1. Introduction
Thank you for your interest in our website. Protecting your personal data matters to us. Below we inform you, in line with Art. 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process when you visit our website, for what purposes, on what legal basis, and which rights you have.
This website (likakandel.com) is the website of Lika Kandel. The provider of the website and the controller within the meaning of the GDPR is VOXE.Studio (see section 2).
2. Controller
The controller for data processing on this website is:
VOXE.Studio
represented by Andrei Pertache
Radegundisstr. 3
86316 Friedberg
Germany
Phone: +49 176 621 70798
Email: business@voxe.studio
3. General information on data processing
We process personal data only to the extent necessary to provide a working website and our content and services. Processing is based on Art. 6(1) GDPR, in particular:
- consent (Art. 6(1)(a) GDPR), where you have given us consent; where information is stored on or read from your device, additionally § 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act),
- contract or pre-contractual measures (Art. 6(1)(b) GDPR),
- legal obligation (Art. 6(1)(c) GDPR), e.g. retention duties under commercial and tax law,
- legitimate interest (Art. 6(1)(f) GDPR), unless your interests or fundamental rights override it.
We pass your data to third parties only as described in this privacy policy. Where we use service providers in countries outside the EU or EEA (third countries), data is transferred only under the conditions of Art. 44 et seq. GDPR, for example on the basis of an adequacy decision of the EU Commission (such as the EU-U.S. Data Privacy Framework for certified US companies, adequacy decision of 10 July 2023) or of standard contractual clauses (Art. 46(2)(c) GDPR).
4. Hosting and content delivery (Cloudflare)
Our website is provided through the services of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA ("Cloudflare"). Our website is hosted on the Cloudflare Workers platform. Cloudflare operates a globally distributed server network for this.
When you visit our website, your requests are routed through Cloudflare's servers. Cloudflare processes in particular your IP address, the date and time of access, the page or file requested, the amount of data transferred, the referrer URL, browser type and version (user agent), the operating system and other technical connection and routing data. This data is needed to deliver our website, balance the load, and detect and fend off attacks (e.g. DDoS attacks or automated access by bots).
Data we need to store (e.g. newsletter signups and bookings in progress, see below) is kept in a Cloudflare database (Cloudflare D1) that runs and stores data exclusively in the European Union. Files are kept in Cloudflare storage (Cloudflare R2), which is also restricted to the European Union.
Server log files
When you visit our website, Cloudflare records technical logs of the requests to our website on our behalf (e.g. requested address, time, status code and technical request metadata). We use them to find errors and to keep the website stable and secure. They are not combined with other data sources. We do not write names, email addresses or message contents into our own logs. The logs are deleted automatically after seven days at the latest.
Request limits
To protect our forms against mass requests, we count how often requests are sent from one IP address to the contact form, the newsletter signup, the booking and the online withdrawal. For the contact form, the newsletter and the online withdrawal this is done with a counter at Cloudflare that expires after one minute at the most. For bookings we store the counter with your IP address (for IPv6 shortened to the first 64 bits) in our database; it is deleted after 48 hours at the latest.
Cookies
Our website itself sets no cookies and uses no analytics or advertising services. Where Cloudflare sets a technically necessary cookie as part of its security functions, such as __cf_bm (detection of automated access, expires after 30 minutes of inactivity) or cf_clearance (proof of a passed security check), it serves only the secure and stable operation of the website. An overview of the cookies Cloudflare uses is available at Cloudflare Cookies (opens in a new tab).
Legal basis and transfers to third countries
We use Cloudflare on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in providing our website securely, quickly and reliably. Storing these cookies or accessing information on your device is based on § 25(2) no. 2 TDDDG, as this is strictly necessary to provide the service you explicitly requested (use of our website); no consent is required for this.
As Cloudflare is a US company, a transfer of personal data to the USA cannot be ruled out. Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF). For certified companies there is an adequacy decision of the EU Commission of 10 July 2023 (Art. 45 GDPR). In addition, Cloudflare's contract terms provide for standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR), which Cloudflare relies on in particular if the certification lapses (Art. 44 et seq. GDPR). Information on the certification is available on the Data Privacy Framework website (opens in a new tab).
More information on how Cloudflare handles your data is available in Cloudflare's privacy policy (opens in a new tab).
Data processing agreement
We have concluded a data processing agreement with Cloudflare under Art. 28 GDPR. Cloudflare's Data Processing Addendum (opens in a new tab) is part of our service agreement with Cloudflare. It ensures that Cloudflare processes the personal data of our website visitors only on our instructions and in compliance with the GDPR. The data processed includes in particular IP addresses, connection and routing data, and usage and metadata.
