Privacy Policy
Last updated: 14 July 2026
Privacy policy
This privacy policy explains how we process personal data when you visit this website, use our editorial content, subscribe to our newsletter, or use the VentureIQ tool. It applies in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection law.
1. Controller
The controller responsible for data processing on this website within the meaning of Article 4(7) GDPR is:
Guido Gehb
Katharinenstraße 19
01099 Dresden
Germany
Phone: +49 1577 0164202
Email: info@sleekline.net
2. Data protection officer
We are not required to appoint a data protection officer under Section 38 of the German Federal Data Protection Act (BDSG). For privacy-related enquiries, please contact the controller using the details above.
3. Your rights as a data subject
You have the following rights regarding your personal data, subject to the conditions set out in the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR), where processing is based on consent
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, please contact us using the details in Section 1. We will respond without undue delay and, in any event, within one month, unless the request is complex or numerous.
Supervisory authority: The competent authority for Saxony is the Saxony State Commissioner for Data Protection (Sächsischer Datenschutzbeauftragter), Maternistraße 17, 01067 Dresden, Germany — www.saechsdsb.de.
4. Right to object (Art. 21 GDPR)
Where we process your personal data on the basis of Article 6(1)(f) GDPR (legitimate interests), you have the right to object at any time on grounds relating to your particular situation.
Where we process personal data for direct marketing purposes, you have the right to object at any time to such processing, including profiling related to direct marketing.
If you object, we will no longer process the relevant data unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
5. Hosting and server log files
This website is hosted by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4–6, 32339 Espelkamp, Germany. The hosting provider processes personal data on our behalf in data centres located in Germany.
When you access our website, the hosting infrastructure automatically collects and temporarily stores information in server log files, including:
- IP address (shortened or anonymised where configured)
- Date and time of the request
- Requested URL and HTTP method
- HTTP status code and data volume transferred
- Browser type and operating system (User-Agent)
- Referrer URL
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in the secure, stable, and efficient provision of our website.
Retention: Server log files are deleted after 30 days, unless longer retention is required for security investigations.
Encryption: This website is delivered over HTTPS (TLS/SSL) to protect data in transit between your browser and our servers.
A data processing agreement pursuant to Article 28 GDPR is in place with the hosting provider.
6. Cookies and consent management
We use cookies and similar technologies. Cookies that are not strictly necessary require your consent under Section 25 of the German Telecommunications and Telemedia Data Protection Act (TTDSG) and Article 6(1)(a) GDPR.
Consent is managed through our Jenva Cookie consent management platform (CMP). The CMP:
- informs you about cookies and third-party services by category;
- blocks non-essential scripts and content until you grant consent;
- records your choices for audit purposes;
- allows you to withdraw or change your consent at any time via the cookie settings link in the footer.
Consent records: Your consent decisions (including timestamp, consent version, categories granted or rejected, and a pseudonymous identifier) are stored in a consent log for 180 days to demonstrate compliance with Article 7(1) GDPR.
For details on individual cookies and services, please see our cookie policy.
7. Web analytics (Analytics WP Pro)
We use Analytics WP Pro, a self-hosted, first-party analytics solution. Analytics data is processed on our own server infrastructure and is not shared with third-party analytics platforms such as Google Analytics by default.
Analytics is activated only after you grant consent to the statistics category in our cookie banner. Without consent, no analytics tracking occurs.
Depending on configuration, the following data may be processed: pseudonymous visitor identifier, pages viewed, referrer, browser and device information, approximate location (without full IP address where configured), and campaign parameters.
Legal basis: Article 6(1)(a) GDPR and Section 25(1) TTDSG (consent).
Retention: Analytics data is retained for up to 365 days, after which it is aggregated or deleted.
8. VentureIQ — AI business analysis tool
VentureIQ is an interactive tool that generates a business analysis based on information you provide (e.g. location, skills, budget, business idea). Before starting an analysis, you are shown an information screen explaining how your inputs are processed.
8.1 Categories of data processed
- Profile and wizard inputs (name or pseudonym, location, skills, budget, industry, business idea, language preferences, and similar fields)
- Technical data: IP address (for abuse prevention and rate limiting), browser language, timestamp
- Analysis results generated by the AI provider
- Pro checkout (planned, not yet active): no payment provider is live on this website at present. Once launched, payments are intended to be processed via Lemon Squeezy; payment-related session data would then be stored temporarily until payment confirmation. This section will be updated with the provider’s full details and international transfer safeguards before the Pro tier goes live.
8.2 Purpose and legal basis
Legal basis: Article 6(1)(b) GDPR — processing is necessary to carry out pre-contractual measures at your request and to perform the analysis service you initiate.
We do not use a consent gate as a precondition for access. Instead, we provide transparent information before you start the analysis.
8.3 AI provider and international transfers
Note on an upcoming provider change: Before this product goes live, we intend to switch the AI provider from OpenAI to a Mistral AI model hosted via Microsoft Azure in an EU region (expected: West Europe or France Central). If processing takes place exclusively within the EU, the international transfer described below would no longer apply; this section will be updated accordingly before the switch. The information below reflects the current state until then.
