Privacy Policy

Last updated: 24 July 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (“GDPR”) and other applicable data protection laws is:

Alessandro Tarshahani
ALETRA
Wattstraße 21
13355 Berlin
Germany
Phone: +49 162 9677312
Email: contact@aletra.co

2. Scope

This Privacy Policy applies to:

  • the website aletra.co;
  • the contact and newsletter forms offered through it;
  • appointment bookings and business enquiries;
  • the ALETRA Hub connected to the website;
  • the optional analysis of website usage;
  • the measurement and attribution of marketing campaigns.

Separate customer accounts, paid services or additional features of the ALETRA Hub may be subject to supplementary data protection information.

3. General principles and legal bases

We only process personal data where there is a legal basis for doing so.

Depending on the respective processing activity, the following legal bases apply in particular:

  • Art. 6(1)(a) GDPR, where you have given us your consent;
  • Art. 6(1)(b) GDPR, where processing is necessary for the performance of a contract or pre-contractual measures;
  • Art. 6(1)(c) GDPR, where processing is necessary to comply with a legal obligation;
  • Art. 6(1)(f) GDPR, where processing is necessary to protect our legitimate interests or those of a third party and your interests, fundamental rights or freedoms do not override them.

Where information is stored on your device or information already stored is accessed, admissibility is additionally governed by Section 25 of the German Telecommunications Digital Services Data Protection Act (“TDDDG”).

4. Provision and hosting of the website by Webflow

We use Webflow to build and provide our website.

The provider is:

Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, CA 94103
USA

When our website is accessed, Webflow may process technically necessary connection and log data. This may include in particular:

  • IP address;
  • date and time of access;
  • the page or file accessed;
  • referrer URL;
  • browser type and version;
  • operating system;
  • device and connection information;
  • volume of data transferred;
  • error messages;
  • security events.

This processing is necessary to deliver the website, ensure its functionality and security, detect technical errors and prevent misuse.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and economical operation of our website.

Webflow processes personal data as a processor in the context of providing the platform and may engage further sub-processors.

As Webflow is based in the USA and may use service providers outside the European Economic Area, personal data may be transferred to third countries.

According to its own information, Webflow is certified under the EU-US Data Privacy Framework. Where the certification or an adequacy decision does not apply, transfers may take place in particular on the basis of the European Commission’s Standard Contractual Clauses or other appropriate safeguards pursuant to Art. 44 et seq. GDPR.

Log data is only processed for as long as necessary for the provision, security, error analysis and defence against attacks. Otherwise, the retention periods set by Webflow apply.

5. ALETRA Hub and hosting by Vercel

The ALETRA Hub is a software application operated by ALETRA.

The ALETRA Hub is used in particular to:

  • manage contact and project enquiries;
  • process appointment bookings;
  • manage newsletter sign-ups and consents;
  • document cookie and tracking consents;
  • process pseudonymous website and campaign data;
  • attribute enquiries to specific marketing channels;
  • manage business contacts and communication.

The ALETRA Hub is technically provided via Vercel.

The provider is:

Vercel Inc.
440 N Barranca Avenue #4133
Covina, CA 91723
USA

When accessing the ALETRA Hub, the following data may be processed in particular:

  • IP address;
  • date and time;
  • pages, functions or interfaces accessed;
  • browser and device information;
  • technical performance data;
  • error and security information;
  • form, booking and contact data you enter voluntarily.

Processing takes place to provide, secure and technically administer the ALETRA Hub.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and economical operation of our digital infrastructure.

Where you send an enquiry, book an appointment or use another expressly requested function via the ALETRA Hub, processing additionally takes place on the basis of Art. 6(1)(b) GDPR.

Vercel processes data as a processor and may engage further sub-processors.

As Vercel is based in the USA and may use globally deployed cloud infrastructure, personal data may be processed outside the European Economic Area.

According to its own information, Vercel is certified under the EU-US Data Privacy Framework. Where the certification or an adequacy decision does not apply, transfers may take place in particular on the basis of the European Commission’s Standard Contractual Clauses or other appropriate safeguards.