5. SSL/TLS encryption
For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by "https://" in your browser's address bar.
6. Fonts and local storage in the browser
Our website uses fonts that are stored locally on our hosting provider's server. When you open our pages, no connection is made to servers of font providers or other third parties.
When you book an appointment, your browser keeps what you have entered so far (e.g. the chosen consultation, time and contact details) in the session storage (sessionStorage) of that browser tab. This way your details are not lost if you cancel the payment or reload the page. The data stays on your device and is deleted as soon as you close the tab. The legal basis is § 25(2) no. 2 TDDDG, as the storage is strictly necessary for the booking you requested, together with Art. 6(1)(b) GDPR.
7. Abuse protection (Cloudflare Turnstile)
To protect our forms (contact form, newsletter signup, booking and online withdrawal) against abuse by automated programs (bots), we use Cloudflare Turnstile, a service of Cloudflare, Inc. (address in section 4). Turnstile uses short technical tests in your browser to check in the background whether an input comes from a human; usually you do not have to solve a picture puzzle.
Turnstile is only loaded when you interact with one of these forms (e.g. click into an input field). Merely opening our pages makes no connection to Turnstile. From that moment on, Cloudflare processes technical characteristics of your connection and browser, in particular your IP address, the TLS fingerprint, the user agent, and our website's identifier (sitekey) and its origin. When you submit the form, our server sends the check result and your IP address to Cloudflare for verification. According to Cloudflare, Turnstile does not access your form entries and is not used to identify individuals, build profiles or serve advertising. For this, a script is loaded from challenges.cloudflare.com.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to protect our website and forms against spam and abusive automated access. Where information is stored on or read from your device, this is based on § 25(2) no. 2 TDDDG, as it is strictly necessary for the secure use of the form you requested.
Cloudflare processes this data as our processor under the data processing agreement mentioned in section 4. In addition, according to Cloudflare, it processes the data under its own responsibility to improve Turnstile's bot detection, based on its own legitimate interest. For the transfer to the USA, section 4 applies (EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses). More information is available in Cloudflare's Turnstile Privacy Addendum (opens in a new tab).
8. Sending email (Resend)
To send emails through our website (notifications from the contact form, booking and payment confirmations, confirmation emails and newsletter issues), we use the Resend service of Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA ("Resend"). Resend processes the recipient address, the content of the email and technical delivery data (e.g. time, delivery status, bounces and complaints).
Our emails are sent through Resend's European region (Ireland). According to Resend, account data, email metadata and logs are stored in the USA regardless. Resend is certified under the EU-U.S. Data Privacy Framework; in addition, the data processing agreement with Resend contains standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR).
We do not measure whether or when you open our emails or click links in them; Resend's open and click tracking is switched off.
The legal basis is the legal basis of the underlying processing (contact request, booking, payment or newsletter, see there) and Art. 6(1)(f) GDPR (our legitimate interest in reliable delivery). We have a data processing agreement with Resend (Art. 28 GDPR). More information: Resend's privacy policy (opens in a new tab).
9. Email inbox (Zoho Mail)
We run our business email inbox (e.g. work@likakandel.com) on Zoho Mail. The provider for customers in Germany is Zoho Corporation GmbH, II. Hagen 7, 45127 Essen, Germany ("Zoho"). When you email us or reply to one of our emails, and when messages from the contact form reach us, these messages are stored with your details in this inbox.
Our inbox is set up in Zoho's European data centre (Netherlands, with a backup site in Ireland). Access by Zoho group companies outside the EU (e.g. for technical support) cannot be ruled out; for this Zoho has agreed standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR).
The legal basis is Art. 6(1)(b) GDPR where your message relates to a contract or its preparation, and otherwise Art. 6(1)(f) GDPR (our legitimate interest in handling your message). We have a data processing agreement with Zoho (Art. 28 GDPR). More information: Zoho's privacy policy (opens in a new tab).
10. Contacting us
When you contact us through the contact form, by email or by phone, we process your details (e.g. name, email address, phone number and the content of your message) to handle your request and any follow-up questions. Required fields in the contact form are marked as such; without them we cannot handle your request.
We do not store messages from the contact form in a database on our website. They are sent through Resend (section 8) as an email to our inbox at Zoho Mail (section 9). To protect the form we use Cloudflare Turnstile (section 7) and request limits (section 4).
