Privacy Policy

Last updated: 19 August 2026 · Version 1.0

PagesAway is operated from Germany. That means the EU General Data Protection Regulation (GDPR) governs everything we do with personal data — including data about customers and visitors located in the United States. This policy explains what we collect, why, how long we keep it, and what you can require us to do. It is written to be read, not to be skimmed past.

Contents
  1. Who is responsible
  2. Why EU law applies to US customers
  3. Data we collect from website visitors
  4. Data we collect from enquiries
  5. Data we collect from customers
  6. Data on websites we host for you
  7. Third parties who process data for us
  8. International transfers
  9. How long we keep things
  10. Your rights under GDPR
  11. Your rights under US state privacy laws
  12. Security
  13. Children
  14. Changes to this policy
  15. How to contact us

1. Who is responsible

The controller for the processing described here is:

Davis von Löwe Kiedrowski, trading as PagesAway
Walsroder Straße 158, 30853 Langenhagen, Germany
Email: privacy@pagesaway.com · Telephone: +49 511 7663766

We have not appointed a Data Protection Officer. Under § 38 BDSG this is only mandatory above thresholds we do not meet. Enquiries go directly to the address above.

2. Why EU law applies to US customers

Article 3(1) GDPR ties the regulation to where the business is established, not to where the customer lives. Because PagesAway is operated from Germany, all processing described here falls under GDPR regardless of whether you are in Texas, Tennessee or Thuringia.

In practice this works in your favour: GDPR grants broader rights than most US state privacy laws. You do not need to be an EU resident to exercise them, and we do not ask where you live before honouring a request.

3. Data we collect from website visitors

Server logs

When you load a page, our server records the request. This is a technical necessity — a web server cannot deliver a page without knowing where to send it.

DataPurposeLegal basis
IP address (shortened after 7 days)Delivering the page, detecting abuse and attacksArt. 6(1)(f) — legitimate interest in operating a secure service
Date and time, page requested, referring pageDiagnosing errors, understanding which pages are usedArt. 6(1)(f)
Browser, operating system, languageEnsuring the site renders correctlyArt. 6(1)(f)

These logs are not combined with any other data and are not used to build a profile of you.

Cookies and tracking

Our marketing website sets no cookies for analytics, advertising or tracking. There is no Google Analytics, no Meta pixel, no advertising network, and no cross-site tracking of any kind. This is why you are not being asked to click through a consent banner.

If we introduce analytics in future, we will either use a cookieless, aggregate-only tool or ask for your consent first under § 25(1) TTDSG — and this policy will be updated before, not after.

Fonts and icons

Typefaces and icon sets used on our website are served from our own servers. They are not loaded from Google Fonts, a content delivery network or any other third party, so your IP address is not transmitted to an external provider when you view a page.

4. Data we collect from enquiries

When you complete our project form or email us, we receive whatever you choose to send. Typically: your name, business name, email address, telephone number, the services you offer, and a description of what you want your website to do.

Legal basis: Art. 6(1)(b) GDPR — steps taken at your request prior to entering a contract. If your enquiry does not lead to a contract, our legitimate interest in retaining a record of the exchange applies instead, Art. 6(1)(f).

Providing this data is voluntary, but we cannot quote for a website without knowing what it should contain.

5. Data we collect from customers

DataPurposeLegal basis
Name, business name, billing address, email, telephonePerforming the contract, issuing invoicesArt. 6(1)(b)
Content you supply for your website — text, photos, logo, opening hours, staff namesBuilding the website you orderedArt. 6(1)(b)
Payment records: amount, date, subscription status, last four digits of cardProcessing payment, accountingArt. 6(1)(b) and Art. 6(1)(c)
Invoices and accounting recordsStatutory retentionArt. 6(1)(c) — §§ 147 AO, 257 HGB
Support correspondenceAnswering your questions, documenting agreed changesArt. 6(1)(b) and 6(1)(f)

We never receive your full card number. Card details are entered directly into Stripe's payment form and are never transmitted to or stored on our systems.

