Privacy Policy
How the provider handles personal data
This privacy policy applies to all websites and services operated by Max Welhöner (hereinafter “the provider”) — including maxwel.xyz, consulting and shop sites on subdomains, and cloud and hosting services. Data processing is deliberately kept minimal: core infrastructure runs on servers in Germany, mostly using self-hosted open-source software. Data is neither sold nor used for advertising.
1. Controller
Max Welhöner, Paul-Lincke-Ufer 33, 10999 Berlin, Germany Email: mail@maxwel.xyz
No Data Protection Officer is required (sole proprietor below the threshold of § 38 BDSG).
2. What data is processed
2.1 Website visits
For reach measurement Umami is used, a privacy-friendly analytics tool running on the provider’s own server infrastructure. It collects anonymised accesses, pages viewed, referring websites, device type, and screen size. No cookies are set, no IP addresses are stored.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and statistically meaningful operation of the site).
2.2 Contact and orders
For enquiries and orders, the following data is processed:
- Name and contact details
- Content of the communication
- Billing and payment data
- Project-related information
Legal basis: Art. 6 (1) (b) GDPR (contract or pre-contractual measures).
2.3 Orders in an online shop
For shop orders, additional data is processed: billing and shipping address, email, order contents and — depending on the product — the details required for production. Payment data (card, bank account) goes directly to the payment provider (see 4.2); the provider never receives it.
Legal basis: Art. 6 (1) (b) GDPR (purchase contract) and (c) (tax retention).
2.4 Cloud and hosting services
Additional data when using cloud services:
- Username and access credentials (stored encrypted)
- Service usage data
- Content stored by the customer on the servers
Legal basis: Art. 6 (1) (b) GDPR.
2.5 Editorial research (Maxwel News, Maxwel Research)
For the news briefing and the research reports, the provider evaluates publicly accessible sources: RSS feeds of media outlets, web search, posts on X, and subscribed newsletters and press mails in the provider’s own news mailbox. This inevitably involves processing personal data — names and statements of people reported on, senders and contents of subscribed newsletters, and usernames, posts and links from X.
Only what the data subjects have published themselves, or what media have published about them, is processed. No personal profiles are created, no data from the provider’s customer or user relationships enters the research, and no research results are sold to third parties.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in reporting and public discourse). For journalistic-editorial processing, the media privilege under Art. 85 GDPR in conjunction with § 23 MStV applies in addition.
Anyone who considers themselves misrepresented in an edition, or who wants a statement concerning them removed, can write informally to mail@maxwel.xyz. Corrections are reviewed and, where justified, made in the edition concerned.
2.6 Newsletter subscription
For the newsletter, the email address and — optionally — the name are stored, together with the time and confirmation of the subscription. Subscription uses double opt-in: the address is only added after the link sent has been confirmed. Sending and administration run on Listmonk, open-source software operated by the provider on its own infrastructure (see 4.1); no external newsletter service is involved.
Legal basis: Art. 6 (1) (a) GDPR (consent). Unsubscribing is possible at any time via the link at the end of every edition or by email, with effect for the future.
3. Retention periods
- Technical logs: 7 days
- Email communication: 3 years from last contact
- Project and contract data: duration of the relationship + 6 months
- Invoice and order data: 10 years (§ 147 AO — German tax law)
- Cloud user data: until termination + 30-day export window
- Newsletter subscription data: until unsubscription; proof of subscription for a further 3 years
- Published editions of the briefing and the reports, including their intermediate research artefacts: permanently, as an archive of the reporting
4. Recipients of the data
4.1 Hosting and server infrastructure
- Hetzner Online GmbH (Gunzenhausen, Germany) — servers and hosting in German data centers
- IONOS SE (Montabaur, Germany) — cloud services and server infrastructure
Data processing agreements pursuant to Art. 28 GDPR are in place with both providers. Email dispatch (transactional, project, and support communication) runs on the provider’s own mail server within this infrastructure — no external SMTP provider is used.
4.2 Payment processing in the shop
Payments in the shop are processed by Stripe Payments Europe, Ltd. (Dublin, Ireland). Stripe offers cards, SEPA, iDEAL, PayPal, Klarna, Apple Pay, and Google Pay as payment methods. Stripe processes payment data as an independent controller for fraud prevention and card-network compliance. Stripe Tax is used to calculate VAT per delivery country; billing and shipping address are transmitted to Stripe for that purpose. Details: stripe.com/privacy.
4.3 Fulfillment partners (on-demand production)
Most shop products are manufactured only after the order and shipped directly to the customer by specialised providers. Depending on the product, name, shipping address, order contents and — for photo products — uploaded images are transmitted to one of the following partners:
- Shirtee Cloud GmbH (Cologne, Germany) — apparel
- Posterflow GmbH (Germany) — posters and wall art
- CDClick Srl (Italy) — CDs, DVDs, vinyl
- theprintspace Ltd. (London, United Kingdom) — fine art prints
Legal basis: Art. 6 (1) (b) GDPR (contract performance). Transfer to the United Kingdom is covered by the EU adequacy decision (Art. 45 GDPR).
