This Privacy Policy explains which personal data we collect on our website https://www.drd-media.com, for which purposes, on which legal basis and to whom we disclose it. It also informs you of your rights as a data subject under the EU General Data Protection Regulation (GDPR).
1. Controller within the meaning of the GDPR
The controller responsible for the processing of personal data within the meaning of Art. 4 (7) GDPR is:
Company: DRD Media Agency LLC
Address: 520 SE 5th Avenue, Fort Lauderdale, FL 33301, USA
Authorized representative: Gertrud Neustadt, Managing Member
E-mail: mail@drd-media.com
Phone: +1 954 210 2612
2. Representative in the Union (Art. 27 GDPR)
As the controller is established outside the European Union, the appointment of a representative in the Union pursuant to Art. 27 GDPR is currently being assessed. This Privacy Policy will be updated with the corresponding contact details once the representative has been appointed. Until then, data subjects may exercise their rights without restriction directly vis-à-vis the controller using the contact details above. Requests will generally be answered in English, German or Spanish.
3. Data Protection Officer
A Data Protection Officer pursuant to Art. 37 GDPR has not been appointed at this time, since the statutory thresholds (core activity consisting of regular and systematic monitoring on a large scale, or large-scale processing of special categories of personal data) are not met. Please address all data-protection enquiries to: mail@drd-media.com.
4. General information on data processing
We process personal data of our users only insofar as this is necessary to provide a functional website as well as our content and services. Processing generally takes place only with the user's consent. An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law.
We use SSL/TLS encryption to transmit your data to our server. You can recognize an encrypted connection by the lock icon in your browser bar and the 'https://' prefix. Personal data that you submit to us cannot be read by third parties when SSL/TLS encryption is active.
5. Legal bases of processing
Where we obtain a data subject's consent for processing operations involving personal data, Art. 6 (1) (a) GDPR serves as the legal basis.
In the case of processing of personal data necessary for the performance of a contract to which the data subject is a party, Art. 6 (1) (b) GDPR serves as the legal basis. The same applies to processing operations required for the performance of pre-contractual measures.
Where processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6 (1) (c) GDPR serves as the legal basis.
If processing is necessary to safeguard a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not override the former, Art. 6 (1) (f) GDPR serves as the legal basis.
6. Storage period and deletion
Personal data are deleted as soon as the purpose of processing ceases to apply and no statutory retention obligations conflict with deletion. The following standard periods apply:
- Server logs: 7 days; thereafter deletion or anonymization.
- E-mail correspondence: until the matter has been settled, then up to 6 years to comply with commercial and tax retention obligations where applicable.
- Appointment booking data (GoHighLevel): until the appointment is concluded, then archived in a pseudonymized overview for a maximum of 24 months for traceability.
- Payment data (Stripe): for as long as required to perform the contract and process tax matters; statutory retention obligations remain unaffected.
- Newsletter data (GoHighLevel): until consent is withdrawn; after unsubscribing, your e-mail address remains on a suppression list for a maximum of 12 months to prevent unwanted re-subscription.
7. Provision of the website and server logs
Each time our website is accessed, our hosting system automatically collects data and information from the computer system of the calling computer. This is temporarily stored in the so-called server log files of the server. The following data are collected:
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Host name of the accessing computer
- Time of the server request
- IP address
Storage takes place in order to ensure the functioning of the website, to protect against attacks (e.g. DDoS) and for statistical evaluation. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the technical security and stability of our website.
Hosting provider: These legal pages are hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. When the pages are accessed, Netlify processes the access data listed above (in particular your IP address) on our behalf in order to deliver the pages and protect them against attacks. A data processing agreement (Netlify Data Processing Agreement) is in place. Data are transferred to the United States; Netlify is certified under the EU-US Data Privacy Framework and additionally relies on the EU Standard Contractual Clauses. More information: https://www.netlify.com/privacy/.
8. E-mail contact (Google Workspace)
If you contact us by e-mail at mail@drd-media.com, your e-mail address, the content of your message, any further metadata contained in the header and any attachments will be processed on the mail servers of our provider Google Workspace.
The processing serves to handle your enquiry and the subsequent business communication. The legal basis is Art. 6 (1) (b) GDPR (initiation/performance of a contract) or Art. 6 (1) (f) GDPR (legitimate interest in efficient business communication).
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A data processing agreement (Google Workspace Data Processing Amendment) is in place. Data is also transferred to the United States; Google is certified under the EU-US Data Privacy Framework (Adequacy Decision of the European Commission of 10 July 2023) and additionally relies on the EU Standard Contractual Clauses (SCCs). Storage period: as long as required to handle the enquiry; statutory retention obligations remain unaffected.
9. Contact form
If we provide a contact form on the website, the data entered in the input mask will be transmitted to us and stored. Mandatory fields are marked as such. The technical delivery of the form data is handled via our e-mail dispatch service GoHighLevel (see section 10). The legal basis is Art. 6 (1) (b) GDPR for contract-related enquiries and Art. 6 (1) (f) GDPR otherwise.
10. E-mail dispatch service and newsletter (GoHighLevel)
We use GoHighLevel for the dispatch of transactional e-mails (e.g. system notifications, appointment confirmations, replies to contact forms) and for our newsletter. We process your e-mail address, your name where applicable, dispatch and opening statistics, and technical metadata (IP address, user agent).
