Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
GOBRAN People Development GmbHBonhoefferstr. 14
44287 Dortmund
Germany
Phone: +49 231 586 957 14
Email: info@gobran.de
Data-protection enquiries may be sent to info@gobran.de.
Processing principles
We process personal data only where necessary to operate the website securely, respond to an enquiry, take pre-contractual steps or provide communications requested by you.
Legal bases
- Article 6(1)(b) GDPR for enquiries relating to a contract or pre-contractual steps.
- Article 6(1)(f) GDPR for secure website operation and other business enquiries. Our legitimate interests are the secure provision of this website and reliable communication.
- Article 6(1)(a) GDPR where processing, in particular newsletter delivery, is based on your consent.
- Article 6(1)(c) GDPR where processing is required to meet a legal obligation.
Retention
Unless a specific period is stated below, we retain data only for as long as necessary for the relevant purpose. We then delete or anonymize the data unless statutory retention obligations or legitimate reasons relating to legal claims require continued storage.
This website does not use automated decision-making or profiling within the meaning of Article 22 GDPR.
Hosting, server logs and website security
This website is provided through Cloudflare Workers by Cloudflare, Inc. and protected by Cloudflare services for DNS, delivery and security. Cloudflare processes technical access data generated by operating the website as our processor.
When you visit a page, the data processed may include your IP address, the time and destination of the request, referrer URL, browser and device information, operating system, HTTP status, amount of data transferred, and technical security and usage data. The purposes are delivery, stability, troubleshooting and prevention of abusive access. The legal basis is Article 6(1)(f) GDPR.
Editorial content is maintained in a separate WordPress instance at cms.gobran.de, operated by RAIDBOXES. Visitor requests are not forwarded to the WordPress administration; published content is synchronized through protected technical processes.
Provider-side log data are processed only for as long as required for operation, security, troubleshooting and compliance with legal obligations. We currently conduct no additional audience measurement and maintain no additional personal visitor logs.
Recipients and international transfers
Cloudflare and its sub-processors may also process data outside the European Economic Area. Relevant transfers are based on an adequacy decision by the European Commission or appropriate safeguards, in particular the EU Standard Contractual Clauses under Article 46(2)(c) GDPR.
Cloudflare Data Processing Addendum ↗Cloudflare Privacy Policy ↗
Contacting us
If you contact us by email or through the contact form, we process the contact details and content you provide, such as your name, email address, organization, topic and message. We use this information solely to review and respond to your request and to coordinate any next steps.
The legal basis is Article 6(1)(b) GDPR where the request relates to a contract or pre-contractual steps, and Article 6(1)(f) GDPR in other cases. Recipients are the people responsible within GOBRAN and the hosting, CRM and email service providers technically required to handle the communication.
We transmit contact-form data to HubSpot for recording and handling enquiries in our CRM, based on the data-processing agreement agreed with HubSpot.
We use Resend, Inc. (USA) for the technical delivery of contact-form emails. Resend processes the contact details and content entered in the form as well as technical delivery data. Resend may process data in the United States and states that it relies on appropriate safeguards, in particular the EU Standard Contractual Clauses, for relevant transfers. We do not use open or click tracking for contact enquiries.
We use Cloudflare Turnstile, provided by Cloudflare, Inc., to protect the form against automated submissions. This involves the processing of technically necessary data such as the IP address, browser and device details, and interaction and security data. The processing serves our legitimate interest in preventing spam and misuse under Article 6(1)(f) GDPR. We additionally store only short-lived, HMAC-pseudonymized counters to limit repeated enquiries. The IP address is not stored in plain text in this rate-limit database, and the counters are deleted after no more than 48 hours.
Providing information is voluntary. Without a means of contacting you and the information required to understand the request, we may be unable to respond. We delete enquiry data once the matter is concluded unless statutory retention obligations or legitimate reasons require further storage.
Please do not send confidential coaching content, health data or other sensitive information through general contact channels.
Requesting CALIBRATE trial access
To process a trial-access request, we use your first name, last name and email address, together with any information you provide voluntarily. The purposes are to process the request, provide information about trial access and coordinate possible next steps. The legal basis is Article 6(1)(b) GDPR.
For the technical transmission of the request by email, we use Resend, Inc. (USA). The contact details provided in the form and technical delivery data are processed for this purpose. Resend may process data in the United States and states that it relies on appropriate safeguards, in particular the EU Standard Contractual Clauses, for relevant transfers.
The data are deleted once the request is concluded unless required for a trial or contractual relationship or subject to statutory retention obligations. Separate privacy information applies to subsequent use of the CALIBRATE platform. This website policy does not describe the processing of personal journals, assessments or AI requests within CALIBRATE.
External services and social networks
This website contains ordinary links to external services, in particular the CALIBRATE platform, LinkedIn and individual articles still hosted on gobran.de. No connection to LinkedIn is made before you click; the LinkedIn icon is served locally.
Only when an external link is opened does the relevant provider receive technically necessary access data such as the IP address. The provider is responsible for subsequent processing under its own privacy information. The CALIBRATE login and app involve separate data processing that must be described separately.
Your data protection rights
Subject to the applicable legal requirements, you have in particular the following rights:
- access to your personal data (Article 15 GDPR),
- rectification of inaccurate or incomplete data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- withdrawal of consent with future effect (Article 7(3) GDPR),
- objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR).
To exercise these rights, email info@gobran.de. You also have the right to lodge a complaint with a data protection supervisory authority. The authority generally responsible for us is:
State Commissioner for Data Protection and Freedom of Information North Rhine-WestphaliaKavalleriestraße 2–4
40213 Düsseldorf
Germany
www.ldi.nrw.de
Data security and updates
We use appropriate technical and organizational measures to protect personal data against loss, manipulation and unauthorized access. The website is transmitted over encrypted HTTPS connections. Complete protection of data transmitted over the internet cannot, however, be guaranteed.
We update this policy when the website, the services used or legal requirements change. The version published on this page is the applicable version.
Important distinction: This policy applies to the company website described here. Additional privacy information may apply to CALIBRATE, job applications, client projects, Impact Analyses or other independent processing activities.