Privacy Policy.

This privacy policy sets out the procedures for the collection, storage, use and protection of personal data processed by the website operator in accordance with the requirements of the GDPR (General Data Protection Regulation) and the applicable German legal provisions, including the BDSG (Federal Data Protection Act).

1. General Information

This privacy policy provides information about which of your personal data are collected and processed when you visit and use this website, as well as the purpose and legal basis of this processing in accordance with the GDPR and national law.

For the purposes of this document, the following central terms derived from the GDPR apply:

2. Definitions

Personal data – all information that can be used directly or indirectly to identify a natural person.

Processing of personal data – any operation relating to personal data, in particular the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller – the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

Processor – the natural or legal person who processes personal data on behalf of the controller.

Data Subject – the natural person whose personal data are processed.

Consent of the data subject – any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Cookies – small text files that are stored on the user’s device to store information about user behavior or settings.

Note: The transmission of data over the Internet (e.g. by e-mail) can have security vulnerabilities; complete protection against access by third parties is not possible. The following sections contain detailed information on data processing and the respective protective measures.

3. Data Collection on this Website

3.1. Who is Responsible for Data Collection on this Website?

The controller is a natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, e-mail addresses, etc.) and is responsible for processing the personal data of the data subject.

Contact details of the controller:

Shadi Valid Khadzhir
Address: Steinworth 10, 30539 Hannover, Germany
Phone: +49 152 01000327
E-mail: info@6amdesign.de

Requests for the processing of personal data:
Please send requests for data processing or notifications of data protection incidents to the e-mail address provided. We will respond within 30 calendar days in accordance with Art. 12 GDPR at the latest.

3.2. How Do We Collect your Data?

Your data is collected, on the one hand, when you provide it to us yourself. This may include the following data:

  • Data that you enter in the contact form on the website;
  • Data that you provide when you send us an e-mail;
  • Data that you provide to us by telephone;
  • Data that you provide by ticking the appropriate boxes in forms (registration form for the newsletter);
  • Data that you enter when ordering or requesting services;
  • any other data that you voluntarily transmit to us while using our services.

Other data is automatically collected by our IT systems or with your consent when you visit the website. This may include:

  • Technical data: Internet browser, browser version, operating system, device type (PC, smartphone, tablet), screen resolution, system language, IP address, time of page view, duration of the session on the website;
  • Usage data: pages visited, click behavior, interaction duration, navigation paths;
  • Location data (e.g. via IP);
  • Origin data: referrer (link you came from), search query or advertising campaign used;
  • Data about downloads and errors: files you have downloaded, errors when loading pages or applications.
3.3. What Do We Use your Data for?

We process your data exclusively for the following purposes:

  • Provision and support of our services: to fulfill contractual obligations, to communicate with you in the context of projects and to process your inquiries.
  • Improvement of the website and our services: to analyze the use of the website with the aim of improving the user-friendliness and the quality of the services.
  • Marketing and communication with customers: only with your consent, e.g. for sending messages and special offers, displaying advertisements.
  • Fulfillment of legal obligations: to comply with tax, accounting and other laws.
  • Ensuring security: to protect our IT systems and to prevent misuse.
3.4. Legal Bases for the Processing of Personal Data

In accordance with Art. 6 GDPR, we only process your personal data if one of the following legal bases exists:

Consent (Art. 6 para. 1 lit. a GDPR) – If you have given us your voluntary, specific, informed and unambiguous consent, we will process your data exclusively within the scope of this consent. This may include, for example:

  • Subscription to a newsletter;
  • the use of optional cookies;
  • the transmission of information via feedback forms outside of contractual relationships.

Performance of a contract or pre-contractual measures (Art. 6 para. 1 lit. b GDPR) – We process your data if this is necessary:

  • for the performance of a contract to which you are a party (e.g. website development, consulting);
  • for the implementation of pre-contractual measures that you have requested (e.g. preparation of an offer).

Legal obligations (Art. 6 para. 1 lit. c GDPR) – Processing may be necessary to comply with our legal obligations, for example:

  • Retention of accounting records during the legally required period;
  • Answering mandatory requests from government authorities.

Legitimate interest (Art. 6 para. 1 lit. f GDPR) – In certain cases, data processing may take place on the basis of our legitimate interest, if:

  • this is necessary for the secure, efficient and reliable operation of our website;
  • we conduct limited communication with customers after completion of a project;
  • we analyze user behavior on the website in order to optimize it.

