Skip to main content
Morgenlight
DEEN
Menu

Pages

Home→Booking→Contact→Legal notice→Privacy→

Language

DEDeutschENEnglish
Book a consultation→
Book a consultation→

Privacy information

Privacy

1. Controller

Morgenlight
Controller: Moritz Gottelt
Bayersdorferstraße 8
80637 München
Germany

In this privacy notice, “Morgenlight” refers to Moritz Gottelt as the controller named above.

Privacy enquiries: datenschutz@morgenlight.com
General contact: info@morgenlight.com

2. Website access and hosting

When the website is requested, the web server must technically process in particular the IP address, time, requested address, response status, transferred data volume, browser/device information and, where supplied, the referring page. This is required for delivery, stability and abuse prevention. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is secure and reliable website operation.

Hosting is provided by Hostinger. Hostinger processes technically necessary connection data as the hosting service provider. Server logs are erased when they are no longer required for secure and reliable operation, unless legal obligations or the investigation of a specific security incident require longer retention. The legitimate interest is the secure and reliable operation of the website. Fonts and images are served through the website itself.

3. Contact by email and contact form

When you contact us by email, we process in particular your email address, time, subject, message content, technical metadata and voluntarily supplied attachments. Communication is handled through Google Workspace. The purpose is to respond to your enquiry. The legal basis is Article 6(1)(b) GDPR where the communication concerns pre-contractual or contractual steps, and otherwise Article 6(1)(f) GDPR based on the legitimate interest in appropriate communication.

Access is limited to authorised persons. Messages are erased once no longer needed for the enquiry unless statutory evidentiary or retention duties apply. Please do not send confidential or particularly sensitive information unsolicited by ordinary email.

The contact form requires only your email address and message. The recipient is fixed on the server as info@morgenlight.com. The form sends no automatic reply. Neither a readable email address nor a copy of the message content is stored in the website database. The email service provider processes the email address, message and language to transmit the message to the Morgenlight contact address. Article 6(1)(b) GDPR applies to transmission and handling where your enquiry concerns a contract or pre-contractual steps; otherwise Article 6(1)(f) GDPR applies based on the legitimate interest in appropriate communication. The access and erasure criteria stated above apply to delivered messages.

To detect unintended repeat transmissions and limit misuse, the application creates an HMAC verification value for the random request identifier that is valid for no more than 24 hours, together with an HMAC verification value derived from the email address, message and language. A separate HMAC of the email address is stored with a counter and time window for transmission limits, together with time-limited global counters. No readable email address, message or network address supplied by the browser is stored in the website database. Expired values are removed from the active database by the next form request or a scheduled cleanup run. The random browser identifier is also used in working memory for a 15-minute limit window; expired entries are removed by the next form request or application restart. The legal basis for these security and limiting data is Article 6(1)(f) GDPR; the legitimate interest is secure transmission, avoiding unintended repeat transmissions and protecting the form, contact address and third parties against misuse.

4. Appointment booking with Google Calendar

Merely opening the booking page does not load the embedded Google appointment scheduler. Only after you select “Load Google appointment scheduler” does your browser connect directly to calendar.google.com. Google then processes technically necessary connection data such as the IP address, time, browser and device information, and the requested appointment-scheduling page. Google may also set or read cookies or similar technologies on your device. The embed sends no referrer to Google.

Loading is optional and takes place only after your informed choice. The legal bases for the resulting direct connection and any access to device information that is not technically necessary are section 25(1) TDDDG and Article 6(1)(a) GDPR. The website does not retain this choice. You can close the embedded scheduler to stop future transfers from the embedded content; this does not reverse transfers that have already occurred and cannot remove cookies set by Google. You may alternatively contact Morgenlight by email without loading the Google scheduler.

If you request or book an appointment in the embedded scheduler, Google Calendar processes in particular your first and last name, email address, selected time, and any additional details you enter in fields shown there. These details are required to review your request, create the appointment and hold the consultation. Morgenlight relies on Article 6(1)(b) GDPR for this processing. Depending on the booking rules configured in Google Calendar, Google may verify your email address, send confirmations or reminders, and create a calendar event with a video-conference link.

