← niklaslenz.com

Privacy Policy

Last updated: 2 August 2026

Controller

Niklas Lenz
Scheidtstr. 71
42369 Wuppertal, Germany
Email: niklas@niklaslenz.de

The short version

This is a static website. It sets no cookies, runs no analytics and no tracking, and loads no third-party scripts, fonts or content when you open a page — fonts and code libraries are served from this domain itself. No consent banner is therefore required. The only personal data that arises is the connection data your browser transmits to load the site, plus whatever you choose to send me by email.

One exception, and it is under your control: the Setup Pack page offers a newsletter sign-up form operated by Kit (ConvertKit LLC, USA). That form is not loaded until you click to load it. Simply visiting the page transmits nothing to Kit. The full detail is in section IV below.

I. Introduction

The controller is a consulting business specialising in the technical and organisational introduction of artificial intelligence.

By way of the following statement, the controller (also referred to below as “we” or the “provider”) informs you about the nature, scope and purposes of the collection, processing and use of your data when you use the controller’s software or digital services, contact the controller by means of telecommunication, or exchange data with the controller.

This privacy policy concerns in particular the website niklaslenz.com (hereinafter the Website) and our further digital services such as company pages, social media profiles and video channels. Where we handle data processing uniformly across the digital services we use, we have summarised the corresponding information on processing purposes, applicable legal bases and storage periods for you. The necessary details on the digital services we use and their third-party providers (hereinafter service providers) can be found following the summary section.

For all data protection matters, your point of contact is the controller identified above, whom you can reach using the contact and address details given above.

II. Legal bases

We observe the provisions of Regulation (EU) 2016/679 (General Data Protection Regulation, or GDPR), as we process your personal data in the European Union. Where the Swiss Data Protection Act (DSG) applies, processing is also carried out in accordance with Swiss data protection law. The Swiss Data Protection Act applies where the processing has effects in Switzerland. If we process personal data of natural persons habitually resident in the United Kingdom, the provisions of the UK General Data Protection Regulation (UK GDPR) in conjunction with the Data Protection Act 2018 apply in addition. Further information is provided in a separate section. If you are a resident of a state of the United States of America in which data protection legislation has been enacted, further rights may be available to you depending on your place of residence. Further information on this is set out below. In all other respects, we additionally observe the provisions of any national data protection law applicable to you.

Legal basis: consent

The legal basis for processing the data is Art. 6(1)(a) GDPR where you have given us your consent. You may withdraw your consent to the processing of personal data at any time. Further information can be found in the section on data subject rights below.

Legal basis: performance of a contract

Where the purpose of the processing is the initiation or performance of a contract, Art. 6(1)(b) GDPR is a legal basis for the processing.

Legal basis: legitimate interests

We are entitled to process your personal data where this constitutes the pursuit of legitimate interests pursuant to Art. 6(1)(f) GDPR. Such processing is not available, however, where your interests or fundamental rights and freedoms requiring the protection of personal data override those interests. Our legitimate interests include the presentation of our business, the conduct of promotional activities and ensuring IT security. Processing on the basis of our legitimate interests will, however, always be carried out only as appropriate to the purpose and limited to the necessary extent.

You may object at any time to processing that is necessary to safeguard the legitimate interests of the controller or of a third party. Further information can be found in the section on data subject rights below.

Legal basis: fault control and prevention of misuse

The legal basis for processing data to detect faults or errors in telecommunications systems is, alongside other legal bases, also Art. 6(1)(c) GDPR, insofar as action is required for reasons of information security.

Where there are actual indications of unlawful use of a telecommunications network or telecommunications service, in particular of unreasonable nuisance, we may process traffic data necessary to detect and prevent that unlawful use in order to protect end users.

Application of further legal bases

Where a further data protection law applies to you in addition to the GDPR, its legal bases apply to you additionally.

III. Definitions

Primarily, the definitions set out in Art. 4 GDPR apply.

Inventory data

Inventory data are personal data of a user that are necessary for the establishment, substantive configuration or amendment of a contractual relationship between the service provider and the user concerning the use of digital services.

