Privacy-Policy

Legal Notice (Impressum)

Information pursuant to Section 5 DDG (Digital Services Act) Kita Digital – Sebastian Götz Jägerstr. 13 67105 Schifferstadt Germany

Represented by: Sebastian Götz

Contact: Phone: 06235 – 455914-0 Email: beratung@ki-insel.de

Responsible for the content pursuant to Section 18 (2) MStV (Interstate Broadcasting Treaty): Sebastian Götz Jägerstr. 13 67105 Schifferstadt Germany

Consumer Dispute Resolution / Universal Arbitration Board We do not participate in dispute resolution proceedings before a consumer arbitration board and are not obligated to do so.

Disclaimer

Liability for Content The contents of our pages were created with the utmost care. However, we cannot guarantee the accuracy, completeness, or timeliness of the content. As a service provider, we are responsible for our own content on these pages under general laws in accordance with Section 7 (1) DDG. However, according to Sections 8 to 10 DDG, we are not obligated as a service provider to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity. Obligations to remove or block the use of information under general laws remain unaffected. However, liability in this regard is only possible from the point in time at which we become aware of a specific legal violation. Upon becoming aware of such legal violations, we will remove this content immediately.

Liability for Links Our website contains links to external third-party websites over whose content we have no influence. Therefore, we cannot assume any liability for these external contents. The respective provider or operator of the pages is always responsible for the content of the linked pages. The linked pages were checked for possible legal violations at the time of linking. Illegal content was not recognizable at the time of linking. However, permanent content monitoring of the linked pages is unreasonable without concrete evidence of a legal violation. Upon becoming aware of legal violations, we will remove such links immediately.

Copyright The content and works created by the site operators on these pages are subject to German copyright law. The duplication, processing, distribution, and any kind of exploitation outside the limits of copyright law require the written consent of the respective author or creator. Downloads and copies of this site are only permitted for private, non-commercial use. Insofar as the content on this site was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is marked as such. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. Upon becoming aware of legal violations, we will remove such content immediately.

Privacy Policy

Last updated: August 17, 2026

1. Data Controller

The data controller responsible for the processing of personal data on this website is: Sebastian Götz Jägerstr. 13 67105 Schifferstadt Germany Email: beratung@ki-insel.de Phone: 06235 – 455914-0

The former website sebastian-goetz.com redirects entirely to this website.

2. General Information on Data Processing

We take the protection of your personal data seriously. Personal data is only processed on this website to the extent necessary to provide the website, communicate with you, secure our technical systems, or provide features expressly requested by you. In particular, we use no reach measurement services, no Google Analytics, no Google Tag Manager, no advertising or marketing trackers, no Meta pixels, no interest-based advertising, and no comparable tracking technologies on this website. Personal data is not passed on for advertising or analysis purposes.

3. Website Provision and Hosting

This website is hosted by Kinsta Inc., 8605 Santa Monica Blvd #92581, West Hollywood, CA 90069, USA. The hosting infrastructure we use for the website is located in a data center in Frankfurt am Main, Germany. When you access the website, technically necessary connection data is processed. This may include, in particular:

  • IP address
  • Date and time of access
  • Requested page or resource
  • Information about the browser used
  • Operating system and technical device information
  • Amount of data transferred
  • Technical status information

The processing is necessary to technically provide the website, ensure its stability and security, and detect and defend against misuse or attacks on our systems. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable, and functional provision of our online presence. Kinsta processes data as a data processor as part of the hosting services. Kinsta provides a Data Processing Agreement for the processing of personal data within the scope of customer applications. Kinsta states that it utilizes the EU-U.S. Data Privacy Framework and provides appropriate safeguards for international data transfers. Further information: Kinsta Privacy Policy

4. Technically Necessary Cookies

Based on our current technical setup, only the technically necessary cookies described below are used on our website.

