Legal information

Privacy

This notice explains which personal data is processed when you visit the website or contact Brand & Beyers.

Last updated · 4 August 2026The publication-ready technical version uses no analytics, marketing or external tracking services. The contact form includes technical safeguards against abuse.
01

Controller

Virgenie Beyers
self-employed professional trading as Brand & Beyers
Leipziger Straße 43
10117 Berlin
Germany
Phone: +49 173 2187047
Email: info@brandandbeyers.com

02

Purposes, legal bases and data minimisation

Personal data is processed only where necessary to provide the website securely, answer enquiries, take pre-contractual steps, carry out a business relationship or comply with legal obligations. The relevant legal bases include Article 6(1)(b), (c) and (f) GDPR. Legitimate interests include the secure, stable and economical operation of the website and responding to business enquiries.

No automated decision-making, including profiling, takes place.

03

Hosting, encryption and server logs

The website is delivered by the hosting provider used for this domain. When the website is accessed, the server processes technically necessary connection data, including IP address, time, requested file, transferred data volume, referrer, browser and operating system, status and error data.

Processing is based on Article 6(1)(f) GDPR to deliver the website, identify errors and defend against attacks. Logs are retained according to the hosting configuration only for as long as necessary for operation, troubleshooting and security; where a specific incident occurs, relevant logs may be kept until the incident has been investigated.

The website should be provided exclusively through encrypted HTTPS connections.

04

Contact form, email and abuse prevention

When you submit an enquiry, the company, country, name, email address, position, discussion topic and message are processed. The information is sent server-side to info@brandandbeyers.com. No external form service is used.

To protect the form, the website uses a technically necessary session cookie, a one-time security token, a timestamp, a hidden bot field and a server-side limit on repeated requests. For rate limiting, the IP address is hashed with a server-related value; the associated timestamps are evaluated for rate limiting in temporary server storage for no more than 24 hours and are then removed through technical clean-up. This data is used solely to prevent spam, automated abuse and attacks and is processed under Article 6(1)(f) GDPR.

Other processing is carried out under Article 6(1)(b) GDPR where a contract or pre-contractual steps are concerned, and otherwise under Article 6(1)(f) GDPR. Enquiries are deleted when no longer required unless statutory retention duties or legitimate documentation interests apply.

Providing the fields marked as required is not a statutory obligation and, before an enquiry is made, is not a contractual obligation. Without those details, however, the enquiry cannot be processed through the form.

05

Cookies and terminal equipment

The website uses no analytics, marketing or tracking cookies. Only when the contact form is opened may a technically necessary session cookie be set with the attributes “Secure”, “HttpOnly” and “SameSite=Strict”. It is used solely to protect the requested form function and is deleted at the end of the browser session.

No consent is currently required for non-essential cookies because no such services are used. If relevant services are added later, this notice will be updated and consent obtained where required.

06

Fonts, images, videos and scripts

The website loads its fonts, images, videos, stylesheets and scripts from its own web storage. Opening the website does not establish a connection to external font, video, analytics or social-media services.

07

Recipients and processors

Personal data is accessible to the controller as the self-employed provider and, where necessary for operation or communication, providers of hosting, server administration and email services. Providers are involved only to the necessary extent and are contractually appointed as processors where required.

Public authorities or other bodies receive data only where legally required or where necessary to establish, exercise or defend legal claims.

08

Transfers outside the EEA

The website is not intended to transfer personal data outside the European Economic Area. Where a provider uses sub-processors in a third country, transfers take place only where the statutory requirements are met, particularly on the basis of an adequacy decision or appropriate safeguards.

09

Your data protection rights

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. Consent can be withdrawn at any time with future effect.

Where processing is based on Article 6(1)(f) GDPR, you may object under Article 21 GDPR on grounds relating to your particular situation.

You also have the right to lodge a complaint with a data protection supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information.

10

Technical and organisational security

Appropriate technical and organisational measures are used to protect the confidentiality, integrity, availability and resilience of systems. These include encrypted transmission, input validation, security headers, access controls, abuse limiting and regular updates to the server environment.

No internet service can guarantee complete protection against every attack. Security measures are therefore reviewed and adjusted on a risk-based basis.

11

Updates and provider details to verify

This notice will be updated when technical services, providers, retention periods, legal requirements or processing activities change. Before publication, the actual hosting provider, email provider and their retention and international-transfer configuration must be checked against the contracts and Plesk settings.