Privacy Policy

Privacy Policy

Last updated: 4 September 2026

1. Scope

This privacy policy explains how we process personal data when you use our websites and subdomains under marskaiser.de and marskaiser.com, the associated sales and information pages, forms, webinar offerings and protected member areas. It also applies to communications, the initiation and performance of contracts and the provision of our digital products, unless more specific privacy information is provided for a particular offering.

Personal data means any information relating to an identified or identifiable natural person.

2. Controller

KaiCon  

Proprietor: Marco Kaiser

Luisenstraße 5  

65558 Heistenbach  

Germany

Telephone: 06432 / 83377

Email: info@marskaiser.com

No data protection officer has been appointed because there is currently no legal obligation to do so.

3. General legal bases

We process personal data only where a legal basis exists. Depending on the processing, the following legal bases may apply in particular:

· Article 6(1)(a) GDPR, where you have given consent,

· Article 6(1)(b) GDPR, where processing is necessary for a contract or pre-contractual measures,

· Article 6(1)(c) GDPR, where we must comply with a legal obligation,

· Article 6(1)(f) GDPR, where processing is necessary for a legitimate interest and your interests or fundamental rights do not override that interest.

Where information is stored on or read from your device, section 25 TDDDG also applies. We use analytics and marketing technologies that are not technically necessary only on the basis of your consent under section 25(1) TDDDG and Article 6(1)(a) GDPR.

Where special categories of personal data, in particular health data, are processed, this takes place only if a condition under Article 9(2) GDPR is also met. Please do not submit health data through general contact or newsletter forms. If such information is required for an individually commissioned service, we will inform you separately about the specific processing.

4. Recipients and processors

We use carefully selected service providers, in particular for hosting, website operation, email delivery, analytics, advertising, payment processing and the provision of digital content. Where these providers process personal data exclusively on our instructions, we conclude data processing agreements under Article 28 GDPR.

Data is disclosed only where necessary for the performance of a contract, where you have consented, where a legal obligation exists or where we can assert an overriding legitimate interest.

5. Transfers to third countries

Some service providers are based outside the European Economic Area or may process data from there. Transfers take place only subject to the conditions in Articles 44 to 49 GDPR, in particular on the basis of:

· an adequacy decision of the European Commission under Article 45 GDPR,

· a valid certification of the recipient under the EU-US Data Privacy Framework,

· standard contractual clauses of the European Commission under Article 46(2)(c) GDPR,

· or a statutory derogation under Article 49 GDPR.

For service providers in the United Kingdom, we rely, where applicable, on the European Commission's adequacy decision. For US recipients, we check whether an active certification under the EU-US Data Privacy Framework exists. Where this is insufficient or inapplicable, we use appropriate additional safeguards, in particular standard contractual clauses.

Despite these safeguards, where processing takes place in third countries, it cannot be completely ruled out that authorities there may access data under statutory powers.

6. Provision of websites, emails and digital content through systeme.io

Our websites, funnels, forms, contact management, email automations and member area are provided wholly or partly using the marketing and course platform systeme.io. The provider is ITACWT Limited, 2 Cruise Park Rise, Tyrrelstown, Dublin 15, Ireland.

systeme.io processes data on our behalf that is necessary for the delivery and security of the pages and for the functions being used. This may include:

· IP address,

· date and time of access,

· page or file accessed and referrer URL,

· browser, device and operating system information,

· technical error, log and security information,

· form, contact, consent and confirmation data,

· email, automation, tag, account, course, membership and usage data when you use the relevant functions.

Technically necessary access data is processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is in providing our offerings securely, reliably and without errors. Where processing is necessary for pre-contractual measures, the performance of a contract or the provision of a purchased product, the legal basis is Article 6(1)(b) GDPR. Processing requiring consent takes place on the basis of Article 6(1)(a) GDPR.

Where systeme.io processes data on our behalf, processing takes place in accordance with Article 28 GDPR. According to the provider, Amazon Web Services server infrastructure in Ireland is used. The provisions on third-country transfers in section 5 also apply to any processing by technical subprocessors.