6. Database and data storage by Supabase

We use Supabase to store and manage the data of the ALETRA Hub.

The contracting party for the cloud services is:

Supabase Pte. Ltd.
65 Chulia Street #38-02/03
OCBC Centre
Singapore 049513
Singapore

The following data in particular may be stored in Supabase:

  • contact and company data;
  • project and message content;
  • appointment and booking data;
  • newsletter sign-ups and unsubscribes;
  • consent and withdrawal records;
  • pseudonymous visitor, session and campaign data;
  • technical status and security information;
  • timestamps of the creation, modification and deletion of records.

Depending on the respective activity, processing takes place on the basis of:

  • Art. 6(1)(a) GDPR for consent-based functions;
  • Art. 6(1)(b) GDPR for enquiries, appointment bookings and pre-contractual measures;
  • Art. 6(1)(c) GDPR for legally required documentation;
  • Art. 6(1)(f) GDPR for technical administration, security and misuse prevention.

Supabase processes personal data as a processor and may engage further sub-processors.

The specific storage region depends on the infrastructure configured for the ALETRA Supabase project. In the course of providing the service, Supabase may process personal data in particular in the USA and in Singapore.

According to Supabase, third-country transfers are safeguarded in particular by the European Commission’s Standard Contractual Clauses or other appropriate safeguards pursuant to Art. 44 et seq. GDPR.

7. Server, error and security logs

When you access our website, the ALETRA Hub or our forms, technically necessary log data may be processed.

This may include:

  • IP address;
  • date and time;
  • the page or function accessed;
  • browser type and operating system;
  • device and connection information;
  • technical errors;
  • failed access attempts;
  • security events;
  • information about possible misuse.

This data is processed in order to:

  • provide the website and the ALETRA Hub;
  • detect technical errors;
  • defend against attacks and abusive use;
  • ensure the stability and security of our systems.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in IT security and the reliable operation of our systems.

Log data is only stored for as long as necessary for the respective technical or security-related purpose.

Longer storage only occurs where there is a specific security incident, a suspicion of misuse, a legal obligation, or the need to assert or defend against legal claims.

8. Cookies, local storage and comparable technologies

8.1 General information

Our website and the ALETRA Hub may use cookies as well as comparable technologies such as local storage or session storage.

Cookies and comparable technologies can store information on your browser or device or read information already stored.

We distinguish between:

  • technically necessary technologies;
  • optional analytics technologies;
  • optional marketing and attribution technologies.

Optional technologies are only activated after you have expressly consented via our consent banner.

The technologies used in each case, their purposes, categories and lifespans are additionally shown in the privacy settings of the consent banner.

8.2 Technically necessary technologies

Technically necessary technologies may be used in particular to:

  • store your privacy choices;
  • take account of consents given or refused;
  • provide forms and booking functions;
  • technically manage sessions;
  • enable security functions;
  • prevent misuse and automated attacks;
  • provide functions you have expressly requested.

Where storage or access is strictly necessary to provide a digital service you have expressly requested, this takes place on the basis of Section 25(2) no. 2 TDDDG.

The associated processing of personal data takes place, depending on the purpose, on the basis of Art. 6(1)(b), (c) or (f) GDPR.

8.3 Consent management

To manage your privacy choices we use a consent solution integrated into the ALETRA Hub.

The following information in particular may be processed:

  • selected consent categories;
  • date and time of the choice;
  • randomly generated consent ID;
  • version of the consent banner;
  • version of this Privacy Policy;
  • language;
  • time of any change or withdrawal;
  • technically necessary browser and device information.

This processing serves to technically implement your choice and to be able to demonstrate whether and to what extent consent was given, refused, changed or withdrawn.

The legal bases are Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR as well as, additionally, Art. 6(1)(f) GDPR.

Our legitimate interest lies in the reliable implementation of your privacy choices and in documenting compliance with legal requirements.

The consent choice stored in the browser is generally kept for up to twelve months. After this period, a renewed request may take place.

