Privacy Policy
1) Introduction and Contact Details of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data refers to all data by which you can be personally identified.
​
1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
​
Olivia Heuer
c/o Familienoase Berlin
Parkstr. 14
13086 Berlin
Germany
Email: info(at)thegoldenhazel.com
​
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
​
2) Data Collection When Visiting Our Website
2.1 When using our website for informational purposes only, i.e. if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to the server (so-called “server log files”).
When you access our website, we collect the following data, which is technically necessary to display the website to you:
-
Website visited
-
Date and time of access
-
Amount of data transmitted (in bytes)
-
Source/referrer from which you reached the page
-
Browser used
-
Operating system used
-
IP address (if applicable, in anonymized form)
The processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.
​
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.
​
3) Hosting & Content Delivery Network
Wix
For hosting our website and displaying the page content, we use the system of the following provider:
Wix HQ, 6350671, Nemal Tel Aviv St 40, Tel Aviv-Yafo, Israel
Data may also be transferred to: Wix Inc., 500 Terry A. Francois Boulevard, San Francisco, CA 94158, USA
All data collected on our website is processed on the provider’s servers. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors’ data and prohibits unauthorized disclosure to third parties.
​
For data transfers to the provider’s location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision of the European Commission.
​
4) Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies. Cookies are small text files that are stored on your device. Some cookies are deleted automatically after closing your browser (“session cookies”), while others remain on your device for a longer period and allow saving of site settings (“persistent cookies”). You can find the storage duration in the overview of your browser’s cookie settings.
​
If personal data is processed through individual cookies used by us, processing is carried out in accordance with Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(a) GDPR if consent has been given, or Art. 6(1)(f) GDPR to safeguard our legitimate interests in optimal website functionality and a user-friendly design.
You can configure your browser to inform you about the setting of cookies and decide individually on their acceptance or exclude the acceptance of cookies in general.
​
Please note that if cookies are not accepted, the functionality of our website may be limited.
​
5) Contacting Us
When contacting us (e.g. via contact form or email), personal data is collected. The data collected when using a contact form can be seen from the respective form.
This data is used exclusively for the purpose of responding to your inquiry and for the associated technical administration.
​
The legal basis for processing is our legitimate interest in responding to your inquiry pursuant to Art. 6(1)(f) GDPR. If your inquiry aims at concluding a contract, Art. 6(1)(b) GDPR is an additional legal basis.
Your data will be deleted after final processing of your request, provided that there are no statutory retention obligations.
​
6) Use of Customer Data for Direct Advertising
6.1 Newsletter Subscription
If you subscribe to our email newsletter, we will regularly send you information about our offers. Only your email address is mandatory for receiving the newsletter. Additional information is voluntary and used to address you personally.
We use the double opt-in procedure. This means that you will only receive newsletters after you have expressly confirmed your consent. You will receive a confirmation email asking you to confirm your subscription by clicking a link.
Upon activation, you give consent pursuant to Art. 6(1)(a) GDPR. We store the IP address and the date/time of subscription to prevent misuse.
You can unsubscribe at any time via the link in the newsletter or by contacting us. Your email address will then be deleted unless further use is legally permitted.
​
6.2 Newsletter Distribution via Brevo
The distribution of our newsletter is carried out using the delivery platform Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany). The data you provide (email address and, if provided, your name) is stored on Brevo’s servers within the European Union. The processing is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR. We have entered into a data processing agreement with Brevo to ensure the protection of your data.
​
7) Website Functionalities
7.1 YouTube Video Integration
This website uses plugins from:
Google Ireland Limited, Dublin, Ireland
Data may be transferred to Google LLC, USA
When you play a video, a connection to Google servers is established. Information such as your IP address may be transmitted. Cookies may be set to collect usage statistics.
All processing occurs only with your explicit consent pursuant to Art. 6(1)(a) GDPR, which can be revoked via the cookie consent tool.
​
7.2 Google reCAPTCHA
Provider: Google Ireland Limited, Dublin, Ireland
Data may be transferred to Google LLC, USA
reCAPTCHA is used to determine whether entries are made by humans or bots. IP address, browser data, date and duration of visit may be processed.
Processing occurs based on consent (Art. 6(1)(a) GDPR) or legitimate interest (Art. 6(1)(f) GDPR).
​
7.3 Appointment Scheduling (TidyCal.com)
For scheduling appointments and discovery calls, we use the service TidyCal.
Provider: Sumo Group Inc., 1645 E 6th St. Suite 125, Austin, TX 78702, USA.
When you book an appointment via TidyCal, personal data such as your name, email address, appointment details, and any information you voluntarily provide is processed for the purpose of organizing and conducting the appointment.
The processing is carried out for the performance of pre-contractual measures or the fulfillment of a contract in accordance with Art. 6 (1) lit. b GDPR.
We have concluded a data processing agreement with the provider.
For data transfers to the USA, the provider relies on appropriate safeguards, including participation in the EU-US Data Privacy Framework.
Further information on data protection at Cal.com can be found at:
https://tidycal.com/privacy-policy
​
7.4 Video Conferences and Online Meetings (Google Meet & Zoom)
To conduct online meetings, coaching sessions, and consultations, we use external video conferencing services. The use of these services takes place outside our website and requires a prior appointment.
Google Meet
Provider:
Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
Data may be transferred to: Google LLC, USA
Zoom
Provider:
Zoom Video Communications, Inc., 55 Almaden Blvd, Suite 600, San Jose, CA 95113, USA
​
When participating in online meetings, personal data of participants may be processed. This includes in particular:
-
Name
-
Email address
-
Meeting metadata (e.g. date, time, duration)
-
IP address
-
Audio, video and chat data (if used)
The processing is carried out for the performance of a contract or pre-contractual measures in accordance with Art. 6 (1) lit. b GDPR.
We have concluded data processing agreements with the providers where required.
For data transfers to the USA, the providers rely on appropriate safeguards, including participation in the EU-US Data Privacy Framework, where applicable.
These services are used exclusively after a prior appointment and are not integrated into this website.
​
7.5 Automation via Zapier
To facilitate the transfer of your registration data from our Wix forms to our newsletter tool, we use the service Zapier (Zapier Inc., 548 Market St. #62411, San Francisco, CA 94104, USA). In this process, your email address and name are transmitted to Zapier. The provider is certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection. We have concluded a data processing agreement with Zapier.
​​
8) Cookie Consent Tool
This website uses a cookie consent tool to obtain legally valid consent for cookies and cookie-based applications. Technically necessary cookies are used to store preferences.
Processing is based on Art. 6(1)(f) GDPR and Art. 6(1)(c) GDPR.
​
9) Rights of the Data Subject
You have the following rights under GDPR:
-
Right of access (Art. 15)
-
Right to rectification (Art. 16)
-
Right to erasure (Art. 17)
-
Right to restriction (Art. 18)
-
Right to notification (Art. 19)
-
Right to data portability (Art. 20)
-
Right to withdraw consent (Art. 7(3))
-
Right to lodge a complaint (Art. 77)
Right to Object
If processing is based on legitimate interests, you may object at any time. Processing for direct marketing will cease upon objection.
​
10) Duration of Storage
Personal data is stored for the duration of the respective legal basis (e.g., statutory retention periods) or until the purpose of processing no longer applies or consent is withdrawn.