Privacy policy
As of: August 2026 · in accordance with the GDPRThis is a courtesy translation. The German version is legally authoritative.
1. Controller
Safety Club GmbH (i.G.)
represented by the Managing Directors Hugo Hoffstadt and Merten Precht
Wiesenstraße 3, 13357 Berlin
Email: info@safetyclub.de
Phone: +49 (0) 1573 4127399
2. General information on data processing
In principle, we process our users' personal data only insofar as this is necessary to provide a functional website as well as our content and services. Processing regularly takes place only with the user's consent (Art. 6 (1) (a) GDPR), on the basis of a legitimate interest (Art. 6 (1) (f) GDPR), or for the performance of a contract (Art. 6 (1) (b) GDPR).
3. Accessing the website (server log files)
When you access our website, the hosting provider automatically records information (including IP address, date and time of access, page accessed, referrer URL, browser type and operating system). The legal basis is our legitimate interest in a technically flawless and secure provision of the website (Art. 6 (1) (f) GDPR). These server log files are stored only for a limited period and then automatically deleted.
Our website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. In this context, personal data (in particular the aforementioned server log files) may also be processed on Vercel's servers. Insofar as processing takes place in the USA, this is done on the basis of appropriate safeguards, in particular the EU standard contractual clauses. A data processing agreement (DPA) with Vercel is in place, incorporated by reference into Vercel's Terms of Service. More information: Vercel Privacy Policy.
4. Contact form and getting in touch
If you contact us via the contact form or by email, your details (name, company, email, phone, number of employees and message) are stored to process your enquiry. The legal basis is Art. 6 (1) (a) and (b) GDPR. We do not pass this data on without your consent and delete it as soon as it is no longer required for the purpose or once statutory retention periods have expired.
For the technical delivery of the contact form we use a server function at our hosting provider Vercel, and the service Brevo (Sendinblue GmbH, EU) for sending emails. When you submit the form, the data you enter is delivered to us as an email via these services. The legal basis is Art. 6 (1) (a) and (b) GDPR. A data processing agreement is in place with both providers. More information: Brevo privacy policy.
5. Sending calculator results (tools)
On our tool pages you can have the result of a calculation sent to you as a PDF by email. For this we process your email address, optionally the company name you provide, the values you entered, the result calculated from them and the address of the tool page you used. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you give via the checkbox in the form.
Your details are used for two purposes: to deliver the PDF to you, and to send us a copy of the request so that we can contact you about your result if needed. This does not add you to the newsletter. For generating and sending we use a server function at Vercel and the email service Brevo (Sendinblue GmbH, EU); a data processing agreement is in place with both providers. You can withdraw your consent at any time by an informal message to info@safetyclub.de. We will then delete your data unless statutory retention periods apply.
6. Newsletter
If you subscribe to our newsletter, we process your email address as well as the date and time of the subscription and the IP address transmitted at that point as proof of your consent. The subscription uses the double-opt-in procedure: after you submit your details you receive a confirmation email; only when you click the link it contains is your address added to the distribution list. The legal basis is your consent (Art. 6 (1) (a) GDPR). For sending and managing the newsletter we use the service Brevo (Sendinblue GmbH, EU), with which a data processing agreement exists. You can unsubscribe from the newsletter at any time via the unsubscribe link at the end of every email or by sending a message to info@safetyclub.de; your consent is then deemed withdrawn.
7. Fonts and embedded content
The fonts used on this website (Manrope and IBM Plex Mono) are served locally from our own server. No connection to third-party servers (e.g. Google Fonts) is established for this purpose; your IP address is not transmitted to any font provider. The images used on the website are likewise served from our own server.
The statement about fonts concerns fonts and images only. Independently of this, we embed the Google tag for conversion tracking on every page; see section 11 for details. Once you consent, the OpenAI Measurement Pixel is added, see section 12.
Where individual pages embed further interactive third-party content, this is indicated separately (see section 9 on appointment booking via Calendly).
8. Your rights
You have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw any consent given at any time. You also have the right to lodge a complaint with a data protection supervisory authority.
