Datenschutzerklärung (Privacy Policy)
1. Controller
The controller responsible for processing personal data on this website is:
Triple R / Esporlas
Owner: Rymonn Esporlas
Bargteheider Straße 65
22143 Hamburg
Germany
Phone: +49 176 138 64 269
Additional phone: +49 176 767 49 199
Email: rymonn.esporlas@yahoo.com
2. General Information
This Privacy Policy explains which personal data is processed when you visit this website and when you contact us. Personal data means any information relating to an identified or identifiable person.
We process personal data only insofar as this is necessary to provide the website, process inquiries, carry out pre-contractual or contractual measures, comply with legal obligations, protect legitimate interests, or where consent has been given.
3. Legal Bases
Depending on the processing activity, we rely in particular on the following legal bases:
- Art. 6(1)(a) GDPR where consent has been given;
- Art. 6(1)(b) GDPR for pre-contractual inquiries or the performance of a contract;
- Art. 6(1)(c) GDPR for compliance with legal obligations;
- Art. 6(1)(f) GDPR to protect legitimate interests, particularly in the secure, reliable, and economical operation of the website and in processing general business inquiries;
- Section 25(1) TDDDG where consent is required for storing information on or accessing information from an end device;
- Section 25(2) TDDDG for technically essential access to end devices.
4. Hosting and Technical Provision
When this website is accessed, the technical infrastructure used to operate the website processes connection and usage data. If an external hosting provider is used, that provider processes the data for the operation, delivery, and security of the website.
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and efficient provision of our online services. Where a data processing agreement exists, processing is carried out on the basis of a contract pursuant to Art. 28 GDPR.
5. Server Log Files
When the website is accessed, the following data may in particular be processed in server log files:
- IP address of the accessing device;
- Date and time of access;
- Accessed address or file;
- HTTP method and protocol version;
- HTTP status code;
- Amount of data transferred;
- Depending on the production server configuration, additionally the referrer URL, browser type, operating system, or device information.
The processing serves the technical delivery, error analysis, stability, detection of misuse, and security of the website. The legal basis is Art. 6(1)(f) GDPR.
The data is deleted or anonymized as soon as it is no longer required for these purposes, unless a security investigation or statutory retention obligation requires longer storage.
6. Encrypted Transmission
When the website is accessed via HTTPS, the connection between the browser and web server is encrypted. This is intended to protect transmitted data against unauthorized interception or alteration.
Unencrypted emails, on the other hand, are generally not completely protected against access by third parties. Therefore, please only transmit confidential information where this is necessary for your inquiry.
7. Contact by Email
If you contact us by email, we process in particular your email address, name, the content of your message, any attachments you send, and other data you voluntarily provide.
For contract-related inquiries, processing is based on Art. 6(1)(b) GDPR. For other inquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the proper processing and documentation of business inquiries.
The published contact address is operated through an email service provided by Yahoo. When sending and receiving emails, the participating email and infrastructure providers may process connection, sender, recipient, and content data. Further information can be found in Yahoo’s Privacy Policy:
https://legal.yahoo.com/emea/en/yahoo/privacy/index.html
8. Contact by Telephone
If you contact us by telephone, we may process your telephone number, the time and duration of the call, and the information you provide. Depending on the telephone provider, corresponding connection data may also be processed by the telecommunications companies involved.
The legal basis is Art. 6(1)(b) GDPR for contract-related matters and Art. 6(1)(f) GDPR for other matters.
9. Contact Form
The website uses a contact form provided by Contact Form 7. When the form is submitted, the entered data is processed in order to receive the inquiry, transmit it by email, and respond to it.
The legal basis is Art. 6(1)(b) GDPR insofar as your inquiry concerns the conclusion or performance of a contract. For general business inquiries, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the organized and efficient processing of incoming inquiries.
10. Processed Form Fields
The contact form requests the following mandatory information:
- Full name;
- Email address;
- Telephone number;
- Requested service;
- Message.
The form does not contain a file upload field. Please do not submit special categories of personal data or confidential information unless this is necessary for processing your inquiry.
11. Storage of Form Submissions
According to the reviewed configuration, the submitted form data is not stored as separate form entries in the WordPress database. It is forwarded by email.
The IP address and submission time are not included as form fields in the email. However, the technical form request may appear in the server log files in accordance with Section 5.
12. Email Delivery of the Contact Form
No separate SMTP plugin is configured for form delivery. The message is sent using the PHP mail function provided by the server or hosting provider.
According to the reviewed configuration, a Gmail mailbox is configured as the recipient. As a result, the form data may be processed by Google and by the servers used for transmission. Further information about Google’s processing can be found at:
https://policies.google.com/privacy?hl=en
The actual delivery, temporary storage, and retention additionally depend on the production hosting and email configuration.
13. Cookies and Similar Technologies
This website uses cookies and comparable browser technologies. Cookies are small pieces of information that can be stored on or read from the end device.
