Legal

Privacy Policy

Last updated: 26 August 2026

We write our privacy policy the way we talk to you: short, direct, plain language. "We" are Öykü and Nils of null3null. "You" are the person whose data we process: as a visitor to our website, as the recipient of a personal analysis page, as the owner or contact person of a business we reach out to, or as a client. This notice informs you, in accordance with Art. 13 and 14 GDPR, which data we process, for what purpose, on what legal basis, for how long, and what rights you have.

Controller

The controller within the meaning of Art. 4 No. 7 GDPR for all processing described in this notice is:

null3null social GbR

Grinbergs, Nils; Bargan, Öykü GbR (partnership under German civil law)

Strausberger Platz 13
10243 Berlin

hello@null3nullsocial.com+49 176 72323283

We are not legally required to appoint a data protection officer and have therefore not appointed one (§ 38 BDSG, Art. 37 GDPR). For any questions about data protection, you can reach us directly at the email address above.

1. What this is about

We process personal data in four situations. Each has its own section in this notice:

  • You visit our website null3nullsocial.com or contact us through the contact form (Sections 4 to 7).
  • You open a personal analysis page whose link we sent you (Section 8).
  • We have identified your business as a potential client from public sources and are preparing an outreach (Section 9).
  • You are a client or business partner of ours (Section 10).

We work exclusively with businesses, self-employed people and organisations. Personal data with us is therefore almost always business contact data: an owner's name, a managing director's email address, a phone number from a legal notice page. We do not process special categories of personal data (Art. 9 GDPR) or data relating to children.

2. Your rights

With regard to the personal data concerning you, you have the following rights:

  • Access to the data we process about you and, if we did not collect it from you directly, information about its origin (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing, for as long as we are not yet permitted to erase data due to legal obligations (Art. 18 GDPR)
  • Data portability, insofar as processing is based on consent or a contract (Art. 20 GDPR)
  • Objection to processing based on our legitimate interest (Art. 21 GDPR, see Section 3)
  • Withdrawal of any consent given, with effect for the future (Art. 7(3) GDPR)

To exercise your rights, an informal email to the address given in the "Controller" section is enough. We usually reply within a few business days, at the latest within one month.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59-61, 10555 Berlin, mailbox@datenschutz-berlin.de, www.datenschutz-berlin.de. You can also contact the supervisory authority at your place of residence or work.

3. Objecting to direct marketing

We base part of the processing described here on our legitimate interest (Art. 6(1)(f) GDPR), in particular researching and reaching out to potential clients (Section 9) and evaluating whether an analysis page has been read (Section 8). You can object to this processing at any time. Where the objection concerns direct marketing, we stop the processing without any further balancing of interests.

An objection can be raised informally: a short email, a phone call or a reply to our message is enough. We then delete your data and keep only your email address or domain on a suppression list, so that we do not accidentally contact you again. That is the sole purpose of this list, and it is based on our obligation to permanently honour your objection (Art. 6(1)(c) and (f) GDPR).

4. Hosting and server log files

Our website is operated by Render Services, Inc., 525 Brannan Street, San Francisco, CA 94107, USA, on servers in the Frankfurt am Main data centre. Render uses the network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, for delivery and protection against attacks. Both providers act as processors for us (Art. 28 GDPR).

Every time you visit our website, the following data is technically stored in server log files: IP address, date and time, the page requested, the amount of data transferred, HTTP status code, referrer URL, and browser and operating system. We need this data to deliver the website, ensure its stability and security, and detect attacks. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).

We do not combine the log files with other data and do not evaluate them on a personal basis. They are automatically deleted after a short time; only if a specific security incident needs to be investigated do we keep the relevant entries until it is resolved.

5. No cookies, no tracking

Our website does not set cookies and does not use any analytics, tracking or advertising tools: no Google Analytics, no Meta pixel, no tag manager, no heatmaps. That is why we do not show a cookie banner either. If you ever see one, it is not from us.

