Back to home

Privacy Policy

Privacy Policy

1. Controller

The controller responsible for data processing on this website is:

chocosite LLC
3833 Powerline Rd, Suite 201
Fort Lauderdale, FL 33309, USA

EU Representative (Art. 27 GDPR):
Dirk Murrnautzky
Phone: +49 173 585 91 00
Email: dirk [at] chocosite [dot] info

2. General Information

The protection of your personal data is important to us. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

We do not use external tracking or analytics tools such as Google Analytics or Facebook Pixel. For simple internal page statistics, we only use our own script, which is loaded after your consent.

3. Hosting & Server Log Files

Hosting Provider

This website is hosted by:

ALL-INKL.COM – Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68, 02742 Friedersdorf, Germany
Web: all-inkl.com

The use of ALL-INKL.COM is based on Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement (DPA) with ALL-INKL.COM pursuant to Art. 28 GDPR.

Server Log Files

When you visit our website, the hosting provider automatically collects the following information:

Log files are deleted after a maximum of 14 days. Legal basis: Art. 6 para. 1 lit. f GDPR.

4. Our Own Visitor Analytics

To understand how the site is used, we operate our own privacy-friendly visitor analytics on our own infrastructure. We do not use external tracking or analytics tools such as Google Analytics or Facebook Pixel, and no data is passed on to third parties.

What is recorded: the pages viewed and their order, the content sections that became visible within a page and therefore the last section reached, the broad origin of the visit (direct, Google, Bing, Instagram, Facebook, Pinterest, AI services, other), the device class (desktop, tablet, mobile), and the opening and successful submission of a contact form. Not recorded are form contents, your name, email address or IP address; the analytics never receives an IP address and never stores one.

Two randomly generated identifiers for visit and session are stored in your browser's local storage; a session ends after 30 minutes without activity. Individual visitor paths are deleted after no more than 72 hours. Only anonymous daily counters are kept permanently.

Consent: from Germany, the EU/EEA, the United Kingdom and Switzerland, and where the country of origin cannot be determined, we only record after your consent; the notice offers "Reject" and "Accept" as equally weighted options. From other countries, recording takes place without a prior dialogue and can be switched off at any time via "Privacy settings" in the footer. The country is determined exclusively on the server; the IP address is not passed to the analytics. The legal basis is Art. 6(1)(a) GDPR where consent is required, otherwise Art. 6(1)(f) GDPR.

5. Contact by Email

If you contact us by email, the data you provide (name, email address, message) will be stored for the purpose of processing your enquiry.

Legal basis: Art. 6 para. 1 lit. b GDPR (pre-contractual measures) or Art. 6 para. 1 lit. a GDPR (consent).

Storage period: Data will be deleted as soon as it is no longer required for the purpose for which it was collected, at the latest after statutory retention periods expire.

6. Locally Hosted Fonts

This website uses web fonts stored locally on our own server. When you access the website, the font files are loaded exclusively from our own server.

No connection to Google servers is established for loading fonts, and no personal data is transmitted to Google in this context.

Legal basis: Art. 6 para. 1 lit. f GDPR.

7. Links to External Sites

Our website contains links to external projects and sites. These are simple references. No data is transmitted to the linked sites until you actively click on the link.

8. SSL/TLS Encryption

This website uses SSL/TLS encryption for security reasons. You can recognise an encrypted connection by the "https://" in the address bar and the padlock symbol in your browser.

9. "Chocosite Finances" App (iOS)

"Chocosite Finances" is an internal iOS app exclusively for authorised employees of chocosite LLC. It is not publicly listed on the App Store and is not offered for sale.

The app displays financial figures (income, cash balances, crypto portfolio) that are loaded solely from our own company server and transmitted encrypted (HTTPS). Data is not shared with or sold to third parties; there is no cross-app tracking and no advertising identifiers.

Access requires a 6-digit code or Face ID; credentials and an access token remain encrypted on the device (keychain) and are not transmitted to third parties. A push token (device ID) is used solely to deliver app notifications via the Apple Push Notification service (APNs).

Legal basis: Art. 6 para. 1 lit. b and lit. f GDPR.

10. "chocosite LLC Moodboard" App (iOS)

"chocosite LLC Moodboard" is an internal iOS app exclusively for authorised employees of chocosite LLC. It is not publicly listed on the App Store (unlisted) and is not offered for sale.

The app is used to collect and manage moodboard entries (images, videos and links) and to create private share links. Content is loaded solely from, or uploaded solely to, our own company server and transmitted encrypted (HTTPS). Data is not shared with or sold to third parties; there is no cross-app tracking, no advertising identifiers and no analytics services.

Access requires a 6-digit code or Face ID. Device pairing is done via a QR code from our own dashboard; an access token created in the process remains encrypted on the device (keychain) and is not transmitted to third parties. Photos and videos you capture or select from your library are uploaded to our own company server to provide the app's functionality. The app does not use push notifications.

Legal basis: Art. 6 para. 1 lit. b and lit. f GDPR.

11. Your Rights as a Data Subject

You have the right to:

To exercise your rights, an informal message to our EU representative is sufficient.

12. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). A list of supervisory authorities can be found at bfdi.bund.de.