Skip to content

Privacy Policy

  1. Introduction

This website is www.midlifetoolkit.com

Below, we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you can understand what happens to your data.

  1. General Information

2.1 Processing of Personal Data and Other Terms

Data protection applies to the processing of personal data. Personal data means any data that can be used to identify you personally. This includes, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently using. Such data is processed whenever something is done with it. For example, the IP address is transmitted by your browser to our provider and automatically stored there. This constitutes processing (pursuant to Art. 4 No. 2 GDPR) of personal data (within the meaning of Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

2.2 Applicable Regulations/Laws – GDPR, BDSG and TDDDG

The scope of data protection is governed by law. In this case, the relevant laws are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as national law.

In addition, the TDDDG supplements the provisions of the GDPR where the use of cookies is concerned.

2.3 The Controller

The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

You can contact the controller at:

shannon [at] midlifetoolkit.com

2.4 How Data Is Generally Processed on This Website

As already explained, certain data (e.g. IP addresses) is collected automatically. This data is primarily required for the technical provision of the website. If we use personal data beyond this or collect other data, we will inform you accordingly or ask for your consent.

You provide other personal data to us knowingly.

You will find more detailed information below.

2.5 Your Rights

The GDPR grants you extensive rights. These include, for example, the right to obtain free information about the origin, recipients and purpose of your stored personal data. You may also request the rectification, restriction or deletion of this data, or lodge a complaint with the competent data protection supervisory authority. You may withdraw consent you have given at any time.

You will find details of these rights and how to exercise them in the final section of this Privacy Policy.

2.6 Data Protection – Our View

For us, data protection is more than just an inconvenient obligation. Personal data is valuable, and careful handling of this data should be a matter of course in our digital world. As a website visitor, you should also be able to decide for yourself what happens to your data, when it happens and who processes it. We therefore undertake to comply with all applicable legal requirements, collect only the data we need and, of course, treat it confidentially.

2.7 Disclosure and Deletion

The disclosure and deletion of data are also important and sensitive issues. We would therefore like to briefly explain our general approach in advance.

Data is disclosed only where there is a legal basis for doing so and only where such disclosure is unavoidable. This may be the case in particular where a service provider acts as a processor and a data processing agreement pursuant to Art. 28 GDPR has been concluded.

We delete your data when the purpose and legal basis for processing no longer apply and no other legal obligations prevent deletion. Art. 17 GDPR also provides a useful overview of this.

Please refer to this Privacy Policy for all further information and contact the controller if you have specific questions.

2.8 Hosting

This website is hosted on our own servers. The personal data collected on this website is stored on our servers. This includes automatically collected and stored log files (see below for further details), as well as any other data provided by website visitors.

The legal basis for processing is Art. 6(1)(a), (b) and (f) GDPR and Section 25(1) TDDDG, insofar as consent covers the storage of cookies or access to information on the website visitor’s or user’s terminal device within the meaning of the TDDDG.

We process only such data as is necessary to fulfil our service obligations.

2.9 Legal Bases

The processing of personal data always requires a legal basis. Art. 6(1), first sentence, GDPR provides for the following possibilities:

  1. a) the data subject has given consent to the processing of their personal data for one or more specific purposes;
  2. b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  3. c) processing is necessary for compliance with a legal obligation to which the controller is subject;
  4. d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  5. e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  6. f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In the following sections, we will specify the applicable legal basis for each type of processing.

  1. What Happens on Our Website

When you visit our website, we process personal data relating to you.

To protect this data as effectively as possible against unauthorised access by third parties, we use SSL and TLS encryption. You can recognise an encrypted connection by the https:// prefix or a padlock symbol in your browser’s address bar.

Below, you will find out which data is collected when you visit our website, for what purpose and on what legal basis.

3.1 Data Collection When Accessing the Website

When you access the website, information is automatically stored in server log files. This includes the following information:

  • Browser type and browser version
    • Operating system used
    • Referrer URL
    • Host name of the accessing computer
    • Time of the server request
    • IP address

This data is temporarily required so that we can display our website to you reliably and without disruption. In particular, the data is used for the following purposes:

  • Website system security
    • Website system stability
    • Website troubleshooting
    • Establishing a connection to the website
    • Displaying the website

The data is processed pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in processing this data, in particular our interest in the functionality and security of the website.