Technically essential technologies are used on the basis of Section 25(2) TDDDG. The associated processing of personal data is based on Art. 6(1)(f) GDPR and, where required, Art. 6(1)(c) GDPR.
Optional technologies and external content are activated on the basis of your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
14. Local Browser and Session Storage
In addition to cookies, the website may use local browser storage. Your cookie selection may be stored there under the key surecookie_preferences.
When the translation function is activated, GTranslate may additionally use the key gt_autoswitch. The storage generally remains in place until it is deleted by the website, a new consent request, or by you through your browser settings.
15. Consent Management with SureCookie
We use SureCookie to manage and document your cookie and privacy settings.
The following information may in particular be processed:
- Randomly generated session ID;
- Selected cookie categories;
- Consent action, such as accepted, rejected, or partially accepted;
- Time of the decision;
- Country or approximate geographic location;
- Masked IP address.
The following are used in particular:
surecookie_session_id: required session and consent identifier; retention period of up to 365 days;surecookie_user_consent: stored consent decision and timestamp; retention period of up to 365 days;surecookie_preferences: category selection stored in local browser storage.
Consent logs may be stored locally in the WordPress database for up to 365 days. To determine the country, the IP address may temporarily be processed through the SureCookie service at library.surecookie.com and a MaxMind-based geolocation service. The IP address is stored in masked form in the local database.
The legal basis for technically necessary storage is Section 25(2) TDDDG. Processing for the management and documentation of settings is based on Art. 6(1)(f) GDPR and, insofar as documentation is required by law, Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
During a cookie scan, selected page addresses may be transmitted to library.surecookie.com. During the initial scanner registration, the website address, WordPress administrator email address, plugin version, and a temporary installation identifier may additionally be processed.
Further information:
https://surecookie.com/privacy-policy/
https://wordpress.org/plugins/surecookie/
16. WordPress
This website is based on WordPress. WordPress processes the technical data required for the provision, administration, and security of the website.
On the reviewed public pages, there was no user registration, customer account, ordering function, or public commenting function. WooCommerce is installed but not activated.
17. Elementor and Theme Components
The pages are built using WordPress, the Brickz theme, Elementor, and additional theme and display plugins. Elementor Pro is not installed.
These components generally process the technical data required for displaying the pages within the website. If a component loads external content, this is described separately in the relevant sections of this Privacy Policy.
18. Google Fonts
Google Fonts are currently used to display fonts. When pages are accessed, font files for Golos Text, Cal Sans, Maitree, and Roboto, among others, are retrieved directly from Google’s servers.
For users in the European Economic Area, the provider is in particular Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other affiliated Google companies in the United States or other countries cannot be ruled out.
When the fonts are retrieved, information such as the IP address, browser and device information, requested resource, date and time, and the previously visited page may be transmitted to Google. According to Google, cookies are not required for the Google Fonts API.
The integration serves the consistent, technically reliable, and efficient presentation of the website. We base the processing on Art. 6(1)(f) GDPR. Our legitimate interest is the consistent presentation of our online services.
Further information:
https://fonts.google.com/faq?hl=en#privacy
https://policies.google.com/privacy?hl=en
19. Locally Hosted Fonts and Icons
Additional font, symbol, and icon files, including local icon fonts, are delivered by the website itself. These local requests do not result in additional transmission to an external font provider. Only the general server log data described in Section 5 is generated.
20. Analytics and Statistics Services
No active services such as Google Analytics, Matomo, Google Tag Manager, or comparable visitor analytics tools were identified on the reviewed public pages.
If such a service is introduced in the future, this Privacy Policy will be updated before it is activated and, where required, consent will first be obtained.
21. Spam Protection and CAPTCHA
No active external CAPTCHA, reCAPTCHA, Turnstile, or comparable spam protection was identified in the contact form. The installed Akismet plugin is not activated.
Therefore, there is currently no form-related transmission to such an external spam protection provider.
22. Google Maps
A Google Maps map is provided on the contact page. For users in the European Economic Area, the provider is in particular Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other affiliated Google companies may occur.
The map remains blocked initially. A connection to Google is only established if you consent to loading the map or activate the corresponding category in the cookie settings.
The following data may in particular be processed:
- IP address;
- Browser and device information;
- Date and time;
- Accessed page;
- Map address and map usage;
- Where applicable, location and Google account data;
- Cookies or similar identifiers used by Google.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future through the cookie settings.
Further information:
https://policies.google.com/privacy?hl=en
https://policies.google.com/privacy/frameworks?hl=en
23. Video and Media Platforms
No embedded YouTube, Vimeo, or comparable external video services were identified on the reviewed pages.
If external videos or media are integrated in the future, they will be blocked until the required consent has been obtained, and this Privacy Policy will be updated accordingly.
24. Social Networks
No active social media plugins or embedded social media feeds were identified on the reviewed public pages.
