Legal
Privacy Policy
Last updated: July 30, 2026
This Privacy Policy applies to rotrax.org and the Rotrax landing pages operated there, including /landing3. It reflects the tools currently visible in the site code as of July 30, 2026.
Where German law supplements the GDPR, this page is intended to work together with the German version at /datenschutz.
1. Controller
The controller for the processing described on this website is:
Kian Dousti
Poccistr. 4
80336 München
Germany
For privacy-related requests, you may contact the controller by post at the address above.
2. Website access and server logs
When you visit this website, technical access data is processed automatically so that the site can be delivered securely and reliably. This typically includes IP address, date and time of the request, requested URL, referrer URL, browser and device information, operating system, and response status.
The processing is necessary to operate the website and to detect, prevent, and investigate technical faults or misuse.
Legal basis: Art. 6(1)(f) GDPR.
3. Browser storage and necessary website functions
The site uses browser local storage for the following purposes:
- to remember your privacy choice under the key rotrax-marketing-consent,
- to temporarily store booking attribution data under the key rotrax-landing3-booking-intent, and
- to avoid duplicate booking tracking under the key rotrax-meta-reported-bookings.
The temporary booking intent is designed to expire after up to seven days in the current implementation.
Legal basis: Art. 6(1)(f) GDPR. Where information is stored on or read from your device and this is strictly necessary to provide the site function you requested, the legal basis is also Section 25(2) TDDDG.
4. Vercel Web Analytics
This site uses Vercel Web Analytics to understand website usage and performance in an aggregated way.
According to Vercel's current documentation, Web Analytics stores anonymized data and does not use cookies.
Legal basis: Art. 6(1)(f) GDPR.
Provider information: Vercel Web Analytics.
5. Meta Pixel and Meta Conversions API
If you actively grant tracking consent in the site's privacy banner, the website loads the Meta Pixel and may also send server-side conversion events to Meta through the Meta Conversions API.
In this context, the following data may be processed: page URL, event ID, event name, consent state, UTM parameters, fbclid, Meta identifiers such as _fbp and _fbc, IP address, user agent, and hashed email address where a waitlist signup or booking event is attributed.
The purpose is to understand whether Meta ads lead to waitlist signups or booked calls.
Legal basis: Art. 6(1)(a) GDPR and, where information is stored on or read from your device, Section 25(1) TDDDG. You can withdraw consent at any time via the privacy controls on the website.
Provider information: Meta Pixel GDPR guidance and Meta cookie settings information.
6. Embedded product video via Wistia
The landing page embeds a product video player from Wistia. When the page loads, your browser connects to Wistia so the player can be displayed.
In that process, technical data such as IP address, browser data, and request details may be transmitted to Wistia. The precise scope of provider-side processing depends on the active Wistia account configuration.
Legal basis: Art. 6(1)(f) GDPR for presenting product information on the website.
Provider information: Wistia Player Privacy Mode and Wistia Privacy Policy.
7. Demo booking through Cal.com
When you open the booking flow on /landing3, the website builds a link to Cal.com and may pass along tracking parameters already present in the page URL, including UTM values, gclid, fbclid, the selected date, and internal placement/source fields used for attribution.
If you complete a booking, booking metadata can also be processed through the site's booking webhook, including the booking UID, attendee email, source, Meta-related identifiers, and related attribution metadata.
The purpose is to process your requested booking and to understand which traffic sources led to a booked demo.
Legal basis: Art. 6(1)(b) GDPR where the processing is necessary to handle your requested booking, Art. 6(1)(f) GDPR for internal lead management, and Art. 6(1)(a) GDPR for any consent-based Meta attribution.
Provider information: Cal.com Privacy Policy.
8. Waitlist signup and email communication
If you submit your email address through the waitlist form, the website processes the email address, source, page URL, event ID, consent state, and any related tracking identifiers submitted with the request.
In the current implementation, the site may:
- store the contact in Resend,
- assign the contact to a waitlist segment,
- send a welcome email to the submitted address, and
- send an internal notification email about the new signup.
If you previously consented to Meta tracking, the site may also send a corresponding server-side Meta lead event.
Legal basis: Art. 6(1)(b) GDPR where processing is necessary to handle your requested waitlist communication, Art. 6(1)(f) GDPR for waitlist management and internal notification, and Art. 6(1)(a) GDPR for any consent-based Meta attribution.
Provider information: Resend Privacy Policy.
9. Recipients and service providers
Depending on the feature you use, personal data may be disclosed to the following categories of recipients:
- hosting and infrastructure providers,
- Vercel for website analytics,
- Meta for consent-based ad measurement,
- Wistia for embedded video delivery,
- Cal.com for scheduling and booking handling, and
- Resend for waitlist contact management and email delivery.
10. International data transfers
Some of the providers used by this site may process data outside the EU/EEA, especially in the United States.
Where this happens, data transfers are intended to take place only on a lawful basis under the GDPR, for example by using an adequacy decision, contractual safeguards, or another recognized transfer mechanism.
11. Storage periods
Personal data is stored only for as long as necessary for the respective purpose.
- Server log data is generally stored temporarily for security and operations.
- The booking intent in local storage is designed to be treated as stale after up to seven days.
- Consent information remains stored in your browser until you change your choice or clear browser storage.
- Waitlist, booking, and communication data may be retained as long as needed to process the request, manage the business relationship, or comply with legal retention obligations.
12. Your rights
Under the GDPR, you may have the right to access, rectify, erase, restrict the processing of, or receive a copy of your personal data. You may also object to processing based on legitimate interests and withdraw consent at any time with effect for the future.
If you believe that the processing of your data violates data protection law, you also have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR.
For a controller based in Bavaria, the competent supervisory authority for the private sector is generally the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, lda.bayern.de.
13. Changes to this policy
This Privacy Policy may be updated if the website, its tools, or the legal framework changes. The current version published on this page applies.