Skip to content
TAA

Privacy Policy

Last updated: August 2026.

1. Controller

DigitalFreedom Global LLC
30 N Gould St, Ste N
Sheridan, WY 82801
United States

Data protection contact: data-protection@digitalfreedom.co.za

2. Hosting (GitHub Pages)

This site is served by GitHub Pages (GitHub Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA). Technical connection data (IP, user agent, timestamp, requested URL) is processed when the site is requested. GitHub is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure provision of the website). Retention: per GitHub's policies, typically a few weeks.

3. Cookies and analytics (Google Analytics 4)

This site uses Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to measure aggregated, anonymised usage of the site (pages viewed, traffic sources, device categories). Google Analytics sets cookies and transfers data to Google. The connection is configured with anonymize_ip so your IP is truncated before processing.

We use Google Consent Mode v2 (Advanced) with all storage categories (analytics_storage, ad_storage, ad_user_data, ad_personalization) defaulting to denied. Before you consent, Google Analytics only sends cookieless pings (no cookies, no client ID, no precise location) which Google uses for aggregated modelling. Cookies and personalised measurement are only set once you actively accept via the cookie banner. Legal basis: Art. 6 (1) (a) GDPR (consent) and § 25 (1) TTDSG for cookies; Art. 6 (1) (f) GDPR (legitimate interest in aggregated reach measurement) for cookieless pings. You can withdraw consent at any time via "Cookie settings" in the footer; the lawfulness of processing before the withdrawal remains unaffected.

Apart from Google Analytics this site sets no cookies. Theme preference (light/dark) and your consent decision are stored only in your browser's localStorage and never transmitted to a server.

4. Booking a consultation (Cal.com)

To schedule a consultation call we embed the booking tool Cal.com (Cal.com, Inc., USA). When the booking calendar loads, its script is fetched from Cal.com's servers, which process your IP address and technical connection data. When you book an appointment you provide your name, email address, the chosen time and time zone, and any notes, used solely to arrange and confirm the appointment.

Legal basis: Art. 6 (1) (b) GDPR (measures taken at your request prior to a contract) and, for loading the embed, Art. 6 (1) (f) GDPR (legitimate interest in offering online scheduling). Data may be transferred to the USA; details are set out in Cal.com's privacy policy at cal.com/privacy. You can also simply email hello@marcelrgberger.com instead of using the calendar.

5. Fonts

We use the "Geist" font hosted locally. No data is sent to third-party font providers (e.g. Google Fonts).

6. Embedded third-party content

Apple iTunes / App Store: App icons and metadata (name, description, version, ratings) are fetched at build time from the public iTunes Lookup API and embedded statically. Icons are loaded from Apple's CDN (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA) when the page is rendered, so your browser transmits technical connection data (IP, user agent) to Apple. Legal basis: Art. 6 (1) (f) GDPR. Apple is certified under the EU-US Data Privacy Framework.

GitHub: The open-source section is fetched at build time from the public GitHub API and embedded statically. In normal operation no live data is pulled from GitHub when you load the site. Clicking a GitHub link forwards you to github.com, where GitHub's privacy notice applies.

7. Server logs

GitHub Pages logs technical connection data on every request (IP, timestamp, URL, user agent, referrer). We have no direct access to these logs; GitHub keeps them for security and operations purposes. Legal basis: Art. 6 (1) (f) GDPR.

8. International transfers

The controller is established outside the EEA. Where we process personal data of users in the EEA ourselves, that processing takes place in the United States; we apply the GDPR standard to it as a global baseline.

Transfers to the United States (GitHub, Apple, Google) take place under the EU-US Data Privacy Framework (Commission decision of 10 July 2023). A transfer to the USA also occurs when you use the Cal.com booking embed; the safeguards set out in Cal.com's privacy policy apply. Transfers within the EU (Google Ireland) take place without restrictions.

9. Retention (summary)

  • Server logs (GitHub): per GitHub's policies, typically a few weeks
  • Booking data (Cal.com): for as long as needed to arrange and follow up the appointment; details per Cal.com's privacy policy
  • Email enquiries: until the enquiry is handled, then six months for follow-up
  • Google Analytics: 14 months (default retention period for user and event data)
  • Theme preference and consent decision (localStorage): until you delete it; lives only in your browser

10. Your rights

You have the right to information (Art. 15 GDPR), rectification (Art. 16), deletion (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21). You can withdraw any consent at any time, the lawfulness of processing before the withdrawal remains unaffected.

Requests to: data-protection@digitalfreedom.co.za

11. Right to complain

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). As the controller has no establishment in the Union, the one-stop-shop mechanism under Art. 56 GDPR does not apply and there is no lead supervisory authority. Please address your complaint to the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement.

12. Data Protection Officer

A DPO has not been appointed, the controller does not meet the threshold criteria for mandatory appointment under Art. 37 GDPR / § 38 BDSG.

Book a free 30-min call