Privacy Policy

Last updated: March 27, 2026

We appreciate your visit to the Geostrategists websites. As a specialised platform for geopolitical and country-specific expertise, the protection of your personal data is particularly important to us. In this privacy policy, we inform you transparently about what data we collect, how we process it, and what rights you have.

Please note that this English translation is provided solely for informational purposes and convenience. The German-language version of this privacy policy constitutes the official and legally binding document. In the event of any inconsistency or contradiction between the German original and this English translation, the provisions of the German version shall take precedence.

Responsible Entity and Contact

Responsible entity within the meaning of the Datenschutz-Grundverordnung (DSGVO):

Geostrategists Consulting GmbH
Zellertal 24
93444 Bad Kötzting
Germany

Email: info@geostrategists.de

If you have questions about data protection, your rights, or this privacy policy, you can contact us at any time using the contact details provided above. When you contact us by email, your email address and the content of your message will be processed to handle your inquiry. This data processing is based on Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in responding to inquiries).

Principles of Data Processing

The protection of your privacy is of the highest importance to us. We process your personal data according to the following principles:

  • Lawfulness, fairness, and transparency,
  • Purpose limitation of collected data,
  • Data minimisation during processing,
  • Ensuring data accuracy,
  • Adherence to storage limitations,
  • Ensuring integrity and confidentiality.

Data Processing During Website Visits

Cookies and Tracking

We deliberately refrain from using tracking cookies. For our web analytics, we use Plausible Analytics, a privacy-friendly alternative that operates without cookies.

On our website, we only use technically necessary cookies:

  • Session cookies: These temporary cookies store a session ID that allows different requests from your browser to be assigned to a common session. This enables us to recognise your computer when you return and, for example, to save your form entries across different page views. Session cookies are automatically deleted when you close your browser.

These cookies are essential for the smooth operation of our website and enable basic functions such as session management during login or saving form content while navigating.

The legal basis for processing is Art. 6 Abs. 1 lit. f DSGVO (legitimate interest), as these cookies are technically necessary for the operation of our website.

You can set your browser to inform you about the placement of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. The functionality of this website may be limited if cookies are deactivated.

Automatically Collected Data

When you visit our website, the following data is automatically collected for technical reasons:

  • IP address (anonymised),
  • Date and time of access,
  • Name and URL of the accessed page,
  • Amount of data transferred,
  • Access status,
  • Browser type and version,
  • Operating system,
  • Referrer URL (the previously visited page).

The legal basis for this processing is Art. 6 Abs. 1 lit. f DSGVO (legitimate interest). Our legitimate interest lies in ensuring the functionality and security of our website.

The data is generally deleted automatically within 90 days.

Hosting and Technical Infrastructure

We use Amazon Web Services (AWS) with server locations within the European Union for hosting our website and Expert Portal. Additionally, AWS employees from third countries, particularly the USA, may have technical access to the systems for maintenance and support.

For such data transfers, we rely on the EU Standard Contractual Clauses and the EU-US Data Privacy Framework as appropriate safeguards within the meaning of Art. 44 ff. DSGVO.

Analytics and Performance Monitoring

Plausible Analytics

We use Plausible Analytics as a privacy-friendly alternative to conventional analytics tools. Plausible Analytics processes the following data:

  • Visited URL,
  • HTTP referrer (the website from which a visitor came),
  • Browser (derived from the User-Agent HTTP header),
  • Operating system (derived from the User-Agent HTTP header),
  • Device type (Desktop, Mobile, Tablet),
  • Country, region, city (based on the IP address, which is not stored).

Important privacy features of Plausible Analytics:

  • No use of cookies,
  • No storage of personal data,
  • No permanent storage of IP addresses,
  • No cross-device tracking,
  • No cross-website tracking,
  • Hosting exclusively in the EU (Germany).

Data processing is based on Art. 6 Abs. 1 lit. f DSGVO (legitimate interest). Our legitimate interest lies in analysing and optimising our web offering.

You have the right to object to data processing based on our legitimate interest at any time (Art. 21 DSGVO). After your objection, we will no longer process your data for these purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Sentry

For technical monitoring and error detection, we use Sentry. The following data is collected:

  • Technical error messages,
  • Performance metrics,
  • Browser and system data,
  • Anonymised usage paths,
  • IP addresses (temporarily for error analysis).