We always check whether the interests, fundamental rights and freedoms of the data subject override our legitimate interest. You can object at any time.

4. Categories of Personal Data Processed

We collect and process the following personal data of our customers and website users:

  • Contact details (first name, last name, e-mail address, telephone number);
  • Data provided in feedback forms and applications;
  • Information about the company (name, address, legal information);
  • IP address and location data, if this is necessary to improve the service and security;
  • Cookie data and other information collected using tracking technologies on the website;
  • Data voluntarily provided in the context of consultations, the performance of contracts and communication with us;
  • Information required for billing and the fulfillment of contractual obligations;
  • Technical data about the user’s browser and device (browser type, version, operating system).

All data is processed only to the extent necessary to achieve the purposes stated in our privacy policy.

5. Storage Period

Unless a more specific retention period is specified in these terms, your personal data will be stored by us until the purpose of the data processing is no longer relevant (Art. 5 para. 1 lit. b GDPR).

After the end of the contract or the cessation of the processing purpose, statutory retention periods apply:

  • Business and accounting documents: up to 10 years (§ 147 AO / § 257 HGB);
  • Correspondence: up to 6 years (§ 257 HGB).

Even in the event of a request for deletion or revocation, we will only delete your data if there are no statutory retention obligations to the contrary – otherwise we will delete it after the expiry of the periods or the elimination of the legal basis.

6. Rights of the Data Subject

Within the framework of the GDPR, you as a data subject have the following rights:

6.1. Right to Rectification (Correction) of Data

You have the right to request the immediate rectification of inaccurate or the completion of incomplete personal data that we process.

6.2. Right to Erasure of Data (“Right to be Forgotten”)

You may request the erasure of your personal data if its processing is not required for legal reasons (e.g. to fulfill legal obligations).

We will inform you about the fulfillment of your request within the legally prescribed period (usually no later than after 30 calendar days).

6.3. Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data (Art. 18 GDPR). You can contact us at any time. The right to restriction of processing applies in the following cases:

  • if you dispute the accuracy of your personal data stored by us, you have the right to request the restriction of processing for the duration of the review.
  • if the processing of your personal data was or is unlawful, you can request the restriction instead of the deletion.
  • if we no longer need your personal data, but you need it for the assertion, exercise or defense of legal claims – you have the right to request the restriction of processing;
  • if you have lodged an objection pursuant to Art. 21 para. 1 GDPR and it is not yet clear whose interests prevail.

If you have restricted the processing of your personal data, it may only be processed – apart from storage:

  • with your consent;
  • for the assertion, exercise or defense of legal claims;
  • to protect the rights of another natural or legal person;
  • for reasons of an important public interest of the EU or a member state.
6.4. Right to Withdraw Consent

You can revoke your consent to the processing of personal data at any time in the following ways:

  • Unsubscribe from the newsletter via the “Unsubscribe” link in emails;
  • Changing the cookie settings via the banner or the browser settings;
  • Contacting us via the contact details provided in the section “Who is responsible for data collection on this website”.

The revocation of consent does not affect the lawfulness of the data processing based on the consent until the time of its revocation.

6.5. Right to Data Portability

You have the right to receive the personal data you have provided in a structured, commonly used and machine-readable format and to transmit it to another controller without hindrance from us, provided that this is technically feasible.

6.6. Right to Object to Data Processing

You have the right to object at any time to the processing of your personal data if it is based on legitimate interests (Art. 6 para. 1 lit. e or lit. f GDPR), for example for analysis purposes or for profiling.

We will stop processing if we cannot demonstrate compelling legitimate grounds.

If your data is used for direct marketing, you can object at any time. In this case, your data will no longer be used for advertising purposes.

6.7. Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, you have the right to lodge a complaint with the supervisory authority pursuant to Art. 77 GDPR, in particular in the EU member state in which you have your permanent residence, your place of work or the place of the alleged violation.

For residents of Germany, especially Lower Saxony, the competent authority is:

State Commissioner for Data Protection Lower Saxony
Address: Prinzenstraße 5, 30159 Hannover, Germany
Phone: +49 511 120 4500
Fax: +49 511 120 4599

7. Cookies

Our websites use so-called “cookies”.

When you first visit our website, you will see a banner with information about cookies and you can agree to their use or set your preferences.

