Legal
Privacy Policy
This is a translation for information purposes. The German version is legally binding: Datenschutzerklärung (Deutsch)
1) What this policy is about
1.1 This policy explains which personal data HumanITy GmbH processes on gainautonomy.com, for what purpose, on what legal basis and what rights you have. Personal data is any information that can be related to you as a person, such as your name, your email address, your IP address or the content of a message to us.
1.2 Gain Autonomy and the Owner Autonomy program are offered by HumanITy GmbH. This policy applies to the website gainautonomy.com, to which www.gainautonomy.com also redirects, to enquiries you submit through the form on this website and to calls you book through it. For our other websites, our communities on Skool and our social media profiles, the privacy policy of HumanITy GmbH at https://humanity-it.com/datenschutz applies. If you are a customer of one of our programs, it applies in addition to this policy.
2) Who is responsible for the processing
2.1 The controller within the meaning of the General Data Protection Regulation (GDPR) is HumanITy GmbH, Brunnenstraße 8a, 66957 Trulben, Germany, represented by its managing directors Fabian Schaub and Kevin Welter. You can reach us by email at support@humanity-it.com or by phone at 01755291394.
2.2 For all questions about data protection and to exercise your rights, an informal message to support@humanity-it.com is sufficient.
3) What applies to all of the following sections
3.1 We only process your data if a legal basis permits it. In each section we state which one applies. The main legal bases are:
- your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future,
- the performance of a contract with you or steps prior to entering into a contract that you have requested (Art. 6(1)(b) GDPR),
- a legal obligation to which we are subject, such as retention obligations under commercial and tax law (Art. 6(1)(c) GDPR),
- our legitimate interest, which we name in the respective section and which must not be overridden by your interests (Art. 6(1)(f) GDPR).
3.2 Under Section 25(1) TDDDG, we may in principle only store information on your device or access information stored there, for example via cookies, with your consent. This does not apply to what is strictly necessary for a service you have explicitly requested (Section 25(2) No. 2 TDDDG).
3.3 We use external service providers for some tasks. Where they process data on our behalf, we contractually oblige them under Art. 28 GDPR to use the data only in accordance with our instructions. Providers that process data as controllers in their own right are identified as such in the respective sections.
3.4 Some providers are based in the USA or transfer data there. If the provider is certified under the EU-US Data Privacy Framework, the transfer is based on the adequacy decision of the European Commission of 10 July 2023. Otherwise, it is based on the Standard Contractual Clauses of the European Commission (Art. 46(2)(c) GDPR). Which of these applies to which provider is stated in the respective section.
3.5 We do not make automated individual decisions, including profiling within the meaning of Art. 22 GDPR, that produce legal effects concerning you.
3.6 You are under no legal or contractual obligation to provide us with data. Without certain information, such as your name and your email address, we cannot answer an enquiry or arrange an appointment, however.
4) Hosting, servers and technology of this website
Hosting
4.1 This website runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in data centres in Germany and Finland, in other words within the EU. Hetzner processes the data as our processor.
4.2 When you access the website, your browser transmits data to the server for technical reasons. The server logs:
- the page or file accessed and the time of access,
- the amount of data transferred and whether the access was successful,
- the page you came from, if your browser transmits it,
- browser type, browser version and operating system,
- your IP address.
We need this data to deliver the pages, find errors and fend off attacks. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in secure and stable operation. We do not evaluate the logs to identify visitors, and we delete them as soon as they are no longer needed for these purposes.
4.3 All connections to this website are encrypted with TLS. You can recognise this by “https://” in the address bar of your browser.
Domains
4.4 We manage the domain gainautonomy.com with ALL-INKL.COM, Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The DNS records pointing to our servers at Hetzner are kept there. The redirect from www.gainautonomy.com to gainautonomy.com is handled by our own servers (see 4.1).