Cookies

Cookies are small text files stored on the user’s device. Cookies always have a validity period, which may be limited to the end of the user’s session (session cookies) or may last for a longer period (persistent cookies). Persistent cookies remain on the user’s device and allow the provider or its partner companies (third-party cookies) to recognise the device on your next visit. You can configure your browser to notify you when a cookie is set and to decide individually whether to accept it, or to refuse cookies in specific cases or generally. If cookies are not accepted, the functionality of the website may be limited.

Note on this website: no cookies are set. The definition is included for completeness.

Service provider

A provider of digital services (also referred to as a “digital service provider”) is any natural or legal person who provides their own or third-party digital services, participates in their provision, or arranges access to the use of their own or third-party digital services.

Digital service

A digital service is a service of the information society, i.e. any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient. For the purposes of this definition, “at a distance” means that the service is provided without the parties being simultaneously present; “by electronic means” means that the service is sent initially and received at its destination by means of electronic equipment for the processing (including digital compression) and storage of data, and entirely transmitted, conveyed and received by wire, by radio, by optical means or by other electromagnetic means; “at the individual request of a recipient” means that the service is provided through the transmission of data on individual request.

Global Privacy Control

Global Privacy Control (GPC) is a browser- or device-based privacy signal by which users can communicate their preference that their personal data should not be sold, shared or used for targeted advertising. Where a user activates GPC in a supported browser or via a corresponding browser extension, a signal is automatically transmitted to the website upon visiting it. That signal serves as a request to opt out of the sale or sharing of personal data and of certain forms of processing for advertising purposes, to the extent required under applicable data protection law.

Log data

Log data are usage and traffic data automatically transmitted from the user’s device to the provider’s server for technical reasons when the provider’s website is accessed. These are stored in what are known as log files.

User

A user is a natural person who uses digital services, in particular in order to obtain or make available information — for example a person who accesses the provider’s website. A user is always a data subject within the meaning of the GDPR.

Usage data

Usage data are personal data of a user that are necessary to enable and bill for the use of digital services. These include in particular characteristics identifying the user, information on the beginning and end and on the extent of the respective use, and information on the digital services used by the user.

Personal data

Personal data means any information relating to an identified or identifiable natural person (the “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Pseudonymisation

Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.

Processing

Processing means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Traffic data

Traffic data are data whose collection, processing or use is necessary for the provision of a telecommunications service.

Website

A website, or web presence, is the presence of a private or commercial provider of digital services on the World Wide Web, brought together under a particular internet address. A web presence comprises web pages and subpages, any downloadable documents, and further retrievable audiovisual media services.

IV. Our processing activities and their purposes

1. Processing for the purpose of general business communication

We process the following data in order to be able to communicate with you for business purposes. This includes, for example, answering your enquiry. If you contact us via the email address we provide, via messenger services or by telephone, or if you contact us by post, we will store your data in our data processing systems and process it until the intended purposes have been fulfilled or the storage periods have expired.

Data collected by us (inventory data):

In the case of an email, a message sent via messenger or contact by telephone, we process the aforementioned inventory data if you expressly provide them to us.

Legal bases

Storage period

Data you provide will be erased immediately after your enquiry has been dealt with, or, if it is not dealt with, no later than 3 months after the last contact, unless your data are subject to a longer storage period for a separate reason (for example the storage of information serving the performance of a contract). An enquiry has been dealt with once it is apparent from the circumstances that the matter concerned has been conclusively clarified.

2. Processing in connection with your use of our website

When you visit our website niklaslenz.com (hereinafter the Website), we process the data you provide in the course of your use in order to enable you to use our website. Through the website we publish information about our business and our services.

Newsletter sign-up via Kit — loaded only on your request

On the Setup Pack page we offer a free PDF (the “Jarvis Setup Pack”) via an email sign-up form operated by Kit, a product of ConvertKit LLC, USA.

The form is not loaded automatically. Opening the Setup Pack page transmits no data whatsoever to Kit. In place of the form you first see a notice and a button; only when you click that button is the form requested from Kit’s servers — and only at that moment does your IP address reach Kit. If you would prefer not to use the form at all, you can simply send us an email and we will send the PDF back personally. The legal basis for loading the form is Art. 6(1)(a) GDPR: your consent, given by that click.