4.1 Cloudflare __cf_bm We use the bot protection provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. For this purpose, the __cf_bm cookie is used. It serves exclusively to detect and ward off automated or abusive data traffic and to secure the website against bots. The cookie is required by Cloudflare for the technical provision of bot protection. Cloudflare describes the cookie as part of its bot management products. It contains information related to the calculation of a bot score and is encrypted. The cookie is not used for personalized advertising or cross-site user tracking. The legal basis for the associated processing of personal data is Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our website from automated attacks, misuse, and malicious traffic. In our assessment, no consent pursuant to Section 25 (1) TDDDG is required for storing or reading the cookie, as its use is technically necessary for the security function we provide. Section 25 (2) No. 2 TDDDG provides an exception to the consent requirement for strictly necessary storage and access operations. Cloudflare processes technical connection data as part of its security services. For international data transfers, Cloudflare provides Standard Contractual Clauses as well as the EU-U.S. Data Privacy Framework as transfer mechanisms. Further information: Cloudflare Privacy and GDPR

4.2 wpEmojiSettingsSupports WordPress uses the wpEmojiSettingsSupports cookie in connection with emoji support. The cookie serves the technical provision of this WordPress functionality and is not used for analysis, advertising, or tracking purposes. Insofar as this cookie is technically necessary for the display and functionality requested by you, it is used on the basis of Section 25 (2) No. 2 TDDDG.

5. Google Fonts

Fonts from Google Fonts are provided on our website exclusively locally on our own web server. Therefore, when you access our website, no connection is made to Google’s servers to retrieve the used fonts. In particular, the font files are not loaded from fonts.googleapis.com or fonts.gstatic.com. As a result, your IP address is not transmitted to Google to retrieve the fonts via this function. The local provision of the fonts is done to ensure a uniform and user-friendly presentation of our website. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in a technically reliable and uniform presentation of our online offering.

6. Contacting Us via Email and Telephone

If you contact us via email, phone, or other means, we process the personal data you provide. This may include, in particular:

  • Name
  • Email address
  • Phone number
  • Content of your inquiry
  • Other information you voluntarily provide to us

The processing takes place exclusively to handle your inquiry, to communicate with you, and, if applicable, to prepare or fulfill a contractual relationship. Depending on the content of the request, the legal basis is Article 6(1)(b) GDPR, provided the processing is necessary for the performance of pre-contractual measures or a contract, and Article 6(1)(f) GDPR, provided the processing is based on our legitimate interest in appropriate communication.

Email via Proton Mail For business email communication, we use Proton Mail by Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland. When communicating by email, the messages you send and the personal data contained therein are processed to handle your request and communicate with you. Proton is a provider based in Switzerland and provides a Data Processing Agreement for business customers. The Proton DPA contains provisions for international data transfers and includes appropriate data protection transfer mechanisms. Further information: Proton Privacy Policy

7. Contact Form

There is a contact form on our website. The contact form is provided using the designated features of WordPress or the Kadence system used. No independent external form provider is used for this. If you use the contact form, we process the data you enter, in particular:

  • Name
  • Email address
  • Phone number (if applicable)
  • Message and other content entered by you

The processing is carried out to handle your contact request and to communicate with you. The legal basis is Article 6(1)(b) GDPR, insofar as your request is aimed at initiating a contractual relationship, and otherwise Article 6(1)(f) GDPR. The data transmitted via the contact form is processed to handle the respective inquiry and communicate with the inquiring person. The email address provided during contact will only be used for advertising or newsletter purposes based on a separate, explicit consent of the data subject. Consent is granted in particular by actively checking a corresponding checkbox and can be revoked at any time with effect for the future.

Newsletter If you register for our newsletter, we will process the personal data you provide for this purpose, in particular your email address, to send the newsletter. Registration only takes place after explicit consent. For this, the corresponding checkbox must be actively selected. Existing contact or the use of the contact form does not automatically lead to a newsletter registration. We send the newsletter manually via Proton Mail. We do not use a separate newsletter dispatch service or any automated tracking or analysis functions for this purpose. The legal basis for sending the newsletter is Article 6(1)(a) GDPR. The consent given can be revoked at any time with effect for the future. A message to beratung@ki-insel.de, for example, is sufficient for this purpose. The lawfulness of the processing carried out up to the time of revocation remains unaffected by the revocation. The email address stored for the newsletter will no longer be used for newsletter dispatch after the revocation of consent or after unsubscribing from the newsletter. Statutory retention obligations remain unaffected.

