Privacy Policy

1. Controller

Martin Koch
Am Steinbruch 10
67685 Weilerbach
Germany

Email: kontakt@martinkoch-fotografie.de
Website: https://martinkoch-fotografie.de

2. General Information on Data Processing

Protecting your personal data is important to me.
I process personal data exclusively in accordance with the General Data Protection Regulation (GDPR) and the applicable national data protection laws.

This privacy policy informs you about which data is processed on this website, for what purposes, and on which legal basis.

3. Provision of the Website and Server Log Files

When you access this website, information is automatically collected and stored in so-called server log files by the hosting provider. This data may include in particular:

โ€“ IP address (in truncated or anonymized form)
โ€“ Date and time of the request
โ€“ Accessed pages or files
โ€“ Browser type and operating system
โ€“ Referrer URL

The processing of this data is carried out to ensure the stable and secure operation of the website, for technical error analysis, and to prevent misuse and attacks.

Legal basis:
Art. 6(1)(f) GDPR (legitimate interest in the secure and functional provision of the website)

The log file data is not merged with other data sources.

4. Contact

If you contact me via contact form, email, or telephone, the information you provide will be processed in order to handle your inquiry.

Processed data may include:
โ€“ Name
โ€“ Email address
โ€“ Telephone number
โ€“ Content of the message

The purpose of the processing is to respond to inquiries and to communicate with you.

Legal basis:
Art. 6(1)(b) GDPR (pre-contractual measures)
Art. 6(1)(f) GDPR (legitimate interest in communication)

The data will be deleted as soon as it is no longer necessary for the purpose of processing and no statutory retention obligations apply.

5. Web Analytics and Online Marketing

5.1 Web Analytics with Rybbit

This website uses Rybbit Analytics, a privacy-friendly web analytics service.

Rybbit processes page views, usage flows (user journeys), and session data including session replay.

Rybbit does not process cookies, IP addresses, personal identifiers, profiling data, or advertising and marketing data.

The analysis is carried out exclusively in anonymized form and serves to improve the website and user experience.

Legal basis:
Art. 6(1)(f) GDPR (legitimate interest in anonymized reach measurement)

5.2 Use of Meta Pixel and Conversions API (including Advanced Matching)

I use the “Meta Pixel” and the “Conversions API” provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Meta”) on this website.

Purpose of Processing
These technologies help me measure the effectiveness of my advertising on Meta’s platforms (Facebook, Instagram) and strategically optimise my campaigns. If you arrive at my website via a Meta ad and complete a defined action (e.g. submitting a contact request), this interaction is recorded. I also use the data to display targeted ads to users who have previously shown interest in my photography work (retargeting).

Data Processed and Conversions API
While the Meta Pixel sends data directly from your browser to Meta, the Conversions API transmits selected event data from my website server directly to Meta’s servers. Data processed typically includes IP address, device and browser information, timestamps, the URL visited and specific event data (e.g. submission of a contact form).

Advanced Matching
I additionally use the “Advanced Matching” feature. This means that certain personal data you enter into forms (such as your email address or name) is cryptographically hashed within your browser before being transmitted to Meta. Meta uses this hashed data solely to match it against data of its own users. This allows more accurate attribution of website actions to Meta profiles and reduces wasted ad spend. Data is never transmitted in plain text.

Legal Basis and Right to Withdraw Consent
These technologies are only activated โ€” and information is only stored or accessed on your device or transmitted to Meta โ€” after you have given your explicit prior consent. The legal basis is Art. 6(1)(a) GDPR and ยง 25(1) TDDDG. You may withdraw or adjust your consent at any time with effect for the future via the consent tool (“Real Cookie Banner”). A permanent link to these settings is available on this website.

Joint Controllership and International Data Transfers
For certain stages of data collection and transmission, Meta and I act as joint controllers (Art. 26 GDPR). I have entered into the corresponding agreement with Meta for this purpose. A transfer of data to the United States cannot be excluded. Such transfers are based on the adequacy decision for the EU-US Data Privacy Framework as well as Standard Contractual Clauses. For further information on joint controllership and Meta’s processing of your data, please refer to Meta’s Privacy Policy: https://www.facebook.com/about/privacy

6. Cookies and Consent

This website does not use cookies for analytics, marketing, or tracking purposes.

Therefore, no cookie banner and no consent mechanism are required.

7. Social Media

This website contains links to my profiles on social networks (e.g. Instagram or Facebook).

When you visit my website, no data is automatically transmitted to these networks.
Only when you click on the respective link do the privacy policies of the respective provider apply.

8. Rights of Data Subjects

Under the GDPR, you have the following rights:

โ€“ Right of access pursuant to Art. 15 GDPR
โ€“ Right to rectification pursuant to Art. 16 GDPR
โ€“ Right to erasure pursuant to Art. 17 GDPR
โ€“ Right to restriction of processing pursuant to Art. 18 GDPR
โ€“ Right to data portability pursuant to Art. 20 GDPR
โ€“ Right to object pursuant to Art. 21 GDPR

You also have the right to lodge a complaint with a supervisory authority.

9. Changes to This Privacy Policy

I reserve the right to amend this privacy policy if this becomes necessary due to technical or legal changes.

Effective date: December 2025