Privacy Policy & Legal Notice
Last updated: 15 August 2026
Part 1 — Legal Notice
Information required under Section 5 DDG (German Digital Services Act).
Provider
LJBVA Group Ltd. Evagora Pallikaridi 38 8010 Paphos Cyprus
Legal form: Private Company Limited by Shares (Ltd.) under Cypriot law
Register
Registered in the commercial register of Cyprus (Registrar of Companies and Intellectual Property, Nicosia)
Contact
Email: info@boese-va.com
Telegram: @lukasboese
Responsible for the content
The content of this website consists of company information and does not constitute journalistic or editorial material. An additional designation under Section 18(2) MStV is therefore not required.
Official authorisation
Our activity does not require any official authorisation.
Regulated professions
We do not practise a regulated profession within the meaning of Section 5(1) no. 5 DDG.
Dispute resolution
The European Commission's Online Dispute Resolution platform was shut down on 20 July 2025. A link to it is no longer required.
We are neither willing nor obliged to take part in dispute resolution proceedings before a consumer arbitration board.
Part 2 — Privacy Policy
1. Who is responsible for your data
The controller for the processing of your personal data on www.boese-va.com is:
LJBVA Group Ltd. Evagora Pallikaridi 38 8010 Paphos Cyprus Email: info@boese-va.com Telegram: @lukasboese
If you have questions about data protection or want to exercise one of your rights, just write to us at info@boese-va.com. You don't have to fill in a form, and you don't have to give a reason.
Our company is based in Cyprus and therefore in the EU. The General Data Protection Regulation applies to us directly. Because our German-language offering is also aimed at people in Germany, the German TDDDG applies in addition — that's the law governing when we may set cookies and access your device.
2. Data protection officer
We have not appointed a data protection officer. We are not under any obligation to appoint one under Art. 37 GDPR. For all questions about data protection you can reach us directly at info@boese-va.com.
3. At a glance
The short version, before we go into detail.
If you only visit this site and do nothing else, our host automatically stores technical access data in server log files: your IP address, the time, the page requested, your browser, your operating system and the page you came from. These log files are deleted after a maximum of eight weeks.
Everything beyond that, we ask you about first. Google Analytics, Google Ads conversion tracking and Calendly's booking calendar only run once you have agreed in the consent banner — and with them Google Tag Manager, which loads them. Before that, this website stores nothing on your device and transmits nothing to Google. There is one exception: if you come to us via one of our short links (go.boese-va.com/…), an identifier is set before you even arrive here. We explain that in section 6.9. You can change or withdraw your decision at any time via *Cookie settings* at the bottom left. The details are in sections 6 and 7.
If you fill in our enquiry form, we process the details you provide — among other things your name, email address and your preferred way of being contacted. This data ends up in a database at our host, and we are notified of the submission by Telegram.
Videos and the booking calendar only load once you click. As long as you don't start a video, nothing goes to YouTube; as long as you don't request an appointment at the end of the enquiry form, nothing goes to Calendly. When you simply read our pages, neither of the two happens.
What we don't do: We don't sell your data, we don't make automated decisions about you, and we don't ask you for data we don't need for the purpose in question.
4. A few terms you'll need for the rest
Personal data is any information that can be related to you — name, email address, phone number, but also your IP address or a cookie identifier.
Processing is anything you can do with data: collecting, storing, using, passing on, deleting.
Controller is whoever decides on the purposes and means of the processing. In this case, that's us.
Processors are service providers who process data exclusively on our behalf and on our instructions — our host, for example. For such service providers, Art. 28 GDPR requires a separate contract.
Cookies and similar technologies are small entries stored on your device. Besides classic cookies, this includes your browser's local storage and the reading of technical device characteristics. The TDDDG treats all of this the same way.
A note on security: The transmission of data over the internet can have security gaps. Complete protection against third-party access is not technically possible.
Server log files
Every time you call up a page on www.boese-va.com, your browser automatically transmits technical data to our server. This is stored in what are known as server log files. According to our host's documentation, these are:
- the date and time of access
- the file or URL requested and the type of request
- the volume of data transferred and the message indicating whether the request was successful
- browser type and browser version as well as your operating system
- the page you visited before (referrer)
- your IP address
Your IP address is truncated in the process. Our host states that it anonymises visitors' IP addresses in the log files for data protection reasons.
