egircys.com / Legal
Privacy Policy
How personal data is handled for website visits, business inquiries, payments and read-only advisory audits.
Updated
1. Who is responsible
This notice applies to personal data connected with egircys.com, business inquiries, audit orders, payment, scheduling and delivery of read-only advisory reviews. A business-only offer does not remove the privacy rights of individual visitors, contacts or other people whose data is processed.
Controller for this website and my own business administration:
Egidijus GirčysMies-van-der-Rohe-Str. 6
14469 Potsdam
Germany
[email protected]
Use this contact for privacy questions and rights requests. Where I process personal data on a client’s instructions, the separate engagement and required processing agreement define that role; see section 6.
2. Information, purposes and legal bases
| When | Information | Purpose and legal basis |
|---|---|---|
| Visiting the website | IP address, request time, requested page, response status and browser or device information transmitted with the request. | Delivering and securing the website. Legitimate interests in reliable hosting and preventing abuse: Article 6(1)(f) GDPR. |
| Contacting me | Name, email address, business details and information you include in your message. | Answering your request and preparing or performing a contract: Article 6(1)(b). For other inquiries and business representatives, legitimate interests in communication: Article 6(1)(f). |
| Booking and paying | Contact and billing details, service selected, amount, currency, payment reference and payment status; tax details where applicable. | Processing the order and payment: Article 6(1)(b) for individual business customers, or Article 6(1)(f) for representatives of a business; billing and record-keeping obligations: Article 6(1)(c); proportionate fraud and dispute handling: Article 6(1)(f). |
| Scheduling and delivering an audit | Availability, meeting details, project contacts, agreed access, relevant code or configuration, findings and report correspondence. | Preparing and providing the agreed service: Article 6(1)(b), or Article 6(1)(f) for contacts acting for a business client. |
| Legal requests or disputes | Relevant correspondence, contract, invoice and payment records. | Meeting legal duties: Article 6(1)(c); establishing, exercising or defending claims: Article 6(1)(f). |
Where a particular optional activity relies on consent, the purpose and consent request are provided separately under Article 6(1)(a) GDPR. A payment, inquiry or privacy-policy link is not blanket consent to unrelated processing.
3. Website hosting: Netlify
The site is hosted by Netlify, Inc., a US-based hosting provider. Netlify and its infrastructure providers process the technical data necessary to deliver and secure requests, including IP addresses, requested resources, timestamps, browser information and request or security records. The purpose is reliable delivery and protection against abuse; the legal basis is Article 6(1)(f) GDPR.
Netlify uses international infrastructure, including processing in the United States. It is not an EU-only hosting commitment. Its published data-processing agreement addresses processor activities and international transfers; its privacy notice separately addresses activities for which Netlify acts as controller.
Provider details: Netlify Privacy Statement, Netlify GDPR information and Netlify Data Processing Agreement. See section 7 for international-transfer information.
4. Payments through Stripe
Where a paid audit is offered, payment is handled on Stripe’s hosted checkout rather than through a card form on this website. Stripe processes the selected payment method, billing and contact details, transaction information and technical or fraud-prevention data. It may process information entered in checkout even if the payment is not completed.
I receive the business contact and billing details, selected service, payment reference, amount, currency and payment status needed to administer the order, issue invoices, provide the service and deal with refunds or disputes. Standard hosted checkout does not provide me with your card security code or full payment-card number.
Stripe acts as processor for some merchant-directed activities and as an independent controller for certain payment, regulatory and fraud-prevention activities. The responsible Stripe entities depend on the activity and location; the current entities and respective roles are identified in Stripe’s Privacy Policy and Privacy Center. Its Data Processing Agreement addresses processor activities and applicable transfer arrangements.
For my processing, the legal bases are contractual necessity for an individual business customer (Article 6(1)(b)), legitimate interests in administering business accounts and resolving fraud or disputes (Article 6(1)(f)), and applicable invoicing and record-keeping duties (Article 6(1)(c)). Ordering an audit is not consent to marketing or unrelated processing.
