Privacy Policy
Last updated: 2 August 2026
Controller
Niklas Lenz
Scheidtstr. 71
42369 Wuppertal, Germany
Email: niklas@niklaslenz.de
The short version
This is a static website. It sets no cookies, runs no analytics and no tracking, and loads no third-party scripts, fonts or content when you open a page — fonts and code libraries are served from this domain itself. No consent banner is therefore required. The only personal data that arises is the connection data your browser transmits to load the site, plus whatever you choose to send me by email.
One exception, and it is under your control: the Setup Pack page offers a newsletter sign-up form operated by Kit (ConvertKit LLC, USA). That form is not loaded until you click to load it. Simply visiting the page transmits nothing to Kit. The full detail is in section IV below.
I. Introduction
The controller is a consulting business specialising in the technical and organisational introduction of artificial intelligence.
By way of the following statement, the controller (also referred to below as “we” or the “provider”) informs you about the nature, scope and purposes of the collection, processing and use of your data when you use the controller’s software or digital services, contact the controller by means of telecommunication, or exchange data with the controller.
This privacy policy concerns in particular the website niklaslenz.com (hereinafter the Website) and our further digital services such as company pages, social media profiles and video channels. Where we handle data processing uniformly across the digital services we use, we have summarised the corresponding information on processing purposes, applicable legal bases and storage periods for you. The necessary details on the digital services we use and their third-party providers (hereinafter service providers) can be found following the summary section.
For all data protection matters, your point of contact is the controller identified above, whom you can reach using the contact and address details given above.
II. Legal bases
We observe the provisions of Regulation (EU) 2016/679 (General Data Protection Regulation, or GDPR), as we process your personal data in the European Union. Where the Swiss Data Protection Act (DSG) applies, processing is also carried out in accordance with Swiss data protection law. The Swiss Data Protection Act applies where the processing has effects in Switzerland. If we process personal data of natural persons habitually resident in the United Kingdom, the provisions of the UK General Data Protection Regulation (UK GDPR) in conjunction with the Data Protection Act 2018 apply in addition. Further information is provided in a separate section. If you are a resident of a state of the United States of America in which data protection legislation has been enacted, further rights may be available to you depending on your place of residence. Further information on this is set out below. In all other respects, we additionally observe the provisions of any national data protection law applicable to you.
Legal basis: consent
The legal basis for processing the data is Art. 6(1)(a) GDPR where you have given us your consent. You may withdraw your consent to the processing of personal data at any time. Further information can be found in the section on data subject rights below.
Legal basis: performance of a contract
Where the purpose of the processing is the initiation or performance of a contract, Art. 6(1)(b) GDPR is a legal basis for the processing.
Legal basis: legitimate interests
We are entitled to process your personal data where this constitutes the pursuit of legitimate interests pursuant to Art. 6(1)(f) GDPR. Such processing is not available, however, where your interests or fundamental rights and freedoms requiring the protection of personal data override those interests. Our legitimate interests include the presentation of our business, the conduct of promotional activities and ensuring IT security. Processing on the basis of our legitimate interests will, however, always be carried out only as appropriate to the purpose and limited to the necessary extent.
You may object at any time to processing that is necessary to safeguard the legitimate interests of the controller or of a third party. Further information can be found in the section on data subject rights below.
Legal basis: fault control and prevention of misuse
The legal basis for processing data to detect faults or errors in telecommunications systems is, alongside other legal bases, also Art. 6(1)(c) GDPR, insofar as action is required for reasons of information security.
Where there are actual indications of unlawful use of a telecommunications network or telecommunications service, in particular of unreasonable nuisance, we may process traffic data necessary to detect and prevent that unlawful use in order to protect end users.
Application of further legal bases
Where a further data protection law applies to you in addition to the GDPR, its legal bases apply to you additionally.
III. Definitions
Primarily, the definitions set out in Art. 4 GDPR apply.
