Long Range Century Cup
(Berater Manufaktur MK GmbH)
Controller
Berater Manufaktur MK GmbH
Mühlstr. 2, 65779 Kelkheim, Germany
Managing Director: Marcus Konitzny
Contact for privacy matters: Marcus.konitzny@berater-manufaktur.de
Introduction
This Privacy Policy explains how Berater Manufaktur MK GmbH (hereinafter “we”, “us”, “our”, or “Company”) processes personal data in connection with the Long Range Century Cup website and related services. We are the data controller under the EU General Data Protection Regulation (GDPR).
Personal data we collect and why
Contact form submissions
What we collect: the fields the form requests (typically name, email address and message text) and metadata required for email delivery.
How transmitted: contact form submissions are transmitted to us by e‑mail. Submitted data is stored and processed by us as the controller.
Purpose: to respond to inquiries and process requests.
Legal basis: Article 6(1)(b) GDPR (steps at the request of the data subject prior to a contract) and/or Article 6(1)(f) GDPR (our legitimate interest in handling enquiries). If processing will instead be based on consent, we will add a clear consent checkbox on the form.
Retention: contact messages are retained for up to 2 years by default (see section 5 on retention).
Hosting and server data (Strato)
Our website is hosted with Strato. Strato processes server and access data required to operate the website (e.g., server logs, IP addresses, error logs). Strato acts as our contract data processor (Auftragsverarbeiter). An order processing agreement (AVV / DPA) is in place.
Purpose: site operation, security, troubleshooting and defence against attacks.
Legal basis: Article 6(1)(f) GDPR (legitimate interest: operation and security of the website) and where applicable legal obligations.
We do not list Strato’s headquarters in this policy at your request; the AVV is active.
Google Analytics (analytics; currently included provisionally)
We plan to use Google Analytics (recommended: GA4). Google collects information about your use of the website (pages visited, duration, referrer, device/browser data). Google may set cookies and may process data outside the EU.
Purpose: measure and improve website performance and user experience.
Legal basis: typically consent (Article 6(1)(a) GDPR). Using analytics without consent may not be lawful for tracking that is not strictly necessary. We therefore recommend obtaining explicit consent via a cookie banner prior to setting analytics cookies.
Recommended configuration to increase privacy: use GA4, enable IP anonymisation, disable advertising features/remarketing, set minimal data retention (default suggested: 14 months or shorter), and require active consent before analytics cookies are set.
Retention: analytics data will be anonymised/aggregated where possible; user-level retention default is 14 months unless you instruct otherwise.
Social media links (Instagram, TikTok, YouTube)
The site will include plain hyperlinks to Instagram, TikTok and possibly YouTube. Plain hyperlinks do not load content from those providers on our pages; data exchange is limited to typical browser/referrer data when the link is clicked.
If you later decide to embed content (videos, posts, plugins), those embeds may cause the respective providers (Meta/Instagram, ByteDance/TikTok, Google/YouTube) to process visitor data and set cookies. Embeds generally require consent for non‑essential cookies. For now the site will only use plain links.
Cookies and similar technologies
We use cookies (and similar technologies) to operate the site and, if enabled, for analytics. Cookies strictly required for the site’s technical operation are set without consent. Cookies for statistics or marketing require prior user consent.
Cookie categories (example):
Necessary: essential site function (no consent required). Retention: session or short-term.
Statistics (e.g., Google Analytics): require consent. Retention: 14 months (default) or as configured.
Marketing (not used currently): require explicit consent.
We will implement a cookie consent mechanism and will not set analytics/marketing cookies before obtaining consent.
Data recipients / processors
Processors currently in use: Strato (hosting) — AVV in place.
If Google Analytics is used, Google Ireland Ltd and other Google entities may receive analytics data. Transfers outside the EEA may occur under Google’s transfer mechanisms.
Currently no mailing providers, payment processors, CRM or other third‑party processors are used. If such services are added in the future we will update this policy and list the providers and purposes.
Transfers outside the EU / EEA
Some third‑party providers (notably Google, YouTube, TikTok, Instagram) may transfer or process data outside the EU/EEA. Where transfers occur, the provider’s policies and safeguards (e.g., standard contractual clauses, adequacy decisions) apply. We will inform users and link to provider privacy policies where appropriate.
Data retention (defaults you asked to use)
Contact form messages: retained for up to 2 years unless deletion is requested earlier.
Server logs (Strato): retained according to Strato’s default operational policy (suggested retention: 30 days for raw logs; longer retention for security incidents as necessary). We will rely on Strato’s documented retention practices and our AVV.
Google Analytics: user‑level data retention set to 14 months (unless you instruct a different period). Aggregated statistics are retained as configured in GA.
Other categories: retention according to relevant legal or operational requirements and the provider’s policy. Data will be deleted or anonymised when no longer necessary for the purpose collected.
Your rights (GDPR)
You have the right to:
Request access to personal data concerning you.
Request correction of inaccurate personal data.
Request erasure of your personal data (right to be forgotten) where applicable.
Request restriction of processing in certain circumstances.
Receive personal data you provided in a structured, commonly used and machine‑readable format (data portability) where applicable.
Object to processing based on legitimate interests or for direct marketing.
Withdraw consent at any time (processing based on consent will no longer be lawful going forward from withdrawal).
To exercise any of these rights, contact: Marcus.konitzny@berater-manufaktur.de. We will respond without undue delay and in accordance with statutory time limits.
Right to lodge a complaint with a supervisory authority
If you believe your data protection rights have been violated you have the right to lodge a complaint with a supervisory authority. As our business is located in Hesse, the competent supervisory authority is the Hessian Data Protection Commissioner (Hessischer Beauftragter für Datenschutz und Informationsfreiheit). You can also contact the supervisory authority in the EU member state of your habitual residence.
Security
We apply technical and organisational measures to protect personal data (e.g., HTTPS/TLS, access controls, limited access rights, regular updates). Despite these measures no transmission over the internet is completely secure.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will be published on the website with the revision date.
Contact details
For questions about privacy or to exercise your rights, contact: Marcus.konitzny@berater-manufaktur.de
Google Analytics — short explanation and recommendation (you asked about difference)
Google offers two main generations of its analytics product: Universal Analytics (UA) and Google Analytics 4 (GA4). Universal Analytics properties stopped processing new hits in July 2023 and GA4 is the actively maintained product. For any new implementation we strongly recommend GA4.
Privacy recommendations for GA4:
Obtain explicit user consent before setting analytics cookies.
Enable IP anonymisation (if available) to reduce identifiability.
Disable advertising features and remarketing if you do not need them.
Configure shortest reasonable data retention (default suggested: 14 months).
Document the use of GA in your cookie banner and privacy policy and provide an opt‑out mechanism where possible.
Social media links (clarification)
Current approach: plain hyperlinks only to Instagram, TikTok and YouTube. Clicking such a link directs users to the external platform and may result in standard browser data being sent to those providers. We do not use embedded posts or social plugins at present; if that changes we will implement consent gating and update this policy.
Data Protection Officer (DPO)
We do not have a designated Data Protection Officer (DPO). For privacy matters please contact the controller at Marcus.konitzny@berater-manufaktur.de.
To provide you with the best possible experience, we use technologies such as cookies to store and/or access device information. If you consent to these technologies, we may process data such as browsing behaviour or unique identifiers on this website. If you do not give your consent or withdraw it, certain features and functions may be affected.