Where possible, this data is stored in pseudonymised form and deleted once the relevant purpose has been fulfilled.

Where the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception applies if a security-related event occurs. In this case, the server log files are stored until the security-related event has been resolved and fully investigated.

Apart from this, the data is not combined with other data.

3.2 Data Processing Through User Input

3.2.1 Data Collected by Us

We offer the following service on our website: contact form.

For this purpose, we collect the following data:

  • Name
    • Email address
    • Name, email address

The legal basis for this data processing is Art. 6(1)(b) GDPR.

The data is deleted as soon as the respective purpose no longer applies and deletion is permitted under the applicable legal requirements.

3.2.2 Contacting Us

  1. a) Contact Form

WPForms

Our website uses the WPForms contact form, a plugin provided by WPForms LLC, 400 Executive Center Dr. Suite 208, West Palm Beach, FL 33401, United States, which enables the creation and provision of forms for contact enquiries, feedback, newsletter subscriptions and other interactions. All information entered by persons completing the contact form, such as name, email address, message content and, where applicable, telephone number and other form fields, is processed. Depending on the website configuration, technical data such as IP address and browser information (user agent) may also be collected. This data is processed for the purpose of handling contact enquiries, customer communication and lead generation and, where applicable, for registration, order processing or feedback, depending on the type of form provided. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to entering into or performing a contract, and Art. 6(1)(f) GDPR on the basis of our legitimate interest in effective communication. Where explicit consent has been given (e.g. for a newsletter), Art. 6(1)(a) GDPR applies. Where form functions use cookies for functionality, analytics or tracking purposes, this takes place only with consent (legal basis: Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG); however, WPForms does not set cookies in its default settings. According to the current state of information, WPForms does not transfer personal data to third countries, as form content is stored exclusively on the website’s own web server; WPForms LLC, as the provider, does not have access to the form data. The stored data is deleted as soon as it is no longer required for the stated purposes, at the latest upon an explicit request or once applicable statutory retention periods no longer apply. Further information is available in the WPForms privacy policy at https://wpforms.com/privacy/.

  1. b)

hCaptcha

We use hCaptcha, a service provided by Intuition Machines, Inc., to protect our website and contact form against spam and abusive automated requests.

When hCaptcha is loaded, a connection to servers operated by Intuition Machines, Inc. is established. In this process, personal data such as your IP address and information about your browser and device may be processed to determine whether a request is made by a human user.

The use of hCaptcha is based on our legitimate interest in protecting our website against spam and misuse in accordance with Article 6(1)(f) GDPR.

Where Intuition Machines, Inc. processes personal data on our behalf, a Data Processing Agreement has been concluded in accordance with Article 28 GDPR.

 

3.3 Analytics and Tracking Tools

3.4 Social Media Plugins

3.5 Social Media Profiles

In addition to our website, our company is also present on social networks. We use these profiles to present our company and to make it possible for people to contact us.

We also use social media to place advertisements and job postings.

Below, we explain which data we and the respective social network process when you visit and interact with our profile.

 

Instagram

We operate an Instagram profile. This social media platform is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Interaction with Our Company Profile

When you visit our Instagram profile and interact with us through it, we process personal data. This includes, on the one hand, data made publicly available on the profile and, on the other hand, personal data contained in posts, comments or direct messages sent to us. Through interactions such as liking or sharing, we can view the user profile together with its public information. The legal basis for this processing is Art. 6(1)(f) GDPR. We have a legitimate interest in providing relevant and interesting content and in enabling the use and functionality of our Instagram profile. Where an enquiry is connected with the performance of a contract or is necessary in order to take steps prior to entering into a contract, our processing is based on Art. 6(1)(b) GDPR.

 

Insights

As explained in Meta’s Privacy Policy under ‘How do we use your information?’, Meta also collects and uses information to provide analytics services, known as Insights, to page operators. This also applies to our Instagram profile. Insights consist of aggregated statistics generated on the basis of certain interactions by visitors with pages and the content associated with them, and these interactions are logged by Meta’s servers. This includes, among other things, information about how many people see and interact with our products, services or content, how people interact with our content, websites, apps and services, and which groups of people interact with our content or use our services.

