Privacy policy
This English version is provided for convenience. The German version is legally binding.
1. Controller
The controller for the processing of personal data on this website is Brand Palace GmbH, Ludwig-Erhard-Straße 1a, 65760 Eschborn, Germany, represented by its managing directors Jonas Müller and Frederic von Borries. You can reach us by email at hello@brand-palace.com or by post at the address above.
2. Overview
This website provides information about the services of Brand Palace GmbH. The information pages set no cookies, use no third-party analytics or advertising services and embed no content from social networks. We process personal data only as far as this is necessary to run the website, to answer your enquiries and to protect our systems. There is no automated decision-making, including profiling. A technically necessary session cookie is used only in the login area (Section 7).
3. Hosting and server log files
This website is operated on a server of IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The server is located in a data centre in Germany. A data processing agreement pursuant to Article 28 GDPR is in place with IONOS.
With every visit, the web server stores in log files: the IP address of the requesting device, date and time, the page requested, the status of the response, the amount of data transferred, the previously visited page (referrer) and the type and version of the browser and operating system. We do not merge this data with other data. It serves to deliver the pages, to detect and fend off attacks and to find errors. From IP addresses that repeatedly send faulty or abusive requests we temporarily accept no further requests. The legal basis is Article 6 (1) (f) GDPR; our legitimate interest lies in the stable and secure operation of the website. The log files are deleted after 15 days at the latest.
4. Reach measurement
To measure reach, we count how often our pages are requested. The count takes place exclusively on our own server, without cookies and without passing data on to third parties. Page views are aggregated into plain totals per day and page. To estimate the number of distinct visitors per day, we derive an encrypted check value from the IP address and the browser identifier; it changes daily and cannot be traced back to the source data. The IP address itself is not stored. We keep the resulting totals for a maximum of 180 days. The legal basis is Article 6 (1) (f) GDPR (legitimate interest in data-sparing reach measurement). You may object to this processing under Article 21 GDPR (Section 11).
5. Contact form
When you send us an enquiry via the contact form, your browser transmits your details (name, company, email address, topic, message) to our server in encrypted form. The server forwards the enquiry as an email to hello@brand-palace.com and does not store its content. We operate this mailbox with Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); your enquiry is held there until it has been dealt with (Section 10). At the same time you receive an automatic confirmation of receipt at the address you provided; it contains your name, the chosen topic and the time of receipt, not the text of your message. Both emails are sent via the mail server of our provider IONOS. To protect against abuse, the server remembers for 15 minutes which IP address enquiries came from, and records the receipt of each enquiry with IP address, browser identifier and chosen topic, without name, address or message, for a maximum of 180 days in a security log.
The legal basis is Article 6 (1) (b) GDPR (handling your enquiry and initiating a contract) as well as Article 6 (1) (f) GDPR (legitimate interest in protection against abuse). Providing your details is voluntary; without name, email address and message we cannot answer an enquiry. We keep the email with your enquiry for as long as is necessary to handle it. If a business relationship results from it, the correspondence becomes part of our business records and is subject to the retention periods under commercial and tax law pursuant to Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO).
6. Contact by email
If you write to us directly by email, we process your email address, the details you provide and the content of your message in order to handle your request. The legal basis is Article 6 (1) (b) GDPR where the initiation or performance of a contract is concerned, otherwise Article 6 (1) (f) GDPR (legitimate interest in answering enquiries). We receive and store our emails in a mailbox with Google Workspace (Section 10). Section 5 applies accordingly to retention.
7. Login area
The area reachable via “Login” is an internal tool for our team and for partners who have access to the Feed Engine. Login credentials are transmitted to our server and checked there. On login, the server sets a technically necessary session cookie that ends on logout or after eight hours at the latest. Logins and failed login attempts are logged with IP address and browser identifier for a maximum of 180 days in order to detect abuse. The business data processed in this area is held on our own server. Where we process personal data on behalf of a partner in doing so, this is done on the basis of a data processing agreement pursuant to Article 28 GDPR. The legal basis is Article 6 (1) (b) GDPR (performance of the contract with the respective partner) and Article 6 (1) (f) GDPR (legitimate interest in secure operation).
Online appointments arranged via this area take place as video calls via Jitsi Meet. For this we use the service meet.jit.si of 8x8, Inc., 675 Creekside Way, Campbell, CA 95008, USA. When you join a call, 8x8 processes your IP address, device and connection data and the display name you choose; video and audio pass through the servers of 8x8. We do not record calls. Participation is voluntary; on request we hold the conversation by telephone or via a service of your choice. The legal basis is Article 6 (1) (b) GDPR (performance of the agreed appointment). For the transfer to the USA see Section 10.
8. Fonts
The typeface Inter, in which this website is set, is stored on our own server and loaded from there. No connection to third-party servers is established for this when a page is requested; no data is transmitted to Google or other providers of font services.
9. Encryption
This website can only be reached via HTTPS. The transmission between your browser and our server is encrypted with TLS. This also applies to the contact form and the login area.
10. Recipients and transfer to third countries
We pass on personal data only where this is necessary to perform a contract, where you have consented or where we are legally obliged to do so. We use the following processors: IONOS SE for hosting and email dispatch, Google Ireland Limited (Google Workspace) for our email mailbox and 8x8, Inc. (Jitsi Meet) for video calls under Section 7. Google Workspace and Jitsi Meet may process data in the USA. Google LLC is certified under the EU-US Data Privacy Framework; for 8x8, Inc. we base the transfer on the standard contractual clauses of the European Commission (Article 46 (2) (c) GDPR). Beyond this, no transfer to countries outside the European Union takes place.
11. Your rights
You have the right vis-à-vis us to information about the data stored about you (Article 15 GDPR), to rectification of inaccurate data (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR) and to data portability (Article 20 GDPR). Where we process data on the basis of Article 6 (1) (f) GDPR, you may object to this processing at any time on grounds relating to your particular situation (Article 21 GDPR). An email to hello@brand-palace.com is sufficient to exercise your rights.
You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, datenschutz.hessen.de.
12. Status and changes
Status: September 2026. We update this policy as soon as the services or procedures used change. The current version can always be found on this page.