The Morgenlight website code cannot read the contents of the third-party Google frame and stores no copy of your booking details in its own website database. After booking, the details are processed in the Google Workspace and Calendar account operated for Morgenlight. They may be visible in particular to invited participants, authorised calendar users and technically authorised Workspace administrators. Google Calendar events and related delivery data are erased once no longer required for performance, follow-up, fault resolution and statutory evidence. Google’s own Privacy Policy also applies.

5. Cookies and consent preferences

For the contact form, the server similarly sets theml-contact-client-v1 cookie. It likewise contains only version, expiry, a random browser identifier and a signature, is restricted to/api/contact/ and expires after no more than one hour. It is protected with HttpOnly, Secure andSameSite=Strict and applies short-term misuse limits to the form submission you requested. Section 25(2) no. 2 TDDDG is also relied on for this cookie.

If the website offers visitor statistics, it stores your choice under the key morgenlight-consent locally in the browser. It contains the consent version, your decision for or against visitor statistics and the time. The choice expires after no more than 180 days or immediately when the consent version changes. This storage is necessary to provide the setting you expressly requested (section 25(2) no. 2 TDDDG). This website’s code does not transmit this local record to Morgenlight or any third party.

You may reject or expressly accept visitor statistics. The “Cookie settings” control remains directly available. Withdrawal applies to the future, removes accessible Google Analytics cookies and reloads the page without the Google runtime.

6. Google Analytics 4

Without visitor statistics, no Google Analytics tag is loaded, no Analytics cookie is set and no consent for audience measurement is requested.

7. Recipients and transfers

Depending on the feature used, recipient categories include the hosting and database provider, the email service provider, and Google for Workspace, Calendar, Meet and, after consent, Analytics. Access is limited to what is necessary. Where a provider processes service or account data for its own purposes, its own responsibilities and privacy information apply.

Google may also process data outside the European Economic Area, particularly in the United States. Where a European Commission adequacy decision applies to the recipient, the transfer is based on that decision, including the EU-US Data Privacy Framework only for currently certified US recipients. Otherwise, the European Commission’s Standard Contractual Clauses and supplementary safeguards may apply. Further information or a copy of the applicable safeguards is available from datenschutz@morgenlight.com. Google also provides a data transfer framework overview.

8. Retention

We retain personal data only for as long as required for its purpose or by law. Criteria include the duration and completion of an enquiry or business relationship, statutory limitation and retention periods, necessary security evidence and an effective objection or withdrawal.

9. Your rights

Subject to the GDPR, you have rights including access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn at any time for the future. Contact datenschutz@morgenlight.com.

You may also complain to a data protection supervisory authority. For non-public controllers in Bavaria, this will generally be the Bavarian State Office for Data Protection Supervision.

10. Required information and automated decisions

Merely visiting the website does not require you to actively provide personal information. Google Calendar generally requires your first name, last name, email address and selected appointment for a booking. Additional fields shown in the Google form may be required or optional as indicated there. The booking cannot be completed without the displayed required fields. To use the contact form, you must provide an email address and message; without them the form message cannot be transmitted or answered. Providing them is neither a statutory nor a contractual requirement. Morgenlight does not make solely automated decisions with legal or similarly significant effects in the website flow described here and does not create its own user profile.

Version and changes

Last updated: 10 August 2026.

Back to Morgenlight

Privacy

Your choice. No preselection.

Morgenlight would like to use Google Analytics 4 from Google to measure page views and the number of browsers and sessions using the website. After your consent, Google Analytics stores and reads _ga cookies containing a random browser identifier on your device for no more than 90 days without renewal. In particular, the page path and title, referrer origin, usage and session data, language, basic browser and device information, approximate location data and the IP address processed when the connection is established are sent to Google. Google may process data in the United States. Without consent, no Google tag is loaded. You may reject or withdraw consent at any time for the future through “Cookie settings”; processing before withdrawal remains lawful.

Privacy information

Your choice

Cookie and analytics settings

Essential technology remains active. Visitor statistics are optional and switched off by default.

Essential

The consent manager stores your choice locally in the browser. When you use the contact form, its API also sets a random, signed protection identifier for no more than one hour. The Google appointment scheduler is loaded separately only after your specific choice.

Always active
Visitor statistics with Google Analytics

Visitor statistics are currently completely disabled on this website.

Switched off
Privacy information