Skip to main content

Privacy Policy

Last Updated: July 15, 2025

Short Version

Building Better Teams - Brian Graham takes your privacy seriously and complies with the General Data Protection Regulation (GDPR). We collect only minimal data necessary for our consulting services, primarily contact information and authentication data for invite-only platforms. Most of our websites don't use cookies, and when they do, it's only for essential functions like maintaining login sessions. We don't track individual users beyond necessary business purposes, sell your data, or share it with third parties except documented service providers. Server logs are anonymized and purged after 7 days. Newsletter data is managed through our self-hosted system with email delivery via Google Workspace under GDPR-compliant data processing agreements. In short, we respect your privacy, follow data minimization principles, and give you full control over your personal data.

1. Data Controller Information

Data Controller: Building Better Teams - Brian Graham
Business Registration: Einzelunternehmen (Sole Proprietorship)
Registration Authority: Bezirksamt Steglitz-Zehlendorf, Berlin
VAT ID: DE354152177
Address: Mühlenstr. 8a, 14167 Berlin, Germany
Email: info@buildingbetterteams.de
Phone: +491783212891

2. Website Coverage

This Privacy Policy covers the following websites:

  • buildingbetterteams.de - Main website
  • kb.buildingbetterteams.de - Knowledge base
  • listmonk.buildingbetterteams.de - Newsletter management interface (accessed via subscription/unsubscribe links)
  • auth.statagroup.com - Private portal (invite-only access)
  • git.statagroup.com - Code hosting (Forgejo instance, account access by invite only)

Important: This policy does NOT cover dashboard.buildingbetterteams.de which has its own separate privacy policy as it hosts an interactive application with different login and data handling requirements.

3. Data Protection Officer

Our Data Protection Officer (DPO) is:

Brian Graham
Building Better Teams - Brian Graham
Email: info@buildingbetterteams.de
Phone: +491783212891

You can contact our DPO directly for all data protection matters, privacy concerns, and to exercise your rights under GDPR.

4. Personal Data We Collect and Legal Basis

We collect and process personal data in accordance with GDPR data minimization principles:

4.1 Client and Business Data

Information we need to deliver consulting services, communicate with clients, and run our business.

  • Contact Information: Name, email, phone, company details
    Legal Basis: Contract performance (Article 6(1)(b)) and legitimate interests (Article 6(1)(f))
  • Project Communications: Consultation details, emails, documents you provide
    Legal Basis: Contract performance (Article 6(1)(b))
  • Billing Information: Payment details, invoicing data
    Legal Basis: Contract performance (Article 6(1)(b)) and legal obligation (Article 6(1)(c))

4.2 Newsletter Data

Information collected when you subscribe to our newsletter and interact with our content.

  • Subscription Information: Email address, first name (optional), subscription preferences
    Legal Basis: Consent (Article 6(1)(a)) with documented double opt-in
  • Processing Method: Self-hosted Listmonk with Google Workspace Gmail SMTP relay
    Data Protection: Processed under Google's Cloud Data Processing Addendum (CDPA) with comprehensive GDPR safeguards
  • Interaction Data: When you visit listmonk.buildingbetterteams.de via subscription/unsubscribe links or view newsletter assets
    Legal Basis: Legitimate interests (Article 6(1)(f)) - managing subscription preferences and newsletter delivery

4.3 Technical Data

Technical information automatically collected to keep our websites secure and functioning properly.

  • Authentication Data: Login credentials for invite-only services
    Legal Basis: Contract performance (Article 6(1)(b))
  • Server Logs: Anonymized IP addresses (last octet masked), timestamps, request types
    Legal Basis: Legitimate interests (Article 6(1)(f)) - security monitoring
  • WAF Security Data: IP addresses, request patterns for threat detection
    Legal Basis: Legitimate interests (Article 6(1)(f)) - system protection

5. Legitimate Interests Assessment

Where we rely on legitimate interests (Article 6(1)(f)), we have conducted balancing tests:

5.1 Client Relationship Management

  • Interest: Maintaining client relationships and business development
  • Necessity: Contact information essential for service delivery
  • Balance: Minimal privacy impact, business contact only, opt-out available
  • Safeguards: Data minimization, secure storage, regular necessity review

