Data Privacy Policy
Short version: MarketingSurfer.com uses no cookies and shows no consent banners. We measure aggregate site usage with Plausible Analytics, a cookieless, EU-hosted service that stores no personal data and cannot follow you across sites or days. When you contact us (email or contact form) or book an appointment (Microsoft Bookings, calls mostly via Teams), we use that information to answer your request and to schedule the conversation. A small number of carefully chosen service providers process data on our behalf: hosting by IONOS (Germany), contact-form email delivery by Resend (USA), scheduling by Microsoft. We never sell your data and never share it for advertising. You can request access to or deletion of your data at any time: company-info@marketingsurfer.com. The full policy follows below.
Terms of Service: All information on this website is provided with the best intention and knowledge, but without any guarantees. In case you find anything which is missing here, please be so kind and let us know so we can fix it, instead of getting us chased down by lawyers. We are nice, really.
Copyright: © Copyright 2026 MarketingSurfer.com. All rights reserved.
Privacy Policy - Full Text
Outline
- Controller
- Overview of processing
- Relevant legal bases
- Safety measures
- International data transfers
- General information on data storage and deletion
- Rights of data subjects
- Provision of the online offer and web hosting
- Web analytics (Plausible)
- Contact form and email delivery
- Appointment scheduling (Microsoft Bookings and Teams)
- Information for visitors outside the EU/EEA
Controller
Marketing Surfer GmbH, Gartenstraße 12a, 85521 Ottobrunn, Germany. Email: company-info@marketingsurfer.com. Full details: Imprint.
Overview of processing
The following overview summarises the types of data processed, the purposes of their processing, and the data subjects concerned.
Types of data processed: Contact details (e.g. name, email address, company); content data (e.g. messages sent via the contact form); usage data (e.g. pages visited, referrer, browser and device type, coarse location); meta, communication and procedural data (e.g. IP addresses, timestamps); appointment data (e.g. chosen time slot).
Categories of data subjects: Website visitors; prospects and clients; communication partners.
Purposes of processing: Provision of our online offer; answering contact requests and managing communication; scheduling and holding appointments; privacy-preserving, aggregate reach measurement; security measures; fulfilment of contractual and legal obligations.
Relevant legal bases
We process personal data on the following legal bases of the GDPR:
- Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) - processing necessary to perform a contract with you or to respond to your pre-contractual enquiries.
- Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) - processing necessary to comply with legal obligations, in particular statutory retention periods.
- Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) - processing necessary to protect our legitimate interests, e.g. the secure and stable operation of this website, answering enquiries, and privacy-preserving aggregate usage statistics, unless overridden by your interests, fundamental rights and freedoms.
In addition to the GDPR, German national rules apply, in particular the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG). This website sets no cookies and does not access information stored on your device, so no consent pursuant to Section 25 TDDDG is required.
Safety measures
In accordance with the legal requirements, and taking into account the state of the art, the implementation costs and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
Connections to this website are encrypted with TLS/SSL (HTTPS).
International data transfers
We process personal data primarily within the European Union. Where we use service providers in the USA, we do so in accordance with Chapter V of the GDPR: Resend (Plus Five Five, Inc.) and Microsoft Corporation are certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023), and we have concluded data processing agreements which include the EU standard contractual clauses as an additional safeguard. Details per provider are listed in the sections below.
General information on data storage and deletion
We delete personal data as soon as it is no longer required for its purpose and no other legal ground for the processing applies. Retention periods under German law include:
- 10 years - books and records, annual financial statements, inventories, management reports (sec. 147 AO, sec. 257 HGB)
- 8 years - accounting documents such as invoices and cost receipts
- 6 years - other business documents, received commercial letters, other documents important for taxation
- 3 years - data necessary to consider potential warranty and indemnity claims (secs. 195, 199 BGB)
Rights of data subjects
As a data subject, you have various rights under the GDPR (Art. 15 to 21 GDPR):
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6 para. 1 lit. f) GDPR.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
- Right of access: You have the right to confirmation as to whether data concerning you is processed and to access this data.
- Right to rectification: You have the right to request the completion or correction of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right to request that data concerning you be deleted or that its processing be restricted.
- Right to data portability: You have the right to receive data concerning you in a structured, commonly used and machine-readable format.
- Complaint to a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence or workplace. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Ansbach, Germany.
To exercise your rights, email company-info@marketingsurfer.com.
Provision of the online offer and web hosting
We process users' data in order to provide our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of this website to your browser or device. Server log files (requested resource, timestamp, IP address, user agent) are processed for security and stability.
1&1 IONOS: Provision of information technology infrastructure (hosting). Service provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; processing takes place in Germany. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Website: https://www.ionos.de; Privacy Policy: https://www.ionos.de/terms-gtc/terms-privacy.
Log file information is stored for a maximum period of 30 days and then deleted or anonymized.
Web analytics (Plausible)
We use Plausible Analytics to understand how this website is used in aggregate. Plausible is a privacy-first, cookieless analytics service provided by Plausible Insights OÜ, Tartu, Estonia; all analytics data is processed and stored within the EU.
Plausible sets no cookies and stores no persistent identifiers. We serve the measurement script from our own domain and relay the measurement events from our server to Plausible's EU infrastructure; this transmission includes your IP address and browser information. Plausible uses these only transiently: raw IP addresses and user-agent strings are never stored. Visits are counted using an identifier hashed with a salt that changes every day, so visitors cannot be recognised across days or across websites. Data points collected: visited page, referrer, browser and operating system, device type, and coarse location (country, region, city - derived from the IP address, which is then discarded).
Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) in privacy-preserving, aggregate measurement of the reach of our website. Because no cookies are set and no information stored on your device is accessed, no consent pursuant to Section 25 TDDDG is required. Plausible's data policy: https://plausible.io/data-policy.
Contact form and email delivery
When you contact us by email or via the contact form, we process the information you provide (name, email address, company (optional), message) to answer your request and for any follow-up questions. We use a hidden anti-spam field instead of cookies or captchas.
Contact-form messages are delivered to our mailbox by Resend (Plus Five Five, Inc., San Francisco, USA), acting as our processor. Resend is certified under the EU-US Data Privacy Framework, and its data processing agreement incorporates the EU standard contractual clauses. Resend privacy policy: https://resend.com/legal/privacy-policy.
Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) in efficient communication management. Contact data is deleted once your request is fully handled, unless statutory retention periods apply.
Appointment scheduling (Microsoft Bookings and Teams)
To book an appointment, our booking buttons take you to a Microsoft Bookings page operated by Microsoft (outlook.office.com) in a new tab; our own website does not transmit any of your data to Microsoft. The data you enter there (name, email address, chosen time slot, optional notes) is processed in our Microsoft 365 environment to schedule and hold the appointment; calls are usually held via Microsoft Teams.
Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, Dublin, Ireland, as our processor. Where data is transferred to Microsoft Corporation (USA), this is covered by Microsoft's certification under the EU-US Data Privacy Framework and the EU standard contractual clauses included in Microsoft's data protection addendum. Microsoft privacy statement: https://privacy.microsoft.com/en-us/privacystatement.
Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) in efficient appointment management.
Information for visitors outside the EU/EEA
We apply the standards of the GDPR to all visitors, regardless of where you are located. Your data is processed in the European Union and, to the extent described above, by our named service providers in the USA. We do not sell personal information and we do not share it for advertising or cross-context behavioural advertising purposes. The rights described in this policy are granted to all visitors worldwide; to exercise them, email company-info@marketingsurfer.com.