Privacy Policy

Last updated: October 7, 2026

1. Introduction and Controller

This Privacy Policy explains how personal data is collected, used and protected when you visit studio.golbasi.de (the “Website”), including all of its sub-pages. It applies to the Website itself and to the features, plugins, widgets and embedded content described below.

The controller responsible for data processing on this Website within the meaning of the EU General Data Protection Regulation (“GDPR”) is:

[FULL NAME / BUSINESS NAME] [STREET AND HOUSE NUMBER] [POSTAL CODE] [CITY], Germany Email: [EMAIL ADDRESS] Phone (optional): [PHONE NUMBER]

Further details are available in the Imprint.

Data protection officer: [A data protection officer has not been appointed because this is not legally required. / Contact details of the data protection officer: NAME, EMAIL]

2. Overview and Legal Bases

We process personal data only where this is permitted by law. Depending on the purpose, we rely on the following legal bases:

  • Consent, Art. 6(1)(a) GDPR. This applies, for example, to analytics, marketing and external embedded media. Where information is stored on or read from your device (e.g. cookies), the additional legal basis is Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
  • Performance of a contract or pre-contractual measures, Art. 6(1)(b) GDPR.
  • Legal obligation, Art. 6(1)(c) GDPR.
  • Legitimate interests, Art. 6(1)(f) GDPR. Our legitimate interests are the secure, stable and efficient operation of the Website, the presentation of my music and the ability to communicate with visitors. Where cookies or similar technologies are strictly necessary to provide a service you requested, Section 25(2) No. 2 TDDDG applies.

This Website is a personal, non-commercial music showcase. Some features may nevertheless involve data processing as described below.

3. Hosting and Server Log Files

This Website is hosted by:

[HOSTING PROVIDER NAME AND ADDRESS]

When you visit the Website, the hosting provider’s servers automatically record technical data in server log files. This typically includes:

  • IP address (shortened or in full, depending on the provider)
  • date and time of the request
  • requested page or file and the amount of data transferred
  • HTTP status code
  • referrer URL (the page you came from)
  • browser type, browser version and operating system

This processing is necessary to deliver the Website, to ensure its stability and security, and to detect and defend against attacks. The legal basis is Art. 6(1)(f) GDPR. Log files are stored for [NUMBER] days and are then deleted or anonymized, unless longer storage is required for evidence in the event of a security incident.

We have concluded a data processing agreement (Art. 28 GDPR) with the hosting provider. [Servers are located in Germany / the EU. / ADJUST AS APPLICABLE]

4. Cookies, Local Storage and Consent Management

The Website uses cookies and similar technologies (such as local storage and pixels). Cookies are small files stored on your device. Some are strictly necessary; others are used only if you consent.

We use a consent management tool (Complianz or a comparable consent plugin) to ask for your consent when you first visit the Website. You can choose between the following categories:

  • Functional: strictly necessary for the operation of the Website (for example, storing your consent choices, security functions, the CAPTCHA). Always active. Legal basis: Section 25(2) TDDDG and Art. 6(1)(f) GDPR.
  • Preferences: store settings you have chosen. Only with your consent.
  • Statistics: help us understand how the Website is used. Only with your consent.
  • Marketing / external media: load content and tracking technologies from third parties, such as video and music players or social media content. Only with your consent.

Your consent choice is stored in a cookie so that we do not have to ask you again on every visit. To prove that consent was given, the tool may also store your anonymized or shortened IP address, the time of consent and the consent version. This is done on the basis of Art. 6(1)(c) and (f) GDPR (accountability, Art. 5(2) GDPR).

Withdrawing or changing consent: You can change or withdraw your consent at any time with effect for the future via the “Manage consent” button on the Website (usually at the bottom left or in the footer). You can also delete cookies in your browser settings at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

5. Contact Form

If you use the contact form, we process the data you enter: your name, email address and message, plus the date and time of your submission and technical data needed to prevent abuse (for example, your IP address). By ticking the consent checkbox you confirm that you have read this Privacy Policy.

