Privacy policy
Protecting your data matters to us. Here you can see which data we process, why, and which rights you have.
Note: This privacy policy is a prototype template. Before going live it should be reviewed by a lawyer and adapted to the actual processing activities.
1. Controller
The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Trepte Ventures UG (haftungsbeschränkt)
Rügenwalder Straße 24
22143 Hamburg
Germany
Owner / managing director: Robin Trepte
VAT ID: DE316938242
Register court: Amtsgericht Lübeck, HRA 9393 HL
Email: trepteventures(at)proton.me
2. Your rights under the GDPR
As a data subject you have the following rights against us at any time. An informal message to the email address above is enough to exercise them.
- Access (Art. 15 GDPR): You can request confirmation of whether and which personal data we process about you.
- Rectification (Art. 16 GDPR): You can request correction of inaccurate data or completion of your data.
- Erasure (Art. 17 GDPR): You can request deletion of your data unless statutory retention duties apply.
- Restriction (Art. 18 GDPR): You can request that processing of your data be restricted.
- Portability (Art. 20 GDPR): You can request that we provide your data in a structured, commonly used and machine-readable format.
- Objection (Art. 21 GDPR): You can object to processing based on our legitimate interests, on grounds relating to your particular situation.
- Complaint to a supervisory authority: You have the right to lodge a complaint about the processing of your data with a data-protection authority — for example the Hamburg Commissioner for Data Protection and Freedom of Information.
3. Data collected when you visit the site (server logs)
Each time you open our website, our hosting provider automatically collects information that your browser transmits and stores it in server log files. This includes in particular:
- anonymised or shortened IP address
- browser type and version, and the operating system used
- date and time of access (timestamp)
- page requested, referrer URL and volume of data transferred
This data is not combined with other data sources. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the technically error-free presentation, stability and security of our website.
4. Cookies and local storage
We use only technically necessary cookies and storage mechanisms. Tracking or marketing cookies are set only with your explicit consent (Art. 6 (1) (a) GDPR).
Your cart is stored only locally in your browser using localStorage. This data stays on your device, is not transmitted to us, and you can delete it at any time in your browser settings.
5. Orders and payment providers
When you buy an e-book from us, we process the data required to perform the contract — for example your email address so we can provide the instant download, and your payment and billing details. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).
To process the payment we pass the necessary data to the payment provider you choose, as recipient or processor. Depending on the method, that is:
- Stripe (card, Apple Pay, Google Pay)
- PayPal
- Klarna
- Apple Pay
- Google Pay
Payment providers process the data under their own responsibility and their own privacy policies. Your full payment details are not passed on to us.
6. Newsletter
If you want to subscribe to our newsletter, we need a valid email address from you. Sign-up uses double opt-in: after you register we send a confirmation email, and you actively confirm the subscription. That way nobody can sign up an address that is not theirs.
The legal basis is your consent under Art. 6 (1) (a) GDPR. You can withdraw that consent at any time with effect for the future, for example via the unsubscribe link at the end of every newsletter. Processing that happened before the withdrawal remains lawful.
7. Hosting
Our website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). Vercel processes, on our behalf, the data generated when the site is visited; a data-processing agreement under Art. 28 GDPR is in place.
This can involve a transfer of personal data to the USA (a third country). The transfer is safeguarded by the European Commission’s standard contractual clauses and additional measures.
8. SSL/TLS encryption
This site uses SSL or TLS encryption for security and to protect the transmission of confidential content. You can recognise an encrypted connection because the browser address bar changes from “http://” to “https://” and by the lock icon. While encryption is active, data you send us cannot be read by third parties.
9. Storage period
We store personal data only for as long as needed for the respective purposes, or for as long as statutory retention periods require. In concrete terms:
- Server log files are usually deleted or anonymised after 30 days at the latest.
- Invoice and order data are subject to commercial and tax retention periods (generally up to 10 years).
- Newsletter data is stored until you withdraw consent or unsubscribe.
When the relevant period ends, the data is deleted as a matter of routine.
10. Privacy contact
If you have questions about the processing of your personal data or about exercising your rights, you can contact us at any time:
Trepte Ventures UG (haftungsbeschränkt)
Rügenwalder Straße 24, 22143 Hamburg
Email: trepteventures(at)proton.me
Note: To avoid spam, we have replaced the “@” in our email address with “(at)”. Please use “@” again when you write to us.