← Back

Privacy Policy

Last updated: August 2026

1. Data Controller

Frederik von der Heyden
Danzigweg 5a, 59755 Arnsberg, Germany
Email: frederik@frederikvonderheyden.de

2. Scope of Data Processing

This website is a static informational site. It uses no cookies, no tracking, no analytics, and no contact forms.

Personal data is only processed when you voluntarily interact with our services, such as purchasing a subscription (see Section 6) or contacting us by email.

3. Server Log Files

The hosting provider automatically collects and stores information in server log files that your browser transmits automatically:

This data cannot be attributed to specific individuals. It is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the technical operation of the website). Logs are deleted after 30 days.

4. Hosting

This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner processes the above data on our behalf. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place. All data processing takes place exclusively in Germany.

5. SSL/TLS Encryption

This site uses SSL/TLS encryption for security. You can recognize an encrypted connection by the lock icon in your browser's address bar and the "https://" prefix.

6. Payment Processing

Paid subscriptions are processed via Stripe, Inc. (510 Townsend St, San Francisco, CA 94103, USA). When you purchase a subscription, Stripe processes your payment data (name, email, payment method) under their own privacy policy. We do not store credit card numbers or payment details on our servers. See: Stripe Privacy Policy.

Stripe is certified under the EU-US Data Privacy Framework, ensuring an adequate level of data protection for transatlantic data transfers.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, contact us at frederik@frederikvonderheyden.de.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR. The competent authority for our business is:
Landesbeauftragte fuer Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2-4, 40213 Duesseldorf, Germany.

9. AI-Generated Content Disclosure

Parts of this website's content, including text and visual elements, were created with the assistance of AI tools. In accordance with the EU AI Act (Art. 50), we disclose that AI-generated content is used. Our products (GuardRail, Compliance Shield, AgentStack) are AI governance and compliance tools — they assist with security and regulatory compliance but do not replace professional legal counsel.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. The current version is always available on this page.