Privacy

Privacy Policy

Information on the processing of personal data pursuant to Art. 13 and 14 of the EU General Data Protection Regulation (GDPR).

This English version is a convenience translation. The legally authoritative version is the German Datenschutzerklärung.

1 · Controller

The controller within the meaning of the GDPR for data processing on this website is:

TT-ECOM Global GmbH
Voltairestr. 11
c/o Thomas Zipf
10179 Berlin
Germany

Represented by the Managing Director: Francis Kleint
Phone: +49 151 50611854
Email: support@doktrin.ai

No data protection officer has been appointed, as the statutory requirements for a mandatory appointment (Section 38 of the German Federal Data Protection Act, BDSG) are not met.

2 · General Information on Data Processing

We process personal data only to the extent necessary to provide this website and to handle your inquiries. Depending on the processing, the legal bases are Art. 6 (1) (b) GDPR (contract/pre-contractual measures) and Art. 6 (1) (f) GDPR (legitimate interests); details are set out in the following sections.

Storage period: Unless a specific period is stated in this policy, we store personal data only for as long as necessary for the respective purpose. It is then deleted, unless statutory retention obligations (e.g. Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB) for business correspondence) prevent deletion — in that case, processing is restricted.

Obligation to provide data: Providing personal data on this website is neither legally nor contractually required. However, without the fields marked as required in the forms, we cannot process your inquiry.

No automated decision-making: No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

3 · Hosting & Server Log Files

This website is operated on a server rented by us and located in Frankfurt am Main, Germany. The hosting provider is Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus (EU). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider; details on its data processing: hostinger.com/legal/privacy-policy.

When you access the website, your browser transmits technically necessary data that may be stored in server log files: IP address, date and time of access, page/file requested, volume of data transferred, referrer URL, and browser type and version. This data is not combined with other data sources and is not evaluated for marketing purposes. The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in the secure, stable and abuse-free operation of the website. Log files are stored only for as long as necessary for these purposes and are then deleted or anonymized.

4 · SSL/TLS Encryption

This website uses SSL/TLS encryption throughout (recognizable by "https://" and the lock symbol in your browser bar). All content — in particular the data submitted via the forms — is transmitted in encrypted form and cannot readily be read by third parties.

5 · No Cookies · Anonymous Reach Measurement

This website sets no cookies, stores no information on your device and reads no information stored there (Section 25 of the German TDDDG is not affected). No third-party analytics, tracking or advertising services are used and no cross-site recognition takes place. A cookie/consent banner is therefore not required.

To improve the structure and clarity of this page, we carry out an anonymous reach measurement on our own server (for hosting see Section 3). Only technical events are recorded: the section visited, the element clicked, the order of and interval between events, and the time spent. Input into form fields is not recorded. No data is passed to third parties.

Your IP address is not stored. It is used transiently only, together with the browser identifier and the current date, to compute a daily-rotating pseudonym (HMAC with a secret key). This value allows events to be attributed to a visit within a single day; linking across days or to you as a person is not possible with it.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in designing our offering to meet demand and in evaluating it statistically. Event data is deleted automatically after 90 days. If "Do Not Track" or "Global Privacy Control" is enabled in your browser, no measurement takes place; you may also object at any time in accordance with Section 11.

Links in our emails. Where emails from us contain links to this website, those links may be routed via our own server so we can see which content helps and where a sequence breaks off. This produces the same anonymous event data as above, plus the name of the mailing sequence — with no reference to the recipient: we learn that a link in that sequence was clicked, not by whom. We do not use tracking or open pixels.

6 · Fonts (Locally Hosted)

This website uses the fonts "Anton" and "Inter". The font files are hosted locally on our own server. When the fonts load, no connection to servers of Google (Google Fonts) or other third parties is established; no personal data is transmitted to third parties in the process.

