Privacy
Last updated: September 2026. This English version is a convenience translation. Only the German version is legally binding.
This statement explains which data arise when you visit this website, what they are processed for and what rights you have. It describes exactly what this site does, and nothing beyond that.
Who is responsible
Essential Advertising GmbH
Adenauerallee 2, 61440 Oberursel (Taunus), Germany
Represented by Daniel Klantke, Managing Director
Phone: +49 6172 90 84 747
Email: hello@lindenbrook.ai
lindenbrook is a brand of Essential Advertising GmbH.
We have not appointed a data protection officer because the requirements of Art. 37 GDPR and Section 38 BDSG are not met. The contact for all data protection questions is the managing director at the address above.
What happens when you visit this site
When you open this site, your browser transmits technically necessary information to the server: your IP address, the date and time of the request, the address requested, the amount of data transferred, the message on whether the request succeeded, the referring page as well as browser and operating system. Without this information the site cannot be delivered.
It is stored in the server's log files and serves solely the secure operation of the site, in particular detecting faults and attacks. It is not combined with other data and not evaluated in relation to you.
The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in the secure and functioning operation of this website. The logs are deleted after 30 days at the latest.
Visitor counts without cookies
This site sets no cookies and stores nothing on your device to recognise you. There is no Google Analytics, no Meta pixel and no recognition across devices. The only exception is the AI check, which keeps your answers in your browser for the duration of the session, see the section on booking an appointment.
We do, however, count which pages are visited. We record: the page visited, its title and language, the type of your device, browser and operating system, the country of access and the website you came from, and only its address without any additions. We also count clicks on individual paths such as booking, contact or language switching, together with the label of the link clicked, whether an AI check was started and completed (without your answers), whether a booking was confirmed and whether a form reported an error.
Your IP address is not stored. From it, your device information, the date of the day and a secret known only to us, an identifier is calculated. Only this identifier is stored. It cannot be reversed and changes every night. This lets us group the visits of one day, but not recognise you across several days.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in understanding which content is needed and where the site does not work. The data is processed in the European Union, by Supabase in the Frankfurt area. It is deleted after 24 months, not sold and not used for advertising. When a personal proposal page under /fuer/ is opened, we receive an email with the page, time, type of device, country and referrer. It is sent via Resend, see the section on the contact form.
If your browser sends the “Do Not Track” setting or an objection signal such as Global Privacy Control, we do not count you. You can also object to the counting at any time without giving reasons. A message to hello@lindenbrook.ai is enough.
You still will not see a consent banner. In our assessment, no consent under Section 25 TDDDG is required for the visitor count: it stores nothing on your device and only uses information your browser transmits anyway when a page is requested. The only thing read is whether your browser sends an objection signal, so that we do not count you in that case.
The only setting this site knows is the choice between a light and a dark appearance. It follows the setting of your operating system and is not stored.
No connections to third-party servers
We deliver fonts, images, videos and program code entirely from our own server. Opening this site establishes no connection to Google Fonts, to a third-party delivery network or to a social network. No maps, no third-party video players and no social media buttons are embedded. Booking also runs on our own server, without an embedded window from a booking service.
Your IP address is therefore passed on to no one other than the provider that delivers this site.
When you write to us
Through our contact form we process the information you provide there: your name, your email address, your company, if you wish the topic, and your message. We use it exclusively to answer your enquiry. It is not stored in a database. The enquiry is delivered as an email.
We use Resend, a service of Resend Inc., 2261 Market Street, San Francisco, CA 94114, United States, for sending. Resend is our processor under Art. 28 GDPR. Two emails are sent: your enquiry to us and an acknowledgement to you that does not repeat your message. Our mailbox is hosted by IONOS SE in Germany. Where data may reach the United States or Singapore in the process, we base the transfer on the European Commission's standard contractual clauses (Art. 46 (2) (c) GDPR), which form part of the respective data processing agreement, and, for providers certified under the EU-US Data Privacy Framework, additionally on the Commission's adequacy decision (Art. 45 GDPR).
If you contact us directly by email or phone instead, we process your information in the same way: only to answer your enquiry.
