Privacy Policy

1. Controller

The controller responsible for data processing on this website is:

Susanne Madee
UNDERCOVER AGENTS (Sole Proprietorship)
Sonnenblumenstr. 36a
81377 München
Germany

Email: [email protected]
Phone: +49 172 737 04 03

The appointment of a data protection officer is not required.

2. General Information and Mandatory Disclosures

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

The use of our website is generally possible without providing personal data. The provision of personal data is neither legally nor contractually required. However, without the transmission of your IP address, it is not possible to access the website.

SSL/TLS Encryption

This site uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognise an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar.

3. Hosting and Server Log Files

This website runs on the DigitalOcean App Platform. The server location is the Frankfurt am Main data centre (region FRA1), so access data is processed within the European Union.

DigitalOcean, LLC
105 Edgeview Drive, Ste. 425
Broomfield, CO 80021, USA
Website: digitalocean.com

Content delivery network (CDN): A CDN sits in front of the App Platform, which DigitalOcean has Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) provide as a sub-processor. Content may therefore be served from a location outside the European Union. The full list of sub-processors used by DigitalOcean is available at: digitalocean.com/trust/subprocessors.

When you access our website, DigitalOcean automatically collects information in so-called server log files that your browser automatically transmits. These are:

  • IP address of the requesting computer
  • Date and time of the request
  • Name and URL of the retrieved file
  • HTTP status code
  • Amount of data transferred
  • Browser type and browser version
  • Operating system used
  • Referrer URL (the previously visited page)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in the technically error-free provision and optimisation of the website and ensuring system security.

Storage duration: According to the provider, access logs are retained only for the duration of technical processing. We have not set up any permanent storage of this log data, nor any forwarding of it to an external service. Logs covering the building and publishing of the website (build and deploy logs) are retained by DigitalOcean for 90 days and then deleted.

Data processing agreement: A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with DigitalOcean. It forms an integral part of the terms of service and therefore applies without separate execution. Details can be found at: digitalocean.com/legal/data-processing-agreement.

4. Transfer to Third Countries

The website is operated in the Frankfurt am Main data centre, so access data is generally processed within the European Union. As DigitalOcean, LLC and Cloudflare, Inc. are both based in the USA, a transfer of personal data (in particular IP addresses) to the USA cannot be ruled out. It may occur in particular when content is served from a CDN location outside the EU, and during maintenance, administration and support access.

The transfer is based on the adequacy decision of the EU Commission pursuant to Art. 45 GDPR (EU-US Data Privacy Framework). Both DigitalOcean, LLC and Cloudflare, Inc. are certified under the EU-US Data Privacy Framework (DPF). You can verify the certification status at dataprivacyframework.gov.

In addition, the data processing agreement with DigitalOcean provides for the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. These apply where a transfer cannot be based on the adequacy decision.

5. Contact via Email and Phone

If you contact us by email or phone, your enquiry including all resulting personal data (name, email address, phone number, content of the enquiry) will be stored and processed by us for the purpose of handling your request.

Note: This website does not contain a contact form. The email and phone contact details provided on the website open your own email client or phone application. Processing only occurs when you actually contact us.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to your enquiry).

Storage duration: Your data will be deleted once your enquiry has been conclusively processed, unless statutory retention obligations apply (e.g. commercial or tax law retention periods of 6 or 10 years).

6. Cookies and Local Storage

This website does not use cookies or analytics tools. No tracking takes place.

No data is stored in your browser's local storage or session storage.

The fonts used on this website are served locally from our own server. No connections are made to external font providers (such as Google Fonts).

7. Your Rights as a Data Subject

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR) – You have the right to request information about your personal data processed by us.
  • Right to rectification (Art. 16 GDPR) – You have the right to request the correction of inaccurate or the completion of your personal data stored by us.
  • Right to erasure (Art. 17 GDPR) – You have the right to request the deletion of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression, for fulfilling a legal obligation, or for reasons of public interest.
  • Right to restriction of processing (Art. 18 GDPR) – You have the right to request the restriction of processing of your personal data.
  • Right to data portability (Art. 20 GDPR) – You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to object (Art. 21 GDPR) – You have the right to object at any time to the processing of your personal data based on Art. 6(1)(f) GDPR. We will then no longer process the personal data unless there are demonstrably compelling legitimate grounds.

To exercise your rights, you can contact us at any time using the contact details provided above.

Note: Since no consent-based data processing takes place on this website, there is no right of withdrawal pursuant to Art. 7(3) GDPR.

8. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR.

The supervisory authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany

Phone: +49 981 180093-0
Email: [email protected]
Website: www.lda.bayern.de

9. Validity and Amendment of this Privacy Policy

This privacy policy is currently valid and dated March 2026.

Due to the further development of our website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed at any time on this page.