Privacy Policy
This policy applies to the website a11yplan.de. Separate terms apply to our application at hub.a11yplan.de and are provided to you there.
1. Controller
A11YPLAN GmbH
Hartlaubstraße 3
74541 Vellberg
Germany
Represented by the managing directors Marcel Bertram and Marvin Kelm.
Email: info@a11yplan.de
2. Your rights
You have the right to obtain information about the data we hold about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing (Art. 21). An informal email to info@a11yplan.de is sufficient.
Where we process data on the basis of your consent, you may withdraw it at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal. You can change or withdraw your cookie consent via the cookie settings at the bottom of every page.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
3. Hosting and server logs
This website is hosted by Cloudflare, Inc. When you open a page, your browser transmits technically necessary data that is processed in server logs: IP address, date and time, the address requested, the amount of data transferred, the referring page, your browser and operating system.
The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). This data is not combined with other sources.
4. Fonts are served locally
The fonts used on this website are stored on our own server. There is no connection to Google Fonts or any other font provider, and no IP address is transmitted to third parties for this purpose.
5. Cookies and consent management
We set two technically necessary cookies to remember your cookie decision: ncc_c (whether you decided) and ncc_e (which categories you allowed). They expire after six months. Without them we would have to ask you again on every page.
All other cookies are only set after you have consented to the relevant category (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can change your choice at any time via the cookie settings.
6. Audience measurement with Umami
For audience measurement we use Umami on our own server (u.a11yplan.de). Umami sets no cookies and collects no data that would allow individual visitors to be recognised. Only aggregated information is recorded, such as the page viewed, the referring page, approximate region, browser and device type. The data does not leave our server.
The legal basis is our legitimate interest in a data-minimising analysis of website usage (Art. 6(1)(f) GDPR). Because no information is stored on or read from your device, no consent is required for this.
7. Google Ads and Consent Mode
We advertise our services via Google Ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Please note: the Google script (gtag.js) is loaded as soon as the page opens, that is, before you have made a cookie decision. Your IP address is transmitted to Google in the process. However, the script starts in what is known as Consent Mode with the default setting “denied”: it stores nothing on your device, sets no advertising cookies, and Google removes advertising identifiers from the signals (ads data redaction). The legal basis for this is our legitimate interest in being able to measure our advertising (Art. 6(1)(f) GDPR).
Only once you consent to the “Google Ads” category does the script switch to full measurement and set cookies (including _gcl_au, _gcl_aw, _ga, _gid, IDE). From that point on, your consent is the legal basis (Art. 6(1)(a) GDPR).
Google also processes data in the USA. Further information is available in Google’s privacy policy.
8. LinkedIn Insight Tag
After you consent, we load the Insight Tag of LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. It measures the performance of our advertising on LinkedIn and sets cookies for this purpose (including li_sugr, bcookie, lidc, UserMatchHistory).
Without your consent this script is not loaded. The legal basis is your consent (Art. 6(1)(a) GDPR). LinkedIn also processes data in the USA. Further information is available in LinkedIn’s privacy policy.
9. Usage analysis and session recording with PostHog
After you consent, we use PostHog for usage analysis and session recordings. The data is processed in PostHog’s EU cloud (PostHog, Inc., EU region). The connection runs via our own address e.a11yplan.de.
The recordings mask all text and all input fields. Of the page content, only the layout and the flow of interaction are visible — no readable text and no entries. We create a person profile only for signed-in users.
In addition to the recording, we collect the following with PostHog:
- clicks, scrolling and mouse movement in aggregated form (heatmaps),
- page load times and technical performance values,
- JavaScript errors together with their technical description, so that we notice malfunctions,
- browser console output during a recording. This is not masked. We do not write personal data to it; we disclose it here regardless, because it is the one channel not covered by the masking.
Without your consent, PostHog is not loaded and records nothing. The legal basis is your consent (Art. 6(1)(a) GDPR). Further information is available in PostHog’s privacy policy.
10. Contact form, enquiries and quickcheck
If you write to us through a form on this website or request an audit, we process the data you provide — depending on the form, your name, email address, company, phone number, the web address to be audited and your message — in order to handle your enquiry.
This data is processed on our own server and forwarded internally to our team. The legal basis is the performance of pre-contractual measures (Art. 6(1)(b) GDPR) or our legitimate interest in responding to your enquiry (Art. 6(1)(f) GDPR).
We keep enquiries until they are settled and no further questions are to be expected, but no longer than statutory retention periods require.
11. Appointment booking and payment
For consultation appointments we link to cal.com with an ordinary link, and for bookings to Stripe. Neither service is embedded in this website: no script of theirs is loaded and no cookies of theirs are set unless you click the link. Only when you follow such a link do you leave our website, and the privacy policy of the respective provider applies.
12. Transfers to third countries
The providers named under sections 3, 7 and 8 may also process data outside the European Union, in particular in the USA. This is based on the European Commission’s standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework.
Umami and PostHog process this website’s data within the European Union.
13. Data security
This website is served exclusively over encrypted HTTPS. Data transmitted between your browser and our server therefore cannot be read by third parties.
14. Changes to this policy
We update this policy when the services we use or the legal situation change.
Last updated: 2 September 2026.