Legal
Privacy notice
1. Data Controller
The controller responsible for the processing of personal data on this website is:
Dragonfly Support
Kiss-Rabata Júlia
Erwin-Bock-Str. 1
12559 Berlin
info@dragonflysupport.de
If you have any questions regarding data protection, you can contact me at the above email address at any time.
No Data Protection Officer has been appointed, unless there is a legal obligation to appoint one.
2. General Information on Data Processing
The protection of your personal data is important to me. I process personal data exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR) and applicable German data protection law.
Personal data means any information relating to an identified or identifiable natural person.
This Privacy Policy explains which personal data is processed when you use this website, for what purposes the data is processed, the legal basis for such processing, and what rights you have as a data subject.
3. Website Access and Hosting by Netlify
This website is hosted by Netlify.
When you access the website, the hosting provider processes technically necessary information. This may include, in particular:
- IP address,
- date and time of access,
- browser and operating system information,
- pages accessed and technical access data,
- and other technical information required to provide and secure the website.
The processing is carried out primarily to ensure the technical provision, stability and security of the website and to prevent and analyse misuse and technical disruptions.
The legal basis for this processing is Art. 6(1)(f) GDPR. The legitimate interest lies in providing the website securely and ensuring its proper functioning.
Netlify may process personal data outside the country in which the data was collected. According to its own information, Netlify uses appropriate safeguards for such transfers, including the Standard Contractual Clauses adopted by the European Commission and, where applicable, the EU-U.S. Data Privacy Framework.
The retention period depends on the technical and legal requirements. Data is deleted as soon as it is no longer required for the purposes stated above, unless statutory retention obligations apply.
4. Contact Form – Web3Forms
The contact form on this website uses the service Web3Forms.
If you contact me via the contact form, the information you enter will be processed. This may include, in particular:
- name,
- email address,
- content of your message,
- and any other information you voluntarily provide.
The data is used exclusively to process your enquiry and to communicate with you regarding your request.
The legal basis is generally Art. 6(1)(b) GDPR if your enquiry relates to the initiation or performance of a contract. In other cases, processing is based on Art. 6(1)(f) GDPR, namely my legitimate interest in responding to enquiries.
According to Web3Forms, data submitted through a form is not permanently stored by Web3Forms but is processed and forwarded to the email address or endpoint specified by the website operator. Web3Forms states that technical server logs may contain personal information and are regularly deleted according to its own retention practices.
Web3Forms’ servers are located in the United States. Where personal data is transferred to a third country, the applicable legal requirements for such transfers are observed.
5. Appointment Scheduling via Calendly
This website uses Calendly for appointment scheduling.
When you book an appointment through Calendly, the personal data required to arrange the appointment is transmitted to Calendly.
This may include, in particular:
- first and last name,
- email address,
- selected date and time,
- booked service,
- information regarding the type of appointment, such as online or in-person,
- and any additional information you voluntarily provide during the booking process.
The processing is carried out in particular for the purpose of:
- scheduling and managing appointments,
- managing availability,
- sending booking confirmations and appointment-related notifications,
- and preparing and providing the booked service.
The legal basis for processing is Art. 6(1)(b) GDPR insofar as the appointment booking is necessary for the performance of a contract or for taking steps prior to entering into a contract.
Calendly processes personal data in connection with the services I use, including as a processor acting on my behalf. Calendly provides a Data Processing Addendum (DPA) containing provisions regarding the processing of personal data and international data transfers.
Personal data may also be processed in the United States and other countries. Where required, appropriate safeguards under applicable data protection law are used for such transfers.
6. Payment Processing via Stripe
Payments for paid services are processed through Stripe.
When you book and pay for a paid service, the data required to process the payment is transmitted to Stripe.
This may include, in particular:
- name,
- email address,
- billing information,
- payment information,
- transaction details,
- amount paid,
- date and status of the payment,
- and information relating to refunds or payment disputes.
The processing is carried out primarily for the purpose of processing and administering payments, assigning payments to bookings, preventing fraud, and complying with legal obligations.
The legal basis is Art. 6(1)(b) GDPR insofar as processing is necessary for the performance of a contract. Where Stripe processes data to comply with legal obligations, the legal basis is Art. 6(1)(c) GDPR.
Depending on the specific processing activity, Stripe may act either as a processor or as an independent data controller. The processing of personal data may also involve transfers to third countries, including the United States. Stripe provides appropriate contractual and other safeguards for such transfers.
Further information on the processing of personal data by Stripe can be found in Stripe’s Privacy Policy.
7. Link to Instagram
This website contains a link to my Instagram profile.
No Instagram content is automatically embedded on this website. If you click the Instagram link, you will leave this website and be redirected to Instagram.
From that point onwards, Instagram’s own privacy policy and data processing practices apply.