Cookies and local storage
4.5 Without your consent, this website does not set any cookies that are not strictly necessary. Advertising and measurement services that set cookies or read information from your browser are only loaded once you have agreed in the consent banner. Section 6 explains which services these are and how to change your choice. The only things stored without consent, because they are strictly necessary, are your choice in the banner (see 6.2) and, after the short check, your details for booking a call until you close the tab (see 7.4).
Fonts and images
4.6 We deliver fonts and images from our own server. No connection to Google or any other provider is established for this when a page is loaded.
Links to other websites
4.7 This website contains links, for example to kevinwelter.com including our community page, to our community on Skool and to the booking service for calls (see 7.4). As long as you do not click on them, no data is transferred to these providers. After the click, the privacy policy of the respective provider applies. Links to Skool carry campaign information (UTM parameters) that shows us in our community statistics that a visit came from this website.
5) Audience measurement with Umami
5.1 On this website we use the open source software Umami to find out how many people visit our pages and which pages are read. Umami also counts these events:
- clicks on the “Book a call” button (“gespraech-klick”, with the position on the page),
- starting the short check on the inbox page (“formular-start”),
- submitting the short check (“formular-abgesendet”), with your selected answers for industry and team size and the version of the page, never with your name or email address,
- clicks on the booking button after the short check (“calendly-klick”),
- clicks on links to our community on Skool (“community-klick”),
- clicks on the link to the inbox page on the home page (“posteingang-klick”).
We operate Umami ourselves on our servers at Hetzner (see 4.1). The data is not passed on to third parties.
5.2 Umami does not set cookies and does not store any information on your device. Your IP address is not stored. To group repeat visits within one day, Umami creates a check value from your IP address, your browser identifier and a random value that changes daily. This check value cannot be traced back to you, and its assignment expires after 24 hours at the latest. Umami also stores the page accessed including campaign information in the address (UTM parameters, such as which ad you came from), the referring page, browser type, operating system, device type, screen size, language and the country, region and city, which are derived from the IP address and then stored without the IP address. Umami never records the name or email address from the short check; the only form data it receives are the selected answers listed in 5.1.
5.3 The processing is based on Art. 6(1)(f) GDPR, on the basis of our legitimate interest in privacy-friendly audience measurement. As no information is stored on or read from your device, no consent under Section 25 TDDDG is required. You can object to the processing by disabling JavaScript in your browser or by using an ad blocker; the website remains fully usable.
6) Consent, Meta Pixel and Hyros
Consent banner
6.1 For the services in this section, we ask for your consent in a banner on your first visit. You can accept all of them, allow only the necessary ones or choose each service individually under “Settings”. Before you agree, none of these services is loaded and no connection to their providers is established. We run the banner ourselves, without an external provider.
6.2 We store your choice in your browser's local storage under the entry “ga-einwilligung”: which services you have allowed, the time and the version of the banner. This is strictly necessary so that we can respect your decision (Section 25(2) No. 2 TDDDG). The legal basis is Art. 6(1)(c) in conjunction with Art. 7(1) GDPR, because we must be able to demonstrate whether and for what you have consented. We also have a legitimate interest in not asking you again on every visit (Art. 6(1)(f) GDPR). The entry remains until you delete it in your browser. If we use new services or their purpose changes, we will ask you again.
Withdrawal
6.3 You can withdraw or change your consent at any time with effect for the future via the “Cookie settings” link at the bottom of every page. If you withdraw consent, we delete the service's cookies, as far as they are stored on our domain, and reload the page so that the service stops running. This does not affect the lawfulness of processing before the withdrawal (Art. 7(3) GDPR).
Meta Pixel
6.4 With your consent, we use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”). It lets us measure whether people come to this website via our ads on Facebook and Instagram and whether they then submit the short check, and it allows Meta to show our ads to people who are likely to be interested. We also use Meta to group visitors of this website who have consented into audiences, so that we can show them our ads again later on Facebook and Instagram (retargeting). For this, your browser loads a script from Meta and transmits to Meta the page accessed with its address, the referring page, your IP address, information about your browser and device, the time and the events “PageView” and, after you submit the short check, “Lead”. The pixel sets the cookie “_fbp” and, if you come via an ad, the cookie “_fbc”, each with a lifetime of 90 days. If you are logged in to Facebook or Instagram, Meta can link the data to your account. We do not pass the content of the form, that is your name, email address and other details, on to Meta.