Two purely technical exceptions that are not cookies: if you arrive on our site through a link with campaign parameters (so-called UTM parameters), your browser remembers these parameters together with a random form identifier in what is called session storage. Both leave your browser only if you submit the contact form, and are deleted as soon as you close the tab. This storage is strictly necessary for the function of the form (§ 25(2) No. 2 TDDDG, German Telecommunications-Digital-Services Data Protection Act).

We serve our typeface Outfit from our own server; your browser does not connect to Google for this. Some images and videos on the website are hosted with our database and storage provider Supabase (see Section 12) and are loaded from there. Our social media profiles are embedded as plain links, not as plugins; you only leave our website once you click on one.

6. Contact form on the website

Through our contact form, you can send us a request in three steps. In doing so, we collect: your goal (video, social media, or both), optionally the address of your website and your social media profile, your name, your email address, optionally your phone number, and a message. You also confirm that you have read this privacy policy.

We process this information to answer your request, arrange an initial conversation, and prepare a proposal. The legal basis is taking pre-contractual measures at your request (Art. 6(1)(b) GDPR). We use the website and social media profile you provide to get an idea of your presence before the conversation.

To protect against spam and abuse, the form contains an invisible honeypot field and a minimum fill-in time. In addition, we form a hash value from your IP address and a daily-changing random value, which we use to limit the number of requests per hour. We do not store your IP address itself, and the hash value can no longer be matched to you once the day changes. The legal basis is our legitimate interest in a working form (Art. 6(1)(f) GDPR).

Your request is stored in our database at Supabase (Section 12) and transferred to our internal client system. Only our team has access to it. If it leads to an assignment, the retention periods in Section 10 apply. If it does not lead to an assignment, we delete the request at the latest twelve months after our last contact.

7. Email, phone and initial conversation

If you contact us by email or phone, we process the information you give us to handle your request (Art. 6(1)(b) GDPR, for general inquiries Art. 6(1)(f) GDPR). Our email inboxes and calendars run on Google Workspace by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which acts as a processor for us.

You book an initial conversation through a Google Calendar scheduling link. Clicking the link takes you away from our website; Google's privacy policy applies to the booking page (policies.google.com/privacy). The information you provide there (name, email address, requested time, optionally a note) is entered as an appointment in our calendar and is used only to prepare for and hold the conversation. It is kept and deleted together with your request (Section 6).

We only record conversations if everyone involved has explicitly agreed to it beforehand. For recordings and their transcription, see Section 11.

8. Personal analysis pages

When we reach out to your business, we often send you a personal link to an analysis page. On it, we show what your presence in video looks like today and what we would suggest for you. The page can only be accessed through the link, is blocked for search engines, and is intended for your business. Please do not share the link.

The content of the page comes from publicly accessible sources about your business: screenshots of your website and your Instagram profile, your Google reviews (number and average), where applicable your currently running Meta ads, plus our resulting assessment and a suggestion for what a first video could look like. Section 9 describes how we collect and evaluate this data. At the bottom of the page, you will find a short introduction video from us and a contact form.

So that we know whether our suggestion has landed and whether it is worth following up, the page evaluates whether and how it is read. For this, your browser sends the following events to our server: that the page was opened, how far it was scrolled (in quarters), how long the page was open (in ten-second steps), which sections were visible, and which buttons were clicked, each with a timestamp. These events are linked to the link and therefore to your business. We do not store your IP address or your browser in doing so; we only check whether the visit came from an automated program and flag such visits so that they do not count.

So that multiple visits within the same tab count as one visit, the page stores a random session identifier in your browser's session storage. It contains no personal information and is deleted as soon as you close the tab. The page does not set cookies. The legal basis for this evaluation is our legitimate interest in dosing our outreach sensibly instead of following up blindly (Art. 6(1)(f) GDPR). You can object to this evaluation at any time (Section 3); we will then deactivate the link.

Through the contact form on the analysis page, you can reply to us with your name, email address and a message. This information is linked to your business in our client system and handled like a request submitted through the website (Section 6).

9. How we find and evaluate businesses for our outreach

We win clients by researching businesses that could be a good fit for our services, forming an idea of their presence in advance, and then reaching out to them in a targeted way. In doing so, we also process personal data that we did not collect from you directly. This section is our notice under Art. 14 GDPR.

