Privacy policy of Hanseatic Media Harbour GmbH.
We measure the reach of this website with Matomo on our own server, without cookies and with a shortened IP address. When you read, your browser does not load any fonts, scripts or images from third-party providers; the only exception is the appointment calendar, which you only load on the appointment page after explicit consent (section Appointment booking). Log files are created on our server in the process. On pages with a form, the spam protection sets a session cookie, plus your decision on the notice at the bottom of the screen. If you ask a question via the search or the chat window, we transmit it to a service provider with your consent and record it in a separate log, which we evaluate. If you come via an ad or a marked campaign link and have consented, our server remembers the identifier of this click. What happens in detail is set out in the following sections.
Who is responsible
Hanseatic Media Harbour GmbH
Charlie-Mills-Straße 3
22159 Hamburg
Germany
Phone: +49 40 468 978 220
E-mail: mail@media-harbour.com
If you have a question about data protection, write to this address; your enquiry goes to the management. We have not appointed a data protection officer.
Your rights
You can request information about which data we have stored about you, and you can demand its correction, deletion or a restriction of processing. You have the right to object to processing insofar as we base it on a legitimate interest, and you can receive data that you have given us yourself in a portable format. Whether and to what extent we can comply with such a request depends on the requirements of Articles 15 to 21 of the General Data Protection Regulation. Where we cannot fulfil a right or can only do so in part, we tell you the reason. You can revoke any consent you have given us at any time with effect for the future. An e-mail to the address given above is sufficient for this.
If you believe that we are not processing your data lawfully, you can lodge a complaint with a supervisory authority. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information.
When you open a page
So that your browser can display a page, our server needs to know what it should deliver. This creates log files containing your IP address, the time of access, the requested address, the amount of data transferred, the previously visited page and the identifier of your browser. We need these entries to ensure operation, find faults and detect attacks. The legal basis is our legitimate interest in a functioning and secure service under Article 6 paragraph 1 letter f of the General Data Protection Regulation. We do not combine these logs with other data and do not evaluate them to trace the behaviour of individual visitors. They are deleted as soon as they are no longer required for the purposes mentioned; the retention period is set on the server of our hosting service provider.
A service provider operates the servers for us as a processor, with whom we have concluded a contract under Article 28 of the General Data Protection Regulation. Processing takes place in Germany.
These log files are something different from the logs we keep on search and the chat window; those are described in a separate section below. However, whatever is in the requested address ends up here in both cases: the text of a search query as well as the identifier of an ad click, each together with your IP address. Please therefore do not enter any personal or confidential information in the search.
Encrypted transmission
We deliver this website exclusively via HTTPS. The connection between your browser and our server is therefore encrypted according to the state of the art, which makes eavesdropping on the transport route considerably more difficult. A transmission over the internet cannot offer complete protection against every conceivable access.
Cookies
We do not need any cookies for reading our pages. Only what you trigger yourself or what would not work without technical necessity is stored on your device: a cookie with your decision on the notice at the bottom of the screen, once you have decided, and a session cookie if you open a page with a form or come to us via an ad with your consent. If you load the calendar on the appointment page, the provider named there can add its own (section Appointment booking).
hmh_consent records how you decided on the notice at the bottom of the screen. It expires after six months, after which we ask again. We also set this cookie if you decline everything else, because without it we would have to ask you again on every visit. It contains the version of the notice text you decided on, the time of your decision and the names of the categories you consented to; nothing else. One of these categories is “AI search”; what it unlocks is set out in the section on search and the chat window.
fe_typo_user is the session cookie of our content management system. It is created in two cases. On every page with a form — currently the contact page, the newsletter page, the insights overview and the individual articles —, the spam protection of the form sets it as soon as you open the page. It then contains nothing but a random identifier — no name, no address, no information that describes you. It is also created if you come to us via an ad or a marked campaign link and have consented to the “Marketing” category; the section on assigning ad clicks describes what for.
