1. Controller
The controller responsible for processing personal data through this website is:
Mirko van Anken
trading as MvA Marketing
Kästnerstr. 9
49406 Barnstorf
Germany
Telephone: +49 (5442) 91180
Email: mirkovamarketing (@) gmail.com
2. Scope of this policy
This Privacy Policy explains how we process personal data when you visit mirkovamarketing.com, contact us, subscribe to marketing communications, purchase or access a digital product, use a membership area, or interact with a sales page operated by us through a third-party service.
Personal data means information relating to an identified or identifiable person. Processing includes collecting, storing, using, transmitting and deleting personal data.
3. Website hosting and server logs
This website is hosted using services provided by HostGator.com, LLC. When you access the website, the hosting infrastructure may process technical information such as:
IP address;
date and time of access;
requested page or file;
referrer URL;
browser type and version;
operating system;
device information; and
access status or error messages.
This processing is necessary to deliver the website, maintain security, identify technical problems and defend against misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure and reliable operation of our website. Where processing is required to take steps at your request or provide a contracted service, Article 6(1)(b) GDPR may also apply.
Log data is retained only for as long as reasonably necessary for security, troubleshooting and legal purposes, subject to the hosting providerâs documented retention periods.
HostGator may process data outside the European Economic Area. Where required, transfers are protected by an applicable adequacy decision, appropriate safeguards such as standard contractual clauses, or another lawful transfer mechanism under Chapter V GDPR.
4. WordPress and technically necessary functions
Our website uses WordPress. WordPress and installed plugins may process technical data or place technically necessary cookies to provide security, page navigation, login sessions, forms, preferences and membership functions.
Technically necessary storage or access is based on Section 25(2) TDDDG. Associated personal-data processing is based on Article 6(1)(b) GDPR where required to provide a requested service, or Article 6(1)(f) GDPR for secure and functional website operation.
5. Contacting us
If you contact us by email, telephone or through a contact form, we process the information you provide, normally including your name, contact details, message and related correspondence.
If your request concerns a contract or steps before entering a contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is responding to enquiries and maintaining business communications. Where a legal retention obligation applies, Article 6(1)(c) GDPR is the legal basis for continued storage.
6. Email newsletters and marketing communications
We use GetResponse and SendOnyx to manage email lists, subscriptions, automated sequences and marketing communications. Depending on the form and system used, we may process:
name and email address;
date, time and source of registration;
consent record and confirmation status;
IP address used during registration or confirmation;
tags, list membership and preferences;
messages, replies and support history;
delivery, bounce and unsubscribe information; and
opening and link-interaction data where email measurement is enabled and lawfully consented to.
Marketing emails are sent on the basis of your consent under Article 6(1)(a) GDPR and the applicable requirements for electronic marketing. We normally use a confirmation process to document subscription consent. You may withdraw consent at any time by using the unsubscribe link in an email or contacting us. Withdrawal does not affect processing that was lawful before withdrawal.
Operational emails required to deliver a purchase, provide access, confirm account activity or answer a support request may be sent under Article 6(1)(b) GDPR and are not dependent on newsletter consent.
Where opening or click measurement involves access to information on your device or similar tracking, it will be activated only when the necessary consent has been obtained. If the configured mailing system does not provide a lawful consent mechanism for such measurement, the measurement function should be disabled for affected recipients.
GetResponse is operated by GetResponse S.A., Grunwaldzka 413, 80-309 GdaĹsk, Poland. SendOnyx acts as an email-service provider according to the account configuration and applicable provider documentation. Service providers process data on our behalf where an appropriate data-processing arrangement applies.
7. Sales funnels and landing pages through Systeme.io
We use Systeme.io for landing pages, forms, funnels, email functions and related digital marketing operations. The service is provided by ITACWT Limited, 2 Cruise Park Rise, Tyrrelstown, Dublin 15, Ireland.
When you use a Systeme.io page or form operated by us, the service may process contact information, form entries, technical data, cookies, page interactions, purchase-related information and account data. Processing for requested content, account creation or a purchase is based on Article 6(1)(b) GDPR. Security and reliable operation are based on Article 6(1)(f) GDPR. Optional marketing or tracking functions are based on Article 6(1)(a) GDPR where consent is required.
8. Product delivery and membership areas through ProductDyno
We use ProductDyno to provide protected digital content, customer accounts and membership access. ProductDyno may process a customerâs name, email address, account credentials, purchase or access status, IP address, login data and usage information necessary to provide and secure the membership area.
Processing required to deliver purchased products and administer access is based on Article 6(1)(b) GDPR. Processing for security, fraud prevention and reliable platform operation is based on Article 6(1)(f) GDPR.
Customers must keep login details confidential and should contact us promptly if they suspect unauthorised account access.
