
PRIVACY POLICY
Effective date: July 30, 2026
LANGUAGE NOTICE
This English version is provided for international and U.S. visitors. The website is operated from Germany. The processing of personal data described in this Privacy Policy is primarily governed by the General Data Protection Regulation (GDPR) and applicable German law. In the event of any inconsistency between this English version and the German version, the German version shall prevail.
1. SCOPE
The protection of your personal data is important to me. This Privacy Policy explains which personal data is processed when you visit my websites and landing pages or use the functions offered through them, and for which purposes such processing takes place.
This Privacy Policy applies to:
– all content available under the domain nativeads.info;
– landing pages and interactive forms operated by me on the Heyflow platform, where this Privacy Policy is referenced; and
– the redirection from these pages to external services, in particular Calendly.
External websites and services are additionally subject to the privacy notices of their respective providers.
2. DATA CONTROLLER
The controller responsible for the processing of personal data within the meaning of the GDPR is:
Patrick Coyle
Baldurstr. 21
90461 Nuremberg
Germany
Email: mail@patrickcoyle.de
Telephone: +49 155 60389790
3. GENERAL INFORMATION ON LEGAL BASES
Personal data is processed only where a lawful basis exists. Depending on the processing activity, the following legal bases may apply in particular:
– Article 6(1)(a) GDPR: consent;
– Article 6(1)(b) GDPR: performance of a contract or steps taken at your request prior to entering into a contract;
– Article 6(1)(c) GDPR: compliance with a legal obligation; and
– Article 6(1)(f) GDPR: legitimate interests, in particular the secure and economically efficient operation of the website, the handling of business inquiries, and protection against misuse.
Where information is stored on your terminal device or information already stored on your terminal device is accessed, Section 25 of the German Telecommunications-Digital-Services Data Protection Act (TDDDG) also applies. Cookies and comparable technologies that are not strictly necessary are used only after prior consent.
4. WEBSITE ACCESS AND SERVER LOG FILES
When you access the websites or landing pages, the hosting and platform providers used may automatically process technical connection data. This may include in particular:
– IP address;
– date and time of access;
– page or file accessed;
– referrer URL;
– browser type and browser version;
– operating system and device type;
– language settings;
– amount of data transferred;
– HTTP status code; and
– technical error and security information.
This processing is necessary to provide the pages technically, ensure their stability and security, detect attacks and misuse, and analyze technical errors.
The legal basis is Article 6(1)(f) GDPR. To the extent strictly necessary information is stored on or accessed from your terminal device, this is based on Section 25(2)(2) TDDDG.
The data is deleted or anonymized once it is no longer required for the stated purposes, unless statutory retention obligations or legitimate security interests require longer storage.
5. HOSTING OF THE MAIN WEBSITE BY WIX
The main website at patrickcoyle.de is hosted by Wix.
Provider:
Wix.com Ltd.
5 Yunitsman Street
Tel Aviv
Israel
EU representative:
Wix Online Platforms Limited
1 Grant’s Row
Dublin 2, D02HX96
Ireland
Wix provides hosting, infrastructure, security, analytics, and cookie-management functions. In this context, the technical data listed in Section 4 and, depending on the functions used on the website, additional usage and interaction data may be processed.
Wix generally processes personal data on my behalf as a processor. The processing is governed by a data processing agreement pursuant to Article 28 GDPR.
The legal basis for using Wix is Article 6(1)(f) GDPR. My legitimate interest is the secure, stable, and user-friendly provision of the website.
Wix is based in Israel. The European Commission has adopted an adequacy decision for Israel. Wix may also use affiliated companies and service providers in other countries, particularly the United States. According to Wix, such transfers are based on appropriate safeguards, including adequacy decisions, the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses.
Further information is available in Wix’s privacy policy:
https://www.wix.com/about/privacy
6. LANDING PAGES AND FORMS PROVIDED THROUGH HEYFLOW
I use Heyflow to create and provide interactive landing pages and forms.
