Privacy Policy
Last updated: June 22, 2026
Last updated: 2 August 2026
1. General Information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on the subject of data protection can be found in the text below.
Storage Duration
Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, provided that we have no other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, the deletion will take place after these reasons cease to apply.
2. Controller (Responsible Party)
The party responsible for data processing on this website (the "controller") is:
Oliver Riechert
Wiesenstraße 71
29525 Uelzen
Germany
Contact — Email: hello@boilerplatedeals.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).
3. Data Collection on Our Website
Cookies
Our website uses "cookies". Cookies are small text files and do not cause any damage to your terminal device. They are either stored temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device.
Technically Necessary Cookies
We use strictly necessary cookies that are required for the operation of our website. The storage of these cookies on your device is based on § 25 (2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act), as they are strictly necessary to provide the service you have requested; no consent is required. Any subsequent processing of personal data is based on Art. 6 (1) (f) GDPR — we have a legitimate interest in the technically error-free and optimized provision of our services.
- Security & Bot Protection (cf_clearance): Provided by Cloudflare. It ensures that a user has successfully completed a security challenge. Storage duration: 30 minutes.
- Bot Protection (Cloudflare Turnstile): We use Cloudflare Turnstile on our contact and sign-up forms to distinguish human visitors from bots, without the need for a traditional CAPTCHA. Turnstile analyzes technical signals (e.g., browser characteristics, IP address) and may set cookies to perform this check. This data is processed by Cloudflare Inc. (see "Web Hosting, Security & CDN: Cloudflare" below). Legal Basis: § 25 (2) No. 2 TDDDG for storage of / access to information on your device, in conjunction with Art. 6 (1) (f) GDPR (legitimate interest in protecting our website against spam and automated abuse).
Web Analytics: Umami
To understand how our website is used, we operate the open-source analytics tool Umami. Our Umami instance is self-hosted on infrastructure provided by Bunny.net, located in Frankfurt, Germany (see "Analytics Hosting: Bunny.net" below); no data is shared with any other third party.
Umami operates without cookies and without a persistent, cross-session identifier for individual visitors. Data collected includes: pages visited, referrer URL, browser type, operating system, device type, screen resolution, and country/city (derived from the IP address). The IP address itself is not stored — it is used only momentarily to generate an anonymized daily hash and is then discarded.
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in anonymized, privacy-friendly analysis of website usage). No consent is required, as no cookies or comparable identifiers are stored on or read from your device.
Advertising Banners
Advertisers can book banner advertisements on this website. All banners are hosted on our own infrastructure and delivered directly by us. We do not use any third-party advertising networks, and no personal data is shared with advertisers. No advertising cookies or comparable tracking identifiers are stored on or read from your device. Banner impressions and clicks are measured exclusively in anonymized, cookieless form using our self-hosted Umami analytics (see "Web Analytics: Umami" above).
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in financing our services through advertising).
- Note: If you click on a banner, you will be taken to the advertiser's website. The advertiser's own privacy policy applies there.
Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us:
- Browser type and version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
The basis for data processing is Art. 6 (1) (f) GDPR, which permits the processing of data for the technically error-free presentation and optimization of the website.
- Retention: Raw server logs are generally deleted within 24 hours. Where IP addresses are needed for security analysis or to defend against specific attacks, they may be retained in security logs for up to 30 days or until the incident in question has been resolved.
Contacting Us (Form or Email)
If you send us inquiries via the contact form or email, your data (e.g., name, email address, message content) will be stored for the purpose of processing the inquiry.
- Legal Basis: Processing is based on Art. 6 (1) (b) GDPR (contractual/pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in effective communication).
- Provision of Data: Providing your data is neither required by law nor by contract. Without your contact details and your message, however, we are unable to respond to your inquiry.
- Retention: Data remains with us until you request deletion, revoke consent, or the purpose for storage lapses (e.g., the request has been completed), subject to mandatory statutory retention periods.
Newsletter
This website provides a sign-up form for our newsletter, which is operated jointly across several of our websites under boilerplatenewsletter.com. If you subscribe, your email address (and, if provided, your name) is transmitted to and stored on boilerplatenewsletter.com, where it is used to send you the newsletter. As this and boilerplatenewsletter.com are operated by the same controller (Oliver Riechert), this does not constitute a disclosure to a third party. Subscription requires your explicit consent and is completed using the double opt-in procedure: after signing up, you will receive a confirmation email containing a link that you must click to activate your subscription. This ensures that no one can subscribe using someone else's email address. We log the sign-up and confirmation (including timestamp and IP address) so that we can demonstrate your consent in accordance with Art. 7 (1) GDPR.
- Legal Basis: Art. 6 (1) (a) GDPR (consent).