The form is built with the WordPress plugin Contact Form 7. The data is used only to process and answer your enquiry and for follow-up questions. Legal basis: Art. 6(1)(b) GDPR if your enquiry relates to a contract or pre-contractual measures; otherwise Art. 6(1)(f) GDPR (our interest in answering enquiries) or, where you have given it, Art. 6(1)(a) GDPR.

We delete your enquiry once it has been dealt with and there is no further need to keep it, unless statutory retention obligations apply. As a rule this is [NUMBER] months after the last communication.

The form may be delivered by email through [MAIL PROVIDER / SMTP SERVICE]. Emails are transmitted over the internet and may not be protected against access by third parties unless transport encryption is used.

6. CAPTCHA / Spam Protection

To protect the contact form (and, where applicable, the comment function) against automated spam, we use a CAPTCHA plugin (“Captcha for Contact Form 7” or a comparable solution). You are asked to enter characters shown in an image or to solve a simple challenge.

The plugin works on our own server and does not, to our knowledge, transmit data to third-party CAPTCHA providers. It may set a technical cookie or session value and process your IP address and the CAPTCHA result for a short time. Legal basis: Art. 6(1)(f) GDPR (protection against spam and abuse), Section 25(2) No. 2 TDDDG where applicable.

[If you additionally use Google reCAPTCHA, Cloudflare Turnstile, hCaptcha or Akismet, add the corresponding provider here and list it as an external service requiring consent.]

7. Comments

Visitors may leave comments on posts and pages of this Website. When you submit a comment, we process:

  • the comment text,
  • the name or pseudonym you enter,
  • your email address (not published),
  • optionally your website URL,
  • the date and time of the comment,
  • your IP address and your browser’s user agent string (which WordPress stores to combat spam and abuse).

Cookie consent for comments: WordPress offers a checkbox allowing you to save your name, email address and website in a cookie so that you do not need to re-enter them next time. This cookie is stored for up to one year and only if you tick the checkbox.

Publication: Your comment, name and the time of posting are publicly visible. Please do not publish sensitive personal data and consider using a pseudonym.

Moderation and spam checks: Comments may be held for moderation before they appear. Where a spam filter such as Akismet is used, comment data (including IP address and email address) may be sent to the service provider for spam analysis. [CONFIRM OR DELETE: Akismet is operated by Automattic Inc., USA.]

Subscriptions: Where a function exists to be notified of follow-up comments, we process your email address for this purpose only and only after you have confirmed your subscription (double opt-in). You can unsubscribe at any time using the link in each notification email.

Legal basis: Art. 6(1)(a) GDPR (your consent when submitting the comment) and Art. 6(1)(f) GDPR (our interest in preventing abuse and in being able to defend ourselves if a comment violates third-party rights; in such cases we may be liable ourselves).

Storage period: Comments and associated data remain stored until the comment is deleted, the underlying post is removed, or you ask us to delete them. IP addresses are deleted or anonymized after [NUMBER] days. We may remove comments that are unlawful, abusive or off-topic.

Your options: You can request deletion or correction of your comment at any time by emailing [EMAIL ADDRESS], stating the page and approximate time of your comment so that we can identify it.

8. Gravatar

WordPress can display a profile image (avatar) next to comments using the service Gravatar, operated by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. To check whether an avatar exists, a one-way hash (an irreversible encoded value) of your email address may be sent to Gravatar. Your IP address is also transferred when your browser loads the image. Gravatar is only used if you have consented to external media or if avatars are disabled by default on this Website. [ADJUST: delete this section if avatars are disabled.]

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG. More information: https://automattic.com/privacy/

9. Website Search

If you use the search function, we process your search terms together with technical data such as your IP address in order to show you the results. Search terms are not linked to your person and are not used to create profiles. Legal basis: Art. 6(1)(f) GDPR.

