Privacy policy
LAST UPDATED SEPTEMBER 25, 2026§ 1 Purpose of this Privacy Policy
1.1. The protection of personal data is of utmost importance to The Brand Case.
1.2. This Privacy Policy explains how personal data is processed in connection with the use of this website, contacting The Brand Case, subscribing to services, and the provision of strategic consulting services.
1.3. In particular, this Privacy Policy explains:
- what personal data is collected and processed;
- the purposes for which personal data is processed;
- the legal bases for the processing of personal data;
- the categories of recipients to whom personal data may be disclosed;
- how long personal data is retained;
- and the rights of data subjects under the General Data Protection Regulation (GDPR).
1.4. This Privacy Policy applies to all online services provided by The Brand Case unless a separate or supplementary privacy notice expressly applies.
§ 2 Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
The Brand Case Lara Katharina Schmitt Prälat-Diehl-Straße 2 64372 Ober-Ramstadt Germany Email: info@thebrandcase.studio Website: www.thebrandcase.studio
§ 3 Definitions
This Privacy Policy uses the terminology of the General Data Protection Regulation (GDPR). For the purposes of this Privacy Policy, the following definitions shall apply in particular:
3.1 Personal Data
Any information relating to an identified or identifiable natural person.
3.2 Processing
Any operation or set of operations performed on personal data, whether or not by automated means, including the collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure, or destruction of personal data.
3.3 Data Subject
Any identified or identifiable natural person whose personal data is processed.
3.4 Controller
The natural or legal person that determines the purposes and means of the processing of personal data, either alone or jointly with others.
3.5 Processor
A natural or legal person that processes personal data on behalf of the Controller.
§ 4 Principles of Data Processing
4.1. Personal data is processed exclusively in accordance with the applicable data protection legislation.
4.2. The Brand Case processes personal data in accordance with the following principles:
- lawfulness, fairness, and transparency;
- purpose limitation;
- data minimization;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- and accountability.
4.3. Only such personal data as is necessary for the respective processing purpose shall be collected and processed.
§ 5 Legal Bases for Processing
5.1. Personal data is processed exclusively on the basis of the applicable legal provisions.
5.2. Where personal data is processed on the basis of consent, the legal basis is Article 6(1)(a) GDPR.
5.3. Where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract, the legal basis is Article 6(1)(b) GDPR.
5.4. Where processing is necessary to comply with a legal obligation, the legal basis is Article 6(1)(c) GDPR.
5.5. Where processing is necessary for the purposes of the legitimate interests pursued by The Brand Case or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject, the legal basis is Article 6(1)(f) GDPR.
5.6. Where special categories of personal data is processed, such processing shall take place only where permitted by the applicable legal provisions.
§ 6 Website Hosting
6.1. This website is hosted by STRATO AG.
6.2. Whenever this website is accessed, the hosting provider automatically processes certain technical information required to operate, secure, and deliver the website.
6.3. This information may include, in particular:
- IP address;
- date and time of access;
- pages accessed;
- browser type and browser version;
- operating system;
- referrer URL;
- amount of data transferred;
- HTTP status codes;
- and other technical connection data.
6.4. The processing of this information is carried out for the purpose of providing the website, ensuring system security and stability, and identifying technical errors. The legal basis for this processing is Article 6(1)(f) GDPR.
6.5. The legitimate interest consists of providing a secure, reliable, and technically functional website.
6.6. Where required by law, a Data Processing Agreement pursuant to Article 28 GDPR has been concluded with the hosting provider.
§ 7 Server Log Files
7.1. Whenever this website is accessed, certain technical information is automatically stored in server log files.
7.2. This processing is carried out solely to ensure the proper operation of the website, maintain system security, and prevent misuse.
7.3. As a general rule, this information is not combined with data obtained from other sources.
7.4. The retention period for server log files depends on the technical and legal requirements of the hosting provider as well as the legitimate interest in maintaining IT security.
