Data Privacy Policy
Data Privacy Policy
1) Introduction and contact details of the controller
1.1 We are glad you are visiting our website and thank you for your interest. This Privacy Policy explains how we process personal data when you use our website. Personal data means any information relating to an identified or identifiable natural person.
1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Joachim Kynast
Kynast AI & IT Advisory
Blumenweg 2c
65520 Bad Camberg
Germany
E-mail: contact@kynast-advisory.com
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
2. Data processed when you visit our website
2.1 When you use our website purely for information purposes, that is, without submitting a form or otherwise providing information to us, technical access data is processed in connection with the delivery of the website. Depending on the request, this may include:
The requested website, page, or file
Date and time of access
Source or referrer from which you arrived at the page
Browser type and browser version
Operating system used
Device type used
IP address, which is anonymised immediately after transmission where processed by IONOS
This processing takes place under Art. 6(1)(f) GDPR on the basis of our legitimate interest in the secure, stable, and technically reliable operation of the website. The data is not used for unrelated purposes or disclosed to unauthorised third parties. It is processed by our hosting provider on our behalf as described in Section 3.
We reserve the right to review available technical records retrospectively where there are concrete indications of unlawful use or a security incident.
2.2 For security reasons and to protect the transmission of personal data and other confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the string “https://” and the padlock icon in your browser bar.
3. Hosting and website analytics
3.1 Hosting by IONOS
We use IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany, to host and technically deliver this website. The data generated in connection with the hosting and technical delivery of the website is processed by IONOS on our behalf.
We have concluded a data processing agreement with IONOS in accordance with Art. 28 GDPR. This agreement requires IONOS to protect the data of website visitors and to process it only in accordance with our instructions and the applicable legal requirements.
3.2 IONOS WebAnalytics
IONOS WebAnalytics is used as part of the website service to provide aggregated statistical information about website use and to support technical optimisation. The data is collected through log files or a tracking pixel. IONOS WebAnalytics does not use cookies.
When a page is accessed, the IP address is transmitted for technical reasons and is anonymised immediately after transmission. The resulting information is processed without a direct personal reference. Depending on the service configuration, the statistical data may include the requested page or file, referrer, browser type and version, operating system, device type, time of access, and approximate location derived from the anonymised IP address.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in understanding the general use of the website, maintaining its technical quality, and improving its content and performance.
We do not use IONOS WebAnalytics to create identifiable user profiles, track visitors across different websites, or deliver personalised advertising.
4. Cookies and comparable technologies
This website does not currently use cookies for analytics, advertising, or profiling. IONOS WebAnalytics operates without cookies.
The Executive Quick Scan uses browser storage to preserve your progress and may, only where other storage mechanisms are unavailable, use a strictly necessary cookie with a maximum lifetime of two hours.
The appointment-booking service may also use strictly necessary short-lived storage to protect the booking process. These mechanisms are not used by us for cross-site tracking or personalised advertising.
Where storage in or access to your device is strictly necessary to provide a digital service expressly requested by you, it is used without consent in accordance with Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG).
If we introduce cookies or comparable technologies that require consent in the future, this Privacy Policy will be updated and an appropriate consent mechanism will be implemented before those technologies are activated.
5. Executive Quick Scan
5.1 Local processing and temporary storage
The Executive Quick Scan is designed as an organisational self-assessment. It does not ask for your name, e-mail address, or other directly identifying information.
Your selected answers, the current question, completion status, and a timestamp are processed locally in your browser to calculate the result and preserve your progress if the website section is reloaded.
Depending on browser support, the scan uses local storage or session storage. If those mechanisms are unavailable, it may use a strictly necessary cookie with a maximum lifetime of two hours or comparable browser storage.
These mechanisms are used solely to provide the scan functionality requested by you and not for analytics, advertising, or cross-site tracking.
Stored progress is no longer restored after two hours. It is cleared when you choose “Start again” and may also be deleted when an expired state is detected or when you clear your browser data.
5.2 Print, download, and e-mail functions
The print function and the download of a text result are performed locally in your browser.