Records of consents given, changed or withdrawn may be stored for up to three years after the withdrawal or the end of the respective processing, where this is necessary to meet legal documentation obligations or to defend against legal claims.

9. Optional website analytics via the ALETRA Hub

If you consent to the “Analytics” category, we may process pseudonymous information about how our website is used.

This may include in particular:

  • randomly generated visitor ID;
  • randomly generated session ID;
  • pages accessed;
  • time and sequence of page views;
  • entry and exit pages;
  • approximate session duration;
  • clicks on key buttons;
  • views of specific services, offers or case studies;
  • form starts and form completions;
  • referrer domain;
  • campaign parameters such as UTM Source, UTM Medium and UTM Campaign;
  • browser, device and language category;
  • approximate country or region;
  • technical performance and error data.

A full IP address is not permanently stored as part of an analytics profile.

It may be processed temporarily on a technical level in order to establish a connection, carry out security checks or make an approximate geographic assignment.

The processing serves to:

  • understand how the website is used;
  • improve content and user guidance;
  • measure the effectiveness of our website;
  • detect technical problems;
  • attribute enquiries and bookings to specific marketing channels.

The storage of or access to information on your device takes place on the basis of your consent pursuant to Section 25(1) TDDDG.

The further processing of personal data takes place on the basis of your consent pursuant to Art. 6(1)(a) GDPR.

Pseudonymous analytics information is generally stored for a maximum of twelve months.

It is then deleted or aggregated in such a way that it can no longer be attributed to individual visitors.

10. Optional marketing and campaign attribution

If you consent to the “Marketing” category, we may store information about which channel, link or campaign brought you to ALETRA.

This may include in particular:

  • referrer;
  • original entry page;
  • UTM and campaign parameters;
  • service or offer pages visited;
  • clicks on contact or booking buttons;
  • completion of a contact enquiry;
  • completion of an appointment booking;
  • completion of a newsletter sign-up.

This information helps us assess the effectiveness of our B2B marketing measures and improve our communication.

If you subsequently voluntarily complete a contact, booking or newsletter form, the origin and campaign information belonging to that activity may be linked to your contact or enquiry record.

We do not attempt to automatically identify unknown visitors by name on the basis of their IP address, their device or external data sources.

We do not automatically link your complete previous website history to your name.

Any further combination of personal contact data with detailed usage profiles only takes place where this has been clearly described in advance and you have given corresponding consent.

The storage of or access to information on your device takes place on the basis of your consent pursuant to Section 25(1) TDDDG.

The further processing takes place on the basis of Art. 6(1)(a) GDPR.

Pseudonymous attribution data is generally stored for a maximum of 90 days.

If it is linked to a specific enquiry or booking, it may be kept together with the respective activity in accordance with the retention period applicable to it.

We currently do not use any external advertising or retargeting pixels from Google, Meta, LinkedIn or comparable advertising platforms.

If such services are used in future, this Privacy Policy will be updated before their activation and any required consent will be obtained.

11. Changing and withdrawing your cookie choice

You can withdraw or change your consent at any time with effect for the future.

For this purpose, the link “Privacy Settings” (or “Datenschutzeinstellungen”) is available in the footer of our website.

The withdrawal does not affect the lawfulness of the processing carried out on the basis of your consent before the withdrawal.

Refusing optional analytics or marketing technologies does not prevent general access to our website.

However, certain non-essential functions may be restricted.

12. Contact form and project enquiries

You can contact us via the forms provided on our website or in the ALETRA Hub.

Depending on the form, the following details in particular may be processed:

  • name;
  • email address;
  • phone number;
  • company;
  • professional role;
  • subject;
  • type of project;
  • budget range;
  • message and project description;
  • files submitted voluntarily;
  • date and time of the enquiry;
  • origin and campaign information, where you have consented to this beforehand.

Mandatory fields are marked accordingly. All other details are provided voluntarily.

Processing takes place to handle your enquiry, to communicate with you and to prepare for a possible business collaboration.

Where your enquiry relates to the initiation or performance of a contract, the legal basis is Art. 6(1)(b) GDPR.

