This is the English version of my privacy policy. The German version is legally binding.
The controller responsible for data processing on this website is:
David Liebnau
Gardeschützenweg 103
12203 Berlin
Email: mail@davidliebnau.com
Phone: +49 170 4326737
Where I ask you for information in order to prepare or perform a contract, providing it is not required by law but is necessary for the contract. Without it, I cannot handle your request or provide the service. You can leave out any optional information.
This website is hosted on GitHub Pages, a service of GitHub Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA, a subsidiary of Microsoft Corporation.
When you visit the website, GitHub automatically collects data transmitted by your browser. This includes your IP address, the date and time of access, the page requested, the browser used and the operating system. This processing is technically necessary to deliver the website.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in providing the website free of technical errors.
As GitHub is based in the USA, data is transferred to a third country. GitHub is certified under the EU-US Data Privacy Framework.
This website uses the typefaces Cormorant Garamond and Hanken Grotesk. The font files are served from my own server. No connection is made to servers of Google or any other third party, and no data such as your IP address is transmitted to third parties.
This website does not set any cookies of its own.
For anonymous audience measurement I use Plausible Analytics, a cookie-free web analytics tool. The provider is Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia.
When a page is visited, Plausible collects technical data such as the URL requested, the referring page, the country, the device type and the browser. Your IP address is processed only briefly to calculate a daily rotating value that cannot be traced back, and is not stored afterwards. No personal data is stored, there is no cross-device tracking and no profiling. The analysis takes place exclusively in aggregated, anonymous form.
Processing takes place on servers within the EU. No data is transferred to a third country.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in an anonymous, data-minimising analysis of how the website is used, without identifying or tracking you as a person.
A data processing agreement pursuant to Art. 28 GDPR is in place with Plausible; it is concluded automatically through the use of Plausible’s services.
You can object to this processing at any time; details of your right to object are in section 14.
Further information from Plausible: https://plausible.io/data-policy
If you contact me by email, I process your details to handle your enquiry and in case of follow-up questions. I do not pass this data on to third parties without your consent. For email I use Microsoft 365 as a processor (see section 7).
The legal basis is Art. 6(1)(b) GDPR if your enquiry relates to a contract or its preparation, otherwise Art. 6(1)(f) GDPR.
I delete the data once it is no longer needed for its purpose, at the latest after three years. Documents relevant for tax purposes are kept for as long as the law requires.
I use Microsoft 365, including Microsoft Teams, provided by Microsoft Ireland Operations Limited, Ireland, and Microsoft Corporation, USA, for email, calendar and video calls. When you write to me, when we talk, or when I send you documents such as a situation report or an invoice, Microsoft processes this content on my behalf under the Data Protection Addendum to the Microsoft Product Terms. Data may be transferred to the USA. Microsoft is certified under the EU-US Data Privacy Framework; transfers are based on Art. 45(1) GDPR and additionally on Standard Contractual Clauses under Art. 46(2)(c) GDPR. The legal basis is Art. 6(1)(b) GDPR where a request or an engagement is concerned, otherwise Art. 6(1)(f) GDPR, my legitimate interest being to answer your message. I only record a video call if you have expressly agreed beforehand; the legal basis is then Art. 6(1)(a) GDPR, and you can withdraw your consent at any time. A recording includes video, audio and, where applicable, an automatic transcript. I store it in my Microsoft 365 account, share it with no one and delete it no later than three months after the call, or immediately if you withdraw your consent. I delete emails once they are no longer needed for their purpose, at the latest after three years. Invoices and documents relevant for tax purposes are kept for as long as the law requires.
For MIRROR requests and agreed steps of our work, I use forms provided by Tally BV, Sint-Pietersnieuwstraat 11, 9000 Ghent, Belgium. When you fill in a form, I process what you enter: for a request, your contact and billing details and a few details about your role and company; for the intake, your answers to open questions about your professional situation. I do not ask for health information. I use this information to answer your request, invoice you and prepare and provide the agreed service. The legal basis is Art. 6(1)(b) GDPR. If you book for a company that is the contracting party rather than you personally, I process your contact details on the basis of Art. 6(1)(f) GDPR, my legitimate interest being the handling of the business relationship. Tally processes the data on my behalf under a data processing agreement pursuant to Art. 28 GDPR. According to the provider, all form data is encrypted in transit and at rest and stored in Europe. Tally notifies me of each new submission by email; the notification contains the information from the form. Tally sends these emails via SendGrid, a service of Twilio Inc., USA. Twilio is certified under the EU-US Data Privacy Framework; transfers are based on Art. 45(1) GDPR. I do not automatically pass the information on to other services. I only use AI on intake answers if you have expressly agreed in the form (see section 10). I delete request data six months after the request has been closed and intake answers within 30 days after our conversation. Invoices are kept for eight years as required by tax law. Please only enter what is necessary in free-text fields, and no sensitive information about other people.
