— Privacy
Data Protection
We take the protection of your personal data seriously. This notice explains what information we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR).
Controller
Workplace Wellbeing Solutionsc/o Klemke Services
Senckenberganlage 10–12
60325 Frankfurt
Germany
Contact: hello@workplacewellbeingsolutions.de
Responsible for data protection: Jacqueline Klemke
What data we collect and why
When you use our contact form, we collect your name, email address, company name (optional), and message. We process this data solely to respond to your inquiry and, where applicable, to prepare a proposal or consultation.
Legal basis
Processing is based on Article 6(1)(b) GDPR (pre-contractual measures at your request) and Article 6(1)(f) GDPR (legitimate interest in communicating with prospective clients). We do not use your data for automated decision-making or profiling.
Storage and retention
We retain your contact data for as long as necessary to handle your inquiry and for any subsequent business relationship, up to a maximum of three years, unless statutory retention obligations require longer storage.
Third parties and hosting
We do not sell or share your personal data with third parties for marketing purposes. Your data is stored and processed via our secure cloud infrastructure provider (Lovable Cloud) solely for the purpose of delivering our services to you.
Cookies and similar technologies
We use only what is strictly necessary to run this site by default. Non-essential cookies (analytics, marketing) are loaded only after you give consent via the cookie banner. You can change or withdraw your choice anytime via “Cookie settings” in the footer. The table below lists every cookie and similar storage item this site may set, its purpose, retention period and source.
| Name | Category | Purpose | Retention | Provider |
|---|---|---|---|---|
| wws-cookie-consent-v1 | Strictly necessary | Stores your cookie preferences so the banner is not shown again. | 12 months (local storage) | First party (this site) |
| sb-<project>-auth-token | Strictly necessary | Set only if you authenticate (e.g. for admin access). Maintains your secure session. | Session / up to 7 days (local storage) | Lovable Cloud (Supabase, EU) |
| _ga, _ga_* | Analytics (consent required) | Distinguishes users to measure site usage. Loaded only after consent. | Up to 13 months | Google Analytics, Google Ireland Ltd. |
| li_at, bcookie, lidc | Marketing (consent required) | Set if LinkedIn Insight Tag is loaded to attribute campaign visits. Loaded only after consent. | Session – 2 years | LinkedIn Ireland Unlimited Co. |
| wws-li-adsid-v1 | Marketing (consent required) | Stores the LinkedIn ad click identifier (li_adsid / li_fat_id) from the URL as a first-party value, so we can tell which LinkedIn campaign led to an enquiry. Written only after marketing consent and deleted if you withdraw it. | 90 days (local storage) | First party (this site) |
Analytics and marketing items are listed for transparency and are not active unless you opt in. If we add or change any cookie, this list and the consent banner will be updated accordingly.
LinkedIn ad attribution (li_adsid)
When you reach this site by clicking one of our LinkedIn ads, LinkedIn adds an identifier to the link address, named li_adsid (sometimes li_fat_id). It is a random campaign click reference created by LinkedIn. It does not contain your name, email address, job title or LinkedIn profile, and we cannot use it to identify you.
- Purpose: to understand which LinkedIn campaign brought a visitor to the site and whether that visit led to a meaningful action, such as starting the wellbeing maturity check or sending an enquiry. This is campaign measurement only: we do not use it for profiling, automated decision-making or advertising to you personally.
- Consent: the identifier is only read and stored if you accept marketing cookies. Without that consent it is ignored entirely, and if you later withdraw consent via “Cookie settings” the stored value is deleted from your browser immediately and no longer sent with any event.
- Where it is stored: as a first-party value in your browser's local storage under wws-li-adsid-v1, and alongside consented analytics events in our own database in the EU. It is not shared with LinkedIn or any other third party.
- Retention: the value stored in your browser expires after 90 days from the ad click, after which it is discarded and a new click starts a fresh 90-day window. The identifier recorded with analytics events in our database is kept for a maximum of 12 months and then deleted.
- Legal basis: your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG, which you can withdraw at any time with effect for the future.
You can clear the identifier yourself at any time by rejecting marketing cookies, or by clearing site data for this domain in your browser settings.
Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing and to lodge a complaint with a supervisory authority.
To exercise your rights, please contact us at hello@workplacewellbeingsolutions.de.
Data security
We apply appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.
Right to complain
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In Hesse, this is the Hessian Data Protection Commissioner (Hessischer Datenschutzbeauftragter).