Three periods must be distinguished here. The cookie itself expires as soon as you close the browser. The associated entry on our server expires 24 hours after your last visit and is cleaned up afterwards. If you revoke the “Marketing” category, we delete a stored assignment on your next page view, regardless of these 24 hours, and block a data record that has already been created for it (section on assigning ad clicks).
You can change your decision at any time. For this purpose, the footer of every page contains the item “Cookie settings”, which brings back the notice and lets you select or deselect individual categories. A revocation takes effect from the time you declare it.
For hmh_consent and for the spam protection cookie, we rely on § 25 paragraph 2 number 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG): both serve to provide the page you requested as you opened it. If, on the other hand, fe_typo_user is created because of an ad click, it is based on your consent under § 25 paragraph 1 of the same act. As long as you do not consent, this case does not occur.
Reach measurement with Matomo
We would like to know which pages are read and where visitors come from. For this, we use Matomo, a reach measurement software that runs on our own server at matomo.media-harbour.com. No data flows to any third-party provider in the process.
With us, Matomo works without cookies and without an identifier that recognises you across several visits. The page opened, the time, the page you came from, browser and device type as well as your IP address in shortened form are recorded: for an IPv4 address, Matomo removes the last two of the four number blocks before anything is stored. If your browser sends the “Do Not Track” signal, your visit is not counted.
The legal basis is our legitimate interest in finding out how our website is used (Art. 6 para. 1 lit. f GDPR). Since nothing is stored on or read from your device, no consent under § 25 TDDDG is required. You can object to the measurement by switching on “Do Not Track” in your browser.
Contact form
Required fields in the form on the contact page are your name, your e-mail address and your message. Your company, your phone number and the information on what it is about are voluntary; these fields help us to pass the enquiry on to the right person straight away.
Your details are sent as an e-mail to our mailbox mail@media-harbour.com. We do not additionally store the form in a database. Beyond the service providers named below, which we need for operation and e-mail, we do not pass on the details. If you have consented to the “Marketing” category and came to us via an ad or a marked campaign link, we add the available information on the origin of your enquiry to the e-mail: the click identifier, the campaign information from the address, the page you landed on, the previously visited page and the time of your first visit. If the enquiry came via a Google ad, we additionally create a separate data record for ad assignment, which contains neither your name nor your message, and report the enquiry to Google Ads. What this data record contains, what Google receives and how you revoke it is set out in the section on assigning ad clicks.
After sending, you automatically receive a short confirmation of receipt from us at the e-mail address you provided. It contains the confirmation and a random identifier of your enquiry; we do not repeat your details in it. If we have assigned your enquiry to a click on a Google ad, it also contains a link with which you can revoke this assignment.
The legal basis is Article 6 paragraph 1 letter b of the General Data Protection Regulation if your enquiry aims at a contract with us, and otherwise our legitimate interest under letter f in answering enquiries. We keep the correspondence as long as we need it for processing or for a possible collaboration and delete it afterwards, unless a statutory retention period prevents this. You can object to further processing at any time.
Contact by phone, e-mail or post
If you call or write to us, we process your details in order to deal with your request. The same applies as for the form: we only use the data for this and delete it when we no longer need it. The service providers without which phone and e-mail do not work are involved: our phone provider and the provider through which our e-mail runs. Beyond that, we do not pass anything on.
Newsletter
For the newsletter, we only need your e-mail address. You can provide your name and your company, but you do not have to. Registration takes place in two steps: after sending, you receive an e-mail with a confirmation link, and only when you click it do we add you. Without confirmation, we do not include your address in the newsletter distribution list.
Until your click, your registration is stored on our server in a separate table: your details, the IP address from which the registration came, and the time. The confirmation link itself contains none of this, only a random key that leads to this entry. If you click the link, we pass the entry on to our mailbox and delete it at the same time; the link is then used up, and a second click only shows a notice page. If you do not click, we delete the entry after seven days. In the log files of our server, only the key is recorded when you click, not your details.
With the confirmation, we record when you registered and when you confirmed, from which IP address the registration came and which wording you consented to. The IP address is therefore that of the registration, not that of the confirmation. We need this information to be able to prove in the event of a dispute that the registration came from you; it serves no other purpose. We keep the addresses in a separate system; no special service provider for sending the newsletter is involved. The same applies to the transport route of the e-mails as to our other post, see the section “Recipients of your data”.
