We use both cookies for analytics and advertising. By clicking "Accept", you agree to our use of cookies. More info in our privacy policy

For impact-driven leaders & brands: Custom design that builds trust, authority & premium pricing.

Contacts
  • info@voelckerdesign.com
  • +27 (64) 954-1174
  • St. Petersburg, USA
Navigation
  • Projects
  • Testimonials
  • About us
Legal
  • Legal Notice
  • Privacy Policy
  • Terms and Conditions
Socials
  • Instagram
  • LinkedIn

©2026 by voelcker international llc. All rights reserved.

  • Instagram
  • LinkedIn

Website Privacy Policy

General Information

The protection of your personal data is taken very seriously. This statement is intended to provide information on how personal data is processed, either alone or jointly with others, regarding the purposes and means of data processing. It is important to the controller to inform you as transparently as possible about the nature, scope, purpose, duration, and legal basis of data processing.

Definitions

In order to make the privacy policy as understandable as possible for the reader, the legal terms used in this privacy policy are defined below.

“Personal Data” (Art. 4 No. 1 GDPR)

All data through which you are identified or can be personally identified are considered personal data (“PD”) within the meaning of Art. 4 No. 1 of the General Data Protection Regulation (GDPR). It is sufficient if the data have been pseudonymized but could be linked to an identifiable individual by adding supplementary information. Completely anonymized data do not constitute personal data.

“Processing” (Art. 4 No. 2 GDPR)

Processing within the meaning of Art. 4 No. 2 GDPR includes any automated operation performed on personal data, whether in virtual (digital) or physical (analog) form. This covers all types of processing—collection, storage, modification, disclosure, or deletion. The term is deliberately broad and covers almost every action involving your personal data.

“Controller” (Art. 4 No. 7 GDPR)

A natural or legal person, authority, institution, or other body that alone or jointly with others determines the purposes and means of processing personal data is deemed the controller under the GDPR.

Third Party” (Art. 4 No. 10 GDPR)

Any natural or legal person, authority, institution, or other body other than the data subject, the controller, the processor, and those authorized to process personal data under the direct authority of the controller or processor, is considered a third party as defined by Art. 4 No. 10 GDPR.

“Processor” (Art. 4 No. 8 GDPR)

A natural or legal person, authority, institution, or other body that processes personal data on behalf of the controller—particularly according to the controller’s instructions (e.g., an IT service provider)—is a processor within the meaning of Art. 4 No. 8 GDPR. Legally, a processor is not a third party.

“Consent” (Art. 4 No. 11 GDPR)

Consent is deemed to exist when an action clearly indicates that the data subject voluntarily, for a specific purpose, in an informed manner, and unequivocally agrees to the processing of their data.

Legal Bases for Data Processing

Your personal data are processed only within the legal framework of the GDPR and other applicable national and international data-protection laws. The controller processes personal data solely when a lawful basis exists.

Consent (Art. 6 para. 1 a, Art. 9 para. 1 a GDPR)

If you have expressly granted consent to the processing of your data, those data may be used for the stated purpose.

Performance of a Contract (Art. 6 para. 1 b GDPR)

When processing your data is required to fulfill a contract concluded with us, your data may be processed accordingly. This also includes data processed for pre-contractual steps, such as contact information exchanged during contract initiation.

Compliance with a Legal Obligation (Art. 6 para. 1 c GDPR)

If a statutory obligation governs how data must be processed, processing is carried out in accordance with Art. 6 para. 1 (c) GDPR.

Protection of Vital Interests (Art. 6 para. 1 d GDPR)

Your data may also be processed if necessary to protect your vital interests.

Performance of a Task in the Public Interest (Art. 6 para. 1 e GDPR)

Processing is permissible when carried out in the public interest or in the exercise of official authority.

Legitimate Interests (Art. 6 para. 1 f GDPR)

Where there is an overriding legitimate interest in data processing, processing may take place on this basis.