6.5 The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). We are jointly responsible with Meta for collecting the data on this website and transmitting it to Meta (Art. 26 GDPR). This is based on Meta's Controller Addendum at https://www.facebook.com/legal/controller_addendum. Under it, Meta provides the information required by Art. 13 and 14 GDPR about its own processing and handles your rights; you can, however, exercise your rights against both us and Meta. Meta alone is responsible for any further processing after the transmission. How Meta processes data is described at https://www.facebook.com/privacy/policy.
6.6 Meta may transfer data to Meta Platforms, Inc. in the USA. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework (see 3.4). Meta determines on its own responsibility how long it stores the transmitted data.
Hyros
6.7 With your consent, we use Hyros, a service of Hyros, Inc., 13359 N Highway 183, Ste 406 #2008, Austin, TX 78750, USA. Hyros attributes visits, enquiries and bookings to the ad a visitor came from (attribution), so that we can see which advertising leads to enquiries. For this, your browser loads a script from Hyros and transmits the page accessed with its address including campaign information (UTM parameters), the previous and the referring page, your IP address, a session identifier, information about your browser and device and the time. Hyros stores identifiers in cookies and in your browser's local storage for this purpose and, where present, reads the Meta Pixel cookies (“_fbp”, “_fbc”). [PRÜFEN: names and lifetime of the Hyros cookies and storage entries. Hyros sets none on localhost; can only be read on the preview at gainautonomy.com]
Hyros and forms
6.8 To attribute an enquiry to the ad you came from (lead attribution), the Hyros script also reads information you enter in forms on this website: email addresses as soon as you leave the field, even if you do not submit the form afterwards, and fields for name, phone and address. In the short check on the inbox page, these are only your first name and your email address; we have blocked the other fields (industry, team size, letters per week) for Hyros. This only happens if you have allowed Hyros in the consent banner; without this consent, the script is not loaded. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).
6.9 Hyros processes the data as our processor (Art. 28 GDPR). [PRÜFEN: data processing agreement with Hyros concluded (available in the Hyros Trust Center on request only)] The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). The data is processed in the USA. Hyros, Inc. is certified under the EU-US Data Privacy Framework, so the transfer is based on the adequacy decision (see 3.4). We delete the data at Hyros as soon as we no longer need it to attribute our advertising, at the latest 12 months after it was collected.
7) When you contact us
Email and phone
7.1 If you send us an email or call us, we process your contact details and the content of your enquiry in order to answer it. If it concerns a contract or its initiation, the legal basis is Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR, our interest in answering enquiries. We manage our emails with Microsoft 365 from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. This may involve transfers to Microsoft Corporation in the USA; Microsoft is certified under the EU-US Data Privacy Framework.
Short check on the inbox page
7.2 On our inbox page you can submit a short check. We process your first name, your email address, your industry, the size of your team and, if you provide it, the approximate number of letters per week. With the form we also transmit which version of the page you saw and which campaign you came from (UTM parameters from the address). We use the information to answer your enquiry, contact you and prepare a call. If you have allowed Hyros in the banner, Hyros reads your first name and email address while you fill in the form in order to attribute the enquiry to an ad (see 6.8). The legal basis is Art. 6(1)(b) GDPR, because you ask us to take these steps before a possible contract. We evaluate the campaign information to see which advertising leads to enquiries; the legal basis for this is Art. 6(1)(f) GDPR, our legitimate interest in effective advertising.
