Privacy Policy

Last updated: 25 September 2025

Thank you for your interest in My German Origin. This page explains what personal data we process when you use this website, on what legal basis, and which rights you have under the EU General Data Protection Regulation (GDPR).

1) Controller

Gunar Bodendiek
Silberdistelweg 9
12357 Berlin
Germany
Email: info@mygermanorigin.com

2) What data we process

a) Contact form

When you submit the contact form, we process the information you provide (e.g., first name, last name, email address, phone number if provided, selected service(s), and your message).

  • Purpose: Handling your enquiry and any follow-up communication.
  • Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps / performance of a contract) or Art. 6(1)(a) GDPR (consent) if your enquiry does not relate to a contract.
  • Retention: We keep enquiries only as long as necessary to process them and in line with statutory storage obligations (e.g., under commercial/tax law, if applicable).

b) Server log files (technical necessity)

When you visit this site, the web server automatically processes minimal technical data (such as IP address, date/time, requested URL, referrer, user agent) to deliver pages and ensure security.

  • Purpose: Technical delivery, troubleshooting, and security.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interests in secure, reliable website operation).
  • Retention: Log data is deleted or anonymized after a short period unless needed to investigate security incidents.

3) Cookies and tracking

We do not set any cookies for marketing or personalization. The only cookies used on this site are those associated with Google Analytics (see Section 4). No other cookies are placed.

4) Google Analytics (GA4)

We use Google Analytics to understand how visitors use our website and to improve our content. Google Analytics (GA4) may use cookies and similar technologies.

  • Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; for some processing, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
  • Data categories: Pseudonymous usage data (e.g., page views, events, approximate location, device/browser info). We have activated IP anonymization, so your IP address is shortened before further processing.
  • Purpose: Audience measurement and website optimization.
  • Legal basis: Art. 6(1)(a) GDPR (your consent via the cookie/consent banner). Google Analytics only runs if you give consent. You can withdraw consent at any time via the banner settings.
  • Retention: We currently retain Google Analytics event data for 14 months (or the closest available GA4 retention setting).
  • International transfers: Where applicable, data may be processed by Google LLC in the USA. Google participates in the EU–US Data Privacy Framework. We also have a Data Processing Agreement with Google as required by Art. 28 GDPR.
  • Opt-out: You can revoke consent via the banner at any time. You can also configure your browser to block cookies or use Google’s browser add-on for Analytics opt-out.

Google Analytics cookies (GA4)

Aside from strictly necessary technical operation (see logs), the only cookies we use are for Analytics:

NamePurposeDuration
_gaDistinguishes users (pseudonymous ID).Up to 2 years
_ga_<container-id>Persists session state for GA4.Up to 2 years
_gid (if used)Distinguishes users.24 hours

No marketing, social media, or other third-party cookies are set.

5) Recipients and processors

  • Hosting provider: For secure hosting and delivery of this website (server operation and logs).
  • Email provider: To receive and respond to your enquiries.
  • Google (Analytics): As described above.

All service providers are contractually bound to process personal data only on our instructions and in compliance with GDPR (Data Processing Agreements where required).

6) How long we keep your data

We process personal data only as long as necessary for the stated purposes or as required by law. Contact enquiries are removed once handled unless statutory retention or legitimate interests (e.g., legal claims) require longer storage. Analytics data follows the retention settings noted above.

7) Your rights under GDPR

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21) — in particular to processing based on legitimate interests
  • Right to withdraw consent at any time (Art. 7(3)), without affecting the lawfulness of processing before withdrawal

You also have the right to lodge a complaint with your local supervisory authority. In Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit.

8) Security

We use technical and organizational measures (e.g., TLS/SSL encryption, access controls) to protect your data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

9) No automated decision-making

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

10) Updates to this policy

We may update this policy when our services or legal requirements change. The current version is always available on this page.

Contact

If you have questions about this policy or your data, please contact us at info@mygermanorigin.com.