1. Controller and contact
The controller for the processing of personal data in connection with this website and my offers is:
Raphael Alexander Wagener, trading as „Raphael Alexander“
Im Siepen 14, 42555 Velbert, Germany
Telephone: +49 152 28473595
Email: raphael@raphael-alexander.com
For all questions about data protection and to exercise your rights, please use these contact details directly.

2. Principles and legal bases
I process personal data only where this is necessary to operate this website, handle enquiries, prepare and perform contracts, comply with legal obligations, or where you have given valid consent.
Depending on the processing, the legal bases are in particular:
● Article 6(1)(a) GDPR – your consent, for example for the newsletter or for particularly sensitive information
● Article 6(1)(b) GDPR – performance of a contract or pre-contractual measures at your request
● Article 6(1)(c) GDPR – compliance with legal obligations, in particular tax retention duties
● Article 6(1)(f) GDPR – legitimate interests, in particular the secure operation of the website, answering general enquiries and establishing or defending legal claims
My offers may touch on very personal areas of life. Where special categories of personal data within the meaning of Article 9(1) GDPR are processed, in particular health data, this takes place only on a suitable legal basis. Where the processing is based on consent, I obtain separate express consent under Article 9(2)(a) GDPR beforehand (see the section ‘Particularly sensitive information and express consent’).
I process only data necessary for the respective purpose and do not store it longer than required for that purpose or by statutory retention and evidence obligations. An overview of the intended deletion periods is set out in the annex to this policy.
Providing personal data is generally voluntary. Without the data required for a contract or an enquiry, however, the service or reply cannot be provided. A legal obligation to provide data exists only where this is expressly indicated.
Automated decision-making, including profiling, within the meaning of Article 22 GDPR does not take place.

3. Hosting and server log files
This website is operated at dogado GmbH, Antonio-Segni-Straße 11, 44263 Dortmund, Germany. When the website is accessed, the web server processes technically necessary access data. This may include the page accessed, the date and time, the volume of data transferred and the retrieval status, browser type and version, operating system, referrer URL and IP address.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in the secure, stable and fault-free operation of the website and in preventing and investigating technical attacks.
Regular server log files are deleted after 7 days. Longer storage takes place only in individual cases where there are specific indications of a security incident or where the data is required to pursue legal claims. Separately secured data is deleted once the purpose ceases to apply.
Where the hosting provider processes personal data on my behalf, a data processing agreement under Article 28 GDPR is in place.

4. Contact form, email and telephone contact
Through the contact form, your name, email address, the selection of your concern and your message are processed. Providing a telephone number is optional. The form is operated with the Fluent Forms extension within my WordPress installation; the information is stored on the web server and additionally sent to me by email.
Where your enquiry is directed at preparing or performing a contract, the processing is based on Article 6(1)(b) GDPR. For other general enquiries it is based on Article 6(1)(f) GDPR; my legitimate interest lies in handling and answering your enquiry appropriately.
The data protection checkbox in the form confirms only that you have taken note of this privacy policy. It is not consent to processing that is already based on Article 6(1)(b) or (f) GDPR.
Please do not send diagnoses, health data or other particularly sensitive details through the contact form. Data that may be required during subsequent guidance is governed by the section ‘Data in connection with my services’.
Where you contact me by email or telephone, I process the data transmitted for the same purposes and on the same legal bases. Unencrypted email is sent over the internet and may have security gaps; for confidential content we can agree another route. Telephone calls are not recorded.
I delete enquiries that do not lead to a contract six months after their processing has been completed, unless statutory retention obligations or other legitimate grounds require longer storage. This applies to the copy stored in the form and to the corresponding email, unless specific further communication, a statutory retention obligation or another documented ground requires longer storage.
Where a contract comes about, only the data required for performance, invoicing and statutory evidence is transferred into the relevant records. Free-text information that is not needed is not retained as a precaution.

5. Appointment booking via Cal.com
For booking the free initial consultation I link to the external service Cal.com. The provider is Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. When you click the link, you leave my website.
For the booking, Cal.com processes in particular your name, your email address, the requested appointment and technical usage data. I receive the booking data required to organise the appointment.
The legal basis for my processing of the booking data is Article 6(1)(b) GDPR, as the booking serves pre-contractual measures at your request. The booking form contains no field inviting diagnoses, health data or confidential case details. Please do not enter such information there.
Cal.com also processes personal data in the United States. The transfer to the United States takes place on the basis of the European Commission’s standard contractual clauses under Article 46(2)(c) GDPR. A documented transfer impact assessment is in place.
Appointment bookings that do not lead to a paid contractual relationship are deleted in my own systems no later than six months after the appointment, unless they are needed for ongoing communication. Where a contract subsequently comes about, the periods set out under contract, appointment and invoicing data apply. Storage within Cal.com is additionally governed by that provider’s settings and privacy terms.
Cal.com is connected to calendar, video and reminder services. Where those services receive personal data, they are listed in the overview ‘Recipients, processors and other service providers’.