The data is processed in the EU and generally deleted automatically within 90 days.

Google Maps

For location search in our Expert Portal (e.g., when entering your location), we use the Google Maps API, a service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). When using this service, the following data is transmitted to Google:

  • IP address,
  • Search terms entered (place names),
  • Browser and device information.

The data processing is based on Art. 6 Abs. 1 lit. b DSGVO (contract performance), as the location search is an essential function of our placement platform. Google also processes data in the USA; for this, we rely on the EU-US Data Privacy Framework and EU Standard Contractual Clauses as appropriate safeguards.

For more information on data processing by Google, please see Google's privacy policy at: https://policies.google.com/privacy

Recipients of Your Data and Technical Service Providers

In the course of our placement services, the following recipients may have access to your personal data:

  • Potential clients: As part of the placement process, we may share anonymised short profiles with potential clients. Your full name and contact details are only disclosed after your explicit consent. Business data (tax information, bank details) is never shared with clients.
  • Federal Central Tax Office (BZSt): In the context of statutory reporting obligations under the PStTG (see section "Tax Reporting Obligations").
  • Technical service providers: For the provision of our platform services (see below).

We use the following technical service providers for the operation of our platform:

  • Amazon Web Services (AWS) for hosting, cloud infrastructure, and AI-powered services (incl. Amazon Bedrock and Amazon Comprehend),
  • Plausible Analytics for web analytics,
  • Sentry for technical monitoring,
  • Google Maps for location search in the Expert Portal,
  • Wise for payment processing (when selected as payment method),
  • Video conferencing and telecommunications service providers for the conduct of Expert Calls.

We have concluded data processing agreements with all service providers according to Art. 28 DSGVO and ensure through appropriate safeguards that an adequate level of data protection is guaranteed even when processing in third countries.

Data Processing When Using Our Platform

Registration and Profile Management as an Expert

When registering and using our Expert Portal, we process personal data across several areas. The processing of this data is based on Art. 6 Abs. 1 lit. b DSGVO, as it is necessary for the performance of the placement contract.

Account Data:

During registration, we collect your first and last name as well as your email address(es). You can sign in via a magic link sent by email, or through Google or Microsoft (see section "Social Media and External Services").

As part of the onboarding form, we also collect further information, including title/salutation, phone number, your preferred role in the network, and supplementary details. The timestamps of your consent to the Privacy Policy and Terms and Conditions are stored for documentation purposes.

We send transactional emails (e.g., sign-in links, notifications) through our existing cloud infrastructure at AWS.

Profile Data:

As part of your expert profile, you may provide the following information in particular:

  • Profile picture,
  • Tagline (brief description of your expertise),
  • Main location (using Google Maps, see section "Google Maps"),
  • Summary and external links ("About Me" section),
  • Fee expectations,
  • Expertise entries (regions/countries, services offered, topic areas),
  • Industry experience,
  • Language skills,
  • LinkedIn profile URL.

Your profile is private by default. For details on how profile data may be shared with clients, see the section "Recipients of Your Data and Technical Service Providers".

Documents:

You can upload documents through the portal, including your CV / résumé (required) as well as optional portfolio / work samples and certificates / credentials. Uploaded documents are stored in encrypted form on our servers and used exclusively for assessing your qualifications and suitability for projects.

Project and Performance Data:

In the course of using the platform, we also process:

  • Project overviews and performance metrics,
  • Client feedback and testimonials that clients may submit after project completion regarding their collaboration with you,
  • Financial data (credit notes, payment history).

Project Readiness:

We track your Project Readiness as a checklist to facilitate your onboarding and ensure that all information necessary for project placement is available.

Settings:

In addition, we process your language and region preferences as well as display settings (e.g., portal appearance) to provide you with an optimal user experience.

Feedback:

You can provide feedback on the platform at any time using the feedback function in the portal. The data submitted is stored on our own infrastructure and used to improve our services.

Personal Data and Business Data

Through the "Settings" section of the Expert Portal, we collect additional personal and business data required for contract processing and the fulfilment of statutory reporting obligations.