Controller Responsible for Processing Your Data

Voelcker International LLC

7901 4th St N, STE 300

St. Petersburg, Florida FL 33702 USA

info@floravoelcker.de

Owner: Flora Völcker

Data Protection Officer

In accordance with Art. 37 GDPR, the controller has appointed Dipl. Jur. Lars Averstegge as Data Protection Officer.

For any data-protection inquiries, you may contact him at: datenschutz@averstegge.de

Storage Period

Unless a more specific retention period is stated in this Privacy Policy, your personal data will be stored only as long as the purpose of processing exists (Art. 5 para. 1 GDPR). If you exercise a legitimate deletion request or withdraw your consent to processing, your data will be erased unless other lawful grounds exist for retention (e.g., tax or commercial record-keeping obligations). In such cases, data are deleted once those obligations have expired.

Purposes of Data Processing

Personal data are processed solely for specific, legitimate purposes (Art. 5 para. 1 b GDPR). In accordance with the principle of purpose limitation, data are processed exclusively for the purposes described in this Privacy Policy. If the purpose changes, the data subject will be informed in advance unless the change is permitted by law without separate notification.

Once the processing purpose ceases to apply, your personal data are deleted or protected by technical-organizational measures (for example, anonymization), provided no statutory retention periods prevent deletion.

Rights of Data Subjects

The following section informs you of your rights regarding the processing of your personal data.

Right to Information (Art. 13 and 14 GDPR)

You have the right to know who collects your personal data, why they are collected, and how they are used. This information must be provided in a clear and comprehensible form.

Right of Access (Art. 15 GDPR)

You have the right to request a copy of your personal data that the controller processes. This includes information about the origin of the data, the recipients or categories of recipients, the purpose of processing, and the retention period.

Right to Rectification (Art. 16 GDPR)

If your personal data are inaccurate or incomplete, you have the right to request correction or completion. The organization processing your data must carry this out without undue delay.

Right to Erasure (“Right to Be Forgotten”, Art. 17 GDPR)

Under certain circumstances, you may request the deletion of your personal data. If your data are no longer needed for their original purpose, if you have withdrawn consent, or if processing is unlawful, the controller must delete your data.

Right to Restrict Processing (Art. 18 GDPR)

You have the right to restrict processing if you dispute the accuracy of your data, if processing is unlawful, or if the organization no longer needs the data. While processing is restricted, your data may be used only to a limited extent.

Right to Data Portability (Art. 20 GDPR)

Data Processing in Third Countries

When using third-party services, tools, or platforms—or cooperating with other companies—personal data may be processed outside the EU in so-called third countries. Such processing is lawful only when it is exceptionally justified under Art. 44 et seq. GDPR.

A justification exists, for example, when an adequacy decision has been issued, recognizing that a third country ensures data protection standards comparable to those in the EU.

A list of countries that have received such an adequacy decision is available here:

https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en

Particularly regarding data transfers to the United States, the Data Privacy Framework (DPF) now allows U.S. companies to self-certify. When a U.S. company is certified under the DPF, data transfers to that company are considered GDPR-compliant, provided all other national and EU requirements are met.

A list of DPF-certified U.S. companies can be found here:

https://www.dataprivacyframework.gov/list

For countries without an adequacy decision, data transfers can still be lawful under Art. 46 para. 1 and 2(c) GDPR if the respective company agrees to the Standard Contractual Clauses (SCCs) drafted by the EU Commission. By accepting the SCCs, the company guarantees GDPR-equivalent data-protection standards.

The SCCs can be found here:

https://www.dataprivacyframework.gov/list

Data Processing in Detail

Contact by Email or Telephone

When you contact the controller via email or telephone, any personal data arising from that inquiry (such as name and the content of your request) are stored and processed to handle your inquiry.

Processing is based on Art. 6 para. 1 b GDPR if your request is related to the performance of a contract or necessary for pre-contractual measures.

If your inquiry is not related to contract initiation or execution, it is processed under our legitimate interest in effective business communication (Art. 6 para. 1 f GDPR).