Your inputs are transmitted from our server to OpenAI Ireland Ltd. (with processing potentially involving OpenAI, L.L.C. in the United States) for AI analysis. Transfers to countries outside the European Economic Area are safeguarded by:
- the EU–US Data Privacy Framework (DPF), where applicable; and/or
- Standard Contractual Clauses (SCCs) pursuant to Article 46 GDPR.
We do not rely on Article 49(1)(a) GDPR (explicit consent) as the legal basis for these transfers. Data submitted via our API is not used to train OpenAI models where the provider’s enterprise/API terms so provide.
8.4 Sensitive data (Art. 9 GDPR)
Please do not enter special categories of personal data (e.g. health information, political opinions, religious beliefs) in free-text fields. If you nevertheless submit such data, we will process it only to the extent strictly necessary to deliver the requested analysis and will delete it as soon as possible.
8.5 No automated decision-making (Art. 22 GDPR)
VentureIQ provides informational AI output only. It does not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. You remain solely responsible for any decisions you make based on the analysis.
8.6 Retention and rate limiting
Free analyses: your wizard inputs are not permanently stored. IP-based rate limiting applies for abuse prevention (retention of the IP hash for up to 24 hours).
Pro checkout (planned, not yet active): once enabled, profile data may be stored temporarily for up to 48 hours until payment is confirmed or the session expires.
8.7 PDF export
When you export your analysis as a PDF, the jsPDF library is loaded locally from this website (self-hosted in our theme assets). No data is transferred to external CDNs such as cdnjs or Cloudflare for PDF generation. PDF creation takes place entirely in your browser; we do not receive the exported file.
9. Newsletter
If you subscribe to our newsletter, we process your email address and, if provided, your name and preferred language.
Double opt-in: After registration, you will receive a confirmation email with a link. Your subscription becomes active only after you confirm. This ensures that no third party can register using your email address.
Legal basis: Article 6(1)(a) GDPR (consent). You may withdraw your consent at any time by using the unsubscribe link in every newsletter email or by contacting us.
Consent logging: We record the time of consent, the consent text version, and the IP address at signup for audit purposes (Article 7(1) GDPR).
Retention: We store your data until you unsubscribe. Consent records are retained for the statutory limitation period for evidence purposes.
Rate limiting: A maximum of three signup attempts per IP address per hour is permitted to prevent abuse.
10. Contact by email
If you contact us by email, we process the personal data you provide (typically your email address, name if stated, and the content of your message) to handle your enquiry.
Legal basis: Article 6(1)(b) GDPR if your message relates to a contract or pre-contractual relationship; otherwise Article 6(1)(f) GDPR — our legitimate interest in responding to enquiries.
Retention: We retain correspondence for as long as necessary to process your request and for the statutory limitation period where relevant, then delete it unless statutory retention obligations apply.
We do not operate a contact form on this website. Communication takes place exclusively via the email address published in the legal notice.
11. Typography (local fonts)
We serve web fonts from our own server (self-hosted font files in the theme). Google Fonts and other external font CDNs are not loaded on the public-facing website when local fonts are active. This prevents your IP address from being transmitted to font providers when you visit our pages.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in a privacy-friendly, performant, and consistent presentation of our website.
12. Disclosure of data to third parties
We disclose personal data to third parties only where:
- you have given consent (Art. 6(1)(a) GDPR);
- disclosure is necessary for the performance of a contract (Art. 6(1)(b) GDPR);
- we are legally obliged to do so (Art. 6(1)(c) GDPR); or
- disclosure is necessary for the purposes of our legitimate interests and is not overridden by your interests (Art. 6(1)(f) GDPR).
Recipients may include hosting providers, AI service providers (see Section 8), email delivery services, and backup service providers (see Section 13). We conclude data processing agreements pursuant to Article 28 GDPR with processors where required.
13. Backups (UpdraftPlus)
We use the UpdraftPlus plugin to create backups of the website and database. Backups may contain personal data processed through this website (e.g. newsletter subscribers, consent logs, analytics data).
Backups are stored on our server and, if configured, on external storage services connected by the site administrator. Retention periods depend on the backup configuration.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in securing data and ensuring recoverability in the event of technical failures.
14. Social media links
Our website contains simple text or icon links to social networks (e.g. LinkedIn, X/Twitter). These are regular hyperlinks — no social media plugins or embedded content that transmit data to the respective platforms before you click are used.
Only when you actively click a link will you be redirected to the third-party platform, which then processes your data under its own privacy policy. We have no control over data processing on external platforms.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in informing visitors about our social media presence.
15. Security measures
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, including:
- TLS/SSL encryption for data in transit
- Access controls and role-based permissions in the administration area
- Regular software updates for WordPress, themes, and plugins
- Consent-based blocking of non-essential third-party scripts
- Blocking of external avatar and font CDNs on the public website
- Rate limiting for newsletter signups and VentureIQ requests
- Backup and recovery procedures
16. Changes to this privacy policy
We may update this privacy policy when our processing activities, legal requirements, or technical infrastructure change. The current version is always available on this page.
Material changes will be communicated appropriately where required by law. The version dated 14 July 2026 is the current version.
If you have questions about this privacy policy or our data processing practices, please contact us at info@sleekline.net.