Privacy Policy
This is an English translation provided for convenience. The German-language version of this privacy policy is legally binding.
1. Privacy at a glance
Protecting your personal data matters to us. Below we explain what personal data is processed when you visit this website and when you contact us.
Personal data is any information that can be used to identify a natural person, directly or indirectly.
Processing is based in particular on the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG).
2. Controller
The controller responsible for data processing on this website is:
Kern Digital
Owner: Niklas Harnack
Dreihäuser Straße 37
35085 Ebsdorfergrund
Germany
Phone: +49 176 7265 9615
Email: contact@kerndigital.de
The controller within the meaning of the GDPR is Niklas Harnack.
3. Hosting
This website is hosted by the following provider:
IONOS SE
Elgendorfer Str. 57
56410 Montabaur, Germany
When you visit our website, the hosting provider's web server processes technically necessary data. This may include in particular:
- IP address of the device used
- Date and time of access
- Page or file accessed
- Previously visited page / referrer URL
- Browser type and version
- Operating system used
- Amount of data transferred
- HTTP status code
- Requesting internet service provider
This processing is carried out to technically deliver the website, ensure the stability and security of the service, and detect potential attacks or misuse.
The legal basis is Art. 6 (1)(f) GDPR. Our legitimate interest lies in the secure, stable, and functional operation of our website.
Server log files are generally deleted after 7 days. Longer retention may occur if necessary to investigate a specific security incident. In such a case, the relevant data is deleted once the investigation is complete, unless statutory retention obligations or other legal grounds require otherwise.
Where required, we have entered into a data processing agreement with our hosting provider pursuant to Art. 28 GDPR.
4. Encrypted connection
For security reasons, this website uses SSL/TLS encryption. This protects transmitted content, such as inquiries submitted through a contact form, from unauthorized access by third parties.
You can typically recognize an encrypted connection by the padlock icon in your browser's address bar and by the web address beginning with "https".
5. Contact forms and getting in touch
You can reach us in several ways: through the general contact form, by requesting a free website analysis, through the "Request a website" and "Request a shop check" forms, or by email or phone.
Depending on the form used, the following data may in particular be processed:
- Name
- Email address
- Phone number
- Website or store address
- Desired service or project type (e.g., business website, landing page, online store, relaunch)
- Project goal and desired timeline
- Details about products marketed or planned
- Content and subject of the message
- Other information you provide
- Time of contact
All forms additionally contain a honeypot field that is not visible to you. It is used exclusively to automatically detect spam bots and is only evaluated if it gets filled in by a script, contrary to normal use.
Processing takes place for the purpose of handling and responding to your inquiry, and for the resulting communication. After submitting the form, you'll also automatically receive a confirmation email at the address you provided.
Where your inquiry is aimed at entering into a contract or relates to an existing contract, processing is based on Art. 6 (1)(b) GDPR. For other business or general inquiries, processing is based on Art. 6 (1)(f) GDPR. Our legitimate interest lies in the proper and efficient handling of inquiries addressed to us.
Providing this data is neither legally nor contractually required. However, without the information marked as required, we may not be able to process your inquiry.
Data is deleted once your inquiry has been fully handled and no statutory retention obligations, contractual reasons, or legitimate interests in further storage remain. If a contractual relationship is entered into, the data may continue to be stored as part of our business and contract records in line with statutory retention periods.
For sending emails, we use the open-source library PHPMailer, which runs on our own web server and uses your data solely to send messages via our email mailbox. No data is passed on to third parties in this process.
6. Cookies and local storage technologies
Our website uses technically necessary cookies or comparable storage technologies where required to provide certain features.
This includes, in particular, storing your choice from the cookie banner (technical name: cookieConsent, stored in your browser's local storage). This prevents the banner from reappearing on every page visit.
Under Section 25 (2) TDDDG, no consent is required for technically necessary storage or access where this is strictly necessary to provide a digital service you have explicitly requested. The legal basis for the related processing of personal data is Art. 6 (1)(f) GDPR.
Non-essential technologies, in particular the Google Analytics described below, only become active after you explicitly consent via the cookie banner. Until then, data collection is technically blocked (see Section 7).
Consent already given can be withdrawn at any time with future effect by clearing this website's data in your browser; the cookie banner will then reappear. This does not affect the lawfulness of processing carried out prior to withdrawal.
7. Google Analytics
We use the web analytics service Google Analytics (GA4) on our website, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Google Analytics uses cookies or comparable technologies that allow analysis of your use of our website. The information generated in this process — including a shortened IP address, pages visited, time spent, and technical device data — is generally transmitted to and processed on a Google server.