The legal basis is your consent under Article 6 paragraph 1 letter a of the General Data Protection Regulation, and for the logging our legitimate interest under letter f in conjunction with the obligation to provide evidence under Article 7 paragraph 1. You can revoke your consent at any time, most easily via the unsubscribe link at the end of every issue. The revocation takes effect for the future; the lawfulness of the sending until then remains unaffected. After unsubscribing, we delete your address. We keep the proof of consent for a further three years, because claims for unauthorised advertising become time-barred within this period.
AI search and chat window
On this website, you can ask questions via the search or via the chat window. The answer consists of texts from this website and of answers that we have written ourselves. A language model only selects which of these texts match your question; nothing is formulated in the process. Because your input leaves our company for this selection, we explain this in a little more detail.
Only with your consent. We only transmit your question if you have consented to the “AI search” category in the notice at the bottom of the screen. Without this consent, your question stays with us: the search then finds pages via keywords and only answers questions for which we have stored a fixed answer ourselves; the chat window is switched off. You can change your decision at any time via the item “Cookie settings” in the footer of every page.
What is transmitted. We send your question and the matching text sections of this website to our service provider Mistral AI, based in Paris, France. If you ask a follow-up question in the chat, the previous course of the conversation needed for the answer is included, so that your question can refer to what came before. We do not transmit your IP address, the identifier of your browser or cookies.
Who processes there. Mistral AI processes this information as a processor on our behalf. The basis is a contract under Article 28 of the General Data Protection Regulation, which Mistral AI provides as an integral part of its terms of use. It obliges Mistral AI to use the data only for answering your question. We have excluded the use of your input for training Mistral AI's models for our account.
When something stays with us. The suggestions that appear while you type are created entirely on our own server; nothing is transmitted for this. We also answer some questions directly on our server: literally stored questions, fixed information on certain topics such as prices and appointments, and information on our project pages. For all other questions, we use Mistral AI to classify your question and to select the matching text blocks; in the process, your question is transmitted to the service. This also applies if we only show you a list of results, and also if you ultimately see a fixed answer written by us — because the classification of which fixed answer fits takes place at Mistral AI. Without your consent, when the quota is exhausted or when the service is unavailable, we search using keywords alone in our own content; your question then stays with us. So even if no answer selected by AI appears, your question may have been transmitted — but never without your consent.
What we log. For all enquiries that reach our search or our chat window — regardless of whether we answered them on our server or with Mistral AI —, we record: the time, the text of your question, whether it came from the search or from the chat, whether we were able to answer it, the text of the answer you saw and the pages from which it was created, the number of pages found, the page that matched best, technical key figures such as response time and consumption, and your rating of the answer if you give one. We do not store your IP address or a session identifier. These entries are therefore not necessarily anonymous: whatever you write in your question yourself — such as a name or contact details — is also recorded in the log. Please do not enter passwords or confidential information there. We look at this list. It shows which questions our website does not yet have a good answer to. It makes consumption transparent. And it documents what was answered when and on what basis. We delete the entries after 90 days.
Protection against overload. So that individual callers do not overload the search, we limit the number of requests. To do this, we convert your IP address into a check value and use it to count the requests of the current minute. We do not store the IP address itself at this point. The check value only applies to the current minute and is not used afterwards; we clear away the expired rows during ongoing operation.
Legal basis. We base the transmission of your question to Mistral AI on your consent under Article 6 paragraph 1 letter a of the General Data Protection Regulation. You can revoke it at any time via the cookie settings; the revocation takes effect from that time and leaves previous processing unaffected. We base the log and the protection against overload on our legitimate interest under letter f: to make the information you are looking for quickly accessible to you, to improve the quality of our content and to protect the service against overload. Using search and chat is voluntary, and we ask you not to enter any personal or confidential information there.
About the answers themselves. Below each answer, it says how it came about: formulated by us or selected from our texts by AI. The selection can be off the mark; the content of the respective page and our written information are binding. No automated decision about you within the meaning of Article 22 of the General Data Protection Regulation takes place, and we do not create a profile from your questions.
