Privacy Policy
Information pursuant to GDPR
The protection of your personal data is important to us. This privacy policy informs you pursuant to Art. 13 GDPR about how we handle your personal data.
Controller (Art. 13 para. 1 lit. a GDPR)
The controller within the meaning of the GDPR is: Kester von Gerlach, reachable at kester@von-gerlach.com. This website is a private, non-commercial family website and is not operated commercially.
Data Collected and Purpose of Processing
We collect and process only the data necessary for operating the family website: email address and name upon registration, as well as optional profile information (photo, biography). Data is not shared with third parties and is not used for commercial purposes.
Legal Basis for Processing (Art. 6 GDPR)
The processing of your data is based on Art. 6 para. 1 lit. b GDPR (performance of a contract or pre-contractual measures) for account management and access to the members area, and on Art. 6 para. 1 lit. f GDPR (legitimate interests) for the operation and security of the website.
Hosting and Data Processing Agreement
This website is hosted by Vercel Inc. (340 Pine Street, Suite 701, San Francisco, CA 94104, USA). The database and authentication run on Supabase (Supabase Inc., San Francisco, USA). Both providers process data under a data processing agreement pursuant to Art. 28 GDPR and offer standard contractual clauses for transfers to the USA.
Your Rights as a Data Subject
Under the GDPR, you have the following rights. To exercise them, please contact kester@von-gerlach.com:
- Art. 15Right of access – You may request information about the personal data stored about you at any time (Art. 15 GDPR).
- Art. 16Right to rectification – You may request the correction of inaccurate or incomplete data (Art. 16 GDPR).
- Art. 17Right to erasure – Under certain conditions, you may request the deletion of your data (Art. 17 GDPR).
- Art. 18Right to restriction of processing – You may request restriction of processing where certain conditions apply (Art. 18 GDPR).
- Art. 20Right to data portability – You have the right to receive your data in a structured, commonly used, machine-readable format and to transfer it to another controller (Art. 20 GDPR).
- Art. 21Right to object – You may object at any time to the processing of your data that is based on a legitimate interest (Art. 6 para. 1 lit. f GDPR) (Art. 21 GDPR).
- Art. 77Right to lodge a complaint – You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority can be found at: https://www.bfdi.bund.de
For all enquiries regarding your rights: kester@von-gerlach.com – We respond within 30 days.
Cookies and Session Management
This website uses only technically necessary cookies for session management. No tracking, analytics, or marketing cookies are used. Technically necessary cookies are exempt from the consent requirement pursuant to § 25 para. 2 TTDSG.
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract) in conjunction with § 25 para. 2 no. 2 TTDSG. This cookie is technically required for the secure operation of the login area. As of: May 2025.