This statement informs you pursuant to Art. 13 GDPR about the processing of personal data when you visit this website.
Baltasaar Services GmbH
Gensinger Str. 14, 55457 Horrweiler, Germany
Managing Director: Christian Heinz
Email: hello@christianheinz.com
HRB 38168 (Local Court of Augsburg) · VAT ID DE346169366
This website is hosted on servers within the European Union (providers: Contabo / Hetzner, Germany). No data is transferred to third countries unless explicitly stated in this notice.
When you access this website, technically necessary data is processed: IP address (shortened), date/time, user-agent, referrer, requested URL. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). Retention: max. 14 days.
We use technically necessary cookies and localStorage entries (e.g. to store your cookie decision, language preference, and theme). Audience measurement and web analytics — both first-party (self-hosted, EU) and selected third-party providers — are used exclusively on the basis of your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG); without consent, no such measurement takes place. Providers in use, purposes, and retention periods will be added to this notice once activated. Legal basis for necessary storage: § 25(2) no. 2 TTDSG.
You can reach us by email or via the chat widget embedded in the site. For the chat widget:
Your form data (name, email, company, ROI details where applicable, message) is stored to process your request (Art. 6(1)(b) GDPR). In parallel with storage, a summary of your request is forwarded via Telegram to the team for timely handling (see section 5 on Telegram).
Retention: max. 36 months (3 years) from the last contact, after which automatic deletion follows, unless commercial or tax retention obligations apply. Every record carries an internal retention_until date; a regular sweep job removes records once they mature.
If you navigate to booking.christianheinz.com and book a slot there, your details (name, email, company, phone, message, chosen slot) are processed on a server operated by the controller within the EU. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures).
The following processors are involved in the booking flow:
christianheinz.com domain. Processes IP address and user-agent, among others, to secure the connection. Third-country transfer on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR); a Data Processing Addendum with Cloudflare is in place.Retention for booking-request data: max. 36 months from the last contact, with the same deletion mechanism as in section 6.
We process business contact data of representatives at companies that may be a fit for our services (name, role, company, business contact details, publicly available company information). This data originates from publicly accessible sources — e.g. company websites, legal notices, registers and trade directories — or from direct correspondence with you. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in initiating and maintaining B2B business relationships).
We also use AI-assisted tools to prepare and prioritise these contacts; the same safeguards as in section 5 apply: processing exclusively to handle the matter at hand, and no training of AI models with your data. Retention: max. 36 months from last contact, then automatic deletion. You may object to this processing at any time (Art. 21 GDPR) — an informal email to hello@baltasaar.com or the unsubscribe link in our messages suffices; we will then cease processing without delay.
Under GDPR you have the right to:
A plain-text email to hello@christianheinz.com is enough to exercise any of these.
No automated decision-making within the meaning of Art. 22 GDPR takes place.
This website uses end-to-end TLS encryption (HTTPS via Let's Encrypt).
Last updated: April 2026 · Imprint · Deutsche Fassung