Provider:
Heyflow GmbH
Jungfernstieg 49
20354 Hamburg
Germany
Heyflow enables the provision of interactive flows, the collection of selections and form entries, and the technical evaluation of how a flow is used.
When a Heyflow landing page is accessed, the technical data described in Section 4 and information about the use of and progress through the flow may be processed.
Depending on the design of the relevant flow, data that you actively submit through a selection or entry may also be processed. This may include confirmation that your business meets certain eligibility requirements for an introductory call.
The processing is carried out to provide the landing page technically, handle inquiries, assess whether the requirements for an introductory call are met, and prepare a possible business relationship.
The legal basis is Article 6(1)(b) GDPR where the processing is carried out at your request in preparation for a possible business relationship. In all other cases, the processing is based on Article 6(1)(f) GDPR. My legitimate interest is the efficient handling of business inquiries and the user-friendly organization of introductory calls.
Heyflow processes personal data on my behalf as a processor. The processing is governed by a data processing agreement pursuant to Article 28 GDPR. Heyflow may use contractually bound subprocessors.
According to Heyflow, customer data is hosted and processed in Europe. Heyflow uses infrastructure provided by Google Cloud Platform, among others.
Personal inquiry data collected through Heyflow is generally deleted by me no later than six months after the inquiry is concluded if no business relationship is established and no statutory retention obligation or legitimate interest requires longer storage. If a business relationship is established, the necessary data is retained in accordance with applicable statutory retention periods.
Further information is available in Heyflow’s privacy information:
https://heyflow.com/legal/data-privacy/
7. REDIRECTION FROM HEYFLOW TO CALENDLY
After completing the Heyflow flow, you may use a link to open an external Calendly booking page. Calendly is opened only when you click the relevant link or button.
If no information is included in the destination URL and no booking fields are pre-populated, merely displaying the link does not automatically transfer your entries from Heyflow to Calendly.
The processing of data by Calendly is described in Section 11.
8. COOKIES AND CONSENT MANAGEMENT
Cookies, local storage, and comparable technologies may be used on the websites. Cookies are small data records that are stored on or accessed from your terminal device.
Strictly necessary technologies are used where required to provide a digital service expressly requested by you. The legal basis for access to your terminal device is Section 25(2)(2) TDDDG. The related processing of personal data is generally based on Article 6(1)(f) GDPR.
Technologies that are not strictly necessary, in particular technologies used for analytics, conversion measurement, remarketing, or advertising, are used only after your prior consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.
Consent decisions are recorded. The processing of consent records is necessary to comply with data protection accountability requirements and is based on Article 6(1)(c) GDPR in conjunction with Articles 5(2) and 7(1) GDPR.
You may withdraw or change your consent at any time with effect for the future through the cookie settings available on the relevant website. The lawfulness of processing carried out before the withdrawal remains unaffected.
9. META PIXEL
Where you have provided consent through the consent-management system, the Meta Pixel is used on the relevant pages.
Provider for users in the European Economic Area:
Meta Platforms Ireland Limited
Block J, Serpentine Avenue
Dublin 4
Ireland
The Meta Pixel is used in particular for:
– measuring page views and conversions;
– attributing actions to advertising campaigns;
– optimizing advertising campaigns;
– creating audiences;
– remarketing; and
– displaying interest-based advertising.
The following data may be processed in particular:
– pages visited;
– time and type of interaction;
– referrer URL;
– IP address;
– browser and device information;
– cookie and device identifiers; and
– campaign and conversion data.
The data may be linked to an existing Meta account and processed by Meta in accordance with its own privacy terms.
For the collection and transmission of certain event data to Meta, Meta Platforms Ireland Limited and I may be joint controllers within the meaning of Article 26 GDPR. The allocation of data protection responsibilities is governed by Meta’s Joint Controller Addendum. Meta is generally independently responsible for subsequent processing of the data.
The legal bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. The Meta Pixel is not activated before you have provided consent.
Meta may transfer data to the United States and other countries outside the European Economic Area. According to Meta, such transfers are based in particular on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses approved by the European Commission.
You may withdraw your consent at any time with effect for the future through the cookie settings on this website.