Simple links to external profiles would only establish a connection to the respective provider when clicked. No functional external social media links were identifiable on the reviewed pages.
25. Translation Function with GTranslate
The GTranslate WordPress plugin is installed on the website. If the translation function is visibly integrated and activated by you, resources from cdn.gtranslate.net and translation services from Google may be loaded.
The following data may in particular be processed: IP address, browser and device information, language settings, time, accessed address, and page content required for translation. The function may use the cookie name googtrans and the local browser storage key gt_autoswitch.
GTranslate is provided by:
GTranslate Inc.
4394 NW 120th Ave
Coral Springs, FL 33065
USA
Processing is carried out only on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time through the cookie settings.
Further information:
https://gtranslate.io/privacy-policy
https://policies.google.com/privacy?hl=en
26. Content Delivery Networks and Cloudflare
No active use of Cloudflare or a general external Content Delivery Network for the website was identified.
Exceptions are the external requests described in this Privacy Policy, particularly Google Fonts and, if activated, resources from GTranslate and Google Maps.
27. Security
We take appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
No standalone WordPress security plugin was identified during the review. Independently of this, security measures may exist at the server, hosting, or network level.
28. Caching and Optimization
No active WordPress caching, performance, or image optimization plugin was identified. Technical caching by browsers, web servers, hosting infrastructure, or network components may nevertheless occur independently.
Such processing serves the efficient and stable provision of the website and is based on Art. 6(1)(f) GDPR.
29. Data Recipients
Depending on how the website is used, data may in particular be transmitted to the following recipients or categories of recipients:
- Hosting, server, and technical infrastructure service providers;
- Telecommunications and email service providers;
- Google and affiliated Google companies when using Google Fonts, Google Maps, and the Gmail mailbox;
- Yahoo for direct email communication;
- SureCookie and its technical services and MaxMind for consent management and country determination;
- GTranslate Inc. and Google when the translation function is activated;
- IT service providers where access is required to perform their duties;
- Authorities, courts, or other public bodies where there is a legal obligation.
30. Data Processing Agreements
Where external service providers process personal data exclusively on our behalf, they are engaged on the basis of a data processing agreement pursuant to Art. 28 GDPR. Where providers process data for their own purposes, their privacy information and responsibilities also apply.
31. Transfers Outside the EU and EEA
When using Google, GTranslate, Yahoo, or technical subcontractors, processing may take place in countries outside the European Union and the European Economic Area, particularly in the United States.
According to the providers, such transfers are carried out in particular on the basis of an adequacy decision, valid certification under the EU-U.S. Data Privacy Framework, Standard Contractual Clauses issued by the European Commission, or explicit consent, insofar as these mechanisms are applicable to the specific processing activity.
Despite such safeguards, processing in third countries may involve a level of data protection that differs from that of the European Union.
32. Retention Period
Personal data is stored only for as long as necessary for the respective purpose or as required by statutory retention, documentation, or limitation periods.
In particular, the following criteria apply:
- General inquiries: until the matter has been conclusively processed and, where applicable, beyond this period for the required documentation;
- Contract-related communication: during the performance of the contract and subsequently in accordance with statutory commercial and tax retention periods;
- Server log data: until it is no longer required for operation, security, and error analysis;
- SureCookie consent data: under the current configuration, for up to 365 days;
- Cookies and local browser storage: according to the periods specified in this Privacy Policy or until deleted through the browser settings;
- Data held by external providers: according to their own retention policies and statutory obligations.
If the legal basis ceases to apply and there are no legal reasons for further storage, the data will be deleted or anonymized.
33. Rights of Data Subjects
Subject to the applicable legal requirements, you have in particular the right to:
- Obtain information about your personal data;
- Have inaccurate data corrected;
- Request deletion of your data;
- Request restriction of processing;
- Receive your data in a structured, commonly used, and machine-readable format;
- Have your data transferred to another controller where the legal requirements are met.
To exercise your rights, you can contact us using the contact details provided in Section 1.
34. Withdrawal of Consent
You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out on the basis of consent before its withdrawal remains unaffected.
Cookie and service consents can be changed or withdrawn through the “Cookie Settings” link in the footer.
35. Right to Object
Where processing is based on Art. 6(1)(f) GDPR, you have the right to object to such processing for reasons arising from your particular situation.
Where personal data is processed for direct marketing purposes, you may object to such processing at any time without giving any specific reason.
36. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
In particular, you may contact the supervisory authority responsible for Hamburg.
37. Competent Data Protection Supervisory Authority
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22
20459 Hamburg
Germany
Phone: +49 40 42854-4040
Email: mailbox@datenschutz.hamburg.de
Website: https://datenschutz-hamburg.de/
38. Changes to This Privacy Policy
We will update this Privacy Policy if the website, services used, technical processes, or legal requirements change.
Last updated: August 7, 2026

