Legal

Data Privacy Policy

Last updated: September 2026

At thirdplace, we take the protection of your personal data seriously. This Privacy Policy explains what personal data we collect when you visit our website, contact us, or engage with us regarding our services, how we use that information, and the rights you have under applicable data protection law.

We process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection law (Regulation (EU) 2016/679).

1. Who is responsible for your data?

The controller responsible for the processing of personal data on this website is:

thirdplace
c/o Alexander Frank
Zum Gensstueck 8
35614 Asslar
Germany

Email: info@third-place.eu
Telephone: +49 151 200 476 07

“thirdplace”, “we”, “us” and “our” in this Privacy Policy refer to the above controller.

2. Visiting our website

When you visit our website, certain technical information may automatically be transmitted by your browser to the server hosting our website. This may include:

  • IP address
  • date and time of access
  • pages or files accessed
  • referring website
  • browser type and version
  • operating system
  • device information
  • access status and amount of data transferred

This information is processed to enable the website to be delivered securely and reliably, to maintain its technical functionality, and to identify and prevent misuse or security incidents.

The legal basis for this processing is our legitimate interest in operating a secure and functional website pursuant to Art. 6(1)(f) GDPR.

Server log data is retained only for as long as necessary for these purposes, unless longer retention is required for security, legal or evidentiary reasons.

Hosting

Our website is hosted by:

STRATO GmbH
Otto-Ostrowski-Straße 7, 10249 Berlin
www.strato.de

The hosting provider may process personal data on our behalf insofar as this is necessary to provide and secure the website. Where required, we have entered into an appropriate data processing agreement with the provider.

3. Contacting us

If you contact us by email, telephone or through a contact form on our website, we process the information you provide in order to respond to your inquiry.

Depending on how you contact us and the nature of your inquiry, this may include:

  • your name
  • your organization and role
  • your email address
  • your telephone number
  • the content of your message
  • other information you choose to provide

Where your inquiry relates to a potential or existing contractual relationship, the processing is based on Art. 6(1)(b) GDPR. In other cases, the processing is based on our legitimate interest in responding to inquiries and communicating with clients, prospective clients and other business contacts pursuant to Art. 6(1)(f) GDPR.

We retain correspondence for as long as necessary to deal with your inquiry and any subsequent business relationship. Information may be retained for longer where required by statutory retention obligations or where necessary for the establishment, exercise or defense of legal claims.

Spam protection (Google reCAPTCHA)

To protect our contact form against automated submissions and spam, we use the reCAPTCHA service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

reCAPTCHA analyses the behaviour of the person completing the form in order to determine whether the entry is made by a human being or by an automated program. This analysis may include the IP address, the duration of the visit, mouse movements and keyboard input, browser and device information, as well as data already stored by Google. This data is transmitted to Google and may also be processed on servers in the United States.

reCAPTCHA is not loaded when you simply open the page. The service is only requested at the moment you click into a field of the contact form. If you do not use the contact form, no data is transmitted to Google.

The legal basis for this processing is our legitimate interest in protecting our website against abuse, automated data collection and spam pursuant to Art. 6(1)(f) GDPR.

Where personal data is transferred to the United States, Google relies on the EU-U.S. Data Privacy Framework and on the standard contractual clauses adopted by the European Commission. Further information is available in Google’s privacy policy at policies.google.com/privacy and in the reCAPTCHA terms at policies.google.com/terms.

4. Clients, prospective clients and business contacts

In the course of developing and maintaining professional relationships, we may process personal data relating to clients, prospective clients, participants in our services, suppliers, partners and other professional contacts. This may include:

  • name and professional contact information
  • organization and position
  • information relating to inquiries, proposals and assignments
  • contractual and billing information
  • correspondence
  • information required to organize and deliver our services

We process this information where necessary to take steps prior to entering into a contract or to perform a contract pursuant to Art. 6(1)(b) GDPR. Where the contractual relationship is with your employer or another organization rather than with you personally, processing may be based on our legitimate interest in establishing, managing and delivering our professional relationship with that organization pursuant to Art. 6(1)(f) GDPR. Where required by law, processing may also take place pursuant to Art. 6(1)(c) GDPR.

This Privacy Policy relates primarily to our website and general business communications. Where a particular service, assessment, coaching engagement or other activity involves additional processing of personal data, we may provide additional privacy information where appropriate.

5. Cookies and similar technologies

Our website does not use cookies for analytics, advertising, marketing or cross-site tracking. Where technically necessary storage is used, it serves solely to deliver the website securely and correctly or to provide a function you have expressly requested. Strictly necessary technologies of this kind do not require your consent.

Further details are set out in our Cookie Policy.

Consent management (Real Cookie Banner)

To manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and the related consents, we use the consent tool “Real Cookie Banner”. Details on how “Real Cookie Banner” works can be found at devowl.io/knowledge-base/real-cookie-banner-data-processing.

The legal bases for the processing of personal data in this context are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.

The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we cannot manage your consents.

