Zum Inhalt springen

For new clients: we design your mobile menu free of charge.See mobile designs

Privacy policy

This is a convenience translation. The German version is legally binding. Thank you for your interest in our website. This privacy policy describes which personal data we process when you visit labrigart.de, book an appointment or write to us, why we do so, and which rights you have.

1. Controller

Labrigart.Design GmbH
Zeppelinring 34
88400 Biberach an der Riß
Germany

Represented by the Managing Directors David Pehl and Anas Elimani
Email: info@labrigart.de

2. The key points in brief

  • When you visit our pages we set no cookies and load no analytics or advertising tools without your consent. A notice on your first visit asks whether we may use Google Analytics (statistics) and Google Ads (marketing) (sections 8 to 11).
  • We serve fonts and images from our own server. Your browser does not connect to third parties for this.
  • On the page “Book an intro call” we embed the appointment calendar of our provider HighLevel (section 6).
  • We only load the chat once you click “Ask a question” (section 7).
  • You can change or withdraw your decision at any time via “Cookie settings” at the bottom of every page.

3. Hosting and server log files

Our website is hosted and delivered by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. With every request, Cloudflare processes technically necessary data so that the page reaches you and is protected against attacks:

  • IP address of the requesting device
  • date and time of the request
  • the address requested and the page you came from (referrer)
  • browser, operating system and the amount of data transferred

The legal basis is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in the secure, fast and error-free delivery of our website. Cloudflare processes this data on our behalf under a data processing agreement (Art. 28 GDPR). Cloudflare is certified under the EU-US Data Privacy Framework. For transfers to the USA, an adequacy decision of the EU Commission is therefore in place (Art. 45 GDPR).

4. Contact by email

If you send us an email, we process your address and the details in your message in order to answer your request. The legal basis is Art. 6 (1) lit. b GDPR where your request relates to a contract, otherwise Art. 6 (1) lit. f GDPR (our interest in answering requests). We delete the data once the request has been dealt with and no statutory retention obligations stand in the way.

5. Data you do not have to provide

You can visit our website without providing any personal details. For an intro call we need your name and an email address, otherwise we cannot arrange the appointment. All other details are voluntary.

6. Booking an appointment for the intro call

On the page Book an intro call the appointment calendar of HighLevel LLC, 5473 Blair Rd Ste 100, PMB 383313, Dallas, Texas 75231-4227, USA, is embedded (calendar address: meet.labrigart.de). Its representative in the EU is Rickert Rechtsanwaltsgesellschaft mbH, Colmantstraße 1, 53115 Bonn, Germany.

When you open the page

As soon as you open the page, your browser loads the calendar from HighLevel's servers. In the process, your IP address, the date and time, the page requested and details about your browser and operating system are transmitted to HighLevel. HighLevel sets a technically necessary cookie (__cf_bm) to block automated access.

The calendar in turn loads content from further providers:

  • fonts and files from Google (fonts.googleapis.com, fonts.gstatic.com, storage.googleapis.com), provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
  • program libraries from unpkg.com, a public service for delivering program code
  • a script from Meta (connect.facebook.net), provider Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland

Your IP address is also transmitted to these providers. Google and Meta may transfer data to the USA. According to their own statements, both companies are certified under the EU-US Data Privacy Framework.

When you book

If you book an appointment, HighLevel processes on our behalf the details you enter in the form, for example your name, email address, phone number, your online store and the appointment you chose. We use these details to prepare and hold the call and to send you a confirmation and a reminder.

The legal basis for the booking is Art. 6 (1) lit. b GDPR (steps prior to entering into a contract, taken at your request). For embedding the calendar we rely on Art. 6 (1) lit. f GDPR: our legitimate interest is simple appointment scheduling directly on our website. HighLevel is certified under the EU-US Data Privacy Framework, so the adequacy decision of the EU Commission applies to transfers to the USA (Art. 45 GDPR). A data processing agreement is in place with HighLevel (Art. 28 GDPR).

We store your booking data for as long as we need it for the call and a possible collaboration. If no collaboration comes about, we delete it as soon as we no longer need it for this purpose and no statutory retention obligations stand in the way.

More about privacy at HighLevel: www.gohighlevel.com/privacy-policy

7. Chat

At the bottom right of our pages you will find the button “Ask a question”. Only when you click it do we load the chat of our provider LeadConnector (HighLevel LLC, address see section 6). Nothing is transmitted to the provider before that.

After the click, your browser connects to LeadConnector's servers (leadconnectorhq.com, msgsndr.com). The data transmitted includes your IP address, details about your browser and operating system, the address of the page you are on, and everything you write in the chat, such as your name, email address or phone number. The chat loads fonts from Bunny Fonts (BunnyWay d.o.o., Slovenia) and uses the service Cloudflare Turnstile (Cloudflare, Inc., address see section 3) to block automated access. In the process, a technically necessary cookie (__cf_bm) is set.