§ 8 Cookies and Consent Management
8.1. This website uses cookies and similar technologies to ensure the proper functionality of the website, analyze its use, and, where applicable, provide additional services.
8.2. Cookies are small text files stored on a user's device that contain certain information.
8.3. A distinction is made between technically necessary cookies and cookies that require the user's prior consent.
8.4. Technically necessary cookies are processed on the basis of Article 6(1)(f) GDPR, where such processing is required to ensure the secure and functional operation of the website.
8.5. All other cookies, including analytics, marketing, or personalization cookies, are used only after the user has provided prior consent in accordance with Article 6(1)(a) GDPR in conjunction with Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
8.6. User consent is managed through the following Consent Management Platform: Cookiebot (Usercentrics A/S).Cookiebot.
8.7. Visitors may grant, refuse, or withdraw their consent at any time through the consent banner.
§ 9 Contacting The Brand Case
9.1. If you contact The Brand Case by email, by telephone, or via the contact form on this website, the personal data you voluntarily provide will be processed to the extent necessary to respond to your inquiry.
9.2. This may include, in particular:
- name;
- company name;
- email address;
- telephone number;
- the content of your inquiry;
- and any other information voluntarily provided.
9.3. The processing is carried out solely for the purpose of responding to your inquiry and, where applicable, taking steps prior to entering into a contractual relationship.
9.4. Where your inquiry relates to a potential or existing contractual relationship, the legal basis is Article 6(1)(b) GDPR.
9.5. In all other cases, processing is based on the legitimate interest pursuant to Article 6(1)(f) GDPR in maintaining efficient and effective business communication.
§ 10 Appointment Scheduling via Calendly
10.1. Appointment scheduling is facilitated through Calendly.
10.2. When using Calendly, the following personal data may be processed, in particular:
- name;
- email address;
- appointment details;
- telephone number (where provided);
- information voluntarily submitted through the booking form;
- and technical usage data.
10.3. This processing is carried out exclusively for the purpose of scheduling, preparing, and conducting consultation meetings.
10.4. Where the appointment relates to the initiation or performance of a contractual relationship, the legal basis is Article 6(1)(b) GDPR.
10.5. In all other cases, processing is based on the legitimate interest pursuant to Article 6(1)(f) GDPR in providing an efficient appointment management process.
10.6. Further information regarding Calendly's processing of personal data can be found in Calendly's Privacy Policy.
§ 11 Email Newsletter
11.1. Visitors may subscribe to The Brand Read newsletter and to launch notifications for The Brand Subscription.
11.2. The newsletter is distributed using Brevo.
11.3. For this purpose, the following personal data may be processed:
- email address;
- date and time of subscription;
- confirmation of subscription via the Double Opt-In procedure;
- and technical verification data.
11.4. The newsletter is sent only after the subscriber has provided explicit consent. The legal basis for this processing is Article 6(1)(a) GDPR.
11.5. Consent may be withdrawn at any time with effect for the future. Every newsletter contains an unsubscribe link enabling recipients to withdraw their consent at any time.
11.6. Further information regarding Brevo's processing of personal data can be found in Brevo's Privacy Policy.
§ 12 Pre-Contractual Measures and Provision of Consulting Services
12.1. In the course of initiating, performing, and managing consulting engagements, The Brand Case processes personal data to the extent necessary for the provision of the agreed consulting services.
12.2. Depending on the nature of the engagement, this may include:
- contact details of representatives and contact persons;
- company information;
- communication records;
- project-related information;
- workshop materials;
- strategy documents;
- presentations;
- project files;
- feedback;
- invoicing information;
- and any other project-related information required for the performance of the consulting services.
12.3. Personal data is processed exclusively for the purpose of providing the agreed consulting services. The legal basis is Article 6(1)(b) GDPR.
12.4. Where statutory retention obligations apply, processing is additionally based on Article 6(1)(c) GDPR.
§ 13 Project Collaboration Tools
13.1. Various digital collaboration and productivity tools may be used in connection with consulting engagements.
13.2. These currently include, in particular:
- Notion;
- Google Drive;
- Figma;
- and Miro.
