Privacy policy
What data is processed when you visit this website — why, for how long, and what rights you have.
This is a convenience translation. In case of any discrepancy, the German version at hartleb.consulting/datenschutz prevails.
With this privacy policy I explain how your personal data is processed when you visit this website hartleb.consulting and when you contact me by email or through the contact form.
I. Definitions
This privacy policy is based on the GDPR and is meant to be readable. First, the central terms:
1. Personal data is any information relating to an identified or identifiable natural person — directly (e.g. name, email address) or indirectly (e.g. IP address, online identifier) (Art. 4 (1) GDPR).
2. Processing is any operation performed on personal data, from collection and storage through to erasure (Art. 4 (2) GDPR).
3. Controller is the person or body that determines the purposes and means of processing — in this case Ralf Hartleb (see II.) (Art. 4 (7) GDPR).
4. Processor is a body that processes personal data on my behalf — in this case the hosting and analytics providers with whom corresponding contracts exist (Art. 4 (8) GDPR).
5. Consent is a freely given, informed and unambiguous indication of your wishes by which you agree to the processing of your data for a specific purpose (Art. 4 (11) GDPR).
II. Controller
The controller for data processing within the meaning of the GDPR is:
Ralf Hartleb
RHM-Beratung
Bogenstrasse 16 b
93051 Regensburg
Germany
Email: ralf@hartleb.consulting
Within RHM-Beratung, in addition to the controller, permanently employed staff (currently two people) also have access to personal data in the course of their professional duties — for example to answer enquiries, coordinate appointments, or provide cover during illness or holidays. All staff are bound to confidentiality pursuant to Art. 29 GDPR and are trained accordingly. Given the size of the company, there is currently no legal obligation to appoint a data protection officer under section 38 BDSG; for data protection questions, please contact the email address above directly.
III. Collection and storage of personal data, and the nature and purpose of its use
1. When visiting the website
When you call up this website, your browser automatically sends general information to the server. This transmission happens automatically and is part of how devices communicate on the internet.
The following is collected by default:
- IP address
- date and time of access
- name and URL of the file retrieved
- volume of data transferred
- browser type and version (user agent)
- operating system
- referring website (referrer)
This data is stored in server log files. It makes it possible to detect errors, monitor the load on the website and ensure the security of the server. It is not merged with other data sources, and no personal identification is carried out on the basis of this information.
The legal basis is Art. 6 (1) sentence 1 (f) GDPR (legitimate interest in the operation and security of the website). The data is stored for a limited period (max. 7 days) and then deleted.
2. When contacting me by email or contact form
If you contact me by email or through the contact form on the “Clarity Call” page, the data you provide (name, email address, role or company where applicable, and your request) is stored solely in order to process your enquiry.
The contact form on hartleb.consulting works without server-side processing — on submission it opens your local email program directly and sends the enquiry to me as an email. No data is therefore cached on third-party servers.
The legal basis is Art. 6 (1) sentence 1 (b) GDPR (pre-contractual measures) or (f) GDPR (legitimate interest in answering your enquiry). Where necessary, I process your data beyond handling the enquiry in order to safeguard legitimate interests (e.g. asserting legal claims).
Your data is deleted as soon as it is no longer required for the purpose for which it was collected and no statutory retention obligations prevent this.
3. Audience measurement with Plausible Analytics
This website uses the web analytics service Plausible Analytics for statistical evaluation of visitor access. The provider is Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible processes the data exclusively on servers within the European Union (Frankfurt, Germany).
Plausible sets no cookies and collects no personal data. No IP addresses are stored (they are only briefly converted into a hash for aggregation), no device fingerprint is created and no recognisable visitor profiles are built. The anonymised access data allows conclusions such as which pages were visited, time spent, approximate origin (country or region) and referral source (e.g. LinkedIn, a search engine).
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in privacy-friendly audience measurement). A consent banner is not required, since Plausible neither sets cookies nor processes personal data.
4. Appointment booking via Cal.eu (the EU variant of Cal.com)
The “Clarity Call” page contains a button linking to Cal.eu — the variant of the booking service Cal.com hosted in the European Union. Cal.eu is deliberately not embedded automatically in the page. Data is only transmitted to Cal.eu once you actively click the button. If you leave the page without clicking, you leave no trace at Cal.eu.
If you click the button, the booking page opens at Cal.eu in a new tab. There, technical connection data (IP address, browser information, date and time) is processed and — if you complete a booking — the data entered in the form (typically name, email address and your request). This data is used solely to arrange and hold the appointment and is transferred into the calendar I keep (Microsoft 365 / Outlook).
The provider is Cal.com, Inc., 2261 Market Street #4858, San Francisco, CA 94114, USA — operator of the EU infrastructure under the Cal.eu brand. All data processed in the course of a booking remains physically on servers within the EU. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures). A data processing agreement pursuant to Art. 28 GDPR is in place with Cal.com, Inc. Since processing via Cal.eu takes place exclusively on EU servers, no third-country transfer to the USA is required for the data processed during booking.