You can book the 20-minute fit call and agreed appointments via a link to Calendly. Clicking the link takes you away from my website. Calendly processes the information you provide there, in particular your name, email address, the chosen time and, for the fit call, your answer to a short question about the reason for the call. I use this information to arrange and hold the appointment. The legal basis is Art. 6(1)(b) GDPR. Calendly processes booking data on my behalf; the corresponding data processing agreement applies through Calendly’s customer terms. Calendly also processes data from the booking process under its own responsibility, for example for the operation and security of its platform, and may show its own cookie banner depending on your region. Details are in Calendly’s privacy notice: https://calendly.com/privacy. The provider is Calendly LLC, USA, which stores data in data centres in the USA. Calendly is certified under the EU-US Data Privacy Framework; transfers are based on Art. 45(1) GDPR, and Standard Contractual Clauses under Art. 46(2)(c) GDPR form part of the data processing agreement. I delete the details of a fit call six weeks after the appointment; if we start working together, I keep them with the contract documents. Calendly adds the appointment to my Microsoft 365 calendar and creates the video call link there (see section 7).
When working out your situation report, I may use AI, but only if you have expressly agreed in the intake. I use Claude by Anthropic or ChatGPT by OpenAI. Before any input, I remove your name, your company and recognisable details. Training on my inputs is switched off in both accounts. I have no separate data processing agreement with these providers; they process the texts under their own privacy terms and on their own responsibility. Processing may take place in the USA, where the level of data protection is not the same as in the EU and public authorities may be able to access the data. The legal basis is your consent under Art. 6(1)(a) GDPR and, for transfers to the USA, Art. 49(1)(a) GDPR. Consent is voluntary. If you say no, I work without AI, with no disadvantage to you. You can withdraw your consent at any time by email with effect for the future. I review and revise every result myself. The providers’ privacy information: https://www.anthropic.com/legal/privacy and https://openai.com/policies/privacy-policy/
If you take part in a programme, I process the information required to run it and to invoice it.
This may include information about your health, for example your general state of health or medication. You provide this information voluntarily. I process it on the basis of your explicit consent under Art. 9(2)(a) GDPR, solely to take your health-related suitability into account and to reduce health risks for you. You can withdraw your consent at any time with effect for the future.
I delete this information after the end of the programme, unless there is a statutory obligation to retain it.
I do not pass on content from our conversations and groups, and I do not enter it into external systems. There are three exceptions. I send you the written situation report by email via Microsoft 365 (see section 7). Written answers you give me for MIRROR or EDGE via a form are held by the form service Tally (see section 8) and deleted there after the period stated. A copy also reaches me as an email notification in my Microsoft 365 mailbox. I delete it there within the same period. And with your express consent, I may use AI when working out the situation report (see section 10). More on this in my commitment on the use of AI (in German).
Reviews on ProvenExpert
On the homepage I state my average rating and the number of client reviews I have received on ProvenExpert. This information appears as text on my own page and is maintained by me. Nothing is loaded from ProvenExpert when the page is opened, and no data flows there.
Next to it is a link to my review profile on ProvenExpert, a service of Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin. Only when you click this link do you leave my website; Expert Systems AG then processes data.
Details in ProvenExpert’s privacy policy: https://www.provenexpert.com/en-us/privacy-policy/
Podcast player from Spotify
On the podcast page (/podcast.html) you can play the podcast directly. The player comes from Spotify and is only loaded when you click on it. Until then you only see a preview image served from my own server; there is no connection to Spotify and no data flows there.
If you click on the player, your browser connects to Spotify’s servers. Spotify receives your IP address, technical details about your browser and device, and the information that you have visited this page. The provider is Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden. I have no influence on Spotify’s data processing; Spotify may set its own cookies or similar technologies in the player.
Your choice is not stored, neither in a cookie nor in your browser’s storage. If you open the page again, the player is once more not loaded.
Details in Spotify’s privacy policy: https://www.spotify.com/uk/legal/privacy-policy/
Episode list from Apple Podcasts
The podcast page (/podcast.html) shows a list of all episodes. To keep it up to date without my maintaining it by hand, your browser retrieves this list from Apple’s public podcast interface. Unlike with the Spotify player, this happens automatically when the page is opened.
Apple receives your IP address and technical details about your browser and device. The provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. No cookies are set, and no data about you is transmitted to Apple beyond what is technically necessary to establish the connection.
The retrieved list is stored in your browser’s session storage for the duration of your browser session, so that it does not have to be reloaded on every page view. It contains only information about the episodes and no data about you, remains on your device and is deleted as soon as you close the tab.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in keeping the episode overview up to date without manual maintenance.
Details in Apple’s privacy policy: https://www.apple.com/legal/privacy/en-ww/
This website links to external services, including Apple Podcasts, LinkedIn, ProvenExpert and light-creators.com. When you click these links, you leave this website. The privacy policies of the linked sites apply to the data processing there.
Mere links do not load anything: as long as you do not click on them, no data flows there. The two cases described in section 12 are exceptions: the Spotify player, which loads when you click on it, and the Apple Podcasts episode list, which is retrieved when the page is opened.
You have the right of access to your stored data, to rectification, to erasure, to restriction of processing, to data portability and to object to processing. You can withdraw any consent you have given at any time with effect for the future.
You also have the right to lodge a complaint with a supervisory authority. The competent authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59-61, 10555 Berlin.
I adapt this privacy policy when the legal situation or the technology of this website changes. The version published on this website applies, with the German version prevailing.
Last updated: September 2026