Assigning ad clicks
We run ads, and we would like to know which of them lead to an enquiry. This only happens with your consent to the “Marketing” category. If you have consented and come to our website via an ad or a marked campaign link, our server remembers the identifier from the address for the duration of your visit. In addition, there is the page you landed on, the previously visited page, the time and the campaign information from the address. If you then send the contact form, we include this information in the e-mail to ourselves.
If your enquiry came via a Google ad and you have consented to the “Marketing” category, we also create a separate data record for it. It contains a random identifier of your enquiry (it is also included in our confirmation of receipt to you), the click identifier of the ad, the time at which you first came to our website with this identifier, the time at which your enquiry reached us, the version and time of your consent, the status of the transmission and of any revocation, and the time and file name of each transmission file in which it appeared. It contains no name, no e-mail address and not the content of your message; via the identifier, however, we can assign it to your enquiry, which we have as an e-mail.
At regular intervals, we transmit a file from these data records to Google Ireland Limited (“import of conversions from clicks”). For each enquiry, it contains the click identifier, the name of the count (“Kontaktanfrage Website”), the time of the enquiry, the identifier of the enquiry and the information that you have consented to use for advertising purposes, but not to personalisation. Google assigns the click identifier to the ad click and shows us which ads have led to enquiries. We do not transmit names, e-mail addresses or phone numbers; we do not use “enhanced conversions”. The random enquiry identifier itself contains no information about you. Via the additionally transmitted click identifier, Google can assign the enquiry to the ad click. The data is therefore not to be regarded as anonymous.
You can revoke your consent to this assignment at any time. During your visit, it is enough to deselect the “Marketing” category under “Cookie settings” in the footer of every page: on your next page view, we also block a data record that was created for your enquiry during this visit. After your visit, our website no longer knows this connection; then use the link in our confirmation of receipt or write to us at mail@media-harbour.com, if possible quoting the identifier from the confirmation of receipt.
If the enquiry has not yet been transmitted to Google, we block the data record: we then no longer report it to Google, and we delete any already prepared transmission file in which it appears. If we had already included it in a transmission file without it being certain whether Google received it, we clarify this and initiate a retraction if necessary. If the transmission has taken place, we initiate a retraction of the conversion at Google (“conversion adjustment”). If Google accepts it, we check in our Google Ads account whether the enquiry has been removed from the count. The retraction corrects the count; it is not a deletion at Google. The click data that Google processes independently of this for the ad click remains unaffected; Google's privacy notices and the settings in your Google account apply to it. Whether Google still accepts a retraction is decided by Google; your right of revocation applies regardless.
With the revocation, we remove the click identifier from our data record. Until we delete it (see the periods in the next paragraph), it only retains the information we need to implement the revocation: the identifier of your enquiry, a checksum of the click identifier with which we recognise the same click, the type of identifier, the names of the transmission files and the status of the retraction. So that the same ad click is not assigned again after your revocation, not even for a further enquiry, we also keep such a checksum separately until 90 days after the click, for at least one day – even if the data record itself has already been deleted. Your contact enquiry itself, i.e. the e-mail to us, is not affected; the section on the contact form applies to it. This also applies to the information on the origin of your enquiry contained in that e-mail.
We delete data records that have not yet been transmitted after 90 days from the first recorded website visit with the click identifier. We keep transmitted data records for evidence purposes for 90 days after transmission. After a revocation, the reduced data record remains until the revocation has been completed and is then deleted: if the enquiry was never transmitted, at the next deletion run; if Google had to receive a retraction, as soon as we have checked in our Google Ads account that it has been processed, but no later than 90 days after Google accepted it. If it cannot be clarified whether the enquiry reached Google, or if Google does not accept the retraction, we mark the case for manual processing 68 days after your enquiry and delete it no later than 90 days after that. Deletion takes place in each case at the next deletion run, which takes place at least once a week. We delete prepared transmission files after the import, at the latest after 30 days, and immediately if they contain a revoked enquiry.