If you then sign up, the email address you enter (and, optionally, your name) is processed by Kit in order to deliver the PDF and to send you our newsletter for as long as you remain subscribed. Sign-up uses double opt-in: after submitting the form you receive a confirmation email, and your address is only added to the list once you click the confirmation link. You may unsubscribe at any time — via the link in every email or by replying to us — without giving a reason.

Legal basis

Storage period

We store the data you provide until you withdraw your consent, and for no longer than 3 years from the date consent was given.

No cookies, no analytics, no third-party content

No cookies are set on this website and no analytics, tracking or audience measurement procedures are used. Fonts and code libraries are served from this domain itself; opening a page therefore establishes no connections to third-party servers. The only exception is the Kit sign-up form described above, which is loaded exclusively on your explicit click. A consent banner is therefore not required.

External links

This website links to external offerings, including social media profiles. Merely visiting this website transmits no data to those providers. The privacy policies of the respective providers apply only once you follow the links.

Processing of data for fault control and prevention of misuse

We analyse log data for the purposes of fault control and the prevention of misuse. A fault exists in the case of a malfunction of a digital service. Misuse of a digital service is present, for example, where there is unreasonable nuisance. The measures we take include the evaluation of error states and system monitoring to detect and defend against threats to the system.

Data collected by us (traffic data):

We do not combine these data with other data sources.

Legal bases

Right to object

As we process your data on the basis of our legitimate interests, you have a right to object. The collection of data to provide the digital service and the storage of data in log files is necessary for its operation and may also be justified on other legal grounds. You may, however, exercise your right to object by technical means, for example by anonymising your IP address through a VPN provider.

Storage period

Where data are stored in log files, they are erased after 7 days at the latest. Storage beyond that period is possible in accordance with data protection permissions.

V. Processing on our behalf

As part of our digital business processes we engage carefully selected service providers who process personal data on our behalf. This takes place on the basis of data processing agreements pursuant to Art. 28 GDPR. Processing on behalf of a controller always exists where an external service provider processes personal data not for its own purposes but exclusively on our instructions and for precisely defined purposes, such as in the use of hosting services. In such cases we ensure that our service providers take appropriate technical and organisational measures to protect your data and comply with statutory data protection requirements.

1. Vercel Inc. (hosting of this website)

For the provision and operation of this website we use services of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA (hereinafter Vercel). Vercel provides us with the technical infrastructure for hosting and operating the digital services. In operating the digital services, Vercel may process your personal data such as your traffic data and information on your geographic location. Vercel is our processor.

As Vercel is a company based in the USA, a transfer of personal data to a third country may take place. Insofar as personal data are transferred to the USA, this is done on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular by concluding the European Commission’s standard contractual clauses or on the basis of an existing certification under the EU-U.S. Data Privacy Framework, where applicable to the processing in question.

Further information on data processing by Vercel can be found at vercel.com/legal/privacy-policy.

2. Kit / ConvertKit LLC (newsletter)

The newsletter sign-up form described in section IV is operated by ConvertKit LLC (trading as Kit), USA. Kit processes the email address you provide, any name you provide, and the technical connection data arising when the form is loaded and submitted. Kit acts as our processor; we are the controller.

As Kit is based in the USA, data are transferred there. The transfer is based on the European Commission’s standard contractual clauses (SCCs). Further information can be found in Kit’s privacy policy. As set out above, no data reach Kit unless you actively load the form.

3. IONOS SE (domain, DNS and email mailbox)

The domain and the associated email mailbox are maintained with IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany (hereinafter IONOS). IONOS operates the name resolution (DNS) for the domain and the mail server through which our business email correspondence runs. If you send us an email, IONOS processes the personal data it contains on our behalf. The hosting of this website, by contrast, is not with IONOS but with Vercel (see above).

Further information on data processing by IONOS can be found in IONOS’s privacy policy.

VI. Appropriate safeguards

1. Pseudonymisation

Insofar as we collect usage data, we always store these under pseudonyms. We do not combine pseudonymous data with data about the holder of the pseudonym (such as inventory data).

2. Use of encryption technologies

For the transfer of data between your computer or mobile device and our servers or the digital services we use, we employ modern encryption methods (TLS/SSL). This technology is intended to protect your data from being read by unauthorised third parties and offers a very high security standard. You can tell that your data are being transmitted in encrypted form by the padlock symbol displayed in your browser’s address bar.