The legal basis for transactional e-mails is Art. 6 (1) (b) and (f) GDPR. For the newsletter dispatch, the legal basis is your consent pursuant to Art. 6 (1) (a) GDPR; subscription is implemented via double opt-in. You can unsubscribe at any time using the unsubscribe link in every newsletter or by writing to mail@drd-media.com.
Provider: HighLevel Inc., 400 N. Saint Paul St. Suite 920, Dallas, Texas 75202, USA. A data processing agreement pursuant to Art. 28 GDPR is in place. Data are transferred to the United States; the EU Standard Contractual Clauses apply.
11. Appointment booking (GoHighLevel)
We use GoHighLevel for the online booking of consultation and discovery appointments. When you book an appointment, at least your name, e-mail address, the chosen time slot and any free-text input (e.g. relating to your enquiry) are processed. You may optionally provide further information (phone number, company). GoHighLevel sets technically required cookies and transmits your data to its servers.
The legal basis is Art. 6 (1) (b) GDPR (initiation and performance of the consulting relationship). Data are transferred to the United States.
Provider: HighLevel Inc., 400 N. Saint Paul St. Suite 920, Dallas, Texas 75202, USA. A data processing agreement is in place. Data are transferred to the United States; the EU Standard Contractual Clauses apply. More information: https://www.gohighlevel.com/privacy-policy.
12. Payment processing (Stripe)
We use Stripe to process payments. When you pay through Stripe, the data required for the transaction (e.g. name, e-mail address, billing address, payment instrument data) are transmitted directly to Stripe and processed there. We ourselves do not receive complete payment data (e.g. credit card numbers), but only the information necessary for processing the contract.
The legal basis is Art. 6 (1) (b) GDPR (performance of contract) and Art. 6 (1) (f) GDPR (efficient payment processing, fraud prevention). Data transmission to Stripe is encrypted.
Provider: Stripe Payments Europe, Limited (SPEL), 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Parent company: Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA. A data processing agreement (Stripe DPA) is in place. Data are transferred to the United States; protected by the EU-US Data Privacy Framework and the EU Standard Contractual Clauses. More information: https://stripe.com/privacy.
13. Overview of processors and third-country transfers
| Service | Provider / Location | Purpose | Third-country transfer |
|---|---|---|---|
| Netlify (hosting of legal pages) | Netlify, Inc., USA | Delivery of web pages, server logs | USA – DPF + SCCs |
| Google Workspace (e-mail) | Google Ireland Ltd. (IE) / Google LLC (US) | E-mail correspondence | USA – DPF + SCCs |
| GoHighLevel (E-Mail, Appointment Booking) | HighLevel Inc., USA | Transactional e-mails, newsletter, appointment booking | USA – SCCs |
| Stripe | Stripe Payments Europe Ltd. (IE) / Stripe Inc. (US) | Payment processing | USA – DPF + SCCs |
| GoDaddy (Domain/DNS) | GoDaddy.com LLC, USA | Domain registration, DNS | USA – SCCs |
14. Third-country transfers and appropriate safeguards
To the extent that personal data are transferred to recipients outside the European Economic Area (in particular to the United States), we rely on:
- an adequacy decision of the European Commission (in particular the EU-US Data Privacy Framework, adequacy decision of 10 July 2023) where the recipient is certified;
- in addition or alternatively, the EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR;
- supplementary technical and organizational safeguards (in particular encryption in transit and at rest) within the meaning of the CJEU's Schrems II judgment (Case C-311/18).
An overview of the applicable safeguards is available on request at mail@drd-media.com.
15. Use of artificial intelligence and automated decisions
For internal processes (e.g. text generation, research, workflow automation) we use generative AI systems, namely models from the providers Anthropic, OpenAI and Google. Personal data of website visitors or customers are NOT entered into these systems unless this is necessary for the performance of a contract and you have been informed separately.
Automated individual decisions within the meaning of Art. 22 GDPR — including profiling — do not take place on this website. If we introduce such procedures in the future, we will inform you separately and, where required, obtain your explicit consent.
16. Data subjects' rights
You have the following rights regarding your personal data:
- Right to information (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure ('right to be forgotten') (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw a granted consent (Art. 7 (3) GDPR) — the lawfulness of processing prior to withdrawal remains unaffected
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, an informal e-mail to mail@drd-media.com indicating the desired action is sufficient.
17. Right to lodge a complaint with the supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. In Germany, the competent authority is the State Data Protection Authority responsible for your place of residence. A list is available at https://www.bfdi.bund.de.
18. Obligation to provide data
You are under no statutory or contractual obligation to provide us with your personal data. However, without certain data, you may not be able to use our services in full (e.g. booking an appointment without providing an e-mail address).
19. Data security
We implement technical and organizational measures (TOMs) pursuant to Art. 32 GDPR to protect your data against unauthorized access, loss or manipulation. These include in particular: TLS encryption of the website, secure authentication with two-factor methods for administrative access, brute-force protection, regular security updates of the systems in use, and a documented record of processing activities (RoPA). An overview of the TOMs is available on request.
20. Currency and changes to this Privacy Policy
This Privacy Policy is currently valid and bears the date stated above. Due to the further development of our website and offerings or due to changes in legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version is available on this page at any time and can be retrieved and printed.
Last updated: September 29, 2026