10. Web Analytics: Google Site Kit, Google Analytics and Google Search Console

This Website uses the WordPress plugin Site Kit by Google, which connects the Website to Google services. Depending on the configuration, these include Google Analytics 4, Google Search Console and potentially Google Tag Manager, AdSense or PageSpeed Insights. The provider for users in the EEA, the UK and Switzerland is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The parent company is Google LLC, USA.

Google Analytics helps us understand how visitors use the Website, for example which pages are viewed, how long visitors stay, from which country they come and which devices they use. For this purpose, cookies or similar identifiers are placed in your browser and the following data may be processed: pseudonymous user IDs, IP address (in Google Analytics 4 IP addresses are not logged or stored), approximate location, pages viewed, interactions, referrer, device and browser information, and session duration.

Analytics is only activated after you consent through the consent banner. Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG. [If consent mode is used: before consent is given, data may be processed in a limited, cookieless way without identifiers. ADJUST TO YOUR SETTINGS.]

Google Search Console is a service for site owners. It analyzes how the Website appears in Google Search and does not place cookies or collect data from you as a visitor on the Website itself.

Data retention: Analytics data on the user and event level is retained for [2 / 14] months and then automatically deleted. [ADJUST TO YOUR GOOGLE ANALYTICS SETTINGS.]

Data transfer to third countries: Data may be transferred to the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (“DPF”), for which the European Commission has adopted an adequacy decision. In addition, Standard Contractual Clauses may apply.

We have concluded a data processing agreement with Google. More information: https://policies.google.com/privacy and https://business.safety.google/adsprocessorterms/

11. Social Sharing Buttons: AddToAny

The Website uses AddToAny Share Buttons, operated by AddToAny LLC, USA, so that you can easily share content via services such as WhatsApp, Facebook Messenger, Telegram, email, Facebook, Threads, X (formerly Twitter) and others, or copy the link.

The buttons are links. When you click one, you are forwarded to the respective service (or your email program or app opens) and the page address and title are transmitted to that service. The respective provider then processes your data under its own privacy policy and as an independent controller. Depending on the technical implementation, AddToAny may load a script from its servers, which may transmit your IP address and browser data to AddToAny. [ADJUST TO SETTINGS: this script is only loaded after consent.]

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG where scripts are loaded; otherwise Art. 6(1)(f) GDPR. More information: https://www.addtoany.com/privacy

12. Embedded Third-Party Media and Content

The Website is a showcase for my music and creative work. For that reason it embeds a wide range of external audio, video, social media and other content. This chapter explains how such embeds work in general (12.1) and then lists the providers that may be embedded (12.2 to 12.9).

12.1 General information on embedded content

When a page contains an embed, your browser establishes a direct connection to the servers of the respective provider to load the content (for example a video, a music player or a post). In doing so, the provider receives at least your IP address, the URL of the page you are visiting, the date and time, and information about your browser and device. Providers may also store or read cookies, device identifiers, local storage entries or pixels on your device, may recognize you across websites, and may link the data with your account if you are logged into that provider at the same time. Providers often use such data for their own purposes, including analytics, personalized advertising and profiling. We have no influence on this processing.

To the extent that the embedding technique allows, the content is only loaded after you have given your consent (for example through the consent banner or by clicking a “load content” placeholder). Until then, no connection to the provider is established and no data is transferred to it. Where several embeds of the same provider are on a page, a single consent for that provider may apply to all of them.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent). You can withdraw your consent at any time with effect for the future via “Manage consent”.

Responsibility: Where we embed content, we and the provider may be jointly responsible for the collection and transmission of data to the provider (Art. 26 GDPR; see the decision of the Court of Justice of the European Union in Case C-40/17, “Fashion ID”). We are not responsible for the provider’s subsequent processing. The respective providers act as independent controllers for this.

Third-country transfers: Many providers are located in or have group companies or processors in the USA or other countries outside the EU/EEA. Where this applies, the transfer rests on your consent (Art. 49(1)(a) GDPR), an adequacy decision such as the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses (Art. 46 GDPR). Please note the risks described in Section 20.

