Privacy Policy

As of: February 14, 2026

We take the protection of your personal data very seriously. This privacy policy informs you about the type, scope and purpose of the processing of personal data on our website (www.slaide.de).

Note: A separate privacy policy applies to the use of our web application (app.slaide.de), which you can find in the web application under "Data Protection".

1. Responsible Entity (Controller)

The entity responsible for data processing on this website (www.slaide.de) is: Nathalie Scholl Slaide UG (haftungsbeschränkt) Neckarstraße 10 74257 Untereisesheim Germany Email: info@slaide.de Phone: +49 172 8812969

2. Data Protection Officer

We have not appointed a data protection officer, as we do not meet the statutory requirements for this.

3. General Information on Data Processing

3.1 Scope of processing of personal data

We process personal data of our users only insofar as this is necessary to provide a functional website and our content and services. The processing of personal data takes place regularly only after the user's explicit consent.

Insofar as we obtain the consent of the data subject for processing operations of personal data, Art. 6 Para. 1 lit. a EU General Data Protection Regulation (GDPR) serves as the legal basis. For the processing of personal data necessary for the fulfillment of a contract to which the data subject is a party, Art. 6 Para. 1 lit. b GDPR serves as the legal basis. This also applies to processing operations necessary for carrying out pre-contractual measures. Insofar as processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Art. 6 Para. 1 lit. c GDPR serves as the legal basis. If processing is necessary to protect a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not outweigh the first-mentioned interest, Art. 6 Para. 1 lit. f GDPR serves as the legal basis.

3.2 Legal basis for processing

4. Provision of the website and creation of log files

4.1 Description and scope of data processing

Every time our website is called up, server log files are automatically created by our hosting provider (Vercel). These contain technical data required for the provision of the website. The following data is stored automatically:

  • IP address of the calling computer
  • Date and time of access
  • Requested URL and HTTP method
  • HTTP status code
  • Amount of data transferred
  • User agent (browser and operating system)

In addition, we use rate limiting via the Upstash service. Your IP address is temporarily stored here to prevent abuse. Order processing contracts (AVV) in accordance with Art. 28 GDPR have been concluded with Vercel and Upstash. Data may be processed in the USA (see Section 15).

4.2 Legal basis

The legal basis is Art. 6 Para. 1 lit. f GDPR (legitimate interest in security and functionality).

4.3 Storage duration

Log files are deleted after seven days at the latest, unless there is a security incident.

5. Contact Form and Email Inquiries

If you send us inquiries via contact form or email, your details will be stored for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent. The legal basis is Art. 6 Para. 1 lit. b GDPR (contractual/pre-contractual measures) or Art. 6 Para. 1 lit. f GDPR (legitimate interest in processing inquiries).

6. Appointment Booking via Cal.com

For online appointment booking, we use the service Cal.com. The provider is Cal.com, Inc., 152 San Francisco St, San Francisco, CA 94133, USA. When booking, data such as name, email address and the desired appointment are processed. A data processing agreement (DPA) based on standard contractual clauses has been concluded with Cal.com.

7. Vercel Analytics and Speed Insights

We use Vercel Analytics and Speed Insights for statistical evaluation of visitor numbers and to optimize website performance. These services are provided by Vercel Inc. Data is generally processed anonymously.

8. Content Security Policy (CSP) Reports

To ensure the security of our website, we use CSP reporting. In the event of security breaches (e.g. XSS), your browser sends an anonymized report to our API to inform us of potential attacks.

9. Rate Limiting (Upstash)

To protect against abuse and DDoS attacks, we use Upstash for rate limiting. Your IP address is briefly processed to limit the number of requests per time period.

10. Email Dispatch (Resend)

For the delivery of transactional emails (e.g. whitepaper download), we use the service Resend. The provider is Resend Labs Inc., 2261 Market St #4039, San Francisco, CA 94114, USA.

11. Cookies

We predominantly use technically necessary cookies required for the operation of the website. Tracking cookies are only set after your explicit consent (opt-in).

12. Rights of the Data Subject

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights against the controller:

  • Right to Information (Art. 15 GDPR)
  • Right to Rectification (Art. 16 GDPR)
  • Right to Erasure (Art. 17 GDPR)
  • Right to Restriction of Processing (Art. 18 GDPR)
  • Right to Data Portability (Art. 20 GDPR)
  • Right to Object (Art. 21 GDPR)
  • Right to Withdraw Consent (Art. 7 Para. 3 GDPR)
  • Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)

13. Data Security

We use the SSL procedure in connection with the highest encryption level. We also use technical and organizational security measures.

14. Automated Decision-Making

We use automated systems for Rate Limiting (Upstash) and CSP reports to ensure security.

15. Third-Country Transfers

We use service providers in the USA (Vercel, Cal.com, Resend, Upstash). The transfer is based on Standard Contractual Clauses (SCC) and additional guarantees.

16. Up-to-dateness

This privacy policy is currently valid.