Privacy Policy
In short
This is a static website. It sets no cookies, embeds no tracking or analytics tools, loads no content from third-party servers, and has no contact form. Visiting it only produces server log files, in which we shorten IP addresses before they are stored. If you write to us, your email is processed on our own mail server. No further processing takes place.
Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
velaluqa GmbHc/o Andersen
Kiautschoustraße 1A
13353 Berlin
Germany
Phone: +49 30 13 88 33 20
Email: info@velalu.qa
We are not legally required to appoint a data protection officer. Please direct any questions about data protection to the address above.
Server log files
When you access this website, our web server automatically collects information transmitted by your browser. We store:
- the IP address truncated by its last segment (e.g. 203.0.113.0 instead of 203.0.113.42)
- the date and time of access
- the address requested, along with the HTTP status code and the amount of data transferred
- the previously visited page (referrer), where your browser transmits it
- browser type and operating system (user agent)
The IP address is truncated during processing, before anything is written to disk. We never store a complete IP address, and we are unable to link this data to you as an individual. Nor do we combine log files with any other data source.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and stable operation of the website and in being able to investigate technical faults. Log files are rotated automatically and overwritten after 14 days at the latest.
Hosting
This website runs on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Germany; no personal data is transferred to countries outside the European Union.
Hetzner processes the data arising from operations solely on our behalf and according to our instructions, governed by a data processing agreement pursuant to Art. 28 GDPR. The legal basis for using a hosting provider is Art. 6(1)(f) GDPR.
Encryption
This website is served exclusively over HTTPS, so the connection between your browser and our server is encrypted and cannot be read by third parties. The certificates used are issued by the Let's Encrypt certificate authority (Internet Security Research Group). No personal data of yours is transmitted to the certificate authority in this process.
Contacting us by email
This website has no contact form. If you contact us at one of the email addresses provided, or by phone, we process the information you supply — typically your name, your contact details and the content of your message — solely in order to handle your enquiry.
We operate our own mail server. Your message therefore remains exclusively in our control; no external email provider is involved. We do not use a customer relationship management system for website enquiries.
The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to entering into or performing a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries. We delete your enquiry once it is no longer needed; statutory retention obligations — in particular for commercial and business correspondence — remain unaffected.
Fonts
The fonts used on this website (Source Sans 3 and Kreon) are served from our own server. Your browser makes no connection to Google Fonts or any other third party, and your IP address is not transmitted to third parties for this purpose.
Links to social networks
In the footer we link to our profiles on external services. These are plain links, not embedded content or social media plugins. No data is transmitted to those providers unless you actively click such a link. From that point on, the privacy policy of the respective provider applies.
Your rights
You have the following rights in relation to us:
- Access to whether and which data we process about you (Art. 15 GDPR)
- Rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR)
- Erasure of your data, unless a retention obligation applies (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR)
- Objection to processing based on our legitimate interest (Art. 21 GDPR)
As we carry out no processing on the basis of consent, there is no consent for you to withdraw. An informal message to info@velalu.qa is sufficient to exercise your rights.
Right to lodge a complaint
Independently of the above, you may lodge a complaint with a data protection supervisory authority under Art. 77 GDPR. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit(Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59–61
10555 Berlin, Germany
www.datenschutz-berlin.de
Changes to this privacy policy
We update this policy when the technical implementation of this website or the legal framework changes. The version published here is the one that applies.
Our company details can be found in the imprint.
Last updated: September 2026