Further information: https://systeme.io/privacy-policy

7. Technical infrastructure and content delivery

According to systeme.io, it uses Amazon Web Services infrastructure in Ireland for hosting and data storage. Content delivery, security and error analysis services may be used to ensure fast and secure delivery. In particular, the IP address, requested URL, time, browser and device information and technical error and security data may be processed.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is in the secure, resilient and fast provision of our online offerings. Where access to information on your terminal equipment is strictly necessary for the expressly requested page delivery or security function, section 25(2), no. 2 TDDDG also applies.

Further information: https://aws.amazon.com/privacy/

8. Consent management and cookies

On your first visit, you are shown a cookie and consent prompt. There you can accept or reject non-essential analytics and marketing services. Rejecting them must not prevent the use of basic website functions.

Your choice is stored so that it can be respected on later visits. You can change your choice at any time using the cookie settings available on the respective website or withdraw consent with effect for the future.

Technically necessary storage

Technically necessary cookies or similar storage may be used to:

· store your cookie choice,

· manage sessions and login states,

· provide forms and member functions,

· protect the website against misuse,

· perform expressly requested functions.

The legal bases are section 25(2), no. 2 TDDDG and, where personal data is processed, Article 6(1)(b) or (f) GDPR.

Analytics and marketing technologies

Analytics and marketing technologies are activated only after you have given consent. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. Your consent is voluntary and can be withdrawn at any time with effect for the future.

9. Technical usage data at systeme.io

systeme.io may process technical access and usage data for the technical operation, security and evaluation of our pages. This may include page views, referrer and campaign information, times, device and browser data, technical identifiers and form and conversion events.

Technically necessary processing takes place on the basis of Article 6(1)(f) GDPR and, where information is stored on or read from your terminal equipment, under section 25(2), no. 2 TDDDG. Any further personal analytics or marketing evaluation is activated only after your consent on the basis of section 25(1) TDDDG and Article 6(1)(a) GDPR.

The specific storage period depends on the respective function and the settings of the service used. We limit storage to what is necessary for the respective purpose.

10. Google Analytics 4

After you have given consent, we use Google Analytics 4, an analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Measurement ID G-R14YH0VKTX is used for this website.

Google Analytics helps us understand how visitors use our website. In particular, the following may be processed:

· pages viewed and events,

· time, approximate duration of visits and interactions,

· referrer URL and campaign information,

· device, browser and operating system information,

· approximate region,

· pseudonymous identifiers.

According to Google, Google Analytics 4 does not log or store the IP addresses of users from the EU. However, the IP address is used technically for transmission and to determine an approximate region.

Google Analytics may use cookies such as _ga and _ga_<ID>, among others. Depending on configuration and renewed use, these may be stored for up to two years. The retention period for event and user data that we can control in Google Analytics is set to a maximum of 14 months. Aggregated reports may remain available for longer without being directly attributable to an individual user.

The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. Google Analytics is not activated without your consent.

Google may transfer data to Google LLC and other group companies in the USA. Google LLC is certified under the EU-US Data Privacy Framework. Standard contractual clauses may also be used.

Google privacy information: https://policies.google.com/privacy

Google Analytics information: https://support.google.com/analytics/answer/6004245

11. Google Ads and conversion measurement

After you have consented to marketing technologies, we use services from Google Ads, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads tag AW-18111586703 is used on the sales page.

The service helps us measure whether a user performs a desired action on our website after coming into contact with an advertisement. In particular, page views, campaign information, technical device and browser data, pseudonymous identifiers and conversion events may be processed.

Google Ads may use cookies or similar storage such as _gcl_au. The specific duration depends on configuration and is generally up to three months. Other Google cookies may have different durations.

The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. The Google Ads tag is activated only after you have given marketing consent.

Google may transfer data to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework. Standard contractual clauses may also be used.

Google privacy information: https://policies.google.com/privacy

Manage personalised advertising: https://adssettings.google.com/

12. Meta Pixel and Meta Conversions API

After you have given consent, we use the Meta Pixel and the Meta Conversions API of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

These services allow us to determine whether users visit our website or complete a purchase after coming into contact with an advertisement. A PageView event is used on the funnel pages. A Purchase event may be transmitted on the thank-you page after a successful purchase.