Inventory data
Inventory data are personal data of a user that are necessary for the establishment, substantive configuration or amendment of a contractual relationship between the service provider and the user concerning the use of digital services.
Cookies
Cookies are small text files stored on the user’s device. Cookies always have a validity period, which may be limited to the end of the user’s session (session cookies) or may last for a longer period (persistent cookies). Persistent cookies remain on the user’s device and allow the provider or its partner companies (third-party cookies) to recognise the device on your next visit. You can configure your browser to notify you when a cookie is set and to decide individually whether to accept it, or to refuse cookies in specific cases or generally. If cookies are not accepted, the functionality of the website may be limited.
Note on this website: no cookies are set. The definition is included for completeness.
Service provider
A provider of digital services (also referred to as a “digital service provider”) is any natural or legal person who provides their own or third-party digital services, participates in their provision, or arranges access to the use of their own or third-party digital services.
Digital service
A digital service is a service of the information society, i.e. any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. For the purposes of this definition, “at a distance” means that the service is provided without the parties being simultaneously present; “by electronic means” means that the service is sent initially and received at its destination by means of electronic equipment for the processing (including digital compression) and storage of data, and entirely transmitted, conveyed and received by wire, by radio, by optical means or by other electromagnetic means; “at the individual request of a recipient” means that the service is provided through the transmission of data on individual request.
Global Privacy Control
Global Privacy Control (GPC) is a browser- or device-based privacy signal by which users can communicate their preference that their personal data should not be sold, shared or used for targeted advertising. Where a user activates GPC in a supported browser or via a corresponding browser extension, a signal is automatically transmitted to the website upon visiting it. That signal serves as a request to opt out of the sale or sharing of personal data and of certain forms of processing for advertising purposes, to the extent required under applicable data protection law.
Log data
Log data are usage and traffic data automatically transmitted from the user’s device to the provider’s server for technical reasons when the provider’s website is accessed. These are stored in what are known as log files.
User
A user is a natural person who uses digital services, in particular in order to obtain or make available information — for example a person who accesses the provider’s website. A user is always a data subject within the meaning of the GDPR.
Usage data
Usage data are personal data of a user that are necessary to enable and bill for the use of digital services. These include in particular characteristics identifying the user, information on the beginning and end and on the extent of the respective use, and information on the digital services used by the user.
Personal data
Personal data means any information relating to an identified or identifiable natural person (the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Pseudonymisation
Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.
Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Traffic data
Traffic data are data whose collection, processing or use is necessary for the provision of a telecommunications service.
Website
A website, or web presence, is the presence of a private or commercial provider of digital services on the World Wide Web, brought together under a particular internet address. A web presence comprises web pages and subpages, any downloadable documents, and further retrievable audiovisual media services.
IV. Our processing activities and their purposes
1. Processing for the purpose of general business communication
We process the following data in order to be able to communicate with you for business purposes. This includes, for example, answering your enquiry. If you contact us via the email address we provide, via messenger services or by telephone, or if you contact us by post, we will store your data in our data processing systems and process it until the intended purposes have been fulfilled or the storage periods have expired.
Data collected by us (inventory data):
- title, first name and surname,
- company name,
- address details (contact and billing address) such as street, postcode, town and country,
- communication data such as telephone (landline and mobile), fax and email address,
- website.
In the case of an email, a message sent via messenger or contact by telephone, we process the aforementioned inventory data if you expressly provide them to us.
Legal bases
- your consent,
- our legitimate interests (presentation of our business, advertising appropriate to the target group),
- the performance of contractual obligations or the initiation of a contract.
Storage period
Data you provide will be erased immediately after your enquiry has been dealt with, or, if it is not dealt with, no later than 3 months after the last contact, unless your data are subject to a longer storage period for a separate reason (for example the storage of information serving the performance of a contract). An enquiry has been dealt with once it is apparent from the circumstances that the matter concerned has been conclusively clarified.