13.3. These tools are used solely where necessary for the provision of the agreed consulting services.
13.4. Depending on the project, these platforms may be used to prepare, store, exchange, or collaboratively edit project documentation, presentations, workshop materials, strategy documents, and other project-related files. The legal basis for this processing is Article 6(1)(b) GDPR.
13.5. Where personal data is transferred to external service providers, such transfers are limited to what is necessary for the respective consulting engagement and are carried out in accordance with the applicable data protection legislation.
§ 14 Video Conferencing
14.1. Video conferencing services are used for sales meetings, consultation sessions, workshops, presentations, and other business meetings.
14.2. As a general rule, meetings are conducted via Google Meet.
14.3. Upon request of the Client or where project requirements make it appropriate, other widely used video conferencing services, such as Microsoft Teams or Zoom, may also be used.
14.4. Depending on the meeting, the following personal data may be processed:
- name;
- email address;
- audio and video streams;
- chat messages;
- shared content;
- and technical connection data.
14.5. The processing is carried out solely for the purpose of conducting the respective meeting. The legal basis is Article 6(1)(b) GDPR.
14.6. Where meetings are to be recorded, participants will be informed in advance and, where legally required, their prior consent will be obtained.
§ 15 Payment Processing
15.1. At present, payments for consulting services are made exclusively by bank transfer.
15.2. Only such personal data as is necessary for invoicing and payment processing is processed.
15.3. This may include, in particular:
- name;
- billing address;
- company information;
- payment information;
- and invoice data.
The legal basis for this processing is Article 6(1)(b) GDPR.
15.4. Where commercial or tax law requires records to be retained, processing is additionally based on Article 6(1)(c) GDPR.
15.5. Digital products of The Brand Kit are sold through Gumroad, Inc., which acts as Merchant of Record. Gumroad processes the personal data required for the purchase, such as name, email address, billing address, payment information, and transaction data, under its own responsibility and in accordance with its own privacy policy. Where The Brand Case receives personal data from Gumroad in order to provide access to a purchased product, the legal basis for this processing is Article 6(1)(b) GDPR.
§ 16 Use of Artificial Intelligence (AI)
16.1. The Brand Case may use AI-powered applications to support internal business processes in the course of providing consulting services.
16.2. Such applications currently include, in particular:
- ChatGPT (OpenAI);
- and Claude (Anthropic).
16.3. These tools are used solely to support strategic consulting activities, including idea generation, content structuring, drafting, research support, and comparable internal work processes.
16.4. Where personal data is processed using AI-powered applications, such processing takes place only where it is necessary for the performance of the respective consulting services and permitted under applicable data protection laws.
16.5. Appropriate technical and organizational measures are implemented to protect personal data. Wherever reasonably possible, personal data is anonymized or pseudonymized before being processed through AI-powered applications.
16.6. The legal basis for this processing is Article 6(1)(b) GDPR and, where applicable, Article 6(1)(f) GDPR.
§ 17 Analytics and Tracking Services
17.1. This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited.
17.2. Google Analytics enables the analysis of website usage in order to continuously improve the functionality, content, and user experience of this website.
17.3. Depending on the configuration of the service, the following information may be processed:
- IP address (shortened or anonymized where technically available);
- device information;
- browser information;
- pages visited;
- user interactions;
- session duration;
- referrer information;
- and technical event data.
17.4. Google Analytics is used only after the user has granted consent through the Consent Management Platform. The legal basis for this processing is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
17.5. Consent may be withdrawn at any time with future effect.
17.6. Further information regarding Google's processing of personal data is available in Google's Privacy Policy.
§ 18 Social Media Presence
18.1. The Brand Case maintains professional profiles on various social media platforms.
18.2. These currently include, in particular:
- LinkedIn;
- TikTok;
- and Substack.