Simply visiting this website does not result in personal data being transmitted to Instagram through the Instagram link.
8. Domain and Domain Registration
The domain used for this website was registered through checkdomain.
As part of the registration and management of the domain, checkdomain processes the contractual and contact information required for domain registration and administration.
The processing of personal data by checkdomain is governed by checkdomain’s own privacy policy and applicable contractual data protection provisions.
The registration of the domain itself does not mean that personal data of every visitor to this website is automatically transmitted to checkdomain.
9. Fonts
The fonts used on this website are loaded from our own server or from the hosting infrastructure used for the website.
No automatic connection is made to external font services such as Google Fonts.
By hosting the fonts locally, the website avoids establishing a connection to an external font provider when the website is accessed and therefore avoids the transmission of information such as the visitor’s IP address to such a provider.
10. Cookies and Similar Technologies
According to the current configuration, this website does not use cookies for advertising, tracking or analytics purposes.
Where technically necessary cookies or similar technologies are used solely to provide a service explicitly requested by you, they are used in accordance with the applicable legal requirements.
Where consent is legally required for storing information on your device or accessing information already stored on your device, consent will be obtained beforehand. The relevant legal provision is, in particular, Section 25 of the German Telecommunications-Telemedia Data Protection Act (TDDDG).
11. Legal Bases for Processing
Depending on the specific purpose, personal data is processed on the basis of the following legal grounds:
Art. 6(1)(a) GDPR – Consent
Where you have given your explicit consent to the processing of your personal data.
Art. 6(1)(b) GDPR – Contractual necessity
Where processing is necessary for the performance of a contract or for taking steps prior to entering into a contract, in particular in connection with appointment bookings, consulting services and payment processing.
Art. 6(1)(c) GDPR – Legal obligation
Where processing is necessary to comply with a legal obligation, in particular statutory retention and documentation requirements.
Art. 6(1)(f) GDPR – Legitimate interests
Where processing is necessary for my legitimate interests, in particular for the secure technical operation of the website, protection against misuse and the handling of general enquiries, provided that these interests are not overridden by your rights and freedoms.
12. Data Retention
Personal data is stored only for as long as necessary for the respective purpose or as required by statutory retention obligations.
Once the purpose for processing no longer applies, the data will be deleted unless statutory retention obligations or another legally permissible reason requires continued storage.
Data that must be retained due to statutory obligations will be stored for the applicable retention period and subsequently deleted.
Data relating to enquiries will generally be retained for as long as necessary to process the enquiry and for reasonable follow-up communication. If there is no legal or contractual reason for further storage, the data will subsequently be deleted.
13. Recipients of Personal Data
Depending on how you use the website and which services you request, personal data may be transmitted to or processed by the following service providers:
- Netlify – website hosting and technical infrastructure
- Web3Forms – processing and forwarding of contact form submissions
- Calendly – appointment scheduling and appointment management
- Stripe – payment processing
- checkdomain – domain registration and domain management, insofar as this concerns the domain holder’s data.
Personal data will only be disclosed to other third parties where there is an applicable legal basis or a legal obligation to do so.
14. International Data Transfers
When using certain external service providers, personal data may be processed outside the European Union or the European Economic Area.
This may particularly apply to services such as Calendly, Stripe, Netlify and Web3Forms.
Where personal data is transferred to a third country, the applicable requirements of the GDPR are observed. This may include an adequacy decision by the European Commission, Standard Contractual Clauses or other appropriate safeguards permitted under the GDPR.
The respective providers provide information in their own privacy policies and contractual documentation regarding the mechanisms used for international data transfers.
15. Your Rights as a Data Subject
Subject to the applicable legal requirements, you have the following rights:
Right of access
You have the right to request information about whether and which personal data concerning you is being processed.
Right to rectification
You have the right to request the correction of inaccurate personal data or the completion of incomplete personal data.
Right to erasure
Under certain legal conditions, you have the right to request the deletion of your personal data.
Right to restriction of processing
Under certain legal conditions, you have the right to request the restriction of the processing of your personal data.
Right to data portability
Under the applicable legal conditions, you have the right to receive personal data that you have provided in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller.
Right to object
You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where the processing is based on Art. 6(1)(e) or (f) GDPR.
Where personal data is processed for direct marketing purposes, you have the right to object to such processing at any time.
Right to withdraw consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
To exercise any of these rights, you may contact me using the contact details provided above.
16. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection law.
The competent supervisory authority may, in particular, be:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
The right to lodge a complaint is provided for under Art. 77 GDPR.
17. Automated Decision-Making
Dragonfly Support does not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
18. Updates to this Privacy Policy
This Privacy Policy may be updated if the services used on this website, the nature of the data processing or the applicable legal requirements change.
The current version published on this website shall apply.
Last updated: August 2026