Back to the home page

Privacy

Privacy notice

This notice transparently explains what data is processed when you visit the website or submit a voluntary booking enquiry. Enquiries are stored in a private database; no automated decisions are made.

1. Controller

Knappe Entertainment UG (haftungsbeschränkt), Elisabeth-Wolf-Straße 68, 03042 Cottbus, Germany, represented by Alexander Knappe. Email: booking@knappeentertainment.com. Phone: +49 176 61365632.

2. Hosting and delivery

The website is delivered through Vercel Inc., USA. When you visit, technically necessary connection data such as your IP address, time of access, requested file, referrer, browser and device information is processed so the website can be delivered securely and reliably. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure, abuse-resistant and efficient operation. Vercel documents the EU-U.S. Data Privacy Framework and supplementary EU Standard Contractual Clauses for transfers to the United States.

3. Audience and performance measurement

Vercel Web Analytics and Speed Insights are disabled by default. The measurement scripts load only after you enable analytics with the control below. Web Analytics then records page views with the path, filtered parameters, referrer, approximate region, browser and device data. Vercel states that this is anonymous and uses no third-party cookies; the daily visitor hash generated from the request is discarded after 24 hours. Speed Insights reports anonymous Web Vitals, route, network type, country, browser, device and operating system without identifying a visitor or reconstructing a session across pages. Booking fields and custom conversion events are not sent. The legal basis is your consent under Article 6(1)(a) GDPR and, where information is read from or stored on your device, section 25(1) TDDDG. You can withdraw consent for the future at any time using the same control. Storing your local choice is necessary to implement the privacy setting you expressly request under section 25(2)(2) TDDDG. In addition, since 12 August 2026 we operate our own first-party reach measurement whose figures are visible only inside this website's protected admin area and are not passed to third parties. Recorded per page view: the page path without query parameters, the dwell time as actually visible reading time, the referrer origin (its domain only, never the full address) or a UTM source, the country from the platform header, and a coarse device class (mobile, tablet, desktop). Your IP address is not stored, not truncated and not logged: it serves solely as input to a keyed digest (HMAC-SHA256) whose secret key is generated randomly each day and deleted no later than two days on — the previous day's key survives one extra night so that a request crossing the day boundary does not run into an empty table. Recognition beyond a single day is therefore not merely hard but impossible. There is no session list, no individual analysis and no combination of these attributes into a profile. Raw records are deleted after 90 days; the anonymous daily totals derived from them are kept. The legal basis is likewise your consent under Article 6(1)(a) GDPR. Because this measurement is a separate purpose, the control below asks once more: consent given earlier for Vercel alone does not cover it.

Checking analytics preference …

Without a saved activation, analytics is disabled by default. Your choice is stored only in your browser. The page reloads after a successful change.

4. Booking enquiry form

When you submit the form, we process your name, email address, wedding date, location, requested moment, optional message, language, privacy version and a public enquiry reference. The data is transmitted securely to Supabase, stored in a private access-controlled database and made available in the protected admin area. For direct handling, Resend sends the same business fields, the form language and the public reference in a private transactional email to the recipient configured in the admin area; your email address is set as the validated reply address. Enquiries that are no longer required are deleted automatically after no more than 180 days unless statutory duties or legal claims require otherwise. The legal basis is Article 6(1)(b) GDPR for pre-contractual enquiries.

5. Booking via WhatsApp

Email and WhatsApp are voluntary fallbacks if secure form storage is unavailable. The website opens only an empty email or WhatsApp chat; no form details are placed in the URL. The chosen provider receives the details only after you deliberately paste and send the separately displayed copy text. WhatsApp Ireland Limited then processes information including your phone number, message content, usage, device and connection data under its own terms. Messages are generally end-to-end encrypted, but authorised people at the business you contact may process them. WhatsApp and Meta document the EU-U.S. Data Privacy Framework for specified US transfers and EU Standard Contractual Clauses for other transfers. Use email instead if you prefer not to use WhatsApp. Knappe Entertainment processes your message under Article 6(1)(b) GDPR to handle the enquiry.

6. External videos

YouTube content is loaded in Privacy-Enhanced Mode from youtube-nocookie.com only after you explicitly consent. Google Ireland Limited and, where applicable, Google LLC then receive information including your IP address, device and usage data. YouTube states that this mode prevents the view from being used to personalise your YouTube experience or advertising outside this site; processing still occurs. Google documents the EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses for US transfers. The legal basis is your consent under Article 6(1)(a) GDPR in conjunction with section 25(1) TDDDG. Reloading the page withdraws activation for the future.

