Legal
Privacy Policy
How this website handles personal data.
Last updated: 5 September 2026
The German version is the binding one. This English text is provided for information only. In the event of any discrepancy, the German version prevails. Read the German version
1. Controller
The controller within the meaning of the General Data Protection Regulation is:
Lukas Höver Mathiasstraße 10 50676 Köln Germany
Telephone: 0176 42410567 Email: kontakt@lukashoever.de
No data protection officer has been appointed, as the statutory conditions for this are not met.
2. General information
Personal data is all data relating to an identified or identifiable natural person. This policy describes which data is processed when you visit this website and use its offerings, for what purpose and on what legal basis.
Transmission is encrypted throughout via TLS. Completely gap-free security of data transmission on the internet cannot be guaranteed.
Processing only takes place insofar as it is necessary to provide the respective function. On automated fraud prevention during payment, see section 9.3.
3. Cookies and storage on your device
This website sets no cookies — neither for analytics or advertising purposes nor technically necessary ones. There is no session management, no login and no shopping basket. No reach measurement or web analysis takes place; no analytics tools are integrated.
A consent banner is therefore not required.
The only storage on your device concerns drafts of the enquiry form; see section 7.
4. Visiting this website (hosting)
This website is hosted by:
Netlify, Inc. 512 2nd Street, Suite 200 San Francisco, CA 94107, USA
When you visit, the hosting provider automatically records server log files. Processed in this context are the IP address of the requesting device, the date and time of access, the page requested, the volume of data transferred, the page visited previously, and the browser type and operating system.
The purpose is the secure, stable and trouble-free operation of the website as well as the prevention and investigation of attacks. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the aforementioned purposes.
A data processing agreement under Art. 28 GDPR is in place with Netlify. On transfer of data to the United States, see section 12.
Access logs including IP addresses are stored by the hosting provider for less than 30 days. Logs of the server functions are retained for between 24 hours and seven days depending on the plan.
Email mailbox
The mailbox reachable at kontakt@lukashoever.de is operated by netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. All correspondence addressed there is stored on their systems. The servers are located in Germany; no transfer to third countries takes place.
5. Typefaces
The typefaces used, “Instrument Serif” and “Karla”, are served exclusively from this server. No connection to Google Fonts or any other third-party provider is established; no IP address is transmitted to third parties in this context.
6. Audio samples (YouTube)
Audio samples provided via YouTube are embedded on this website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The videos are not loaded automatically. As long as you do not click on an audio sample, no connection to YouTube is established and no information leaves your browser.
Only when you click on an audio sample is a connection to YouTube established in privacy-enhanced mode (youtube-nocookie.com). Your IP address is transmitted to the provider in the process; the provider learns that you have called up the page in question. If you are signed in to your Google account at the same time, the request may be associated with your account. According to the provider, privacy-enhanced mode prevents cookies from being set for personalisation purposes before playback, but does not entirely exclude processing.
The legal basis is your consent, given by clicking on the audio sample, Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG. You may withdraw this consent at any time with effect for the future by not calling up any further audio samples.
On data processing by the provider see https://policies.google.com/privacy. On transfer to the United States see section 12.
Links to YouTube, Spotify, Instagram and the NRWision media library are simple references. No widgets, feeds or counting pixels of these services are embedded; merely visiting this website transfers no data to them.
7. Enquiry form for weddings and church services
7.1 Details processed
The following details can be submitted via the enquiry form:
Mandatory: date of the ceremony, church, town, names, email address.
Optional: time, whether the parish provides its own organist, the desired forces, musical requests, telephone number, and how you came across this offer.
7.2 Purpose, legal basis and special categories of data
The details are processed exclusively to handle your enquiry and to prepare a possible contract. The legal basis for this is Art. 6 (1) (b) GDPR.
Details about a church wedding, the church and musical requests may allow conclusions to be drawn about religious beliefs. As special categories of personal data, such data enjoys heightened protection under Art. 9 GDPR. It is processed exclusively on the basis of your explicit consent under Art. 9 (2) (a) GDPR, which you give separately in the form.
You are not obliged to provide this data; without it, however, a meaningful handling of an enquiry for a church wedding is not possible. You may withdraw your consent at any time with effect for the future without any disadvantage to you; the lawfulness of processing carried out up to that point remains unaffected.
7.3 Transmission and storage
No external form service is used for the form. The details submitted are forwarded directly as an email to the mailbox named in section 4 by a server function of our own. The server function does not store the details; they exist solely in that mailbox.
The data is deleted as soon as the purpose of storage no longer applies, that is once the enquiry has been finally dealt with and no statutory retention obligations stand in the way.
7.4 Saving a draft in the browser
The enquiry form runs over several steps. So that entries are not lost if you leave the page inadvertently, you can store them locally in your browser’s storage using the button “Entwurf in diesem Browser sichern” (save a draft in this browser).
This happens exclusively upon your express action, not automatically. The data is not transmitted to the server, does not leave your device, and is deleted once the form has been sent.
The legal basis is your consent under § 25 (1) TDDDG, given by pressing the button.
