Tariq Khan | Public Impact
Am Neuen Markt 9 E-F
14467 Potsdam
Germany
Email: [email protected]
Types of data processed: contact data such as name, email address and company; contract data such as the project commissioned and its duration; content data such as briefings and material provided by clients; usage data such as access logs and IP addresses; meta and communication data such as device and browser information.
Categories of data subjects: visitors to this website, prospective clients, business and contractual partners.
Purposes: providing this website, handling enquiries, performing contracts, producing marketing content on behalf of clients, security and fraud prevention.
Performance of a contract and steps taken prior to entering into a contract under Article 6(1)(b), for delivering the agreed services and for answering your enquiry. Legal obligation under Article 6(1)(c) for record-keeping and tax duties. Legitimate interests under Article 6(1)(f) for secure and efficient operation of the website. No consent is collected on this website, because nothing here requires it.
Technical and organisational measures are in place to protect personal data appropriately, including encryption, restricted access and regular review of the services used.
This website uses no analytics, no advertising and no tracking. It sets no cookies and needs no cookie banner. The typefaces are served from this website itself, so no data is sent to a font service. All videos play directly from this website and are not embedded from YouTube, Vimeo or any other platform, so no data is sent to a video provider.
Hosting: the site runs on Cloudflare Pages, operated by Cloudflare, Inc. Cloudflare processes server log data, including IP address and browser information, to deliver and secure the website. Legal basis: Article 6(1)(f) GDPR. How long those logs are kept is determined by the hosting provider, see cloudflare.com/privacypolicy. Where data is transferred to the United States, the transfer is based on the European Commission's standard contractual clauses under Article 46(2)(c) GDPR.
Name, email address and message are required so that I can answer you; the company field is optional. Without the required fields the form cannot be sent, and you can always write an email instead.
What happens with the data: the form posts to a Cloudflare Worker operated by me. The Worker first stores the enquiry in Cloudflare KV as a backup, where it is deleted automatically after 30 days, and then sends it on by email through Resend, operated by Resend, Inc. The email is sent from [email protected] and arrives in my own mailbox. Legal basis: Article 6(1)(b) GDPR for steps taken prior to entering into a contract and Article 6(1)(f) GDPR for the legitimate interest in answering enquiries. Beyond the 30-day backup, the data is kept until your enquiry has been handled and any statutory retention periods have expired.
The booking link on this site opens cal.eu/publicimpact/strategyintrocall, operated by Cal.com. No booking widget is embedded here, so nothing is loaded from Cal before you follow that link. If you book an appointment there, Cal processes the data you enter, such as name, email address and appointment details. Legal basis: Article 6(1)(b) GDPR. Cal's privacy policy: cal.com/privacy.
Invoicing (Lexware): invoices are created in Lexware and sent by email. Lexware processes contract data such as name, address and service details.
Social media scheduling (Metricool): used to plan and publish social media content within client projects, which can involve content data from those projects.
AI-assisted systems, language models and external programming interfaces are used to deliver the services. Content provided by clients may be processed by those systems, solely for the purpose of delivering the agreed services. I do not use client data to train AI models; the terms of the providers involved apply in addition. A current list of those providers is available on request at [email protected].
This website is open to the AI training crawlers of the large model providers, among them GPTBot by OpenAI, ClaudeBot by Anthropic, PerplexityBot and Google-Extended by Google. Content published publicly here can be collected by those providers and used to train their language models or to answer their users' questions. Access can be controlled per provider through the robots.txt file of this website. If you are a data subject and wish to object to the processing of your publicly available data here for AI training, write to [email protected]. The crawler rules or the content in question will then be adjusted.
Where data is processed outside the EU and EEA, it is transferred only to countries covered by an adequacy decision or on the basis of the European Commission's standard contractual clauses.
Where data is processed on the basis of legitimate interests under Article 6(1)(f) GDPR, which here means operating the website and answering enquiries, you have the right to object to that processing at any time on grounds relating to your particular situation, under Article 21 GDPR. An email to [email protected] is enough.
Under the GDPR you also have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), and the right to lodge a complaint with a supervisory authority (Article 77). The supervisory authority responsible here is Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow. To exercise your rights, write to [email protected].
This policy may be updated to reflect changes to the website or to legal requirements. The current version is always available on this page.