Last updated: October 10, 2026
This policy explains what personal data I collect through briantomlinson.me, why I use it, who may receive it, and what choices you have.
1. Who is responsible for your data
The controller responsible for this website is:
Brian Curtis Alexander Tomlinson
Sole proprietor (Einzelunternehmer)
Poppenbütteler Berg 38
22399 Hamburg
Germany
Email: hello@authoritysocial.com
No data protection officer has been appointed. You can send privacy questions and requests directly to the email address above.
2. The data this website processes
The data processed depends on how you use the website. It may include:
- technical data such as your IP address, browser, device, operating system, referring page, pages viewed, and access times;
- cookie identifiers, consent choices, and analytics events;
- your email address and subscription information when you join a newsletter or podcast list;
- your name, email address, booking details, and message when you contact me or book a call; and
- information you choose to provide in an email, form, or booking request.
I do not intentionally collect special-category data through this website. Please do not include health information, political views, religious beliefs, or other sensitive information in a booking form or ordinary email unless it is necessary.
3. Hosting and server logs
This website runs on WordPress and is hosted by Hostinger.
When you open a page, the hosting systems process technical data needed to deliver and secure the website. This can include your IP address, the requested page, the date and time, browser and device information, the referring page, and server status information.
I use this data to operate the website, detect faults, prevent abuse, and protect the site from attacks. The legal basis is my legitimate interest in providing a stable and secure website under Article 6(1)(f) GDPR.
Server-log data is retained only for as long as it is needed for security, fault diagnosis, and legal claims, then deleted or anonymized under the hosting provider’s retention settings.
Hostinger group companies may process website data on my behalf. The exact contracting entity and server location depend on the hosting account and selected data center. Hostinger states that personal data may be processed in the United Kingdom, the Netherlands, Lithuania, Cyprus, and other jurisdictions. Where data is transferred outside the European Economic Area without an adequacy decision, Hostinger states that it uses safeguards including the European Commission’s Standard Contractual Clauses. You can read the Hostinger Privacy Policy.
4. Cookies and similar technologies
Cookies are small files stored on your device. Similar technologies include local storage, pixels, tags, and scripts that can recognize a browser or record an interaction.
I use two categories:
Necessary technologies
These are required to deliver the website, keep it secure, remember your privacy choices, or provide a feature you have requested. They are used without consent where the requirements of Section 25(2) TDDDG are met. The related processing is based on Article 6(1)(f) GDPR unless another legal basis applies.
Optional technologies
Analytics, measurement, affiliate-link tracking, embedded media, and similar optional technologies are activated only after you consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.
The consent panel shows the current providers, purposes, cookie names, and storage periods. You can reject optional technologies and still use the main parts of the website.
You can change or withdraw your choice at any time through the Cookie settings link in the footer. Withdrawing consent does not affect processing that took place before withdrawal.
5. Consent records
The consent tool stores the choice you made, the time of that choice, the policy version, and a technical identifier needed to remember it. This allows the website to respect your preference and helps me show that consent was obtained where required.
The legal basis is Article 6(1)(c) GDPR where the record is needed to meet a legal obligation, and Article 6(1)(f) GDPR for the legitimate interest in managing and documenting privacy choices.
6. Google Analytics and Google Tag Manager
With your consent, this website uses Google Analytics to understand how visitors find and use the site. Google Tag Manager manages measurement tags but does not decide how the data is used.
The services may process:
- a shortened or otherwise protected version of your IP address;
- browser, device, operating system, and approximate location information;
- pages viewed, referring pages, access times, and session information;
- interactions such as link clicks, scrolling, and form events; and
- cookie or device identifiers.
Google Analytics and the related Google tags are activated only after consent. I do not use this data to identify you directly.
The providers are Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and, where relevant, Google LLC in the United States. Google may process data outside the European Economic Area. Google describes the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses as transfer safeguards where applicable.
The legal bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw consent through Cookie settings. More information is available in Google’s Privacy Policy.
7. Matomo analytics
With your consent, this website uses a self-hosted version of Matomo to measure visits and improve the site. The Matomo software and analytics endpoint are hosted on briantomlinson.me rather than on Matomo’s cloud service.
Matomo may process your IP address, device and browser details, referring page, pages viewed, access times, and interactions with the site. The configuration must anonymize IP addresses and avoid user-level profiling beyond what is needed for aggregated site measurement.
Matomo is activated only after consent. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw consent through Cookie settings.
Analytics data is retained for the period shown in the consent panel and then deleted or aggregated so that it can no longer be linked to a visitor.
8. Newsletter and podcast updates through Kit
Newsletter and podcast signup forms are provided by Kit, Inc., formerly ConvertKit. When you subscribe, Kit processes the information needed to manage the subscription and send emails. This includes your email address and may include your IP address, signup time, consent record, device and browser information, tags assigned to the form, and information about email delivery and engagement.
I use a double opt-in process. After signing up, you must confirm the subscription through an email before I add you to the active mailing list.
The legal basis for sending the newsletter or podcast updates is your consent under Article 6(1)(a) GDPR. You can withdraw that consent at any time by using the unsubscribe link in an email or contacting me.
Your active subscriber data is retained until you unsubscribe or I end the mailing list. After an unsubscribe request, limited information may remain on a suppression list so that I can respect the request and show that no further marketing email should be sent. Records needed for legal claims or proof of consent may be retained for the applicable limitation period.
Kit acts as a processor for subscriber data. Kit and its subprocessors may process data in the United States and other countries. Kit’s Data Processing Addendum uses the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses, including the controller-to-processor module, where applicable. You can read the Kit Privacy Policy and Kit Data Processing Addendum.