9. Purchases through WarriorPlus, JVZoo and ClickBank
Our standard digital products may be offered through WarriorPlus, JVZoo or ClickBank. These platforms provide checkout, payment, transaction administration, affiliate tracking and refund-related functions according to the specific offer and the platformâs terms.
When you purchase through one of these platforms, the platform may independently collect and process identity, contact, transaction, tax, device, fraud-prevention and payment information. PayPal or Stripe may be offered by the platform as a payment method. We do not operate a separate direct PayPal or Stripe checkout on this website.
We may receive information necessary to identify the purchase, deliver access, provide support, prevent fraud, maintain records and process or respond to a refund request. This may include your name, email address, order number, product, transaction date, payment status, refund status and affiliate attribution.
Processing for fulfilment, customer access, support and refunds is based on Article 6(1)(b) GDPR. Processing required for accounting and tax compliance is based on Article 6(1)(c) GDPR. Fraud prevention and the establishment or defence of legal claims are based on Article 6(1)(f) GDPR.
The platform and payment provider may act as independent controllers for their own processing. Their privacy notices apply to information collected directly through their services.
10. Affiliate links and tracking
This website contains affiliate links. If you click an affiliate link, the destination platform or merchant may use a link identifier, cookie or comparable technology to recognise that a referral came from us. If you later purchase, we may receive a commission and limited reporting information.
Affiliate links are identified in context where required. Any non-essential cookie or device access on our own website is used only with consent where required under Section 25 TDDDG. Once you follow an external link, the destination provider is responsible for its own processing.
11. Cookies and consent management
We use technically necessary cookies and similar functions required to provide the website and services requested by users. Optional analytics, advertising, personalisation or cross-site tracking technologies will not be activated on this website unless an appropriate consent mechanism has been implemented and the required consent has been obtained.
We do not currently state that Google Analytics, Meta Pixel or comparable analytics and advertising pixels are active. This Privacy Policy and the consent interface must be updated before any such service is enabled.
You can withdraw or change a cookie decision at any time through the âCookie Settingsâ link once the consent-management tool has been installed. Browser settings can also restrict cookies, but blocking necessary cookies may affect website or membership functionality.
12. Recipients
We disclose personal data only where necessary and lawful. Recipient categories may include:
hosting, website and IT providers;
email marketing and communication providers;
sales-funnel and form providers;
membership and product-delivery providers;
checkout, marketplace and payment providers;
accountants, tax advisers, legal advisers and other professional advisers;
public authorities where disclosure is legally required; and
parties involved in a business transfer, subject to applicable confidentiality and data-protection requirements.
We do not sell personal data.
13. International data transfers
Some service providers or their subprocessors may be located outside the European Economic Area. Where personal data is transferred to a third country, we rely on a lawful mechanism such as an adequacy decision, the EU-US Data Privacy Framework where applicable to a certified recipient, standard contractual clauses combined with supplementary measures where required, or another mechanism permitted by Chapter V GDPR.
You may contact us for further information about safeguards relevant to a particular transfer.
14. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected and to satisfy legal obligations.
Typical criteria include:
contact enquiries: until the enquiry is resolved, followed by a reasonable period for documentation;
newsletter records: until consent is withdrawn, plus a limited suppression record to ensure the withdrawal is respected;
customer, transaction and accounting records: for the periods required by applicable German commercial and tax law;
membership data: for the duration of access and a reasonable period thereafter, subject to contractual and legal requirements;
consent records: for as long as required to demonstrate lawful processing; and
security logs: for a limited period appropriate to security and troubleshooting needs.
Data may be retained longer where necessary to establish, exercise or defend legal claims. Data no longer required is deleted or anonymised.
15. Your rights
Subject to the legal requirements, you may have the right to:
obtain information about and access to your personal data;
correct inaccurate or incomplete data;
request deletion;
request restriction of processing;
receive data you provided in a structured, commonly used and machine-readable format;
object to processing based on legitimate interests;
withdraw consent at any time; and
lodge a complaint with a data-protection supervisory authority.
Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without providing reasons.
The supervisory authority generally responsible for a private business established in Lower Saxony is:
The State Commissioner for Data Protection of Lower Saxony
PrinzenstraĂe 5
30159 Hannover
Germany
Website: https://www.lfd.niedersachsen.de
You may also contact another competent supervisory authority where permitted by law.
16. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure and access. No internet transmission or storage system can be guaranteed to be completely secure.
17. Children
Our products and services are directed to adults and are not intended for persons under 18. We do not knowingly solicit personal data from children. If you believe a minor has provided personal data, please contact us.
18. Automated decision-making
We do not use solely automated decision-making that produces legal effects or similarly significant effects concerning website visitors or customers, unless separately disclosed where such processing is introduced.
19. Updates to this policy
We may update this Privacy Policy when our website, providers or legal obligations change. The current version date appears at the top of the page. Material changes will be communicated where required by law.