18.3. The operators of these platforms process personal data independently in accordance with their respective privacy policies.
18.4. When visiting these platforms, personal data may also be processed outside the European Union or the European Economic Area.
18.5. Where users contact The Brand Case via social media, the personal data provided will be processed solely for the purpose of responding to the respective inquiry. The legal basis for this processing is Article 6(1)(f) GDPR.
§ 19 Embedded Content
19.1. This website may include content provided by third-party services.
19.2. Such embedded content may include, in particular, videos hosted on YouTube.
19.3. When embedded content is accessed, personal data — such as the user's IP address and technical connection data — may be transmitted to the respective provider.
19.4. Embedded content is integrated only in accordance with the applicable data protection legislation.
19.5. Where user consent is legally required, such content will only be loaded after prior consent has been obtained pursuant to Article 6(1)(a) GDPR.
§ 20 Recipients of Personal Data
20.1. Personal data is not disclosed to third parties unless:
- disclosure is required by law;
- disclosure is necessary for the performance of a contract;
- the data subject has given consent;
- or another legal basis permits or requires the disclosure.
20.2. Depending on the circumstances, recipients of personal data may include:
- hosting providers;
- IT service providers;
- newsletter providers;
- appointment scheduling services;
- digital sales platforms;
- video conferencing providers;
- analytics and tracking providers;
- cloud storage and collaboration platforms;
- tax advisors;
- banks;
- and public authorities where disclosure is required by law.
20.3. Where service providers process personal data on behalf of The Brand Case, they do so only under a Data Processing Agreement in accordance with Article 28 GDPR, where legally required.
§ 21 International Data Transfers
21.1. Some of the service providers used by The Brand Case may process personal data in countries outside the European Union or the European Economic Area.
21.2. Where personal data is transferred to a third country, such transfers take place only in accordance with Articles 44 et seq. GDPR.
21.3. Where required, appropriate safeguards are implemented, including:
- adequacy decisions issued by the European Commission; or
- the European Commission's Standard Contractual Clauses (SCCs) or other legally recognized safeguards.
§ 22 Data Retention
22.1. Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable legal obligations.
22.2. Once the relevant processing purpose no longer applies, personal data will be deleted unless statutory retention periods or other legal obligations require continued storage.
22.3. Statutory commercial and tax retention obligations remain unaffected.
§ 23 Data Security
23.1. The Brand Case implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
23.2. Security measures are continuously reviewed and updated in line with technological developments and evolving security requirements.
23.3. Despite all reasonable precautions, the transmission of information over the internet can never be guaranteed to be completely secure.
§ 24 Rights of Data Subjects
24.1. Subject to the applicable legal requirements, data subjects have the following rights:
- the right of access pursuant to Article 15 GDPR;
- the right to rectification pursuant to Article 16 GDPR;
- the right to erasure pursuant to Article 17 GDPR;
- the right to restriction of processing pursuant to Article 18 GDPR;
- the right to data portability pursuant to Article 20 GDPR;
- the right to object pursuant to Article 21 GDPR;
- the right to withdraw consent at any time with future effect; and
- the right to lodge a complaint with a competent supervisory authority pursuant to Article 77 GDPR.
24.2. The exercise of these rights is generally free of charge.
§ 25 Changes to this Privacy Policy
25.1. The Brand Case reserves the right to amend this Privacy Policy where necessary to reflect legal, regulatory, technical, or organizational developments.
25.2. The version published on this website at the time of access shall apply to the use of the website.
25.3. For existing contractual relationships, the version incorporated into the contractual relationship at the time of its conclusion shall apply, unless mandatory legal provisions require otherwise or the parties expressly agree otherwise in writing.
§ 26 Contact
If you have any questions regarding this Privacy Policy or the processing of your personal data, or if you wish to exercise your rights under applicable data protection law, you may contact the Controller at any time.
The Brand Case Lara Katharina Schmitt Email: info@thebrandcase.studio Website: www.thebrandcase.studio