Privacy Policy

Privacy Policy

This privacy policy informs you about the type, scope, and purpose of the processing of personal data (hereinafter referred to as "data") within our online offering and the associated websites, functions, and content (hereinafter collectively referred to as "online offering"). Regarding the terms used, such as "processing" or "controller," we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).

Last updated: 31 July 2026

No Cookies, No Tracking

This website sets no cookies, uses no analytics or tracking services, and loads no content from third-party servers. Fonts, scripts, styles, and images are delivered from this domain only. Nothing you do here is measured, profiled, or shared, and there is nothing to consent to.

The only data processed is what any web server unavoidably receives when it answers a request. That is described under "Collection of Access Data and Log Files" below.

Controller

Melanie Stief
hey at viridis dot de

Owner

Stief, Melanie
Link to Imprint

Types of Processed Data

Usage data (e.g., pages visited, access times).
Meta/communication data (e.g., browser and device information, IP addresses).
Contact data (e.g., your email address), but only if you write to us.

Categories of Data Subjects

Visitors and users of the online offering (hereinafter collectively referred to as "users").

Purpose of Processing

Provision of the online offering, its functions, and content.
Responding to contact requests and communication with users.
Security measures.

Definitions of Terms

"Personal data" refers to all information that relates to an identified or identifiable natural person (hereinafter "data subject"). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

"Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data.

"Controller" refers to the natural or legal person, public authority, agency, or other body which alone or jointly with others determines the purposes and means of the processing of personal data.

"Processor" means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.

Relevant Legal Bases

In accordance with Article 13 GDPR, we inform you of the legal bases of our data processing activities. Unless the legal basis is explicitly stated in the privacy policy, the following applies: the legal basis for processing in response to inquiries is Article 6(1)(b) GDPR, the legal basis for processing to fulfill our legal obligations is Article 6(1)(c) GDPR, and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) GDPR.

Security Measures

We take appropriate technical and organizational measures in accordance with Article 32 GDPR, considering the state of technology, implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

These measures include delivering this site exclusively over HTTPS, a strict Content Security Policy that blocks any third-party resource, and the principle of data protection by design and default (Article 25 GDPR): the site collects nothing it does not need.

Collaboration with Processors and Third Parties

This website is hosted by ALL-INKL.COM (Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany), which acts as our processor under Article 28 GDPR and operates the server that receives your requests. We pass data to no one else, and no other third party receives data through this website.

Rights of Data Subjects

You have the right to request confirmation as to whether relevant data is being processed and to obtain information about such data, as well as further information and a copy of the data in accordance with Article 15 GDPR.

You have the right to request the completion of data concerning you or the correction of incorrect data concerning you in accordance with Article 16 GDPR.

In accordance with Article 17 GDPR, you have the right to request that relevant data be deleted immediately or, alternatively, to request a restriction of the processing of data in accordance with Article 18 GDPR.

You have the right to receive the data concerning you that you have provided to us in accordance with Article 20 GDPR and to request its transmission to other controllers.

Additionally, you have the right to lodge a complaint with the competent supervisory authority in accordance with Article 77 GDPR.

Right to Object

You can object to the future processing of your data at any time in accordance with Art. 21 GDPR.

Deletion of Data

The data processed by us will be deleted or restricted in its processing in accordance with Articles 17 and 18 GDPR. Unless explicitly stated within this privacy policy, the data stored by us will be deleted as soon as it is no longer required for its intended purpose and the deletion does not conflict with any statutory retention obligations. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for other purposes.

Contact

When you contact us by email, your information will be processed to handle the request in accordance with Art. 6 (1) lit. b) GDPR. We delete inquiries once they are no longer necessary and review that need every two years; statutory archiving obligations remain unaffected.

Collection of Access Data and Log Files

Our hosting provider collects data on the basis of our legitimate interests within the meaning of Art. 6 (1) lit. f. GDPR about every access to the server on which this service is located (so-called server log files). Access data includes the name of the accessed webpage, file, date and time of access, data volume transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address, and the requesting provider.

Log file information is stored for security reasons (e.g., to investigate abuse or fraud) for a maximum duration of 7 days and then deleted. Data whose further retention is required for evidence purposes is excluded from deletion until the respective incident is finally clarified.

Online Presence on Social Media

We maintain profiles on social networks and link to them from this website. Those are plain links: no content is embedded here, and no data reaches the networks until you follow a link yourself. Once you do, the terms and data processing policies of the respective operator apply.

If you communicate with us within those networks, e.g., by sending us a message there, we process that communication to respond to it.