5.2 Security Monitoring

  • Interest: Protecting systems and client data from cyber threats
  • Necessity: Log analysis required for threat detection and prevention
  • Balance: IP anonymization and 7-day retention minimize privacy impact
  • Safeguards: Immediate anonymization, short retention, no individual profiling

5.3 Newsletter Delivery and Management

  • Interest: Ensuring reliable newsletter delivery and managing subscription preferences
  • Necessity: Interaction tracking required for delivery confirmation and subscription management
  • Balance: Limited to technical delivery data, short retention, anonymization after 7 days
  • Safeguards: No behavioral profiling, data minimization, easy unsubscribe options

6. How We Use Your Personal Data

  • Service Delivery: Providing consulting services and client support
  • Business Operations: Billing, payment processing, client relationships
  • Legal Compliance: Tax reporting, financial records, regulatory obligations
  • Communications: Newsletter delivery (consent-based only)
  • Security: Protecting systems and preventing unauthorized access

7. Data Retention

7.1 Specific Retention Periods

  • Active Client Data: Duration of engagement plus 6 years (legal/tax requirements)
  • Financial Records: 7 years (German tax law)
  • Newsletter Subscriptions: Until consent withdrawn or 3 years of inactivity
  • Server Logs: 7 days on live systems (anonymized immediately, then purged)
  • Log Data in Backups: Up to 14 days total (7 days live + up to 7 days in system backups)
  • WAF Security Logs: 7 days maximum on live systems, up to 14 days including backups
  • Gmail SMTP Relay Processing: Email delivery processed through Google Workspace SMTP relay infrastructure in accordance with Google's standard data processing practices as outlined in the CDPA

7.2 Backup Retention

For business continuity and disaster recovery, we create encrypted backups stored offline in a secured location:

  • Backup Retention: Maximum 7 days before secure deletion
  • Log Data in Backups: Since backups may contain logs within their 7-day retention period, the effective maximum retention for log data is 14 days (7 days live + 7 days in oldest backup)
  • Security: All backups fully encrypted and remain under our direct physical control
  • Access: Backup data only accessed for disaster recovery purposes

8. Data Sharing and Transfers

All subscriber data storage and processing occurs within the European Economic Area (EEA):

8.1 Service Providers

  • Hetzner Online GmbH (Finland): Server hosting with GDPR-compliant data processing agreement
  • Google Workspace (Ireland): Email communications (incoming emails) and Gmail SMTP relay for newsletter delivery with CDPA ensuring GDPR compliance

8.2 Gmail SMTP Processing

Newsletter email delivery is processed through Google Workspace under our CDPA, ensuring that Google acts as a data processor in compliance with GDPR requirements. While our subscriber data remains stored within the EEA, email delivery may route through Google's global infrastructure under EEA data protection standards.

8.3 No International Transfers

All subscriber data storage remains within the EEA. Email delivery through Google's SMTP relay operates under EEA data protection standards via our CDPA.

9. Newsletter Management

9.1 Technical Setup

  • Primary System: Self-hosted Listmonk for subscriber management and newsletter creation
  • User Interface: listmonk.buildingbetterteams.de for subscription management, unsubscribe, and preference updates
  • Newsletter Assets: Images, documents, and other content served from our servers
  • Delivery: Google Workspace Gmail SMTP relay service
  • Data Protection: Processed under Google's CDPA with comprehensive GDPR safeguards
  • Location: Mailing lists stored on Building Better Teams servers within the EU (Finland); email delivery processed through Google's GDPR-compliant infrastructure

9.2 Consent and Management

  • Double Opt-In: Email confirmation required to verify subscription
  • Subscription Management: Direct access via listmonk.buildingbetterteams.de for preference updates
  • Frequency: Maximum 1-2 newsletters per month
  • Unsubscribe: One-click unsubscribe in every email or via web interface
  • Data Deletion: Subscriber data deleted within 30 days of unsubscription

9.3 Newsletter Interaction Tracking

  • Asset Access: When you view newsletter content, images, or documents, your interaction may be logged for delivery purposes
  • Link Tracking: Subscription/unsubscribe links contain a special code to identify you uniquely, so you can modify your subscription state
  • Data Collected: Access timestamps, IP addresses (anonymized after 7 days), user agent information
  • Purpose: Ensuring newsletter delivery, managing subscriptions, and system maintenance
  • Log Retention:Web interaction logs follow our standard 7-day anonymization and purge schedule.

