Skip to content
Back

Privacy policy

We take the protection of your personal data seriously and treat it confidentially and in accordance with statutory provisions (GDPR, German Federal Data Protection Act). Below we explain the nature, scope and purpose of our processing.

1. Controller

JADAKA UG (haftungsbeschränkt)
Jannis Mulzer, Geschäftsführer (Managing Director)
Senckenbergturm
Senckenberganlage 19, 60325 Frankfurt am Main, Germany
Email: hello@jadaka.eu

2. Your rights as a data subject

Subject to the applicable legal conditions, you have the right to:

  • access the data we process about you (Art. 15 GDPR),
  • have inaccurate data corrected (Art. 16 GDPR),
  • erasure (Art. 17 GDPR) and restriction (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing (Art. 21 GDPR),
  • withdraw consent with effect for the future (Art. 7 (3) GDPR),
  • lodge a complaint with a supervisory authority (Art. 77 GDPR).

Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. You may contact, in particular, the Hessian Commissioner for Data Protection and Freedom of Information.

3. Hosting and technical logs

This website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Requests involve processing IP addresses, requested URLs, timestamps, browser information and technical status data to deliver the site, investigate errors and prevent abuse. Our legal basis is Art. 6(1)(f) GDPR.

Our server functions are configured for Frankfurt. Vercel also uses a global delivery network, so processing is not confined to Europe. Technical logs may contain personal data. Retention depends on the Vercel service and its settings. See the Vercel Privacy Notice.

4. Contact and email delivery

We process your email address and message to respond to your enquiry. The legal basis is Art. 6(1)(b) GDPR for enquiries relating to a contract, or our legitimate interest in responding under Art. 6(1)(f) GDPR for other enquiries. We need a contact address to reply.

The contact form sends your message and a confirmation through Resend, Inc., USA. Resend processes sender and recipient details, message contents and delivery information. According to the provider, standard plans retain emails and delivery logs for 30 days, with backups kept for up to seven additional days. See Resend and GDPR.

We use Google Workspace for our email mailbox. Google processes message contents, addresses and technical metadata to provide and secure the service. See the Google Workspace data processing terms.

To protect the form, we check a hidden field, the time before submission and submissions per IP address. A temporary counter is held in server memory. After one hour it resets on further use; expired entries are removed during cleanup or when the server instance ends. Hosting logs are processed separately. The legal basis is Art. 6(1)(f) GDPR.

5. Appointment booking and video calls

We embed a booking calendar provided by Cal.com, Inc., USA. The calendar loads automatically as you scroll towards the contact section. This transfers technical connection data, including your IP address and browser information, to Cal.com. For this processing and storage access required to provide the booking service, we rely on Art. 6(1)(f) GDPR and § 25(2) TDDDG respectively.

When you book, Cal.com processes the details you enter, including your name, email address, appointment and time zone, to arrange and manage the call, confirmations and changes. The legal basis is Art. 6(1)(b) GDPR. Appointment details are synchronised with our connected Google Calendar. See the Cal.com privacy policy for information about US processing, retention and necessary cookies.

We use Google Meet, part of Google Workspace, for video calls. This involves processing your name, connection data and any audio, video or screen content you share. The purpose and legal basis are those of handling your enquiry. Our website does not automatically record meetings.

6. Website analytics

The hosted website uses Vercel Web Analytics to measure page views and events such as booking-link clicks and successful form submissions. We do not send message contents or email addresses as analytics events. Data includes the page path, referrer, timestamp, device and browser information. URL parameters are removed before transmission.

The service uses no analytics cookies. It distinguishes visits using a hash derived from the request, discarded after 24 hours according to Vercel. This does not mean that all statistical data is deleted after 24 hours. Our legal basis is our legitimate interest in limited website measurement under Art. 6(1)(f) GDPR. See Vercel Web Analytics privacy information.

7. LinkedIn Insight Tag

With your consent, we use the LinkedIn Insight Tag provided by LinkedIn Ireland Unlimited Company, Ireland. It lets us measure LinkedIn advertising and conversions and show ads to previous website visitors (retargeting). LinkedIn also processes this data for its own purposes as a controller, as described in its Independent Controller Addendum.

LinkedIn receives information including the visited URL, referrer, IP address, device and browser details, timestamp and interactions such as button clicks. Cookies and similar identifiers may link a visit to a LinkedIn account. We receive statistical reports. Our integration does not send email addresses for enhanced matching.

The legal bases are your consent under Art. 6(1)(a) GDPR and, for cookies and other access to your device, § 25(1) TDDDG. The tag stays disabled without consent. You can withdraw consent at any time through “Cookie settings” at the bottom of the page, without affecting the lawfulness of earlier processing. Withdrawing consent reloads the page to stop tracking functions that have already loaded.

LinkedIn also processes data in the US. It identifies the EU-US Data Privacy Framework and standard contractual clauses as transfer safeguards; see its international data transfer information. According to LinkedIn, directly identifying information is removed within seven days, and the remaining pseudonymised data is deleted within 180 days.

Cookie lifetimes vary: for example, 30 days for li_fat_id and lms_ads, 90 days for li_sugr and one year for bcookie. The LinkedIn Cookie Table lists further cookies and details. On withdrawal, we remove LinkedIn identifiers accessible on our domain. Cookies on LinkedIn domains can be deleted through your browser settings. For more information and your rights, see the LinkedIn Privacy Policy and Insight Tag information.

8. Browser storage, fonts and films

We store your cookie choice, timestamp and notice version in your browser’s local storage under “jadaka.marketing-consent” for up to 180 days so that we can apply your decision. The legal bases are § 25(2) no. 2 TDDDG and Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR. We then ask again. The record contains no visitor identifier. LinkedIn tracking is enabled only with consent, as described in section 7. The language switch uses neither cookies nor persistent browser storage. The embedded calendar additionally uses the storage described in section 5.

Our fonts, images and software films are delivered through our hosting. Our own fonts do not connect to Google Fonts. The software demonstrations use fictional data and do not send visitor input to an AI service. External content in the booking calendar is separate.

9. Recipients and international transfers

The technical providers named above process data to deliver their services. Processing on our behalf is subject to Art. 28 GDPR. Data may also be processed outside the EU or EEA. Transfers to the US may rely on the EU-US Data Privacy Framework where the recipient is certified and the processing is covered, or otherwise on EU standard contractual clauses. The linked provider terms describe the applicable safeguards. You can also request copies from us.

10. Retention and security

We delete enquiries and appointment records when no longer needed to handle the matter or follow-up questions. If a business relationship follows, applicable statutory retention duties also apply. Records needed to establish or defend claims may be retained for the relevant limitation periods. Provider-specific retention is described above.

The website and contact form use HTTPS encryption. We do not make solely automated decisions with legal or similarly significant effects under Art. 22 GDPR.

Last updated: September 2026. We update this notice when processing changes.