6. Transfers to third countries
Personal data is transferred to a country outside the European Union and the European Economic Area only where the conditions of Articles 44 to 49 GDPR are met.
The transfer to Cal.com, Inc. in the United States takes place on the basis of the European Commission’s standard contractual clauses under Article 46(2)(c) GDPR as part of the data processing agreement. A documented transfer impact assessment is in place.
A copy of the appropriate safeguards can be requested at raphael@raphael-alexander.com.
Despite these safeguards, it cannot be ruled out in every case that authorities in the recipient country may access transferred data and that data subjects there may not have the same level of legal protection as in the European Union. If you wish to avoid a transfer to the United States, you can arrange the free initial consultation by email or telephone instead; using Cal.com is not required.
Further service providers based or hosting outside the European Union are listed, where applicable, in the overview of recipients with the respective transfer basis. This concerns in particular the video conferencing service used for online appointments and the platforms on which my podcasts are published.

7. Audience measurement with Matomo
For statistical analysis and improvement of the website I use Matomo in a self-hosted configuration on my own server. The analysis data is not transferred to third parties.
In the configuration used, no cookies are set and no information is stored on your device. Consent under Section 25(1) of the German TDDDG is therefore not required. IP addresses are truncated before storage, the browser „Do Not Track“ setting is respected, and the analysis data is not combined with external data sources.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest lies in the data-minimising statistical analysis of website use and in its technical and editorial improvement.
Matomo raw data that can still be related to a person is deleted after 90 days. Only aggregated statistics without personal reference remain thereafter.
You may object to audience measurement at any time, using the objection option on that page, by activating „Do Not Track“ in your browser, or by sending a message to raphael@raphael-alexander.com.

8. Language selection
The Polylang extension is used for the German and English language versions. Where a technically necessary language cookie is set, it contains only the language identifier so that the language you have chosen is retained as you continue browsing.
This storage is strictly necessary for the language function you have expressly requested and takes place on the basis of Section 25(2) no. 2 TDDDG. The subsequent processing is based on Article 6(1)(f) GDPR.

9. Newsletter
If you sign up for my newsletter, I process your email address and, where you provide it voluntarily, your name. Sign-up uses the double opt-in procedure: after signing up you receive an email asking you to confirm. Sign-up and confirmation are logged so that consent can be demonstrated.
The legal basis for sending is Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future. Every newsletter contains a simple unsubscribe option.
After you unsubscribe, your address is deleted from the active distribution list. Evidence of the consent given is blocked and retained only for as long as necessary to defend or pursue possible legal claims or to meet legal evidence obligations; three years after unsubscribing are provided for.
No personalised open or click tracking takes place.
The newsletter is sent using MailPoet, Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