10. Cookies and Tracking

Most of our websites are cookie-free:

  • buildingbetterteams.de: No cookies used
  • kb.buildingbetterteams.de: No cookies used
  • listmonk.buildingbetterteams.de:Essential session cookies only for features which allow you to manage your subsription
  • auth.statagroup.com: Essential session cookies only for authentication
  • git.statagroup.com: Essential session cookies only for logged-in users

11. Data Security

11.1 Technical Measures

  • Encryption: All data for kb.buildingbetterteams.de is encrypted in transit, and at rest.
  • Access Controls:Server administration access requires multi-factor-auth, role-based access, or cryptographic key where appropriate.
  • Network Security: Self-hosted BunkerWeb WAF for threat protection
  • Monitoring:Automated security monitoring and log analysis via self-hosted BunkerWeb, SigNoz, CheckMk, and standard logging interfaces.
  • Backups: Encrypted offline backups in physically secured location. Web access logs are not backed up.

11.2 Organizational Measures

  • Documentation: Comprehensive records of all processing activities
  • Incident Response: Documented procedures for security incidents
  • Regular Review: Quarterly assessment of security measures and data processing

12. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Access (Article 15): Request copies of your personal data
  • Rectification (Article 16): Correct inaccurate information
  • Erasure (Article 17): Request deletion (subject to legal obligations)
  • Restriction (Article 18): Limit processing of your data
  • Portability (Article 20): Receive data in portable format
  • Object (Article 21): Object to processing based on legitimate interests
  • Withdraw Consent: For newsletter and other consent-based processing

12.1 Exercising Your Rights

Contact us at info@buildingbetterteams.de with:

  • Clear description of your request
  • Information to verify your identity
  • Preferred response format (if applicable)

12.2 Identity Verification

  • Active Clients: Email verification to registered address
  • Newsletter Subscribers: Verification to subscription email
  • Sensitive Requests: Additional verification as appropriate

Response Time: Within one month (extendable to three months for complex requests)

13. Data Breach Response

In the unlikely event of a data breach, we will:

  • Immediate Response (0-24 hours): Contain breach and assess impact
  • Authority Notification (72 hours): Report to Berlin Commissioner for Data Protection if breach likely causes risk to individuals
  • Individual Notification: Notify affected persons without undue delay if high risk likely
  • Documentation: Record all details, actions taken, and preventive measures

Given our minimal data collection and short retention periods, any breach impact is inherently limited.

14. Email Communications

Our business email (info@buildingbetterteams.de) uses Google Workspace. When you email us:

  • Your communication is processed on Google's servers as our data processor
  • We have appropriate data processing agreements in place (CDPA)
  • Emails are retained for business and legal purposes only
  • Access is limited to necessary business functions

15. Changes to This Privacy Policy

  • Updates: Material changes communicated via email and website notice
  • Effective Date: Changes effective 30 days after notification
  • New Purposes: Fresh consent required for new processing purposes
  • Review: Policy reviewed annually and updated as needed

16. Contact Information

For all privacy inquiries and data subject requests:

Email: info@buildingbetterteams.de (preferred)
Phone: +491783212891
Address: Building Better Teams - Brian Graham
Mühlenstr. 8a, 14167 Berlin, Germany

Response Times: Privacy inquiries within 72 hours, data subject requests within one month.

17. Supervisory Authority

You have the right to lodge a complaint with the supervisory authority. We encourage contacting us first to resolve concerns.

Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstraße 219, 10969 Berlin, Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de

18. Compliance Documentation

In accordance with GDPR Article 5(2) accountability principle, we maintain:

  • Processing Records: Article 30 documentation of all processing activities
  • Consent Records: Newsletter opt-in logs with timestamps and source tracking
  • Legitimate Interests Assessments: Documented balancing tests
  • Vendor Agreements: Data processing agreements with all service providers
  • Security Documentation: Technical and organizational measures
  • Incident Logs: Breach response documentation and lessons learned

This Privacy Policy reflects current GDPR requirements and our actual data processing practices. For questions about specific provisions, contact info@buildingbetterteams.de.