If consent is requested, processing is based on Art. 6 para. 1 a GDPR. Consent may be revoked at any time. If no consent is granted, reliance on Art. 6 para. 1 f GDPR as an alternative is not permitted.

Personal data transmitted through a contact request are retained until you request deletion or the purpose for storage ceases to apply (e.g., after your request has been resolved). Statutory retention obligations remain unaffected.

Contact Form

If you contact us via email or our contact form, you voluntarily consent to the processing of your provided personal data upon submitting your request. Processing serves only to establish contact and handle your inquiry.

A valid email address is required to assign and respond to your message; any other data you provide are voluntary and serve to improve communication.

Your transmitted data are treated confidentially and used solely to process your inquiry and follow-up questions. They are stored only as long as necessary for this purpose and deleted afterward unless statutory obligations require longer retention. You may withdraw consent at any time with future effect.

Data Processing on the Website

Your data is collected when you provide it yourself. This may be data that you have provided in a contact form, order form, or via another digital means of communication.

Furthermore, technical data may be collected in the form of log data (so-called server log files). The log file usually consists of:

  • The page from which the request originated (referrer URL)
  • The name and URL of the accessed page
  • Date and time of access
  • Description, language, and version of the browser used
  • IP address (shortened to prevent identification)
  • Data volume transmitted
  • Operating system
  • Access status / HTTP status code
  • Time zone difference (GMT)

Data collection for user-behavior analysis (via analytics tools, cookies, or device fingerprinting) only occurs with your explicit consent.

Please note: Data transmission over the internet (e.g., via email) may contain security vulnerabilities. A complete protection of data from third-party access is technically not possible.

Detailed information about type, scope, purpose, duration, and legal basis of processing is provided below.

Technical and Organizational Measures

The controller ensures integrity and confidentiality of IT systems and implements all necessary security measures. However, even high security cannot guarantee full protection against hacking or unauthorized access. Systems are continually adapted to meet modern security requirements.

SSL/TLS Encryption

This website uses SSL/TLS encryption (Secure Socket Layer / Transport Layer Security) to safeguard personal data during transmission.

Social Media Presence

Privacy Policy for YouTube

The controller maintains a profile on YouTube, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Profile URL: https://www.youtube.com/channel/UCkS9gTx8cnN6wzzN6iVdjBQ

By interacting with our YouTube profile, personal data may be processed—such as name, age, nationality, or business affiliation. YouTube also collects data for analytics (e.g., engagement, subscriptions) and uses cookies to create user profiles and personalized ads, even for visitors without accounts.

Cookies remain on your device until deleted.

Processing is based on Art. 6 para. 1 f GDPR (legitimate interest in company representation). Image publication requires consent (Art. 6 para. 1 a GDPR) or may rely on Art. 6 para. 1 b (contractual obligation) or Art. 6 para. 1 f GDPR in conjunction with §23 para. 1 No. 3 KUG (legitimate interest).

If you contact us via YouTube (e.g., comments or messages), we process your data solely for communication purposes based on consent (Art. 6 para. 1 a) or contract fulfillment (Art. 6 para. 1 b).

Data are deleted when no longer necessary or upon your deletion request, unless statutory retention obligations apply.

YouTube Privacy Policy:

https://policies.google.com/privacy
Data Processing Agreement

We have a DPA with Google for YouTube to ensure processing follows our instructions and GDPR requirements.

Privacy Policy for Instagram

The controller maintains an Instagram profile under Meta Platforms Ireland Limited.

Profile URL: https://www.instagram.com/flora.voelcker/

By interacting with our Instagram profile, personal data may be processed (name, nationality, occupation, etc.). Instagram also uses cookies to collect data for analytics and advertising—even for non-logged-in users.

Processing is based on Art. 6 para. 1 f GDPR (legitimate business interest in public visibility). Publication of photos requires consent (Art. 6 para. 1 a) or may rely on Art. 6 para. 1 b or Art. 6 para. 1 f GDPR in conjunction with §23 para. 1 No. 3 KUG.

