Privacy Policy & Cookie Policy
Last Updated: March 2026
1. Introduction
This Privacy & Cookie Policy explains how we (“we”, “us”, “our”) collect and process personal data when you visit and use the website anu‑kay.com.
We take the protection of your data seriously. All processing is carried out in accordance with:
- the EU General Data Protection Regulation (GDPR / DSGVO)
- the German Federal Data Protection Act (BDSG)
- the Telecommunications‑Telemedia Data Protection Act (TTDSG)
By using this website, you agree to the practices described in this policy.
2. Controller
Responsible for data processing:
Anu Kay
Email: info@anu-kay.com
3. Data We Collect
3.1. Server Log Files
When you access our website, the hosting provider automatically collects:
- IP address
- Date and time of access
- Name of requested file or page
- Referrer URL
- Browser type and version
- Operating system
- Amount of data transferred
- Access status
Purpose: website functionality, security, fraud prevention
Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
3.2. Contact Form & Email Contact
If you contact us, we process:
- Your name
- Email address
- Message content
Purpose: responding to inquiries
Legal basis: Art. 6(1)(b) GDPR
Retention: deleted when no longer necessary unless legally required otherwise
3.3. Newsletter Subscription
If you subscribe to updates or newsletters:
- First name
- Last name
- Email address
We use a double opt‑in process to confirm your subscription.
Purpose: sending news, updates, and publications
Legal basis: Art. 6(1)(a) GDPR (consent)
Withdrawal: possible at any time via unsubscribe link or by contacting us
4. Cookies & Similar Technologies
Our website uses cookies and similar technologies to enhance your experience.
Some are essential for basic functionality; others require your explicit consent.
You will be asked to grant consent via our cookie banner when you first visit the website.
5. Types of Cookies We Use
5.1. Essential Cookies
Required for core functionality such as security, navigation, and saving cookie settings.
- Legal basis: Art. 6(1)(f) GDPR
- Consent: not required
5.2. Preference / Functional Cookies
Allow the website to remember your settings (e.g., language or display preferences).
- Legal basis: Art. 6(1)(a) GDPR
5.3. Statistics / Analytics Cookies
Help us understand how visitors use the site (page views, time spent, interactions).
Data is anonymized where possible.
- Legal basis: Art. 6(1)(a) GDPR (consent)
5.4. Marketing / Tracking Cookies
Used for embedded media (e.g., YouTube) or third‑party tracking technologies.
Activated only after consent.
- Legal basis: Art. 6(1)(a) GDPR
6. Third‑Party Services
6.1. YouTube (Google Ireland Limited)
Our website uses embedded YouTube videos.
These are blocked until you actively consent to loading them.
Once consented, YouTube may collect:
- IP address
- Browser/device information
- Interactions with the video
- Cookies for analytics and marketing
Google Privacy Policy:
https://policies.google.com/privacy
6.2. Consent Management System (Cookie Banner)
We use a cookie‑consent tool that sets a cookie to remember your selected privacy preferences.
This cookie is essential and cannot be disabled.
7. Managing & Withdrawing Cookie Consent
You may:
- Accept all cookies
- Reject non‑essential cookies
- Customize cookie preferences
- Withdraw consent at any time
via the cookie banner or “Cookie Settings” link on the website.
You can also manage cookies in your browser settings.
8. Legal Basis for Cookies Under TTDSG
According to German TTDSG:
- Essential cookies may be stored without prior consent
- All others (analytics, marketing, tracking) require opt‑in consent
Our website follows these rules using a compliant cookie‑consent banner.
9. Third‑Country Data Transfers
Some data may be transferred outside the EU/EEA (e.g., when using Google/YouTube).
Such transfers occur only when:
- the EU Commission has issued an adequacy decision, or
- Standard Contractual Clauses (SCCs) are in place
10. Retention Periods
We store personal data only as long as necessary to fulfil the purposes described or as required by law.
After that, the data is deleted routinely.
11. Your Rights Under GDPR
You have the following rights:
- Right to access your data (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
Supervisory authority example (Germany/Hessen):
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
12. Data Security
We use appropriate technical and organizational security measures, including:
- TLS/HTTPS encryption
- Secure hosting environment
- Access restrictions
- Regular security assessments
These measures help protect your data against unauthorized access, loss, or misuse.
13. External Links
Our website may contain links to external sites.
This policy applies only to our website, not to third‑party websites.
We are not responsible for external content or privacy practices.
14. Changes to This Policy
We may update this Privacy & Cookie Policy to reflect changes in law, technology, or site functionality.
The most recent version will always be posted here.