- Delivery Logs: Our email service provider records whether a message could be delivered (e.g. bounces), so that undeliverable addresses can be removed from the distribution list. We do not use tracking pixels, we do not measure whether a newsletter is opened, and we do not track which links are clicked. Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in maintaining a functioning distribution list).
- Provision of Data: Providing your email address is neither required by law nor by contract. It is, however, necessary in order to receive the newsletter — without it, we cannot send it to you.
- Retention: Your email address is stored until you unsubscribe and is then removed from the distribution list. The record of your sign-up and confirmation is retained beyond that point for up to three years, solely to demonstrate your consent (Art. 7 (1) GDPR) and to defend against legal claims.
- Revocation: You can withdraw your consent at any time by clicking the unsubscribe link contained in every newsletter email or by contacting us directly.
4. Hosting and Infrastructure
Web Hosting, Security & CDN: Cloudflare
We use services provided by Cloudflare Inc. (101 Townsend St., San Francisco, CA 94107, USA). Our websites are hosted and delivered via Cloudflare Pages. In addition, Cloudflare provides a Content Delivery Network (CDN) and protects our websites against attacks (e.g., DDoS).
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in security and performance).
- Data Transfer: Cloudflare Inc. is certified under the EU-U.S. Data Privacy Framework. We have concluded a Data Processing Amendment (DPA) including Standard Contractual Clauses with Cloudflare.
Analytics Hosting: Bunny.net
We use services provided by Bunny.net (BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia) to host our self-hosted Umami analytics instance (see Section 3, "Web Analytics: Umami"). It runs on a server located in Frankfurt, Germany; analytics data does not leave the EU.
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in operating our own analytics on reliable infrastructure).
- Data Transfer: All processing takes place within the EU. A DPA has been concluded with the provider.
Newsletter Infrastructure: netcup
The software used to manage our newsletter subscriptions runs on a server provided by netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. Subscriber data — your email address, any name provided, and the sign-up and confirmation log — is stored there. The actual delivery of the emails is handled by EmailIT (see below).
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in operating our own newsletter infrastructure); the subscription itself is based on your consent under Art. 6 (1) (a) GDPR.
- Data Transfer: All processing takes place on servers within Germany. A DPA has been concluded with the provider.
Email Marketing and Transactional Emails: EmailIT
For sending our newsletter and transactional emails, we use EmailIT, provided by FunFirst s.r.o. (Na louži 258/13, Vršovice 101 00 Praha 10, Czech Republic).
- Processing: Data is processed on servers within the European Union.
- Legal Basis: Art. 6 (1) (a) GDPR (consent) for newsletters or Art. 6 (1) (f) GDPR (legitimate interest) for system-critical emails like confirmation messages.
- Compliance: We have concluded a DPA with FunFirst s.r.o. to ensure processing in accordance with GDPR standards.
Business Email and Backups: Google Workspace
We use Google Workspace for our email communication. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
We also store encrypted backups of our websites and databases in Google Drive within the same Google Workspace account. These backups may contain personal data from the systems described above.
- Data Processing and Storage Location: We have configured our Google Workspace settings to ensure that the storage of our data ("Data at Rest") occurs on servers within the European Union. However, please note that in the context of maintenance or technical support, access by Google LLC (USA) cannot be completely ruled out.
- Legal Basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and professional business communication).
- Data Security: We have concluded a Data Processing Amendment (DPA) with Google. For potential data transfers to the USA, Google relies on the EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses.
5. Your Rights
As a data subject, you have the following rights:
- Right to Access (Art. 15 GDPR): Information about your stored data.
- Right to Rectification (Art. 16 GDPR): Correction of inaccurate data.
- Right to Erasure (Art. 17 GDPR): Deletion of your data.
- Right to Restriction (Art. 18 GDPR): Limiting how we process your data.
- Right to Data Portability (Art. 20 GDPR): Receiving your data in a machine-readable format.
- Right to Object (Art. 21 GDPR): You can object to processing based on legitimate interests (Art. 6 (1) (f) GDPR) at any time.
- Right to Withdraw Consent: You can revoke any consent given (Art. 6 (1) (a) GDPR) at any time with future effect.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony), Prinzenstraße 5, 30159 Hannover, Germany, https://lfd.niedersachsen.de. You may also contact the supervisory authority of your habitual residence or place of work.
Right to Object (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6 (1) (E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 (1) GDPR).
IF YOUR PERSONAL DATA ARE PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO SUCH PROCESSING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 (2) GDPR).
To exercise your right to object, an informal message (e.g., by email) is sufficient.
Automated Decision-Making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 (1) and (4) GDPR.
6. Data Security
We use SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by "https://" and the lock symbol in your browser address bar.