Messages or comments sent to us are processed solely for communication purposes under Art. 6 para. 1 a or b GDPR. Stored data are deleted once no longer necessary or upon your request, unless legal retention obligations apply.

Instagram Privacy Policy: https://help.instagram.com/155833707900388

Data Processing Agreement

A DPA with Instagram ensures processing is limited to our instructions and compliant with GDPR.

Details https://privacycenter.instagram.com/policy

Data Privacy Framework

Privacy Policy for Facebook

The controller also maintains a Facebook profile operated by Meta Platforms Ireland Limited.

Profile URL: https://www.facebook.com/profile.php?id=100078679423985

Facebook processes user data such as name, nationality, employment, and interaction data. Cookies are used to analyze engagement and deliver personalized ads, even for non-logged-in users. Cookies remain on your device until deleted.

Processing is based on Art. 6 para. 1 f GDPR (legitimate business interest). Photo publications follow Art. 6 para. 1 a (consent) or Art. 6 para. 1 b/f GDPR in conjunction with §23 para. 1 No. 3 KUG.

Messages or comments are processed only to maintain communication (Art. 6 para. 1 a/b GDPR). Data are deleted when no longer required or upon request unless retention obligations apply.

Facebook Privacy Policy: https://de-de.facebook.com/privacy/policy/

Data Processing Agreement

A DPA has been executed with Facebook to ensure GDPR-compliant processing.

Details: https://www.facebook.com/business/gdpr#Facebook-als-Datenverantwortlicher-vs.-Facebook-als-Auftragsverarbeiter

Data Privacy Framework

Data Transfer to Third Countries (Art. 44 et seq. GDPR)

If your personal data are processed in third countries, such processing takes place only where an adequacy decision exists or standard contractual clauses have been agreed upon. Any transfer to a third country is carried out strictly in accordance with Art. 44 et seq. GDPR.

Device Fingerprinting (§ 25 TDDDG)

Where consent has been obtained for the storage of cookies and access to your device’s information, the additional requirements of the German Telecommunications-Telemedia Data Protection Act (TDDDG) are always observed.

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit those data to another controller, provided processing is based on consent or contract.

Right to Object (Art. 21 GDPR)

You may object to the processing of your personal data if it is carried out for direct-marketing purposes or on the basis of public or legitimate interests under Art. 6 para. 1 f GDPR, unless compelling legitimate grounds override your interests. This includes in particular cases of direct advertising or newsletter marketing.

Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)

If you believe that the processing of your personal data violates the GDPR, you have the right to file a complaint with the competent data-protection authority. Because the controller is located outside the EU, the authority within whose jurisdiction the processing takes place may act.

Detailed information on the responsibilities of supervisory authorities is provided in the dossier of the Stiftung Datenschutz:

https://stiftungdatenschutz.org/fileadmin/Redaktion/Dokumente/Dossiers_Infoplattform/2020-07-Update/DSGVO-Praxis__Aufsichtsbehoerden_Zustaendigkeiten_Juni2020.pdf

Google Drive, Google Calendar (Google Workspace)

To optimize internal workflows, schedule management, file exchange, and overall productivity, the controller uses Google Workspace services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Personal data such as names, addresses, and other contract-related details may be processed.

The legal basis is Art. 6 para. 1 b GDPR, as processing is necessary for contractual performance. Any data not essential to contract fulfillment are processed only with voluntary consent (Art. 6 para. 1 a GDPR).

Use of Google Workspace complies with GDPR requirements, including implementation of technical and organizational safeguards. If Google processes data outside the EEA, such processing is based on adequate safeguards under Art. 44 et seq. GDPR.

Data Processing Agreement (DPA)

A Data Processing Agreement under Art. 28 GDPR has been concluded with Google Inc. This ensures processing occurs only per our instructions and under GDPR-compliant conditions.