5. Email and scheduling
When you email [email protected], the email-hosting and delivery providers involved in the exchange process your address, message, attachments and delivery records. I use this information to answer the inquiry, arrange the engagement and communicate findings. Do not send passwords, API secrets, sensitive personal data or customer exports in ordinary email.
The legal basis is Article 6(1)(b) for inquiries and contracts with an individual business customer, or Article 6(1)(f) for communication with a company representative and other legitimate business inquiries. Providers used for email delivery and mailbox hosting are recipients for this purpose, not recipients authorized to use audit material for unrelated advertising.
The website links to Calendly LLC, a US-based scheduling provider. When you open that link, Calendly receives the technical information for that visit and processes the scheduling information you submit, such as your name, email address, time selection and booking answers. I receive the appointment details, which may also appear in the calendar used to manage the meeting. The purpose and legal bases are arranging and carrying out the requested business discussion as above.
See Calendly’s Privacy Notice and Data Processing Addendum. You can arrange a discussion by email instead. Recording, transcription or an AI meeting assistant is not authorized merely by booking a call; any such additional activity requires advance information and an appropriate legal basis.
6. Client material and read-only access
The default review uses limited repository access, sanitized source or configuration exports, and existing evidence rather than live end-user records. Project materials may nevertheless contain names, commit-author information, contact details or identifiers. Viewing, downloading or storing personal data is still processing even where no record is changed.
Only information necessary for the agreed review should be supplied. Remove live user records, secrets and unnecessary personal information from exports. Reports should use redacted or synthetic examples where they can explain the finding adequately. I do not need unrestricted production access for a standard advisory audit.
If end-user personal data must be processed on a client’s behalf, access does not begin until the processing roles, documented instructions, security measures, permitted providers, deletion arrangements and any required Article 28 GDPR agreement are established. The client may be a controller or a processor; my role may correspondingly be processor or subprocessor. That role is determined by the actual activity, not by the word “audit”.
Where I act on another organization’s instructions, it provides the appropriate end-user notice and determines the relevant purpose and legal basis. End-user requests are referred to that organization, with assistance as required by the processing agreement and law. This does not restrict anyone’s right to contact a supervisory authority or exercise rights against a responsible party.
External AI tools must not receive confidential code or personal data merely because a customer has accepted these terms, paid or granted repository access. Any such use requires advance agreement about the tool, purpose and material and the necessary data-protection arrangements. Model training on client material is not an authorized purpose of this service. Unexpected exposure to unnecessary personal data is treated as a reason to restrict the affected review and agree a safer method, not as permission to expand processing.
7. Recipients and international transfers
Recipients are limited to those needed for the purposes described: Netlify and its infrastructure providers for hosting; Stripe and necessary payment participants for payment; Calendly and relevant calendar providers for scheduling; email-hosting and delivery providers for communication; and agreed project-access or storage providers for an engagement. Professional advisers or public authorities may receive necessary records where there is an appropriate legal basis or obligation.
Some of these services involve processing outside the European Economic Area, notably in the United States. For hosting, Netlify’s published DPA section 14 provides for applicable EU–US Data Privacy Framework coverage and standard contractual clauses for restricted transfers not covered by that framework. Calendly’s DPA similarly describes framework coverage and fallback contractual clauses. Stripe’s DPA and associated transfer terms address applicable restricted transfers for its processor activities, while its privacy notice describes its own controller transfers.
These are provider-specific published mechanisms, not an assurance that every provider, product or onward transfer has identical coverage. Necessary contracts and safeguards must apply to the actual service and transfer. New providers receiving confidential audit material, and any additional restricted transfers for that engagement, must be addressed before that material is shared. An inquiry, purchase or acceptance of this notice is not blanket consent to international transfers.
Contact me for information about the recipients and transfer safeguards relevant to your data, including how to obtain a copy of applicable safeguards with any necessary redactions. The linked provider notices and agreements provide additional details about their own processing.
