Sprache:

Privacy Policy

Last updated: February 22, 2026

1. Introduction

This Privacy Policy informs you about the processing of personal data when using our website designpodio.com and our services (SaaS platform for websites, blogs, online shops, and design services). Our services are directed exclusively at entrepreneurs (B2B). We explain which data we collect, how we process it, and which rights you have.

2. Controller
2.1)

Controller within the meaning of the GDPR:

DesignPodio – Karen Imani Shakibaei
Hildegard-Knef-Straße 51
40549 Düsseldorf
Germany
Email: [email protected]

3. Collected Data and Purposes of Processing
3.1) Automatically Collected Data When Visiting the Website

When accessing our website, technical data is automatically processed (e.g., IP address – anonymized –, browser type, access times, referrer URL, device data). Purpose: Provision of the website, system security, error analysis, and improvement of the offer. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

3.2) Data Provided During Registration, Ordering, and Use of Services

During registration, ordering, or support requests, we collect: first and last name, company name, address, email address, optional phone number, VAT ID (for entrepreneurs), payment data (via Stripe). Purpose: Contract performance, invoicing, customer support, provision of the platform and design services. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligations, e.g., invoicing).

3.3) Data in the Platform (Data Processing on Behalf)

We do not collect or process personal data of your end users. The platform is provided as a hosted SaaS solution; you as the customer are the controller for your end users’ data. We act as processor (Art. 28 GDPR). Details on data processing within the platform are provided in our separate page located in the footer “Software & Data”. We conclude separate data processing agreements (DPA) where required.

4. Cookies and Similar Technologies
4.1) Technically Necessary Cookies

We use technically necessary cookies (e.g., for login, registration, session management, Instagram feed display) without consent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest) and/or § 25(2) TTDSG.

4.2) Non-Essential Cookies and Tracking

Analytics and marketing cookies (Google Analytics with IP anonymization, Hotjar) are only set after your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG). Consent is obtained via our cookie consent tool and can be withdrawn at any time.

4.3) Google Fonts

We use Google Fonts locally (no external call), so no data is transmitted to Google.

5. Embedded Services and Third-Party Providers
5.1) Google Analytics and Hotjar

Analytics: Google Analytics (IP anonymized) and Hotjar for usage analysis. Providers: Google Ireland Ltd. (Ireland) / Hotjar Ltd. (Malta). Legal basis: Consent.

5.2) YouTube Videos

Embedding of YouTube videos (no-cookie mode where possible). Provider: Google Ireland Ltd. Legal basis: Consent.

5.3) Instagram Feed

Embedding of Instagram content. Provider: Meta Platforms Ireland Ltd. Legal basis: Consent / legitimate interest (display of social content).

5.4) Payment Processing (Stripe)

Payments processed via Stripe. Provider: Stripe Payments Europe Ltd. (Ireland). Legal basis: Contract performance.

5.5) Email Delivery (Brevo)

Transactional and marketing emails via Brevo. Provider: Brevo SAS (France). Legal basis: Contract performance / consent.

5.6) Hosting & Infrastructure

Hosting and servers via selected infrastructure and hosting providers (processors). No personal data except technical logs (e.g., traffic volume, visitor count).

6. Data Sharing

Data is only shared where necessary: with processors (hosting, support, payment, email), for legal obligations, or to defend legal claims. No sale of data.

7. International Data Transfers

Some services (Stripe, Google Analytics/YouTube, Hotjar, Instagram/Meta, hosting providers) transfer data to the USA. We rely on:

  • EU-U.S. Data Privacy Framework (DPF) for certified providers,
  • EU Standard Contractual Clauses (SCC) and supplementary measures where required.
8. Data Storage and Deletion

Contract data: Up to 10 years (statutory retention obligations under HGB/AO). Other data: As long as necessary for the purposes or until withdrawal. Server logs (anonymized): Short-term only.

9. Data Security

We implement technical and organizational measures (e.g., encryption, access controls). No absolute protection possible.

10. Your Rights

You have the right to access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent (Art. 15–22 GDPR). Contact: [email protected]. You may lodge a complaint with a supervisory authority.

11. Changes to This Privacy Policy

We may update this policy as needed. The current version is always available on the website. Significant changes will be notified.

  • Products
  • Design Service
  • Pricing
  • More