8. EleMo – AI-Powered Chatbot

On our website, we provide the AI-powered chatbot “EleMo” (Elementary Pedagogical Model) as a test version. EleMo serves to test an AI system for elementary pedagogical questions and to generate answers to the texts you enter.

8.1 Processing on Own Hardware The language model used by EleMo is operated on our own hardware at our location in Schifferstadt. The actual inference processing takes place on this proprietary hardware. We do not use an external AI provider such as OpenAI, Anthropic, Google, Microsoft, or comparable cloud AI services to process chat texts for EleMo. The entered texts are not transmitted to external AI providers for training purposes.

8.2 Transmission via ngrok For the technical accessibility of the locally operated EleMo system, we use an encrypted tunnel from the service ngrok by ngrok, Inc. Here, the connection between the browser and our locally operated EleMo system is routed via ngrok’s infrastructure. Within the scope of the tunnel connection, ngrok processes technical connection and metadata. According to ngrok, connection events, IP addresses, and information about the agent used are logged in particular. According to ngrok, permanent storage of the transmitted request and response content generally does not take place unless the “Traffic Inspector Full Capture” function is activated. This function is not used for EleMo. For international data transfers, ngrok provides, among other things, a Data Processing Agreement and Standard Contractual Clauses and states that it is certified under the EU-U.S. Data Privacy Framework. Further information: ngrok Privacy and Security

8.3 No Permanent Storage of Chat Texts The texts you enter in the EleMo chat are not permanently stored by us in a database. In particular, no user profiles and no permanent chat histories are created. The inputs are processed to generate the respective response and are subsequently discarded by the application. Technically necessary connection data and server requests may be processed independently of this within the framework of the infrastructure or hosting.

8.4 Local Storage EleMo uses only the local cache (Local Storage) in the browser, insofar as this is necessary for the technical function of the current session. Local Storage is not used to create user profiles or for advertising or tracking purposes.

8.5 No Input of Real Personal Data EleMo is in a testing phase. Please do not enter real personal data of children, parents, legal guardians, employees, or other persons into EleMo. Use only anonymized, fictional, or pseudonymized information for test cases. This applies in particular to names, addresses, contact details, health data, developmental data, or other information that could identify a person.

8.6 Legal Basis The processing of the content you voluntarily enter is carried out to provide the chat function you expressly requested. The legal basis is Article 6(1)(b) GDPR, provided the use of the test offer is classified as pre-contractual or contract-related use, or Article 6(1)(f) GDPR, provided the processing is based on our legitimate interest in providing and testing the EleMo test system. Separate consent is currently not obtained via a consent banner or checkbox.

9. Server and Security Logs

When operating our website and the associated technical systems, technical connection data and server requests inevitably arise. These may include, in particular, IP addresses, timestamps, requested resources, technical status information, and information about the system used. The processing takes place exclusively for the technical provision, error analysis, and security of the systems. We do not evaluate this data for audience measurement, profiling, or personalized advertising. Insofar as technical server logs arise in our own infrastructure, they are deleted according to the respective technically provided deletion periods. Based on our current technical status, the log data we control is deleted automatically after 24 hours at the latest. We do not have full influence on the logging and storage processes of external service providers such as Kinsta, Cloudflare, or ngrok. The respective technical and contractual storage periods of the providers apply to them. We only have influence on the logging and storage processes of external technical service providers, in particular ngrok or Cloudflare, within the scope of the respective service configuration and contractual possibilities. The respective providers process technical connection data in accordance with their own data protection and contractual conditions.

10. No Analytics and Marketing Services

We currently do not use any of the following on this website:

  • Google Analytics
  • Google Tag Manager
  • Meta Pixel
  • LinkedIn Insight Tag
  • Matomo
  • Hotjar
  • Microsoft Clarity
  • Comparable analytics or tracking services
  • Advertising or retargeting pixels
  • Interest-based advertising services

No user profiles are created for advertising or marketing purposes.

