1. Controller
MorgenlightController: Moritz Gottelt
Bayersdorferstraße 8
80637 München
Germany
In this privacy notice, “Morgenlight” refers to Moritz Gottelt as the controller named above.
Privacy enquiries: datenschutz@morgenlight.com
General contact: info@morgenlight.com
2. Website access and hosting
When the website is requested, the web server must technically process in particular the IP address, time, requested address, response status, transferred data volume, browser/device information and, where supplied, the referring page. This is required for delivery, stability and abuse prevention. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is secure and reliable website operation.
Hosting is provided by Hostinger. Hostinger processes technically necessary connection data as the hosting service provider. Server logs are erased when they are no longer required for secure and reliable operation, unless legal obligations or the investigation of a specific security incident require longer retention. The legitimate interest is the secure and reliable operation of the website. Fonts and images are served through the website itself.
3. Contact by email and contact form
When you contact us by email, we process in particular your email address, time, subject, message content, technical metadata and voluntarily supplied attachments. Communication is handled through Google Workspace. The purpose is to respond to your enquiry. The legal basis is Article 6(1)(b) GDPR where the communication concerns pre-contractual or contractual steps, and otherwise Article 6(1)(f) GDPR based on the legitimate interest in appropriate communication.
Access is limited to authorised persons. Messages are erased once no longer needed for the enquiry unless statutory evidentiary or retention duties apply. Please do not send confidential or particularly sensitive information unsolicited by ordinary email.
The contact form requires only your email address and message. The recipient is fixed on the server as info@morgenlight.com. The form sends no automatic reply. Neither a readable email address nor a copy of the message content is stored in the website database. The email service provider processes the email address, message and language to transmit the message to the Morgenlight contact address. Article 6(1)(b) GDPR applies to transmission and handling where your enquiry concerns a contract or pre-contractual steps; otherwise Article 6(1)(f) GDPR applies based on the legitimate interest in appropriate communication. The access and erasure criteria stated above apply to delivered messages.
To detect unintended repeat transmissions and limit misuse, the application creates an HMAC verification value for the random request identifier that is valid for no more than 24 hours, together with an HMAC verification value derived from the email address, message and language. A separate HMAC of the email address is stored with a counter and time window for transmission limits, together with time-limited global counters. No readable email address, message or network address supplied by the browser is stored in the website database. Expired values are removed from the active database by the next form request or a scheduled cleanup run. The random browser identifier is also used in working memory for a 15-minute limit window; expired entries are removed by the next form request or application restart. The legal basis for these security and limiting data is Article 6(1)(f) GDPR; the legitimate interest is secure transmission, avoiding unintended repeat transmissions and protecting the form, contact address and third parties against misuse.
4. Appointment booking with Google Calendar
Merely opening the booking page does not load the embedded Google appointment scheduler. Only after you select “Load Google appointment scheduler” does your browser connect directly to calendar.google.com. Google then processes technically necessary connection data such as the IP address, time, browser and device information, and the requested appointment-scheduling page. Google may also set or read cookies or similar technologies on your device. The embed sends no referrer to Google.
Loading is optional and takes place only after your informed choice. The legal bases for the resulting direct connection and any access to device information that is not technically necessary are section 25(1) TDDDG and Article 6(1)(a) GDPR. The website does not retain this choice. You can close the embedded scheduler to stop future transfers from the embedded content; this does not reverse transfers that have already occurred and cannot remove cookies set by Google. You may alternatively contact Morgenlight by email without loading the Google scheduler.
If you request or book an appointment in the embedded scheduler, Google Calendar processes in particular your first and last name, email address, selected time, and any additional details you enter in fields shown there. These details are required to review your request, create the appointment and hold the consultation. Morgenlight relies on Article 6(1)(b) GDPR for this processing. Depending on the booking rules configured in Google Calendar, Google may verify your email address, send confirmations or reminders, and create a calendar event with a video-conference link.
The Morgenlight website code cannot read the contents of the third-party Google frame and stores no copy of your booking details in its own website database. After booking, the details are processed in the Google Workspace and Calendar account operated for Morgenlight. They may be visible in particular to invited participants, authorised calendar users and technically authorised Workspace administrators. Google Calendar events and related delivery data are erased once no longer required for performance, follow-up, fault resolution and statutory evidence. Google’s own Privacy Policy also applies.
5. Cookies and consent preferences
For the contact form, the server similarly sets theml-contact-client-v1 cookie. It likewise contains only version, expiry, a random browser identifier and a signature, is restricted to/api/contact/ and expires after no more than one hour. It is protected with HttpOnly, Secure andSameSite=Strict and applies short-term misuse limits to the form submission you requested. Section 25(2) no. 2 TDDDG is also relied on for this cookie.
If the website offers visitor statistics, it stores your choice under the key morgenlight-consent locally in the browser. It contains the consent version, your decision for or against visitor statistics and the time. The choice expires after no more than 180 days or immediately when the consent version changes. This storage is necessary to provide the setting you expressly requested (section 25(2) no. 2 TDDDG). This website’s code does not transmit this local record to Morgenlight or any third party.
You may reject or expressly accept visitor statistics. The “Cookie settings” control remains directly available. Withdrawal applies to the future, removes accessible Google Analytics cookies and reloads the page without the Google runtime.
6. Google Analytics 4
Without visitor statistics, no Google Analytics tag is loaded, no Analytics cookie is set and no consent for audience measurement is requested.
7. Recipients and transfers
Depending on the feature used, recipient categories include the hosting and database provider, the email service provider, and Google for Workspace, Calendar, Meet and, after consent, Analytics. Access is limited to what is necessary. Where a provider processes service or account data for its own purposes, its own responsibilities and privacy information apply.
Google may also process data outside the European Economic Area, particularly in the United States. Where a European Commission adequacy decision applies to the recipient, the transfer is based on that decision, including the EU-US Data Privacy Framework only for currently certified US recipients. Otherwise, the European Commission’s Standard Contractual Clauses and supplementary safeguards may apply. Further information or a copy of the applicable safeguards is available from datenschutz@morgenlight.com. Google also provides a data transfer framework overview.
8. Retention
We retain personal data only for as long as required for its purpose or by law. Criteria include the duration and completion of an enquiry or business relationship, statutory limitation and retention periods, necessary security evidence and an effective objection or withdrawal.
9. Your rights
Subject to the GDPR, you have rights including access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn at any time for the future. Contact datenschutz@morgenlight.com.
You may also complain to a data protection supervisory authority. For non-public controllers in Bavaria, this will generally be the Bavarian State Office for Data Protection Supervision.
10. Required information and automated decisions
Merely visiting the website does not require you to actively provide personal information. Google Calendar generally requires your first name, last name, email address and selected appointment for a booking. Additional fields shown in the Google form may be required or optional as indicated there. The booking cannot be completed without the displayed required fields. To use the contact form, you must provide an email address and message; without them the form message cannot be transmitted or answered. Providing them is neither a statutory nor a contractual requirement. Morgenlight does not make solely automated decisions with legal or similarly significant effects in the website flow described here and does not create its own user profile.
Version and changes
Last updated: .