Privacy Policy

1. Responsible person

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:

Capstone Digital Advisory UG (limited liability company)
Managing Director: Tuncay Ozer
Linienstraße 218
10119 Berlin
Germany

Telephone: +49 30 61640494
E-mail: info@capstone-advisory.eu


2. General information on data processing

The protection of your personal data is important to us.

We process personal data only to the extent necessary for providing our website, processing contact and project requests, initiating or carrying out a business relationship, or due to legal obligations.

Personal data is any information relating to an identified or identifiable natural person.

The processing is carried out in particular on the basis of the General Data Protection Regulation (GDPR) and the respective relevant German data protection regulations.


3. Hosting

Our website is hosted by the following provider:

STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany

As part of the hosting process, technical data may be processed, in particular data that is necessary for the provision, security and stability of the website.

This can include:

  • IP address,
  • Date and time of access,
  • accessed page or file,
  • amount of data transferred,
  • Referrer URL,
  • browser used
  • Browserversion,
  • operating system used,
  • Hostname of the accessing device.

STRATO itself states that it also acts as a data processor in the context of providing its hosting services.

The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the technically secure, stable, and reliable provision of our website.

Insofar as the use of the website serves the purpose of initiating or executing a contractual relationship, the processing may additionally be based on Art. 6 para. 1 lit. b GDPR.


4. Server log files

When you visit our website, the hosting provider can automatically collect information in so-called server log files.

This data is used in particular to...

  • to provide the website technically,
  • to ensure system security,
  • to detect technical errors
  • to identify abusive access,
  • to ensure the stability of the system.

We generally do not combine this data with other personal data unless there is a specific reason to do so.

The legal basis for this processing is Article 6(1)(f) GDPR.


5. SSL or TLS encryption

This website uses SSL or TLS encryption for security reasons and to protect confidential content.

You can recognize an encrypted connection, among other things, by the fact that the address bar of your browser begins with "https://".

Encryption prevents unauthorized third parties from easily reading the data you send us.


6. Contact via email or telephone

When you contact us by email or telephone, we process the personal data you provide in order to handle your request.

This may include, in particular:

  • Name,
  • company or organization,
  • Function or position,
  • Telephone number,
  • Email address,
  • Content of your message,
  • Information about a project or undertaking,
  • other information you voluntarily provide.

Insofar as your contact is aimed at initiating or carrying out a business relationship, the processing is based on Art. 6 para. 1 lit. b GDPR.

For other inquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the proper processing and response to your inquiry.


7. Non-binding inquiry and project inquiry

On our website we offer a form for non-binding consultation and project inquiries.

This form is used to professionally assess your request before an initial personal meeting and to better prepare for potential cooperation.

Depending on your input, the following data in particular may be processed:

  • The nature of your consulting or project request,
  • current situation or project phase,
  • Description of your project,
  • desired result,
  • thematic focus areas,
  • desired timeframe,
  • Urgency,
  • desired scope of consulting or project work,
  • If applicable, a voluntarily specified budget range,
  • For EU projects, information on the funding program may be required.
  • Call bzw. Topic,
  • Project phase,
  • Consortium or partner status,
  • desired role in the project
  • Name,
  • Company or organization,
  • Function or position,
  • Email address,
  • Telephone number,
  • Website,
  • preferred contact method.

The information will be used for:

  • professional assessment of your request,
  • Processing and responding,
  • Preparing for a possible initial consultation,
  • Initiating a potential business relationship

processed.

Insofar as your request is aimed at concluding a contract or carrying out pre-contractual measures, the processing is based on Art. 6 para. 1 lit. b GDPR.

For other inquiries, processing is based on Article 6 Paragraph 1 Letter f GDPR.


8. Using Fluent Forms Pro

We use [cookies/cookies] for the provision and processing of our contact and project request forms. Fluent Forms Pro as a WordPress form system.

The information submitted via the form is stored in the WordPress database of our website and can be managed as form entries in the protected administration area.

Fluent Forms uses its own database structures within the WordPress installation and stores form submissions as so-called Submissions or Entries.

The storage serves in particular to

  • To process requests transparently,
  • To enable communication and follow-up questions
  • to document the processing status,
  • to organize contact with interested parties and potential clients.

The form entries are only accessible to appropriately authorized administrators or users of the website.

The data will be deleted as soon as it is no longer required for processing the respective request and there are no legal retention obligations or other legitimate reasons for further storage.