This affects owners, managing directors and contact persons of businesses, practices, studios, galleries, restaurants and similar establishments, mostly in Berlin and Germany. We collect exclusively data that you or your business have made publicly accessible yourselves, and only from these sources:

  • Google Maps and the Google Business Profile: company name, address, phone number, website, industry, opening hours, and the number and average of reviews (retrieved via the service provider Apify, see Section 12)
  • your website, in particular the legal notice, contact and about pages: names and roles of the persons responsible, business email addresses and phone numbers, texts, images and embedded videos, plus a screenshot of the homepage
  • your Instagram profile: profile name, bio, follower and post counts, the most recent posts with text, date and engagement, plus a screenshot of the profile (retrieved via Meta's official interface, or via Apify as a fallback)
  • the existence and address of your profiles on LinkedIn, TikTok and YouTube (via a Google search and Apify; we do not log in there and do not read any private content)
  • Meta's public Ad Library: which ads your business is currently running on Facebook and Instagram, with text, run time and reach figures

For each piece of data, we store which source it came from and when we collected it, so that we can always tell you its origin on request.

We evaluate this content partly with the help of AI services (Section 11): a language model reads website texts and posts and summarises how your business presents itself. An image model looks at screenshots and images and assesses, for example, whether videos are embedded, how consistent your visual presence is, and whether the people behind the business are visible in it. Photos of people that you have published yourselves on your website or in your profile are used only for this assessment and, where applicable, in an example visualisation that appears exclusively on your own analysis page. We do not create biometric profiles and do not pass the photos on to third parties.

From the data collected, we form an internal assessment of how well your business fits our services, in order to decide who to reach out to first. This assessment serves only our own prioritisation. We do not make any automated decisions that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

The purpose of this processing is to initiate a business relationship: we only want to reach out to you if we can concretely do something for your business, and then send you a well-founded proposal instead of a generic mail. The legal basis is our legitimate interest in direct marketing towards businesses (Art. 6(1)(f) GDPR, Recital 47). We have weighed this up: it concerns only business data that you have published yourselves, a limited amount of outreach, and an offer that can benefit your business. You can object at any time (Section 3).

Outreach takes place by email from our domains null3nullsocial.com and their subdomains, by phone, or by post.You can decline further messages at any time; a short reply is enough, no unsubscribe link is needed. We use the service provider Resend to send emails (Section 12). We do not measure whether you have opened an email or clicked links within it; we only learn whether delivery failed or you reported the message as unwanted, and in that case add your address to our suppression list.

Retention period: if no contact results or you decline, we delete all data collected about your business at the latest twelve months after our last outreach. In the event of an objection, we delete immediately and keep only the suppression entry (Section 3). If it leads to a conversation or an assignment, the retention periods in Section 10 apply.

10. Clients and business partners

If you commission us or work with us, we process the data needed for proposals, contracts, production, coordination and billing: contact details of the people involved, contract and project documents, communication, and invoicing and payment data. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR) and, for accounting and tax purposes, our legal obligations (Art. 6(1)(c) GDPR).

We process invoices and receipts with our business account and accounting provider and pass them on to our tax advisor. Under § 147 AO / § 257 HGB (German Fiscal Code / Commercial Code), we retain accounting records for eight years, books and annual financial statements for ten years, and business correspondence for six years; after that they are deleted. We delete project documents and communication at the latest three years after the end of the collaboration, provided no claims remain open.

If you give us access to your Meta accounts (Facebook page, Instagram account, ad account) for account management, we retrieve the performance data of your posts and ads via Meta's official interface and store it with us in order to evaluate and report on your results. We use this data exclusively for managing your account and do not pass it on to other clients. You can withdraw access at any time in your Meta settings.

We separately inform people who appear on camera in our film productions and obtain the necessary consents. We retain raw footage from productions in accordance with our terms and conditions.

