Hanna Tempelhagen
  • About
  • Mindful Performance
  • Programmes
  • References
  • DE
  • EN
Free Consultation
  • About
  • Mindful Performance
  • Programmes
  • References
Free Consultation
  • DE
  • EN

Legal

Data Protection Declaration

Last updated: July 2026

Contents
  • 1. Data Controller
  • 2. Your Rights
  • 3. Right to Object (Art. 21 GDPR)
  • 4. Legal Bases for Processing
  • 5. Recipients of Personal Data
  • 6. Hosting
  • 7. SSL/TLS Encryption
  • 8. Fonts
  • 9. Newsletter
  • 10. Conferencing Tools Used
  • 11. Changes

1. Data Controller

The controller responsible for data processing on this website is:

The Mindful Spaces GmbH
Humboldtstr. 62
22083 Hamburg, Germany
Email: info@themindfulspaces.com

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).

Unless a more specific retention period is stated in this declaration, your personal data remains with us until the purpose for processing no longer applies. If you make a valid request for erasure or withdraw your consent, your data will be deleted unless we have other legally permissible grounds for retaining it (e.g. tax or commercial law retention periods).

2. Your Rights

Under the applicable statutory provisions, you have the right at any time to free-of-charge information about your stored personal data, its origin and recipients, and the purpose of the processing, as well as a right to have this data corrected or deleted.

You also have the right to request the restriction of the processing of your personal data — for example while we verify data you dispute, or if you prefer restriction of processing instead of deletion.

Many data processing operations are only possible with your express consent. You may withdraw consent you have already given at any time; the lawfulness of processing carried out before the withdrawal remains unaffected.

You have the right to receive data that we process automatically on the basis of your consent or in fulfilment of a contract, in a common, machine-readable format (right to data portability).

In case of breaches of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your workplace, or the place of the alleged infringement.

For all of this, as well as any further questions about data protection, feel free to contact us at any time.

3. Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

Where data processing is based on Art. 6(1)(e) or (f) GDPR, you have the right at any time, for reasons arising from your particular situation, to object to the processing of your personal data; this also applies to profiling based on these provisions. If you object, we will no longer process your affected data unless we can demonstrate compelling legitimate grounds that outweigh your interests, or the processing serves to assert, exercise or defend legal claims.

If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling connected with such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes.

4. Legal Bases for Processing

Where you have given consent to processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. Where your data is required for the performance of a contract or to carry out pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. Where processing is necessary to comply with a legal obligation, it is carried out on the basis of Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR. The relevant legal basis in each individual case is stated in the corresponding sections of this declaration.

5. Recipients of Personal Data

As part of our business activities, we work with various external parties. We only pass on personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so, where we have a legitimate interest in the disclosure under Art. 6(1)(f) GDPR, or where another legal basis permits the disclosure. When using processors, we only pass on personal data of our customers on the basis of a valid data processing agreement.

6. Hosting

We host the content of our website with the following provider:

All-Inkl

The provider is ALL-INKL.COM – Neue Medien Münnich, Inh. René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. For details, see All-Inkl’s privacy policy: all-inkl.com/datenschutzinformationen.

Use of this service is based on Art. 6(1)(f) GDPR — we have a legitimate interest in a reliable presentation of our website.

Data processing agreement: We have entered into a data processing agreement (DPA) for the use of this service. This agreement ensures that All-Inkl only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

7. SSL/TLS Encryption

For security reasons, and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the address bar of your browser changes from “http://” to “https://” and by the lock icon in your browser bar.

8. Fonts

The fonts used (Lora, Work Sans) are served locally from our own server. No connection is made to third-party servers.

9. Newsletter

If you would like to receive the newsletter offered on this website, we require an email address from you, as well as information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use the following provider to deliver the newsletter:

Brevo

This website uses Brevo to send newsletters. The provider is Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany, a subsidiary of Sendinblue SAS (Paris, France). Brevo is a service that can be used to organise and analyse the sending of newsletters, among other things. The data you enter for the purpose of receiving the newsletter is stored on Brevo’s servers.

Data analysis by Brevo: With the help of Brevo, we can analyse our newsletter campaigns — for example, whether a message was opened and which links were clicked. If you do not want your data analysed by Brevo, you must unsubscribe from the newsletter; we provide a corresponding link in every newsletter.

Brevo partly uses service providers outside the EU, which may result in your data being transferred across national borders. Brevo bases such transfers on a lawful basis (including EU standard contractual clauses). You can find Brevo’s privacy policy at: brevo.com/de/legal/privacypolicy.

Legal basis: Processing is based on your consent (Art. 6(1)(a) GDPR). You can withdraw this consent at any time, for example via the “unsubscribe” link in the newsletter.

Retention period: The data you provide for the purpose of receiving the newsletter is stored until you unsubscribe, and is then deleted from the distribution list. Your email address may subsequently be stored on a blocklist if this is necessary to prevent future mailings.

Data processing agreement: We have entered into a data processing agreement (DPA) for the use of Brevo. This agreement ensures that Brevo only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

10. Conferencing Tools Used

We use the following conferencing and appointment-scheduling tool:

Zoom

We use Zoom. The provider of this service is Zoom Communications Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For details on data processing, see Zoom’s privacy policy: explore.zoom.us/en/privacy. The transfer of data to the USA is based on the European Commission’s standard contractual clauses.

Data processing agreement: We have entered into a data processing agreement (DPA) for the use of this service. This agreement ensures that Zoom only processes the personal data of our website visitors according to our instructions and in compliance with the GDPR.

11. Changes to this Data Protection Declaration

We update this data protection declaration whenever legal requirements or the services we use change. The version published here always applies.

Hanna Tempelhagen
  • Legal Notice
  • Data Protection

Hanna Tempelhagen is a brand of The Mindful Spaces GmbH