We use both cookies for analytics and advertising. By clicking "Accept", you agree to our use of cookies. More info in our privacy policy
For impact-driven leaders & brands: Custom design that builds trust, authority & premium pricing.
The protection of your personal data is taken very seriously. This statement is intended to provide information on how personal data is processed, either alone or jointly with others, regarding the purposes and means of data processing. It is important to the controller to inform you as transparently as possible about the nature, scope, purpose, duration, and legal basis of data processing.
In order to make the privacy policy as understandable as possible for the reader, the legal terms used in this privacy policy are defined below.
All data through which you are identified or can be personally identified are considered personal data (“PD”) within the meaning of Art. 4 No. 1 of the General Data Protection Regulation (GDPR). It is sufficient if the data have been pseudonymized but could be linked to an identifiable individual by adding supplementary information. Completely anonymized data do not constitute personal data.
Processing within the meaning of Art. 4 No. 2 GDPR includes any automated operation performed on personal data, whether in virtual (digital) or physical (analog) form. This covers all types of processing—collection, storage, modification, disclosure, or deletion. The term is deliberately broad and covers almost every action involving your personal data.
A natural or legal person, authority, institution, or other body that alone or jointly with others determines the purposes and means of processing personal data is deemed the controller under the GDPR.
Any natural or legal person, authority, institution, or other body other than the data subject, the controller, the processor, and those authorized to process personal data under the direct authority of the controller or processor, is considered a third party as defined by Art. 4 No. 10 GDPR.
A natural or legal person, authority, institution, or other body that processes personal data on behalf of the controller—particularly according to the controller’s instructions (e.g., an IT service provider)—is a processor within the meaning of Art. 4 No. 8 GDPR. Legally, a processor is not a third party.
Consent is deemed to exist when an action clearly indicates that the data subject voluntarily, for a specific purpose, in an informed manner, and unequivocally agrees to the processing of their data.
Your personal data are processed only within the legal framework of the GDPR and other applicable national and international data-protection laws. The controller processes personal data solely when a lawful basis exists.
If you have expressly granted consent to the processing of your data, those data may be used for the stated purpose.
When processing your data is required to fulfill a contract concluded with us, your data may be processed accordingly. This also includes data processed for pre-contractual steps, such as contact information exchanged during contract initiation.
If a statutory obligation governs how data must be processed, processing is carried out in accordance with Art. 6 para. 1 (c) GDPR.
Your data may also be processed if necessary to protect your vital interests.
Processing is permissible when carried out in the public interest or in the exercise of official authority.
Where there is an overriding legitimate interest in data processing, processing may take place on this basis.
7901 4th St N, STE 300
St. Petersburg, Florida FL 33702 USA
info@floravoelcker.deOwner: Flora Völcker
In accordance with Art. 37 GDPR, the controller has appointed Dipl. Jur. Lars Averstegge as Data Protection Officer.
For any data-protection inquiries, you may contact him at: datenschutz@averstegge.de
Unless a more specific retention period is stated in this Privacy Policy, your personal data will be stored only as long as the purpose of processing exists (Art. 5 para. 1 GDPR). If you exercise a legitimate deletion request or withdraw your consent to processing, your data will be erased unless other lawful grounds exist for retention (e.g., tax or commercial record-keeping obligations). In such cases, data are deleted once those obligations have expired.
Personal data are processed solely for specific, legitimate purposes (Art. 5 para. 1 b GDPR). In accordance with the principle of purpose limitation, data are processed exclusively for the purposes described in this Privacy Policy. If the purpose changes, the data subject will be informed in advance unless the change is permitted by law without separate notification.
Once the processing purpose ceases to apply, your personal data are deleted or protected by technical-organizational measures (for example, anonymization), provided no statutory retention periods prevent deletion.
The following section informs you of your rights regarding the processing of your personal data.
You have the right to know who collects your personal data, why they are collected, and how they are used. This information must be provided in a clear and comprehensible form.
You have the right to request a copy of your personal data that the controller processes. This includes information about the origin of the data, the recipients or categories of recipients, the purpose of processing, and the retention period.
If your personal data are inaccurate or incomplete, you have the right to request correction or completion. The organization processing your data must carry this out without undue delay.
Under certain circumstances, you may request the deletion of your personal data. If your data are no longer needed for their original purpose, if you have withdrawn consent, or if processing is unlawful, the controller must delete your data.
You have the right to restrict processing if you dispute the accuracy of your data, if processing is unlawful, or if the organization no longer needs the data. While processing is restricted, your data may be used only to a limited extent.
When using third-party services, tools, or platforms—or cooperating with other companies—personal data may be processed outside the EU in so-called third countries. Such processing is lawful only when it is exceptionally justified under Art. 44 et seq. GDPR.