12.2 Video platforms

YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We embed YouTube videos. Where possible we use the extended data protection mode (youtube-nocookie.com), in which YouTube sets cookies only when you start playing a video. Even then, data such as your IP address and your interactions may be transmitted. If you are logged into a Google account, YouTube may attribute your viewing behavior directly to your personal profile. Privacy policy: https://policies.google.com/privacy

Vimeo (Vimeo.com, Inc., USA). Vimeo may set cookies, collect your IP address and analyze your viewing behavior. Where available, we use the “Do Not Track” setting to limit tracking. Privacy policy: https://vimeo.com/privacy

Twitch (Twitch Interactive, Inc., USA, a company of the Amazon group). Embedded streams or clips may set cookies and transmit data to Twitch. Privacy notice: https://www.twitch.tv/p/legal/privacy-notice/

Dailymotion (Dailymotion S.A., France). Privacy policy: https://legal.dailymotion.com/en/privacy-policy/

12.3 Music streaming and audio platforms

Spotify (Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden). We embed Spotify players for tracks, albums, playlists and podcasts. When the player is loaded, Spotify receives your IP address and the page you are on, and may set cookies. If you are logged into Spotify, your visit may be linked to your account. Privacy policy: https://www.spotify.com/legal/privacy-policy/

SoundCloud (SoundCloud Global Limited & Co. KG, Rheinsberger Str. 76/77, 10115 Berlin, Germany). SoundCloud players may set cookies and process your IP address, device data and listening behavior, including for advertising purposes. Privacy policy: https://soundcloud.com/pages/privacy

Apple Music (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland). Embedded Apple Music players load content from Apple servers, which receive your IP address and device information. Privacy policy: https://www.apple.com/legal/privacy/

Bandcamp (Bandcamp, Inc., USA). Embedded Bandcamp players transmit your IP address and may set cookies. Privacy policy: https://bandcamp.com/privacy

Mixcloud (Mixcloud Ltd., United Kingdom). Privacy policy: https://www.mixcloud.com/privacy/

Deezer (Deezer S.A., France). Privacy policy: https://www.deezer.com/legal/personal-datas

TIDAL (Tidal Music AS and affiliated companies). Privacy policy: https://tidal.com/privacy

Amazon Music (Amazon Europe Core S.à r.l., Luxembourg, and affiliated companies). Privacy notice: https://www.amazon.com/privacy

Audiomack, Beatport and similar music platforms. Where a player or link to another music service is embedded, the same principles of Section 12.1 apply, and the privacy policy of the respective service applies.

12.4 Social media posts and profiles

Embedded posts, feeds and share widgets from social networks cause your browser to connect to the network and transmit data as described in Section 12.1. These networks may also use your data for advertising and profiling.

  • Instagram and Facebook (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland). https://www.facebook.com/privacy/policy/
  • Threads (Meta Platforms Ireland Limited). https://help.instagram.com/515230437301944
  • X, formerly Twitter (X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland). https://x.com/en/privacy
  • TikTok (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland). https://www.tiktok.com/legal/page/eea/privacy-policy/en
  • Pinterest (Pinterest Europe Ltd., Dublin, Ireland). https://policy.pinterest.com/en/privacy-policy
  • LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland). https://www.linkedin.com/legal/privacy-policy
  • Bluesky, Mastodon and other decentralized networks. Embedded posts may load content from the servers of the respective instance or operator. Please refer to the privacy policy of the relevant operator.

We also link to our profiles on these networks. A simple link does not transmit data until you click it. When you click, the respective network may process your data in line with its own policy.

