Tan Kayitmaz
Privacy Policy
Transparent information about the processing of personal data on kayitmaz.ch, kayitmaz.de and kayitmaz.com – last updated 18 July 2026.
1. Controller
Tan Kayitmaz
Rappenstraße 9
75045 Walzbachtal
Germany
Email: tan@kayitmaz.ch
No data protection officer has been appointed because no statutory appointment requirement is currently apparent.
2. Hosting and server logs
The website is hosted by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. A data processing agreement is in place with the hosting provider.
When the website is requested, technically necessary log data is processed: IP address, date and time, requested file or URL, access status, transferred data volume, referrer, browser, operating system and language information. Processing is required to deliver, stabilise and secure the website and is based on Art. 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of the service.
According to the hosting provider, regular server logs are deleted after no more than seven days. A longer period may be necessary in the event of a specific security incident.
3. Encrypted transmission
The website uses TLS encryption to protect content, form details and other transfers between your browser and the server from unauthorised access. Complete security of electronic transmissions cannot be guaranteed.
4. Enquiry form and email
Depending on the information you provide, an enquiry processes your name, company, email address, optional telephone number, role and function, purpose, topics, timeframe, message, language and submission time. The information is sent to Tan Kayitmaz by email; the form does not create an additional customer database.
The purpose is to respond to your enquiry and initiate or perform a business relationship. The legal basis is Art. 6(1)(b) GDPR and, for general communications, Art. 6(1)(f) GDPR. Required information is needed to classify and answer the enquiry. The form cannot be submitted without it.
Enquiries are erased once the matter has been conclusively resolved. Where a contractual relationship follows or statutory evidence, commercial or tax retention duties apply, the relevant records are retained for the applicable statutory period.
5. Protection against misuse
The enquiry and checkout systems use timing checks, an invisible spam field and request rate limiting. The server converts the IP address into a non-reversible hash and temporarily stores it with timestamps. The normal rate-limit file covers a 15-minute window.
This processing protects the website, email inbox and payment flow from automated or abusive requests and is based on Art. 6(1)(f) GDPR.
6. Payments and Stripe Checkout
Before opening the secure Stripe Checkout, you select a displayed appointment preference and provide an email address and telephone number for confirmation and callbacks. The selected service, appointment preference, contact details, language and return address are transmitted when Checkout is created. Stripe Checkout then additionally collects information such as name, billing address, where applicable a tax ID, payment details and transaction information. Full card or account details are not stored on this website.
After successful payment, Stripe sends a signed server event to this website. The selected service, appointment preference, payment status, name, email address and telephone number are then emailed to Tan Kayitmaz as booking information. Availability shown in the calendar is provisional; personal appointment confirmation follows separately.
Payment services are provided by the Stripe group. The contracting entity for many EEA services is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Other Stripe entities and financial service providers may be involved depending on the payment method and context.
Processing is necessary for pre-contractual steps, performance of a contract and payment processing under Art. 6(1)(b) GDPR, and may be required for statutory tax and retention duties under Art. 6(1)(c) GDPR. Stripe also processes certain data as an independent controller, including for fraud prevention and financial-law compliance. Data may be transferred to third countries in accordance with Stripe's privacy policy and the transfer mechanisms described there.
7. Local preferences, cookies and consent management
This website does not use analytics, marketing or profiling cookies and does not perform audience measurement. Fonts, images and scripts are delivered locally from the website's own domain.
The website uses browser storage solely for settings you choose: ‘tk-theme’ stores light or dark mode, ‘tk-locale-preference’ stores your language selection and ‘tk-consent-v1’ stores your privacy choices. These entries remain until deleted, replaced or changed through the cookie settings. Dismissing the one-time language suggestion is stored for the browser session and removed when the tab is closed.
This storage is required to provide the display and language settings requested by you. The information is not transmitted to the website operator. If no preference is stored, the browser language, requested domain and operating-system colour scheme are evaluated locally only.
Where optional analytics or external media are offered on a page, they are enabled only after your active consent. You can change or withdraw your choice at any time through ‘Cookie settings’ in the footer.
Stripe may place its own technically necessary cookies or similar technologies on the external Checkout page. Stripe's information applies there.
8. Recipients and international transfers
Recipients receive data only where necessary for hosting, communication, payment processing, legal or tax obligations. They include ALL-INKL.COM as processor and, when Checkout is used, Stripe and the selected payment networks.
Hosting takes place in Germany. No transfer outside the European Economic Area is intended through this website itself. Stripe's global infrastructure may involve international transfers under its privacy terms; Stripe describes the applicable adequacy decisions and safeguards, including EU Standard Contractual Clauses.
9. Your rights
Subject to the statutory requirements, you have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Consent can be withdrawn at any time with future effect.
To exercise your rights, email tan@kayitmaz.ch. A proportionate proof of identity may be requested to prevent unauthorised disclosure.
10. Right to lodge a complaint
Under Art. 77 GDPR you may lodge a complaint with a data protection authority. The authority responsible for the controller's place of establishment is: The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany; email: poststelle@lfdi.bwl.de.
11. Automated decisions and updates
The controller does not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. Payment providers may use their own automated fraud and risk checks.
This policy will be updated if the technology, providers or legal framework change. The version published on this website applies.