VII. Recipients and further processing

1. Further recipients of personal data in the EU

We process your contact and payment data within the EU or within the European Economic Area via payment service providers. No payment processing takes place via this website.

2. Recipients of personal data in third countries

In the course of using our services, further personal data may be transferred to recipients in third countries outside the European Union or the European Economic Area. Insofar as this occurs, the transfer takes place on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular by concluding standard contractual clauses.

3. Further processing for other purposes

Unless stated otherwise above, your data are not passed on to third parties and are not further processed for purposes other than those stated.

VIII. Data subject rights

You have the right:

Right to object

Where your personal data are processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing of your personal data on grounds relating to your particular situation.

If you wish to exercise your right to object, an email to niklas@niklaslenz.de is sufficient.

IX. Additional information for residents of the United Kingdom

For natural persons resident in the United Kingdom, your rights are governed by the UK General Data Protection Regulation (UK GDPR).

1. Competent supervisory authority

Data subjects in the United Kingdom have the right to lodge a complaint with the competent data protection supervisory authority: Information Commissioner’s Office (ICO), ico.org.uk.

2. Rights of data subjects

As a natural person in the United Kingdom you have the following data subject rights:

These rights arise both from the GDPR and from the UK GDPR. For further information on your data subject rights, please refer to section VIII above.

International data transfers

Insofar as we transfer personal data from the United Kingdom to states outside the United Kingdom or the European Economic Area, this takes place only under the conditions of the UK GDPR. Appropriate safeguards are used for this purpose, in particular standard contractual clauses recognised by the UK government (International Data Transfer Agreement – IDTA) or the UK Addendum to the EU standard contractual clauses (SCCs).

Adequacy decisions

For data transfers between the United Kingdom and the European Union an adequacy decision is currently in place, so that an adequate level of data protection within the meaning of the UK GDPR and the GDPR is recognised.

X. Privacy notice for residents of California, USA

If you are a resident of the State of California, USA, the following section on the California Consumer Privacy Act of 2018 (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), applies to you and supplements the information contained elsewhere in this privacy policy.

Section “IV. Our processing activities and their purposes” sets out which information we collect and from which sources it originates. Where we use the term “personal data” in this section, it is to be understood as defined under the CCPA, in deviation from the definitions of the GDPR.

1. Data protection rights for residents of the State of California

As a resident of the State of California, USA, the CCPA grants you certain rights in relation to your personal data. Subject to the applicable statutory requirements and exceptions, you have the following rights:

Right to know

You have the right to know:

Right to deletion

You have the right to request the deletion of your personal data that we have collected from you, subject to certain statutory exceptions.

Right to correction

You have the right to request the correction of inaccurate personal data that we hold about you.

Right to opt out of the sale or sharing of personal data

You have the right to opt out of the sale or sharing of your personal data for purposes of cross-context behavioural advertising. Where required by law, we recognise corresponding opt-out signals, including Global Privacy Control (GPC).

Right to limit the use of sensitive personal data

Insofar as we process sensitive personal data within the meaning of the CPRA, you have the right to limit the use and disclosure of such data to the purposes permitted under applicable law.

Right to non-discrimination

We will not discriminate against you, disadvantage you or deny you services because you exercise any of your data protection rights under the CCPA or CPRA.

Exercising your rights

You can exercise your data protection rights by contacting us using the contact details given in this privacy policy. Before processing your request, we may take reasonable measures to verify your identity in order to ensure that the request was made by the data subject or an authorised representative.

Time limits for responding to your request

We will respond to data protection requests under the CCPA within the statutory time limit, generally within forty-five (45) days of receipt of the request. If we are unable to respond to your request within that period, we will inform you in writing and explain the reasons. The extension period is then a further 45 days (90 days in total).

XI. Data protection rights for residents of the USA outside the State of California

If you are a resident of states of the USA outside California in which data protection legislation has been enacted, you may have the following rights depending on your place of residence:

Depending on the data protection law applicable to you, you may additionally have the option to opt out of:

This policy is provided in English for the international audience of this site. The controller is based in Germany and the GDPR applies. In the event of any discrepancy, the German version at niklaslenz.de/datenschutz is the authoritative text.