Two conditions must come together for this: you actually come via an ad or a marked campaign link, and you have consented to the “Marketing” category. If either is missing, we do not store the identifier for this purpose and do not evaluate it. It is nevertheless recorded in the server's log files, because it is part of the requested address; we delete these entries together with the other logs.
For the assignment itself, our system creates a session cookie. It contains a random identifier, no name and no address, and expires when you close the browser. The associated information on our server expires 24 hours after your last visit and is cleaned up afterwards. If you revoke your consent, we delete it on your next page view. On pages with a form, a session cookie can be created independently of this by the spam protection.
The legal basis is your consent under Article 6 paragraph 1 letter a of the General Data Protection Regulation and § 25 paragraph 1 of the German Telecommunications Digital Services Data Protection Act. How you can revoke your consent is set out above. The revocation takes effect from that time and leaves previous processing unaffected.
Image and video material
Some of the photos and videos on this website come from image agencies; which ones is stated in the legal notice. The files are stored on our own server. No data is transmitted to these providers when viewing.
Links to other websites
We link to clients' websites, to partners and to our profiles on social networks. These references are simple links. No buttons are built in that send data to the providers concerned as soon as our page loads. Only when you click such a link does the other provider find out about it, and from that moment its privacy policy applies.
Sharing articles
Below our articles, you will find buttons with which you can share the article on LinkedIn, forward it by e-mail or copy its address. These are also simple links. As long as you do not click any of these buttons, nothing is transmitted to LinkedIn, and no program code of the network is loaded into our page.
If you click the LinkedIn button, a new window opens at LinkedIn, and the address of the article is transmitted there. From this moment, LinkedIn's privacy policy applies. The e-mail button opens your own e-mail program; we do not learn anything about it. When copying the link, the address does not leave your browser.
Appointment booking
On the page “Arrange an initial consultation”, you can choose a phone or video appointment with us. The calendar for this is provided by TidyCal, a service of Sumo Group Inc., based in the USA. There is no connection to this provider while reading the page. The calendar is only loaded when you consent to the “Appointment booking” category and explicitly load it there; we record your decision in the hmh_consent cookie.
When it loads, the provider receives technical information from your browser such as IP address, browser type, language and time. The embedded calendar integrates further services that do not come from us: Google reCAPTCHA against automated bookings and, according to our check of 26 September 2026, the provider's Google Tag Manager, Microsoft Clarity and Stripe. The provider is responsible for this processing; its privacy notices apply. The provider may set its own cookies in the calendar.
If you book an appointment, the provider processes your name, your e-mail address, your phone number for a phone appointment, your information on the project and the selected time and transmits them to us. The appointment is entered in our Google Calendar; for video appointments, Google Meet generates the access link that you receive with the confirmation. We do not record conversations. We keep the appointment data as long as we need it for preparing and following up the conversation; the section on contact by phone, e-mail or post applies to further correspondence.
The legal basis for loading the calendar is your consent (Art. 6 para. 1 lit. a GDPR, § 25 para. 1 TDDDG). You can revoke it at any time in the cookie settings; the calendar is then removed. Information that has gone to the provider until then remains unaffected. The booking itself serves to initiate a contract (Art. 6 para. 1 lit. b GDPR). Since the provider is based in the USA, your information is processed there. Without the calendar, you arrange appointments by phone or e-mail and receive the same service.
Recipients of your data
Outside our company, your data is only received by the service providers we need for operation: the provider on whose servers this website runs, our e-mail service provider for receiving and sending our post, and Mistral AI, which selects the matching texts from our prepared answer texts for search and the chat window. Only with your consent to the “Marketing” category and only for enquiries via a Google ad do we also transmit the information named in the section on assigning ad clicks to Google Ireland Limited. If you load the calendar on the appointment page, TidyCal (Sumo Group Inc.) receives the information named in the section Appointment booking. Beyond these expressly described purposes and recipients, we do not pass on your data.
Changes
If we change something on this website that is relevant to data protection, we also change this statement. The version published here applies in each case.
Status: 24 September 2026