Purpose: We need this data so the website can be delivered at all, so it runs stably, and so we can detect and fend off attacks and abuse.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is specifically: the technically error-free delivery of the website, keeping it running, and defending our server against attacks.
Storage period: According to our host, the log data is kept for a maximum of eight weeks and is then deleted automatically.
Recipients: Our host IONOS SE as a processor (see 6.1).
6.1 IONOS — hosting and database
Provider: IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany (Montabaur Local Court, HRB 24498, VAT ID DE815563912)
What happens: IONOS provides the servers this website runs on. That's where the server log files from section 5 are stored, along with the MySQL database in which we store the details submitted through our forms.
Data: server log files as described under 5, plus everything you enter into our forms.
Purpose: provision and secure operation of the website, storage of the form data.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the secure, stable and efficient provision of our online offering.
Role: IONOS processes the data on our behalf and on our instructions.
Third country:
IONOS privacy policy: https://www.ionos.de/terms-gtc/datenschutzerklaerung/
6.2 Google Tag Manager
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland
What happens: Tag Manager (container ID GTM-NPDM4G9M, embedded on 52 pages) is a tool we use to manage website tags. It does not itself collect data for analytics purposes and does not set its own cookies — but it loads the other services. Data goes to Google as soon as the container loads.
What runs through the container: Google Analytics 4 (see 6.3) and Google Ads conversion tracking (see 6.4). The container has only Google Analytics 4 and Google Ads conversion tracking set up in it; no other services are loaded through it.
Data: IP address, browser type and version, operating system, referrer, time of access.
Purpose: managing and delivering the tags used on this website.
Legal basis: your consent under Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Without your consent the container is not loaded at all — so no connection to Google is established beforehand either. You can withdraw it at any time with effect for the future via the *Cookie settings* button at the bottom left.
Third country: Transfer to Google LLC in the USA is possible. Google LLC is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.
Storage period: Log data is held at Google; we do not store any of it ourselves.
More information: https://policies.google.com/privacy
The Google Ads Data Processing Terms, which we have accepted, apply to the Google services.
6.3 Google Analytics 4
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland
What happens: Google Analytics 4 measures how our website is used. To do so, cookies are set and events are transmitted to Google.
Data: a pseudonymous identifier (client ID), the pages you call up and the events you trigger, time spent, referrer, your approximate location at country and region level, device type, browser, operating system, screen resolution, language setting and your IP address. According to Google, in Analytics 4 the IP address is used exclusively to derive location and is neither logged nor stored.
Cookies: _ga and _ga_FK48EV5SEW, each with a lifetime of two years.
Purpose: reach measurement, analysis of usage behaviour, optimisation of the website and our marketing.
Legal basis: Analytics requires consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR; the exception for strictly necessary access (Section 25(2) no. 2 TDDDG) does not apply to reach measurement. The basis is therefore your consent; without it, Analytics is not loaded and the associated cookies are not set. You can withdraw it at any time with effect for the future via the *Cookie settings* button at the bottom left.
Third country: transfer to Google LLC in the USA; DPF certification plus standard contractual clauses.
Storage period: The retention of user- and event-level data is set to 2 months in the property.
The measurement ID of the property is G-FK48EV5SEW. Google Consent Mode is active. "Google signals" are not enabled, so no cross-device enrichment takes place.
Objection: You can additionally prevent collection by Google Analytics using the browser add-on at https://tools.google.com/dlpage/gaoptout.
More information: https://policies.google.com/privacy and https://support.google.com/analytics/answer/6004245
6.4 Google Ads and conversion tracking
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland
What happens: We advertise our services through Google Ads. To measure which ad leads to which result, we use Google's conversion tracking. If you click on one of our ads, an identifier is stored on your device. That identifier makes it possible to trace whether, after clicking the ad, you performed a particular action on our website — submitted a form or booked an appointment, for example. We ourselves only receive aggregated statistics from this and cannot identify individual people from them.
Data: cookie identifier or click ID, time, pages called up, the conversion event, IP address, browser and device data.
Cookies and storage entries: _gcl_au with a lifetime of 90 days, plus the _gcl_ls entry in your browser's local storage. For conversion tracking, Google also documents the cookies Conversion (90 days) and IDE (13 months in the EEA); we have not checked in detail whether these are actually set on our website.