A justification exists, for example, when an adequacy decision has been issued, recognizing that a third country ensures data protection standards comparable to those in the EU.
A list of countries that have received such an adequacy decision is available here:
https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_enParticularly regarding data transfers to the United States, the Data Privacy Framework (DPF) now allows U.S. companies to self-certify. When a U.S. company is certified under the DPF, data transfers to that company are considered GDPR-compliant, provided all other national and EU requirements are met.
A list of DPF-certified U.S. companies can be found here:
https://www.dataprivacyframework.gov/listFor countries without an adequacy decision, data transfers can still be lawful under Art. 46 para. 1 and 2(c) GDPR if the respective company agrees to the Standard Contractual Clauses (SCCs) drafted by the EU Commission. By accepting the SCCs, the company guarantees GDPR-equivalent data-protection standards.
The SCCs can be found here:
https://www.dataprivacyframework.gov/listWhen you contact the controller via email or telephone, any personal data arising from that inquiry (such as name and the content of your request) are stored and processed to handle your inquiry.
Processing is based on Art. 6 para. 1 b GDPR if your request is related to the performance of a contract or necessary for pre-contractual measures.
If your inquiry is not related to contract initiation or execution, it is processed under our legitimate interest in effective business communication (Art. 6 para. 1 f GDPR).
If consent is requested, processing is based on Art. 6 para. 1 a GDPR. Consent may be revoked at any time. If no consent is granted, reliance on Art. 6 para. 1 f GDPR as an alternative is not permitted.
Personal data transmitted through a contact request are retained until you request deletion or the purpose for storage ceases to apply (e.g., after your request has been resolved). Statutory retention obligations remain unaffected.
If you contact us via email or our contact form, you voluntarily consent to the processing of your provided personal data upon submitting your request. Processing serves only to establish contact and handle your inquiry.
A valid email address is required to assign and respond to your message; any other data you provide are voluntary and serve to improve communication.
Your transmitted data are treated confidentially and used solely to process your inquiry and follow-up questions. They are stored only as long as necessary for this purpose and deleted afterward unless statutory obligations require longer retention. You may withdraw consent at any time with future effect.
Your data is collected when you provide it yourself. This may be data that you have provided in a contact form, order form, or via another digital means of communication.
Furthermore, technical data may be collected in the form of log data (so-called server log files). The log file usually consists of:
Data collection for user-behavior analysis (via analytics tools, cookies, or device fingerprinting) only occurs with your explicit consent.
Please note: Data transmission over the internet (e.g., via email) may contain security vulnerabilities. A complete protection of data from third-party access is technically not possible.
Detailed information about type, scope, purpose, duration, and legal basis of processing is provided below.
The controller ensures integrity and confidentiality of IT systems and implements all necessary security measures. However, even high security cannot guarantee full protection against hacking or unauthorized access. Systems are continually adapted to meet modern security requirements.
This website uses SSL/TLS encryption (Secure Socket Layer / Transport Layer Security) to safeguard personal data during transmission.
The controller maintains a profile on YouTube, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Profile URL: https://www.youtube.com/channel/UCkS9gTx8cnN6wzzN6iVdjBQ
By interacting with our YouTube profile, personal data may be processed—such as name, age, nationality, or business affiliation. YouTube also collects data for analytics (e.g., engagement, subscriptions) and uses cookies to create user profiles and personalized ads, even for visitors without accounts.
Cookies remain on your device until deleted.
Processing is based on Art. 6 para. 1 f GDPR (legitimate interest in company representation). Image publication requires consent (Art. 6 para. 1 a GDPR) or may rely on Art. 6 para. 1 b (contractual obligation) or Art. 6 para. 1 f GDPR in conjunction with §23 para. 1 No. 3 KUG (legitimate interest).
If you contact us via YouTube (e.g., comments or messages), we process your data solely for communication purposes based on consent (Art. 6 para. 1 a) or contract fulfillment (Art. 6 para. 1 b).
Data are deleted when no longer necessary or upon your deletion request, unless statutory retention obligations apply.
YouTube Privacy Policy:
https://policies.google.com/privacyWe have a DPA with Google for YouTube to ensure processing follows our instructions and GDPR requirements.
The controller maintains an Instagram profile under Meta Platforms Ireland Limited.
Profile URL: https://www.instagram.com/flora.voelcker/
By interacting with our Instagram profile, personal data may be processed (name, nationality, occupation, etc.). Instagram also uses cookies to collect data for analytics and advertising—even for non-logged-in users.
Processing is based on Art. 6 para. 1 f GDPR (legitimate business interest in public visibility). Publication of photos requires consent (Art. 6 para. 1 a) or may rely on Art. 6 para. 1 b or Art. 6 para. 1 f GDPR in conjunction with §23 para. 1 No. 3 KUG.