Further information:
Meta Privacy Policy:
https://www.facebook.com/privacy/policy/
Joint Controller Addendum:
https://www.facebook.com/legal/controller_addendum
Meta ad preferences:
https://www.facebook.com/adpreferences/ad_settings
10. REDDIT PIXEL
Where you have provided consent through the consent-management system, the Reddit Pixel is used on the relevant pages.
Provider or contact entity for users in the European Economic Area:
Reddit Netherlands B.V.
Euro Business Center
Looiersgracht 43
1016 VR Amsterdam
The Netherlands
The Reddit Pixel is used in particular for:
– measuring page views and conversions;
– attributing actions to Reddit advertising campaigns;
– analyzing and optimizing advertising campaigns;
– creating audiences; and
– remarketing.
The following data may be processed in particular:
– pages visited;
– event and conversion data;
– referrer URL;
– IP address;
– browser and device information;
– cookie and device identifiers; and
– timestamps and interactions.
Reddit may combine this information with other data available to Reddit and process it for measurement, security, analytics, and advertising purposes in accordance with its own privacy terms.
The legal bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. The Reddit Pixel is not activated before you have provided consent.
Reddit processes and stores data in the United States and may transfer data to affiliated companies and service providers in other countries. According to Reddit, transfers from the European Economic Area are based on appropriate safeguards, in particular adequacy decisions and Standard Contractual Clauses. Reddit, Inc. also states that it is certified under the EU-U.S. Data Privacy Framework.
You may withdraw your consent at any time with effect for the future through the cookie settings on this website.
Further information:
Reddit Privacy Policy:
https://www.reddit.com/policies/privacy-policy
Reddit privacy settings:
https://www.reddit.com/settings/privacy
11. EXTERNAL APPOINTMENT BOOKING THROUGH CALENDLY
I use Calendly to arrange free introductory calls. The Calendly booking page is not embedded in the Heyflow landing page but is opened through an external link.
The service is provided by Calendly, LLC and affiliated companies. Privacy contact:
Calendly, Inc.
Attn: Privacy Department
115 E Main St., Suite A1B
Buford, GA 30518
United States
EU representative:
DPO Centre Europe
Friedrichstraße 88
10117 Berlin
Germany
Email address of the EU representative:
eurep@calendly.com
When the Calendly page is accessed, the following technical data may be processed in particular:
– IP address;
– date and time;
– browser and operating system;
– device information;
– referrer URL;
– time zone;
– approximate location information; and
– cookie and usage data.
When you book an appointment, the information you enter is processed. Depending on the configuration, this may include:
– first and last name;
– email address;
– telephone number;
– company;
– professional role;
– selected appointment time;
– time zone;
– answers to booking questions; and
– voluntary information and messages.
The data is processed to display available appointments, enable the booking, manage the appointment, send confirmations and reminders, and prepare for and conduct the call.
The legal basis is Article 6(1)(b) GDPR where the booking is made at your request for the purpose of taking steps prior to entering into a possible contract. In all other cases, the processing is based on Article 6(1)(f) GDPR. My legitimate interest is the efficient organization and conduct of appointments.
Calendly generally processes appointment and participant data as a processor when providing the booking function. The processing is governed by Calendly’s Data Processing Addendum, which forms part of its contractual terms. Calendly may also process certain data as an independent controller, in particular for account management, billing, security, fraud prevention, compliance with legal obligations, and development of the service.
Calendly may use cookies and comparable technologies. Strictly necessary technologies are used on the basis of Section 25(2)(2) TDDDG. Non-essential technologies generally require prior consent. Cookie settings on Calendly’s pages are provided and managed by Calendly.
Calendly processes data in the United States and potentially in other countries outside the European Economic Area. According to Calendly, transfers from the European Economic Area are based in particular on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses approved by the European Commission.
After a booking has been completed, automatic appointment confirmations, calendar invitations, and appointment reminders may be sent. These messages are used solely to organize and conduct the booked appointment and do not constitute sales follow-up communications.