In particular, the following may be processed:

· IP address and technical connection data,

· browser, device and operating system information,

· URL accessed and referrer,

· time and type of an event,

· event ID, pixel ID and funnel ID,

· cookie and event identifiers, in particular _fbp and _fbc,

· campaign, purchase value and conversion information,

· where advanced matching is enabled, possibly email address, telephone number and first and last name in hashed form, provided this information is available from a form, a URL or browser storage.

The Meta Pixel processes data in the browser. The Conversions API may additionally transmit event data to Meta server-side. An event ID may be used to match browser and server events and avoid double counting. Both transmission routes and advanced matching are used only after you have given marketing consent.

Meta may link the data to an existing Meta account and process it for measurement, security and advertising purposes under Meta's terms. Where we and Meta are joint controllers for the collection and transmission of event data, Meta's Controller Addendum applies. Meta is independently responsible for further processing at Meta.

The Meta Pixel may in particular set the _fbp cookie, generally for up to three months. Other cookies may have different durations depending on your Meta login and settings.

The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR.

Data may be transferred to Meta Platforms, Inc. in the USA. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework. Standard contractual clauses may also be used.

Meta privacy policy: https://www.facebook.com/privacy/policy/

Meta Controller Addendum: https://www.facebook.com/legal/controller_addendum  

Advertising preferences: https://www.facebook.com/adpreferences/

13. Email forms, guides and newsletters through systeme.io

Our signup forms, contact management, double opt-in process and delivery of guides, newsletters and automated emails are handled through systeme.io from ITACWT Limited, 2 Cruise Park Rise, Tyrrelstown, Dublin 15, Ireland.

When you sign up, we process in particular:

· your email address and, if requested, your name,

· date and time of signup and confirmation,

· IP address and technical evidence data,

· source or form used,

· status, content and time of consent and confirmation,

· where applicable, tags and interests derived from the form used or your usage.

The newsletter is sent only if you have consented or another legal permission exists. For voluntary signups, we generally use a double opt-in process. You receive a confirmation email and are added to the mailing list only after clicking the confirmation link. Logging serves as evidence of valid consent.

The legal bases are Article 6(1)(a) GDPR for delivery and voluntary performance measurement and Article 6(1)(f) GDPR for secure documentation of the signup process. Our legitimate interest is in demonstrating consent and preventing unauthorised signups.

Newsletter performance measurement

Where the consent text expressly covers this, emails may contain tracking pixels and individualised links. These enable us to identify whether a message was delivered or opened and whether a link was clicked. Times, technical information and the interaction may be associated with a recipient profile. We use this information to improve delivery, content and sending times.

The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. Withdrawal has no adverse effect on processing that has already lawfully taken place.

Newsletter data is stored until you unsubscribe. After unsubscribing, your email address may be stored on a suppression list to prevent further mailings. Evidence of consent may be retained until statutory limitation periods expire.

Further information about systeme.io: https://systeme.io/privacy-policy

You can unsubscribe from the newsletter at any time using the unsubscribe link in each message or by emailing info@marskaiser.com.

13a. Webinar registration and delivery through Webinaris

We use Webinaris for the registration, organisation and delivery of automated or live webinars. The provider is Webinaris GmbH, Bussardstraße 5, 82166 Gräfelfing, Germany.

When you register for or participate in a webinar, the following data in particular may be processed, depending on the functions used:

· name and email address,

· selected webinar date and registration status,

· registration, confirmation and participation times,

· IP address and browser, device and connection data,

· evidence of consent and double opt-in,

· participation history, interactions, answers, chat contributions or questions if you use these functions,

· information about the delivery of confirmation, reminder and follow-up emails.

Processing serves registration, provision of the webinar room, webinar delivery, technical security, communication before and after the webinar and evaluation of participation and interest. The legal basis is Article 6(1)(b) GDPR where the webinar forms part of a contract or a pre-contractual measure. For voluntary registration and promotional follow-up, the legal basis is Article 6(1)(a) GDPR. We process technically necessary security and log data on the basis of Article 6(1)(f) GDPR.

To this extent, Webinaris processes participant data on our behalf. The scope of processing on our behalf is governed by the agreement under Article 28 GDPR. Technically necessary cookies or similar storage in the webinar room may be used on the basis of section 25(2), no. 2 TDDDG. Non-essential analytics or marketing technologies are used only after your consent.

