Last updated: August 2026
Frederik von der Heyden
Danzigweg 5a, 59755 Arnsberg, Germany
Email: frederik@frederikvonderheyden.de
This website is a static informational site. It uses no cookies, no tracking, no analytics, and no contact forms.
Personal data is only processed when you voluntarily interact with our services, such as purchasing a subscription (see Section 6) or contacting us by email (see Section 7).
The hosting provider automatically collects and stores information in server log files that your browser transmits automatically:
This data cannot be attributed to specific individuals. It is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the technical operation of the website). Logs are deleted after 30 days.
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner is a data processor (Auftragsverarbeiter) and recipient of your data pursuant to Art. 13(1)(e) and Art. 28 GDPR. A data processing agreement (DPA) is in place. All data processing takes place exclusively in Germany.
This site uses SSL/TLS encryption for security. You can recognize an encrypted connection by the lock icon in your browser's address bar and the "https://" prefix.
Paid subscriptions are processed via Stripe, Inc. (510 Townsend St, San Francisco, CA 94103, USA). When you purchase a subscription, Stripe processes your payment data (name, email, payment method) as a data recipient pursuant to Art. 13(1)(e) GDPR. The legal basis for processing payment data is Art. 6(1)(b) GDPR (performance of a contract). We do not store credit card numbers or payment details on our servers. Stripe retains payment data in accordance with their own privacy policy and applicable financial record-keeping obligations. See: Stripe Privacy Policy.
Stripe is certified under the EU-US Data Privacy Framework, ensuring an adequate level of data protection for transatlantic data transfers.
When you contact us by email, we process your email address and message content to respond to your inquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures or contract performance) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).
Email correspondence is retained for as long as necessary to process your inquiry and deleted thereafter, unless retention is required by law (e.g., commercial or tax retention periods).
You have the following rights regarding your personal data:
To exercise any of these rights, contact us at frederik@frederikvonderheyden.de.
You have the right to lodge a complaint with a supervisory authority pursuant to
Art. 77 GDPR. The competent authority for our business is:
Landesbeauftragte fuer Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW),
Kavalleriestr. 2-4, 40213 Duesseldorf, Germany.
Parts of this website's content, including text and visual elements, were created with the assistance of AI tools. In accordance with Art. 50(2) of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), we disclose that AI-generated or AI-assisted content is used where applicable. Our products (GuardRail, Compliance Shield, AgentStack) are AI governance and compliance tools — they assist with security and regulatory compliance but do not replace professional legal counsel.
We may update this Privacy Policy to reflect changes in our practices or applicable law. The current version is always available on this page.