PRIVACY POLICY
for macejmahu.de
1. Controller
Maciej Kopania
c/o IP-Management #7854
Ludwig-Erhard-Straße 18
20459 Hamburg, Germany
Email: contact@macejmahu.de
2. General Information
I take the protection of your personal data seriously.
This privacy policy explains:
what data I collect,
how it is processed,
for which purposes,
and what rights you have under the GDPR.
Personal data is processed based on:
Art. 6(1)(a) GDPR — Consent
Art. 6(1)(b) GDPR — Contract / Booking requests
Art. 6(1)(f) GDPR — Legitimate interests
Art. 6(1)(c) GDPR — Legal obligations
3. Hosting & Website Operation (Squarespace)
My website is hosted by Squarespace,
Squarespace Ireland Ltd., Le Pole House, Ship Street Great, Dublin 8, Ireland.
Squarespace may process:
IP address
Browser type & version
Device information
Referrer URLs
Access timestamps
Technical logs
Legal basis: Art. 6(1)(f) GDPR
(legitimate interest in secure, stable website operation)
A Data Processing Agreement (DPA) is in place.
4. Multilingual System (Weglot)
To provide my website in multiple languages, I use Weglot,
Weglot SAS, 7 rue de Madrid, 75008 Paris, France.
Weglot processes:
Browser & device data
Language preferences
Anonymous IP data
Interactions with the language switcher
Legal basis: Art. 6(1)(f) GDPR.
5. Google Fonts (Local Integration)
Google Fonts are hosted locally on the server.
➡️ No data is transmitted to Google.
➡️ No tracking by Google takes place.
6. Contact & Booking Form
If you contact me through the website, I process:
Name
Email address
Message content
Event or booking details (optional)
Legal basis: Art. 6(1)(b) GDPR — Pre-contractual communication.
Your data will not be shared with third parties unless required for contract execution.
7. Newsletter Services
If you subscribe to my newsletter, I may use tools such as:
Mailchimp (The Rocket Science Group LLC, USA)
Brevo / Sendinblue (France)
ConvertKit (USA)
Processed data:
Email address
Name (optional)
IP address (for security)
Interaction data (opens, clicks)
A Double-Opt-In system is used.
Legal basis: Art. 6(1)(a) GDPR — Consent.
Transfers to third countries (USA) are secured with Standard Contractual Clauses (SCCs).
8. Ticket Sales & Online Purchases
If tickets or services are sold through the website, I may use:
Squarespace Commerce
Data processed:
Name
Email
Address
Order details
Payment information
Legal basis: Art. 6(1)(b) GDPR
Eventbrite
Eventbrite, Inc. (USA)
Data processed:
Ticket buyer information
Payment data
IP address
Shopify
Shopify International Ltd.
Data processed:
Order details
IP address
Payment info
9. Payment Providers
If you make payments using online methods:
Stripe
Stripe Payments Europe Ltd.
Processes:
Cardholder data
Billing address
IP address
Transaction details
PayPal
PayPal (Europe) S.à r.l.
Processes:
Account data
Payment information
Transaction metadata
Legal basis: Art. 6(1)(b) GDPR.
10. Cookies & Consent Management
My website uses a consent tool (Squarespace built-in, CookieYes, Cookiebot, or Borlabs).
The tool stores:
Your consent status
Date/time of consent
Browser/cookie information
Legal basis:
Necessary cookies: Art. 6(1)(f) GDPR
Analytics/Marketing: Art. 6(1)(a) GDPR
11. Analytics & Tracking Tools
11.1 Squarespace Analytics
Squarespace collects anonymized data about:
Page views
Session duration
Device types
Browser types
Basic geographic regions
Scroll & click interactions
Legal basis: Art. 6(1)(f) GDPR.
11.2 Google Analytics 4 (optional future use)
Google Ireland Ltd.
Processed data:
IP address (anonymized)
Device IDs
User interactions
Event-based tracking
Behavior flows
Legal basis: Art. 6(1)(a) GDPR (consent).
IP anonymization is enabled.
11.3 Meta Pixel (Facebook Pixel)
Meta Platforms Ireland Ltd.
Collected data:
Page views
Pixel ID
Browser data
Interaction data
Conversion events
Used for:
Targeted advertising
Retargeting
Conversion tracking
Legal basis: Art. 6(1)(a) GDPR.
11.4 Google Tag Manager
Manages tracking scripts.
Does not process personal data itself.
Legal basis: Art. 6(1)(f) GDPR.
12. Embedded Media
YouTube Videos
Provided by Google Ireland Ltd.
When playing a video:
IP address
Device data
Interaction data
Viewing behavior
“Privacy-Enhanced Mode” is used whenever possible.
Instagram Embeds
Meta may collect:
IP address
Device data
Interaction data
Spotify Embeds
Spotify AB processes:
IP address
Browser information
Legal basis: Art. 6(1)(f) GDPR.
13. Social Media Links
Simple links to social platforms do not transmit data until clicked.
Platforms include:
Instagram
TikTok
YouTube
14. Data Processing Agreements (DPAs)
I maintain valid DPAs with:
Squarespace
Weglot
Payment providers
Newsletter services
Business address provider (IP-Management)
according to Art. 28 GDPR.
15. Storage Periods
Contact inquiries: 6 months
Booking & contract data: 10 years (legal requirement)
Newsletter data: until unsubscribed
Analytics cookies: depends on the tool (30–26 months)
16. Your Rights under the GDPR
You have the right to:
Access your data (Art. 15)
Rectification (Art. 16)
Erasure (Art. 17)
Restriction of processing (Art. 18)
Data portability (Art. 20)
Object to processing (Art. 21)
Withdraw consent at any time (Art. 7)
To exercise these rights:
Email: contact@macejmahu.de
17. Right to Lodge a Complaint
You may contact the supervisory authority:
Hamburg Commissioner for Data Protection
Ludwig-Erhard-Str. 22
20459 Hamburg
Germany
18. Changes to This Policy
This privacy policy will be updated whenever:
technical changes occur
new tools are installed
legal requirements change