Privacy Policy

Last updated: 27 July 2026

This Privacy Policy applies to the website yeliq.com and, where expressly stated, to interactions relating to our products and services.

1. Controller

Human Context Systems (Inh. Johannes Wicht)
Fabriciusstraße 59, 65933 Frankfurt, Germany
Email: team@yeliq.com

2. Contact for data protection inquiries

Email: privacy@yeliq.com

3. Data Protection Officer

We have not appointed a Data Protection Officer. You can contact us about data protection matters at privacy@yeliq.com.

4. General information and sources of data collection

We process personal data when you visit our website, use forms, request content, or interact with our products and services.

We process data only where this is required for operation, security, communication, pre-contractual steps, legal obligations, or consent you have given.

5. Categories of personal data

Depending on the interaction, we may process in particular:

  • technical access data such as IP address, date/time, URL, referrer, user agent, status codes, and request IDs,
  • contact and form data such as name, email address, organization, subject, message, and requested content,
  • consent records such as time, language, version, and text of the consent,
  • optional website analytics data such as page views, clicks, scroll depth, time on page, session ID, visitor ID, and basic campaign parameters.

6. Hosting, delivery, and server logs

Processed data:
When you visit the website, hosting and infrastructure providers may process technical access data, in particular IP address, date/time, URL accessed, referrer, user agent, status codes, and technical metadata.

Purposes:
Website delivery, operation, IT security, error analysis, and prevention of misuse or attacks.

Legal basis:
Art. 6(1)(f) GDPR (legitimate interest in secure and functional operation).

Recipients:
Vercel for hosting/CDN/deployment and Supabase for database and backend functions of the website.

Third-country transfers:
Where service providers process data outside the EU/EEA, we rely on appropriate safeguards, such as Standard Contractual Clauses or an adequacy decision.

Storage period:
Server logs are generally retained for up to 30 days unless longer retention is required for security investigation.

7. Optional website analytics after consent

We use optional, privacy-conscious website analytics only after you have given consent. Without consent, analytics does not start; server-side tracking requests without consent are discarded.

Processed data:
Page views, clicks on explicitly marked elements, scroll depth, time on page, section times, form interactions, session ID, optionally a pseudonymous visitor ID, referrer as origin only, and UTM parameters only for source, medium, and campaign.

Data not stored:
In our analytics table, we do not store IP address, user agent, email address, account ID, or cross-site advertising profiles. IP address and user agent may still be processed independently in technical server logs.

Local storage:
Your consent choice is stored in the browser. If you consent, we use a pseudonymous visitor ID in local storage and session IDs in session storage. If you withdraw consent, future analytics collection stops and local tracking storage is removed.

Purposes:
Improving the website, content, navigation, and capacity planning.

Legal basis:
Art. 6(1)(a) GDPR (consent).

Storage period:
Raw data in `web_events` is deleted after no more than 180 days. Aggregated statistics without direct personal reference may be retained for longer.

8. Contact forms and gated content

If you use a form or request a download link, we process the data you enter to handle your request, provide the requested content, and keep a record of your consent.

Processed data:
Name, email address, organization, subject, message, requested content, page, request ID, consent text, consent version, and language.

Recipients:
Supabase for storing the request and Resend for sending notifications or download emails.

Legal basis:
Art. 6(1)(b) GDPR (pre-contractual steps/communication), Art. 6(1)(f) GDPR (efficient handling and record keeping), and, where applicable, Art. 6(1)(a) GDPR (consent).

Storage period:
Form data is generally retained for up to 12 months after entry unless legal obligations or legitimate documentation interests require longer retention.

9. Optional consent to marketing contact

If you expressly consent to marketing contact, we may use your contact details to occasionally inform you about yeliq.

Legal basis: Art. 6(1)(a) GDPR (consent). We keep a record of your consent on the basis of Art. 6(1)(f) GDPR.

Withdrawal: You can withdraw your consent at any time with effect for the future, for example by email to privacy@yeliq.com.

10. External links

Our website contains links to external services, for example for scheduling appointments. If you click such a link, you leave our website. The respective provider is responsible for data processing on the linked pages.

11. Your rights

Subject to the requirements of the GDPR, you have in particular the following rights:

  • access (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • objection to processing based on legitimate interests (Art. 21 GDPR),
  • withdrawal of consent with effect for the future (Art. 7(3) GDPR),
  • complaint with a data protection supervisory authority (Art. 77 GDPR).

To exercise your rights, please contact us at privacy@yeliq.com. In some cases, we may need to verify your identity to protect your data.

12. Updates

We will update this Privacy Policy if the website, our processes, or legal requirements change.