Purpose: measuring the success of our advertising.
Legal basis: your consent under Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Without it, none of this is loaded. You can withdraw it at any time with effect for the future via the *Cookie settings* button at the bottom left.
Alongside measuring the success of our ads, remarketing is also used — that is, the building of audiences for serving advertising to them later on.
Enhanced conversions with hashed email addresses are not transmitted.
Third country: transfer to Google LLC in the USA; DPF plus standard contractual clauses.
Ad settings: https://adssettings.google.com
More information: https://policies.google.com/technologies/ads
6.5 Fonts
We deliver the Inter typeface from our own server (directory /fonts/). When you call up this website, no connection to Google Fonts is established — neither to fonts.googleapis.com nor to fonts.gstatic.com. No data is transmitted to Google for this purpose.
The font file is fetched through our host like any other component of the page and appears there in the server log files (see section 5).
6.6 Calendly
Provider: Calendly, LLC, 115 E Main St., Ste. A1B, Buford, GA 30518, USA EU representative under Art. 27 GDPR: The DPO Centre Europe, Friedrichstraße 88, 10117 Berlin, eurep@calendly.com
What happens: At the end of our enquiry form you can pick an appointment with us directly. The Calendly booking calendar is loaded for that. Once it has loaded, data is transmitted to Calendly — even if you end up not booking an appointment.
Data: on loading, IP address, browser and device data, referrer. When you book, additionally your name, your email address, where applicable your phone number, the appointment you chose, your time zone and your answers to the questions in the booking form.
Sharing with Trakyo: If you book an appointment, Calendly reports this to Trakyo via an automatic interface — with your name, your email address, the appointment you chose and your answers from the booking form. We use this to see which marketing source an appointment originated from (see 6.9). Only the fact that a booking has come about is reported, not what is discussed in the conversation itself.
Purpose: arranging and preparing appointments.
When it loads: The calendar does not load with the page. It is only loaded once you choose "Book a call" at the end of the enquiry form — and even then only if you have agreed to the *booking calendar* category. If you have declined that category, what first appears in place of the calendar is a note that loading it transmits your IP address to Calendly in the USA, together with a button to load it. Before that, there is no connection to Calendly whatsoever.
Legal basis: for loading the widget, your consent under Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR; for processing your booking data, Art. 6(1)(b) GDPR — taking steps prior to entering into a contract at your request.
Role: Calendly processes the booking data for us.
Third country: USA. Calendly is self-certified under the EU-U.S. Data Privacy Framework and additionally relies on standard contractual clauses for transfers.
Storage period: Calendly states that it retains data for as long as necessary to fulfil the purposes for which it was collected. Under the setting in our Calendly account, the appointment data recorded there is deleted after 24 hours.
More information: https://calendly.com/legal/privacy-notice
6.7 YouTube
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland
What happens: We embed videos via YouTube and consistently use extended privacy mode through the domain youtube-nocookie.com.
The player does not load with the page. What you see when you call up a page is only a preview image from our own server. Only when you click a video is the YouTube player loaded, and your browser then establishes a connection to Google. If you only call up our pages without starting a video, Google learns nothing about it.
Data: on loading, IP address, browser and device data, referrer. On playback, additionally which videos you watch and how you interact with the player. If you are logged into your YouTube or Google account at the time, Google can assign this information to your account — you can prevent that by logging out before visiting our website.
Purpose: embedding and playing videos.
Legal basis: Art. 6(1)(b) or (f) GDPR in conjunction with Section 25(2) no. 2 TDDDG. Fetching the player is strictly necessary in order to provide you with exactly the service you explicitly requested by clicking the video. Without that click, nothing is loaded and nothing is transmitted.
Third country: transfer to Google LLC in the USA; DPF plus standard contractual clauses.
More information: https://policies.google.com/privacy
6.8 Telegram
Provider: Telegram Messenger Inc., Commerce House, Wickhams Cay 1, PO Box 3140, Road Town, Tortola, VG1110, British Virgin Islands EU representative under Art. 27 GDPR: European Data Protection Office (EDPO), Avenue Huart Hamoir 71, 1030 Brussels, Belgium
What happens: Two things that need to be kept apart.
*First, the links.* We link to Telegram in several places on our pages. Simply calling up our pages does not transmit any data to Telegram — that only happens when you click one of those links.
