Privacy

Your data. Clearly governed.

This notice explains which personal data is processed on this website, why it is processed, and which rights you have under European data protection law.

Updated: 26 August 2026

01

Controller

The controller under Article 4(7) GDPR is PEPE Splits UG (haftungsbeschränkt) i.G., represented by managing director Sören Hochberg. Email: hello@pepesplits.de. The provider information is in the legal notice. Privacy enquiries can be sent to the email address above at any time.

02

Website, hosting and server logs

When you access the website, our hosting provider processes technically necessary connection data, which may include IP address, date and time, requested URL, referrer, HTTP status, transferred data volume and browser, device and operating-system information.

This processing delivers the website, maintains stability and security and prevents abuse under Article 6(1)(f) GDPR. We use Vercel Inc.as our hosting processor. See Vercel’s Privacy Notice and DPA.

03

Event registration and email

For event registrations we process your name, email address, professional role, company or project, attendance choice, language and registration timestamps. We use this data solely to manage the registration, plan the event and send confirmations and organisational information. It does not subscribe you to a newsletter.

Through the waitlist on our website you can register to be notified when PEPE Splits launches. We process your name, email address, professional role, label, company or artist name, language and the registration timestamp solely to inform you about the launch and give you access. It does not subscribe you to a newsletter. The legal basis is Article 6(1)(b) GDPR (pre-contractual steps at your request).

The legal basis is Article 6(1)(b) GDPR and, for general event organisation, Article 6(1)(f) GDPR. Data is stored in a PostgreSQL database operated by PlanetScale, Inc. in a configured EU region. Transactional email is delivered by Plus Five Five, Inc. (Resend), including processing in the United States based on the EU-US Data Privacy Framework and, where required, Standard Contractual Clauses. See Resend’s Privacy Policy and DPA.

04

Bot protection and security

The event and waitlist forms are protected by Vercel BotID. BotID evaluates technical request, browser and device signals to identify automated or abusive submissions. The legal basis is Article 6(1)(f) GDPR. Any necessary device access is based on section 25(2)(2) TDDDG.

05

Optional analytics and session recordings

We only use PostHog EU Cloud after your express consent. It may process pseudonymous identifiers, pages visited, clicks and interactions, technical device and browser data, approximate location and session duration. RSVP forms are excluded from recordings and inputs are masked.

The legal basis is Article 6(1)(a) GDPR and section 25(1) TDDDG. Without consent, PostHog is not started. You may withdraw consent at any time.

Ad measurement with the Meta Pixel

On the waitlist page we use the Meta Pixel of Meta Platforms Ireland Limited only after your separate consent to the “Ad measurement” category, to measure whether our Facebook and Instagram ads lead to waitlist signups. Page views and the form submission event, technical browser data, your IP address and, where present, Meta identifiers are transmitted to Meta, which may link them to your Meta account. With this consent, your name (first and last name, where provided) and email address from the waitlist form are also sent to Meta for Advanced Matching. The values are normalized in your browser and hashed using SHA-256 before transmission. Meta can match these hashes against its own data to associate events with your Meta account; hashing does not make the data anonymous. Our integration does not send your role or company to Meta. Meta also processes data in the United States under its EU-US Data Privacy Framework certification. The legal basis is Article 6(1)(a) GDPR and section 25(1) TDDDG. Without consent, the pixel is not loaded. See Meta’s Privacy Policy.

  • pepe-consent: c15t stores the choice locally in the browser in offline mode (localStorage and a technically necessary first-party consent-cookie copy). No choice is sent to a c15t server. The record expires after no more than 180 days.
  • PostHog records (ph_*): pseudonymous identifiers, only after consent, retained for no more than 180 days.
  • Meta Pixel (_fbp, _fbc): ad attribution cookies, only after consent to ad measurement, retained for no more than 90 days.

See the PostHog Trust Center.

06

Recipients and international transfers

Access inside PEPE Splits is limited to people who need it. Processors may include Vercel, PlanetScale, Resend and, after consent, PostHog and Meta (ad measurement). Transfers outside the EEA rely on an adequacy decision under Article 45 GDPR, including a valid EU-US Data Privacy Framework certification, or safeguards under Article 46 GDPR, particularly the EU Standard Contractual Clauses.

07

Retention and deletion

We retain data only while necessary for its purpose, then delete or anonymise it unless statutory duties or overriding grounds require continued storage.

  • Server and security data is deleted once no longer required for operational or security investigations.
  • Event registrations are deleted after the event is fully completed unless needed for enquiries or legal claims.
  • Waitlist entries are deleted after the product launch once the notification has been sent and no customer relationship follows.
  • The local c15t consent record and PostHog browser identifiers expire after no more than 180 days.
  • Correspondence is deleted after resolution, subject to statutory retention duties.
08

Your rights

Subject to the statutory conditions, you have rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21) and withdrawal of consent (Article 7(3) GDPR). Contact hello@pepesplits.de. You may also lodge a complaint with a supervisory authority under Article 77 GDPR.

09

Provision, automated decisions and updates

Connection data is necessary to access the website; required RSVP data is necessary to process registration. Analytics consent is voluntary. No solely automated decision with legal or similarly significant effects under Article 22 GDPR takes place. BotID may reject clearly abusive submissions.

We update this notice when processing, providers or applicable law change. The version published on this page applies.