Personal Data:

  • Legal name (first and last name, as shown on official documents),
  • Date of birth,
  • Nationality,
  • Country of birth,
  • Place of birth.

Your Role in the Network:

You select one of the following roles, which determines what further business data is collected:

  • Self-employed – Individual (freelancer or independent consultant),
  • Self-employed – Own company (owner/managing director of own consultancy),
  • Company representative (employee or partner, acts on behalf of a firm),
  • Network member only (not looking to take on projects at present – no business data required).

Business Address and Phone Number:

  • Business address and phone number (with country code).

Tax Information:

  • Tax residence (country),
  • Tax ID (TIN),
  • VAT ID (required for EU reverse charge),
  • Small business exemption status pursuant to § 19 UStG (if applicable).

To verify VAT IDs, we use the VIES service (VAT Information Exchange System) of the European Commission. The entered VAT ID is transmitted to servers of the EU Commission for this purpose.

Company Data (only for roles "Own company" or "Company representative"):

  • Company name,
  • Legal form,
  • Commercial register number (if available),
  • Name of the authorised representative.

Bank Details:

  • Account holder, selected payment method, and associated account details (e.g. IBAN or Wise account information).

If you select "Wise" as a payment method, data will be transmitted to Wise Payments Limited (United Kingdom) or Wise Europe SA (Belgium) for payment processing. For more information, please see Wise's privacy policy at: https://wise.com/gb/legal/global-privacy-statement

Legal Basis:

The processing of personal and business data is based on:

  • Art. 6 Abs. 1 lit. b DSGVO (contract performance) – insofar as the data is required for the preparation of offers, credit notes, and the processing of the collaboration,
  • Art. 6 Abs. 1 lit. c DSGVO (legal obligation) – insofar as the data is required to fulfil tax reporting obligations under the Platform Tax Transparency Act (Plattformen-Steuertransparenzgesetz, PStTG) (see section "Tax Reporting Obligations").

Registration as a Client

When contacting us through our "Find Experts" form, we collect information about the company and contact person, the expertise sought (regions, subject areas, services, and languages), the parameters of the collaboration (form of deployment, start date, duration, and intensity), as well as optional compensation preferences and additional project notes.

The processing of this data is based on Art. 6 Abs. 1 lit. b DSGVO, as it is necessary for the performance of the placement contract.

Tax Reporting Obligations (DAC7/PStTG)

As a platform operator for personal services, Geostrategists is subject to the reporting obligations of the Platform Tax Transparency Act (Plattformen-Steuertransparenzgesetz, PStTG), which implements the EU Directive DAC7 into German law.

We are legally required to report certain data of our experts to the Federal Central Tax Office (Bundeszentralamt für Steuern, BZSt) on an annual basis. The report is submitted by 31 January of the following year.

Depending on the expert type, the report includes:

For natural persons (Self-employed – Individual): first and last name, date of birth, address, Tax Identification Number (TIN), VAT ID (if available), bank details (IBAN or account number), and remuneration per quarter (amount, number of activities, fees withheld).

For legal entities (Self-employed – Own company / Company representative): company name and legal form, business address, Tax Identification Number (TIN) of the company, VAT ID, commercial register number (if available), bank details, and remuneration per quarter.

The report is submitted to the Federal Central Tax Office (BZSt) in Germany. For experts with tax residence in another EU Member State, the BZSt forwards the data to the competent tax authority of the respective Member State.

The legal basis is Art. 6 Abs. 1 lit. c DSGVO in conjunction with §§ 13 ff. PStTG (legal obligation). Data relevant for reporting purposes is retained for up to 10 years in accordance with statutory retention periods.

Referral Programmes

We offer two referral programmes in which personal data is processed:

Expert Referrals:

You can recommend colleagues for our expert network through a personalised invitation link. When the referred person registers through your link, your name is displayed to them as the referrer. We store the association between you and the referred person to track the recommendation.

Client Referrals:

You can recommend companies that could benefit from geopolitical expertise. When submitting a referral, you provide contact details of a company representative. Please ensure that the relevant person is aware of and agrees to their contact data being shared with us.

The processing is based on Art. 6 Abs. 1 lit. b DSGVO (contract performance within the referral programme). For third-party contact data entered by you, we rely on Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in business development).

