Privacy policy.

1. Controller

Michael Lutz
Tunnkoppelstieg 22
22359 Hamburg
Germany

Phone: +49 151 22 81 42 61
Email: michael@herr-lutz.com

2. General Information

This Privacy Policy explains how Michael Lutz processes personal data when you visit this website, use its functions, contact us, submit booking, ticket, shop, or contract-related inquiries, or interact with embedded third-party content and consent-based technologies.

Personal data means any information relating to an identified or identifiable natural person.

3. Categories of Data Processed

Depending on how you use this website, personal data may be processed, in particular:
– technical access data
– contact details
– communication content
– booking, ticket, voucher, shop, or contract-related data
– payment-related data
– consent preferences
– usage data relating to cookies, analytics, marketing, embedded content, and third-party services, where applicable

4. Website Access and Server Log Files

When you visit this website, certain technical data is processed automatically in order to ensure the operation, security, and stability of the website.

This may include:
– browser type and version
– operating system
– referrer URL
– host name of the accessing device
– date and time of access
– IP address
– requested pages and files
– status codes
– transferred data volume

The processing of such data is based on Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, stable, and technically proper provision of the website.

5. Contact Inquiries

If you contact us by email, contact form, or any comparable communication channel provided on this website, the data you submit will be processed in order to handle your inquiry and any follow-up communication.

The processing is based on Art. 6(1)(b) GDPR where your inquiry relates to pre-contractual steps or a contract, and otherwise on Art. 6(1)(f) GDPR based on the legitimate interest in responding to inquiries and managing communications.

6. Bookings, Ticket Requests, Vouchers, Shop Inquiries, and Contractual Communication

If you submit booking requests, ticket requests, voucher inquiries, order-related inquiries, shop inquiries, or other contract-related inquiries, the data required to review, manage, and, where applicable, perform the contractual relationship will be processed.

This may include:
– name
– contact details
– booking, ticket, order, or voucher details
– invoice-related information
– communication history
– payment-related information, where applicable

Processing in this context is based on Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(c) GDPR if legal retention, tax, or accounting obligations apply.

7. Payments

Where payments are processed, the relevant payment and transaction data is processed to carry out payment handling, accounting, and related administrative obligations.

The processing is based on Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR.

Where external payment or shop providers are used, their privacy information may apply in addition to this Privacy Policy.

8. Cookies and Consent Management

This website uses cookies and similar technologies.

Some cookies are technically necessary to provide the website and its basic functions. These cookies may be used without consent where permitted by applicable law.

Other cookies and similar technologies, especially for analytics, marketing, personalization, social media integration, shop functionality, or external media, are only used if and to the extent that you have provided your consent through the consent management tool used on this website.

Your consent preferences can be changed or withdrawn at any time with effect for the future via the consent settings available on this website.

The legal basis for necessary cookies is Art. 6(1)(f) GDPR or, where applicable, the relevant legal provisions permitting strictly necessary storage or access.

The legal basis for all non-essential cookies and similar technologies is your consent pursuant to Art. 6(1)(a) GDPR.

9. Consent Management Platform

To collect, store, and manage cookie and consent preferences, this website may use a consent management platform.

In this context, the following data may be processed:
– consent status
– time and date of consent or refusal
– device or browser-related identifiers
– IP address, where necessary
– technical log data relating to the consent decision

The processing is based on Art. 6(1)(c) GDPR, where required to document consent, and/or Art. 6(1)(f) GDPR based on the legitimate interest in operating a compliant consent management system.

Consent tool used: Complianz – GDPR/CCPA Cookie Consent.

10. Analytics and Reach Measurement

Subject to your consent where required, this website may use analytics and reach measurement tools in order to understand how visitors use the website and to improve content, structure, performance, and user experience.

This may include services provided by Google or comparable providers, for example Google Analytics or related website measurement services.

In this context, usage data, device data, cookie identifiers, and similar online identifiers may be processed.

Such processing only takes place if and to the extent that you have provided your consent where required. The legal basis is Art. 6(1)(a) GDPR.

11. Marketing and Tracking Technologies

Subject to your consent where required, this website may use marketing and tracking technologies in order to measure campaign performance, build audiences, and display relevant advertising on third-party platforms.

This may include services provided by Meta, Google, or similar advertising and remarketing providers.

Such technologies may involve the processing of cookie identifiers, usage data, device data, IP-related data, and interactions with website content.

The legal basis for such processing is Art. 6(1)(a) GDPR.

12. Embedded Third-Party Content and External Services

This website may include embedded or externally loaded content and services, such as videos, maps, fonts, social media content, event tools, booking widgets, shop integrations, payment tools, or similar functionalities.

This may include, for example, services or content provided by Google, Meta, Eventbrite, Stripe, Spreadshirt, YouTube, Google Maps, Google Fonts, or comparable providers, where applicable.

When such content is activated, personal data such as your IP address, device information, browser information, and usage data may be transmitted to the respective third-party provider.

Where required, such content is only loaded after your consent has been given. The legal basis is Art. 6(1)(a) GDPR. Where external content is technically necessary or explicitly requested by you, processing may also be based on Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR, as applicable.

13. Social Media Links and Profiles

This website may contain links to external social media profiles or platforms, including services operated by Meta or LinkedIn. Clicking such links will redirect you to the respective third-party provider. Data processing on those platforms is governed by the privacy policies of the respective providers.

14. Recipients of Data

Personal data may be disclosed to service providers and processors involved in the operation of the website or business processes, where necessary. This may include, in particular:
– hosting providers
– email providers
– IT and maintenance providers
– consent management providers
– analytics and marketing providers, where consent has been given
– payment, accounting, and administration service providers
– event, booking, ticketing, shop, print-on-demand, or newsletter providers, where applicable

Such providers only receive data to the extent necessary for the relevant purpose.

15. International Data Transfers

Where personal data is transferred to recipients in countries outside the European Economic Area, such transfers will only take place in accordance with applicable data protection law.

Where required, appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or another legally recognised transfer mechanism, will be used.

16. Data Retention

Personal data will only be stored for as long as necessary for the respective purposes described in this Privacy Policy, or for as long as there is a legal obligation to retain the data.

Communication, contract, accounting, tax, and payment-related data may be retained for the duration of applicable statutory retention periods.

17. Your Rights

Subject to the applicable legal requirements, you have the right to:
– request access to your personal data
– request rectification of inaccurate data
– request erasure of your data
– request restriction of processing
– object to processing based on Art. 6(1)(f) GDPR
– withdraw consent at any time with effect for the future
– receive your data in a portable format, where applicable
– lodge a complaint with a competent data protection authority

18. Obligation to Provide Data

You are generally not obliged to provide personal data. However, certain website functions, inquiries, bookings, purchases, contractual processes, or communications may not be possible without the processing of the data required for those purposes.

19. Automated Decision-Making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place unless expressly stated otherwise in this Privacy Policy.

20. Changes to this Privacy Policy

Michael Lutz reserves the right to update this Privacy Policy with effect for the future. The current version will always be available on this website.

21. Contact Regarding Privacy Matters

If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact:

Michael Lutz
Tunnkoppelstieg 22
22359 Hamburg
Germany

Phone: +49 151 22 81 42 61
Email: michael@herr-lutz.com