*Second, the notification.* When you submit one of our forms, a Telegram bot operated by us notifies us of the submission so we can respond promptly. Details from the form are transmitted to Telegram in the process.
Data: the details entered in the form, which go to the bot; Telegram additionally processes metadata such as IP address, device and time. If you choose Telegram as your preferred way of being contacted, we use the username you provide to reach you there.
Purpose: internal instant notification of new enquiries; getting in touch via the messenger you chose yourself.
Legal basis: for the internal notification, Art. 6(1)(f) GDPR — our legitimate interest is handling your enquiry promptly. For contacting you via the messenger you chose, Art. 6(1)(b) GDPR.
Third country: Telegram processes data outside the European Union. There is no adequacy decision by the European Commission for the British Virgin Islands.
Storage period: Telegram states a maximum of 12 months for security-related metadata.
One piece of advice from us: Don't send particularly sensitive information over messengers.
The notification contains your name, your email address, your preferred contact channel together with the username or phone number, and your answers from the form — in plain text, not merely a reference number.
More information: https://telegram.org/privacy
6.9 Trakyo — matching enquiries to marketing sources
Provider: Trakyo. Technically, the service is connected via the endpoint app.trakyo.io.
Trakyo names "Trakyo (United States)" as the controller, without stating a legal form, registration number or address for service. The provider can be reached at privacy@trakyo.io, and for data protection matters additionally at dpo@trakyo.io.
What happens: Trakyo helps us trace which marketing source an enquiry originated from.
There are two routes by which data reaches Trakyo. The first is our enquiry form, the second a booking via Calendly: if you arrange an appointment, Calendly reports this directly to Trakyo, together with your name, email address, the appointment and your answers from the booking form (see 6.6).
From this website, data is only sent to Trakyo when you submit the enquiry form. If you merely call up our pages, nothing is transmitted to Trakyo from here. If you come to us via one of our short links, however, you will already have called up Trakyo's intermediate page beforehand — see the paragraph after next.
Data: your name, your email address, the name of the form and — if Trakyo has previously assigned you a visitor identifier — that identifier. If you choose WhatsApp as your preferred way of being contacted, your phone number is sent along as well. If you choose Telegram, your username is not transmitted.
If you come to us via one of our short links: For video descriptions and similar places we use short links of the form go.boese-va.com/…. If you click one of them, you first land on an intermediate page operated by Trakyo. That page creates a recognition value from the technical characteristics of your device and browser (fingerprinting), stores it as a cookie trakyo_id for a period of one year and then forwards you to us. Because the short link sits on a subdomain of our own domain, this cookie subsequently applies to the entire website. If you later submit the enquiry form, we transmit that value together with your enquiry so that we can see which source it came from.
No Trakyo script is embedded on the website itself. If you call up our pages directly, without coming via a short link, no such recognition value is created.
Legal basis: Three operations, three bases.
For the transmission of your form details to Trakyo — name, email address, the name of the form and, where applicable, your phone number — we rely on Art. 6(1)(f) GDPR. Our legitimate interest is evaluating which channels enquiries come in through. You can object to this processing under Art. 21 GDPR (see section 13).
For the notification of a booking by Calendly — name, email address, the appointment and your answers from the booking form — the same applies: Art. 6(1)(f) GDPR, with the same legitimate interest and the same right to object.
For the cookie trakyo_id and the device recognition that goes with it, by contrast, we need your consent under Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. If you do not consent to the *Advertising* category, or if you withdraw it, we delete the cookie from your browser and do not transmit the identifier to Trakyo. The enquiry is then not matched to a marketing source.
How you can additionally push back: according to its own statements, Trakyo honours the Global Privacy Control signal and the Do Not Track browser setting. You can also reset the identifier by deleting the cookies for this site, or contact privacy@trakyo.io directly. Regardless of that, it is enough to deselect the *Advertising* category in the consent banner — then we delete the cookie and transmit nothing.
Trakyo's own privacy policy: https://trakyo.io/privacy-policy
Role: according to its own statements, Trakyo acts as a processor: "Trakyo provides the tracking technology as a data processor, but Customers as data controllers must ensure they have proper legal basis and consent mechanisms." So it is we who are responsible for the data of website visitors.