If a business relationship is established based on the inquiry, the necessary data may be stored further within the framework of the statutory commercial and tax law retention obligations.


9. Email communication and mail servers

We use the email infrastructure of our hosting provider to process contact and project inquiries.

When sending or receiving an email, the following personal data may be processed in particular:

  • Name,
  • Email address,
  • Sender and recipient information,
  • Time of communication,
  • Reference,
  • Message content,
  • Attachments (if applicable)
  • Project-related information.

Insofar as the communication takes place in connection with the initiation of a contract or an existing contractual relationship, the legal basis is Art. 6 para. 1 lit. b GDPR.

Furthermore, processing is based on Article 6(1)(f) GDPR.


10. Cookies and similar technologies

Our website uses cookies and similar technologies.

Cookies are small files or pieces of information that can be stored on or read from your device.

Some cookies are technically necessary for the website to function properly.

Other services or technologies will only be used if you have given your prior consent.

For technically unnecessary access to information on your terminal device, Section 25 Paragraph 1 of the German Telemedia Act (TDDDG) may be particularly relevant.

For services requiring consent, the processing of personal data is additionally based on Article 6 Paragraph 1 Letter a GDPR.

You can withdraw your consent at any time with effect for the future.


11. Borlabs Cookie

We use on our website Borlabs Cookieto obtain and manage consent for cookies and external services.

Borlabs Cookie stores information about your consent decision.

According to Borlabs, this includes information about:

  • granted consents,
  • Cookie-Version,
  • Cookie lifespan
  • Domain and path
  • a randomly generated identifier

saved.

The data is stored to take your decision into account on subsequent page visits and to be able to prove legally required consents.

The processing is based on Art. 6 para. 1 lit. c GDPR or Art. 6 para. 1 lit. f GDPR in conjunction with the requirements of the TDDDG.

You can change your cookie and consent settings at any time via the relevant cookie settings on our website.


12. Google Fonts

Our website currently uses fonts via the service Google Fonts loaded.

The provider for users in the European Economic Area is:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

When you access a page, your browser may connect to Google's servers to load the necessary fonts.

In this process, technical data, in particular your IP address and information about the browser or device used, may be transmitted to Google.

Google points out that Google Fonts is delivered via appropriate server infrastructure and that the necessary technical requests are processed for this purpose.

Insofar as Google Fonts are loaded based on your consent, the processing is based on:

Article 6 paragraph 1 letter a GDPR
as well as
Section 25 Paragraph 1 TDDDG.

You can withdraw your consent at any time via the cookie settings.

Google services may involve the processing of personal data outside the European Union or the European Economic Area.

Google states that Google LLC participates in and is certified under the EU-US Data Privacy Framework.

Further information on data processing by Google can be found in Google's privacy policy.

A notice: Once Google Fonts are fully integrated locally on our own web server, no further connection to Google servers will be established via the fonts. This section will then be adjusted accordingly.


13. Google reCAPTCHA

To protect our forms from spam, automated entries and abusive access, we use Google reCAPTCHA.

The provider for users in the European Economic Area is:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

reCAPTCHA is used to determine whether an entry is likely to be made by a natural person or by an automated system.

Google describes reCAPTCHA as a service to protect websites from spam and abuse.

The audit may process technical information, such as:

  • IP address,
  • Browser information,
  • Device information,
  • Information about the use of the website,
  • Security and interaction data.

If reCAPTCHA is activated based on your consent, processing is based on:

Article 6 paragraph 1 letter a GDPR
as well as
Section 25 Paragraph 1 TDDDG.

Consent can be withdrawn at any time via the cookie settings.

Google services may involve the processing of data outside the European Economic Area.

Google LLC states that it is certified under the EU-US Data Privacy Framework.

For more information, please see Google's privacy policy.


14. External links and LinkedIn

Our website may contain links to external websites and services, for example to LinkedIn.

These links are simply normal external links.

As long as you do not click on such a link, the mere linking, according to our configuration, does not establish a direct connection between your browser and LinkedIn.

If you click on an external link, you will leave our website.

The respective provider of the external website is generally responsible for the subsequent data processing.

We currently do not use a LinkedIn Insight Tag or an embedded LinkedIn feed on our website.


15. Google Search Console

We use the Google Search Console, in order to monitor the discoverability and technical indexing of our website in Google search.