For general business enquiries, processing takes place on the basis of Art. 6(1)(f) GDPR.

Our legitimate interest lies in responding to business enquiries and maintaining business contacts.

Submitting a contact form does not automatically result in a newsletter sign-up.

Enquiries that do not lead to a contractual relationship are generally deleted no later than six months after the enquiry has been finally dealt with, unless further retention is necessary to document the communication, to assert or defend against legal claims, or due to legal obligations.

If a contractual relationship arises, the data is stored in accordance with the statutory and contractual retention periods.

13. Appointment bookings and discovery calls

When you book an appointment via the ALETRA Hub, the following data in particular may be processed:

  • name;
  • email address;
  • phone number, if provided;
  • company;
  • occasion or topic of the call;
  • selected appointment;
  • time zone;
  • voluntary details about the project;
  • technical booking and confirmation data;
  • origin and campaign information, where you have consented to this beforehand.

Processing takes place to select and manage the appointment, to communicate with you and to prepare for the call.

The legal basis is Art. 6(1)(b) GDPR insofar as the appointment booking serves to initiate a business collaboration.

For other appointment bookings, the legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest lies in the efficient organisation of business calls.

Booking data is deleted as soon as it is no longer required for appointment management, further communication or a possible collaboration, and no statutory retention obligations prevent this.

14. Communication by email and phone

When you contact us by email or phone, we process the details you provide.

This may include in particular:

  • name;
  • contact details;
  • company and role;
  • content of the communication;
  • date and time;
  • files and documents submitted.

Processing takes place to handle your request and to communicate with you.

The legal basis is Art. 6(1)(b) GDPR where the communication serves to initiate or perform a contract.

For other business communication, the legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest lies in handling and documenting business communication.

15. Newsletter and marketing emails

15.1 Sign-up

You can voluntarily sign up for the ALETRA newsletter.

The newsletter may contain in particular:

  • information on branding, marketing, websites and AI systems;
  • expert content and practical recommendations;
  • information about ALETRA’s services and offers;
  • invitations to events, workshops and calls;
  • case studies;
  • news and updates from ALETRA.

A valid email address is required to sign up.

Further details such as first name, company, role, language or interests are provided voluntarily, unless expressly marked as a mandatory field.

The legal basis for sending is your consent pursuant to Art. 6(1)(a) GDPR.

Newsletter consent is voluntary and is not a precondition for a contact enquiry, appointment booking or engagement.

Consent to analytics or marketing cookies is not newsletter consent.

15.2 Double opt-in procedure

We use a double opt-in procedure.

After signing up you receive a confirmation message.

Your email address is only activated for newsletter dispatch once you have clicked the confirmation link it contains.

Until confirmation, the sign-up is only stored as pending. No regular newsletters are sent to unconfirmed addresses.

To evidence consent, the following information in particular may be stored:

  • email address;
  • time of sign-up;
  • time of confirmation;
  • sign-up form used;
  • version and wording of the consent declaration;
  • version of this Privacy Policy;
  • language;
  • technically necessary log information;
  • time and type of any later withdrawal.

The legal basis for this documentation is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR as well as, additionally, Art. 6(1)(f) GDPR.

Our legitimate interest lies in evidencing a proper newsletter sign-up and in defending against unjustified complaints or claims.

15.3 Processing in the ALETRA Hub

Newsletter sign-ups, consent records, unsubscribes and recipient lists are managed via the ALETRA Hub.

The ALETRA Hub is operated via Vercel. Recipient and consent data is stored in Supabase.

Technical dispatch is triggered by the ALETRA Hub and carried out via the email infrastructure set up for ALETRA.

The following data in particular may be processed:

  • email address;
  • name provided voluntarily;
  • company and professional role;
  • language and interests;
  • sign-up and confirmation time;
  • consent version;
  • sign-up source;
  • unsubscribe status;
  • technical delivery and error information.

We currently do not use any external newsletter management platform such as Newsletter2Go, Mailchimp or Brevo.