Third country: according to its own statements, Trakyo stores the core data in data centres in the USA and additionally processes it via a worldwide edge network, whereby data may temporarily be processed in further regions. For transfers outside the EU, Trakyo refers to standard contractual clauses.
Storage period: according to Trakyo's own statements, event data is retained for 12 months by default; the recognition cookie is set there with a lifetime of up to 90 days.
7. Cookies and similar technologies
Section 25 TDDDG governs when we may store information on your device and access it. The provision applies not only to classic cookies but to any storage and any access — so it also covers your browser's local storage and the reading of device characteristics. It also applies regardless of whether personal data is involved.
There are two cases:
- Strictly necessary (Section 25(2) no. 2 TDDDG): the access is technically required for a
service you have explicitly requested to work. We don't need consent for that.
- Everything else (Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR): for that we need
your consent before anything is stored or read out.
What is actually set on this website
| Entry | Provider | Purpose | Storage period | Category |
|---|---|---|---|---|
_ga | distinguishing individual users for reach measurement | 2 years | consent required | |
_ga_FK48EV5SEW | session state in Google Analytics 4 | 2 years | consent required | |
_gcl_au | conversion tracking for Google Ads | 90 days | consent required | |
_gcl_ls (local storage) | identifier for conversion tracking | until you delete it | consent required | |
| Cookies set when a video is played | YouTube / Google | playback and reach measurement | set by Google | only if you start a video (see 6.7) |
| Cookies of the booking widget | Calendly | appointment booking | set by Calendly | consent required |
bva_consent (local storage) | us | stores your cookie decision so we don't have to ask again on every visit | 6 months | strictly necessary, Section 25(2) no. 2 TDDDG |
trakyo_id | Trakyo | recognising your device in order to match a later enquiry to the source you came to us through | 1 year | consent required — set when you click a short link, not on this website (see 6.9) |
For conversion tracking, Google additionally documents the cookies Conversion (90 days) and IDE (13 months in the EEA). We have not checked in detail whether they are set on this website. According to Google, Google Tag Manager does not set any cookies of its own — but it loads the services that do. That is why we ourselves only load it once you have consented to reach measurement or to advertising.
How you can control this
On your first visit, a consent banner asks you what you want to allow. Until you have decided, this website loads none of the entries listed above and stores nothing on your device — not even Google Tag Manager. Two entries from the table do not depend on this decision. The first is trakyo_id: that cookie does not come from this website, but from the intermediate page of a short link you clicked before you ended up here (see 6.9). The second are the YouTube cookies, which are only set if you start a video yourself (see 6.7).
On the first level, "Accept all", "Reject all" and "Settings" stand side by side as equals: same size, same typeface, same colour, with no option highlighted or pre-selected. Under "Settings" you can decide on each of the four categories individually. The banner covers neither the legal notice nor this privacy policy, and you can use the site without deciding at all — in which case everything this website would otherwise load stays switched off.
You can change your decision or withdraw it with effect for the future at any time, via the *Cookie settings* button at the bottom left of every page. Withdrawing costs you just as few clicks as consenting. If you withdraw, we actively delete the Google entries we set from your browser — and likewise the cookie trakyo_id, even though it does not come from this website.
We store your decision in your browser's local storage under the name bva_consent, for six months. The entry contains only the time, the version of the banner text and your choice per category — no identifier by which you could be recognised.
Independently of that, you can prevent cookies through your browser settings or delete ones already set. For Google Analytics, the browser add-on at https://tools.google.com/dlpage/gaoptout is also available.
8.1 Enquiry form
On nine pages (contact, services and results, each in the English, German and Spanish version) we offer a multi-step enquiry form.
What we collect: your name, your email address, which path you're taking (creator or agency), your answers to five or six questions, and your preferred way of being contacted (Telegram or WhatsApp) together with the username or phone number. Technically, we also record the page you came from (referrer), how long it took you to fill in the form, and whether a control field invisible to you was filled in. Together with your enquiry, we also store your IP address, your browser's identifier (user agent) and the referrer permanently in our database — not just briefly in order to fend off spam.
Why we need it: We need your name, email address and preferred contact channel in order to be able to reply to you at all. We need your answers to the questions in order to assess whether and how we can help you. The processing time and the invisible control field serve exclusively to fend off spam. We process your IP address in order to detect automated bulk enquiries and to limit the number of submissions within a given period.