Use of Artificial Intelligence

We employ artificial intelligence (AI) methods to improve the quality of our placement services. The following processing activities may occur in particular:

  • Support in the assessment and verification of expert profiles,
  • Evaluation of applications and qualification documents,
  • Optimisation of matching between experts and project enquiries,
  • Analysis and preparation of profile data for quality assurance purposes, as well as AI-powered assistance features to support the description of expertise and project requirements.

For these purposes, we use AI services within our existing Amazon Web Services (AWS) cloud infrastructure in the EU, in particular Amazon Bedrock and Amazon Comprehend. In addition, we may use AI-powered tools in our internal processes to support the assessment of expert profiles and quality assurance.

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 DSGVO). AI-supported analyses serve exclusively to support human decision-making processes. The final assessment of profiles and applications is always carried out by our team.

The legal basis is Art. 6 Abs. 1 lit. f DSGVO (legitimate interest). Our legitimate interest lies in the efficient and high-quality placement of experts.

Data Processing for Expert Calls

Expert Calls are time-limited, oral knowledge transfer sessions in which an expert conveys their specialist knowledge to a client of Geostrategists or its end client. In the course of placing, organising, and conducting Expert Calls, we process personal data as follows:

Matching: When assigning an expert to an Expert Call, we process your name, professional qualifications, and, where applicable, your fee expectations in order to provide the client with an anonymised or – with your prior consent – personalised expert profile. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (contract performance).

Compliance screening: Prior to the call, we may send you project-specific screening questions, in particular regarding potential conflicts of interest or contractual obligations. Compliance and conflict-check data is used exclusively internally. Responses to qualification-related screening questions may be disclosed to the client as part of the matching process. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (contract performance) in conjunction with Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in compliance with regulatory requirements).

Conduct: For the conduct of Expert Calls, we use video conferencing and telecommunications services, which may involve the processing of technical data (IP address, connection data, participant metadata). The legal basis is Art. 6 Abs. 1 lit. b DSGVO (contract performance).

Recording: Expert Calls may be recorded and/or transcribed with your prior consent. You will be informed of any recording before the call begins. Recordings and transcripts are stored on our cloud infrastructure at Amazon Web Services (AWS) within the EU and are used exclusively for quality assurance, compliance review, and – where agreed on a case-by-case basis – provision to the client for its internal purposes. Recordings and transcripts are deleted 12 months after the Expert Call unless statutory retention obligations apply. The legal basis is Art. 6 Abs. 1 lit. a DSGVO (consent). You may withdraw your consent at any time with effect for the future.

Data disclosure: Before the call, the client receives an anonymised or – with your consent – personalised expert profile. During the call, the information and assessments you share are accessible to the client. After the call, a transcript or summary may be provided where agreed. The client is contractually obligated to treat the data received confidentially. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (contract performance).

Data retention: We retain your contact details, professional qualifications, and remuneration data beyond the individual Expert Call in order to contact you for future Expert Calls. The legal basis is Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in maintaining the business relationship and contacting you for future Expert Calls). You may object to this processing at any time; in such case, we will no longer contact you for Expert Calls and will delete your data unless statutory retention obligations apply.

Documentation: We document the conduct of Expert Calls (date, duration, participants, topic, compliance status) for contract administration and compliance documentation purposes. Compensation from Expert Calls is subject to reporting obligations under the PStTG (see section "Tax Reporting Obligations"). The legal basis is Art. 6 Abs. 1 lit. b DSGVO (contract performance) in conjunction with Art. 6 Abs. 1 lit. c DSGVO (legal obligation).

Storage Duration

We process and store your personal data only for the period necessary to fulfil the storage purpose or as required by legal provisions.

The following retention periods apply to the individual data categories:

  • Profile data, documents, and project data: For the duration of your active membership in the network. After the end of the active business relationship, this data is deleted after 6 months unless legal retention obligations prevent this.
  • Business data (tax information, bank details): For the duration of the collaboration and subsequently in accordance with statutory retention periods of up to 10 years (§§ 147 AO, 257 HGB).
  • Data from tax reporting obligations (DAC7/PStTG): Up to 10 years in accordance with statutory retention periods.
  • Referral data: For the duration of your active membership and the term of the respective referral programme.
  • Expert Call data: Contact details, professional qualifications, and remuneration data are retained for the duration of the business relationship; call documentation (date, duration, participants, topic, compliance status) in accordance with statutory retention periods of up to 10 years; recordings and transcripts 12 months after the respective Expert Call unless statutory retention obligations apply.
  • Automatically collected data and Sentry data: Generally within 90 days.