The data is deleted when it is no longer required for the webinar, follow-up and any agreed further information, unless statutory retention or evidence obligations prevent this. You can withdraw consent at any time with effect for the future.

Webinaris privacy information: https://www.webinaris.com/datenschutzerklaerung/

14. Contacting us

If you contact us by email, telephone, contact form or social media, we process your information to handle your enquiry. This may include your name, contact details, content of the enquiry, communication history and technical metadata.

The legal basis is Article 6(1)(b) GDPR if your enquiry concerns a contract or pre-contractual measures. For other enquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is in properly handling and documenting your enquiry.

Enquiries are deleted once they have been fully dealt with and there are no statutory retention obligations or legitimate reasons for further storage. We review necessity regularly, at the latest after two years.

15. Digital products, contracts and member accounts

If you purchase a digital product or receive member access, we process the data necessary for purchase, provision, support and administration. This may include:

· name and email address,

· billing and contract data,

· purchased product and access entitlement,

· membership and login data,

· password in technically protected form,

· login times and security data,

· learning progress, unlocked content and test results,

· support and communication data.

The legal basis is Article 6(1)(b) GDPR. We additionally base security logs and measures against misuse on Article 6(1)(f) GDPR.

Contract and account data is stored for as long as the contractual relationship exists and the data is needed to provide the product. It is then deleted unless statutory retention periods, warranty rights, limitation periods or outstanding legal claims prevent this.

16. Gravatar in the member area

On individual pages of the member area, a default profile image may be loaded through Gravatar, a service of Automattic Inc., 60 29th Street #343, San Francisco, California 94110, USA.

When the image is retrieved, at least your IP address, browser and device information and the requested image URL are transmitted to Automattic. Where a user-specific Gravatar is used, the image URL may also contain a hash generated from the email address. A placeholder image is used in the standard configuration currently reviewed.

The integration takes place only insofar as necessary to display the member area. The legal basis is Article 6(1)(b) GDPR where the profile image is part of the requested member function, otherwise Article 6(1)(f) GDPR. Our legitimate interest is in a consistent and user-friendly presentation of the member area.

Data may be transferred to the USA. Automattic participates in the EU-US Data Privacy Framework. Standard contractual clauses may also be used.

Automattic privacy information: https://automattic.com/privacy/

17. Digistore24 and purchase processing

When you click a purchase button, you are redirected to an order form of Digistore24 GmbH, St.-Godehard-Straße 32, 31139 Hildesheim, Germany.

Digistore24 acts under the reseller model as the seller and the buyer's own contractual partner. Digistore24 independently processes the data required for ordering, payment, invoicing, fraud prevention, withdrawal and, where applicable, product delivery. This may include name, address, email address, product, order and payment data, IP address and technically and fiscally necessary information.

We receive from Digistore24 the information necessary to perform our service, unlock the product, provide customer support and settle accounts. The legal bases for our processing are Article 6(1)(b) GDPR and, where statutory retention obligations exist, Article 6(1)(c) GDPR.

Digistore24 decides which payment services are offered in the order form. Processing by the selected payment service is governed by the privacy information provided there.

Digistore24 privacy information: https://www.digistore24.com/page/privacy/de/

18. Accounting and statutory retention

We process contract, invoice, payment and business data for accounting, compliance with tax obligations and enforcement of rights. The legal bases are Article 6(1)(c) and (f) GDPR.

Invoices and accounting vouchers are generally retained for eight years. Commercial and business correspondence is generally retained for six years. Longer periods may apply to certain books, records or special circumstances. Once the respective period has expired, the data is deleted unless it is still required for ongoing proceedings or a legal claim.

19. Social media presences

We maintain business presences on social networks, in particular Instagram and Facebook. If you visit these presences or communicate with us there, the respective platform operator processes personal data under its own responsibility. This may also occur if you are not logged into the platform.

Where the platform provides us with aggregated statistics about visitors to our presence and joint controllership exists, this is governed by the agreements of the respective platform operator. We use the information provided to improve our content and handle enquiries.

