Skip to content
Momentum Advisory Momentum Advisory Management consultancy
Menu
Legal

Privacy & Data Protection

Data protection for sensitive business conversations: this page explains how Momentum Advisory processes personal data, which infrastructure and providers may be involved, how consent is controlled and how you can exercise your rights.

Advisory discussion about privacy governance and data flows in a modern office.

Privacy at a glance

The essentials for visitors, customers, legal teams and procurement stakeholders.

Controller

Momentum Advisory GmbH, Kieler Str. 72, 24119 Kronshagen, Germany. Email: info@momentumadvisory.de, phone: +49 431 556062-00.

Privacy contact

Please send privacy enquiries and data subject rights requests to datenschutz@momentumadvisory.de.

Main processing contexts

Website, contact forms, downloads, consultation enquiries, account portal, checkout, invoices, email communication and internal lead and CRM processes.

European-oriented infrastructure

We use a technical architecture with European-oriented infrastructure and avoid unnecessary third-party data flows.

Consent control

Optional analytics or marketing functions are activated only where consent is required and has been given.

No external tracking suites

We do not use Google Tag Manager, Google Analytics or Microsoft/Bing tracking scripts on this website.

Your rights

You may request access, correction, erasure, restriction, portability, objection and withdrawal of consent.

Procurement documentation

For client projects, processor relationships or procurement checks, we can provide appropriate data protection information.

Our privacy principles

We process personal data under the GDPR, the German TDDDG and the principle that sensitive business information should be handled only for clear, traceable purposes.

Data minimisation

We ask for and process only the data that is reasonably necessary for the relevant purpose.

Purpose limitation

Personal data is used for website operation, communication, downloads, account portal, checkout, support, business relationships and consent management.

Responsible infrastructure

For hosting, backend, database, email, security and monitoring, we focus on security, availability and appropriate provider selection.

Consent-based optional services

Optional tracking or marketing is not activated without the consent required for the relevant function.

Transparent provider use

Where providers are involved, we describe the categories and relevant providers transparently.

DPA-ready collaboration

For client projects and procurement checks, we can discuss data protection information, TOMs and contractual documentation.

Processing contexts

This overview summarises what personal data may be processed in typical website and customer processes.

The concrete processing depends on which functions you use and which information you provide voluntarily.
ContextDataPurpose and legal basisRetention
Website delivery and security logsIP address, timestamps, URL, referrer, browser, operating system, status code and technical connection data.Website delivery, IT security, troubleshooting and abuse prevention on the basis of Art. 6(1)(f) GDPR; where terminal-device access is involved, the TDDDG may also apply.Only for as long as required for security, troubleshooting and system operation.
Cookies, consent and optional measurementConsent status, technical identifiers, local storage information and, where consent is given, usage or interaction data.Website operation, consent documentation and optional internal analytics or marketing measurement on the basis of the TDDDG, Art. 6(1)(a) or Art. 6(1)(f) GDPR.Only for as long as required to document choices, operate the site or perform legitimate evaluation.
Contact forms, downloads and consultation enquiriesName, company, email, phone number, role, message, topic, requested resource and voluntary project information.Handling enquiries, providing requested resources, preparing conversations and initiating business relationships on the basis of Art. 6(1)(b), Art. 6(1)(f) or Art. 6(1)(a) GDPR.Enquiry and lead data is reviewed and deleted or anonymised when no longer needed and no statutory reason prevents this.
Account portal, account and protected downloadsAccount and login data, sessions, permissions, download entitlements, activity and security logs, support information.Secure access, contract performance, access control, download delivery, support and documentation on the basis of Art. 6(1)(b) and Art. 6(1)(f) GDPR.Only for as long as the account, contract, entitlement, security interest or statutory obligation requires.
Checkout, payments and invoicesName, company, billing address, email, product, order, payment status, transaction metadata and invoice data.Purchase processing, digital delivery, invoicing, tax obligations, support and fraud prevention on the basis of Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f) GDPR.Purchase and invoice data is retained in line with statutory commercial, tax and documentation obligations.
Email, CRM and lead managementContact details, communication content, enquiry and status information, project notes, consent or communication preferences.Communication, follow-up, customer relationship management and internal documentation on the basis of Art. 6(1)(b) and Art. 6(1)(f) GDPR.Data is periodically reviewed and deleted, anonymised or restricted when no longer required.

Infrastructure and providers

We operate the website and related functions through a multi-layer technical architecture. External providers are used only where required for operation, communication, payment, security or actively started external media content.

Website, hosting and backend

Hosting and infrastructure may include Hetzner and IONOS. This covers web frontend, API backend, database, reverse proxy, security, monitoring and backups.

Email and communication

Email communication may be processed through Postale.io and internal systems to handle enquiries, support and business communication reliably.

Internal CRM, lead and consent systems

Forms, downloads, consent logs, leads, customer relationships and portal processes are processed through Momentum-owned backend components.

Checkout and payments

For digital purchases, Mollie is used as payment provider. We do not receive full payment card details unless the checkout expressly states otherwise.

Embedded YouTube videos

Some pages may embed YouTube videos in privacy-enhanced mode. The player is loaded only when you actively start the video; this may transfer data to YouTube/Google.

Your rights

You can exercise your rights at any time by contacting datenschutz@momentumadvisory.de or info@momentumadvisory.de. We respond to data subject requests in accordance with the statutory deadlines.

Access

You may request information about which personal data we process about you.

Correction

You may request correction of inaccurate or incomplete personal data.

Erasure and restriction

You may request erasure or restriction of processing where the statutory requirements are met.

Portability

You may request certain data in a structured, commonly used and machine-readable format.

Objection

Where processing is based on legitimate interests, you may object on grounds relating to your particular situation.

Withdrawal and complaint

You may withdraw consent with effect for the future and lodge a complaint with a data protection supervisory authority.

Objection, supervisory authority and automated decisions

Changes to this privacy policy