The legal basis is Art. 6(1)(b) GDPR where your request relates to the performance of a contract or is needed for pre-contractual measures, and otherwise Art. 6(1)(f) GDPR (our legitimate interest in handling requests effectively). We do not pass on this data without your consent, except to the service providers named in this privacy policy who work on our behalf (Cloudflare, Resend, Zoho).
Your data is deleted once your request has been fully handled and no statutory retention duties apply.
11. Booking (Cal.com) and video call (Google Meet)
On our website you can book a free intro call or a paid AI consultation. For this we process the details from the booking form: first and last name, email address, phone number, the chosen time and time zone, language, and your answers to the questions how you found us, what you are interested in and whether you are available for a call right now.
How it works. During the booking we keep a booking record in our database at Cloudflare (section 4). It is no longer used after 48 hours and is deleted for good in the next nightly cleanup. We manage the appointment itself with the scheduling service Cal.com of Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA ("Cal.com"). Our server sends your details directly to Cal.com; no Cal.com script or widget is loaded on our website. Cal.com first holds the chosen time, creates the appointment once the booking is complete and sends you a calendar invitation with the link to the video call. Using the link in your confirmation email, you can reschedule or cancel the appointment on a Cal.com page. Our own confirmations are sent through Resend (section 8).
Cal.com processes the data as our processor. According to Cal.com, it processes the data in the USA. Cal.com is certified under the EU-U.S. Data Privacy Framework; in addition, Cal.com uses standard contractual clauses of the EU Commission where needed. Cal.com's representative in the EU under Art. 27 GDPR is Felix Kolodziej (felix@cal.com). We have a data processing agreement with Cal.com (Art. 28 GDPR). More information: Cal.com's privacy policy (opens in a new tab).
Calendar and video call. Cal.com adds the appointment to our Google Calendar and creates a Google Meet link for the call. Both are Google services, provided for users in the European Economic Area by a Google group company based in Dublin, Ireland. Your name, email address and the appointment details are stored in our calendar. When you join the video call, Google processes the data needed to run it, in particular your IP address, device and connection data, your display name, and video and audio during the call. We do not record calls. A transfer to Google LLC in the USA is possible; Google LLC is certified under the EU-U.S. Data Privacy Framework. More information: Google's privacy policy (opens in a new tab).
Call back. If you state that you are available right now, we call you at the phone number you gave.
Proof for the paid AI consultation. For a paid AI consultation we keep a booking record in our database at Cloudflare (section 4) after the booking: name, email address, language, appointment and time zone, price, booking reference, the identifiers of the appointment at Cal.com and of the payment at Stripe, the version and time of your statement on starting before the withdrawal period ends, and any cancellation, withdrawal and refund. If you or we cancel the appointment at Cal.com, Cal.com tells our server so that we can issue a refund that is due. The legal basis is Art. 6(1)(b) GDPR (performing and unwinding the contract) and Art. 6(1)(c) and (f) GDPR (proof of the statement under § 356(5) no. 2 BGB, defence against claims).
Online withdrawal. If you withdraw from a contract through our withdrawal function ("Withdraw from contract"), we process your name, your email address, the booking reference or your description of the contract, your message and the time we received it. We store the declaration in our database at Cloudflare, send you the confirmation of receipt required by law by email (through Resend, section 8) and handle the withdrawal. The legal basis is Art. 6(1)(c) GDPR in conjunction with § 356a BGB, and Art. 6(1)(b) GDPR.
The legal basis is Art. 6(1)(b) GDPR (contract or pre-contractual measures). The questions on how you found us and what you are interested in are part of the booking form and help us prepare the call. Protection of the booking against abuse is covered in section 4 (request limits) and section 7 (Turnstile).
12. Payment processing (Stripe)
You pay for the AI consultation through Stripe Checkout, a payment page of the payment service provider Stripe Payments Europe, Limited, Ireland ("Stripe"). After you choose a time, we redirect you to Stripe's payment page. We send Stripe your email address, the booked service and an internal booking number. On the payment page Stripe collects the data needed for the payment (e.g. name, billing address, payment details) as well as device and connection data such as your IP address for fraud prevention. Payment details such as card numbers are processed only by Stripe and are not stored on our servers. Stripe creates a customer record with your email address for the payment; if you wish, you can save your payment method there for later payments. After the payment, Stripe tells our server whether it was successful. If a payment has to be refunded, we issue the refund through Stripe.