Kit forms and tracking technologies that are not strictly necessary are loaded only after consent where consent is required.
9. Link routing and measurement through Geniuslink
Some outbound links may use Geniuslink, a service operated by GeoRiot Networks, Inc. Geniuslink can route a link to the appropriate regional destination and provide aggregated click information.
When a Geniuslink-enabled link is used, the service may process an IP address at the time of the click, browser and device information, language, the page containing the link, destination or product information, and limited purchase information supplied by an affiliate program. Geniuslink states that IP addresses used to process a click are not stored afterward and that location information is typically deleted within five minutes.
Geniuslink is used only after consent where its technology accesses or stores information on your device. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. Data may be processed in the United States under safeguards described by Geniuslink, including the EU Standard Contractual Clauses where applicable.
You can read the Geniuslink Privacy Policy. If a link is an affiliate link, I may receive a commission without increasing the price you pay.
10. Booking a call through Cal.com
Links marked as contact or booking links may take you to my booking page on Cal.com. Cal.com, Inc. processes the information you provide there on my behalf. This can include your name, email address, time zone, meeting time, answers to booking questions, notes, and technical data such as your IP address and browser.
I use the information to schedule and prepare for the requested conversation. The legal basis is Article 6(1)(b) GDPR when the booking concerns a contract or steps you ask me to take before a contract. In other cases, the legal basis is Article 6(1)(f) GDPR and my legitimate interest in organizing requested meetings.
Booking data is retained for as long as it is needed to arrange and document the meeting, manage any resulting business relationship, and meet legal retention duties. Cal.com may process data in the United States. It describes the EU-U.S. Data Privacy Framework and Standard Contractual Clauses as transfer safeguards where applicable. Read the Cal.com Privacy Policy.
Cal.com may connect to calendar, video-call, and email services selected for the booking workflow. Those services receive the meeting information needed to create and manage the appointment.
11. Contact by email
When you email me, I process your name, email address, message, and any information you choose to include. I use it to answer your request and manage follow-up communication.
The legal basis is Article 6(1)(b) GDPR when the message concerns a contract or a request made before entering one. For other inquiries, the legal basis is Article 6(1)(f) GDPR and my legitimate interest in responding to messages sent to me.
I delete ordinary inquiries when they are no longer needed, usually within six months after the conversation ends. If the communication relates to a contract, invoice, legal claim, or other record that must be retained, the relevant statutory retention period applies.
12. Embedded media
Some pages may include videos or other media from third-party platforms such as YouTube. Embedded media can allow the provider to receive your IP address, browser and device information, the page you visited, and information about how you interact with the media. If you are signed in to the provider, it may connect that activity to your account.
Embedded third-party media is blocked until you consent. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw consent through Cookie settings. For YouTube, see Google’s Privacy Policy.
13. External links and social networks
The website links to external services, including LinkedIn, Instagram, and X. A normal link does not send those services data until you click it. After you leave this website, the privacy policy of the destination service applies.
14. Website automation
The WordPress installation uses plugins and automation tools, including SureTriggers, to connect website functions and reduce manual administration. These tools may process an event only when a configured website action requires it. They must not receive visitor data unless the action and its legal basis are documented and, where required, covered by consent.
15. Recipients and processors
I share personal data only where it is needed to provide the website, send requested communications, arrange meetings, meet a legal duty, or protect legal rights. Depending on how you use the site, recipients may include:
- Hostinger group companies for WordPress hosting and related infrastructure;
- Kit, Inc. and its subprocessors for email subscriptions and delivery;
- Google Ireland Limited and Google LLC for consented analytics and tag management;
- Cal.com, Inc. and selected calendar, email, or video-call providers for bookings;
- GeoRiot Networks, Inc. for consented Geniuslink routing and measurement;
- technical support, security, and automation providers acting under appropriate agreements; and
- public authorities, courts, advisers, or other recipients where disclosure is required by law or needed for legal claims.
I do not sell personal data.
16. International transfers
Some providers are based in the United States or use subprocessors outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, the transfer must use an approved safeguard. Depending on the provider, this may include certification under the EU-U.S. Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
You can contact me if you want more information about the safeguard used for a specific service.
17. How long data is kept
I keep personal data only for as long as the purpose requires or the law requires me to retain it. The relevant period depends on the data:
- server and security data follows the hosting and security retention settings;
- consent records are retained for as long as needed to document the choice and related legal claims;
- analytics data follows the period shown in the consent panel;
- subscriber data is kept until unsubscribe, subject to limited suppression and proof-of-consent records;
- ordinary inquiries are usually deleted within six months after the conversation ends; and
- contracts, invoices, and tax records are kept for the periods required by German commercial and tax law.
Data may be retained longer when it is needed to establish, exercise, or defend a legal claim.
18. Your rights
Subject to the conditions in the GDPR, you may have the right to:
- ask for access to your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- receive data you provided in a portable format;
- object to processing based on legitimate interests; and
- withdraw consent at any time for future processing.
You also have the right to lodge a complaint with a data protection authority. The authority responsible for Hamburg is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22
20459 Hamburg
Germany
You may also contact the authority where you live or work, or where you believe a GDPR infringement took place.
To exercise your rights, email hello@authoritysocial.com. I may ask for information needed to verify your identity. I will not ask for more information than is reasonably necessary.
19. Automated decisions
I do not use personal data collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects for you.
20. Security
I use reasonable technical and organizational measures to protect personal data. The website uses HTTPS encryption during transmission. No internet service can guarantee complete security, so please do not send sensitive information through ordinary email or public forms unless necessary.
21. Changes to this policy
I may update this policy when the website, providers, or legal requirements change. The date at the top shows when it was last revised. Material changes will be explained on this page or through another appropriate notice.
