DeepRise
DE EN

Privacy Policy

1. Controller

The controller responsible for data processing on this website within the meaning of the GDPR is:

DeepRise – Goñi & Brunk GbR i.Gr.
Im Wiesengrund 57
22147 Hamburg, Germany
Email:

2. Your Rights at a Glance

You have the right at any time to:

The competent authority is:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany
datenschutz-hamburg.de

For any questions regarding these rights, please contact us at the email address above.

3. Hosting

This website is hosted by an external service provider:

Stefan Riegel IT-Consulting
Im Wiesengrund 57, 22147 Hamburg, Germany

All personal data collected on this website (including server log files, contact form data, email communication) is stored on this host's servers in Germany — no data is transferred to third countries through hosting. The legal basis is our legitimate interest in a secure, fast and professional provision of our online services (Art. 6(1)(f) GDPR).

We have a data processing agreement (DPA) in place with the host in accordance with Art. 28 GDPR.

4. Server Log Files

When you access this website, our host automatically collects information that your browser transmits ("server log files"):

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the technically error-free and secure operation of our website). This data is not combined with other data sources.

5. Cookies

We do not use any cookies on this website — not even a technically necessary session cookie. Neither the contact form nor the spam protection we use (see Section 6) requires a server-side session state; form processing is entirely stateless, with no identifier stored in your browser. Therefore, no cookie consent banner is required.

Should cookies be introduced in future — for example, through an analytics tool or an additional feature — we will obtain your consent beforehand (Art. 6(1)(a) GDPR, Section 25(1) TDDDG) and update this Privacy Policy accordingly.

6. Contact Form & Spam Protection

If you contact us via the contact form, we process the data you provide (name, email address, optionally phone number and company, as well as your message) in order to process your enquiry and for any follow-up questions. The form runs on a server component developed specifically for this website (no third-party plugin); the data is stored in a dedicated database on the same server as the website (see Section 3), and emails are sent via our host's SMTP server — without involving any external third-party email provider.

The legal basis is Art. 6(1)(b) GDPR (taking steps prior to entering into, or performance of, a contract) or Art. 6(1)(f) GDPR (legitimate interest in processing your enquiry). Data is deleted as soon as it is no longer required for this purpose, latest after 6 months, and no statutory retention obligations apply.

Spam protection (honeypot & ALTCHA): To distinguish human input from automated requests, we use two technical measures that both run entirely on our own server: a hidden form field ("honeypot"), invisible to genuine visitors and only ever filled in by automated bots, and ALTCHA — a self-hosted, open-source solution that solves a small computational task in the background to distinguish human from automated requests. Unlike many widely used CAPTCHA services, ALTCHA runs entirely on our own infrastructure — no data is transferred to any external third party, no cookies are set, and no separate data processing agreement with a CAPTCHA provider is required (processing is already covered by the existing DPA with our host, see Section 3).

The legal basis is our legitimate interest in protection against misuse and spam (Art. 6(1)(f) GDPR).

7. Appointment Booking

For automated scheduling of a call, we link to the external booking service cal.eu. The booking process takes place entirely on cal.eu's servers, not embedded on our website — no data is transmitted from us to cal.eu, as you access their page directly. cal.eu's privacy policy applies: cal.eu/privacy

8. Disclosure of Data

We only disclose personal data where this is necessary for the performance of a contract, where we are legally obliged to do so, where a legitimate interest under Art. 6(1)(f) GDPR applies, or where you have given explicit consent. When engaging processors (e.g. our host), we only disclose data on the basis of a valid data processing agreement.

9. Retention Period

Unless a more specific retention period is stated in this Privacy Policy, your data will remain with us until the purpose of processing no longer applies or you assert a legitimate request for erasure — provided no statutory retention obligations (e.g. under tax or commercial law, 6–10 years for invoicing data) apply.

10. Changes to This Privacy Policy

We will update this Privacy Policy whenever changes to data processing or the legal framework make this necessary. The version published on this page at any given time applies.

Last updated: July 2026