2. Processing in connection with your use of our website
When you visit our website niklaslenz.com (hereinafter the Website), we process the data you provide in the course of your use in order to enable you to use our website. Through the website we publish information about our business and our services.
Newsletter sign-up via Kit — loaded only on your request
On the Setup Pack page we offer a free PDF (the “Jarvis Setup Pack”) via an email sign-up form operated by Kit, a product of ConvertKit LLC, USA.
The form is not loaded automatically. Opening the Setup Pack page transmits no data whatsoever to Kit. In place of the form you first see a notice and a button; only when you click that button is the form requested from Kit’s servers — and only at that moment does your IP address reach Kit. If you would prefer not to use the form at all, you can simply send us an email and we will send the PDF back personally. The legal basis for loading the form is Art. 6(1)(a) GDPR: your consent, given by that click.
If you then sign up, the email address you enter (and, optionally, your name) is processed by Kit in order to deliver the PDF and to send you our newsletter for as long as you remain subscribed. Sign-up uses double opt-in: after submitting the form you receive a confirmation email, and your address is only added to the list once you click the confirmation link. You may unsubscribe at any time — via the link in every email or by replying to us — without giving a reason.
Legal basis
- your consent (Art. 6(1)(a) GDPR), given by loading the form and confirmed by double opt-in.
Storage period
We store the data you provide until you withdraw your consent, and for no longer than 3 years from the date consent was given.
No cookies, no analytics, no third-party content
No cookies are set on this website and no analytics, tracking or audience measurement procedures are used. Fonts and code libraries are served from this domain itself; opening a page therefore establishes no connections to third-party servers. The only exception is the Kit sign-up form described above, which is loaded exclusively on your explicit click. A consent banner is therefore not required.
External links
This website links to external offerings, including social media profiles. Merely visiting this website transmits no data to those providers. The privacy policies of the respective providers apply only once you follow the links.
Processing of data for fault control and prevention of misuse
We analyse log data for the purposes of fault control and the prevention of misuse. A fault exists in the case of a malfunction of a digital service. Misuse of a digital service is present, for example, where there is unreasonable nuisance. The measures we take include the evaluation of error states and system monitoring to detect and defend against threats to the system.
Data collected by us (traffic data):
- browser type and browser version,
- operating system used,
- referrer URL,
- host name of the accessing computer,
- time of the server request,
- IP address.
We do not combine these data with other data sources.
Legal bases
- our legitimate interests (protection of our IT systems),
- fault control and prevention of misuse.
Right to object
As we process your data on the basis of our legitimate interests, you have a right to object. The collection of data to provide the digital service and the storage of data in log files is necessary for its operation and may also be justified on other legal grounds. You may, however, exercise your right to object by technical means, for example by anonymising your IP address through a VPN provider.
Storage period
Where data are stored in log files, they are erased after 7 days at the latest. Storage beyond that period is possible in accordance with data protection permissions.
V. Processing on our behalf
As part of our digital business processes we engage carefully selected service providers who process personal data on our behalf. This takes place on the basis of data processing agreements pursuant to Art. 28 GDPR. Processing on behalf of a controller always exists where an external service provider processes personal data not for its own purposes but exclusively on our instructions and for precisely defined purposes, such as in the use of hosting services. In such cases we ensure that our service providers take appropriate technical and organisational measures to protect your data and comply with statutory data protection requirements.
1. Vercel Inc. (hosting of this website)
For the provision and operation of this website we use services of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA (hereinafter Vercel). Vercel provides us with the technical infrastructure for hosting and operating the digital services. In operating the digital services, Vercel may process your personal data such as your traffic data and information on your geographic location. Vercel is our processor.
As Vercel is a company based in the USA, a transfer of personal data to a third country may take place. Insofar as personal data are transferred to the USA, this is done on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular by concluding the European Commission’s standard contractual clauses or on the basis of an existing certification under the EU-U.S. Data Privacy Framework, where applicable to the processing in question.
Further information on data processing by Vercel can be found at vercel.com/legal/privacy-policy.
