Legal
Privacy Policy
Last updated: 25 July 2026
This English version is a non-binding convenience translation. The legally binding version is the German version (Datenschutzerklärung).
Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Henri Matteo Mache, Dorothea-Erxleben-Straße 56, 23562 Lübeck, Germany. Phone: +49 1516 4327820. Email: hello@molisera.com.
Full contact details can be found in our legal notice (Impressum).
Overview of data processing
Molisera is a software agency. This website is a presentation website; it requires no customer account and offers no registration, login, or payment functions. We process personal data only to the extent necessary to operate the website, respond to enquiries, and carry out our client projects. We adhere to the principle of data minimization (Art. 5(1)(c) GDPR) and do not collect more data than necessary for the respective purpose.
The following categories of data are processed:
- Server logs and access data
- Communication data (enquiries by email)
- Appointment booking data (via the embedded Cal.com booking calendar)
- Contract and billing data (in the course of client projects)
Data collected and purposes
Server logs (IP address, browser type and version, operating system, referrer URL, timestamp), collected automatically when the website is accessed. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security, stability, and abuse prevention). Retention: 30 days, then automatic deletion.
Communication data (email content, sender information), collected when you contact us, for example via hello@molisera.com. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures or performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Purpose: handling enquiries and project initiation.
Appointment booking data (name, email address, chosen time slot, optional notes about your enquiry), collected when you book an intro call via the booking calendar on the “Start a project” page (see section 05). Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request). Purpose: scheduling the call and project initiation.
Contract and billing data (name, company, contact details, invoicing details, project-related content and documents), collected when you engage us. Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) GDPR (statutory retention obligations). Purpose: carrying out and invoicing projects.
Hosting and delivery of the website
The website is served as static files from the infrastructure of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in data centers in Germany. When a page is loaded, the server processes technically necessary access data (server logs), in particular the IP address, the date and time of access, and the requested resource. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable provision).
Appointment booking (Cal.com)
On the “Start a project” page (/start) we embed the scheduling service Cal.com, provided by Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. When you open that page, the booking calendar is loaded from Cal.com’s servers; for technical reasons Cal.com thereby receives your IP address and the usual access data. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in convenient appointment scheduling); the page serves this purpose only and is opened solely at your initiative.
If you book an appointment, Cal.com processes the data you enter (name, email address, chosen time slot, optional notes) on our behalf. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request).
The booking calendar sets only technically necessary cookies (security and CSRF protection, bot prevention) and stores a display preference (12/24-hour format) in your browser’s local storage; no tracking for advertising or analytics purposes takes place (see section 08). Processing may take place in the United States; the transfer is based on the safeguards described in section 07.
Processors
We use the following processors, bound by data-processing agreements (DPAs):
- Hetzner (Hetzner Online GmbH, Germany), hosting infrastructure. Processes server logs.
- Cal.com (Cal.com, Inc., USA), appointment scheduling on the “Start a project” page. Processes access and booking data.
Where we engage further service providers in the course of individual client projects, this is done on the basis of the respective project agreement and, where required, a data-processing agreement pursuant to Art. 28 GDPR.
International data transfers
The data collected through this website is generally processed in Germany. When the Cal.com scheduling service is used (section 05), data may be transferred to the United States. Transfers to a third country only take place on the basis of an adequacy decision (Art. 45 GDPR), such as the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR). Supplementary technical measures include encryption in transit (TLS/HTTPS).
Cookies
This website itself does not set any cookies. We do not use analytics cookies, advertising cookies, social-media tracking pixels, or other tracking technologies.
Only the Cal.com booking calendar embedded on the “Start a project” page sets technically necessary cookies (security and CSRF protection, bot prevention) and stores a display preference in your browser’s local storage. Such storage that is strictly necessary for the service you expressly requested does not require consent under Section 25(2) no. 2 TTDSG. Accordingly, no cookie-consent banner is required.
Retention periods
- Server logs: automatically deleted after 30 days.
- Communication data: retained for the duration of the business relationship plus 3 years, corresponding to the general statutory limitation period (Section 195 BGB).
- Appointment booking data: retained like communication data.
- Invoices and billing records: retained for 10 years in accordance with commercial and tax law (Section 147 AO, Section 257 HGB).
After the respective retention period expires, data is deleted or anonymized unless a further statutory retention obligation exists.
Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): You may request information about whether and which personal data we process about you.
- Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate personal data.
- Right to erasure (Art. 17 GDPR): You may request the deletion of your personal data, subject to statutory retention obligations.
- Right to restriction of processing (Art. 18 GDPR): You may request the restriction of the processing of your data under certain conditions.
- Right to data portability (Art. 20 GDPR): You may request that your data be provided to you or another controller in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21 GDPR): You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interest.
- Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority.
Competent supervisory authority: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
To exercise your rights, contact us at hello@molisera.com. We will respond to your request within one month of receipt (Art. 12(3) GDPR). This period may be extended by a further two months where necessary, taking into account the complexity and number of requests.
Data security
We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access (Art. 32 GDPR). These measures include:
- Encryption in transit: All data transmitted between your browser and our servers is protected by TLS/HTTPS.
- Access controls: Access to personal data is limited to authorized persons on a need-to-know basis.
- Regular backups: Data is backed up regularly to prevent data loss.
Changes
We may update this Privacy Policy from time to time to reflect changes in our data-processing practices or legal requirements. The current version is published on this page. The "last updated" date shown at the top of this page indicates when this Privacy Policy was last revised.