Stripe processes some of the data as an independent controller (e.g. to meet regulatory duties and to prevent fraud). A transfer to Stripe, LLC in the USA is possible; Stripe, LLC is certified under the EU-U.S. Data Privacy Framework, and Stripe's contract terms additionally provide for standard contractual clauses. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(c) and (f) GDPR (legal duties, fraud prevention). More information: Stripe's privacy policy (opens in a new tab).
13. Newsletter
When you subscribe to our newsletter, we process your email address to send it. We write to you at most twice a month about websites, automation and AI. Apart from your email address and your consent, no details are required.
Double opt-in and proof. Signup uses the double opt-in procedure: after you submit the form, you receive an email with a confirmation link that is valid for 48 hours. Only after you confirm do we add you to the list. To prove your consent, we store in our database at Cloudflare (section 4) your email address, the language, the form used, the version of the consent text, the time of signup, the time of confirmation and the status of your subscription. We do not store your IP address for this. If the signup is not confirmed, we delete the data after three days.
Download. Where we offer a free download, you receive it only together with the newsletter. We point this out in the form concerned; the download is sent by email after you confirm.
Sending. We send the newsletter through Resend (section 8). After you confirm, we add your email address there as a contact on our newsletter list. We do not measure opens or clicks.
Unsubscribing. You can unsubscribe at any time through the unsubscribe link in every email (one click, also directly through the unsubscribe function of your email program) or by sending us a message. You can withdraw your consent at any time with effect for the future.
Legal basis. The legal basis for sending the newsletter is your consent (Art. 6(1)(a) GDPR). The confirmation email, the storage of the proof and the blocklist are based on Art. 6(1)(f) GDPR; our legitimate interest is not to send unwanted emails, to be able to prove consent (Art. 5(2), Art. 7(1) GDPR) and to defend ourselves against claims.
Retention. We store your data for as long as you receive the newsletter. After you unsubscribe, we keep the proof of your consent and unsubscription until the end of the third calendar year after the year you unsubscribed (regular limitation period, §§ 195, 199 BGB (German Civil Code); Art. 17(3)(e) GDPR) and then delete it together with the contact at Resend. Addresses that triggered a spam complaint or are permanently undeliverable stay on a blocklist so they are not emailed again.
14. Links to social networks
Below our blog posts we offer links to share a post on LinkedIn or X. These are plain links; no data is sent to these networks when you visit our website. Only when you click a link are you taken to the provider's page, which then processes data under its own responsibility. More information is available in the providers' privacy policies: LinkedIn (opens in a new tab), X (opens in a new tab).
15. Retention
Unless this privacy policy names a more specific period, your personal data stays with us until the purpose of processing no longer applies or you request a justified deletion or withdraw your consent. Statutory retention periods (in particular under § 257 HGB (German Commercial Code) and § 147 AO (German Fiscal Code)) remain unaffected; in that case the data is deleted when these periods end. This applies in particular to records of paid bookings.
The main periods at a glance:
| Data | Retention |
|---|---|
| Technical logs at Cloudflare | seven days at the most |
| Request limit counters | one minute at the most (contact, newsletter) or 48 hours (booking) |
| Booking form entries in the browser | until you close the browser tab |
| Booking record in our database | 48 hours, then deleted in the next nightly cleanup |
| Proof of a paid AI consultation and online withdrawals | until the end of the third calendar year after the appointment or the receipt of the withdrawal (§§ 195, 199 BGB); records subject to tax retention longer (§ 147 AO) |
| Unconfirmed newsletter signup | three days |
| Proof of newsletter consent after unsubscribing | until the end of the third calendar year after unsubscribing |
| Messages and contact requests | until fully handled, subject to statutory retention duties |
16. Your rights
You have the following rights towards us regarding your personal data:
- right of access (Art. 15 GDPR),
- right to rectification (Art. 16 GDPR),
- right to erasure (Art. 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to withdraw consent with effect for the future (Art. 7(3) GDPR); the lawfulness of processing before the withdrawal remains unaffected.
Right to object (Art. 21 GDPR)
Where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation. Where your data is processed for direct marketing, you can object to this processing at any time without giving reasons.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de (opens in a new tab).
To exercise your rights, an informal message to the contact details under "Controller" above is enough.
17. Providing your data and automated decisions
You are not legally required to provide your data. Without the details marked as required, however, we cannot handle your request, your booking or your newsletter signup. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
18. Updates to this privacy policy
This privacy policy is dated October 2026. As our website develops, or because of changed legal or regulatory requirements, it may become necessary to update it. You can always find the current version at likakandel.com/en/datenschutz (opens in a new tab).