7. Server logs

Technically necessary log and security data is used to analyse errors, prevent attacks and maintain operations under Article 6(1)(f) GDPR. It is not combined with booking content. Runtime logs available in Vercel are retained for between one hour and no more than 30 days depending on the plan. Supabase Auth processes the user ID, email address, role and MFA status for the invitation-only CMS. Booking content is held separately in private tables; notification and application logs contain neither name nor email, date, location, requested moment or message.

8. Recipients and international transfers

Recipients are, only where necessary, Vercel Inc. for hosting and optional analytics, Supabase Inc. for private storage and authentication, and Resend for the private transactional email sent to the booking team. That email contains the name, email address, wedding date, location, requested moment, optional message, form language, public enquiry reference and protected admin link; the email address is used as the validated reply address. The subject, technical logs, outbox and provider receipt remain free of these form details. Email or telecommunications providers receive form data through the voluntary fallback only after you paste and send the copy text; WhatsApp/Meta only after your deliberate selection. Google receives data only after video consent. Only approved public marketing copy may be sent to OpenAI Ireland Ltd. for protected CMS translation; booking, contact, email, telephone, legal and admin content is technically excluded. OpenAI API content is not used for training by default. Translation requests use store: false; this is not a Zero Data Retention commitment. Abuse-monitoring logs may generally be retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect the services or third parties. Your booking data is not sold.

9. Retention

Form drafts remain in the browser until submission, reload or closing. Securely submitted booking enquiries are deleted automatically no later than 180 days after receipt unless they are deleted sooner or statutory duties or legal claims require longer purpose-limited retention. If an enquiry leads to an engagement, relevant commercial correspondence may be retained for six years and accounting records for eight years under sections 257 HGB and 147 AO. Short-lived rate-limit records are removed after their protection window; notification and audit records contain no form content. The purpose-based periods stated here continue to apply to CMS, media and analytics data.

10. Voluntary provision and automated decisions

Using the website and providing booking data are not statutory requirements. Fields marked as required are necessary so the booking team can identify and answer the enquiry. Email and WhatsApp are voluntary fallbacks, and you may contact the booking team directly. There is no solely automated decision-making within Article 22 GDPR and no profiling. We do not ask for special categories of personal data under Article 9 GDPR.

11. Your rights

Subject to the GDPR, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. This also applies to invited CMS administrators; upon an eligible account deletion, account data that is no longer required is erased and remaining technical attribution is anonymised unless overriding obligations or legal claims apply. You may withdraw consent at any time with future effect; processing before withdrawal remains lawful. Requests are generally free of charge and answered without undue delay, normally within one month. To prevent unauthorised disclosure, we may request proportionate proof of identity.

12. RIGHT TO OBJECT UNDER ARTICLE 21 GDPR

You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will stop that processing unless compelling legitimate grounds or legal claims override your interests. You may object to direct marketing at any time without giving a particular reason; this website does not conduct direct marketing. You can withdraw any consent given for Vercel analytics for the future directly with the control in section 3.

13. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority. The authority responsible for the controller is the Brandenburg Commissioner for Data Protection and Access to Information, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany. You may also contact the authority at your habitual residence or place of work.

14. Data security

The website is transmitted over encrypted HTTPS. Booking fields are validated on the server, stored in private Supabase tables with enforced access protection and shown only after sign-in with a verified second factor. The private notification email contains the form details only in its message body; its subject, URL, logs, queue and provider receipt remain PII-free. The reply address is validated and line breaks are rejected. Abuse prevention uses only cryptographically hashed short-lived identifiers; failed notifications remain safely stored in a bounded retry queue. Please do not send identity documents, health information or other sensitive data through the form.

15. Privacy contact

Send privacy questions or requests to exercise your rights to booking@knappeentertainment.com, or by post to Knappe Entertainment UG (haftungsbeschränkt), Elisabeth-Wolf-Straße 68, 03042 Cottbus, Germany.

16. Provider information and safeguards

17. Updates and governing version

We update this privacy notice when features, service providers or legal requirements change. The version published on this page applies. The German version governs; the English and Spanish versions are equivalent plain-language translations.

Last updated: 15 August 2026