The Google Search Console is particularly useful for us for:

  • to identify technical indexing problems,
  • to check how our website is displayed in Google search,
  • To statistically evaluate search queries and search performance.

Our website does not use a visitor tracking script comparable to Google Analytics.

Therefore, with our current configuration, using Search Console does not result in any additional tracking technology integrated by us on the end devices of website visitors.


16. Recipients of personal data

We only share personal data to the extent necessary to fulfill the respective purposes or as permitted by law.

Possible recipients or categories of recipients include, in particular:

  • responsible employees or authorized persons of Capstone Digital Advisory,
  • Hosting and IT service providers,
  • Email service providers,
  • technical security service providers,
  • Google, insofar as Google services are used with your consent,
  • Authorities or public bodies, provided there is a legal obligation.

Personal data will not be passed on to third-party advertising purposes.


17. Data transfer to third countries

When using certain external services, personal data may be transferred to countries outside the European Union or the European Economic Area.

Such a transfer will only take place if the legal requirements of Art. 44 et seq. GDPR are met.

This can be based in particular on:

  • an adequacy decision by the European Commission,
  • EU-US Data Privacy Framework,
  • suitable standard contractual clauses,
  • or with explicit consent

take place.

Google states that Google LLC participates in the EU-US Data Privacy Framework.


18. Storage duration

We only store personal data for as long as is necessary for the respective processing purpose.

If the purpose of the processing ceases to exist, the data will be deleted unless there are legal retention obligations or other legitimate reasons for further storage.

For contact and project inquiries, data is generally stored until the inquiry has been fully processed.

STRATO also describes a basic storage policy for its own contact forms until they are fully processed, unless there are further legal retention obligations.

If a business relationship is established, data may be stored for a longer period in accordance with legal commercial and tax law retention requirements.


19. Legal basis for processing

Depending on the type of processing, we base the processing of personal data in particular on the following legal bases:

Article 6 paragraph 1 letter a GDPR – Consent

If you have given us your consent for a specific data processing activity.

Article 6 paragraph 1 letter b GDPR – Contract and pre-contractual measures

If the processing is necessary for the performance of a contract or for taking steps prior to entering into a contract.

Article 6(1)(c) GDPR – Legal obligation

If we are legally obligated to process personal data.

Article 6(1)(f) GDPR – Legitimate interest

If the processing is necessary to protect our legitimate interests or the interests of third parties and there are no overriding interests, fundamental rights or freedoms of the data subject that conflict with this.


20. Revocation of consent

You can revoke your consent at any time with effect for the future.

The lawfulness of the processing carried out until the revocation remains unaffected.

Consent to cookies or external services can be changed or withdrawn, in particular via the cookie settings of our website.


21. Your rights

Subject to the legal requirements, you have in particular the following rights:

  • Right to information pursuant to Article 15 GDPR,
  • Right to rectification pursuant to Article 16 GDPR,
  • Right to erasure pursuant to Article 17 GDPR,
  • Right to restriction of processing pursuant to Article 18 GDPR,
  • Right to data portability pursuant to Article 20 GDPR,
  • Right to object pursuant to Article 21 GDPR,
  • Right to withdraw consent pursuant to Article 7(3) GDPR.

If the processing is based on Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.

You can contact us at any time to exercise your rights:

info@capstone-advisory.eu


22. Right to lodge a complaint with a data protection supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.

The following supervisory authority is particularly responsible for our company based in Berlin:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moab 59–61
10555 Berlin
Germany

Telephone: +49 30 13889-0
E-mail: mailbox@datenschutz-berlin.de

The Berlin data protection authority confirms these current contact details on its official website.


23. Automated decision-making and profiling

We do not use exclusively automated decision-making, including profiling as defined in Article 22 GDPR.

In particular, the information provided in our inquiry form does not automatically determine whether a collaboration will take place.

Project and consulting requests are reviewed personally.


24. Data security

We take appropriate technical and organizational measures to protect personal data from:

  • Loss,
  • unauthorized access,
  • Change,
  • Disclosure
  • abuse

to protect.

Our security measures are adapted in accordance with technological developments and the requirements of our systems.


25. Update of this privacy policy

We reserve the right to amend this privacy policy if:

  • legal requirements,
  • our website,
  • services used
  • technical functions,
  • or our data processing processes

change.

The version published on this website is the applicable one.

Stand: August 2026