Legal Foundation
Privacy Policy (Datenschutzerklärung)
Last Updated: August 28, 2026
This policy outlines how Anderson Rairt Timana Solier (“Consultant,” “I,” “me”) handles personal data on this platform. As a digital business strategist, I am committed to the highest standards of data protection and transparency in accordance with the European General Data Protection Regulation (GDPR/DSGVO) and the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG).
1. General Information and Mandatory Information
Designation of the Responsible Party
The party responsible for data processing on this website is:
Anderson Rairt Timana Solier
Brahmsbogen 17
06124, Halle (Saale)
Email: redevelop@andersontimana.me
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can revoke consent that has already been given at any time (Art. 7 (3) GDPR). An informal communication by email to me is sufficient for this purpose. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Lodge a Complaint with the Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of their habitual residence, place of work, or place of the alleged violation. In your case (Sachsen-Anhalt), the competent authority is:
Landesbeauftragte für den Datenschutz Sachsen-Anhalt
Visitor Address: Otto-von-Guericke-Straße 34a, 39104 Magdeburg
Postal Address: Postfach 1947, 39009 Magdeburg
Phone: +49 (0) 391 81803-0
Email: poststelle@lfd.sachsen-anhalt.de
Website: https://datenschutz.sachsen-anhalt.de
2. Data Collection on this Website
Server Log Files & Hosting (Cloudflare Pages)
This website is hosted via Cloudflare Pages (Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA). When you visit this site, Cloudflare automatically collects and stores information in server log files:
- Browser type/version and operating system
- Referrer URL and IP address
- Time of the server request
Legal Basis: Art. 6 (1)(f) GDPR (Legitimate Interest) to ensure secure, stable operation and protection against cyber-attacks.
Data Processing Agreement & Third-Country Transfer: A Data Processing Agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Cloudflare Inc. Transfer of personal data to the USA is safeguarded via Cloudflare’s certification under the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs).
Security Verification & Bot Protection (Cloudflare Turnstile)
To protect our web forms (such as newsletter subscription and strategic tool access) from automated abuse, spam, and denial-of-service attacks, this website uses Cloudflare Turnstile (Cloudflare Inc.).
- Data Processed: Turnstile collects non-telemetric signals, HTTP header fields, browser characteristics, mouse/touch interaction patterns, and IP address to distinguish human users from automated bots.
- Legal Basis: Art. 6 (1)(f) GDPR (Legitimate Interest in maintaining the security, integrity, and operational availability of digital services).
- Third-Country Transfer & Safeguards: Covered under the EU-U.S. Data Privacy Framework (DPF) certification and Standard Contractual Clauses (SCCs) concluded with Cloudflare, Inc.
Reach Measurement and Behavioral Analysis (Plausible)
To optimize content and measure reach without compromising user privacy, this website uses Plausible Analytics.
- Self-Hosted & Privacy-First: The analytics script is self-hosted on my own server infrastructure.
- No Cookies & TDDDG Compliance: This method does not store any information on your end device (cookieless) and sets no cookies, fully complying with § 25 TDDDG. No personal data is stored, and no individual user profiles are created.
- Legal Basis: Art. 6 (1)(f) GDPR (Legitimate Interest).
Newsletter (Brevo)
If you sign up for the newsletter, the data entered (Email) is processed by Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany / France).
- Double Opt-In & Consent: Registration uses a Double-Opt-In (DOI) process. The legal basis is Art. 6 (1)(a) GDPR (Consent).
- Storage & Revocation: Data is stored until you unsubscribe via the link in any newsletter or by contacting redevelop@andersontimana.me. You may revoke your consent at any time (Art. 7 (3) GDPR).
- DPA: A Data Processing Agreement (Art. 28 GDPR) has been concluded with Sendinblue GmbH.
3. Contact and Qualification Forms (Tally)
I use Tally (Tally BV, Belgium) to manage inquiries and applications. Tally is a European provider that processes and stores data strictly within the European Union (EU). To ensure data processing complies with GDPR requirements, a Data Processing Agreement (DPA) according to Art. 28 GDPR has been concluded with Tally BV.
3.1 General Contact Form
When you use the contact form to reach out for general inquiries:
- Categories of Data: Name (optional), Mandatory Email/Identification Field, and text content of your message.
- Legal Basis: Art. 6 (1)(f) GDPR (Legitimate Interest to handle and respond to your inquiry) or Art. 6 (1)(b) GDPR (Pre-contractual measures).
- Storage Duration: Inquiries are retained only as long as necessary to process your request or satisfy statutory retention obligations (e.g. 6 to 10 years under commercial/tax law if relevant).
3.2 The Qualification Form
When you apply for a Strategic Assessment:
- Categories of Data: Contact information, Business Metrics (Revenue ranges, Tech Stack), and Qualitative descriptions.
- Legal Basis: Art. 6 (1)(b) GDPR (Pre-contractual measures).
- Anonymization for Benchmarking: As outlined in the mNDA, once data is disassociated from your identity, it may be used for anonymized benchmarking (Art. 89 GDPR). To ensure privacy, only values from predefined fields (such as multiple-choice, dropdowns, or checkboxes) are utilized for benchmarking; the contents of qualitative text fields are strictly excluded from this process. This is only performed provided the dataset exceeds a statistically significant sample size of at least five (5) entries.
4. Third-Party Tools and Communications
Email Communication & End-to-End Encryption (PGP)
My primary professional email (@andersontimana.me) is hosted via Namecheap (Namecheap Inc., USA).
- Compliance & Transfers: Data transfers to the USA are safeguarded by Standard Contractual Clauses (SCCs) pursuant to Art. 46 (2)(c) GDPR as incorporated into Namecheap’s Universal Terms of Service.
- Encryption Standards: To ensure the highest level of data confidentiality regardless of server location, I offer End-to-End Encryption via PGP (Pretty Good Privacy).
- Client Security: Clients and leads are encouraged to use my PGP Public Key for all sensitive communications and document transfers. This ensures that the content of the communication remains encrypted and unreadable to any third parties, including the email service provider, until it reaches my local, secured environment. My public key is available upon request.
5. Your Rights as a Data Subject
Under the GDPR, you have the following rights free of charge at any time:
- Right of Access (Art. 15 GDPR): Request confirmation as to whether personal data concerning you is being processed and obtain information about it.
- Right to Rectification (Art. 16 GDPR): Request the immediate correction of inaccurate personal data or completion of incomplete data.
- Right to Erasure / “Right to be Forgotten” (Art. 17 GDPR): Request the deletion of your personal data stored by us.
- Right to Restriction of Processing (Art. 18 GDPR): Request the restriction of processing your personal data under statutory conditions.
- Right to Data Portability (Art. 20 GDPR): Receive your personal data provided to us in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21 GDPR): Object at any time, on grounds relating to your particular situation, to processing based on Art. 6 (1)(e) or (f) GDPR.
- Right to Withdraw Consent (Art. 7 (3) GDPR): Revoke any consent previously granted at any time with effect for the future.
To exercise any of these rights, please contact me via email at redevelop@andersontimana.me.
6. Data Security and TDDDG Compliance
This website uses SSL/TLS encryption for all data transmissions to protect personal data against unauthorized third-party access. In compliance with § 25 TDDDG, no non-essential tracking cookies or local terminal storage mechanisms are placed on user devices.
Last Updated: August 28, 2026