2. Kit / ConvertKit LLC (newsletter)
The newsletter sign-up form described in section IV is operated by ConvertKit LLC (trading as Kit), USA. Kit processes the email address you provide, any name you provide, and the technical connection data arising when the form is loaded and submitted. Kit acts as our processor; we are the controller.
As Kit is based in the USA, data are transferred there. The transfer is based on the European Commission’s standard contractual clauses (SCCs). Further information can be found in Kit’s privacy policy. As set out above, no data reach Kit unless you actively load the form.
3. IONOS SE (domain, DNS and email mailbox)
The domain and the associated email mailbox are maintained with IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany (hereinafter IONOS). IONOS operates the name resolution (DNS) for the domain and the mail server through which our business email correspondence runs. If you send us an email, IONOS processes the personal data it contains on our behalf. The hosting of this website, by contrast, is not with IONOS but with Vercel (see above).
Further information on data processing by IONOS can be found in IONOS’s privacy policy.
VI. Appropriate safeguards
1. Pseudonymisation
Insofar as we collect usage data, we always store these under pseudonyms. We do not combine pseudonymous data with data about the holder of the pseudonym (such as inventory data).
2. Use of encryption technologies
For the transfer of data between your computer or mobile device and our servers or the digital services we use, we employ modern encryption methods (TLS/SSL). This technology is intended to protect your data from being read by unauthorised third parties and offers a very high security standard. You can tell that your data are being transmitted in encrypted form by the padlock symbol displayed in your browser’s address bar.
VII. Recipients and further processing
1. Further recipients of personal data in the EU
We process your contact and payment data within the EU or within the European Economic Area via payment service providers. No payment processing takes place via this website.
2. Recipients of personal data in third countries
In the course of using our services, further personal data may be transferred to recipients in third countries outside the European Union or the European Economic Area. Insofar as this occurs, the transfer takes place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular by concluding standard contractual clauses.
3. Further processing for other purposes
Unless stated otherwise above, your data are not passed on to third parties and are not further processed for purposes other than those stated.
VIII. Data subject rights
You have the right:
- pursuant to Art. 7(3) GDPR, to withdraw your consent to us at any time once given. The consequence is that we may no longer continue the data processing based on that consent for the future;
- pursuant to Art. 15 GDPR, to request information about the personal data we process concerning you. In particular, you may request information about the processing purposes, the categories of personal data, the categories of recipients to whom your data have been or will be disclosed, the envisaged storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data where these were not collected by us, and the existence of automated decision-making including profiling and, where applicable, meaningful information about the details thereof;
- pursuant to Art. 16 GDPR, to request without undue delay the rectification of inaccurate personal data, or the completion of personal data stored by us;
- pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
- pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data insofar as the accuracy of the data is contested by you, the processing is unlawful but you oppose its erasure, we no longer need the data but you require them for the establishment, exercise or defence of legal claims, or you have objected to the processing pursuant to Art. 21 GDPR;
- pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller; and
- pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a rule you may address the supervisory authority of your habitual residence or place of work, or that of our place of business. The authority competent for our place of business is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestrasse 2–4, 40213 Düsseldorf, Germany.
Right to object
Where your personal data are processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing of your personal data on grounds relating to your particular situation.
If you wish to exercise your right to object, an email to niklas@niklaslenz.de is sufficient.
IX. Additional information for residents of the United Kingdom
For natural persons resident in the United Kingdom, your rights are governed by the UK General Data Protection Regulation (UK GDPR).
1. Competent supervisory authority
Data subjects in the United Kingdom have the right to lodge a complaint with the competent data protection supervisory authority: Information Commissioner’s Office (ICO), ico.org.uk.
2. Rights of data subjects
As a natural person in the United Kingdom you have the following data subject rights:
- right of access to the personal data processed,
- right to rectification of inaccurate data,
- right to erasure of personal data,
- right to restriction of processing,
- right to data portability,
- right to object to certain processing operations,
- right to withdraw consent given.