4.4 AI models
Depending on the service and function, different AI models are used. The respective service or website page indicates which model is used and whether it is GDPR-compliant. What enters the models is the working data of the respective service — for the briefing and the reports that means publicly accessible research material only, no customer or user data.
No transfer (processing on the provider’s own hardware):
- locally operated open models — the data never leaves the provider’s infrastructure
GDPR-compliant (EU providers, data processing within the EU):
- Lyceum Technology (Berlin, Germany) — open models on EU infrastructure
Not GDPR-compliant (providers outside the EU — transfers based on Art. 46 GDPR Standard Contractual Clauses):
- Anthropic PBC (San Francisco, USA) — language models (Claude), also used directly for research and synthesis of the briefing and the reports
- OpenRouter, Inc. (San Francisco, USA) — API gateway for models including Anthropic (USA), OpenAI (USA), Google DeepMind (USA), Meta (USA), xAI (USA), Cohere (Canada), Perplexity (USA), Alibaba Cloud (China), DeepSeek (China), Moonshot AI (China), Zhipu AI (China), MiniMax (China). Current full list: openrouter.ai/models
- fal.ai, Inc. (San Francisco, USA) — generation of image, speech, music and video; behind it, depending on the function, third-party models including Google (image), ElevenLabs (speech and music) and ByteDance (video)
- Fireworks AI, Inc. (Redwood City, USA) — open models on a fast inference platform
- Groq, Inc. (Mountain View, USA) — speech recognition (speech-to-text)
- xAI Corp. (Palo Alto, USA) — language models (Grok), direct interface
- RoEx Ltd. (London, United Kingdom — adequacy decision) — audio mastering
- Direct interfaces of Chinese providers, only for content without personal data and without confidentiality requirements, transfers based on Art. 46 GDPR: DeepSeek (Hangzhou, China), Moonshot AI (Beijing, China — Kimi), Zhipu AI / Z.ai (Beijing, China — GLM)
4.5 AI agents over messaging platforms (optional)
As an optional service, the provider offers personal AI agents reachable over messaging platforms (e.g. Telegram). The user decides which model is used (see 4.4). Billing for model usage runs usage-based directly via the respective API provider; the provider only supplies the infrastructure.
4.6 Recommended external software and services
Some pages recommend external software and services. These recommendations are not part of the provider’s service. The respective provider’s privacy policy applies to their use. Non-EU providers are clearly marked as such on the recommendation pages.
4.7 Research interfaces
For research into the briefing and the reports, the provider queries third-party interfaces. What is transmitted is the search query or retrieval request, no customer or user data:
- Brave Software, Inc. (San Francisco, USA) — web search
- X Corp. (Bastrop, USA) — retrieval of public posts via the X API, including the timeline of an account operated by the provider
Transfers to the USA are based on Art. 46 GDPR (Standard Contractual Clauses). Processing on the platforms themselves is governed by their own privacy policies.
4.8 Delivery of the briefing and the reports
Published editions are freely available on the website. In addition there are two delivery channels:
- Newsletter via the self-operated Listmonk software (see 2.6) — no external sending service.
- Messenger delivery to users who have connected to the provider’s bot for that purpose. The chat identifier is stored for this; message transport runs via Telegram FZ-LLC (Dubai, United Arab Emirates), for which no adequacy decision of the EU Commission exists. Connecting is voluntary and can be ended at any time; the legal basis is Art. 6 (1) (a) and (b) GDPR.
5. Cookies and local storage
Where possible, the provider does not set cookies and generally limits itself to technically necessary cookies (e.g. cart, authentication, language). These are required for the function requested by the user and are set without separate consent.
Where cookies or comparable technologies beyond the technically necessary are used, they are only activated after consent has been given via a cookie banner (§ 25 TTDSG in conjunction with Art. 6 (1) (a) GDPR). The banner discloses purpose, services involved, and storage duration; consent can be withdrawn at any time with effect for the future.
Third-party tracking, advertising, or profiling services — in particular ad networks, cross-site pixels, and behaviour-based analytics involving personal data — are not used.
Navigation behaviour and preferences may additionally be stored in the browser’s local storage; that data never leaves the browser.
6. Data subject rights
Data subjects have the right to:
- Access the data stored about them (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure, as long as no retention obligation applies (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a commonly used format (Art. 20 GDPR)
- Objection to processing for reasons arising from the particular situation (Art. 21 GDPR)
Requests by email to mail@maxwel.xyz. Processing usually takes place within 30 days.
7. Right to lodge a complaint
Data subjects may lodge a complaint with a data protection supervisory authority at any time. The authority competent here is:
Berlin Commissioner for Data Protection and Freedom of Information Friedrichstr. 219, 10969 Berlin, Germany datenschutz-berlin.de