PagesAway is operated from Germany. That means the EU General Data Protection Regulation (GDPR) governs everything we do with personal data — including data about customers and visitors located in the United States. This policy explains what we collect, why, how long we keep it, and what you can require us to do. It is written to be read, not to be skimmed past.
The controller for the processing described here is:
Davis von Löwe Kiedrowski, trading as PagesAway
Walsroder Straße 158, 30853 Langenhagen, Germany
Email: privacy@pagesaway.com · Telephone: +49 511 7663766
We have not appointed a Data Protection Officer. Under § 38 BDSG this is only mandatory above thresholds we do not meet. Enquiries go directly to the address above.
Article 3(1) GDPR ties the regulation to where the business is established, not to where the customer lives. Because PagesAway is operated from Germany, all processing described here falls under GDPR regardless of whether you are in Texas, Tennessee or Thuringia.
In practice this works in your favour: GDPR grants broader rights than most US state privacy laws. You do not need to be an EU resident to exercise them, and we do not ask where you live before honouring a request.
When you load a page, our server records the request. This is a technical necessity — a web server cannot deliver a page without knowing where to send it.
| Data | Purpose | Legal basis |
|---|---|---|
| IP address (shortened after 7 days) | Delivering the page, detecting abuse and attacks | Art. 6(1)(f) — legitimate interest in operating a secure service |
| Date and time, page requested, referring page | Diagnosing errors, understanding which pages are used | Art. 6(1)(f) |
| Browser, operating system, language | Ensuring the site renders correctly | Art. 6(1)(f) |
These logs are not combined with any other data and are not used to build a profile of you.
Our marketing website sets no cookies for analytics, advertising or tracking. There is no Google Analytics, no Meta pixel, no advertising network, and no cross-site tracking of any kind. This is why you are not being asked to click through a consent banner.
If we introduce analytics in future, we will either use a cookieless, aggregate-only tool or ask for your consent first under § 25(1) TTDSG — and this policy will be updated before, not after.
Typefaces and icon sets used on our website are served from our own servers. They are not loaded from Google Fonts, a content delivery network or any other third party, so your IP address is not transmitted to an external provider when you view a page.
When you complete our project form or email us, we receive whatever you choose to send. Typically: your name, business name, email address, telephone number, the services you offer, and a description of what you want your website to do.
Legal basis: Art. 6(1)(b) GDPR — steps taken at your request prior to entering a contract. If your enquiry does not lead to a contract, our legitimate interest in retaining a record of the exchange applies instead, Art. 6(1)(f).
Providing this data is voluntary, but we cannot quote for a website without knowing what it should contain.
| Data | Purpose | Legal basis |
|---|---|---|
| Name, business name, billing address, email, telephone | Performing the contract, issuing invoices | Art. 6(1)(b) |
| Content you supply for your website — text, photos, logo, opening hours, staff names | Building the website you ordered | Art. 6(1)(b) |
| Payment records: amount, date, subscription status, last four digits of card | Processing payment, accounting | Art. 6(1)(b) and Art. 6(1)(c) |
| Invoices and accounting records | Statutory retention | Art. 6(1)(c) — §§ 147 AO, 257 HGB |
| Support correspondence | Answering your questions, documenting agreed changes | Art. 6(1)(b) and 6(1)(f) |
We never receive your full card number. Card details are entered directly into Stripe's payment form and are never transmitted to or stored on our systems.
For the website we build and host for you, you are the controller and we are the processor. You decide what personal data your site collects — for example through a contact form — and you are responsible for having a lawful basis and your own privacy notice for it.
Where required, we will enter into a data processing agreement with you under Art. 28 GDPR. Ask us and we will provide one at no cost.
Personal data submitted through forms on your website — names, email addresses, messages from your own customers — is forwarded to your email address and stored on our servers only for as long as is necessary to deliver it. We do not use it for any purpose of our own, we do not sell it, and we do not use it to market to your customers.
We keep this list short deliberately. Every additional processor is an additional risk.
| Provider | What they process | Where |
|---|---|---|
| Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) | Payment data, subscription billing, fraud prevention | EU and USA |
| Our hosting provider | Server logs, website files, form submissions | Germany |
| Our email provider | Correspondence with you | Germany |
| Our domain registrar | Domain registration data where we register a domain on your behalf | EU |
Each of these acts on our documented instructions under an Art. 28 GDPR processing agreement. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to third parties for their own purposes. Disclosure to public authorities occurs only where we are legally compelled.
Personal data is primarily stored on servers in Germany. Transfers to the United States occur in connection with payment processing through Stripe.
These transfers are safeguarded by the EU Standard Contractual Clauses adopted by the European Commission and, where the recipient is certified, by the EU–U.S. Data Privacy Framework. You may request a copy of the safeguards in place by writing to privacy@pagesaway.com.
You should be aware that US law permits public authorities access to personal data in circumstances that the European Court of Justice has previously found not fully equivalent to EU standards. We limit US transfers to what is strictly necessary for payment.
| Category | Period | Why |
|---|---|---|
| Server logs | IP shortened after 7 days, logs deleted after 30 days | Security and error diagnosis |
| Enquiries that did not become contracts | 12 months | Follow-up and evidence of the exchange |
| Customer and project data | Duration of the contract, then 3 years | German statute of limitations, § 195 BGB |
| Invoices and accounting records | 10 years from the end of the calendar year | Mandatory under §§ 147 AO, 257 HGB |
| Website backups | 30 days rolling | Recovery after failure or error |
Statutory retention periods override deletion requests. Where we must keep a record for tax purposes, we restrict its processing to that purpose alone rather than deleting it.
You can exercise any of these free of charge. We respond within one month; complex requests may take up to three, and we will tell you if that applies.
Based on our size and the volume of data we handle, we do not currently meet the applicability thresholds of the California Consumer Privacy Act or the comprehensive privacy statutes of other US states.
We nevertheless extend the following to every customer and visitor, regardless of residence, because we consider them the correct baseline rather than a compliance obligation:
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA. We have never done so and have no plans to. There is therefore no "Do Not Sell or Share My Personal Information" mechanism on this site — there is nothing for it to switch off.
Requests go to privacy@pagesaway.com. We will verify your identity by replying to the email address we hold for you before disclosing any data.
All connections to our website and to the websites we host are encrypted with TLS. Data at rest is stored on servers in Germany with access limited to the operator. Backups are encrypted. We apply security updates to server software promptly.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours under Art. 33 GDPR and inform you directly where the risk is high under Art. 34.
Our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
We will update this policy when our processing changes. The version number and date at the top always reflect the current text. Where a change materially affects your rights, we will notify active customers by email at least 30 days before it takes effect.
We do not make changes retroactive. Data collected under a previous version continues to be handled under the terms in force when it was collected, unless the newer terms are more protective.
Privacy enquiries and rights requests: privacy@pagesaway.com
Postal: Davis von Löwe Kiedrowski, Walsroder Straße 158, 30853 Langenhagen, Germany
Full provider details are in our Legal Notice.