Legal
Privacy policy
Last updated: 29 August 2026
1. Controller
The controller responsible for processing under the GDPR is:
Clickspire LLC
30 N Gould St
82801 Sheridan
Email: kontakt@visnakovs.de
2. Contact and booking
If you contact me or book a consultation, I process the details you provide (such as name, email, company, phone number, message and appointment details) to answer your request or deliver the appointment. The legal basis and retention period depend on the request and the applicable contract, pre-contractual relationship or consent. Depending on the function, Resend handles email, Google Calendar handles appointments, and a configured Google Sheet is used to process the enquiry. The long-lived lead row in that Google Sheet stores neither the request IP address nor the user agent. Those details may be processed separately and transiently for hosting, abuse prevention and Cloudflare Turnstile, but they are not copied into the lead record. Result, report, download and enquiry emails do not subscribe you to a newsletter. Only a form explicitly labelled as a newsletter adds your address to that audience. Newsletter consent can be withdrawn at any time for the future by emailing kontakt@visnakovs.de.
3. Cookies, consent and measurement
The vis_consent cookie stores your category choice. Before an affirmative analytics or marketing
choice, the site does not load Google Tag Manager and does not write campaign attribution to local storage.
General UTM, referrer and page context may be retained after analytics or marketing consent. Advertising click
identifiers such as GCLID, GBRAID, WBRAID and FBCLID are stored and transmitted only with marketing consent; with
analytics-only consent they are also removed from retained page URLs. The lead record stores both category
decisions, their timestamp and consent version. Without either optional choice, campaign context is not attached
to a form submission.
- Necessary: site functionality, security, Cloudflare Turnstile on protected forms and the consent preference.
- Analytics: after consent, Google Tag Manager may load Google Analytics 4; PostHog events, experiments, session replay and heatmaps; and Dealfront/Leadfeeder for company-level visit analysis. A self-hosted company-visit service may also run server-side. These services may process URLs, referrers, events, device and browser details, IP addresses and pseudonymous identifiers.
- Marketing: after consent, Google Ads, the Meta Pixel and the TikTok Pixel may measure conversions, optimise campaigns and build audiences. Depending on the tag, cookies, click and event data, URLs, IP address, user agent and — where configured — hashed contact data may be transmitted. Consent Mode v2 starts with storage denied.
- Server-side events: contact and booking events are sent to GA4 only when analytics consent exists.
- Bot protection: Cloudflare Turnstile may be loaded on configured forms to prevent abuse. It is not used as advertising or audience measurement, but the Cloudflare transfer and legal basis should still be reviewed.
- Embedded YouTube videos: talk videos initially appear as a local preview only. The site loads an embedded video from
youtube-nocookie.comonly after your active click. This establishes a connection to YouTube/Google, which may receive and process your IP address, browser and device information and the page you viewed. “No-cookie” mode does not prevent every form of storage or further processing. The legal basis is the consent expressed by your informed click under Article 6(1)(a) GDPR and, where applicable, the relevant device-storage rule.
This is a technical implementation summary, not legal advice. Vendor agreements, international transfers, retention periods and the final legal bases should be confirmed with qualified privacy counsel. You can change your optional choice at any time using “Cookie settings” in the footer. Withdrawal blocks future optional transmissions, clears local campaign attribution and resets the local PostHog identity. Scripts already loaded may remain in the document until the page reloads, but their consent signals are changed to denied.
4. Hosting and external services
The site is hosted by a technical hosting provider. Depending on the tool or form you use, data may be processed by providers such as Resend (email), Google (calendar, measurement and PageSpeed), Notion (optional follow-up checks), Microlink or image.thum.io (optional page previews), and Cloudflare (Turnstile). The relevant service is only called for the feature you use; applicable processor agreements and transfers must be assessed for the current deployment.
5. Anonymised evaluation of the free tools
The details you enter into the free tools on this website — for example a website address you have checked or figures you have typed in — may be evaluated in anonymised, aggregated form in order to produce general statistics (for example “X % of the pages checked measure no conversions”). For that purpose the details are separated from you and from your email address and are only considered as a total across many checks. Only such aggregate figures are ever published; individual domains, URLs, entries or other details that can be attributed to a person or a company are neither published nor passed on to third parties. The legal basis for the anonymisation step is Article 6(1)(f) GDPR (legitimate interest in improving and benchmarking the services offered on this website); the anonymous dataset that results no longer permits any reference to a person. Results that remain attributed to a person — such as a report requested by email — continue to be governed by sections 2 and 4.
6. Server logs and company-level analysis
Technical request data such as IP address, browser, URL, referrer and timestamp may be processed to operate and protect the site.
Dealfront/Leadfeeder
After analytics consent, Dealfront/Leadfeeder may receive the IP address, timestamp, URL, referrer, browser and device information, location and usage data, and pseudonymous identifiers to associate a visit with a possible company and the pages it viewed. The script is loaded through Google Tag Manager; this is not a local-only lookup. The purpose is company-level audience analysis, service improvement and preparation of B2B outreach. The legal basis is consent under Article 6(1)(a) GDPR and, where applicable, the relevant device- storage rule. Dealfront says processing takes place primarily in the EU, with safeguards for processing outside the EEA. See the Dealfront Privacy Center. The exact retention period depends on the active Dealfront plan and account settings and must be confirmed, together with processor terms, transfer safeguards and the final legal basis, before production use.
Self-hosted company-visit measurement
A separate first-party, server-side B2B company-identification path is also prepared. On a page request,
Vercel Routing Middleware reads the existing vis_consent cookie. It creates an event only when that
cookie contains an affirmative analytics choice. No event is sent without a choice, after analytics is denied,
when Do Not Track (DNT) or Global Privacy Control (GPC) is enabled, or for detected bots. This means the first
page viewed before you make a choice is not captured retroactively.
Data: timestamp, IP address, page path without the query string, referrer, user agent/browser identifier and the country inferred by Vercel. Advertising click identifiers in a referrer are excluded when analytics — but not marketing — is the only optional category granted. The event is encrypted at application level and sent over an authenticated HTTPS connection from Vercel to a VPS controlled by us. The VPS uses a local RIPE database and a conventional reverse-DNS lookup to infer a possible organisation; it does not identify a person.
Purpose and legal basis: company-level audience analysis, improvement of the service and preparation of B2B sales activity, based on consent under Article 6(1)(a) GDPR. Withdrawing analytics consent through “Cookie settings” prevents every future event from this path.
Recipients: we perform the analysis ourselves; no outside sales-intelligence provider receives data through this self-hosted path. The VPS hosting provider may have technical access as a processor. The intended server location is Germany/EU. The provider, location, data-processing terms and production DNS setup must be confirmed against the live deployment before activation.
Retention: the raw event containing the IP address is deleted during the next nightly processing run, normally within about 24 hours, with a safety deletion no later than 7 days. The resulting company record contains no IP address. A binding deletion period for those IP-free company and page records must still be set and technically verified before activation.
Configuration: the self-hosted path stays disabled until HTTPS ingress, authentication and the encryption key are fully configured. Before activation, those transport controls, the nightly deletion job, seven-day maximum and the legal details above must be verified in production.
7. Your rights
Subject to the applicable requirements, you may request access, rectification, deletion, restriction, portability or object to processing. You may also lodge a complaint with a data-protection supervisory authority. For questions, email kontakt@visnakovs.de.