Legal
Last updated: 6 September 2026
This privacy policy explains how Kirsten Rulf processes personal data when you visit this website, contact us by email, or subscribe to the newsletter (the “Briefing”). In this policy, “we”, “us” and “our” refer to Kirsten Rulf. It provides information in accordance with Article 13 of the EU General Data Protection Regulation (GDPR).
The controller responsible for the processing described in this policy is:
Kirsten Rulf
Chausseestraße 37
10115 Berlin, Germany
Email: office@kirstenrulf.com
This website is hosted using GitHub Pages, a static website hosting service. GitHub states that when a GitHub Pages site is visited, the visitor's IP address is logged and stored for security purposes, whether or not the visitor is signed in to GitHub. GitHub may also process technical request and usage information, such as the date and time of access, the requested page or file, browser and device information, and referring information, insofar as this is generated when the service is used.
Purpose and legal basis: The processing is necessary to deliver the website and to maintain its availability, integrity and security. It is based on our legitimate interests in operating a secure and reliable website (Article 6(1)(f) GDPR).
Recipient: The data is processed by GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA, and may also involve GitHub B.V., Prins Bernhardplein 200, 1097 JB Amsterdam, the Netherlands. GitHub processes certain data under its own responsibility in accordance with its privacy statement.
International transfers: GitHub processes data in the United States and other countries. GitHub states that it participates in the EU-U.S. Data Privacy Framework and generally uses the European Commission's Standard Contractual Clauses where required for transfers from the EEA to countries without an adequacy decision. You may contact us to request further information about the safeguards relied upon.
Retention: We do not receive or control GitHub's security logs. GitHub determines their retention according to the purpose of collection, applicable legal requirements, security needs and its contractual obligations. We do not create a separate copy of these logs.
Further information: GitHub Pages data collection and the GitHub General Privacy Statement.
You can subscribe to our Briefing, which contains information about political and economic developments relating to digital and technological sovereignty, related programmes and events, and other relevant updates.
To subscribe, you must provide your email address. You may also provide your first and last name; these name fields are optional and are used only to personalise the newsletter. We also process the date and time of registration and confirmation, the IP addresses used during those steps, subscription status, changes to the subscriber record, and technical delivery information such as bounces and unsubscribe events.
Registration uses a double opt-in procedure. After submitting the form, you receive an email asking you to confirm the subscription. The newsletter is sent only after confirmation. The confirmation email is used solely to verify the registration.
Purpose and legal basis: Your email address and any optional name information are processed to manage and send the Briefing on the basis of your consent (Article 6(1)(a) and Article 7 GDPR). Where the Briefing constitutes advertising, consent also addresses the requirements of section 7(2) no. 2 of the German Act Against Unfair Competition (UWG). The double opt-in records are processed on the basis of our legitimate interests in preventing misuse and demonstrating that valid consent was obtained (Article 6(1)(f) GDPR).
We use Kit to provide the signup form, manage subscribers and send the Briefing. Kit, Inc., 750 West Bannock Street #761, Boise, Idaho 83701-0761, USA, processes subscriber personal data on our behalf. Kit may use subprocessors in accordance with its Data Processing Addendum. For limited service-usage data processed for Kit's own legitimate business purposes, Kit states that it acts as a controller under its own privacy policy.
When the signup form is displayed or used, a technical connection to Kit may be established. Kit receives the information required to provide and secure the form, which can include the visitor's IP address, request time and browser or device information. We use this integration only to provide the subscription function and prevent misuse.
International transfers: Subscriber data may be processed in the United States and other countries. Kit states that it participates in the EU-U.S. Data Privacy Framework. Its Data Processing Addendum also incorporates the European Commission's Standard Contractual Clauses, Module 2 (controller to processor), where required. You may contact us to request further information about the safeguards relied upon.
Further information: Kit Privacy Policy and Kit Data Processing Addendum.
We do not use Kit's personalised open or click tracking and do not create profiles based on whether an individual subscriber opens the Briefing or clicks its links. Kit may still process technical delivery information needed to send messages, manage bounces, maintain security and process unsubscribe requests.
