Legal
Privacy Policy
Last updated: July 2026
1. Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
Christian Moser Consulting GmbHIm Mediapark 5
50670 Köln, Germany
Email: cm@cmoser.com
Phone: +49 171 7450747
2. General Principles
We process personal data only to the extent necessary to provide a functioning website and our services. Personal data is processed either with the user's consent or where processing is permitted by law.
This website uses no tracking or analytics cookies. No user profiles are created and no data is shared with advertising networks.
3. Hosting and Server Log Files
Each time our website is accessed, our hosting provider automatically collects information transmitted by your browser, including:
- IP address of the requesting device
- Date and time of access
- URL requested
- Referring website (referrer)
- Browser type and operating system
- Data volume transferred and HTTP status code
This data is stored in server log files and is not combined with other data sources.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the technically error-free and secure delivery of the website.
Retention: Log files are deleted after no more than 30 days, unless a security-related event requires longer retention.
Hosting provider: This website is hosted by Hostingschmiede (a brand of Starter Hosting UG, haftungsbeschränkt), Germany.
Hostingschmiede processes server log files solely for the purpose of operating and securing the service. As the hosting provider is based in Germany, all data is stored and processed within the European Union. No transfer of personal data to third countries takes place through the hosting of this website.
For more information, see Hostingschmiede's Privacy Policy.
4. Self-Hosted Fonts
This website uses the typefaces DM Sans and Inter. Both fonts are stored locally on our server and loaded directly from it. No connection is made to external servers (e.g. Google Fonts). No personal data is transferred to third parties through the use of these fonts.
5. Contact by Email
If you contact us by email, the data you provide (your email address, and optionally your name and message) will be stored for the purpose of handling your enquiry and any follow-up questions.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Retention: Data is deleted once the enquiry has been fully resolved and no statutory retention obligations apply.
6. Podcast Guest Application (Waiting List)
On our podcast guest page you can apply to be considered as a guest. Depending on your answers to two short eligibility questions, you are either offered a booking (see Section 7) or invited to leave your details on a waiting list.
If you use the waiting-list form, we process the information you enter: your name, email address, your company and what it makes or delivers, a short description of you and your business, and your answers to the two eligibility questions. Your IP address is processed at the moment you submit, for spam protection (see Section 8).
Purpose: to review your application and to contact you by email about appearing on the podcast.
Legal basis: Art. 6(1)(a) GDPR (your consent, given by ticking the consent box before you submit). You can withdraw your consent at any time with effect for the future by emailing us; withdrawal does not affect processing already carried out.
Storage: submissions are sent to us by email and kept in a backup file on our server that only we can access. We keep them only as long as needed to consider your application and any follow-up, after which they are deleted on request or when no longer required.
7. Appointment Booking
For scheduling calls we use the booking tool Cal.com in its EU-hosted version (accessed via cal.eu, provided by Cal.com, Inc.). The calendar is embedded on our site and only loads once you reach the booking step. When you book, the details you enter (such as name, email address, company, and any further information requested) are transmitted to and processed by the provider on our behalf.
Legal basis: Art. 6(1)(b) GDPR (steps taken in connection with an appointment you request).
The EU-hosted service is designed to keep processing within the European Union. Please also see Cal.com's own privacy notice for details of their processing.
8. Spam Protection (Cloudflare Turnstile)
To protect the waiting-list form from automated abuse, we use Cloudflare Turnstile, a service of Cloudflare, Inc. (USA). Turnstile loads only when the form is shown to you and checks whether a request is likely to come from a person rather than a bot. For this, your IP address and technical information about your browser are transmitted to Cloudflare.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting our website and form from spam and misuse).
As Cloudflare is based in the USA, personal data may be transferred to a third country. Such transfers are safeguarded by the EU Standard Contractual Clauses. For more information, please see Cloudflare's own privacy policy.
9. Cookies
This website uses only technically necessary cookies required for the operation of the site. No marketing, tracking, or analytics cookies are used. Consent is not required for technically necessary cookies.
10. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR): You may request information about the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): Under certain conditions, you may request deletion of your data.
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR): You may object at any time to processing based on Art. 6(1)(f) GDPR.
To exercise your rights, please contact: cm@cmoser.com
11. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for North Rhine-Westphalia is:
Landesbeauftragte für Datenschutz und InformationsfreiheitNordrhein-Westfalen (LDI NRW)
Kavalleriestr. 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de
12. Changes to this Policy
This privacy policy is current as of July 2026. As our website evolves or legal requirements change, it may be necessary to update this policy. The latest version will always be available on this page.