7 · Contacting Us by Email or Phone

If you contact us by email or phone, we process the data you provide (e.g. name, email address, content of your message) to handle your inquiry. The legal basis is Art. 6 (1) (b) GDPR (initiation/performance of a contract) or Art. 6 (1) (f) GDPR (legitimate interest in handling your inquiry). The data is deleted as soon as it is no longer required for the purpose and no statutory retention obligations apply.

8 · Contact & Download Forms (CRM)

On this website you can submit an inquiry via a contact form (name, company, email address, company size, optionally a message) and request free PDF templates (email address). When you submit a form, the data you entered is transmitted TLS-encrypted via an automation interface operated by us (n8n, hosted with Hostinger on a server in Frankfurt am Main, Germany — see Section 3) to our customer relationship management system (CRM), where it is stored to handle your inquiry, to provide the requested materials, and for related follow-up communication. No external form service provider is used. Legal bases: Art. 6 (1) (b) GDPR (handling your inquiry / providing the requested content) and Art. 6 (1) (f) GDPR (legitimate interest in the structured management of inquiries and in direct marketing to business customers, cf. Recital 47 GDPR). You can unsubscribe from topic-related follow-up information at any time (see below).

Third-country transfer (USA): As our CRM we use Close (provider: Elastic Inc., Jackson, WY, USA — close.com/privacy). In the course of this, personal data is processed in the USA. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider, which incorporates the EU Commission's Standard Contractual Clauses (Art. 46 (2) (c) GDPR) as the safeguard. The provider is not certified under the EU-U.S. Data Privacy Framework; the Standard Contractual Clauses are the applicable safeguard. You can request a copy of the safeguards via support@doktrin.ai; the clauses are also available on the EU Commission's website.

If the technical transmission fails, the website instead opens your email client with a prepared message to support@doktrin.ai — in that case Section 7 applies. You may object to follow-up communication at any time with effect for the future (see Section 11) — an informal message to support@doktrin.ai is sufficient; in addition, every marketing email contains an unsubscribe link. The data is deleted as soon as it is no longer required for the purposes stated and no statutory retention obligations apply.

9 · Appointment Booking (Calendly)

For booking calls we link to the external service Calendly (Calendly LLC, 115 E Main St., Buford, GA, USA). Merely visiting our website transmits no data to Calendly — the service is not embedded, only linked, and opens only when you click the booking link. The data processing on the Calendly site is governed by its own privacy notice: calendly.com/legal/privacy-notice.

We process the booking data transmitted to us by Calendly (name, email address, selected time slot, and any details you provide about the topic) to prepare and conduct the appointment (Art. 6 (1) (b) GDPR). Calendly is certified under the EU-U.S. Data Privacy Framework; to that extent, the transfer to the USA is based on the EU Commission's adequacy decision (Art. 45 GDPR). Calendly provides a data processing agreement pursuant to Art. 28 GDPR for this, which additionally incorporates the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR). You can request a copy of the clauses via support@doktrin.ai; they are also available on the EU Commission’s website.

10 · Your Rights

Under the GDPR, you have the following rights vis-à-vis the controller:

To exercise your rights, an informal message to support@doktrin.ai is sufficient.

11 · Right to Object (Art. 21 GDPR)

Right to Object

You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6 (1) (f) GDPR (Art. 21 (1) GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where your data is processed for direct marketing purposes, you have the right to object to such processing at any time and without stating reasons (Art. 21 (2) GDPR). After your objection, the data will no longer be used for direct marketing purposes.

An informal message to support@doktrin.ai is sufficient. No costs arise other than the transmission costs at basic rates.

12 · Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). For the controller, based in Berlin, this is usually:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59–61, 10555 Berlin, Germany · datenschutz-berlin.de

13 · Currency of this Privacy Policy

We update this privacy policy whenever the data processing on this website or the legal framework changes. The version published here applies.


Last updated: July 6, 2026 · To the Legal Notice → · Deutsche Fassung →