Data Privacy Framework

Google Inc. is certified under the EU–U.S. Data Privacy Framework (DPF), ensuring adherence to European data-protection standards.

Details: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active

Standard Contractual Clauses

Data transfers to the USA are also governed by EU Commission Standard Contractual Clauses.

Details: https://privacy.google.com/businesses/controllerterms/mccs/

Slack

The controller uses the Slack communication and organization platform operated by Slack Technologies, Inc., 500 Howard Street, San Francisco, CA 94105, USA.

If you contact us via Slack, personal data are stored and processed on Slack’s servers (including Amazon AWS). This may include log data, device information, contact details, account data, and any content you share via messages.

For details, see Slack’s Privacy Policy: https://slack.com/intl/de-de/trust/privacy/privacy-policy#collect

Processing is based on Art. 6 para. 1 b GDPR when necessary to fulfill a contract, or on Art. 6 para. 1 a GDPR when based on consent. If no consent is provided, processing may still rely on legitimate interest (Art. 6 para. 1 f GDPR).

Nonessential data will be deleted immediately unless retention is legally required.

EU–U.S. Data Privacy Framework Certification

Slack Technologies, LLC (under parent company Salesforce Inc., 415 Mission St FL 3, San Francisco, CA 94105) is certified under the EU–U.S. DPF.

Details: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000KzLyAAK&status=Active

Data Processing Agreement

A DPA, including Standard Contractual Clauses, has been integrated into Slack’s Terms of Service through Salesforce.

More info: https://www.salesforce.com/content/dam/web/en_us/www/documents/legal/Agreements/data-processing-addendum.pdf

Zoom

The controller uses Zoom Video Communications Inc., 55 Almaden Blvd, 6th Floor, San Jose, CA 95113, USA, for conducting online meetings.

Collected data may include names, email addresses, IP addresses, browser and device data (camera, microphone, speaker types), approximate location, and meeting metadata. Zoom may also collect limited data from integrated services such as Zoom Email or Zoom Calendar.

Privacy Policy: https://explore.zoom.us/de/privacy/

Processing is based on Art. 6 para. 1 b GDPR when necessary for contract execution or pre-contractual actions. Otherwise, processing may rely on consent (Art. 6 para. 1 a GDPR) or legitimate interest in effective communication (Art. 6 para. 1 f GDPR).

Data are retained only as long as needed for the above purposes or as required by law.

Data Processing Agreement

By registering and creating a Zoom account, you agree to Zoom’s integrated DPA, which includes EU Standard Contractual Clauses.

Details: https://explore.zoom.us/docs/doc/Zoom_GLOBAL_DPA.pdf

Site Success

The controller periodically conducts sessions called “Site Success” via Zoom. During these sessions, participants’ websites are reviewed, and recommendations for design optimization are shared.

The personal data processed include those listed under the “Zoom” section, plus any data publicly visible on participants’ websites.

Processing is based on consent (Art. 6 para. 1 a GDPR). Participants are informed about the data displayed during these sessions, and no processing occurs without their consent.

Data are deleted immediately once the purpose is fulfilled, unless retention is required by consent, contractual obligations, or legal requirements.

Hosting (Cloudways)

This website is hosted by Cloudways Ltd., 52 Springvale, Pope Pius XII Street, Mosta MST2653, Malta.

Cloudways processes data such as your IP address, DNS logs, performance metrics, and data used to analyze malicious traffic.

Use of Cloudways is based on Art. 6 para. 1 f GDPR — our legitimate interest in ensuring reliable and secure website performance.

More information: https://www.cloudways.com/en/terms.php#privacy

Data Processing Agreement

A DPA, included as part of Cloudways’ Terms of Service, has been executed.

Details:

Cloudflare

Cloudways utilizes Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA, as a sub-processor for hosting infrastructure.

Cloudflare may process your IP address, DNS logs, performance data, and data used for traffic and security analysis.

Details:

Data Privacy Framework

Cloudflare is certified under the EU–U.S. Data Privacy Framework (DPF), ensuring adherence to European data-protection standards.