11. Social Media

Our website may contain references or links to our profiles on social networks. However, no social media feeds, social media pixels, or other social media content are integrated directly into our website. Therefore, the mere accessing of our website does not establish a connection to the respective social networks solely based on such an external link. Data processing by the respective social network only occurs when you access the corresponding external service.

12. No Other External Content

No external YouTube, Vimeo, Google Maps, Instagram, or comparable content is automatically embedded on our website. Likewise, no external Google Fonts files are loaded.

13. Legal Bases

Unless otherwise stated in this Privacy Policy, the processing of personal data is carried out in particular on the following legal bases:

  • Article 6(1)(a) GDPR – Consent, insofar as this is required and obtained in individual cases.
  • Article 6(1)(b) GDPR – Processing for the performance of a contract or for the implementation of pre-contractual measures.
  • Article 6(1)(f) GDPR – Processing to protect our legitimate interests, in particular in the secure, stable, and functional provision of our website, in the defense against misuse and attacks, and in appropriate communication.
  • For the use of technically necessary storage and access operations on the end device, Section 25 (2) TDDDGmust also be taken into account.

14. Recipients of Personal Data

Personal data may be processed by the following service providers, in particular, as part of the processing described:

  • Kinsta Inc. – Hosting and technical infrastructure
  • Cloudflare, Inc. – Technical bot and security protection
  • ngrok, Inc. – Encrypted tunnel connection for EleMo
  • Proton AG – Business email communication

As a matter of principle, data is only passed on to other third parties if this is necessary to fulfill the respective purposes, if there is a legal obligation, or if another data protection legal basis permits it.

15. International Data Transfers

With some of the technical service providers we use, processing of personal data outside the European Union or the European Economic Area cannot be ruled out. This applies in particular to Kinsta, Cloudflare, and ngrok. For such transfers, the appropriate safeguards or adequacy decisions provided by law are used, where necessary. These may include, in particular, the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses of the European Commission. Kinsta, Cloudflare, and ngrok each specify corresponding data protection and transfer mechanisms. Proton is based in Switzerland. Switzerland has an adequacy decision from the European Commission, so that a transfer of personal data to Switzerland can generally take place on this basis. Proton also provides a Data Processing Agreement.

16. Storage Duration

We only store personal data for as long as is necessary for the respective purpose or as long as legal retention obligations exist. Inquiries by email, telephone, or contact form are deleted as soon as the respective process is completed and there are no legal retention obligations or legitimate reasons for further storage. Statutory retention obligations, in particular from tax and commercial law, remain unaffected. For the technical processing by Kinsta, Cloudflare, and ngrok, the respective technical and contractual storage periods of the providers apply additionally. For EleMo, chat texts are not permanently stored by us.

17. Your Rights

Under the statutory conditions, you have the following rights in particular:

  • Right of access pursuant to Article 15 GDPR
  • Right to rectification pursuant to Article 16 GDPR
  • Right to erasure pursuant to Article 17 GDPR
  • Right to restriction of processing pursuant to Article 18 GDPR
  • Right to data portability pursuant to Article 20 GDPR
  • Right to object pursuant to Article 21 GDPR
  • Right to withdraw given consent with effect for the future, provided processing is based on consent.

Insofar as we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to this processing at any time for reasons arising from your particular situation. In the case of processing for direct marketing purposes, there is a general right to object at any time.

18. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The authority responsible for the data controller based in Rhineland-Palatinate is in particular: The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz) Further information and the contact details of the authority can be found on their website.

19. Data Security

We use appropriate technical and organizational security measures to protect personal data against loss, destruction, manipulation, or unauthorized access. The transmission between your browser and our online offerings generally takes place via an encrypted HTTPS connection. For EleMo, an encrypted tunnel is used for the connection to the locally operated infrastructure.

20. Updates to this Privacy Policy

We reserve the right to adapt this Privacy Policy if the technical processes, services, or legal requirements we use change. The version published at the time of the website visit applies. Last updated: August 17, 2026