Digital RelaxMunich
Preparing website experience
Digital Relax logo lower section

Modern websites, clear systems and digital workflows for small businesses in Munich and the surrounding area.

AuditDesignLaunch
Web DesignAutomation / Support
Digital Relax Logo

PRIVACY / DIGITAL RELAX

Privacy Policy

Information about the processing of personal data when using our website and our digital enquiry, referral, preview and offer systems. This English translation is provided for convenience; in case of discrepancies, the German version is authoritative.

Updated: 05.09.2026

1. Controller

The controller responsible for data processing on this website is:

Digital Relax · Owner: Elias Stüdemann von Ehrenstein · Parkstraße 31 · 82065 Baierbrunn · Germany

Phone: +49 155 10172179 · Email: info@digital-relax.de

2. Principles of Processing

We process personal data only to the extent required to securely provide this website, handle enquiries, carry out pre-contractual measures and contracts, document offer acceptances, or on the basis of consent.

The data processed in each case depends on the functions you use. We apply the principles of data minimisation, purpose limitation and storage limitation.

3. Hosting and Technical Delivery via Vercel

This website is delivered via Vercel. When you access it, technically necessary connection and log data may be processed, in particular IP address, access time, requested resource, referrer, browser and device information. This processing serves the secure, stable and performant delivery of the website.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable provision of the website. Where Vercel processes personal data on our behalf, this takes place under the applicable contractual data-protection arrangements.

4. Contact and Appointment Enquiries

If you contact us through contact or appointment forms, by email or by phone, we process the information you provide, in particular your name, email address, phone number, company, message, requested service and appointment information, in order to handle your enquiry and respond to follow-up questions.

Processing is based on Article 6(1)(b) GDPR where it serves to take steps prior to entering into a contract or to perform a contract. Other business communication is processed on the basis of our legitimate interest in appropriate communication under Article 6(1)(f) GDPR.

5. Operational Data Processing via Convex

We use Convex for operational functions of the website and Digital Relax system. This may include contact and appointment enquiries, referral information, status information, settings, and data from the protected preview and offer system. Public Digital Relax website text and images are not managed through Convex as a live editorial source.

Depending on the process, form data, customer and contact data, offer and project information, timestamps, technical status data and security information may be processed. The legal basis depends on the relevant process, in particular Article 6(1)(b) or (f) GDPR. Where Convex processes data on our behalf, the applicable data-processing arrangements apply.

6. Email Delivery via Resend

We use Resend, a service of Plus Five Five, Inc., for the technical delivery of certain transactional and business emails. The data required for delivery may be processed, in particular recipient and sender addresses, subject line, message content and technical delivery information.

The legal basis follows the purpose of the communication, in particular Article 6(1)(b) GDPR for pre-contractual or contractual communication and Article 6(1)(f) GDPR for other necessary business communication. Newsletters or comparable promotional communication are sent only where a lawful basis exists for that purpose.

7. Referrals and Third-Party Data

Through the referral function, information about a company or contact person may be provided to us. We expressly ask that personal contact data of third parties is shared only where the person concerned agrees to the disclosure and, where direct contact is selected, to being contacted by Digital Relax. Alternatively, the referring person can make the first introduction themselves.

Where personal data is not obtained directly from the person concerned, it originates from the referral. We process only the contact details and information provided about the possible business need. When we make direct initial contact, we inform the person concerned about the source of the data and these privacy notices in accordance with Article 14 GDPR.

Processing takes place to handle the referral and possible business initiation on the basis of Article 6(1)(f) GDPR and, once the person concerned personally enters into contractual negotiations, where applicable Article 6(1)(b) GDPR. Our legitimate interest is the handling of expressly initiated business referrals.

8. Protected Previews and Offer Acceptances

For protected website previews, depending on the configuration, we process the company, names and email addresses of authorised recipients, project and offer data, access and status information, timestamps and records of accepted preview terms and binding offer acceptances.

For evidentiary purposes, we store in particular the confirmed offer and terms version, price and billing information, the name and, where applicable, role of the confirming person, the timestamp, cryptographic hashes and technical audit data. Passwords and access tokens are not stored in plain text as evidence.

For confirmations and comparable evidence events, we additionally record a server-side technical request context. This may include a request ID, the IP address observed by the server, a masked representation derived from that address, and coarse browser, operating-system and device-class information. The full IP address is encrypted and retained only briefly; its deletion time is set to seven days after capture and it is then removed by the automated cleanup process. We do not store the full User-Agent, device fingerprints or derived location for this purpose. An IP address is used only as technical context and is not treated as proof of a particular person’s identity.

Processing serves pre-contractual measures and contract performance under Article 6(1)(b) GDPR and our legitimate interest in access protection, abuse prevention and traceable documentation of legally relevant declarations under Article 6(1)(f) GDPR.

9. Technically Necessary Storage and Cookie Choice

The website uses technically necessary local storage, in particular for display and theme settings and for your cookie choice. Your consent decision is stored in your browser's local storage. These operations support the use of the service and the management of your selected settings.

Where access to information on your terminal device is strictly necessary for the service expressly requested by you, it is carried out in accordance with Section 25(2) TDDDG. Where applicable, the related processing of personal data is based on Article 6(1)(f) GDPR.

You can change your choice at any time using ‘Cookie settings’ in the footer.

10. Google Analytics 4

After your explicit consent, we use Google Analytics 4 provided by Google Ireland Limited. The Google tag is loaded only after you have consented to analytics in the cookie banner. Google Analytics processes in particular page views, timestamps, referrer and device and browser information and may set analytics cookies.

In our configuration, ad storage, personalised advertising, Google Signals and personalised advertising signals are disabled. The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw consent at any time with effect for the future using ‘Cookie settings’.

11. Recipients and International Data Transfers

Personal data is received only by internal recipients and external service providers who require it for the purposes described. These may include Vercel for hosting, Convex for operational data processing, Resend for email delivery and Google for consent-based web analytics.

Where personal data is processed outside the European Union or European Economic Area, transfer takes place only in accordance with Chapter V GDPR. Depending on the provider and processing activity, this may include an applicable adequacy decision, Standard Contractual Clauses or other appropriate safeguards. The current contractual and data-protection arrangements of the respective service are authoritative.

12. Retention Period

We retain personal data only for as long as it is required for the relevant purpose or as long as statutory retention and evidentiary duties or legitimate evidentiary interests require continued retention.

Contact, appointment and referral data that does not lead to a contract is reviewed regularly and deleted once further handling or a reasonable business record is no longer required. Security and session data is retained only for the technically necessary period. Contract, offer-acceptance, billing and tax-relevant records may be retained for longer in accordance with the applicable statutory retention and limitation periods.

For technical confirmation evidence, the full observed IP address is stored separately in encrypted form with a deletion time set to seven days after capture. After the automated cleanup, only the masked network indication, server-side request ID, coarse browser/system/device classes and cryptographic evidence information remain where still required for the relevant evidentiary purpose.

13. Your Rights

Subject to the statutory requirements, you have in particular the right of access, rectification, erasure, restriction of processing and data portability. Consent can be withdrawn at any time with effect for the future. You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation.

To exercise your rights, a message to info@digital-relax.de is sufficient.

14. Right to Lodge a Complaint

You have the right to lodge a complaint with a data-protection supervisory authority. For non-public bodies in Bavaria, the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, is in particular responsible.

15. Security and Updates

We use appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. This privacy policy is updated when services, processing activities or legal requirements change.