Mandatory fields are your name, your email address and — if you want us to get back to you — the contact channel together with the username or phone number. Without those details we cannot process your enquiry. All other details are voluntary.
Legal basis: For handling your enquiry, Art. 6(1)(b) GDPR — taking steps prior to entering into a contract at your request. For fending off spam and abuse, including the IP-based rate limit, Art. 6(1)(f) GDPR; our legitimate interest is specifically fending off automated bulk enquiries and protecting our systems from overload.
Where the data goes:
- into a MySQL database at our host IONOS (see 6.1),
- to a Telegram bot operated by us, which notifies us of the submission (see 6.8),
- to Trakyo, in order to match your enquiry to the source it originated from: your name, your email
address, the name of the form, where applicable a visitor ID assigned to you earlier, and, if you choose WhatsApp as your preferred way of being contacted, your phone number (see 6.9).
Storage period: We delete your enquiry once it has been dealt with conclusively and no statutory retention obligations stand in the way, but at the latest after 24 months.
8.2 Contact by email
If you write to us directly at info@boese-va.com, we process your email address, your name and the content of your message in order to answer it. The legal basis is Art. 6(1)(b) GDPR if your enquiry relates to a contract or the initiation of one, and otherwise Art. 6(1)(f) GDPR with our legitimate interest in answering enquiries.
9. Who else receives your data
We only pass on your data where it is necessary for the purposes described, where you have consented, or where we are legally required to do so. The recipients are:
- Hosting and database: IONOS SE (processor)
- Analytics and advertising: Google Ireland Limited and Google LLC
- Appointment booking: Calendly, LLC (processor)
- Videos: Google Ireland Limited (YouTube)
- Marketing attribution: Trakyo — role not yet clarified (see 6.9)
- Messenger notification and contact: Telegram Messenger Inc.
Service providers who process data exclusively on our behalf may only do so under Art. 28 GDPR on the basis of a separate contract and only on our instructions.
10. Transfers to countries outside the EU
Some of the services listed above process data outside the European Union. This concerns:
- Google (Tag Manager, Analytics, Ads, YouTube): transfer to Google LLC in the USA.
Google LLC is certified under the EU-US Data Privacy Framework; an adequacy decision by the Commission therefore exists. Standard contractual clauses under Art. 46(2)(c) GDPR apply in addition.
- Calendly: transfer to the USA. Calendly is self-certified under the EU-U.S. Data Privacy
Framework and additionally relies on standard contractual clauses for transfers.
- Telegram: processing outside the EU. There is no adequacy decision by the European
Commission for the British Virgin Islands (see 6.8).
Where data is transferred to countries without an adequacy decision, a residual risk remains despite contractual safeguards: the authorities of the country in question may under certain circumstances access the data without legal protection comparable to European law being available against it.
You can obtain a copy of the standard contractual clauses, or information on where you can view the safeguards, from us on request at info@boese-va.com (Art. 13(1)(f) GDPR).
11. How long we store data
We store personal data only for as long as it is necessary for the respective purpose or as long as statutory retention obligations require.
- Server log files: a maximum of eight weeks (see 5).
- Enquiries from the form: until the enquiry has been dealt with conclusively and no statutory
retention obligations stand in the way any longer, at the latest after 24 months (see 8.1).
- Appointment data at Calendly: 24 hours (see 6.6).
- Google Analytics: 2 months (see 6.3)
- Trakyo: event data 12 months, recognition cookie 1 year (see 6.9).
- Cookies and comparable entries: as stated in the table under 7.
- Email correspondence: until the enquiry has been dealt with conclusively and no statutory
retention obligations stand in the way any longer.
Where commercial or tax law retention obligations exist, we delete the data concerned only after those periods have expired. Until then, we restrict processing to fulfilling those obligations.
12. Your rights
You have the following rights in relation to us. An informal message to info@boese-va.com is enough.
- Access (Art. 15 GDPR): You can find out whether and which data we process about you, for what
purpose, to whom we pass it on and how long we store it — and you can request a copy of that data.
- Rectification (Art. 16 GDPR): We must correct incorrect data and complete incomplete data.
- Erasure (Art. 17 GDPR): You can request that your data be deleted. Statutory retention
obligations may stand in the way in individual cases — in which case we will tell you which ones.
