Privacy policy

Version of 2026-09-08

This policy explains what happens to your personal data when you use this website. Short version: we count visits without cookies, we only load advertising tools if you agree, and we use what you send us in a form to answer you — nothing else.

1. Controller

The controller responsible for data processing on this website is:

BarrierZero GmbH (i. G.)
Musterstraße 1
10115 Berlin
Germany
Email: privacy@barrierzero.de
Phone: +49 30 000000

TODO: If a data protection officer is appointed, name them here.

2. Your rights at a glance

Under the GDPR you have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7 (3)).

To exercise a right, write to privacy@barrierzero.de. You also have the right to lodge a complaint with a supervisory authority — for us that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.

3. Hosting and server log files

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA (TODO: confirm or replace with your hosting provider). Vercel processes data on our behalf under a data processing agreement (Art. 28 GDPR). Transfers to the USA are based on the EU standard contractual clauses and the EU–US Data Privacy Framework.

When you open a page, the server automatically records:

  • the requested URL and referrer
  • date and time of the request
  • browser type and version, operating system
  • a shortened or hashed IP address

This is technically necessary to deliver the page and to keep the service secure and stable. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure, functioning provision of the website). Log data is deleted or anonymised after 30 days at the latest.

4. Cookies and local storage

This website sets no cookies for analytics. We store one entry in your browser's local storage to remember your choice about advertising tools, so we do not ask again. That entry contains no personal data and is not transmitted.

If you agree to marketing tools, Google sets cookies as described in section 6. Details, including how to withdraw consent, are in the cookie notice.

5. Reach measurement with Plausible Analytics

We use Plausible Analytics to count visits. Plausible is cookieless: it sets no cookies, stores nothing on your device and does not create a cross-site profile. IP addresses are only processed transiently to generate a daily, salted hash and are never stored. The data collected — page, referrer, country, device class, browser — cannot be traced back to you.

Processing takes place on servers in the EU. Provider: Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia, as a processor under Art. 28 GDPR.

Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in understanding how many people visit which pages. Since no information is stored on or read from your device, no consent under § 25 TDDDG is required.

6. Google Ads and conversion measurement — only with your consent

We advertise our service with Google Ads. Only if you press “Agree” in our consent banner do we load Google's tag, which then sets cookies and transmits data to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (and, where applicable, to Google LLC in the USA under the EU–US Data Privacy Framework and standard contractual clauses).

The purpose is conversion measurement: to see which advertisement led to a request for a scan or a demo, and to optimise our campaigns. Data processed may include: click identifiers, the pages you visit on this site, device and browser information, an IP address, and interaction events.

Until you agree, we operate Google Consent Mode v2 with all storage set to denied, and advertising data redaction switched on.

Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (consent). You can withdraw consent at any time via “Cookie settings” in the footer, with effect for the future. Google's privacy information: policies.google.com/privacy.

7. Contact forms and email

If you send us a request for a free scan, a demo or a general enquiry, we process the details you enter (name, email address, company, website, your message) in order to answer you. The form is submitted to our own server function and forwarded to our internal inbox and CRM.

Legal basis: Art. 6 (1) (b) GDPR where your request relates to a contract or pre-contractual steps, otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries). Providing the data is voluntary, but without an email address we cannot reply.

We keep enquiries for as long as needed to process them and afterwards in line with statutory retention obligations (generally 6 or 10 years for commercially relevant correspondence under § 257 HGB and § 147 AO). Enquiries with no commercial relevance are deleted after 12 months.

TODO: If you use an external CRM or email marketing provider (e.g. HubSpot, Brevo, Resend), name it here with its role as processor.

8. When you run a free scan of your website

If you ask us to scan a website, our crawler retrieves publicly accessible pages of the domain you specify and stores the results (findings, screenshots, HTML fragments) in order to produce your report. Where those pages contain personal data, we process it solely to produce the report and delete the crawl data no later than 90 days after delivery, unless you become a customer and the data belongs to your account.

Legal basis: Art. 6 (1) (b) GDPR (performance of the requested service). Please only request scans for domains you are authorised to have tested.

9. Recipients and transfers

We pass personal data only to processors who support us in operating this website and our business, bound by data processing agreements: our hosting provider, our email provider and — with your consent — Google for advertising measurement. We do not sell personal data and do not use your data to train third-party AI models.

10. Security

This website is delivered exclusively over TLS (HTTPS). We apply technical and organisational measures appropriate to the risk, including access control, encryption in transit and at rest, and least-privilege access for our team. Report a suspected vulnerability to security@barrierzero.de.

11. Changes to this policy

We update this policy when our processing changes or the legal situation requires it. The current version is always available at this address. Version: 2026-09-08.