Cookies are small text files and do not cause any damage to your end device. They are either temporarily stored on your end device for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or they are automatically deleted by your web browser.

In some cases, cookies from third-party companies may also be stored on your end device when you enter our site (third-party cookies). These enable us or you to use certain services of the third-party company (e.g., cookies for processing payment services).

Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies are used to evaluate user behavior or display advertising.

Cookies that are required to carry out the electronic communication process, to provide certain functions you have requested (e.g. for the shopping cart function) or to optimize the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services.

If consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); consent can be revoked at any time.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

If cookies are used by third-party companies or for analysis purposes, we will inform you about this separately within the framework of this privacy policy and, if necessary, obtain your consent.

Server Log Files

The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources. This data is collected on the basis of Art. 6 para. 1 lit. f GDPR. The website provider has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, the server log files must be recorded.

8. External Services and Analysis Tools

8.1. Cookie Banner CookieYes

Service provider:
CookieYes Limited
Address: 3 Warren Yard Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom

Purpose of the service:

  • Management of user consent to the use of cookies on our website.

How it works:

  • When you visit our website, the CookieYes cookie banner stores a cookie file in your browser.
  • This file stores the user’s selection: consent or rejection; date; IP address.
  • This data will not be passed on to third parties.

Data processing:

  • The plugin does not process any personal data in the sense of disclosure or use by third parties.
  • All information about your selection is stored locally in the browser in the form of cookies.

Rights of users:

  • You can change or revoke your consent at any time by clicking on the “Cookie settings” button at the bottom of the website.

CookieYes Privacy Policy:
https://www.cookieyes.com/privacy-policy/

8.2. Google Analytics

Service provider:
Google Ireland Limited
Address: Gordon House, Barrow Street, Dublin 4, Ireland

Purpose of the service:

  • Analysis of the use of the website using cookies.

How it works:

  • Google Analytics uses cookies that enable an analysis of your use of the website.
  • The information collected with cookies (including the shortened IP address) is usually transferred to Google servers in the USA and stored there.
  • We use IP anonymization – your IP is shortened beforehand in the member states of the EU or the EEA.

Rights of users:

  • You can withdraw your consent at any time.

Google Privacy Policy:
https://policies.google.com/privacy?hl=de

8.3. Divi’S Basic Captcha

Service provider:
Elegant Themes
Address: 977 West Napa Street #1002, Sonoma, CA 95476, USA

Purpose of the service:

  • Protection of contact forms against automatic submission (bots).
  • Prevention of misuse.
  • Ensuring the technical security of the website.

How it works:

  • Runs locally.
  • Does not use external APIs or servers.
  • Does not transmit or store any personal data with third parties.
  • The verification takes place entirely in the user’s browser.

Data processing:

  • The processing is limited exclusively to the functional input verification.

Privacy policy of Elegant Themes:
https://www.elegantthemes.com/policy/privacy/

8.4. Google Maps

Service provider:
Google Ireland Limited
Address: Gordon House, Barrow Street, Dublin 4, Ireland

Purpose of the service:

  • Display of the geolocation of our studio in real time on the map.

How it works:

  • When using the map, your IP address may be transmitted to Google.
  • As part of using the service, cookies can be set and used.

Google Privacy Policy:
https://policies.google.com/privacy?hl=de

8.5. Third-party Platforms (WhatsApp, Telegram, Threads, LinkedIn)

Our website may use hyperlinks, buttons, icons, or widgets that lead to pages or chats on third-party platforms:

  • WhatsApp (WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland)
  • Telegram (Telegram Messenger LLP, London, United Kingdom)
  • Threads (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland)
  • LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland)

The mentioned elements (icons, buttons, etc.) are implemented as simple links that are only activated by your click.

When accessing these platforms, the following personal data can be transmitted:

  • IP address;
  • Information about your browser and operating system;
  • Address of the page from which the change is made;
  • Identifier of your user account on the respective platform (in case of registration).

Important: We have no influence on the further processing of this data by the respective providers. The data processing takes place according to the conditions and according to the data protection guidelines of these platforms.

Access to these links is exclusively at your request and initiative.
Recommendation: Please inform yourself about their data protection guidelines before using such functions.