The legal basis for loading the chat is your consent given by clicking (Art. 6 (1) lit. a GDPR, § 25 (1) TDDDG). We process the content of your messages in order to answer your question (Art. 6 (1) lit. b or f GDPR). You can withdraw your consent at any time with effect for the future by closing the chat and deleting the data your browser has stored for our site. For transfers to the USA, the information in section 6 applies.

8. Consent to cookies and measurement tools

On your first visit we show a notice that lets you decide whether we may use Google Analytics 4 (statistics) and Google Ads conversion tracking (marketing). Without your consent we do not load these tools and no cookie is set for them. We only store your decision itself in your browser's local storage (entry “nx_einwilligung”: chosen categories and time) so the notice does not appear on every visit. This entry is valid for one year and is not passed on to third parties.

The legal basis for storing your decision is § 25 (2) no. 2 TDDDG (strictly necessary). The legal basis for the measurement tools is your consent under § 25 (1) TDDDG and Art. 6 (1) lit. a GDPR. You can withdraw your consent at any time with effect for the future via “Cookie settings” at the bottom of every page. Withdrawal does not affect the lawfulness of processing carried out before it.

We use Google Consent Mode: before you consent, all consent categories are set to “denied” and no data is sent to Google (basic mode). Only after your consent do we load the Google services with the categories you chose.

9. Google Tag Manager and server-side tagging

After your consent we load Google Tag Manager, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Tag Manager itself does not process personal data for its own purposes; it controls which measurement tools (sections 10 and 11) are triggered. The connection runs through a server we have operated by the provider Stape (Stape Inc., 2093 Philadelphia Pike #1991, Claymont, DE 19703, USA; server location in the EU), reachable under our address gtm.labrigart.de. Your browser therefore connects to our server instead of directly to Google; this server forwards the measurement data to Google and can shorten or remove data on the way. A data processing agreement with Stape is in place (Art. 28 GDPR).

The legal basis is your consent (Art. 6 (1) lit. a GDPR, § 25 (1) TDDDG). Google is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). Further information: Google privacy policy and Stape privacy policy.

10. Google Analytics 4

With your consent to the “Statistics” category we use Google Analytics 4, a web analytics service by Google. Google Analytics uses cookies (among others “_ga” and “_ga_*”, lifetime up to two years) and records which pages you open, where you come from, which device and browser you use, your approximate region, and events such as booking an intro call, signing up for the newsletter or opening the chat. Google Analytics 4 does not store IP addresses and only evaluates them roughly to determine location. We use the reports to understand which content helps our visitors and to improve the website.

The legal basis is your consent (Art. 6 (1) lit. a GDPR, § 25 (1) TDDDG). The data is stored for 14 months and then deleted. Google processes the data on our behalf (Art. 28 GDPR); transfers to the USA are covered by Google's certification under the EU-US Data Privacy Framework. Withdrawal: via “Cookie settings” at the bottom of every page. More: Privacy at Google Analytics.

11. Google Ads conversion tracking

With your consent to the “Marketing” category we use Google Ads conversion tracking. If you reach our website through a Google ad and book an intro call, Google learns that the ad led to this booking. For this Google sets a cookie (among others “_gcl_au”, lifetime 90 days) that contains no personal details about you. We only see how many bookings go back to which ads, not who you are. Each booking is counted once.

The legal basis is your consent (Art. 6 (1) lit. a GDPR, § 25 (1) TDDDG). Google is certified under the EU-US Data Privacy Framework. Withdrawal: via “Cookie settings” at the bottom of every page. More: Google privacy policy and Ads settings.

12. Links to other websites

On our website we link to our profiles on LinkedIn, Instagram, Facebook and YouTube and to the Shopify partner directory. These are plain links: only when you click one does your browser connect to the respective provider. That provider's privacy policy applies there.

13. Recipients of your data

Your data is received only by the service providers named in this policy, to the extent they need it for their task, and within our company by the people who handle your request. We do not sell your data and do not pass it on for advertising purposes.

14. Your rights

You have the following rights towards us regarding your personal data:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • withdrawal of consent with effect for the future (Art. 7 (3) GDPR)

An email to info@labrigart.de is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg), Heilbronner Straße 35, 70191 Stuttgart, Germany.

15. Right to object

Where we process your data on the basis of our legitimate interest (Art. 6 (1) lit. f GDPR), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defense of legal claims.

16. Retention period

We store personal data only for as long as is necessary for the respective purpose. After that we delete it, unless statutory retention obligations (for example under commercial and tax law, up to ten years) require longer storage. In that case we restrict the processing.

17. No automated decision-making

We do not make decisions based solely on automated processing, including profiling (Art. 22 GDPR).

18. Encryption

Our website is transmitted in encrypted form (TLS). You can recognize this by the padlock symbol and “https://” in your browser's address bar.

19. Changes

We update this privacy policy whenever our website or the legal situation changes. The version published here applies.
Last updated: October 2026

Clicking loads the chat of our provider. No data is sent to them before that.