12.5 Support, donation and payment services

The Website may contain buttons or widgets that allow you to support the artist, for example through Buy Me a Coffee, Ko-fi, Patreon or PayPal. When you click or load such a widget, data such as your IP address and the page you came from may be transmitted. Payments themselves are processed solely by the respective payment or support provider, and we do not receive or store your payment card or bank details. We may receive limited information such as your name, the amount and a message you have chosen to include. The respective provider is an independent controller. For PayPal, the provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (https://www.paypal.com/webapps/mpp/ua/privacy-full). Please consult the privacy policies of Buy Me a Coffee (https://www.buymeacoffee.com/privacy-policy), Ko-fi (https://more.ko-fi.com/privacy) and Patreon (https://www.patreon.com/policy/privacy) as applicable.

If you make a payment or donation, the legal basis for our own processing is Art. 6(1)(b) GDPR (performance of a contract) and, for retention of records, Art. 6(1)(c) GDPR (tax and accounting obligations).

12.6 Maps, fonts and other technical resources

Google Maps (Google Ireland Limited). If we embed a map, your IP address and usage data are transmitted to Google. Privacy policy: https://policies.google.com/privacy

Google Fonts and other web fonts. We aim to host fonts locally on our own server so that no connection to Google is established. If fonts are loaded from Google or Adobe servers, your IP address is transmitted to the provider, and this occurs only with consent.

Content delivery networks (CDN) and script libraries such as cdnjs, jsDelivr or Cloudflare. If used, they receive your IP address in order to deliver files faster. Legal basis: Art. 6(1)(f) GDPR (efficient and secure delivery of the Website).

WordPress emojis, oEmbed and Gravatar. WordPress core functions can load emoji graphics or embed links to other WordPress sites. Where these load data from external servers, they are covered by the principles in Section 12.1.

12.7 Link-in-bio services, newsletters and other tools

If the Website uses or links to services such as Linktree, Mailchimp, MailerLite, Brevo or similar tools, your data is processed by these providers when you use them. For newsletters, we send them only on the basis of your explicit consent (double opt-in), and you can unsubscribe at any time. [DELETE THIS SECTION IF NOT USED.]

12.8 Messenger and communication services

The sharing buttons for WhatsApp (WhatsApp Ireland Limited, Dublin, Ireland), Facebook Messenger (Meta Platforms Ireland Limited), Telegram (Telegram Messenger Inc. and affiliated companies) and email open the respective app or service when clicked. The privacy policy of the respective service applies from that point.

12.9 Further embeds and future additions

The range of available embeds is wide, and additional services may be added over time (for example further streaming platforms, ticketing services, livestream tools or social networks). Wherever such a service is added, the principles in Section 12.1 apply as a minimum standard, in particular the requirement of consent before external content is loaded. We will update this Privacy Policy when a new category of provider or purpose is introduced. You will always find the provider’s name at or near the embedded content, or in the consent management tool.

13. Links to External Websites

This Website contains links to external websites, including streaming platforms and social media profiles. We have no influence on the content or the data processing of these websites. When you click a link, you leave this Website and the privacy policy of the respective operator applies. We checked the linked pages for apparent legal violations at the time of linking but cannot monitor them continuously.

14. Plugins and Technical Components of the Website

The Website is built on WordPress. Core functions, themes and plugins process data in the manner described in this policy. Other plugins that serve purely technical purposes (for example caching, image optimization, security or backup plugins) may process your IP address and technical request data on our server. This is done on the basis of Art. 6(1)(f) GDPR to ensure the security and performance of the Website. [IF YOU USE A SECURITY PLUGIN SUCH AS WORDFENCE OR A CDN SUCH AS CLOUDFLARE, NAME IT HERE. THESE MAY TRANSFER DATA TO THIRD COUNTRIES.]

We do not use plugins to create user profiles for advertising purposes. If this changes, we will update this Privacy Policy and obtain your consent where required.

15. User Accounts

[ADJUST OR DELETE: Visitors cannot register on this Website. Accounts exist only for the administrator and any editors. If registration is enabled, describe the data collected (username, email address, password hash) and the retention period here.]