Storage beyond these periods may occur in particular if:

  • It is necessary for the fulfilment of contractual obligations,
  • Legal retention obligations require it,
  • You have consented to longer storage,
  • It is necessary for the establishment, exercise, or defence of legal claims.

International Data Transfers

Principles

We generally process your data in Germany or the European Union. Should a transfer to third countries occur, we ensure that this only happens under the strict requirements of Art. 44 ff. DSGVO.

International Data Transfers and Safeguards

For any data transfers to the USA (e.g., in the context of maintenance and support by our technical service providers), we rely on:

  • The EU-US Data Privacy Framework,
  • EU Standard Contractual Clauses according to Art. 46 Abs. 2 lit. c DSGVO,
  • Appropriate safeguards according to Art. 46 DSGVO,
  • Binding corporate rules according to Art. 47 DSGVO.

In addition, profile data may be shared with potential clients based outside the EEA as part of the placement process. This only occurs with your explicit consent and on the basis of Art. 49 Abs. 1 lit. a DSGVO (explicit consent) or Art. 49 Abs. 1 lit. b DSGVO (contract performance).

Furthermore, within the scope of the tax reporting obligations (see section "Tax Reporting Obligations"), personal data is transmitted to the Federal Central Tax Office (BZSt), which forwards this data to the competent foreign tax authority if the expert has tax residence in another EU Member State.

We ensure through appropriate contractual agreements and technical and organisational measures that an adequate level of data protection is guaranteed even when data is processed in third countries.

Social Media and External Services

Google and Microsoft Sign-In

You can alternatively sign in to our Expert Portal using your existing Google or Microsoft account ("Continue with Google" or "Continue with Microsoft"). In doing so, the following data is retrieved from the respective provider via the OAuth protocol:

  • Name,
  • Email address,
  • Profile picture (where provided by the sign-in provider; only stored if you choose to adopt it as your profile picture),
  • Where available, gender and date of birth.

This data is used exclusively for authentication and account linking purposes. No further synchronisation with your Google or Microsoft account takes place.

The data processing is based on Art. 6 Abs. 1 lit. b DSGVO (contract performance – provision of the sign-in process). For more information on data processing, please see the privacy policies of the respective providers:

Social Media Presences

We maintain presences on various social networks. When you visit these, personal data may be transmitted to the respective platform operators.

Technical and Organisational Measures

To protect your personal data, we have implemented appropriate technical and organisational security measures in accordance with Art. 32 DSGVO:

  • Encryption through end-to-end SSL/TLS encryption of the website and all data transfers,
  • Access control through strictly regulated access rights and two-factor authentication,
  • Data security through regular backups and redundant systems,
  • Availability control through protection against technical disruptions and DDoS attacks,
  • Separation requirement through separate processing of data for different purposes,
  • Regular security audits and penetration tests,
  • Training and sensitisation of our employees.

Your Rights as a Data Subject

You have the following rights:

  • Right to information (Art. 15 DSGVO),
  • Right to rectification (Art. 16 DSGVO),
  • Right to erasure (Art. 17 DSGVO),
  • Right to restriction of processing (Art. 18 DSGVO),
  • Right to data portability (Art. 20 DSGVO),
  • Right to object (Art. 21 DSGVO),
  • Right to withdraw given consent (Art. 7 Abs. 3 DSGVO).

To exercise your rights, please contact us using the contact details provided above.

You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.

Changes to the Privacy Policy

We continuously develop our services. In doing so, we reserve the right to adapt this privacy policy to ensure that it always complies with current legal requirements and transparently reflects our services and their data processing.

Changes may arise in particular due to:

  • Further development of our services,
  • Adaptation to new technologies,
  • Changes in the legal situation,
  • Optimisation of our processes.

The current version of this privacy policy can always be found at https://www.geostrategists.de/en/privacy.