the IP address using a secret key. The full IP address is not stored in the lead record. The checksum and associated counter are used as a short-lived technical cache. It remains valid for ten minutes after the latest request that updated the counter. Expired entries are removed on subsequent access or by WordPress cleanup; exact physical deletion after ten minutes is therefore not guaranteed. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to protect the forms and email delivery against abuse.
The calculator’s recommendation and price range are non-binding. No decision is made solely by automated means that produces legal effects concerning you or similarly significantly affects you.
We delete inquiries that do not result in an engagement once further handling is complete and storage is no longer necessary. If there is no further contact, deletion generally takes place no later than six months after the last substantive contact. Longer storage takes place only where specific statutory retention duties or evidence needed for legal claims require it. Marketing consent does not justify retaining the entire inquiry history. To support this manual deletion process, records without documented contact for five months are flagged for review; that review interval does not justify keeping data after the purpose has ended sooner.
8. Marketing consent and double opt-in
In the contact form and when requesting an email from the pricing and fit calculator, you can voluntarily consent to being contacted personally by email and occasionally receiving information and offers about performance marketing, performance audits, fractional and interim performance marketing, and senior-led performance marketing systems. Your contact form or calculator details may be used to tailor content and offers to your situation and setup. Marketing consent is not required to handle your inquiry.
After you give consent, we send a confirmation email to the address you provided. Marketing consent becomes active only when you open its confirmation link and then select “Confirm consent now” on the page that opens. Opening the link alone is not enough. For documentation, we store in particular:
- the wording and version of the consent;
- the times of the request and confirmation;
- consent status;
- a hashed email address;
- the hash and validity period of the confirmation token;
- relevant status events.
The legal basis is Art. 6(1)(a) GDPR. You can withdraw consent at any time with effect for the future using the unsubscribe link in our emails or by writing to office@raonstrohschein.de.
After withdrawal, the email address is no longer used for marketing. We may retain proof of the consent previously given and withdrawn until the regular limitation period expires, based on Art. 6(1)(f) GDPR. Our legitimate interest is to defend or assert possible legal claims. The proof is not used for further marketing.
9. Email delivery and delivery logs
Contact form confirmations, pricing and fit calculator emails, double opt-in messages and internal notifications are sent through our hosting provider dogado’s SMTP service. To support reliable delivery and troubleshooting, WordPress temporarily logs technical delivery data. This may include recipient address, subject, time, delivery status and technical errors. The message content may be included in the delivery log.
Automatic cleanup is set to retain delivery logs for 14 days. Depending on the message, the legal basis is Art. 6(1)(b), (c) or (f) GDPR. Our legitimate interest is reliable delivery and short-term troubleshooting.
10. Booking appointments through Calendly
We link to an external appointment booking page at Calendly. The provider is Calendly, LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA.
No Calendly widget is embedded on our website. Merely visiting our website therefore does not transfer data to Calendly. Only when you select the booking link do you visit Calendly’s website. There, your name, email address, appointment data, time zone, optional details and technical usage data may be processed.
Where Calendly processes booking data on our behalf, this is based on a data processing agreement. Processing booking data to prepare and conduct the conversation you requested is based on Art. 6(1)(b) GDPR. Calendly also processes data in the USA and, according to its information, relies on the EU–US Data Privacy Framework and standard contractual clauses for international transfers.
Further information: Calendly Privacy Notice.
Google Calendar and Google Meet
Calendly is connected to our Google Calendar. When you book, your name, email address, appointment time and any booking details you provide are transferred to the calendar. A Google Meet link is created automatically for the video call. We use a Google account with Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When you join Google Meet, Google processes participant and connection data as well as any audio, video, chat or screen content you choose to share. You control your camera and microphone. Processing initiated by us to organize and conduct the conversation you requested is based on Art. 6(1)(b) GDPR; for other conversations, the basis is Art. 6(1)(f) GDPR and our interest in effective communication. The purpose-specific deletion criteria in this policy apply to appointment and inquiry data.