The e-mail function opens your local e-mail application and prepares a message containing the result and the answer levels. No result or answer is automatically transmitted to us.
Data is transmitted only if you actively send the prepared e-mail. If you do so, the information is processed as a contact enquiry in accordance with Section 6.2.
5.3 Automated result calculation
The scan automatically calculates a non-binding orientation signal based solely on the answers you select.
It does not evaluate a natural person, create a personal profile, or produce legal effects or similarly significant effects.
The result calculation therefore does not constitute automated decision-making within the meaning of Art. 22 GDPR.
6. Contacting us
6.1 Meetergo appointment booking
To provide an online appointment-booking function, we use meetergo GmbH, Hauptstr. 44, 40789 Monheim am Rhein, Germany.
When you open a meetergo booking page, meetergo processes limited technical request data, such as the request IP address, timestamp, user-agent, and requested URL, to deliver and secure the booking service.
Meetergo states that these technical access logs are retained for up to 14 days. This processing is based on Art. 6(1)(f) GDPR, reflecting the legitimate interest in the secure and reliable operation of the booking service.
When you book an appointment, the information requested in the booking form is processed. This normally includes your first name, surname, e-mail address, the selected appointment time, and any information you enter in free-text fields. Where a telephone appointment is requested, your telephone number may also be processed.
The processing is based on Art. 6(1)(b) GDPR where the appointment relates to contractual or pre-contractual measures requested by you.
In other cases, it is based on Art. 6(1)(f) GDPR, reflecting our legitimate interest in responding to enquiries and organising appointments efficiently.
Meetergo processes booking data on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
To coordinate appointments, booking details may be synchronised with our IONOS calendar and transmitted to us by e-mail. These systems are used only for appointment administration and related communication.
Fields marked as mandatory are required to arrange the appointment. Without this information, we may be unable to complete the booking.
Booking and contact data is retained only for as long as necessary for appointment administration, follow-up communication, contractual purposes, or the assertion, exercise, or defence of legal claims, and is then deleted unless statutory retention obligations apply.
Meetergo may use subprocessors to provide the service. Where processing or support access involves a transfer outside the European Economic Area, meetergo states that the transfer is protected by an applicable adequacy decision, including the EU-US Data Privacy Framework where relevant, or by the European Commission’s Standard Contractual Clauses.
6.2 Contact and download forms
When you contact us, for example by e-mail or by using a form on this website to request the Position Paper, Corporate Presentation, Partner Presentation, or other material, personal data is collected.
The data requested in each case is apparent from the relevant form. It may include your name, business e-mail address, organisation, role, and the content of your request.
The data is used to respond to your enquiry or request, provide the requested material, and perform the related technical and administrative tasks.
The legal basis is Art. 6(1)(f) GDPR, reflecting our legitimate interest in responding to professional enquiries and providing requested information.
Where the contact is aimed at concluding or performing a contract, Art. 6(1)(b) GDPR also applies.
Fields marked as mandatory are required to process the request. Without this information, we may be unable to respond or provide the requested material.
The data is deleted once the request has been conclusively dealt with, unless contractual, statutory, or evidentiary retention requirements justify continued storage.
6.3 AI-assisted drafting and quality assurance
We may use artificial intelligence services to support the drafting, structuring, summarisation, translation, and quality review of responses to enquiries and requests submitted to us.
The services currently used for these purposes are ChatGPT Plus, provided by OpenAI Ireland Limited, and Claude Pro, provided by Anthropic Ireland, Limited.
Under the consumer-service privacy terms applicable to these services, the respective providers process personal data as independent controllers and not as processors acting exclusively on our instructions.
These services do not communicate with you directly and do not independently respond to enquiries. Any AI-assisted output is reviewed by us, amended where appropriate, and approved under our responsibility before it is used in external communication.
We apply data minimisation before using these services. Direct identifiers such as names, e-mail addresses, telephone numbers, signatures, and other information that is not required for the drafting or quality-review task are removed or replaced wherever reasonably possible.
We do not intentionally submit special categories of personal data, confidential documents, access credentials, payment information, or other highly sensitive information to these services.