Messages or comments sent to us are processed solely for communication purposes under Art. 6 para. 1 a or b GDPR. Stored data are deleted once no longer necessary or upon your request, unless legal retention obligations apply.
Instagram Privacy Policy: https://help.instagram.com/155833707900388
A DPA with Instagram ensures processing is limited to our instructions and compliant with GDPR.
Details https://privacycenter.instagram.com/policy
The controller also maintains a Facebook profile operated by Meta Platforms Ireland Limited.
Profile URL: https://www.facebook.com/profile.php?id=100078679423985
Facebook processes user data such as name, nationality, employment, and interaction data. Cookies are used to analyze engagement and deliver personalized ads, even for non-logged-in users. Cookies remain on your device until deleted.
Processing is based on Art. 6 para. 1 f GDPR (legitimate business interest). Photo publications follow Art. 6 para. 1 a (consent) or Art. 6 para. 1 b/f GDPR in conjunction with §23 para. 1 No. 3 KUG.
Messages or comments are processed only to maintain communication (Art. 6 para. 1 a/b GDPR). Data are deleted when no longer required or upon request unless retention obligations apply.
Facebook Privacy Policy: https://de-de.facebook.com/privacy/policy/
A DPA has been executed with Facebook to ensure GDPR-compliant processing.
If your personal data are processed in third countries, such processing takes place only where an adequacy decision exists or standard contractual clauses have been agreed upon. Any transfer to a third country is carried out strictly in accordance with Art. 44 et seq. GDPR.
Where consent has been obtained for the storage of cookies and access to your device’s information, the additional requirements of the German Telecommunications-Telemedia Data Protection Act (TDDDG) are always observed.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit those data to another controller, provided processing is based on consent or contract.
You may object to the processing of your personal data if it is carried out for direct-marketing purposes or on the basis of public or legitimate interests under Art. 6 para. 1 f GDPR, unless compelling legitimate grounds override your interests. This includes in particular cases of direct advertising or newsletter marketing.
If you believe that the processing of your personal data violates the GDPR, you have the right to file a complaint with the competent data-protection authority. Because the controller is located outside the EU, the authority within whose jurisdiction the processing takes place may act.
Detailed information on the responsibilities of supervisory authorities is provided in the dossier of the Stiftung Datenschutz:
https://stiftungdatenschutz.org/fileadmin/Redaktion/Dokumente/Dossiers_Infoplattform/2020-07-Update/DSGVO-Praxis__Aufsichtsbehoerden_Zustaendigkeiten_Juni2020.pdfTo optimize internal workflows, schedule management, file exchange, and overall productivity, the controller uses Google Workspace services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Personal data such as names, addresses, and other contract-related details may be processed.
The legal basis is Art. 6 para. 1 b GDPR, as processing is necessary for contractual performance. Any data not essential to contract fulfillment are processed only with voluntary consent (Art. 6 para. 1 a GDPR).
Use of Google Workspace complies with GDPR requirements, including implementation of technical and organizational safeguards. If Google processes data outside the EEA, such processing is based on adequate safeguards under Art. 44 et seq. GDPR.
A Data Processing Agreement under Art. 28 GDPR has been concluded with Google Inc. This ensures processing occurs only per our instructions and under GDPR-compliant conditions.
Google Inc. is certified under the EU–U.S. Data Privacy Framework (DPF), ensuring adherence to European data-protection standards.
Data transfers to the USA are also governed by EU Commission Standard Contractual Clauses.
The controller uses the Slack communication and organization platform operated by Slack Technologies, Inc., 500 Howard Street, San Francisco, CA 94105, USA.
If you contact us via Slack, personal data are stored and processed on Slack’s servers (including Amazon AWS). This may include log data, device information, contact details, account data, and any content you share via messages.
For details, see Slack’s Privacy Policy: https://slack.com/intl/de-de/trust/privacy/privacy-policy#collect
Processing is based on Art. 6 para. 1 b GDPR when necessary to fulfill a contract, or on Art. 6 para. 1 a GDPR when based on consent. If no consent is provided, processing may still rely on legitimate interest (Art. 6 para. 1 f GDPR).
Nonessential data will be deleted immediately unless retention is legally required.
Slack Technologies, LLC (under parent company Salesforce Inc., 415 Mission St FL 3, San Francisco, CA 94105) is certified under the EU–U.S. DPF.
A DPA, including Standard Contractual Clauses, has been integrated into Slack’s Terms of Service through Salesforce.
The controller uses Zoom Video Communications Inc., 55 Almaden Blvd, 6th Floor, San Jose, CA 95113, USA, for conducting online meetings.
Collected data may include names, email addresses, IP addresses, browser and device data (camera, microphone, speaker types), approximate location, and meeting metadata. Zoom may also collect limited data from integrated services such as Zoom Email or Zoom Calendar.