Google may also process data in the USA. Further information on Google’s processing, retention criteria and international transfers can be found in the Google Privacy Policy, Google Meet privacy information and information on international data transfers.
11. Wordfence
We use Wordfence Security to protect the website against attacks and malware. The provider is Defiant, Inc., 1700 Westlake Ave N, Suite 200, Seattle, WA 98109, USA.
Wordfence analyzes access to the website to detect harmful requests, login attempts, modified files and known attack patterns. In particular, it may process IP addresses, requested URLs, timestamps, HTTP headers, browser information, request content, attempted usernames or email addresses, and security-relevant file information. Security events may be transferred to Defiant’s servers.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to protect the website, the data processed there and our IT systems against misuse and attacks. Processing in the USA cannot be ruled out. According to Defiant, it uses the European Commission’s standard contractual clauses, among other safeguards, for international transfers.
Further information: Wordfence Privacy Policy.
12. Google reCAPTCHA in the administrator login
The login page for our WordPress administration area is protected by Google reCAPTCHA v2 against automated and abusive login attempts. This feature loads only on that login page, not in our public contact or calculator forms.
Connections to Google are established as soon as the login page is opened. In particular, IP address, browser and device information, referrer, and interactions with the page and security challenge may be processed. reCAPTCHA uses the _GRECAPTCHA cookie for risk analysis; integration through google.com may also involve other Google cookies already present there.
Our sole purpose is to protect administrator access and the data there against automated attacks, fraud and misuse. The data protection basis for this security purpose is Art. 6(1)(f) GDPR. For access to the user’s device, the exception under Section 25(2) no. 2 TDDDG applies only insofar as strictly necessary for the expressly requested protected login; it does not cover further optional access.
According to Google, since 2 April 2026 it processes reCAPTCHA customer data as a processor under the Google Cloud terms and Cloud Data Processing Addendum. This should be distinguished from our use of other Google services, particularly Google Calendar and Google Meet. Processing in the USA is possible; Google’s contractual terms include provisions on international transfers and standard contractual clauses.
Further information: Google on reCAPTCHA data processing and the Google Cloud Data Processing Addendum.
13. Recipients and transfers to third countries
We share personal data only where necessary for the purposes described, where a legal duty applies or where you have consented. Recipients may include hosting, email, security, analytics and appointment booking providers. The purposes and processing activities of the services used are described above.
For transfers to countries outside the European Union or European Economic Area, we look for an adequacy decision or appropriate safeguards such as the European Commission’s standard contractual clauses. Despite such safeguards, a residual risk may remain when data is processed in third countries: authorities there may access data, and European data subject rights may not always be enforceable to the same extent.
14. Retention period
Unless a specific period is stated in this policy, we keep personal data only for as long as required for the relevant purpose. We then delete or anonymize it unless statutory retention obligations or legitimate grounds require further, restricted storage.
Business records may be subject to retention periods under commercial or tax law. Data required to assert, exercise or defend legal claims may be retained until the statutory limitation periods expire.
15. Your rights
Subject to statutory conditions, you have in particular the right to:
- obtain information about the personal data we process about you;
- have inaccurate data corrected;
- request erasure of your data;
- request restriction of processing;
- receive data in a structured, commonly used and machine-readable format;
- object to processing based on Art. 6(1)(e) or (f) GDPR;
- withdraw consent at any time with effect for the future.
To exercise your rights, email office@raonstrohschein.de.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority particularly responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
mailbox@datenschutz-berlin.de
www.datenschutz-berlin.de
16. Objection to processing based on legitimate interests
Where we process personal data based on Art. 6(1)(f) GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation. If personal data is processed for direct marketing, you may object at any time without giving reasons.
17. Updates to this privacy policy
We update this privacy policy when website functions, service providers or legal requirements change. The version published on this website at the relevant time applies.
Last updated: 24 September 2026