Meta provides us with aggregated reports and insights that allow us to assess how well our content, features, products and services are performing. We do not receive access to personal data, only to the aggregated reports. To analyse reach, we can select certain settings or apply filters relating to a particular period, a specific post or demographic groupings. This data is anonymised. We are therefore unable to draw conclusions about specific individuals.

This data is processed for the purpose of analysing our reach and adapting our content and advertisements to users’ interests. The processing is based on our legitimate interest pursuant to Art. 6(1), first sentence, point (f) GDPR. Where personal data is processed in connection with Insights, the processing is carried out under joint controllership with Meta pursuant to Art. 26(1) GDPR.

 

Processing of Personal Data and Cookies by Meta

When an Instagram page is accessed, the IP address assigned to the terminal device is transmitted to Meta. According to Meta, this IP address is anonymised in the case of German IP addresses. Meta also stores information about its users’ terminal devices (e.g. in connection with the ‘login notification’ function); this may enable Meta to associate IP addresses with individual users. If you are currently logged in to Instagram, a cookie containing your Instagram identifier is stored on your terminal device. This enables Meta to determine who visited and used the page. Meta buttons embedded in websites may also allow Meta to record your visits to those websites and associate them with your Instagram profile. Based on this data, content or advertising may be personalised.

  1. Other Important Information

Finally, we would like to provide you with detailed information about your rights and explain how you will be informed of changes to data protection requirements.

4.1 Your Rights in Detail

4.1.1 Right of Access under Art. 15 GDPR

You may request information as to whether personal data relating to you is being processed. If this is the case, you may request further information about the nature and manner of the processing. A detailed list can be found in Art. 15(1)(a) to (h) GDPR.

4.1.2 Right to Rectification under Art. 16 GDPR

This right includes the correction of inaccurate data and the completion of incomplete personal data.

4.1.3 Right to Erasure under Art. 17 GDPR

This so-called ‘right to be forgotten’ gives you the right, under certain conditions, to request that the controller delete your personal data. This generally applies where the purpose of the data processing no longer exists, where consent has been withdrawn or where the original processing took place without a legal basis. A detailed list of grounds can be found in Art. 17(1)(a) to (f) GDPR. In addition, this ‘right to be forgotten’ corresponds with the controller’s obligation under Art. 17(2) GDPR to take appropriate measures to achieve the general erasure of the data.

4.1.4 Right to Restriction of Processing under Art. 18 GDPR

This right is subject to the conditions set out in Art. 18(1)(a) to (d) GDPR.

4.1.5 Right to Data Portability under Art. 20 GDPR

This provision governs the fundamental right to receive one’s own data in a commonly used format and to transmit it to another controller. However, this applies only to data processed on the basis of consent or a contract pursuant to Art. 20(1)(a) and (b), and only where this is technically feasible.

4.1.6 Right to Object under Art. 21 GDPR

You may generally object to the processing of your personal data. This applies in particular where your interest in objecting overrides the controller’s legitimate interest in the processing and where the processing relates to direct marketing and/or profiling.

4.1.7 Right Not to Be Subject to Automated Individual Decision-Making under Art. 22 GDPR

You generally have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. This right is, however, subject to the limitations and additional provisions set out in Art. 22(2) and (4) GDPR.

4.1.8 Further Rights

The GDPR includes extensive rights relating to the notification of third parties as to whether and how you have exercised your rights under Art. 16, 17 and 18 GDPR. This applies, however, only insofar as such notification is possible or can be carried out with reasonable effort.

We would also like to remind you of your right to withdraw consent you have given under Art. 7(3) GDPR. The lawfulness of processing carried out before the withdrawal is not affected.

We would also like to draw your attention to your rights under Sections 32 et seq. BDSG, which largely correspond in substance to the rights described above.

4.1.9 Right to Lodge a Complaint under Art. 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of personal data relating to you infringes this Regulation.

  1. What If the GDPR Is Abolished Tomorrow or Other Changes Occur?

This Privacy Policy is current as of 22 July 2026. From time to time, it may be necessary to amend the content of this Privacy Policy in order to respond to factual or legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the amended version in the same place and recommend that you review the Privacy Policy regularly.