Where limited personal data from an enquiry is processed through these services, the processing and disclosure are based on Art. 6(1)(f) GDPR and our legitimate interest in preparing accurate, consistent, and efficient responses and carrying out appropriate quality assurance.
You have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data for AI-assisted drafting and quality assurance under Art. 21(1) GDPR.
You may submit your objection by e-mail to contact@kynast-advisory.com. Further information on your right to object is provided in Section 7.2.
Model improvement has been disabled in the privacy settings of both services. Under the current settings, ordinary business-related conversations are not used by the providers for general model training or improvement.
Where appropriate, we additionally use temporary or incognito conversation modes.
This does not exclude limited processing by the providers for service operation, security, misuse and policy-violation detection, compliance with legal obligations, or dispute resolution.
Conversations may also be processed differently if feedback is actively submitted through a provider’s feedback function. We therefore do not intentionally submit product feedback relating to conversations containing information from enquiries.
The providers may process and retain submitted information in accordance with their respective privacy information.
Conversations deleted from the relevant user account may remain in the providers’ systems temporarily or for longer where this is necessary for security, legal compliance, dispute resolution, or enforcement of applicable usage policies.
The providers may process personal data outside the European Economic Area, including in the United States.
According to their respective privacy information, international transfers are based, where applicable, on an adequacy decision of the European Commission or on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
We delete conversations containing information from an enquiry when they are no longer required for the drafting or quality-review purpose, subject to technical retention periods and justified exceptions applied by the respective provider.
No decision producing legal effects or similarly significant effects is made about you through these services.
The services are not used for automated customer communication, profiling, scoring, or automated decision-making within the meaning of Art. 22 GDPR.
7. Rights of the data subject
7.1 General data-subject rights
Applicable data protection law, in particular the GDPR, grants you the following rights in relation to the processing of your personal data. The respective statutory conditions apply:
Right of access under Art. 15 GDPR
Right to rectification under Art. 16 GDPR
Right to erasure under Art. 17 GDPR
Right to restriction of processing under Art. 18 GDPR
Right to notification under Art. 19 GDPR
Right to data portability under Art. 20 GDPR
Right to withdraw consent under Art. 7(3) GDPR, where processing is based on consent
Right to lodge a complaint under Art. 77 GDPR
7.2 Right to object
Where we process your personal data on the basis of Art. 6(1)(f) GDPR, you have the right, at any time and for reasons arising from your particular situation, to object to this processing with future effect.
You may submit your objection by e-mail to contact@kynast-advisory.com.
If you exercise your right to object, we will cease processing the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defence of legal claims.
7.3 Supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority.
As our registered address is in Hesse, the competent supervisory authority is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
Wilhelmstraße 7
65185 Wiesbaden
Germany
Duration of storage of personal data
The duration for which personal data is stored is determined by the applicable legal basis, the purpose of processing, and, where relevant, statutory retention periods, including retention requirements under German commercial and tax law.
Where personal data is processed on the basis of consent under Art. 6(1)(a) GDPR, it is stored until the consent is withdrawn, unless another legal basis or statutory retention obligation permits or requires continued storage.
Where personal data is processed in connection with contractual or pre-contractual obligations under Art. 6(1)(b) GDPR, it is retained for as long as necessary for those purposes and is then deleted once applicable statutory retention periods have expired and no other legitimate basis for continued storage applies.
Where personal data is processed on the basis of Art. 6(1)(f) GDPR, it is retained only for as long as necessary for the relevant legitimate purpose.
If you lodge a valid objection under Art. 21(1) GDPR, the processing will cease unless compelling legitimate grounds or the assertion, exercise, or defence of legal claims justify continued processing.
Unless a specific retention period is stated elsewhere in this Privacy Policy, personal data is deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed and no legal obligation or overriding legitimate interest requires further retention.
Kynast AI & IT Advisory · Joachim Kynast · Blumenweg 2c · 65520 Bad Camberg · Germany · contact@kynast-advisory.com · www.kynast-advisory.com
Version 4 – 31 July 2026