Appointment and contact data transferred to or retained by me is generally deleted no later than six months after the inquiry is concluded if no business relationship is established and no statutory retention obligation or legitimate interest requires longer storage. Calendly may retain data for longer in accordance with its own statutory, contractual, and security-related retention requirements.
Further information is available in Calendly’s Privacy Notice:
https://calendly.com/legal/privacy-notice
12. POSSIBLE DISCLOSURE TO TABOOLA AT YOUR REQUEST
Personal data is not automatically disclosed to Taboola merely because you visit the website, use the Heyflow flow, or book a Calendly appointment.
If, during a call or other communication, you expressly ask me to introduce you to Taboola or forward your inquiry to Taboola, the information required for that introduction may be disclosed to the relevant Taboola entity. This may include in particular:
– name;
– business contact details;
– company and professional role;
– information about the product or service to be advertised;
– information regarding existing advertising spend or marketing activities; and
– the content of your inquiry and your interest in a potential business relationship.
The disclosure is limited to the data required for the introduction requested by you.
The legal basis is Article 6(1)(b) GDPR where the disclosure is made at your request for the purpose of taking pre-contractual steps. Where required, the disclosure may additionally be based on your consent under Article 6(1)(a) GDPR.
Following the disclosure, Taboola generally processes the data under its own responsibility as an independent controller. Further processing is subject to the privacy notice of the relevant Taboola entity.
Further information:
https://www.taboola.com/policies/privacy-policy
13. CONTACT BY EMAIL OR TELEPHONE
If you contact me by email or telephone, I process the information you provide in order to handle your inquiry. This may include in particular:
– name;
– contact details;
– company and professional role;
– content of the inquiry; and
– communication and appointment data.
The legal basis is Article 6(1)(b) GDPR where the communication relates to pre-contractual steps or the performance of a contract. In all other cases, the processing is based on Article 6(1)(f) GDPR. My legitimate interest is the handling and documentation of business communications.
The data is deleted once it is no longer required to handle the inquiry and no statutory retention obligation or legitimate interest requires longer storage. For non-binding inquiries that do not result in a business relationship, deletion generally takes place no later than six months after the inquiry is concluded.
14. RECIPIENTS AND CATEGORIES OF RECIPIENTS
Depending on the function used, personal data may be disclosed to the following recipients or categories of recipients in particular:
– hosting and platform providers;
– form and appointment-booking providers;
– cookie and consent-management providers;
– advertising and analytics platforms following your consent;
– IT, security, and support service providers;
– tax advisers, legal advisers, and public authorities where legally required; and
– Taboola or other platform providers where you expressly request an introduction.
Personal data is disclosed for other purposes only where a lawful basis exists.
15. RETENTION PERIODS
Unless a specific retention period is stated in this Privacy Policy, I retain personal data only for as long as necessary for the relevant processing purpose.
The data is then deleted unless statutory retention obligations, legitimate documentation interests, or the establishment, exercise, or defense of legal claims require longer storage.
Where commercial or tax-law retention obligations apply, the relevant records are retained for the legally required period.
16. REQUIREMENT TO PROVIDE DATA
Providing personal data is generally voluntary. Where fields are marked as mandatory, the relevant information is required to process the inquiry or appointment booking requested by you.
Without the required information, an inquiry or booking may not be processed or completed. There is generally no statutory obligation to provide the data.
17. AUTOMATED DECISION-MAKING
No decision is made solely on the basis of automated processing where that decision produces legal effects concerning you or similarly significantly affects you.
Any preliminary qualification or routing to an appointment-booking page within a Heyflow flow does not constitute automated decision-making within the meaning of Article 22 GDPR with legal or similarly significant effects.
18. YOUR RIGHTS UNDER THE GDPR
Subject to the applicable legal requirements, you have the following rights in particular:
– the right of access under Article 15 GDPR;
– the right to rectification under Article 16 GDPR;
– the right to erasure under Article 17 GDPR;
– the right to restriction of processing under Article 18 GDPR;
– the right to data portability under Article 20 GDPR;
– the right to object under Article 21 GDPR;
– the right to withdraw consent under Article 7(3) GDPR; and
– the right to lodge a complaint with a supervisory authority under Article 77 GDPR.
