Privacy Policy
Legal Disclaimer: This English translation is provided for informational purposes only. In the event of any discrepancies, only the original German version shall be legally binding. The official German Privacy Policy can be found here: → visanerd.de/datenschutz
1. Data Controller
visanerd.de – Marcellus Bartsch
c/o Online-Impressum.de #4905
Europaring 90
53757 Sankt Augustin
Germany
Email: [email protected]
2. Preamble
With the following privacy policy, we would like to inform you about the types of your personal data we process, for what purposes, and to what extent. This policy applies to all processing of personal data carried out by us, both in the context of providing our services and particularly on our websites and external online presences.
Last updated: 5 August 2026.
3. Security Measures
In accordance with legal requirements, we take appropriate technical and organizational measures (TOM) to ensure a level of protection appropriate to the risk. This includes the use of TLS/SSL encryption for secure data transmission (HTTPS).
4. Legal Basis for Processing
According to the GDPR, we process data based on:
- Consent (Art. 6 (1) (a) GDPR)
- Contract Performance (Art. 6 (1) (b) GDPR)
- Legal Obligation (Art. 6 (1) (c) GDPR)
- Legitimate Interests (Art. 6 (1) (f) GDPR)
5. Your Rights as a Data Subject
You have the following rights according to the GDPR:
- Right to Object: You can object to the processing of your data at any time.
- Right of Access: You can request information about your stored data.
- Right to Rectification: You can demand the correction of incorrect data.
- Right to Erasure: You can request the deletion of your data.
- Data Portability: You can request your data in a machine-readable format.
6. Specific Services & Webhosting
Our website is hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). We have concluded a data processing agreement with Hetzner to ensure your data is handled securely and in compliance with GDPR.
Cloudflare delivery, security, Turnstile and Web Analytics: Our website is delivered and protected through services provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Website traffic therefore technically passes through Cloudflare. Cloudflare processes in particular the IP address, requested URL, date and time, referrer, browser and device information, and security, routing and log data. Cloudflare Turnstile protects forms and processes against automated access; its script may load when a page is opened and Cloudflare may set technically necessary cookies such as “cf_clearance”. Cloudflare Web Analytics (RUM) is also active for privacy-friendly performance and reach measurement. Cloudflare states that RUM does not use cookies or persistent user identifiers and that the source IP received for transport is discarded at the nearest data centre rather than stored in the RUM database. Purposes: secure and fast delivery, DDoS and bot protection, and technical performance and reach measurement. Legal basis: legitimate interests (Art. 6(1)(f) GDPR); Section 25(2)(2) TDDDG for storage or access that is strictly necessary. See Cloudflare’s Privacy Policy, cookie information and Data Processing Addendum and Standard Contractual Clauses.
Contact & Inquiry Management
When you contact us through a form, by email or through another channel, we process the information you provide, in particular your name, contact details, message and any other voluntarily supplied content, in order to answer and handle your request.
Transactional email is sent primarily through Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany; Privacy Policy). STRATO (STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany; Privacy Policy) is used for mailbox operation or as a technical fallback. The address, content and metadata required to send, receive and deliver the message are processed.
If you click our WhatsApp link or contact us through WhatsApp, WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland, processes your telephone number, message content and connection data under its own terms. Merely viewing our contact page does not transmit data to WhatsApp. See the WhatsApp Privacy Policy. Legal bases: contract performance and pre-contractual steps (Art. 6(1)(b) GDPR) and legitimate interests in reliable communication (Art. 6(1)(f) GDPR).
Social Media (LinkedIn)
We maintain online presences on LinkedIn, Instagram, TikTok and YouTube to communicate with users and provide information about VisaNerd. Our website contains direct links only: it does not embed social feeds, advertising pixels or other content from these platforms. A platform provider receives the usual connection and usage data only when you click such a link or use our presence on that platform. The respective provider’s privacy information applies: LinkedIn, Instagram, TikTok and YouTube/Google.
Privacy-Friendly Reach and Function Measurement
We use our self-operated OpenSEO Analytics solution to measure page views and whether important contact and application processes function correctly. The tracker is delivered through our own e.visanerd.com domain, and the analysis is stored on a server operated by us at Hetzner Online GmbH in Germany. No data is transmitted to advertising networks.
We record the event type and time, the path of the page viewed, referrer domain and path, UTM campaign parameters where present, a random session identifier that applies only to the current page document, and technical or pseudonymous process references for explicitly marked form, download and process events. We do not collect form input, plain-text email addresses, content, DOM recordings or session replays. Network layers process the IP address for transport and security, but it is not written to our analytics database. OpenSEO Analytics uses no cookies, local storage or other persistent browser identifiers.
Event data is generally retained for 400 days. Purposes: reach measurement, improvement of our website and verification that contact and application processes function technically. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
7. Data Retention and Erasure
We delete personal data as soon as the purpose for its collection no longer exists or consent is withdrawn, provided that no legal retention obligations (e.g., 6 or 10 years for tax records) prevent deletion.