The data is not sold or made available to third parties for their own advertising purposes.

15.4 Newsletter measurement

We currently do not use invisible tracking pixels to individually determine whether a specific recipient has opened a newsletter.

Technically necessary delivery information may be processed, in particular:

  • successful delivery;
  • non-deliverability;
  • invalid email addresses;
  • spam complaints;
  • unsubscribes.

This processing serves to technically carry out the dispatch, remove faulty recipients and prevent further unwanted messages.

Should we use individual open or click measurement in future, we will update this Privacy Policy beforehand and, where necessary, obtain separate consent.

15.5 Unsubscribe and withdrawal

You can withdraw your newsletter consent at any time with effect for the future.

To do so, you can:

  • use the unsubscribe link in the respective email; or
  • send an email to contact@aletra.co.

After unsubscribing, your email address is removed from the active distribution list.

Where necessary, the email address may be stored on a suppression list so that no further newsletters are sent to that address.

The legal basis for this is Art. 6(1)(f) GDPR.

Our legitimate interest lies in reliably implementing your unsubscribe and avoiding further unwanted messages.

Records of a previous newsletter consent and its withdrawal may be stored for up to three years, where this is necessary to meet legal documentation obligations or to defend against legal claims.

16. Individual B2B communication

A newsletter sign-up is to be distinguished from individual business communication.

If you:

  • contact ALETRA;
  • book an appointment;
  • request a proposal;
  • conclude a contract;
  • or provide us with your data in the context of a business contact,

we may send you messages that relate directly to your enquiry, the appointment, the proposal or the existing business relationship.

Such communication does not automatically result in a general newsletter sign-up.

General marketing newsletters are only sent where express consent exists or a statutory exception applies in the specific individual case.

17. Recipients and processors

Within ALETRA, only those persons have access to personal data who need it to handle enquiries, carry out projects, manage the newsletter, do accounting or perform technical administration.

In addition, personal data may be transferred in particular to the following recipients or categories of recipients:

  • Webflow as website and hosting provider;
  • Vercel as hosting and infrastructure provider of the ALETRA Hub;
  • Supabase as database and backend provider;
  • email and communication service providers;
  • IT support and software developers;
  • tax advisors and accounting;
  • legal advisors;
  • authorities or courts, where there is a legal obligation.

Where service providers process personal data on our behalf, this takes place on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Personal data is not sold or made available to other companies for their own independent advertising purposes.

18. Third-country transfers

Webflow and Vercel are based in the USA. Supabase has its contractual seat in Singapore.

In addition, these providers or their sub-processors may use infrastructure in further countries.

A transfer of personal data to a country outside the European Union or the European Economic Area only takes place where the requirements of Art. 44 et seq. GDPR are met.

The following may serve as a basis in particular:

  • an adequacy decision of the European Commission;
  • the EU-US Data Privacy Framework, where the respective provider is validly certified;
  • the European Commission’s Standard Contractual Clauses;
  • additional technical and organisational measures;
  • another legally recognised safeguard.

19. Retention period

We only store personal data for as long as necessary for the respective purpose.

The following principles in particular apply:

  • consent choice in the browser: generally up to twelve months;
  • pseudonymous analytics data: generally up to twelve months;
  • pseudonymous campaign and attribution data: generally up to 90 days;
  • enquiries that do not lead to an engagement: generally up to six months after the enquiry has been dealt with;
  • active newsletter data: until withdrawal or unsubscribe;
  • records of newsletter and tracking consents: generally up to three years after withdrawal or the end of processing;
  • contract, invoice and accounting data: in accordance with the statutory retention periods;
  • security and error logs: only for as long as necessary for security, error analysis or misuse prevention.

Longer storage may take place where:

  • statutory retention obligations exist;
  • the data is needed to perform a contract;
  • the data is necessary to assert, exercise or defend legal claims;
  • a security or misuse incident is being investigated;
  • a consent or its withdrawal must be evidenced.

After the respective periods expire, the data is deleted, anonymised or blocked for other uses.