You may withdraw consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. Where personal data is processed for direct-marketing purposes, you may object to such processing at any time without giving reasons.
To exercise your rights, contact:
19. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for non-public entities based in Bavaria is in particular:
Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach
Germany
Email: poststelle@lda.bayern.de
You may also contact any other supervisory authority competent under Article 77 GDPR.
20. DATA SECURITY
I use appropriate technical and organizational measures to protect personal data against loss, alteration, unauthorized access, and other misuse.
Transmission of the websites and landing pages is generally encrypted using TLS/SSL. However, complete security of data transmitted over the internet cannot be guaranteed.
21. ADDITIONAL INFORMATION FOR RESIDENTS OF THE UNITED STATES
The website is operated from Germany. The GDPR and applicable German law apply to the processing described in this Privacy Policy. Depending on your state of residence, the nature and scale of the processing, and whether the relevant state privacy law applies to me, you may have additional rights under U.S. state privacy laws.
21.1 Categories of Personal Information
During the preceding twelve months, I may have collected the following categories of personal information, as further described in this Privacy Policy:
– identifiers and contact information, such as your name, email address, telephone number, IP address, and online identifiers;
– internet or other electronic network activity, such as pages visited, interactions, device information, referral information, and advertising or conversion events;
– professional or employment-related information, such as your company, role, and business contact details;
– commercial information, such as information about your business, marketing activities, advertising spend, and interest in services; and
– communications and information voluntarily submitted through forms, email, telephone, or appointment-booking services.
I obtain this information directly from you, automatically through your browser or device, and from the service providers and advertising platforms described in this Privacy Policy.
21.2 Purposes of Processing
I use personal information for the purposes described in this Privacy Policy, including to:
– operate, secure, and improve the websites and landing pages;
– process inquiries and appointment bookings;
– prepare for and conduct introductory calls;
– measure and optimize advertising where you have provided consent;
– communicate with you;
– arrange an introduction to Taboola where expressly requested; and
– comply with legal obligations and establish, exercise, or defend legal claims.
21.3 Disclosure to Service Providers and Other Third Parties
Personal information may be disclosed to hosting, website, form, appointment-booking, consent-management, analytics, advertising, IT, security, professional-advisory, and platform providers as described in this Privacy Policy.
I do not sell personal information in exchange for monetary payment. However, where you consent to the use of the Meta Pixel, Reddit Pixel, or comparable advertising technologies, online identifiers and internet or network activity may be transmitted to advertising platforms for measurement, remarketing, audience creation, or interest-based advertising. Under certain U.S. state privacy laws, such disclosures may be considered a “sale,” “sharing,” or processing for “targeted advertising,” even where no money is exchanged.
Where applicable, you may opt out of such processing by rejecting or withdrawing consent for marketing and advertising technologies through the cookie settings on the relevant website.
21.4 Additional U.S. Privacy Rights
If and to the extent an applicable U.S. state privacy law applies, eligible residents may have rights including:
– the right to confirm whether personal information is processed and to access that information;
– the right to request correction of inaccurate personal information;
– the right to request deletion of personal information, subject to exceptions;
– the right to obtain a portable copy of personal information;
– the right to opt out of the sale or sharing of personal information or its use for targeted advertising;
– the right to limit certain uses or disclosures of sensitive personal information, where applicable;
– the right to appeal a refusal of a privacy request, where provided by applicable law; and
– the right not to be discriminated against for exercising applicable privacy rights.
To submit a request, contact:
I may request information reasonably necessary to verify your identity and authority to make the request. An authorized agent may submit a request where permitted by applicable law, subject to appropriate verification.
Requests will be handled within the time limits and subject to the exceptions provided by applicable law.
22. CHANGES TO THIS PRIVACY POLICY
This Privacy Policy may be updated if the services used, the actual data-processing activities, or the applicable legal requirements change.
The version currently published on the website applies.