7.3 We store the information from the short check in our own database on our servers at Hetzner (see 4.1). For every new short check we receive a notification email containing your information. We send this email via the mail server of our provider ALL-INKL.COM, Neue Medien Münnich (address see 4.4), which acts as our processor for this purpose (Art. 28 GDPR); it arrives in our mailbox (see 7.1). Beyond that we do not pass the information on; for Hyros and Calendly see 6.8 and 7.4. If no contract results from your enquiry, we delete it 12 months after the last contact, including the notification email; otherwise section 9 applies. We back up the database daily to storage of Hetzner Online GmbH in Germany; deleted information disappears from these backups after 30 days at the latest.
Booking a call
7.4 You can book appointments for calls via Calendly, a service of Calendly LLC, 115 E Main St, Ste A1B, Buford, GA 30518, USA. We do not embed the calendar on this website. Calendly's website only opens when you click a booking button, after the short check in a new tab. So that you do not have to type anything twice, we keep your name, your email address and the campaign information from the short check in your browser's session storage until you close the tab and pass them on to Calendly when you click, so that the booking form is already filled in. When you book, Calendly processes your name, your email address, the selected appointment and the information you enter in the booking form, and passes it on to us. The legal basis is Art. 6(1)(b) GDPR. Calendly is certified under the EU-US Data Privacy Framework.
Video calls
7.5 We hold calls by video conference using Zoom from Zoom Communications, Inc., 55 Almaden Blvd, Suite 600, San Jose, CA 95113, USA, or using Microsoft Teams from Microsoft Ireland Operations Limited (address see 7.1). The data processed includes your display name, your email address where applicable, image and sound if you switch on your camera and microphone, chat messages and technical connection data such as IP address and time. The legal basis is Art. 6(1)(b) GDPR if the call prepares a contract or is part of one, otherwise Art. 6(1)(f) GDPR, our interest in simple communication over a distance. Both providers are certified under the EU-US Data Privacy Framework.
AI assistants
7.6 We work with AI assistants based on Claude from Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland. Personal data may also be processed in this context, for example when we draft replies to enquiries or prepare a call. The AI supports us in preparation; we ourselves review and take responsibility for what goes out and what is decided. The use of our content to train the models is excluded. Anthropic may transfer data to Anthropic PBC in the USA. The legal basis is the legal basis of the respective processing that the AI serves, and in addition Art. 6(1)(f) GDPR, our interest in working efficiently.
8) When you take part in the program
8.1 For the program's community on Skool, for calls, invoices and accounting, the privacy policy of HumanITy GmbH at https://humanity-it.com/datenschutz applies. If we process personal data of your company on your behalf within the program, we govern this in a data processing agreement under Art. 28 GDPR.
9) How long we store data
9.1 We only store personal data for as long as is necessary for the respective purpose. In detail:
- data based on consent, until you withdraw your consent,
- data based on a legitimate interest, until you effectively object or the purpose no longer applies,
- contract data until the end of the contractual relationship and thereafter for as long as claims arising from it can become time-barred, usually three years from the end of the year,
- invoices, accounting records and business correspondence for as long as commercial and tax law requires, six, eight or ten years depending on the type of document.
If a purpose no longer applies and there is no retention obligation, we delete the data.
10) Your rights
10.1 You have the right
- to obtain information about the data we process about you (Art. 15 GDPR),
- to have inaccurate data rectified and incomplete data completed (Art. 16 GDPR),
- to request the erasure of your data, unless there is an obligation to retain it (Art. 17 GDPR),
- to have the processing restricted (Art. 18 GDPR),
- to receive the data you have provided to us in a commonly used, machine-readable format or to have it transmitted to another controller (Art. 20 GDPR),
- to withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
An informal message to support@humanity-it.com is sufficient.
10.2 You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), Hintere Bleiche 34, 55116 Mainz, Germany.
Your right to object
10.3 If we process your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object to this processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
10.4 If we use your data for direct marketing, you can object to this at any time without giving reasons (Art. 21(2) GDPR). We will then no longer use your data for this purpose.
11) Changes to this policy
11.1 If our offerings, the services we use or the legal situation change, we will adapt this policy. The version published here applies.
As of: 7 October 2026