- Restriction of processing (Art. 18 GDPR): Instead of deleting, we can also merely restrict the
processing, for example while we check whether your data is accurate.
- Data portability (Art. 20 GDPR): Data you have given us on the basis of consent or a contract
and that we process by automated means, we will provide to you in a common, machine-readable format or, on request, transmit directly to another controller.
- Withdrawal of consent (Art. 7(3) GDPR): You can withdraw consent once given at any time with
effect for the future. The lawfulness of processing carried out up to that point remains unaffected. Withdrawing must be as easy as giving consent.
- Objection (Art. 21 GDPR): see the highlighted section 13.
- Complaint to a supervisory authority (Art. 77 GDPR): see section 14.
Deadlines and costs: We respond to your request without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR). If a request is particularly complex, or if there are many requests, that period may be extended by up to two further months — we will inform you of this within the first month and state the reason. Handling your request is free of charge for you (Art. 12(5) GDPR). Only in the case of manifestly unfounded or excessive requests, in particular repetitive ones, may we charge a reasonable fee or refuse to act.
13. Right to object — please read this section
You have the right to object at any time to the processing of your personal data where we base that processing on Art. 6(1)(e) or (f) GDPR — that is, on a legitimate interest. This also applies to profiling based on those provisions.
Which processing operations this relates to here: the evaluation of the server log files (section 5), fending off spam and abuse including the IP-based rate limit on the enquiry form (section 8.1), the internal notification of new enquiries via Telegram (section 6.8), and the transmission of the details from your enquiry form.
What the objection does: If you object, we will no longer process your data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims (Art. 21(1) GDPR).
For direct marketing it applies absolutely: If you object to the processing of your data for direct marketing purposes, we will no longer process it for that purpose — no balancing of interests, no reason required from you, with immediate effect (Art. 21(2) and (3) GDPR).
How to object: informally by email to info@boese-va.com. No particular format is required, and you do not have to give reasons for your objection in the case of direct marketing.
14. Right to lodge a complaint with a supervisory authority
If you believe that we are infringing the GDPR when processing your data, you can lodge a complaint with a supervisory authority.
The lead authority, because of our seat in Cyprus, is:
Office of the Commissioner for Personal Data Protection (Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) 15, Kypranoros Street, 1061 Nicosia P.O. Box 23378, 1682 Nicosia, Cyprus Phone: +357 22 818 456 Email: commissioner@dataprotection.gov.cy Web: www.dataprotection.gov.cy
But you can just as well complain in Germany. Art. 77(1) GDPR gives you the right to turn to a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. If you live or work in Germany, that is the state data protection authority of your federal state. It will accept your complaint and cooperate with the Cypriot authority in the further proceedings.
For cookies and access to your device under Section 25 TDDDG, the German state data protection authorities are directly competent in any case; the GDPR's so-called one-stop-shop procedure does not apply to that.
15. No automated decision-making
We do not make decisions about you based solely on automated processing which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
Whether and how we respond to an enquiry is decided by people.
16. Do you have to give us your data?
Providing your data is neither required by law nor by contract, and you are not obliged to give it to us.
For certain functions, however, we do need it: without your name, email address and contact channel we cannot answer your enquiry, and without the technical access data described in section 5 we cannot deliver the website. The only consequence of not providing it is that the function in question cannot be used — you will suffer no disadvantages beyond that.
17. Security
This website is delivered over HTTPS throughout. Requests via http:// are automatically redirected to the encrypted connection, and our server additionally instructs browsers to call up the domain in encrypted form only from then on (HSTS).
We limit access to the stored data to the people who need it for their tasks, and we use technical and organisational measures to protect your data against loss, alteration and unauthorised access. No one can guarantee absolute protection; we adapt our measures in line with technical developments.
18. Links to other websites
Our pages contain links to third-party websites, including Telegram and other platforms. We have no influence over their content or their data processing. As soon as you click such a link, the privacy policy of the respective provider applies. The respective operators are solely responsible for the processing that takes place there.
19. Changes to this privacy policy
We adapt this privacy policy when the services we use, our processing operations or the legal situation change. The version available here always applies; you will find the current status at the beginning and at the end of this document.
If in doing so we introduce processing that requires your consent, we will obtain that consent separately. Your continued use of the website does not replace consent.
Status of this privacy policy: 10 August 2026