9. Appointment booking via Calendly
For online appointment scheduling we embed the service Calendly (Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA). The embedded calendar loads automatically when you open the relevant page; in doing so, a connection to Calendly's servers is established, and data (including IP address, browser and device information) may be transmitted to Calendly, and cookies or comparable technologies required for the calendar to function may be set. The legal basis for embedding the calendar is our legitimate interest in offering easy online appointment booking (Art. 6 (1) (f) GDPR). If you book an appointment, Calendly processes the data you provide (e.g. name, email, preferred time) to carry out the appointment; the legal basis for this is Art. 6 (1) (b) GDPR (or (a) for voluntary additional information). As Calendly may process data in the USA, the transfer takes place on the basis of appropriate safeguards (in particular EU standard contractual clauses). If you do not want any data transmitted to Calendly, please do not use the appointment booking; you may also object to the embedding pursuant to Art. 21 GDPR. More information: calendly.com/privacy.
10. Usage analytics (Vercel Web Analytics)
To statistically evaluate the use of our website, we use Vercel Web Analytics, a service provided by our hosting provider Vercel Inc. This records usage data in aggregated form (e.g. pages viewed, referrer, approximate region, device type and browser). Collection is cookieless: no cookies are set and no cross-device user profiles are created. Vercel evaluates the data in anonymised or aggregated form, so that no conclusions can be drawn about individual persons; full IP addresses are not stored permanently. The measurement script is served from our own domain, so no additional third-party host is involved. The legal basis is our legitimate interest in the needs-based design and statistical evaluation of our website (Art. 6 (1) (f) GDPR). More information: Vercel Privacy Policy.
11. Google Ads and conversion tracking
We advertise our services via Google Ads. In order to measure whether a visit arriving through one of our ads leads to a contact request, an appointment booking or a calculator result being sent, we embed the Google tag (gtag.js) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, on every page.
Before your consent: the script is loaded from googletagmanager.com, which transmits your IP address to Google. However, no cookies are set and no identifiers are stored on or read from your device. For this we use Google Consent Mode v2, whose defaults for ad_storage, ad_user_data, ad_personalization and analytics_storage are set to "denied". The legal basis for loading the script is our legitimate interest in evaluating the commercial performance of our advertising (Art. 6 (1) (f) GDPR).
After your consent: only once you select "Accept" in the cookie banner are cookies set, or information stored on and read from your device. Google can then recognise that you performed a particular action on our website after clicking an ad, and provide us with aggregated statistics about it. The legal basis for storing and accessing information on your device is section 25 (1) TDDDG, and for the subsequent processing of your data your consent under Art. 6 (1) (a) GDPR.
Withdrawal: you can withdraw your consent at any time with effect for the future. The lawfulness of processing carried out up to that point remains unaffected.
Transfers to third countries: processing by Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; EU standard contractual clauses apply in addition. More information: policies.google.com/privacy and policies.google.com/technologies/ads.
12. ChatGPT Ads (OpenAI Measurement Pixel)
We also advertise our services inside ChatGPT. To measure whether a visit arriving through one of those ads leads to a contact request or an appointment booking, we use the Measurement Pixel provided by OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland.
Nothing is loaded without your consent. Unlike the Google tag (section 11), OpenAI's script is only fetched from bzrcdn.openai.com once you have accepted in the cookie banner. Before your consent there is no connection to OpenAI whatsoever: no script is loaded, no data is transmitted, and no information is stored on or read from your device.
After your consent, the pixel reports the occurrence of a request or booking to OpenAI as an event, so that we can assess how our ads perform. The legal basis for storing and accessing information on your device is section 25 (1) TDDDG, and for the subsequent processing your consent under Art. 6 (1) (a) GDPR.
Withdrawal: you can withdraw your consent at any time with effect for the future. The lawfulness of processing carried out up to that point remains unaffected.
Transfers to third countries: processing by OpenAI OpCo, LLC in the USA cannot be ruled out. Transfers are based on appropriate safeguards, in particular EU standard contractual clauses. More information: openai.com/policies/privacy-policy.
13. Data security
We use SSL/TLS encryption to protect the transmission of confidential content. You can recognise an encrypted connection by "https://" in your browser's address bar.