Details: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000GnZKAA0&status=Active

Cookies

Our website uses cookies—small text files stored on your device by your browser. Cookies cannot execute programs or transmit viruses; they help make our website more user-friendly, efficient, and secure.

Cookies may contain data identifying your device, but not you personally. They may be session cookies (deleted when the browser closes) or persistent cookies (stored longer).

  • Technical Cookies: Required for website navigation, basic functionality, and security.
  • Performance Cookies: Collect anonymous usage data (e.g., pages visited, errors encountered) to improve the site.
  • Advertising / Targeting Cookies: Deliver personalized ads and measure campaign effectiveness; stored for up to 13 months.
  • Sharing Cookies: Enhance interactivity with external platforms (e.g., social media); stored for up to 13 months.

Cookies that are technically necessary for providing the service are lawful under §25 para. 2 No. 2 TDDDG. All other cookies require your explicit consent (§25 para. 1 TDDDG in conjunction with Art. 6 para. 1 a GDPR). Data processed via cookies are shared with third parties only with your explicit consent.

Google Analytics & Google AdSense

This website uses Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables behavioral analysis of website visitors. We receive anonymized data such as page views, time spent, operating systems, and traffic origins. Analytics may use a user ID linked to each device.

Google also employs modeling techniques and machine learning to improve data accuracy. Cookies or device fingerprinting may be used to recognize returning visitors.

Collected data are usually transmitted to Google’s U.S. servers. Processing is based on your consent under Art. 6 para. 1 a GDPR and §25 para. 1 TDDDG, which may be revoked at any time.

Google Tag Manager

Google Tag Manager helps integrate and manage tracking and analytics tools on this site. The Tag Manager itself does not analyze or store personal data but transmits IP addresses to Google servers (potentially in the USA).

Processing is based on Art. 6 para. 1 f GDPR (legitimate interest in efficient tool management). If you grant consent, Art. 6 para. 1 a GDPR and §25 para. 1 TDDDG also apply.

Standard Contractual Clauses

Data transfers to the USA are governed by EU Standard Contractual Clauses.

Details: https://privacy.google.com/businesses/controllerterms/mccs/

Data Processing Agreement

A DPA under Art. 28 GDPR has been concluded with Google Inc. This ensures that processing occurs strictly per our instructions and under GDPR compliance.

Data Privacy Framework

Google Inc. is certified under the EU–U.S. Data Privacy Framework, ensuring adherence to European standards.

Details: https://www.dataprivacyframework.gov/list

Data Privacy Framework

Google Inc. is certified under the EU–U.S. Data Privacy Framework.

Details: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active

Meta Platforms Ireland Limited may transfer personal data to the U.S. under the EU–U.S. Data Privacy Framework.

Details: https://www.facebook.com/privacy/policies/data_privacy_framework

Contact for Instagram’s Data Protection Officer:

https://www.facebook.com/help/contact/713679366292426?IG_EU_PP_Redirect
Insights

The controller and Instagram are joint controllers under Art. 26 GDPR concerning “Instagram Insights.” This means users may exercise GDPR rights (Arts. 12–22, 77) against either party.

Insights data provide only anonymized statistics; the controller has no access to or control over raw user data.

Joint Controller Agreement: https://www.facebook.com/legal/controller_addendum

Meta Platforms Ireland Limited may transfer data to the U.S. under the EU–U.S. Data Privacy Framework.

Details: https://www.facebook.com/privacy/policies/data_privacy_framework

Contact for Facebook’s Data Protection Officer:

https://www.facebook.com/help/contact/713679366292426?IG_EU_PP_Redirect
Insights

The controller and Facebook are joint controllers under Art. 26 GDPR for “Facebook Insights.” Users can exercise GDPR rights against either party. Only anonymized statistics are accessible; raw data remain under Facebook’s control.

Joint Controller Agreement: https://www.facebook.com/legal/controller_addendum