PRIVACY POLICY

Privacy Policy

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Roland Haun
Executive Railway Consultancy
Hochgernstr. 5
83209 Prien am Chiemsee
Germany

Phone: +49 160 95668577
Email: roland.haun@executive-railway-consultancy.com

2. Hosting and Server Log Files

This website is hosted by:

IONOS SE
Elgendorfer Str. 57
56410 Montabaur
Germany

When this website is accessed, technical information is processed by the hosting provider in order to deliver the website and ensure its secure and reliable operation.

According to IONOS, the following information may be collected:

  • referrer (previously visited website),
  • requested webpage or file,
  • browser type and browser version,
  • operating system,
  • device type,
  • time of access, and
  • IP address in anonymised form.

According to IONOS, this visitor data is anonymised directly upon collection and generally retained for eight weeks. IONOS states that this data is not disclosed to third parties and is not transferred to countries outside the European Union.

The processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in providing a secure, stable and technically reliable website.

3. IONOS WebAnalytics

This website uses IONOS WebAnalytics, a web analytics service provided by IONOS SE.

WebAnalytics is used for the statistical evaluation and technical optimisation of this website.

According to IONOS, data is collected either by means of a pixel or from log files. IONOS WebAnalytics does not use cookies.

The following information may be processed:

  • referrer (previously visited website),
  • requested webpage or file,
  • browser type and browser version,
  • operating system,
  • device type,
  • time of access, and
  • IP address in anonymised form.

When a webpage is accessed, the visitor’s IP address is technically transmitted. According to IONOS, it is anonymised immediately after transmission and subsequently processed without reference to an identifiable individual. The anonymised IP address is used only to determine the approximate location of the access.

According to IONOS, WebAnalytics does not store personal data that would allow individual website visitors to be identified. The collected information is used exclusively for statistical analysis and technical optimisation of the website and is not disclosed to third parties.

The processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in analysing the technical use of the website and optimising its operation and performance.

4. Contact Form

If you contact me using the contact form, the information you provide will be processed for the purpose of handling and responding to your enquiry.

The contact form may process:

  • name,
  • company, if provided,
  • email address, and
  • the content of your message.

The contact form is provided using Fluent Forms within this WordPress website. Submitted enquiries may be stored in the website database and are also forwarded to me by email.

Where your enquiry relates to a potential or existing contractual relationship, processing is based on Art. 6(1)(b) GDPR. For other enquiries, processing is based on Art. 6(1)(f) GDPR, based on the legitimate interest in responding to business and other enquiries.

The data will be deleted when it is no longer required for the purpose for which it was collected, unless statutory retention obligations or other legitimate grounds require longer storage.

4.1 Spam Protection with Cloudflare Turnstile

We use Cloudflare Turnstile within our contact form to protect our website and form submissions against automated access, spam and abuse. The service is provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA.

When the contact form is accessed, Turnstile processes technical information required to determine whether a submission originates from a human user or an automated program. This may include the IP address, browser and device characteristics, operating system, language settings, date and time, referrer information and data relating to the security challenge.

According to Cloudflare, Turnstile does not access, store or transmit the content entered into the contact form. We use Turnstile exclusively for security purposes and not for advertising or visitor tracking.

The processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the protection of our website, communication systems and contact form against spam, automated submissions and misuse.

Further information can be found in the Cloudflare Privacy Policy:

https://www.cloudflare.com/privacypolicy/

5. Contact by Email or Telephone

If you contact me directly by email or telephone, the information you provide will be processed for the purpose of handling your enquiry and communicating with you.

Email communication is handled using infrastructure provided by IONOS.

Processing is based on Art. 6(1)(b) GDPR for enquiries relating to contractual or pre-contractual matters and Art. 6(1)(f) GDPR for other legitimate business communications.

Personal data will be deleted when it is no longer required for the respective communication, unless statutory retention obligations or other legitimate grounds require longer storage.

5.1 Appointment Scheduling with Calendly

For online meetings arranged through Calendly, we use Zoom, a video-conferencing service provided by Zoom Communications, Inc., 55 Almaden Blvd, Suite 600, San Jose, CA 95113, USA.

When an appointment is booked, Calendly automatically creates a Zoom meeting. For this purpose, appointment and participant data, such as your name, email address, meeting date and time, and meeting title, may be transmitted to Zoom. When you join the meeting, Zoom may additionally process technical data, including your IP address, device and connection information, as well as any audio, video or chat content that you actively provide.

The legal basis is Art. 6(1)(b) GDPR where the meeting relates to a contract or pre-contractual measures requested by you. In other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is efficient and location-independent business communication.

