Virell ← Back to site

Datenschutzerklärung

Privacy Policy

Last updated 17 August 2026 · Information pursuant to Art. 13 and 14 GDPR


The short version: this site sets no cookies, runs no analytics, and carries no tracking pixels. Nothing you do here is measured. The only personal data involved is what your browser must send to load a page, and whatever you choose to tell me if you get in touch.

Fonts are served from this domain. Many sites load typefaces from Google's servers, which discloses every visitor's IP address to a third party in the United States. This site does not — the font files are hosted here, so no request leaves your browser for a third-party server.

1. Who is responsible

The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:

Jan Schwoll
trading as Virell
Im Grühlingswald 17
66299 Friedrichsthal
Germany
jan@virellhq.com

No data protection officer has been appointed. The statutory thresholds in § 38 BDSG are not met — this is a one-person business.

2. What this policy covers

This policy applies to this website. It does not cover the AI lead-response service itself, which runs inside a client's own email and calendar systems. Where Virell processes data on a client's behalf as part of that service, it does so as a processor under Art. 28 GDPR, governed by a separate data processing agreement with that client.

3. Server log data

Every time a page is loaded, the hosting provider automatically records technical data that your browser transmits:

Purpose
Delivering the site, keeping it stable, and detecting and defending against abuse.
Legal basis
Art. 6(1)(f) GDPR. The legitimate interest is operating a functioning and secure website — a site cannot be served at all without processing an IP address.
Retention
Log data is held for a short period by the hosting provider for operational and security purposes and is then deleted or aggregated. It is not combined with any other data and is not used to build a profile of you.

4. Hosting

This site is hosted by Netlify, Inc., San Francisco, California, USA, which processes the log data described above on my instructions as a processor under Art. 28 GDPR.

This involves a transfer of personal data to the United States. The transfer is safeguarded by the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, together with the provider's certification under the EU–US Data Privacy Framework (Art. 45 GDPR). Despite these safeguards, US authorities may in principle be able to access data held there, and enforcing your rights against a US recipient may be harder than against an EU one.

5. Cookies and tracking

This site sets no cookies. There is no analytics, no tag manager, no advertising pixel, no session tracking, no fingerprinting, and no embedded third-party content that could observe you. Nothing is written to or read from your device beyond what your browser does on its own to display a page.

Because no information is stored on or read from your device, no consent under § 25 TDDDG is required, and you will not be shown a cookie banner.

6. Getting in touch

The message form

If you use the form at the bottom of the home page, you send me three things: your name, your email address, and your message. Nothing else is collected — there is no hidden field capturing your IP, your location, your browser, or which pages you looked at before writing.

The form does not use reCAPTCHA or any similar service. Spam is filtered with a hidden field that only automated submissions fill in, so no data about you is sent anywhere for a check. Your message is passed to my inbox by Resend (Plus Five Five, Inc., 2261 Market Street, San Francisco, CA 94114, USA), acting as a processor under Art. 28 GDPR, with the US transfer safeguarded as described in section 4.

Email

If you email me directly instead, I receive whatever you send: your email address, your name if you give it, and the content of your message. Email runs on Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), acting as a processor under Art. 28 GDPR.

Purpose
Answering you, and if it leads somewhere, discussing and carrying out work together.
Legal basis
Art. 6(1)(b) GDPR where the exchange concerns a contract or steps taken before entering one, otherwise Art. 6(1)(f) GDPR — my legitimate interest in responding to the people who write to me.
Retention
Correspondence is kept while the matter is live and for as long as it may be needed afterwards. Where commercial or tax retention duties apply (§ 257 HGB, § 147 AO), the applicable statutory period governs. Otherwise correspondence is deleted once it no longer serves a purpose.

Ordinary email is not end-to-end encrypted and can in principle be read in transit. Please don't send anything genuinely sensitive by email — to me or to anyone.

7. Booking a call

The buttons inviting you to book a call take you to a scheduling page operated by Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. That page is not embedded here — you leave this site to reach it, and nothing whatsoever is loaded from Calendly unless and until you choose to go there. Simply reading this site sends Calendly nothing.

If you book, you provide your name, email address and chosen time. This is used solely to arrange and hold the call, and to place the appointment in my calendar. Legal basis is Art. 6(1)(b) GDPR (steps prior to entering a contract). Calendly acts as a processor under Art. 28 GDPR; the transfer to the United States is safeguarded as described in section 4. Calendly's own handling of data on its site is governed by its privacy policy.

8. Who receives your data

RecipientPurposeLocation
Netlify, Inc.Website hosting, server logsUSA
Resend (Plus Five Five, Inc.)Delivering the message form to my inboxUSA
Google Ireland Ltd.Email and calendar (Google Workspace)EU, with US transfers
Calendly LLCCall scheduling, if you use itUSA

Your data is not sold, rented, or shared for anyone else's marketing. Beyond the processors above, it is disclosed only where I am legally obliged to do so, or to my tax adviser or authorities where required by tax and accounting law.

9. Your rights

Under the GDPR you have the right to:

To exercise any of these, email jan@virellhq.com. It reaches me directly and costs you nothing.

10. Complaints

You can complain to a supervisory authority, in particular in the member state of your residence, place of work, or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for me is:

Unabhängiges Datenschutzzentrum Saarland
Landesbeauftragte für Datenschutz und Informationsfreiheit
Fritz-Dobisch-Straße 12
66111 Saarbrücken
Germany
datenschutz.saarland.de

11. Automated decision-making

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place on this website.

12. Is providing data required?

No. You are under no statutory or contractual obligation to provide any personal data. The technical data in section 3 is unavoidable if you want to view the site at all; everything else is entirely your choice. Not providing it has no consequence other than my being unable to reply to you.

13. Security

This site is served exclusively over an encrypted TLS connection (HTTPS), which you can verify by the padlock in your browser's address bar. Appropriate technical and organisational measures under Art. 32 GDPR are in place to protect data against accidental or unlawful loss, alteration or unauthorised access.

14. A note for visitors in the United States

Virell is operated from Germany and applies the GDPR to everyone, wherever they are. Personal information is not sold and not shared for cross-context behavioural advertising, as those terms are used under US state privacy laws. If you are in the US and want to know what I hold about you or want it deleted, use the same email address above — you get the same answer and the same treatment.

15. Changes to this policy

This policy will be updated when the site or the services behind it change — for example if a contact form or a new tool is added. The current version always applies and is dated at the top of this page.

See also the Legal Notice for provider identification.