To protect against spam and automated requests, when you submit the contact form or a booking we check whether the request comes from our website, how long it took to fill in and whether the text shows typical signs of spam. We also store, for no more than 15 days, a code that is calculated with a secret key from your IP address (for IPv6, from its network range) and from your email address. Neither the IP address nor the email address can be recovered from this code. Its only purpose is to limit the number of requests from the same sender within a short time, and it is kept in the same database as the bookings, see the following section. Requests that are clearly automated are discarded. If a request only looks suspicious, we still deliver it but send no confirmation. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is protecting our forms against misuse.
We delete enquiries once they have been dealt with, at the latest after six months, unless statutory retention periods apply. The legal basis is Art. 6 (1) (b) GDPR for an enquiry about a possible contract, otherwise Art. 6 (1) (f) GDPR.
A message to us does not sign you up to any mailing list. That would require a separate registration that you would have to make yourself.
When you book an appointment
On the booking page you can choose a time for a first call. The selection runs on our own server. No booking service is embedded, opening the page establishes no connection to a third-party provider and no cookies are set.
We process the information you provide: the chosen time, whether you want a phone call or a video call, your name, your company, your email address and, if you give it, your phone number and an optional note. We use it exclusively to confirm and hold the appointment. The legal basis is Art. 6 (1) (b) GDPR, because the booking serves to initiate a contract.
So that an appointment cannot be given out twice, we store the booking in a database. It is hosted by Supabase, Inc., 970 Toa Payoh North, Singapore, in a data centre in Frankfurt am Main. Supabase is our processor under Art. 28 GDPR. Only lindenbrook has access to the stored information. The website itself cannot read it.
In addition, we send two emails: the booking to us and a confirmation to you. For this we use the same service provider as for the contact form, see the previous section. The appointment is then entered in our calendar, which is hosted by Microsoft Ireland Operations Limited in data centres in the European Union. Microsoft is our processor under Art. 28 GDPR. If you chose a video call, we invite you to a Microsoft Teams meeting. Your email address is passed on to Microsoft for this.
If you completed the AI check beforehand, the booking page offers to send along a summary of your result. Until then, this summary is held only in your browser, in session storage, and is deleted as soon as you close the window. It only reaches us if you leave the box ticked and submit the booking. You see the full text on the page beforehand. After that it is treated like the rest of the appointment data.
The AI check stores your answers and, at the end, the summary in your browser's session storage (the entries lb-kicheck-stand and lb-kicheck). This lets you continue the check after changing pages and carry the result over to the booking. Both remain on your device, are not transmitted to us and are deleted as soon as you close the window. If you leave the check unused for two hours, the page discards both the next time it is opened. This storage is permitted without consent under Section 25 (2) no. 2 TDDDG, because it is necessary for the function you requested. As long as you only fill in the check, your answers do not leave your browser.
We delete appointment data as soon as it is no longer needed, at the latest after six months, unless statutory retention periods apply.
You do not have to use online booking. You can reach us just as well via the contact form, by email or by phone.
Who delivers this site
This site runs on the infrastructure of Vercel Inc., based in the United States. It is delivered from data centres in the European Union, located in Frankfurt am Main. Vercel is our processor; a data processing agreement under Art. 28 GDPR is in place. Where data may reach the United States or Singapore in the process, we base the transfer on the European Commission's standard contractual clauses (Art. 46 (2) (c) GDPR), which form part of the respective data processing agreement, and, for providers certified under the EU-US Data Privacy Framework, additionally on the Commission's adequacy decision (Art. 45 GDPR). The same applies to Supabase, see the section on booking an appointment.
Your rights
At any time you have the right to:
- access the data stored about you (Art. 15 GDPR)
- have incorrect data corrected (Art. 16 GDPR)
- have data erased (Art. 17 GDPR)
- restrict processing (Art. 18 GDPR)
- receive your data in a portable format (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent with effect for the future (Art. 7 (3) GDPR)
An informal message to hello@lindenbrook.ai is enough. We reply within one month.
You can also lodge a complaint with a supervisory authority. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.
Security
Transmission is always encrypted via HTTPS. Access to data is limited to what is necessary.
Changes
We update this statement as soon as our data processing or the legal situation changes. The current version is always available here.
Last updated: September 2026. This English version is a convenience translation. Only the German version is legally binding.
A question about your data?
You can request information or object to processing at any time.