6. Website analytics

We do not use analytics or tracking technologies to create individual profiles of visitors to this website.

7. Fonts, images and other website assets

Apart from the spam protection described in section 3, all fonts, images and other assets used on this website are hosted on our own server. No other content is loaded from external servers or content delivery networks when you visit our website. Your IP address is therefore not transmitted to third-party providers simply because you view a page.

8. Scheduling appointments via Zeeg

We use the scheduling service Zeeg, provided by Zeeg GmbH, Friedrichstraße 114A, 10117 Berlin, Germany, to enable you to schedule a call or meeting with us.

If you choose the “Start a conversation” option on our website, you will be directed to an external Zeeg scheduling page. When you book an appointment, Zeeg processes the information you provide as part of the booking process. This may include your name, email address, appointment details and any other information you choose to provide.

We process this information for the purpose of arranging and managing the requested appointment. Where the appointment relates to a potential or existing contractual relationship, the legal basis is Art. 6(1)(b) GDPR. In other cases, processing is based on our legitimate interest in efficiently organizing and managing appointments pursuant to Art. 6(1)(f) GDPR.

Zeeg processes personal data on our behalf in accordance with a data processing agreement pursuant to Art. 28 GDPR. According to Zeeg, data processed through its service are stored and processed within the European Union, on servers in Germany and the Netherlands.

Further information about how Zeeg processes personal data is available in Zeeg’s Privacy Policy on the Zeeg website.

9. Recipients of personal data

We do not sell your personal data. Where necessary for the purposes described in this Privacy Policy, personal data may be shared with carefully selected service providers that support us in operating our business and website. These may include, as applicable:

  • website and hosting providers
  • IT and technical service providers
  • communication and email providers
  • professional advisers
  • accounting and administrative service providers
  • providers supporting the delivery of our services

Where these providers process personal data on our behalf, we put appropriate contractual arrangements in place as required by applicable data protection law. Personal data may also be disclosed where required by law, regulation, court order or a competent public authority.

10. International data transfers

Where possible, we use service providers that process personal data within the European Union or European Economic Area. Our website hosting and our scheduling provider process data within the EU. Where you use our contact form, the spam protection service reCAPTCHA may transfer data to Google servers in the United States, as described in section 3.

Where personal data are transferred to a country outside the EU or EEA, we ensure that an appropriate legal mechanism is in place as required by the GDPR. Depending on the country and provider, this may include an adequacy decision by the European Commission or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

11. How long we keep personal data

We retain personal data only for as long as necessary for the purposes for which they were collected. The applicable retention period depends on the nature of the information and the purpose of processing.

We may retain information for longer where required by statutory retention obligations, in particular commercial and tax law, or where necessary for the establishment, exercise or defense of legal claims. Once personal data are no longer required and no legal obligation or legitimate reason for retaining them applies, they will be deleted or anonymized as appropriate.

12. Security

We take appropriate technical and organizational measures to protect personal data against accidental or unlawful loss, alteration, disclosure, destruction or unauthorized access. Our website uses encrypted communication via SSL/TLS. Despite these measures, no transmission of information over the internet can be guaranteed to be completely secure.

13. Your rights

Subject to the conditions set out in applicable data protection law, you have the right to:

  • request access to the personal data we hold about you;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of your personal data;
  • request restriction of processing;
  • receive certain personal data in a structured, commonly used and machine-readable format and, where applicable, have those data transmitted to another controller;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing is based on your consent; and
  • lodge a complaint with a competent data protection supervisory authority.

Where processing is based on your consent, withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Right to object

Where we process your personal data on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to that processing on grounds relating to your particular situation. Where personal data are processed for direct marketing purposes, you have the right to object to such processing at any time.

To exercise any of these rights, please contact us using the details provided in Section 1.

14. Right to lodge a complaint

If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:

The Hessian Commissioner for Data Protection and Freedom of Information
(Hessischer Beauftragter für Datenschutz und Informationsfreiheit – HBDI)
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany

You may also contact another competent supervisory authority, in particular in the EU or EEA member state of your habitual residence, place of work or the place of the alleged infringement.

15. LinkedIn and other third-party websites

Our website contains links to websites and services operated by third parties, including LinkedIn.

The LinkedIn link on our website is a simple external link. We do not use LinkedIn plugins or other embedded LinkedIn services on our website. Personal data are therefore not transmitted to LinkedIn simply because you visit our website.

If you choose to follow a link to LinkedIn or another third-party website, you leave our website and the privacy practices of the respective third party apply. The third-party provider may process personal data relating to your visit in accordance with its own privacy policy.

For visitors in the European Union, European Economic Area and other designated countries, LinkedIn identifies LinkedIn Ireland Unlimited Company as the controller responsible for personal data processed in connection with its services.

We are not responsible for the content, security or privacy practices of third-party websites and recommend reviewing the privacy information provided by the relevant website operator.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example where our website, services, legal requirements or the technologies we use change. The current version of this Privacy Policy will always be available on our website.