Privacy Policy
This Privacy Policy is provided in English for international accessibility. It complies with the General Data Protection Regulation (GDPR / DSGVO). In case of conflict, the German version shall prevail.
1. Data Controller
Eva Engel
DNA-Consulting by Eva Engel
Sonnenblumenweg 4, 65396 Walluf, Germany
Email: eva@dna-consulting.school
Phone: +49 (0) 6123 / 2099159
2. General Information on Data Processing
We process personal data only to the extent necessary to provide a functional website, our content, and our services. Personal data is processed based on the user's consent (Art. 6(1)(a) GDPR), for the performance of a contract (Art. 6(1)(b) GDPR), or based on our legitimate interests (Art. 6(1)(f) GDPR). Data is stored only for as long as necessary to fulfill the stated purposes or as required by law.
3. Data Collected When Visiting the Website
When you visit our website, the following data is automatically collected by the hosting provider for the purpose of ensuring stable operation and security:
— IP address (anonymized where possible)
— Date and time of the request
— Browser type and version
— Operating system
— Referring URL
This data is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest in secure and stable website operation). Log data is typically deleted within 14 days unless required for security purposes.
4. Account Registration & Purchase
When purchasing Vault access, the following data is collected:
— Name
— Email address
— Payment information (processed by Stripe; see Section 7)
— Password (encrypted)
This data is processed for the performance of a contract (Art. 6(1)(b) GDPR) and stored for the duration of the contractual relationship and any subsequent legal retention periods.
5. Email Newsletter / Insights
If you subscribe to receive insights via our opt-in form, we collect:
— Name (optional)
— Email address
Subscription requires double opt-in confirmation. Your data is processed based on your consent (Art. 6(1)(a) GDPR). You may unsubscribe at any time using the link in every email. Upon unsubscription, your data will be deleted unless retention is required by law. Email management is handled via FluentCRM (self-hosted on our server).
6. Cookies
This website uses technically necessary cookies to ensure functionality (e.g., session management, login status). These cookies are processed based on Art. 6(1)(f) GDPR (legitimate interest). No tracking or marketing cookies are used without your explicit consent. If analytics or marketing cookies are used in the future, consent will be obtained via a cookie banner prior to activation.
7. Payment Processing — Stripe
Payments are processed by Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA. When you make a purchase, your payment data (card number, expiration date, CVC) is transmitted directly to Stripe via encrypted connection. We do not store or have access to your full payment details. Stripe processes data in accordance with PCI-DSS standards. Stripe's privacy policy: https://stripe.com/privacy
Data transfer to the USA is covered by Stripe's participation in appropriate data transfer mechanisms (Standard Contractual Clauses / EU-US Data Privacy Framework).
8. Hosting
This website is hosted by a professional hosting provider within the European Union. A data processing agreement (Auftragsverarbeitungsvertrag, AVV) is in place in accordance with Art. 28 GDPR.
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
— Right of access (Art. 15 GDPR)
— Right to rectification (Art. 16 GDPR)
— Right to erasure (Art. 17 GDPR)
— Right to restriction of processing (Art. 18 GDPR)
— Right to data portability (Art. 20 GDPR)
— Right to object (Art. 21 GDPR)
— Right to withdraw consent at any time (Art. 7(3) GDPR)
To exercise any of these rights, contact: eva@dna-consulting.school
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
https://datenschutz.hessen.de
11. Changes to This Policy
We reserve the right to update this Privacy Policy to reflect changes in legal requirements or our services. The current version is always available on this page.
Last updated: February 2026