Zoom may process personal data in the United States and other third countries. Zoom participates in the EU-U.S. Data Privacy Framework. Where required, international data transfers are additionally protected by the European Commission’s Standard Contractual Clauses.

We do not record Zoom meetings unless this has been expressly agreed in advance. If a recording is intended, participants will be informed separately and, where required, asked for their consent.

Meeting-related data is retained only for as long as necessary for communication and meeting administration, unless statutory retention obligations require longer storage.

Further information about Zoom’s processing of personal data is available at:
https://www.zoom.com/en/trust/privacy/privacy-statement/

5.2 Video Conferences with Zoom

We use Calendly, a scheduling service provided by Calendly LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA, to enable interested parties and business contacts to arrange appointments with us.

Calendly is not embedded on this website. The scheduling page is opened only when you click the “Schedule a Call” link. Therefore, no connection to Calendly is established merely by visiting this website.

When you book an appointment, Calendly processes the information you provide, in particular your name, email address, company or organisation, your preferred appointment date and time, and the information entered in the booking form. Technical data such as your IP address, browser and device information may also be processed. The data is used to arrange, manage and conduct the requested appointment and is added to our connected calendar.

The legal basis is Art. 6(1)(b) GDPR where the appointment relates to a contract or pre-contractual measures requested by you. In other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the efficient and user-friendly coordination of appointments.

Calendly processes booking data on our behalf under a data processing agreement. Data may also be processed in the United States. Calendly participates in the EU-U.S. Data Privacy Framework. Where required, Calendly also relies on the European Commission’s Standard Contractual Clauses.

We retain appointment data only for as long as necessary for communication and appointment management, unless statutory retention obligations require longer storage.

Further information about Calendly’s processing of personal data is available at:
https://calendly.com/legal/privacy-notice

6. Website Security – Wordfence

This website uses Wordfence Security to protect the website against unauthorised access, malware, attacks and other security threats.

For security purposes, technical information such as IP addresses, access attempts and other security-related information may be processed.

Wordfence is configured to log security-relevant traffic only, rather than general visitor traffic. Security-related Live Traffic information is configured to be retained for a maximum of 30 days and up to 2,000 records.

Processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in protecting the website, its systems and the data processed through it against misuse, unauthorised access and cyberattacks.

7. Website Backups

Regular backups of this website are created using UpdraftPlus.

Backups may include website files and database content. Consequently, personal data stored within the WordPress database, including information submitted through the contact form, may be included in a backup.

Remote backups are stored using Google Drive. The purpose of the backups is to ensure data availability, system recovery and protection against data loss.

Processing is based on Art. 6(1)(f) GDPR. The legitimate interest lies in maintaining the security, integrity and recoverability of the website and its data.

Where the use of Google Drive involves the transfer of personal data outside the European Economic Area, such transfers are subject to the applicable safeguards required under the GDPR.

8. Cookies and Tracking Technologies

This website does not intentionally use analytics, advertising or marketing cookies for ordinary website visitors.

IONOS WebAnalytics operates without cookies according to IONOS.

No Google Analytics, Meta Pixel, LinkedIn Insight Tag or comparable advertising or behavioural tracking technology is currently used on this website.

If the technical configuration or services used on this website change in the future, this Privacy Policy will be updated accordingly.

9. External Links

This website may contain links to external websites, including LinkedIn.

A connection to the respective external service is generally established only when you actively follow such a link. Once you leave this website, the privacy policies and data processing practices of the respective third-party provider apply.

I have no control over the data processing carried out by such external websites.

10. Your Rights under the GDPR

Subject to the applicable legal requirements, you have the right to:

  • obtain information about personal data processed concerning you (Art. 15 GDPR),
  • request correction of inaccurate personal data (Art. 16 GDPR),
  • request deletion of your personal data (Art. 17 GDPR),
  • request restriction of processing (Art. 18 GDPR),
  • receive personal data in a portable format where applicable (Art. 20 GDPR),
  • object to processing based on legitimate interests (Art. 21 GDPR), and
  • withdraw consent at any time where processing is based on consent (Art. 7(3) GDPR).

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise your rights, please contact me using the contact details provided above.

11. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.

You may in particular contact the supervisory authority responsible for your place of residence, place of work or the place of the alleged infringement.

12. Data Security

Appropriate technical and organisational measures are used to protect personal data against loss, misuse, unauthorised access, alteration and other security risks.

This website uses encrypted HTTPS/TLS connections to protect information transmitted between your browser and the website.

13. Changes to this Privacy Policy

This Privacy Policy may be updated where necessary, for example following changes to the website, the services used or applicable legal requirements.

Last updated: September 2026

Drag View

ELEVATE YOUR BUSINESS WITH

Valiance theme

Limitless customization options & Elementor compatibility let anyone create a beautiful website with Valiance.