Imprint

Information according to Section 5 DDG (German Digital Services Act)

Jana Breitmar
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany

Email: hallo@janabreitmar.de
Phone: +49 157 9234 1658

(Note: The address for service of documents and the telephone number are managed by the imprint service Dein-Impressum. All enquiries are forwarded to me. No parcels can be accepted.)

Responsible for the content according to Section 18(2) German Interstate Media Treaty (MStV)

I am responsible: Jana Breitmar (address as above).

VAT

I am a small business as defined in Section 19 of the German VAT Act (UStG) and therefore do not charge VAT.

Consumer dispute resolution

I am neither obliged nor willing to participate in dispute resolution proceedings before a consumer arbitration board.

Privacy Policy

Basics

Controller

The controller within the meaning of the GDPR is me, Jana Breitmar (address see Imprint).

Hosting

My website is hosted on a server in Germany. A data processing agreement under Article 28 GDPR is in place with the server's host. When you visit the website, the server briefly holds your IP address in memory so that the connection can be established (Article 6(1)(f) GDPR). Otherwise, no personal data is stored permanently on the server itself. Your account, feedback, purchase data and payments all run via the data processors listed in the following sections.

Data processors

Some features of my website run on external service providers that process data on my behalf (so-called data processors).

Cloudflare (Cloudflare, Inc., USA) operates my domain's name servers (DNS), translating the address janabreitmar.de into my server's IP address. Visitor traffic does not pass through Cloudflare but goes directly to my server; Cloudflare only processes DNS queries. A data processing agreement under Article 28 GDPR is in place; any transfer to the USA is safeguarded by Cloudflare's certification under the EU-US Data Privacy Framework and, additionally, by EU Standard Contractual Clauses (Article 46(2)(c) GDPR). Privacy notice: cloudflare.com/privacypolicy.

Supabase (Supabase Inc., USA, with an EU branch; servers in Germany) is my database and authentication provider. A data processing agreement under Article 28 GDPR is in place; any transfer to the USA is safeguarded by EU Standard Contractual Clauses (Article 46(2)(c) GDPR). Privacy notice: supabase.com/privacy.

Stripe (Stripe Payments Europe Ltd., Ireland) handles payments. For the payment processing itself Stripe acts as its own controller; otherwise a data processing agreement pursuant to Article 28 GDPR is in place. Transfers to Stripe, Inc. in the USA are covered by the European Commission's adequacy decision on the EU-US Data Privacy Framework and, additionally, by EU standard contractual clauses. Privacy notice: stripe.com/privacy.

Cookies and browser storage

I only use strictly necessary cookies and browser storage (session and local storage) on this website, nothing for tracking, analytics or advertising. The session storage, which is cleared when you close the browser tab, holds for example your shopping cart, the audio player's function, and the songs you mark as favourites while logged out. In the persistent local storage, the fact that you stay logged in is kept, as well as your reading position and bookmarks in the article reader. No personal data is stored in the process, and everything stays on your device. When you are logged in, your favourites are additionally stored in your account so you can use them across devices. Fonts and scripts are loaded directly from my server; only during the payment process is additional code loaded directly from Stripe. The legal basis is Section 25(2)(2) TDDDG.

Website features

Reach measurement

I count page views and songs played as plain totals, so I can see what is being read and listened to. No cookie is set, no IP address is stored and no recognition feature is created; individual visitors cannot be identified from it. No external analytics service is involved. In the end all that is stored is a number. The legal basis for the processing that briefly occurs in the process is my legitimate interest in measuring reach without tracking (Article 6(1)(f) GDPR).

User account

You can voluntarily create a user account, either with email and password or via Google login. This processes your email address and your password (encrypted) or your Google identifier. Optionally you can add profile information such as a username, profile picture or a short text about yourself. The account and profile are managed via Supabase (see "Data processors" section). The legal basis is Article 6(1)(b) GDPR for your account and Article 6(1)(a) GDPR for the optional profile information. Your data is stored until you delete your account. An informal email to me is enough.

Signing in with Google

Instead of email and password you can sign in with your Google account. Google then learns that you are signing in at janabreitmar.de and passes on your email address, your name and a Google identifier to me. The provider is Google Ireland Limited, Ireland; transfers to Google LLC in the USA are covered by the European Commission's adequacy decision on the EU-US Data Privacy Framework and, additionally, by EU standard contractual clauses. The legal basis is Article 6(1)(b) GDPR (setting up your account). Signing in with Google is optional, signing in with email and password is available as an equal alternative. Privacy notice: policies.google.com/privacy.

Feedback form

Via the feedback icon you can send me short messages. This processes your message text, optionally your email address (in case I should reply), the page you opened the form from and the timestamp. The data is stored at Supabase (see "Data processors" section) and additionally emailed to me. Your IP address is not collected. The legal basis is Article 6(1)(a) GDPR (consent by submitting) and Article 6(1)(f) GDPR (handling your request). Storage duration: until your request is handled, at most twelve months.

Withdrawal

Through the withdrawal form you can withdraw from an order, also without a user account. Your name, your details about the order and your email address are processed. The declaration is sent to me by email, and you receive a confirmation of receipt at the same address. Your IP address is not collected. The legal basis is Article 6(1)(c) GDPR (legal obligation under Section 356a of the German Civil Code) and Article 6(1)(b) GDPR (performance of the contract). I keep the declaration for as long as it is needed for the processing and for the statutory tax and commercial retention periods.

Digital article "Soulful Connection"

Purchase and access

When you purchase the article, I process your purchase data (time of purchase, payment status and transaction ID) and link access to the article to your user account. This data is stored at Supabase (see "Data processors" section). The legal basis is Article 6(1)(b) GDPR (contract performance). The data remains stored as long as you have access to the article; it can be deleted on request.

Payment

Payment runs via Stripe (see "Data processors" section). For this, the checkout page loads Stripe code directly from Stripe (js.stripe.com, for fraud prevention); for the actual payment you are then redirected to a secure Stripe page. Stripe processes your payment data (e.g. card number and name) directly; I do not see this data myself. From Stripe I only receive the payment status, a transaction ID and your email address. The legal basis is Article 6(1)(b) GDPR (contract performance). I retain invoice and payment records for 10 years in accordance with German tax and commercial law requirements.

General

External links

This website contains links to external providers (e.g. Instagram). When you click on them, you leave my website; from then on the privacy policies of the respective providers apply.

Contact via email or social media

If you contact me directly via email or social media, I will use your data only to handle your request and will delete it afterwards, unless statutory retention obligations require otherwise.

Your rights

You have the right at any time to access the data I hold about you (Article 15 GDPR), to rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21). You can revoke any consent given at any time with effect for the future (Article 7(3) GDPR). An informal email to hallo@janabreitmar.de is sufficient for all of these. You also have the right to lodge a complaint with a data protection supervisory authority, for example the Hessian Commissioner for Data Protection and Freedom of Information.

No automated decision-making or profiling within the meaning of Article 22 GDPR takes place.

Last updated

August 2026