If you would rather not book online, you can contact me by email at any time — see section III.2.
5. Cookies
This website deliberately uses no cookies — neither technically necessary ones (in the narrower sense) nor tracking or advertising cookies. A cookie consent banner is therefore not required.
Should tools that set cookies be added in future, a consent banner will be integrated beforehand and this privacy policy amended accordingly.
6. Hosting provider: Netlify
This website is hosted by Netlify, Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA. When the website is called up, Netlify processes technically necessary data (see section III.1 above) in order to deliver the content and protect against attacks.
Netlify is certified under the EU-US Data Privacy Framework (DPF) and thereby commits to complying with European data protection standards. In addition, the data transfer is based on the EU standard contractual clauses. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Netlify (through Netlify's standard terms).
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the stable, secure operation of the website).
7. Fonts
This website uses the typeface Inter. It is served exclusively from my own server and is not embedded from an external provider. When a page is called up, no data — in particular no IP address — is therefore transmitted to Google or any other third party.
The font files are stored locally in the directory /assets/fonts/ and are licensed under the SIL Open Font License.
8. Links to external services
This website links to external pages (LinkedIn, Detego, Avance Group, ti communication, Regensburger Business Institut, hartleb.coach, Cal.eu and possibly others). When you click these links you leave this website; the privacy policies of the respective providers apply there.
IV. Disclosure of data
Your personal data is not transferred to third parties for purposes other than those stated above. Disclosure only takes place if:
- you have given your express consent pursuant to Art. 6 (1) sentence 1 (a) GDPR,
- disclosure pursuant to Art. 6 (1) sentence 1 (f) GDPR is necessary for the establishment, exercise or defence of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in your data not being disclosed,
- there is a legal obligation to disclose pursuant to Art. 6 (1) sentence 1 (c) GDPR, or
- this is legally permissible and necessary pursuant to Art. 6 (1) sentence 1 (b) GDPR for the performance of contractual relationships with you.
V. Retention period
Personal data is stored for as long as this is necessary to fulfil the purposes described above. Once the data is no longer required to fulfil contractual or statutory obligations, it is deleted as a matter of routine — unless its temporary further processing is necessary to comply with commercial and tax retention obligations (as a rule two to ten years pursuant to section 257 HGB and section 147 AO) or to preserve evidence within the statutory limitation periods (regular limitation period three years, in exceptional cases up to 30 years pursuant to sections 195 ff. BGB).
VI. Data security
This website uses the widely established TLS procedure (Transport Layer Security, formerly SSL) together with the highest level of encryption supported by your browser. You can tell whether an individual page is transmitted in encrypted form by the padlock symbol in your browser's address bar and by the “https://” prefix in the URL.
In addition, appropriate technical and organisational security measures are used to protect your data against manipulation, loss, destruction or unauthorised access. These measures are continuously improved in line with technological developments. In concrete terms, they include HTTP security headers (HSTS, X-Frame-Options, Content-Security-Policy, Referrer-Policy), a restrictive permissions policy and a modern cross-origin protection concept.
VII. Your rights as a data subject
You have the right:
- pursuant to Art. 15 GDPR to request information about the personal data I process about you — in particular the purposes of processing, the categories of data, recipients, the storage period, the existence of a right to rectification, erasure, restriction or objection, and the existence of a right to lodge a complaint;
- pursuant to Art. 16 GDPR to request without undue delay the rectification of inaccurate personal data or the completion of your stored personal data;
- pursuant to Art. 17 GDPR to request the erasure of your stored personal data, unless processing is necessary for the exercise of the right to freedom of expression, for compliance with a legal obligation, for reasons of public interest or for the establishment of legal claims;
- pursuant to Art. 18 GDPR to request the restriction of processing;
- pursuant to Art. 20 GDPR to receive your personal data in a structured, commonly used and machine-readable format, or to request its transmission to another controller;
- pursuant to Art. 7 (3) GDPR to withdraw consent you have given at any time — processing based on that consent may then no longer be continued for the future;
- pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority — usually the authority of your habitual residence or place of work, or of my registered office (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA, Promenade 18, 91522 Ansbach, Germany).
VIII. Right to object
Where your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) sentence 1 (f) GDPR, you have the right under Art. 21 GDPR to object to that processing, insofar as there are grounds arising from your particular situation. If the objection is directed against direct marketing, you have a general right to object which is implemented without any particular situation having to be stated.
If you wish to exercise your right of withdrawal or objection, an email to ralf@hartleb.consulting is sufficient.
IX. Validity and changes to this privacy policy
This privacy policy is currently valid and dated September 2026. As the website develops or legal and regulatory requirements change, it may become necessary to amend it. The current version can be accessed at any time on this website at hartleb.consulting/en/privacy.
This privacy policy follows the structure of best-practice templates by LiiDU GmbH (Rechtsanwältin Sabine Sobola, Regensburg) and is tailored to the specific setup of this website. It does not replace individual legal advice in a particular case.