20. Profiling and automated decisions

We do not make any decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

If you consent to the analytics or marketing category, pseudonymous usage and campaign profiles may be created.

These profiles serve exclusively:

  • website analysis;
  • campaign measurement;
  • the improvement of our content;
  • the attribution of enquiries to marketing channels.

They are not used to automatically decide on contracts, individual pricing, creditworthiness, employment, insurance or other legally or economically significant matters.

21. Data security

We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and unlawful disclosure.

Depending on the processing activity, these may include in particular:

  • encrypted data transmission;
  • HTTPS;
  • access restrictions;
  • role-based permissions;
  • secure passwords;
  • multi-factor authentication;
  • logging of security-relevant activities;
  • regular updating of the systems used;
  • data backups;
  • contracts with processors.

Complete security in electronic data transmission cannot, however, be guaranteed.

22. Your data protection rights

Subject to the statutory requirements, you have in particular the following rights:

  • right of access pursuant to Art. 15 GDPR;
  • right to rectification pursuant to Art. 16 GDPR;
  • right to erasure pursuant to Art. 17 GDPR;
  • right to restriction of processing pursuant to Art. 18 GDPR;
  • right to data portability pursuant to Art. 20 GDPR;
  • right to object pursuant to Art. 21 GDPR;
  • right to withdraw consent pursuant to Art. 7(3) GDPR;
  • right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.

To exercise your rights, you can contact us at: contact@aletra.co

Where there are justified doubts about your identity, we may request additional information necessary to confirm your identity.

23. Requests to delete personal data

You can request the deletion of the personal data stored about you at ALETRA at any time. Please send your request by email to contact@aletra.co.

We review your request and delete your personal data provided the statutory requirements for this are met.

Complete deletion may not be possible, or only at a later point in time, in particular where:

  • statutory retention obligations exist;
  • the data is still needed to perform a contract or to handle an ongoing enquiry;
  • the data is necessary to assert, exercise or defend legal claims;
  • the data is needed to investigate a security or misuse incident;
  • further storage is necessary to comply with a legal obligation;
  • consent or withdrawal records must be kept for a legally permissible period.

Where immediate deletion is not legally possible, the data concerned is blocked for other processing purposes and deleted after the respective retention period expires.

We will inform you about the handling of your request without undue delay and generally within one month.

If the request is particularly complex or there is a large number of requests, the processing period may be extended to the extent legally permitted. In this case we will inform you in good time about the extension and the reasons for it.

24. Objection to direct marketing

You have the right to object at any time to the processing of your personal data for the purpose of direct marketing.

Following such an objection, your personal data will no longer be processed for direct marketing.

The objection can be declared in particular by email to contact@aletra.co.

25. Withdrawal of consent

Any consent given can be withdrawn at any time with effect for the future.

For cookie, analytics and tracking consents, please use the “Privacy Settings” (or “Datenschutzeinstellungen”) link in the footer of the website.

For the newsletter, use the unsubscribe link in the respective message or write to contact@aletra.co.

The withdrawal does not affect the lawfulness of the processing carried out on the basis of your consent before the withdrawal.

26. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection law.

The supervisory authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de

You may also contact another data protection supervisory authority responsible for you.

27. Obligation to provide personal data

You are generally not obliged to provide us with personal data.

However, certain details are required if you:

  • send a contact enquiry;
  • book an appointment;
  • receive a proposal;
  • conclude a contract;
  • sign up for the newsletter.

Without the details marked as required, we may not be able to handle the respective enquiry or function.

28. External links

Our website may contain links to websites, platforms or social networks of third parties.

When you open such a link, you leave our area of responsibility.

The respective operator is generally responsible for the processing of personal data on the external website.

29. Changes to this Privacy Policy

We may update this Privacy Policy where:

  • our website or the ALETRA Hub change;
  • new functions are introduced;
  • further service providers are used;
  • new tracking or marketing technologies are used;
  • legal or regulatory requirements change;
  • data flows or retention periods are adjusted.

The version published on this website at the relevant time applies.

Last updated: 24 July 2026

Scroll