Privacy Policy
Last updated: February 22, 2026
1. Introduction
This Privacy Policy informs you about the processing of personal data when using our website designpodio.com and our services (SaaS platform for websites, blogs, online shops, and design services). Our services are directed exclusively at entrepreneurs (B2B). We explain which data we collect, how we process it, and which rights you have.
2. Controller
2.1)
Controller within the meaning of the GDPR:
DesignPodio – Karen Imani Shakibaei
Hildegard-Knef-Straße 51
40549 Düsseldorf
Germany
Email: [email protected]
3. Collected Data and Purposes of Processing
3.1) Automatically Collected Data When Visiting the Website
When accessing our website, technical data is automatically processed (e.g., IP address – anonymized –, browser type, access times, referrer URL, device data). Purpose: Provision of the website, system security, error analysis, and improvement of the offer. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
3.2) Data Provided During Registration, Ordering, and Use of Services
During registration, ordering, or support requests, we collect: first and last name, company name, address, email address, optional phone number, VAT ID (for entrepreneurs), payment data (via Stripe). Purpose: Contract performance, invoicing, customer support, provision of the platform and design services. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligations, e.g., invoicing).
3.3) Data in the Platform (Data Processing on Behalf)
We do not collect or process personal data of your end users. The platform is provided as a hosted SaaS solution; you as the customer are the controller for your end users’ data. We act as processor (Art. 28 GDPR). Details on data processing within the platform are provided in our separate page located in the footer “Software & Data”. We conclude separate data processing agreements (DPA) where required.
4. Cookies and Similar Technologies
4.1) Technically Necessary Cookies
We use technically necessary cookies (e.g., for login, registration, session management, Instagram feed display) without consent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest) and/or § 25(2) TTDSG.
4.2) Non-Essential Cookies and Tracking
Analytics and marketing cookies (Google Analytics with IP anonymization, Hotjar) are only set after your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG). Consent is obtained via our cookie consent tool and can be withdrawn at any time.
4.3) Google Fonts
We use Google Fonts locally (no external call), so no data is transmitted to Google.
5. Embedded Services and Third-Party Providers
5.1) Google Analytics and Hotjar
Analytics: Google Analytics (IP anonymized) and Hotjar for usage analysis. Providers: Google Ireland Ltd. (Ireland) / Hotjar Ltd. (Malta). Legal basis: Consent.
5.2) YouTube Videos
Embedding of YouTube videos (no-cookie mode where possible). Provider: Google Ireland Ltd. Legal basis: Consent.
5.3) Instagram Feed
Embedding of Instagram content. Provider: Meta Platforms Ireland Ltd. Legal basis: Consent / legitimate interest (display of social content).
5.4) Payment Processing (Stripe)
Payments processed via Stripe. Provider: Stripe Payments Europe Ltd. (Ireland). Legal basis: Contract performance.
5.5) Email Delivery (Brevo)
Transactional and marketing emails via Brevo. Provider: Brevo SAS (France). Legal basis: Contract performance / consent.
5.6) Hosting & Infrastructure
Hosting and servers via selected infrastructure and hosting providers (processors). No personal data except technical logs (e.g., traffic volume, visitor count).
6. Data Sharing
Data is only shared where necessary: with processors (hosting, support, payment, email), for legal obligations, or to defend legal claims. No sale of data.
7. International Data Transfers
Some services (Stripe, Google Analytics/YouTube, Hotjar, Instagram/Meta, hosting providers) transfer data to the USA. We rely on:
- EU-U.S. Data Privacy Framework (DPF) for certified providers,
- EU Standard Contractual Clauses (SCC) and supplementary measures where required.
8. Data Storage and Deletion
Contract data: Up to 10 years (statutory retention obligations under HGB/AO). Other data: As long as necessary for the purposes or until withdrawal. Server logs (anonymized): Short-term only.
9. Data Security
We implement technical and organizational measures (e.g., encryption, access controls). No absolute protection possible.
10. Your Rights
You have the right to access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent (Art. 15–22 GDPR). Contact: [email protected]. You may lodge a complaint with a supervisory authority.
11. Changes to This Privacy Policy
We may update this policy as needed. The current version is always available on the website. Significant changes will be notified.