The controller for Instagram and Facebook is: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Meta privacy policy: https://www.facebook.com/privacy/policy/

No Instagram plugins are automatically embedded on the website currently reviewed. If this changes, this policy will be updated before they are used.

20. Automated decisions and profiling

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

Analytics and advertising services may create pseudonymous usage or interest profiles. This processing takes place only after your consent and does not constitute automated individual decision-making by us under Article 22 GDPR.

21. Transparency regarding the use of artificial intelligence

This section provides transparency under Regulation (EU) 2024/1689 on artificial intelligence, in particular Article 50, as amended by Regulation (EU) 2026/1744. The requirements of Article 50 generally apply from 2 August 2026. The AI Act is not a legal basis for processing personal data and replaces neither the GDPR nor the TDDDG.

AI-assisted tools may be used to create individual texts, images, audio content or videos. All content published by us is substantively reviewed, revised and editorially overseen by Marco Kaiser. For health-related or other topics of public interest, this review covers in particular statements, sources, limitations and a clear distinction between personal experience, health education and medical advice.

Realistic artificially generated or manipulated image, audio and video content is clearly and accessibly labelled as artificially generated or manipulated, no later than at first exposure, insofar as it falls under the transparency obligations of Article 50 of the AI Act. For fictional testimonials, it is additionally made clear that no real customer experience is being depicted.

This website currently does not use an AI chatbot that communicates directly with visitors. We also do not use emotion recognition or biometric categorisation here. If this changes, affected persons will be clearly informed before or no later than the first interaction, and this privacy policy will be updated before use.

A general notice in this privacy policy does not replace the required labelling of specific AI-generated or manipulated content.

22. Obligation to provide data

For a purely informational visit, you do not have to actively provide us with any data. However, technical access data is processed automatically because otherwise the website cannot be delivered and protected.

For contracts, purchases and member accounts, information marked as required is necessary. Without this data, we cannot provide the contract or requested function. Newsletter signup and consent to analytics and marketing are voluntary.

23. Storage periods and deletion

Unless a specific period is stated in this policy, we store personal data only for as long as necessary for the respective purpose. It is then deleted or anonymised unless statutory retention obligations, outstanding claims, interests in preserving evidence or security reasons prevent this.

When determining the duration, we take into account in particular:

· the duration of a contract or member access,

· statutory limitation and retention periods,

· the duration of consent,

· the need to defend against or enforce claims,

· requirements of the service providers used, insofar as we cannot determine the duration ourselves.

24. Your rights

Subject to the statutory conditions, you have in particular the following rights:

· Access, Article 15 GDPR,

· Rectification, Article 16 GDPR,

· Erasure, Article 17 GDPR,

· Restriction of processing, Article 18 GDPR,

· Data portability, Article 20 GDPR,

· Objection, Article 21 GDPR,

· Withdrawal of consent, Article 7(3) GDPR,

· Lodging a complaint with a data protection supervisory authority, Article 77 GDPR.

Withdrawal of consent

You can withdraw consent at any time with effect for the future. The lawfulness of processing before withdrawal remains unaffected. You can change cookie consent through the website's cookie settings. You can unsubscribe from newsletters using the unsubscribe link in each message.

Objection under Article 21 GDPR

Where we process data on the basis of Article 6(1)(e) or (f) GDPR, you may object on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.

You may object to processing for direct marketing at any time without giving reasons. The data concerned will then no longer be used for direct marketing.

To exercise your rights, simply send a message to info@marskaiser.com.

25. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority. The authority generally responsible for us is:

The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate  

Hintere Bleiche 34  

55116 Mainz  

Germany

Telephone: +49 6131 8920-0

Email: poststelle@datenschutz.rlp.de

Website: https://www.datenschutz.rlp.de/

You may also contact another supervisory authority competent under Article 77 GDPR.

26. Security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. These include in particular encrypted transmission, access restrictions, secure passwords, backups and regular review of our systems and service providers.

Please note that transmitting data over the internet is never entirely risk-free, despite careful measures.

27. Changes to this privacy policy

We update this privacy policy when our data processing, the services we use or the legal situation changes. The version published on this website applies. If a change affects existing consent, we obtain new consent where necessary.