11. AI services and transcription

For evaluating public content (Section 9), drafting text and creating example images, we use AI services as processors. We transmit website texts, posts, screenshots and images to Anthropic for evaluation, along with our notes for drafting proposals. We transmit image and style specifications to Google (Gemini) for creating example visualisations. Under their terms of service, the providers may not use the transmitted data to train their models and retain it only for as long as processing and abuse monitoring require.

If we record a conversation with your explicit consent, we have the recording converted to text by the service Groq in order to prepare a proposal from it. We store the recording and transcript in our client system; only our team has access. You can withdraw your consent at any time; we will then delete the recording and transcript.

The legal basis in each case is the legal basis of the underlying processing: our legitimate interest for research (Art. 6(1)(f) GDPR), pre-contractual measures or contract performance for proposals and projects (Art. 6(1)(b) GDPR), and your consent for conversation recordings (Art. 6(1)(a) GDPR). All providers named are based in the USA; for the safeguards in place, see Section 12.

12. Recipients, processors and third countries

Within null3null, only Öykü and Nils have access to personal data. We only pass on data to service providers that we have contractually bound as processors (Art. 28 GDPR), or where we are legally required to do so. We do not sell data and do not pass it on for third-party advertising purposes. Our service providers:

  • Supabase, Inc., USA: database and file storage for our client system, requests, screenshots and media; data centre in Ireland (EU)
  • Render Services, Inc., USA: hosting of the website and client system, data centre in Frankfurt am Main, with Cloudflare, Inc., USA, as the network in front of it
  • Google Ireland Limited, Ireland: Google Workspace (email, calendar, documents), appointment booking and the AI service Gemini
  • Resend, Inc., USA: sending our emails and reporting failed deliveries
  • Anthropic, PBC, USA: language and image models for evaluating public content and for drafting text
  • Groq, Inc., USA: transcription of conversation recordings, only with your consent
  • Apify Technologies s.r.o., Czech Republic: retrieval of public data from Google Maps and social networks
  • Meta Platforms Ireland Limited, Ireland: retrieval of public profile and ad data via the official interfaces (Graph API, Ad Library); for clients, additionally their performance data
  • Serper.dev: Google search results for identifying social media profiles (we transmit only the company name)

Some of these providers are based in the USA or process data there. For these transfers, we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework, insofar as the provider is certified under it, and additionally on the European Commission's Standard Contractual Clauses (Art. 45 and 46 GDPR). Where possible, we choose data centres in the EU, as with Supabase and Render.

13. Our LinkedIn page

We run a company page on LinkedIn. For the statistics that LinkedIn provides us about visitors to this page (Page Insights), we are joint controllers together with LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (Art. 26 GDPR). The data is collected by LinkedIn; we only see aggregated statistics with no reference to individuals. LinkedIn's privacy policy applies (www.linkedin.com/legal/privacy-policy). You can assert your rights against LinkedIn and against us.

14. Data security

All connections to our website and our systems are encrypted via TLS. Our client system is only accessible to our team with a personal login; access rights are secured at the database level. We store credentials for third-party services in encrypted form. Personal analysis pages are only accessible via links that cannot be guessed and are blocked for search engines. We continuously adapt our measures to the state of the art.

15. Retention periods at a glance

  • Server log files: automatic deletion after a short time (Section 4)
  • Requests via website, analysis page or appointment booking without an assignment: at the latest twelve months after the last contact (Sections 6 to 8)
  • Researched business data without contact: at the latest twelve months after the last outreach (Section 9)
  • After an objection: immediate deletion, only the suppression entry remains (Section 3)
  • Project documents and communication with clients: three years after the end of the collaboration (Section 10)
  • Accounting records eight years, books and financial statements ten years, business correspondence six years, each per legal obligation (Section 10)
  • Conversation recordings and transcripts: until withdrawal, at the latest together with the project documents (Section 11)

16. Changes to this notice

We update this notice whenever our processing activities, the services we use, or the legal situation change. The version published here at any given time applies; the date at the top shows when it was last updated.

Questions about data protection

If you have questions, would like access to your data, want to object, or something in this notice is unclear, write to us:

hello@null3nullsocial.com