Consent via Google Consent Mode v2: Google Analytics only becomes active after you actively select "Accept all" in the cookie banner. Until then, data collection is technically set to "denied"; no analytics cookies are set and no personal usage data is transmitted to Google. If you click "Necessary only," Google Analytics stays permanently disabled.
We have enabled IP anonymization (anonymize_ip). This shortens your IP address within the European Union or the European Economic Area before any further processing.
The legal basis for using Google Analytics, once consent has been given, is Section 25 (1) TDDDG together with Art. 6 (1)(a) GDPR.
Google also processes some data in the United States. Google is certified under the EU-U.S. Data Privacy Framework, which is intended to ensure an adequate level of data protection for transfers of data to the US. Further information is available in Google's privacy policy at policies.google.com/privacy.
You can withdraw consent you've given at any time by clearing this website's data in your browser; the cookie banner will then reappear and you can choose again.
8. Fonts (Google Fonts)
For a consistent display of typefaces, we use Google Fonts (Space Grotesk, Inter, JetBrains Mono). The font files are hosted locally on our own server.
No connection to Google's servers is made in this process, and no data — in particular no IP address — is transmitted to Google. The use of these fonts therefore requires no consent and involves no transfer of data to third parties under data protection law.
9. External links and social media
Our website contains links to external websites and social media platforms, in particular Instagram. These are simple hyperlinks, not embedded social media plugins or widgets.
Displaying an ordinary external link on our site does not, by itself, transmit any personal data to the respective provider. Only once you click such a link do you leave our website and establish a direct connection to that provider.
From that point on, the respective provider may process personal data, in particular your IP address, technical device information, and information about the link accessed. If you're logged into that platform, the visit may be linked to your account there.
The respective provider is generally responsible for data processing on its own platform. That provider's privacy policy applies.
10. Recipients of personal data
Within Kern Digital, only those involved in handling a given inquiry or fulfilling their duties have access to personal data.
Beyond that, personal data may be shared with the following categories of recipients:
- Hosting and server providers (IONOS SE)
- Email and communication service providers
- Google Ireland Limited, where you have consented to Google Analytics
- IT and maintenance service providers
- Tax advisors and other professional advisors
- Authorities and public bodies, where a legal obligation exists
- Lawyers or other parties, where necessary to assert, exercise, or defend legal claims
Where service providers process personal data on our behalf, they are contractually bound under Art. 28 GDPR to the extent legally required.
11. Transfers to third countries
Personal data is transferred to countries outside the European Union or European Economic Area only where expressly stated in this privacy policy or where the legal requirements for such a transfer are met. This applies in particular to the use of Google Analytics once consent has been given (see Section 7).
Simply clicking an external link to a social media platform may also result in the respective platform provider processing data in third countries. We have no direct influence over such processing once you've left our website.
12. Retention period
Unless a more specific retention period is stated in this privacy policy, we only store personal data for as long as necessary for the relevant processing purpose.
Longer retention may occur in particular where:
- statutory retention obligations apply,
- the data is needed to fulfil or process a contract,
- claims may be asserted,
- the data is required to exercise or defend legal claims, or
- valid consent to further storage has been given.
Once the purpose of storage no longer applies and any relevant retention or limitation periods have expired, the data is deleted or anonymized.
13. Your rights
Subject to the applicable legal requirements, you have in particular the following rights:
- Right of access to your personal data pursuant to Art. 15 GDPR
- Right to rectification of inaccurate or incomplete data pursuant to Art. 16 GDPR
- Right to erasure of your personal data pursuant to Art. 17 GDPR
- Right to restriction of processing pursuant to Art. 18 GDPR
- Right to data portability pursuant to Art. 20 GDPR
- Right to object to certain processing pursuant to Art. 21 GDPR
- Right to withdraw consent given, pursuant to Art. 7 (3) GDPR
- Right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR
To exercise your rights, please contact us using the details provided above.
14. Right of withdrawal and right to object
You may withdraw any consent given at any time with future effect. Withdrawal does not affect the lawfulness of processing carried out on the basis of that consent up to the point of withdrawal.
Where we process your personal data based on Art. 6 (1)(f) GDPR, you have the right, on grounds relating to your particular situation, to object to such processing at any time.
We will then no longer process the personal data concerned, unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
15. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
For businesses based in Hesse, the following authority is in particular responsible:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hessian Commissioner for Data Protection and Freedom of Information)
Postfach 3163
65021 Wiesbaden
Germany
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
You may also contact a different supervisory authority, in particular one local to your habitual residence, your place of work, or the place of the alleged infringement.
16. Automated decision-making
No decision-making based solely on automated processing, including profiling within the meaning of Art. 22 GDPR, takes place in connection with the use of this website.
17. Currency of this privacy policy
We reserve the right to update this privacy policy if the services we use, our data processing, or applicable legal requirements change.
Last updated: July 2026