Privacy policies of the third-party platforms:
WhatsApp: https://www.whatsapp.com/legal/privacy-policy-eea
Telegram: https://telegram.org/privacy
Threads (Meta): https://privacycenter.instagram.com/policy
LinkedIn: https://www.linkedin.com/legal/privacy-policy

8.6. MailerLite

Service provider:
MailerLite Limited
Address: 88 Harcourt Street, Dublin 2, D02 DK18, Ireland

Purpose of the service:

  • Sending newsletters and special offers.

How it works:

  • The data is processed on the servers of MailerLite exclusively on the basis of your consent.

Processed data:

  • E-mail address;
  • Name (if specified);
  • IP address;
  • Information about the interaction with the e-mails (openings, clicks).

Your rights:

  • You can unsubscribe from the newsletter at any time by clicking on the “Unsubscribe newsletter” link at the end of the e-mail.

Privacy policy of MailerLite:
https://www.mailerlite.com/legal/privacy-policy

8.7. Web Hosting

Description of the service:
We use a provider to host our website, on whose servers it is stored and made available for internet use (hosting).

Data processing by the provider:
The provider can process all data that is transmitted via the browser you use and that arises when using our website.
This includes in particular:

  • Your IP address – required to provide our online service in your browser;
  • All entries that you make via our website.

In addition, the provider can collect the following data:

  • Date and time of access to our website;
  • Time zone difference to Greenwich Mean Time (GMT);
  • Access status (HTTP status);
  • Scope of the transmitted data;
  • Internet provider of the accessing system;
  • Type and version of the browser you are using;
  • Operating system that you use;
  • Website from which you may have accessed our website;
  • Pages or subpages that you visit on our website.

Data storage:
The above-mentioned data is stored in the form of log files on the servers of our provider.
This is necessary to ensure the stability and security of our website.

Affected data:

  • Content data (e.g. posts, photos, videos);
  • Usage data (e.g. access times, visited websites);
  • Communication data (e.g. information about the device used, IP address).

Affected persons:

  • Users of our website.

Purpose of processing:

  • Presentation of our websites, ensuring their operation.

Web hosting commissioned by us: IONOS
Service provider: IONOS SE
Address: Elgendorfer Str. 57, 56410 Montabaur, Germany

Privacy policy of IONOS:
https://www.ionos.de/terms-gtc/datenschutzerklaerung/?source=termsandconditions

9. Measures to Protect Personal Data

We take a comprehensive set of technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure or destruction in accordance with the requirements of the GDPR and the applicable national legal provisions.

9.1. Technical Safeguards
  • Use of the secure data transfer protocol HTTPS (SSL/TLS) when transferring information via the website.
  • Use of firewalls and intrusion prevention systems.
  • Regular updating of the software, including CMS, plugins and server software.
  • Storage of data on servers with restricted physical and remote access.
  • Data backup with protected storage of backups.
  • Limitation of the access points to data and monitoring of the activities in the systems.
9.2. Organizational Safeguards
  • Access to personal data is only available to authorized employees or contractors who are committed to confidentiality.
  • Training of personnel regarding the processing and protection of personal data.
  • Conclusion of data processing agreements in accordance with Art. 28 GDPR.
  • Introduction of internal guidelines for password and access management.
9.3. Physical Protection
  • Servers are located in data centers with controlled physical access, video surveillance and access systems using ID cards.
  • Restriction of access by unauthorized persons to devices on which personal data is processed.
9.4. Control and Security Audit
  • Periodic review and testing of the security measures.
  • Adaptation of the protective measures in case of changes in the technical conditions or legal requirements.
  • Reaction to security incidents within defined deadlines and notification of the supervisory authorities as well as the persons concerned (in the cases according to Art. 33–34 GDPR).

10. Data Transfer to Third Countries

The processing and storage of your personal data takes place mainly on servers located in the European Union (EU) or in the European Economic Area (EEA).

A transfer of data outside the EU/EEA can only take place in the following cases:

  • When using Google Analytics and Google Maps (provider: Google Ireland Limited, with possible data processing on servers of Google LLC in the USA);
  • When sending newsletters via MailerLite (provider: MailerLite Limited, Ireland; a transfer to third countries may be necessary for technical reasons).

In all other cases, no personal data is transferred to third countries.

11. Changes to this Privacy Policy

We reserve the right to change or adapt this privacy policy at any time in order to adapt it to changed legal requirements or technical changes on our website.

The current version is always available on our website.

Last updated: 11/08/2025