8. Website technology, cookies and links
The website uses locally served styles, images and scripts. I do not embed advertising pixels, third-party visitor analytics, social-media widgets, Calendly calendars or Stripe payment forms in these pages. Calendly, payment and social links take you to the external service when you choose to open them. Hosting-related technical processing is described in section 3.
The site’s own interface does not require an account or add browser storage for advertising or visitor analytics. External services may use cookies and similar technology once you visit them; their notices and choices then apply. This notice does not authorize non-essential device storage or tracking.
Before introducing technology requiring consent, I will provide the relevant information and obtain the necessary consent. That obligation is not replaced by a statement in a privacy policy.
9. Retention and deletion
Data is retained only for its relevant purpose or a specific lawful retention reason. Different records have different rules; invoice retention is not a reason to keep an entire client repository.
Inquiries and appointments
Standalone inquiry and scheduling records are kept until the request and necessary follow-up are resolved, then deleted unless they become part of a contract, legally retained business correspondence or a necessary dispute record. Necessary business correspondence is retained for the statutory period applicable to that record, rather than indefinitely for possible future marketing.
Orders and invoices
Contract, billing and payment records are kept for the applicable statutory period and any additional period necessary for an actual claim or legal hold. Invoices subject to section 14b UStG are generally retained for eight years, beginning at the end of the year in which the invoice was issued; applicable extensions and special rules remain relevant. Other accounting or correspondence records may have different statutory periods.
Working project copies and evidence
For engagements under these terms, temporary working copies of source code and project exports are deleted or returned within 30 days after delivery of the report or cancellation, unless an agreed follow-up still requires specified material or a legal obligation or actual dispute requires limited preservation. A stricter client data-processing agreement takes precedence. Any extension is limited to the necessary material and purpose; live secrets and unnecessary end-user data should not be retained.
The final report, order record and the minimum necessary supporting evidence may be retained for contract administration and establishing, exercising or defending legal claims. Retention is assessed against the relevant limitation period and any actual dispute or legal hold; it is not a commitment to retain all source material for that period. Redaction or extraction of the relevant evidence is preferred to retaining an entire project.
Backups and provider records
Deletion of working copies does not represent a claim that every infrastructure backup is instantly overwritten. Any backup copy must remain access-restricted, be used only for necessary recovery and be removed through the applicable rotation/deletion process; any restoration must respect the deletion decision. Where personal data is processed on a client’s behalf, concrete backup and final-deletion arrangements are established in the processing agreement before access.
Hosting, delivery and payment providers retain their technical or controller records under the applicable service configuration, agreements and legal obligations. Their own notices describe controller retention. Audit access is ended when no longer needed, and the customer is asked to revoke any outstanding invitations.
10. Your rights and complaints
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing and data portability. Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
Right to object: You may object on grounds relating to your particular situation to processing based on Article 6(1)(f). You may object to processing for direct marketing at any time.
Send requests to [email protected]. Only proportionate identity-verification information will be requested. Requests are normally answered within one month; a legally permitted extension and its reasons will be communicated. Advisory-only terms and contractual liability provisions do not waive your data-protection rights.
You may complain to a supervisory authority, particularly in the EU Member State of your habitual residence, workplace or the alleged infringement, without first contacting me. The supervisory authority for Brandenburg is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg.
11. Required information and automated decisions
Business contact, billing and project information necessary for an order or agreed review must be supplied for those purposes. Without it I may be unable to accept or perform the engagement. Optional information is not a condition of purchase, and unnecessary personal data should not be supplied.
I do not make solely automated decisions producing legal or similarly significant effects about customers in delivering these advisory audits. Findings and recommendations are reviewed by me. Stripe may carry out its own fraud or payment-risk decisions as described in its notices.
12. Version and contact
This notice is dated 28 September 2026, version 2026-09-28-b2b-advisory-v2. It may be updated when the actual service or processing changes. A new notice does not itself create a legal basis or authorize unrelated use of previously collected data.
Questions: [email protected]. See also the Terms of Service and Impressum / Legal notice.