7.5 Spam protection
To protect against automated submissions, the form contains an additional field not visible to you as well as a check on how long completion took. Both procedures work exclusively locally; no data is transmitted to third parties. In particular, no service such as Google reCAPTCHA is used.
8. Free arrangement and occasional updates
8.1 Signing up
Only your email address is collected in order to receive the free arrangement and occasional notices about new arrangements. No further details are requested.
Registration takes place using the double opt-in procedure: after signing up you receive an email asking you to confirm your registration. Only after this confirmation is the address added to the mailing list. If confirmation is not given, the address is not added to the mailing list; the confirmation link expires after 30 days. Until then the sign-up attempt is recorded only in the delivery log of the provider named in section 8.4 and is deleted together with it (section 11).
To evidence consent, the time and IP address of the registration and of the confirmation are stored.
The legal basis is your consent under Art. 6 (1) (a) GDPR; the logging of the evidence is based on Art. 6 (1) (c) GDPR in conjunction with Art. 5 (2) and Art. 7 (1) GDPR.
8.2 Scope and withdrawal
The consent covers the one-off sending of the arrangement offered as well as occasional notices about new arrangements, a few times a year.
You may withdraw your consent at any time with effect for the future. The unsubscribe link at the end of every message is sufficient, as is an informal message to kontakt@lukashoever.de. The lawfulness of processing carried out up to the withdrawal remains unaffected.
After unsubscribing, the address is added to a suppression list so that it is not inadvertently contacted again. The legal basis for this is Art. 6 (1) (f) GDPR; the legitimate interest lies in respecting your objection.
The suppression list is maintained permanently for as long as the mailing list exists. Removal from it takes place only upon express request; the consequence would be that the address could be contacted again.
8.3 Recording of opens and clicks
No measurement of success relating to identified individuals takes place. It is not evaluated who opened a message or who clicked which link. No usage profiles are created, and the content of the messages is not personalised on this basis.
Technically, this recording cannot be switched off entirely at the delivery service provider used. Every message contains a counting pixel, and the links it contains are routed via a domain belonging to the provider. The provider uses this to monitor delivery and to prevent abuse; according to the provider, deactivation is not available for that reason.
Recording relating to identified individuals is therefore switched off in the account: opens and clicks are attributed only to those recipients who have expressly consented — and no such consent is obtained. What remains visible are aggregate rates without any personal reference. In addition, the provider stores the date of the last open for each address; this serves solely to assess deliverability.
The legal basis for this remaining processing is Art. 6(1)(f) GDPR; the legitimate interest lies in ensuring deliverability and in preventing abuse.
8.4 Delivery service provider
Brevo is used for delivery. The contracting party is Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany, registered in the commercial register of the Local Court of Berlin-Charlottenburg under HRB 133191, a subsidiary of Sendinblue SAS, 9–17 rue Salneuve, 75017 Paris, France.
Storage and delivery take place on servers in the European Union, predominantly in Germany and France. A data processing agreement under Art. 28 GDPR is in place with the provider; it forms part of its terms of service.
The provider in turn engages sub-processors, including companies established in the United States — among others for content delivery, attack protection and customer support — as well as a group company in India. Access from these countries can therefore not be ruled out. The provider bases these transfers on the European Commission’s standard contractual clauses, in part supplemented by the adequacy decision on the EU-US Data Privacy Framework. The list of sub-processors in force at any given time is published in the provider’s terms of service.
9. Sheet music shop
9.1 Order and performance of the contract
When you place an order, your name, email address and country are processed together with the details of the work ordered. No billing address is collected. The purpose is performance of the contract of sale; the legal basis is Art. 6 (1) (b) GDPR.
No customer account is created; purchases are made as a guest.
For processing, an order record is created containing exclusively: order number, title of the work, time, name of the purchaser, a check value of the download token, and the expiry date. It contains no payment data. The record is stored in the hosting provider’s storage service and is deleted after the 30-day download period has expired.
9.2 Payment processing via Stripe
Payment is processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
The data required for payment is transmitted to Stripe, in particular name, email address, country and invoice amount as well as the payment details you choose. The actual payment data — such as credit card numbers — is processed exclusively by Stripe and is at no point visible to the controller.
The legal basis is Art. 6 (1) (b) GDPR. Insofar as Stripe processes data for its own purposes, in particular for fraud prevention and to fulfil its own regulatory and anti-money-laundering obligations, Stripe is an independent controller in that respect. Details at https://stripe.com/privacy. On transfer to the United States see section 12.
9.3 Automated fraud prevention
Stripe checks payment transactions automatically for indications of fraud. Among other things, technical characteristics of the payment transaction, details of the means of payment used and behavioural patterns are evaluated. Conspicuous transactions may be rejected automatically or held for review.
The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in avoiding payment defaults and abusive transactions, as well as Art. 6 (1) (c) GDPR insofar as Stripe thereby fulfils its own statutory obligations.
If a payment is rejected on this basis, you may contact kontakt@lukashoever.de to request a review involving a natural person, to express your point of view and to contest the decision.
