Last updated: October 2026
The controller within the meaning of the General Data Protection Regulation (GDPR) is Dnkfbrk GmbH, Kollwitzstraße 76, 10435 Berlin, Germany, phone +49 157 59176695, email hi@kur1.com. KUR 1 is a brand of Dnkfbrk GmbH.
We only process personal data where there is a legal basis: consent (Art. 6(1)(a) GDPR), performance of a contract and pre-contractual measures (point (b)), a legal obligation (point (c)) or a legitimate interest (point (f)). In addition, Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) applies to storing information on, and accessing information from, your device, for example through cookies. This website uses TLS encryption.
We delete personal data as soon as the purpose of processing no longer applies and no statutory retention obligations prevent deletion. Retention periods under commercial and tax law are generally six to ten years, and five years under anti-money laundering law.
This website is hosted by Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA, and delivered via a content delivery network. When you visit the website, server log files are processed automatically: the page accessed, date and time, amount of data transferred, source of access (referrer), browser, operating system and IP address. The purpose is the secure and stable operation of the website (Art. 6(1)(f) GDPR). The log files are only stored for as long as necessary for this purpose.
We have concluded a data processing agreement with Webflow. Transfers to the USA are safeguarded by the EU-US Data Privacy Framework and EU standard contractual clauses. More information: webflow.com/legal/eu-privacy-policy
We use technically necessary cookies on the basis of Section 25(2) TDDDG and Art. 6(1)(f) GDPR. All other cookies and similar technologies, in particular for statistics and advertising, are only used with your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw your consent at any time with effect for the future.
To ensure a consistent appearance, this website loads fonts from servers of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Fonts). In doing so, your IP address is transmitted to Google. The legal basis is our legitimate interest in a consistent presentation of our website (Art. 6(1)(f) GDPR). More information: policies.google.com/privacy
If you contact us by email, phone or via the contact form, we process your details, such as name, email address, phone number and message, to handle your request (Art. 6(1)(b) GDPR where there is a contractual context, otherwise point (f)). Entries in the contact form are processed via Webflow. We delete the data once your request has been fully dealt with and no retention obligations apply.
To protect our forms against misuse and spam, we use Google reCAPTCHA from Google Ireland Limited (address above). Based on information such as IP address, browser and device details and behaviour on the page, reCAPTCHA checks whether an entry was made by a human. The legal basis is our legitimate interest in protecting our website (Art. 6(1)(f) GDPR). A transfer to the USA is possible and is safeguarded by the EU-US Data Privacy Framework. More information: policies.google.com/privacy
We use Calendly from Calendly LLC, 115 E Main St, Ste A1B, Buford, GA 30518, USA, for booking consultations. The booking window is only loaded once you interact with the “Book a consultation” button. We process your details for scheduling the appointment as a pre-contractual measure (Art. 6(1)(b) GDPR). Transfers to the USA are safeguarded by the EU-US Data Privacy Framework and EU standard contractual clauses. More information: calendly.com/legal/privacy-notice
When you book a plan, we process master, contract and payment data, for example name, company, address, email address, phone number and the plan booked, to perform the contract (Art. 6(1)(b) GDPR). This includes in particular providing the business address and receiving, scanning and forwarding your mail, exclusively on your behalf. To provide our services, we use carefully selected processors, such as IT and email service providers.
As a provider of business addresses, we are an obliged entity under the German Money Laundering Act (GwG) and must identify our customers and their beneficial owners. For this purpose, we process identity document data in particular (Art. 6(1)(c) GDPR in conjunction with Sections 10 et seq. GwG). Identity verification is carried out digitally via Stripe Identity from Stripe Payments Europe, Ltd. (address below). This involves processing a photo of your identity document and, where necessary, a selfie for comparison. Stripe obtains your explicit consent for the biometric comparison (Art. 9(2)(a) GDPR). We carry out further legally required checks with specialised service providers acting as processors. We retain this data for five years after the end of the business relationship in accordance with Section 8 GwG.
We process payments via Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe receives the data required for payment (Art. 6(1)(b) GDPR, and point (f) for fraud prevention). Transfers to Stripe, Inc. in the USA are safeguarded by the EU-US Data Privacy Framework and EU standard contractual clauses. More information: stripe.com/privacy
We use Google Tag Manager from Google Ireland Limited (address above) to manage services on this website. The Tag Manager itself does not set any cookies. Services that require consent are only loaded with your consent (Art. 6(1)(f) GDPR, otherwise point (a)). More information: policies.google.com/privacy
Only with your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG) do we use Google Analytics 4 from Google Ireland Limited (address above) to statistically evaluate the use of our website. Pseudonymous usage data such as pages visited, time spent on the site and device and browser details are processed. Google Analytics 4 does not store IP addresses. A transfer to the USA is possible and is safeguarded by the EU-US Data Privacy Framework.
Only with your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG) do we use Google Ads to measure whether visitors reach our website via our ads and complete a booking. The provider is Google Ireland Limited (address above). A transfer to the USA is possible and is safeguarded by the EU-US Data Privacy Framework.
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR).
Right to object: you can object at any time to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR). You can object to processing for direct marketing purposes at any time without giving reasons.
To exercise these rights, simply contact hi@kur1.com. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59, 10555 Berlin, Germany.
We will update this privacy policy if the legal situation or our services change. The current version on this page applies.