6. Data on websites we host for you

Important for business customers

For the website we build and host for you, you are the controller and we are the processor. You decide what personal data your site collects — for example through a contact form — and you are responsible for having a lawful basis and your own privacy notice for it.

Where required, we will enter into a data processing agreement with you under Art. 28 GDPR. Ask us and we will provide one at no cost.

Personal data submitted through forms on your website — names, email addresses, messages from your own customers — is forwarded to your email address and stored on our servers only for as long as is necessary to deliver it. We do not use it for any purpose of our own, we do not sell it, and we do not use it to market to your customers.

7. Third parties who process data for us

We keep this list short deliberately. Every additional processor is an additional risk.

ProviderWhat they processWhere
Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA)Payment data, subscription billing, fraud preventionEU and USA
Our hosting providerServer logs, website files, form submissionsGermany
Our email providerCorrespondence with youGermany
Our domain registrarDomain registration data where we register a domain on your behalfEU

Each of these acts on our documented instructions under an Art. 28 GDPR processing agreement. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to third parties for their own purposes. Disclosure to public authorities occurs only where we are legally compelled.

8. International transfers

Personal data is primarily stored on servers in Germany. Transfers to the United States occur in connection with payment processing through Stripe.

These transfers are safeguarded by the EU Standard Contractual Clauses adopted by the European Commission and, where the recipient is certified, by the EU–U.S. Data Privacy Framework. You may request a copy of the safeguards in place by writing to privacy@pagesaway.com.

You should be aware that US law permits public authorities access to personal data in circumstances that the European Court of Justice has previously found not fully equivalent to EU standards. We limit US transfers to what is strictly necessary for payment.

9. How long we keep things

CategoryPeriodWhy
Server logsIP shortened after 7 days, logs deleted after 30 daysSecurity and error diagnosis
Enquiries that did not become contracts12 monthsFollow-up and evidence of the exchange
Customer and project dataDuration of the contract, then 3 yearsGerman statute of limitations, § 195 BGB
Invoices and accounting records10 years from the end of the calendar yearMandatory under §§ 147 AO, 257 HGB
Website backups30 days rollingRecovery after failure or error

Statutory retention periods override deletion requests. Where we must keep a record for tax purposes, we restrict its processing to that purpose alone rather than deleting it.

10. Your rights under GDPR

You can exercise any of these free of charge. We respond within one month; complex requests may take up to three, and we will tell you if that applies.

11. Your rights under US state privacy laws

Based on our size and the volume of data we handle, we do not currently meet the applicability thresholds of the California Consumer Privacy Act or the comprehensive privacy statutes of other US states.

We nevertheless extend the following to every customer and visitor, regardless of residence, because we consider them the correct baseline rather than a compliance obligation:

We do not sell your data

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA. We have never done so and have no plans to. There is therefore no "Do Not Sell or Share My Personal Information" mechanism on this site — there is nothing for it to switch off.

Requests go to privacy@pagesaway.com. We will verify your identity by replying to the email address we hold for you before disclosing any data.

12. Security

All connections to our website and to the websites we host are encrypted with TLS. Data at rest is stored on servers in Germany with access limited to the operator. Backups are encrypted. We apply security updates to server software promptly.

No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours under Art. 33 GDPR and inform you directly where the risk is high under Art. 34.

13. Children

Our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Changes to this policy

We will update this policy when our processing changes. The version number and date at the top always reflect the current text. Where a change materially affects your rights, we will notify active customers by email at least 30 days before it takes effect.

We do not make changes retroactive. Data collected under a previous version continues to be handled under the terms in force when it was collected, unless the newer terms are more protective.

15. How to contact us

Privacy enquiries and rights requests: privacy@pagesaway.com

Postal: Davis von Löwe Kiedrowski, Walsroder Straße 158, 30853 Langenhagen, Germany

Full provider details are in our Legal Notice.