You may withdraw your newsletter consent at any time with effect for the future by using the unsubscribe link included in each Briefing or by emailing us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Subscriber data is retained while the subscription remains active. After withdrawal or unsubscribe, we stop sending the Briefing and delete subscriber profile data when it is no longer required. We may retain limited evidence of the consent and withdrawal, and the minimum information necessary to ensure that no further newsletter is sent, for up to three years after the end of the calendar year in which the subscription ended. Longer retention occurs only where necessary to comply with a legal obligation or to establish, exercise or defend legal claims. Data from an unconfirmed registration is deleted when it is no longer required to complete or document the double opt-in process or investigate misuse.
If you contact us by email, we process your email address, the content of your message, its date and time, technical message metadata, and any other information you choose to provide. Providing this information is voluntary, but we cannot respond without the information needed to understand and answer your enquiry.
Purpose and legal basis: We process the information to handle and respond to your enquiry. Where your enquiry concerns a contract or steps requested before entering into a contract, the legal basis is Article 6(1)(b) GDPR. For other correspondence, the basis is our legitimate interest in communicating with people who contact us (Article 6(1)(f) GDPR). Legal retention obligations, where applicable, are based on Article 6(1)(c) GDPR.
Recipients and retention: Our email-hosting and IT service providers may process messages on our behalf. We retain correspondence for as long as needed to answer the enquiry and deal with any follow-up. Messages are then deleted unless a legal retention duty applies or continued storage is necessary to establish, exercise or defend legal claims.
We do not use analytics or advertising cookies on this website and do not use cookies or similar technologies to create visitor profiles. The technical connections to GitHub Pages and the Kit signup form described above are limited to delivering, securing and operating the website and the subscription function requested by the visitor. To the extent that information is stored on or accessed from a visitor's device solely because it is strictly necessary to provide an expressly requested function, section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) applies.
If we introduce non-essential analytics, advertising, embedded media or comparable technologies in the future, we will update this policy and obtain consent before those technologies are activated where required.
This website contains ordinary links to LinkedIn, WhatsApp and other third-party websites. These are links, not embedded social-media plugins. No connection to the linked provider is initiated by us merely because the link is displayed. If you select a link, your browser or device connects to the relevant provider, which may receive your IP address, the date and time, device or browser information, and referring information. If you are logged in to that provider, it may associate the visit with your account. The provider is responsible for its subsequent processing under its own privacy information.
Further information: LinkedIn Privacy Policy and WhatsApp Privacy Policy.
In addition to the providers identified above, personal data may be disclosed to professional advisers, courts, public authorities or other recipients where disclosure is required by law or necessary to establish, exercise or defend legal claims. We do not sell personal data.
Where a recipient processes personal data outside the European Economic Area in a country without an adequacy decision, we use an applicable transfer mechanism, such as the European Commission's Standard Contractual Clauses, unless another lawful mechanism applies. The provider-specific mechanisms currently relied upon for GitHub and Kit are described above.
Subject to the statutory conditions, you have the following rights:
Access: to obtain confirmation as to whether we process your personal data and, if so, access to that data and the information required by Article 15 GDPR.
Rectification: to have inaccurate personal data corrected and incomplete data completed.
Erasure: to request deletion of personal data where the conditions of Article 17 GDPR are met.
Restriction: to request restriction of processing where the conditions of Article 18 GDPR are met.
Data portability: to receive data you provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, where Article 20 GDPR applies.
Withdrawal of consent: to withdraw consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal.
Where we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.
You may object at any time to the processing of personal data for direct marketing. If you object, we will no longer process your personal data for that purpose.
To exercise your rights, contact us at office@kirstenrulf.com.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. The supervisory authority responsible for a Berlin-based controller is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin, Germany
Website: www.datenschutz-berlin.de
We do not use automated decision-making, including profiling, within the meaning of Article 22 GDPR in connection with this website or the Briefing.
We may update this privacy policy when our processing activities, service providers or legal requirements change. The date shown at the beginning identifies the current version.