Controller
Responsible for data processing on this website:
Heimann + Schwantes GbR
represented by the partners Michael Heimann and Hendrik Schwantes
Kreuzbergstraße 30
10965 Berlin
Germany
mail@heimannundschwantes.de
Phone: +49 (0)30 397 43 977
General Information on Data Processing
We process personal data of our users only to the extent necessary to provide a functioning website and our content and services. The processing of personal data generally takes place only with the user's consent or on the basis of a legal permission (in particular Art. 6 (1) GDPR).
Hosting / Website Builder Framer
We operate our website using the website builder Framer. The provider is:
Framer B.V.
Rozengracht 207B
1016 LZ Amsterdam
Netherlands
Framer provides the infrastructure for creating and hosting our website and, in doing so, processes technically necessary data (e.g. server log files such as IP address, date and time of access, page accessed, browser used, referrer URL). This data is necessary to deliver the website and to ensure its stability and security.
The legal basis is our legitimate interest in a reliable, fast, and secure provision of our website (Art. 6 (1) lit. f GDPR).
Framer also processes data outside the EU in some cases, including in the United States. We have concluded a data processing agreement with Framer based on the EU Standard Contractual Clauses (Art. 46 (2) and (3) GDPR), which is intended to ensure an adequate level of data protection. Further information can be found in Framer's privacy statement:
https://www.framer.com/legal/privacy-statement/
and in the Data Processing Addendum:
https://www.framer.com/legal/data-processing-addendum/
Framer Analytics
This website uses the analytics tool "Framer Analytics" built into Framer to statistically evaluate the use of our website. The provider is also Framer B.V. (address above).
Framer Analytics collects pseudonymized information such as page views, unique visitor counts, traffic sources, and frequently visited pages. To determine unique visitors, the IP address and user agent are hashed using a daily rotating, self-deleting random value (salt). This makes permanent storage or identification of individual persons impossible. No cookies are set, and no persistent identifiers are created.
Processing is based on our legitimate interest (Art. 6 (1) lit. f GDPR) in the needs-based design and continuous optimization of our website. Since IP addresses are briefly processed as part of the hashing process, we treat this processing as relevant under data protection law as a precaution, even though Framer classifies the results as fully anonymized.
Since no cookies or persistent identifiers are used, an opt-out via cookie is technically not possible; if you have questions or wish to object, please contact us using the address given above.
Cookies
Our website itself does not set any cookies of its own. As described in Section 4, Framer Analytics operates without cookies and without persistent identifiers.
Link to Social Media (Instagram)
Our website contains a link to our Instagram profile. This is a plain reference link (hyperlink) to the external page; no Instagram content is embedded into our website, and simply visiting our website does not transmit any data to Meta Platforms Ireland Limited. Only when you actively click the link do you leave our website and go to Instagram. From that point on, Meta's privacy policy applies:
https://www.facebook.com/privacy/policy/
https://help.instagram.com/519522125107875
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the lock icon in your browser bar.
Your Rights as a Data Subject
Within the scope of applicable legal provisions, you have the right at any time to:
Access the personal data we have stored about you (Art. 15 GDPR)
Rectification of inaccurate personal data (Art. 16 GDPR)
Erasure of your data stored with us (Art. 17 GDPR)
Restriction of processing, where we are not yet permitted to delete your data due to legal obligations (Art. 18 GDPR)
Object to the processing of your data by us (Art. 21 GDPR)
Data portability, provided you have consented to data processing or have entered into a contract with us (Art. 20 GDPR)
If you believe that the processing of your personal data violates the GDPR, you also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Generally, the supervisory authority of your habitual residence or of our company's registered office has jurisdiction.
Currency and Amendment of this Privacy Policy
This privacy policy is currently valid and has the status [June 29026]. As we develop our website and offerings, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy.