What we collect.
btaq.io is a static site. It sets no cookies, runs no analytics, and loads nothing from third-party servers — fonts included, those are served from this domain. What follows covers the little that is processed anyway, and what happens once you book a call.
Last updated: August 2026
Controller
btaq GmbH, Am Garather Mühlenbach 26, 40595 Düsseldorf, Germany. Managing director: Paul Dziwoki. Email: info@btaq.io.
We are not required to appoint a data protection officer. Write to the address above for anything concerning your data.
Server logs
This site is hosted by Hetzner Online GmbH in Falkenstein, Germany, on our behalf under a data processing agreement (Art. 28 GDPR). Every request is logged with your IP address, timestamp, requested URL, referrer and browser user agent.
Purpose: delivering the site and detecting attacks and abuse. Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in a secure, working website. Logs are rotated automatically and deleted after 30 days at the latest.
Booking a call
The booking page links out to cal.btaq.io — our own Cal.com instance, on our own server. Nothing from it is embedded here, so no cookie is set until you follow that link.
Once there, we process the name, email address, appointment time and anything you type into the booking form, in order to schedule and hold the appointment. Legal basis: Art. 6 (1) (b) GDPR — pre-contractual measures and performance of a contract.
We keep booking data for as long as the appointment and any work arising from it are being handled. After that we delete it, except where commercial or tax law requires us to keep it (§ 257 HGB, § 147 AO) — which applies to bookings we invoiced, not to a call that led nowhere.
Payments
Paid sessions are charged through Stripe Payments Europe, Ltd., Dublin, Ireland. Card details go to Stripe directly; we never see or store them.
Stripe may transfer data to Stripe, Inc. in the USA, safeguarded by the EU Standard Contractual Clauses and Stripe's certification under the EU–US Data Privacy Framework. You can read the clauses at stripe.com/legal/dpa, look up the certification at dataprivacyframework.gov/list, or request a copy from us at the contact address at the end of this page. Legal basis: Art. 6 (1) (b) GDPR.
Video calls
Sessions run over Zoom (Zoom Communications, Inc., USA) or Google Meet (Google Ireland Limited), whichever your booking confirmation names. Connection metadata and the call itself are processed for the duration of the meeting; we do not record calls.
Legal basis: Art. 6 (1) (b) GDPR. Transfers to the USA rest on the EU Standard Contractual Clauses and the providers' Data Privacy Framework certification, which you can look up at dataprivacyframework.gov/list; the contact address at the end of this page will get you a copy of the clauses.
Our mail runs on Proton Mail (Proton AG, Geneva, Switzerland — a country the EU Commission has recognised as offering an adequate level of protection, Art. 45 GDPR).
We keep your message as long as it takes to answer it, and afterwards only where commercial or tax law requires us to (§ 257 HGB, § 147 AO). We do not pass it on. Legal basis: Art. 6 (1) (b) and (f) GDPR.
Your rights
You have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on legitimate interest (Art. 21). Where processing rests on consent, you may withdraw it at any time with effect for the future (Art. 7 (3)).
You also have the right to complain to a supervisory authority. The one responsible for us is Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf.
Contact for data requests: info@btaq.io.