9.4 Invoicing
Invoices are created via Stripe Invoicing and archived there. They are also transmitted for accounting purposes to Haufe-Lexware GmbH & Co. KG (lexoffice), Munzinger Straße 9, 79111 Freiburg, Germany.
The legal basis is Art. 6 (1) (c) GDPR in conjunction with commercial and tax law retention and record-keeping obligations.
9.5 Personalisation of the files
The PDF files provided are marked automatically with your name and the order number each time they are retrieved. The marking is visible in the file.
The purpose is to protect the works against unauthorised distribution and to make it possible to determine the source in the event of unauthorised dissemination. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in protecting our own and the licensed copyrights.
A personalised file is not stored permanently but generated anew each time it is retrieved. When the order record is deleted after 30 days, the basis for any further personalisation ceases to exist. No evaluation of the marking beyond this takes place.
9.6 Provision of the download
After successful payment, a message containing a personal download link is sent to the email address you provided. The link carries a signed, non-guessable token, is valid for 30 days and is limited in the number of retrievals. The stored work files are not publicly addressable; every access takes place via a server function of our own.
This message is sent via the provider named in section 8.4. The download link may be contained in that provider’s delivery logs; once the validity period has expired it leads nowhere.
The retention period for the delivery logs is set to three months. That is long enough to trace delivery problems and keeps short the period during which a download link appears in a log.
The legal basis is Art. 6 (1) (b) GDPR.
9.7 Documentation of the withdrawal consent
During the ordering process, your express consent to the immediate commencement of performance of the contract and your confirmation of awareness of the associated loss of the right of withdrawal are obtained (§ 356 (5) of the German Civil Code). The consent and the time are stored.
The purpose is to evidence that the statutory conditions for the expiry of the right of withdrawal have been met. The legal basis is Art. 6 (1) (c) GDPR in conjunction with the aforementioned provisions as well as Art. 6 (1) (f) GDPR on the basis of the legitimate interest in securing evidence.
10. Recipients of the data
Personal data is only passed on insofar as this is necessary to fulfil the purposes described or where there is a statutory obligation.
| Recipient | Purpose | Location | Third country |
|---|---|---|---|
| Netlify, Inc. | Hosting, server functions, order records, work files | USA | yes |
| Stripe Payments Europe Ltd. | Payment processing, invoicing | Ireland | transfer to the USA |
| Google Ireland Limited | Audio samples, only after a click | Ireland | transfer to the USA |
| Brevo GmbH | Email and mailing list delivery | Germany, servers in the EU | access by sub-processors in the USA and India |
| netcup GmbH | Email mailbox | Germany | no |
| Haufe-Lexware GmbH & Co. KG | Accounting, invoice archiving | Germany | no |
Data is never sold and never passed on for advertising purposes.
11. Retention periods at a glance
| Data | Period |
|---|---|
| Server log files | less than 30 days |
| Order record with name and token | 30 days from provision, then deleted |
| Personalised PDF file | not stored |
| Invoice and accounting data | 8 years, following the statutory retention period |
| Evidence of the withdrawal consent | for the duration of possible legal claims |
| Enquiries from the form | until finally dealt with |
| Mailing list address | until consent is withdrawn |
| Suppression list after unsubscribing | permanently, for as long as the mailing list exists |
| Delivery logs | 3 months |
12. Transfer of data to third countries
When using the services of Netlify, Stripe and Google named in section 10, personal data is transferred to the United States.
For these three recipients, the transfer is based on the adequacy decision of the European Commission of 10 July 2023 concerning the EU-US Data Privacy Framework. Netlify, Inc., Stripe, Inc. and Google LLC are certified under this framework and maintain an active certification in the list kept by the US Department of Commerce.
At the delivery service provider (section 8.4), storage and delivery take place within the European Union. Access by sub-processors in the United States and in India can nevertheless not be ruled out. The provider bases these transfers on the European Commission’s standard contractual clauses, in part supplemented by the EU-US Data Privacy Framework.
Despite these safeguards, the level of data protection in the United States is not fully comparable with European law. In particular, authorities may under certain conditions access data without equivalent legal remedies being available.
13. Your rights
You have the following rights vis-à-vis the controller:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate or incomplete data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent given with effect for the future (Art. 7 (3) GDPR); the lawfulness of processing carried out up to the withdrawal remains unaffected
- Complaint to a supervisory authority (Art. 77 GDPR)
An informal message to kontakt@lukashoever.de is sufficient for any of these.
Note on the right to object under Art. 21 GDPR
Where personal data is processed on the basis of legitimate interests under Art. 6 (1) (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing. The data concerned will then no longer be processed unless compelling legitimate grounds for the processing can be demonstrated which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Competent supervisory authority
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestraße 2–4 40213 Düsseldorf, Germany
Irrespective of this, you have the right to complain to any other supervisory authority, in particular at your habitual residence or the place of the alleged infringement.
14. Changes to this policy
This privacy policy is adjusted when the processing described or the legal position changes. The version available on this page at any given time applies.