Privacy policy
Last updated: 11 October 2026
Controller and contact
Stefan Wolk · online-driven.de
Im Soll 37 · 22179 Hamburg · Germany

Overview
This website provides information about my professional activities. Personal data may be processed when you visit the website, contact me or voluntarily load the LinkedIn feed. This concerns website visitors and people who get in touch.
Providing the website
When you visit the website, technically necessary data such as your IP address, access time, requested files and browser and device information is transmitted to the hosting service. This enables delivery of the website and helps maintain security and stability. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is providing this website securely.
Contact enquiries
If you contact me by email or telephone, I process your contact details and the content of your message to respond. The legal basis is Article 6(1)(f) GDPR (the interest in responding to enquiries), or Article 6(1)(b) GDPR for enquiries relating to a contract.
Consent management with CCM19
We use CCM19 to manage and document your cookie consent. Your choices and technical connection data are processed for this purpose. You can change your choices at any time using Cookie settings in the footer.
LinkedIn feed via Elfsight
The LinkedIn feed is disabled initially. The external Elfsight widget loads automatically once you enable Elfsight in the CCM19 cookie settings. This transmits information including your IP address, browser and operating system to Elfsight. Embedded providers may load additional resources. Depending on the provider, processing may take place outside the EU or EEA.
Loading is based on your consent under Article 6(1)(a) GDPR. Any storage of or access to information on your device is based on your consent under Section 25(1) TDDDG. You can withdraw consent for further embedding through the “Cookie settings” link; this does not affect the lawfulness of processing before withdrawal. CCM19 stores your choice so it can be respected on subsequent visits.
Elfsight – Privacy policy · LinkedIn – Privacy policy
External links, fonts and analytics
Links to LinkedIn, podcasts and conference websites lead to external services. When you open those links, the respective providers’ data processing applies. Images and fonts are served locally with this website. This version does not embed Google Analytics or advertising tracking.
Storage and deletion
Personal data is processed only for as long as necessary for the relevant purpose or required by statutory retention obligations. Data that is no longer needed is deleted. For embedded external services, the provider’s privacy policy also explains applicable storage periods.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. Furthermore, should more specific legal bases be decisive in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6(1)(a) GDPR) - The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Legitimate interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. These include, in particular, the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act - BDSG). The BDSG contains special provisions on the right to access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated individual decision-making, including profiling. Furthermore, state data protection laws of the individual federal states may apply.
Security Measures
We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input, transmission, securing of availability and their separation. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the deletion of data and responses to data compromise. Furthermore, we already take the protection of personal data into account during the development or selection of hardware, software as well as procedures in accordance with the principle of data protection, through technology design and through data protection-friendly default settings.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Article 6(1)(e) or (f) GDPR, including profiling based on those provisions. Where personal data is processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw your consent at any time.
- Right of access: You have the right to request confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to that personal data and other information and a copy of the data in accordance with the legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request the completion of personal data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with the legal requirements, you have the right to demand that relevant data be erased without undue delay, or alternatively, in accordance with the legal requirements, to demand restriction of the processing of the data.
- Right to data portability: You have the right to receive personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller.
- Complaint to supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the requirements of the GDPR.
The general sections on legal bases, security measures and data subject rights were retained from the previous privacy policy. Text source: Datenschutz-Generator.de – Dr. Thomas Schwenke.