SourcingClub

Privacy Policy

1. Data Controller

Responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

SourcingClub
Eppendorfer Weg 266
20251 Hamburg, Germany
Managing Director: Nick Herbig
Email: deals@sourcingclub.de

2. Overview of Data Processing

The following overview summarizes the types of data processed and the purposes of their processing: inventory data (e.g., names, addresses), contact data (e.g., email addresses), content data (e.g., entries in the contact form and valuation calculator), usage data (e.g., pages visited, access time), and meta/communication data (e.g., IP addresses, browser information).

3. Applicable Legal Bases

Below is an overview of the GDPR legal bases on which I process personal data:

  • Consent (Art. 6 Para. 1 lit. a GDPR) — e.g., for the use of Google Analytics after cookie consent.
  • Contract performance and pre-contractual inquiries (Art. 6 Para. 1 lit. b GDPR) — e.g., when processing contact inquiries and using the company valuation calculator.
  • Legitimate interests (Art. 6 Para. 1 lit. f GDPR) — e.g., for the security and operation of the website and analysis of user behavior to improve the offering.

4. Security Measures

Appropriate technical and organizational measures are taken in accordance with legal requirements, considering the state of the art, to ensure a level of protection appropriate to the risk. These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access. All communication between your browser and the website is encrypted via SSL/TLS (HTTPS).

5. Data Transfer to Third Countries

If data is processed in a third country (i.e., outside the European Union or the European Economic Area) or if processing takes place in the context of using third-party services, this is only done in accordance with legal requirements. For the USA, an adequacy decision by the EU Commission exists (EU-U.S. Data Privacy Framework). Otherwise, data transfer only occurs on the basis of Standard Contractual Clauses (Art. 46 Para. 2 lit. c GDPR) or explicit consent.

6. Retention and Deletion

Personal data is deleted as soon as the purpose of storage ceases to apply, unless statutory retention obligations exist (e.g., commercial or tax law retention obligations of up to 10 years). After expiration of the respective periods, the data is routinely deleted.

7. Website Provision and Web Hosting

This website is hosted by Vercel Inc. (440 N Baxter St, Los Angeles, CA 90012, USA). When you visit the website, Vercel automatically collects information in server log files that your browser transmits: IP address, browser type and version, operating system used, referrer URL, hostname of the accessing computer, and time of server request. This data is processed to ensure trouble-free operation. It is not merged with other data sources. Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interest in secure and efficient operation). Vercel is certified under the EU-U.S. Data Privacy Framework. More information: https://vercel.com/legal/privacy-policy

8. Cookies

This website uses cookies. Cookies are small text files stored on your device.

Technically Necessary Cookies

A technically necessary cookie is used to store your cookie preferences (cookie-consent). This cookie is required for the operation of the website and cannot be disabled. It contains no personal data and is stored exclusively locally in your browser (localStorage). Legal basis: Art. 6 Para. 1 lit. f GDPR.

Analytics Cookies

Analytics cookies (Google Analytics) are only activated after your explicit consent via the cookie banner. You can revoke your consent at any time by deleting your browser cookies. Legal basis: Art. 6 Para. 1 lit. a GDPR.

9. Google Analytics

This website uses Google Analytics 4, a web analytics service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics is only activated when you consent to analytics cookies via the cookie banner.

Google Analytics is used with the "anonymize_ip" extension, so that IP addresses are only processed in shortened form to exclude direct personal identification. The information generated by the cookie about your use of this website is typically transferred to a Google server in the USA. Google is certified under the EU-U.S. Data Privacy Framework.

You can prevent data collection by Google Analytics by downloading and installing the browser add-on: https://tools.google.com/dlpage/gaoptout. Legal basis: Art. 6 Para. 1 lit. a GDPR (consent). More information: https://policies.google.com/privacy

10. Contact Form

When inquiries are sent via the contact form, the provided details (name, email address, optionally company, message) are stored for processing the inquiry and for follow-up questions. Transmission occurs via the email service provider Resend (see Section 12). Data is not shared with other third parties without consent. Legal basis: Art. 6 Para. 1 lit. b GDPR (pre-contractual measures) and Art. 6 Para. 1 lit. f GDPR (legitimate interest in processing inquiries). Data is deleted after final processing, unless statutory retention obligations apply.

11. Company Valuation Calculator

When using the company valuation calculator, the company data you enter (industry, legal form, number of employees, location, financial data, qualitative assessments) is processed. The calculation takes place entirely in your browser (client-side). Your financial data is not transmitted to the servers.

If you request the optional PDF report, your name, email address, and optionally your phone number are transmitted to the server and stored for creating and delivering the report and for potential follow-up contact. Legal basis: Art. 6 Para. 1 lit. a GDPR (consent) and Art. 6 Para. 1 lit. b GDPR (pre-contractual measures).

12. Email Delivery (Resend)

For sending emails (e.g., contact form inquiries, PDF reports), the service Resend (Resend Inc., San Francisco, USA) is used. The data necessary for email delivery (email address, message content) is transferred to Resend. Resend processes this data on behalf of the data controller. Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interest in reliable email delivery). Resend is certified under the EU-U.S. Data Privacy Framework. More information: https://resend.com/legal/privacy-policy

13. Appointment Scheduling (Calendly)

For appointment scheduling, the service Calendly (Calendly LLC, 3423 Piedmont Rd NE, Atlanta, GA 30305, USA) is used. When you book an appointment through the Calendly widget embedded on this website, the data you enter (name, email address, and any additional information) is transferred directly to Calendly. Calendly uses this data exclusively for appointment management. Calendly is certified under the EU-U.S. Data Privacy Framework. Legal basis: Art. 6 Para. 1 lit. b GDPR (pre-contractual measures). More information: https://calendly.com/privacy

14. SSL/TLS Encryption

This website uses SSL/TLS encryption for security purposes and to protect the transmission of confidential content. You can recognize an encrypted connection by the browser address bar changing from "http://" to "https://" and the lock icon in your browser bar.

15. Rights of Data Subjects

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR): You have the right to obtain confirmation as to whether personal data concerning you is being processed, and to access such data.
  • Right to rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate personal data or the completion of incomplete data.
  • Right to erasure (Art. 17 GDPR): You have the right to request the immediate deletion of personal data concerning you, provided one of the legally specified reasons applies.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of processing if one of the legal prerequisites is met.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format.
  • Right to object (Art. 21 GDPR): You have the right to object to the processing of personal data concerning you at any time for reasons arising from your particular situation.
  • Right to withdraw consent (Art. 7 Para. 3 GDPR): Any consent given can be revoked at any time with effect for the future.

To exercise your rights, please contact: deals@sourcingclub.de

16. Changes to This Privacy Policy

I reserve the right to update this privacy policy to ensure it always complies with current legal requirements or to implement changes to the services. The new privacy policy will apply to your subsequent visits.

Last updated: March 2026