These rights arise both from the GDPR and from the UK GDPR. For further information on your data subject rights, please refer to section VIII above.
International data transfers
Insofar as we transfer personal data from the United Kingdom to states outside the United Kingdom or the European Economic Area, this takes place only under the conditions of the UK GDPR. Appropriate safeguards are used for this purpose, in particular standard contractual clauses recognised by the UK government (International Data Transfer Agreement – IDTA) or the UK Addendum to the EU standard contractual clauses (SCCs).
Adequacy decisions
For data transfers between the United Kingdom and the European Union an adequacy decision is currently in place, so that an adequate level of data protection within the meaning of the UK GDPR and the GDPR is recognised.
X. Privacy notice for residents of California, USA
If you are a resident of the State of California, USA, the following section on the California Consumer Privacy Act of 2018 (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), applies to you and supplements the information contained elsewhere in this privacy policy.
Section “IV. Our processing activities and their purposes” sets out which information we collect and from which sources it originates. Where we use the term “personal data” in this section, it is to be understood as defined under the CCPA, in deviation from the definitions of the GDPR.
1. Data protection rights for residents of the State of California
As a resident of the State of California, USA, the CCPA grants you certain rights in relation to your personal data. Subject to the applicable statutory requirements and exceptions, you have the following rights:
Right to know
You have the right to know:
- which categories of personal data we collect about you,
- from which sources these data originate,
- for which purposes we collect, use, disclose or share these data,
- which categories of personal data we disclose, sell or share,
- to which categories of third parties personal data are disclosed, and
- which specific items of personal data we have stored about you.
Right to deletion
You have the right to request the deletion of your personal data that we have collected from you, subject to certain statutory exceptions.
Right to correction
You have the right to request the correction of inaccurate personal data that we hold about you.
Right to opt out of the sale or sharing of personal data
You have the right to opt out of the sale or sharing of your personal data for purposes of cross-context behavioural advertising. Where required by law, we recognise corresponding opt-out signals, including Global Privacy Control (GPC).
Right to limit the use of sensitive personal data
Insofar as we process sensitive personal data within the meaning of the CPRA, you have the right to limit the use and disclosure of such data to the purposes permitted under applicable law.
Right to non-discrimination
We will not discriminate against you, disadvantage you or deny you services because you exercise any of your data protection rights under the CCPA or CPRA.
Exercising your rights
You can exercise your data protection rights by contacting us using the contact details given in this privacy policy. Before processing your request, we may take reasonable measures to verify your identity in order to ensure that the request was made by the data subject or an authorised representative.
Time limits for responding to your request
We will respond to data protection requests under the CCPA within the statutory time limit, generally within forty-five (45) days of receipt of the request. If we are unable to respond to your request within that period, we will inform you in writing and explain the reasons. The extension period is then a further 45 days (90 days in total).
XI. Data protection rights for residents of the USA outside the State of California
If you are a resident of states of the USA outside California in which data protection legislation has been enacted, you may have the following rights depending on your place of residence:
- Right to know — you may request information about which data we process, from which sources these originate, for which purposes they are used and to which recipients they are disclosed.
- Right to deletion — you may request the deletion of your personal data, subject to statutory exceptions.
- Right to correction — you may request the correction of inaccurate personal data.
- Right to data portability — you may request a copy of your data in a structured format.
- Right to restriction or objection — where provided by law, you may object to certain processing operations.
- Right to non-discrimination — exercising your data protection rights does not lead to any disadvantage.
Depending on the data protection law applicable to you, you may additionally have the option to opt out of:
- the sale of your personal data,
- the sharing of personal data for cross-context behavioural advertising,
- the processing of personal data for targeted advertising,
- profiling in connection with decisions that have legal or similarly significant effects on you.
This policy is provided in English for the international audience of this site. The controller is based in Germany and the GDPR applies. In the event of any discrepancy, the German version at niklaslenz.de/datenschutz is the authoritative text.