Privacy notice
Information pursuant to Art. 13 GDPR
This is a translation for convenience. The German version is the legally binding one.
1. Controller
Star Strike Ventures UG (haftungsbeschränkt)Kolonnenstr. 8, 10827 Berlin, Germany
Email: hi@ssvu.de
Further details are set out in the imprint. We are not required by law to appoint a data protection officer.
2. General
This website is deliberately kept simple. It embeds no third-party fonts, maps, videos or scripts and uses no third-party analytics or tracking services. A single cookie is set, and only once you log in to the protected portfolio area, see section 8. As it is strictly necessary for a function you have explicitly requested, no consent is required under § 25 para. 2 no. 2 TDDDG. There is therefore no consent banner.
We process personal data only to the extent necessary to operate this website and to answer your enquiries.
3. Access to the website and server log files
When you access this website, your browser transmits technically necessary data which our server records in log files:
- IP address of the requesting device
- date and time of access
- page or file requested and volume of data transferred
- notification of successful retrieval and HTTP status code
- browser type and version, operating system
- referrer URL, where your browser transmits it
Purpose: delivering the page, operational security, defending against and investigating attacks, and troubleshooting. Legal basis: Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure and stable operation of the website. Retention: log files are deleted after seven days at the latest. This data is not combined with other data sources.
4. Usage statistics and heatmap
We measure the use of this website with a solution we run ourselves on our own server. No third-party services are involved, in particular no Google Analytics, and no data is transmitted to third parties.
What is collected: the page requested, the time, the time spent and the active part of it, the scroll depth reached, the position of clicks as a share of page width and page height, the element clicked, the referring page, window and screen size, device class, browser and browser language.
What is not collected: your IP address in clear text, your name, anything you type into form fields, or text you select. No cookies are set and nothing is stored in your browser. There is no recognition across sessions or devices.
To distinguish individual visits we derive a daily rotating hash, salted with a secret key, from the IP address and the browser identification. It cannot be reversed and loses any link to you when the day changes.
Legal basis: Art. 6 para. 1 lit. f GDPR. Our legitimate interest is to understand which content is read and to improve the website accordingly. As nothing is stored on or read from your device, § 25 para. 1 TDDDG does not apply and no consent is required.
Retention: individual events are deleted after 90 days. The daily figures derived from them are anonymous and are kept permanently.
Objection: no measurement takes place at all if your browser sends "Do Not Track" or "Global Privacy Control". Both can be switched on in your browser settings. Disabling JavaScript for this site has the same effect.
5. Hosting
We run this website on a server that we administer exclusively ourselves. The underlying infrastructure is provided to us as a processor within the meaning of Art. 28 GDPR by:
Hostinger International Ltd.61 Lordou Vironos Street, 6023 Larnaca, Cyprus
The server used is located in the United States of America. The log data referred to in section 3 is therefore processed in a third country. The transfer is based on the Standard Contractual Clauses of the European Commission pursuant to Art. 46 para. 2 lit. c GDPR, supplemented by technical and organisational measures. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
We point out that US authorities may under certain conditions demand access to data held by US providers and that there is, in this respect, no level of legal protection equivalent to European law.
The connection is encrypted using a certificate issued by Let's Encrypt, operated by the Internet Security Research Group (ISRG). No personal data is transmitted to ISRG in this process.
6. Contact form
Via the contact form we collect your name, email address, optionally your company, and your message. This information is stored on our server and additionally forwarded to our mailbox. Together with the submission we record the time, the IP address and the browser identification in order to detect and prevent misuse.
The form uses no third-party services for bot protection. All checks run exclusively on our own server: a hidden field, a time window, a simple arithmetic question and a limit on submissions per connection. No data is transmitted to third parties and no cookies are set in this process.
Legal basis: Art. 6 para. 1 lit. b GDPR where the enquiry serves to initiate or perform a contract, otherwise Art. 6 para. 1 lit. f GDPR based on our legitimate interest in responding and in protecting the form against misuse.
7. Contact by email
If you write to us by email instead, we process your details in order to handle your enquiry and for any follow-up questions. Legal basis: Art. 6 para. 1 lit. b GDPR where the enquiry serves to initiate or perform a contract, otherwise Art. 6 para. 1 lit. f GDPR based on our legitimate interest in responding.
Our mailbox is operated with Google Workspace. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A data processing agreement is in place. A transfer to the USA cannot be excluded; it is safeguarded by the Standard Contractual Clauses and the EU-US Data Privacy Framework.
We delete enquiries once they have been dealt with conclusively, unless statutory retention obligations, in particular under commercial and tax law, apply.
8. Protected portfolio area
The area /en/portfolio is password protected. After a successful login we set a cookie named ssv_pf. It contains only an expiry timestamp and its cryptographic signature, so no personal data and no identifier that makes you recognisable. It expires after 14 days. You can remove it at any time using the log out link or via your browser settings.
Failed login attempts are logged with IP address and time in order to detect and prevent systematic guessing. Legal basis: Art. 6 para. 1 lit. f GDPR, legitimate interest in the security of the protected area.
9. Recipients
Beyond the processors named above we do not pass your data on to third parties. Disclosure only takes place where we are required by law to do so.
10. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on Art. 6 para. 1 lit. f GDPR (Art. 21). You may withdraw any consent given at any time with effect for the future.
An informal message via the contact form is sufficient to exercise these rights.
11. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und InformationsfreiheitAlt-Moabit 59 to 61, 10555 Berlin, Germany
12. No automated decision-making
Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.
13. Changes
We adapt this notice when the website or the legal situation changes. The version published here applies in each case.
Last updated: August 2026