Privacy Policy: https://explore.zoom.us/de/privacy/
Processing is based on Art. 6 para. 1 b GDPR when necessary for contract execution or pre-contractual actions. Otherwise, processing may rely on consent (Art. 6 para. 1 a GDPR) or legitimate interest in effective communication (Art. 6 para. 1 f GDPR).
Data are retained only as long as needed for the above purposes or as required by law.
By registering and creating a Zoom account, you agree to Zoom’s integrated DPA, which includes EU Standard Contractual Clauses.
The controller periodically conducts sessions called “Site Success” via Zoom. During these sessions, participants’ websites are reviewed, and recommendations for design optimization are shared.
The personal data processed include those listed under the “Zoom” section, plus any data publicly visible on participants’ websites.
Processing is based on consent (Art. 6 para. 1 a GDPR). Participants are informed about the data displayed during these sessions, and no processing occurs without their consent.
Data are deleted immediately once the purpose is fulfilled, unless retention is required by consent, contractual obligations, or legal requirements.
This website is hosted by Cloudways Ltd., 52 Springvale, Pope Pius XII Street, Mosta MST2653, Malta.
Cloudways processes data such as your IP address, DNS logs, performance metrics, and data used to analyze malicious traffic.
Use of Cloudways is based on Art. 6 para. 1 f GDPR — our legitimate interest in ensuring reliable and secure website performance.
More information: https://www.cloudways.com/en/terms.php#privacy
A DPA, included as part of Cloudways’ Terms of Service, has been executed.
Cloudways utilizes Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA, as a sub-processor for hosting infrastructure.
Cloudflare may process your IP address, DNS logs, performance data, and data used for traffic and security analysis.
Details:
Cloudflare is certified under the EU–U.S. Data Privacy Framework (DPF), ensuring adherence to European data-protection standards.
Our website uses cookies—small text files stored on your device by your browser. Cookies cannot execute programs or transmit viruses; they help make our website more user-friendly, efficient, and secure.
Cookies may contain data identifying your device, but not you personally. They may be session cookies (deleted when the browser closes) or persistent cookies (stored longer).
Cookies that are technically necessary for providing the service are lawful under §25 para. 2 No. 2 TDDDG. All other cookies require your explicit consent (§25 para. 1 TDDDG in conjunction with Art. 6 para. 1 a GDPR). Data processed via cookies are shared with third parties only with your explicit consent.
This website uses Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables behavioral analysis of website visitors. We receive anonymized data such as page views, time spent, operating systems, and traffic origins. Analytics may use a user ID linked to each device.
Google also employs modeling techniques and machine learning to improve data accuracy. Cookies or device fingerprinting may be used to recognize returning visitors.
Collected data are usually transmitted to Google’s U.S. servers. Processing is based on your consent under Art. 6 para. 1 a GDPR and §25 para. 1 TDDDG, which may be revoked at any time.
Google Tag Manager helps integrate and manage tracking and analytics tools on this site. The Tag Manager itself does not analyze or store personal data but transmits IP addresses to Google servers (potentially in the USA).
Processing is based on Art. 6 para. 1 f GDPR (legitimate interest in efficient tool management). If you grant consent, Art. 6 para. 1 a GDPR and §25 para. 1 TDDDG also apply.
Data transfers to the USA are governed by EU Standard Contractual Clauses.
A DPA under Art. 28 GDPR has been concluded with Google Inc. This ensures that processing occurs strictly per our instructions and under GDPR compliance.
Google Inc. is certified under the EU–U.S. Data Privacy Framework, ensuring adherence to European standards.
Google Inc. is certified under the EU–U.S. Data Privacy Framework.
Meta Platforms Ireland Limited may transfer personal data to the U.S. under the EU–U.S. Data Privacy Framework.
Contact for Instagram’s Data Protection Officer:
https://www.facebook.com/help/contact/713679366292426?IG_EU_PP_RedirectThe controller and Instagram are joint controllers under Art. 26 GDPR concerning “Instagram Insights.” This means users may exercise GDPR rights (Arts. 12–22, 77) against either party.
Insights data provide only anonymized statistics; the controller has no access to or control over raw user data.
Joint Controller Agreement: https://www.facebook.com/legal/controller_addendum
Meta Platforms Ireland Limited may transfer data to the U.S. under the EU–U.S. Data Privacy Framework.
Contact for Facebook’s Data Protection Officer:
https://www.facebook.com/help/contact/713679366292426?IG_EU_PP_RedirectThe controller and Facebook are joint controllers under Art. 26 GDPR for “Facebook Insights.” Users can exercise GDPR rights against either party. Only anonymized statistics are accessible; raw data remain under Facebook’s control.
Joint Controller Agreement: https://www.facebook.com/legal/controller_addendum