Dr. Rebecca

EN

Privacy Policy

Information about how personal data is processed when you visit this website.

1. General information

The following provides a concise overview of how your personal data is processed when you visit this website. Personal data is any information that can be used to identify you directly or indirectly.

2. Controller

The controller responsible for processing data on this website is:

Dr. Rebecca Belvederesi-Kochs
Maxstr. 1
52070 Aachen
Germany
Email: dr.rebecca@belvederesi-kochs.de

3. Hosting

This website is hosted by ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. When you access the website, the hosting provider processes technically necessary connection data so that the content can be delivered securely and reliably.

This processing is based on Article 6(1)(f) GDPR. The legitimate interest is the stable, secure and efficient provision of this website. A data processing agreement pursuant to Article 28 GDPR has been concluded with the hosting provider. For further information, please refer to the privacy information provided by ALL-INKL.COM.

4. SSL and TLS encryption

This website uses SSL or TLS encryption for security reasons. You can recognise an encrypted connection by the “https://” prefix in your browser’s address bar. This helps prevent data transmitted to this website from being read by third parties.

5. Server log files

When you access the website, the hosting provider automatically records information transmitted by your browser. This may include:

  • browser type and version
  • operating system
  • referrer URL
  • host name of the accessing device
  • date and time of the server request
  • IP address
  • requested file, access status and amount of data transferred

This data is processed to provide the website technically, diagnose errors and maintain security. The website operator does not combine it with other data sources or evaluate it for advertising purposes. The legal basis is Article 6(1)(f) GDPR.

6. Local, privacy-friendly audience measurement

This website does not use external analytics or tracking services and does not use cookies for advertising, audience measurement or profiling. Page views are counted only in the local website database. The IP address and browser identifier are processed only temporarily to create a daily-changing hash; the source data is not stored. Do Not Track is respected. Statistics are deleted after 90 days. The legal basis is Art. 6(1)(f) GDPR.

The public website does not set cookies and does not start a PHP session. Only the access-protected administration area under /webadmin/ uses a technically necessary session cookie for authentication and security. This cookie is restricted to the administration path. Drafts and settings may also be stored locally in the browser using LocalStorage within that area. Neither mechanism is used for tracking, advertising or analytics.

Where information is stored on or accessed from your device, this is done only where necessary to provide a service you have expressly requested. The legal basis is section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG); subsequent processing is based on Article 6(1)(f) GDPR.

7. Substack

This website contains links to the newsletter hosted by the Substack service. Substack is not embedded directly into this website. No connection to Substack is established by this website unless you click a corresponding link.

When you open a Substack link, you leave this website. Substack may then process your IP address as well as device and usage data. If you subscribe to the newsletter, your email address, subscription status and any other information you provide will also be processed. The website operator can access this subscription data within her Substack publication and use it to provide the newsletter. The legal basis is your consent pursuant to Article 6(1)(a) GDPR or, for a paid offering, Article 6(1)(b) GDPR. You can unsubscribe at any time using the unsubscribe link included in every issue.

Substack is a service provided by Substack Inc., based in the United States. Processing outside the European Union or European Economic Area therefore cannot be ruled out. For further information about processing and the safeguards used by Substack, please refer to Substack’s privacy policy.

8. Contact by email

If you contact us by email, the information you provide, including your contact details and the content of your message, will be processed to handle your request and answer any follow-up questions. It will not be disclosed without your consent unless there is a legal obligation to do so.

Processing is based on Article 6(1)(b) GDPR where your request relates to a contract or pre-contractual measures. In all other cases, it is based on Article 6(1)(f) GDPR. The legitimate interest is the proper handling of your request. The data will be deleted once it is no longer required for this purpose and no statutory retention obligations apply.

9. Your rights

Subject to the applicable statutory requirements, you have in particular the following rights:

  • access to your stored personal data (Article 15 GDPR)
  • rectification of inaccurate data (Article 16 GDPR)
  • erasure of your data (Article 17 GDPR)
  • data portability where the statutory requirements are met (Article 20 GDPR)
  • objection to processing (Article 21 GDPR)
  • withdrawal of consent with effect for the future
  • the right to lodge a complaint with a data protection supervisory authority

To exercise your rights, an informal message to the email address given above is sufficient.

Last updated: July 2026