10. Data in connection with my services
10.1 Contract, appointment and invoicing data
To deliver booked services I process the necessary contact, appointment, contract and invoicing data on the basis of Article 6(1)(b) GDPR. Where documents must be retained under tax or commercial law, further storage is based on Article 6(1)(c) GDPR.
The retention period depends on the type of document. Under current law, invoices and accounting records must generally be kept for eight years; books, records, inventories and annual financial statements are subject to a ten-year period and other tax-relevant documents to a six-year period. The provisions as amended from time to time apply.
10.2 Particularly sensitive information and express consent
In grief support, support for exhaustion, 1:1 guidance and systemic constellation work you may voluntarily provide information concerning special categories of personal data under Article 9(1) GDPR, in particular health data.
Where such information is processed beyond the conversation itself – in particular in the form of necessary session notes – this takes place exclusively on the basis of separate express consent under Article 9(2)(a) GDPR. That consent is obtained and documented separately from the terms and conditions and from this privacy policy.
The guidance takes place even without that consent. If it is not given or is withdrawn, I keep no notes on the matters concerned and do not store them.
You decide for yourself what personal content you raise. There is no obligation to disclose information beyond what is necessary for working together. You may withdraw consent at any time with effect for the future; the lawfulness of processing before withdrawal remains unaffected.
Where individual data is still required after a withdrawal to establish, exercise or defend specific legal claims, processing may be based on Article 9(2)(f) GDPR to the extent necessary. That data is blocked separately and used only for that purpose.
10.3 Session notes
I prepare only those session notes that are actually necessary to continue the work. They are kept separately from general contact and invoicing data and are access-protected. Where stored digitally, appropriate encryption or device security is used.
Operational session notes are deleted no later than 12 months after the guidance ends, unless they have become unnecessary earlier.
Where in an individual case a documentation set reduced to what is necessary is required for longer to establish, exercise or defend specific legal claims, it is blocked separately and kept only for that purpose, at most until the statutory limitation period expires. It is deleted once the legal ground ceases to apply.
Conversations are not recorded in audio or video.
10.4 Funeral speeches, farewell speeches and laudations
To prepare a speech I process the information you provide about the person who has died or is being said goodbye to, and where applicable personal data of living relatives, colleagues or other people. The legal basis is Article 6(1)(b) GDPR in relation to you and Article 6(1)(f) GDPR in respect of information about other people; my legitimate interest and your interest lie in producing a speech appropriate to the occasion.
Where information relates exclusively to a deceased person, it is not personal data of a living data subject within the meaning of the GDPR. Information about living people is processed according to the principles described here.
Please share only such information about other people as is necessary for the speech, and where possible inform those people that it is being used.
Working notes and source material no longer needed are deleted no later than 3 months after the event. The final speech manuscript is deleted no later than 12 months after the event, unless longer retention has been expressly agreed or is required to establish, exercise or defend legal claims. Contract and invoicing records are unaffected.
Speech content or manuscripts are used as a work sample, reference or publication only where the necessary consents and rights of use are in place.
10.5 Offers for organisations
Where an organisation is the commissioning party, I process the contact details of the contact persons necessary for the enquiry, the contract and the organisation on the basis of Article 6(1)(b) and (f) GDPR.
For the content of confidential individual conversations with employees I am an independent controller within the meaning of Article 4(7) GDPR. I do not pass the content of those conversations to the commissioning organisation. It receives neither conversation content nor personal assessments or individual reports, unless the person concerned expressly wishes otherwise in the specific case and a suitable legal basis exists. Anonymous or aggregated information without personal reference, for example the number of sessions held, is permissible.
Participants receive the information relevant to them under Article 13 GDPR before the work begins. Where an organisation transmits employee data to me before first contact, this is limited to name and business contact details.
10.6 Online appointments and video conferencing
Online appointments are held via Jitsi Meet, 8×8, Inc., 675 Creekside Way, Campbell, CA 95008, USA. Processed are your name or chosen display name, your email address for sending the access link, connection and metadata, and the audio and video transmitted during the appointment. The legal basis is Article 6(1)(b) GDPR.
I do not record the appointments. Any recording function is deactivated where the service allows. Audio and video data is transmitted only during the appointment and is not stored permanently.
Where the provider processes data outside the European Union, the section on third-country transfers applies. On request, an appointment can take place by telephone instead.

11. Podcasts and external platform links
On this website I link to my podcasts on YouTube and Spotify using simple links. No embedded players, no preview images with third-party scripts and no other platform integrations are used. Merely opening my podcast page therefore transfers no data to YouTube or Spotify. Only by clicking an external link do you leave my website; the privacy terms of the respective provider then apply.
Before recording or publication, podcast guests receive a separate agreement covering recording, use and publication. The legal basis is their consent under Article 6(1)(a) GDPR in conjunction with the agreed rights of use.

12. Recipients, processors and other service providers
Personal data is passed to recipients only where necessary for the respective purpose or where there is a legal obligation. Under the current setup, the following recipients and processors are relevant in particular:

CategoryProvider and locationPurpose
Hosting and backupsdogado GmbH, Antonio-Segni-Straße 11, 44263 Dortmund, GermanyOperation of the website, servers and backups
Appointment bookingCal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USAScheduling the free initial consultation
Email and SMTPMZLA Technologies Corporation, 149 New Montgomery St, 4th Floor, San Francisco, CA 94105, USAEmail communication and form notifications
CalendarGoogle LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USAAppointment synchronisation
Video conferencingJitsi Meet, 8×8, Inc., 675 Creekside Way, Campbell, CA 95008, USAHolding online appointments
NewsletterMailPoet, Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USASending the newsletter
Postal and address serviceDeutsche Post AG, Bonn, GermanyReceipt and forwarding of post
IT and website supportdogado GmbH, Dortmund, GermanyAdministration and maintenance
Podcast hostingYouTube (Google Ireland Limited, Dublin, Ireland); Spotify AB, Stockholm, SwedenProvision and distribution of the podcasts
Legal advice, debt collectionwhere requiredEstablishing and defending claims

13. Your rights
Subject to the statutory conditions, you have in particular the following rights: access to the data processed about you (Article 15 GDPR), rectification of inaccurate or incomplete data (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection to processing based on legitimate interests (Article 21).
Right to object: you may object at any time, on grounds relating to your particular situation, to processing of your personal data based on Article 6(1)(f) GDPR. In that case I will no longer process the data concerned unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Consent given may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
To exercise your rights, a message to raphael@raphael-alexander.com is sufficient. To protect your data, I may request additional information where there is reasonable doubt about your identity.
You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR). The authority generally competent for me is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de. Your right to complain is not limited to this authority.