Privacy · Datenschutz · GDPR / DSGVO
Privacy Policy
How we handle data on Peptides:Enhanced. Compliant with the EU General Data Protection Regulation (GDPR / DSGVO) and the German Federal Data Protection Act (BDSG).
Last updated: 8 April 2026
Data Controller
Verantwortlicher
The controller responsible for data processing on this website per Art. 4 (7) GDPR is:
Cloak One GmbH
Parcusstraße 6a
55116 Mainz, Deutschland
Register: HRB 50315 (Amtsgericht Mainz)
See our Impressum for full legal disclosures.
Purpose of this website
Zweck dieser Website
Peptides:Enhanced is an independent research project operated by Cloak One GmbH as part of the company's consulting work with startups across multiple verticals on data analytics, conversion performance, user behaviour, and affiliate / e-commerce trend research. This website is one of several research platforms operated by Cloak One to study user behaviour, conversion dynamics, and affiliate-channel performance in a data-rich consumer segment. Revenue from affiliate links supports the project's operating costs and ongoing research.
We do not manufacture, sell, or ship any products. All content is educational.
What data we collect
Erfasste Daten
We collect the minimum amount of data required to operate the site:
- Server log data (temporary): IP address, user agent, date/time, referrer URL, HTTP status, requested path. Stored briefly by our hosting provider (Vercel Inc.) for security and operational purposes.
- Aggregated analytics (where applicable): page view counts, device category, referrer origin — used for our conversion rate research. We do not build cross-site tracking profiles of individual visitors.
- No account registration — there are no user accounts.
- No contact forms — contact is via email only.
- No first-party tracking cookies beyond essential UI state (dismissed banners, selected syringe type on the calculator).
Legal basis for processing
Rechtsgrundlage der Verarbeitung
The legal basis for processing your personal data depends on the context:
- Art. 6 (1)(f) GDPR — legitimate interest in operating, securing, and improving our website, and in conducting conversion rate research that informs our commercial consulting services.
- Art. 6 (1)(a) GDPR — your consent, where explicitly given.
Third-party services
Drittanbieter
This website is hosted on Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). Vercel processes technical data (IP, user agent, etc.) necessary to deliver the website. Standard Contractual Clauses per Art. 46 (2)(c) GDPR apply for transfers to the USA.
We link to third-party affiliate partners (Ascension Peptides, Limitless Biotech). When you click an affiliate link, a cookie may be set by the destination website (not by us) to track the referral for commission attribution. This cookie typically expires after 60 days. You can opt out by visiting those sites directly instead of via our affiliate links.
Cookies
Cookies
This website does not set first-party tracking cookies. We use only essential, session-scoped storage for UI state (dismissed banners, selected syringe type on the calculator) which is not subject to consent under §25 (2) TTDSG.
Third-party cookies may be set on external destinations when you click out. These are governed by the destination site's privacy policy.
Your rights under GDPR
Ihre Rechte nach DSGVO
As a data subject you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7 (3) GDPR)
Right to lodge a complaint
Beschwerderecht bei einer Aufsichtsbehörde
Under Art. 77 GDPR you have the right to lodge a complaint with a supervisory data protection authority. The competent authority for Cloak One GmbH is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34
55116 Mainz
Data retention
Speicherdauer
We retain personal data only as long as strictly necessary for the purposes outlined above, or where legally required (e.g., tax records: 10 years per §147 AO). Server logs are retained for a short window (typically up to 30 days) and then automatically deleted.
Updates to this policy
Aktualisierungen
We may update this privacy policy to reflect changes in applicable law, our services, or data processing practices. Substantive changes will be announced on this page with a revised "Last updated" date at the top.