16. Recipients of Data

We pass personal data to third parties only if this is permitted by law, for example:

  • to service providers who process data on our behalf under a data processing agreement (hosting, email, security, analytics),
  • to the providers of embedded content and plugins described above, where you consented to their loading,
  • to authorities, courts or other third parties where we are legally obliged to do so, or where this is necessary to establish, exercise or defend legal claims.

We do not sell personal data.

17. Storage Periods

We store personal data only for as long as necessary for the respective purpose, or for as long as statutory retention periods require. Specific periods are stated in the relevant sections above. Data processed on the basis of consent is stored until you withdraw your consent, unless there is another legal reason for storing it. After the purpose has ceased, we delete or anonymize the data. Statutory retention periods under commercial and tax law (generally six or ten years) remain unaffected.

18. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects on you or similarly significantly affects you (Art. 22 GDPR). Third-party providers of embedded content may carry out profiling under their own responsibility. See Section 12.1.

19. Data Security

The Website uses SSL/TLS encryption (you can recognize this by “https://” and the lock symbol in your browser). We use technical and organizational measures to protect your data against loss, misuse and unauthorized access, and we review them regularly. Complete security of data transmitted over the internet cannot be guaranteed.

20. Data Transfers to Third Countries

Some of the providers described above are based in, or process data in, countries outside the European Economic Area, in particular the United States. These countries may not offer the same level of data protection as the EU. For the USA, the European Commission has adopted an adequacy decision (EU-U.S. Data Privacy Framework) covering certified companies. Where a provider is not certified or no adequacy decision applies, we rely on Standard Contractual Clauses or, for embeds that you actively activate, on your explicit consent (Art. 49(1)(a) GDPR).

Please note that, despite safeguards, authorities in the destination country (such as US intelligence agencies) may under certain conditions access data without effective legal remedies for the persons concerned. By consenting to external services, you accept this risk. You can avoid it by not giving consent.

21. Your Rights as a Data Subject

Under the GDPR you have the following rights with respect to your personal data:

  • Right of access (Art. 15 GDPR): you can request confirmation of whether we process your data, and a copy of it.
  • Right to rectification (Art. 16 GDPR): you can ask us to correct inaccurate data.
  • Right to erasure (Art. 17 GDPR): you can ask us to delete your data, for example if it is no longer necessary or if you withdraw consent.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR): you can receive data you provided in a structured, commonly used, machine-readable format.
  • Right to withdraw consent (Art. 7(3) GDPR): you can withdraw consent at any time with effect for the future.
  • Right to object (Art. 21 GDPR), see below.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR), see below.

To exercise your rights, please contact us at [EMAIL ADDRESS]. We may need to verify your identity first.

Right to object (Art. 21 GDPR)

If we process your data on the basis of Art. 6(1)(f) GDPR (legitimate interests), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.

Where personal data is processed for direct marketing, you have the right to object at any time, without giving reasons. We will then stop the processing for this purpose.

Right to lodge a complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. The supervisory authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg Lautenbachstraße 7, 70173 Stuttgart, Germany Website: https://www.baden-wuerttemberg.datenschutz.de

22. Children

This Website is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without the consent of a parent or guardian. If you believe that a child has provided us with personal data, please contact us and we will delete it.

23. Obligation to Provide Data

You are not obliged to provide personal data when visiting the Website. However, certain functions (such as the contact form or commenting) cannot be used without the data marked as required. Declining consent to external services means that the related content (for example an embedded video or music player) cannot be displayed. Where available, you can use the direct link to the respective platform instead.

24. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in the law, in the Website’s features or in the services used. The current version published on this page applies. Please check it regularly. The date of the last update is shown at the top.

25. Contact for Privacy Questions

If you have questions about data protection or this Privacy Policy, please contact:

[FULL NAME / BUSINESS NAME] [STREET AND HOUSE NUMBER] [POSTAL CODE] [CITY], Germany Email: [EMAIL ADDRESS]

Who we are

Suggested text: Our website address is: https://studio.golbasi.de.

Comments

Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

Suggested text: If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Suggested text: Visitor comments may be checked through an automated spam detection service.