Legal
Privacy Policy
Privacy at a glance. This website deliberately does without cookies, tracking tools, external fonts and embedded third-party content. Your browsing behaviour is not analysed. A cookie banner is therefore not required.
Note: The legally binding version is the German privacy policy. This English text is provided for convenience. Statutory references (e.g. Art. 6 GDPR) refer to the EU General Data Protection Regulation (GDPR / German: DSGVO).
1. Controller
The party responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
COREFLECTION
Michael Kessler
Warneckstraße 6
10713 Berlin, Germany
E-mail: contact@coreflection.com
2. Principle of data minimization
This website is deliberately designed to be data-minimal. We process personal data only insofar as this is technically strictly necessary for the operation of the website or where you actively contact us. No usage profiles are created, no cookies are set for analytics or marketing purposes, and no third-party content (e.g. external fonts, video players, maps) is loaded.
3. Hosting
The content of this website is provided as static pages. We use the following provider for delivery.
Cloudflare Pages
The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).
Cloudflare Pages is a service through which static websites are delivered. The data transfer between your browser and our website is routed through Cloudflare's global network. In this process, technical log data (e.g. IP address, date and time of access, requested file, browser type) may be processed in order to minimize loading times, ensure performance and defend against attacks on our infrastructure. This data is not analysed for statistical purposes. The log data is deleted automatically by Cloudflare after a short period; we do not access personal log data.
The use of Cloudflare Pages is based on Art. 6 (1) lit. f GDPR. We have a legitimate interest in providing our website as error-free, fast and secure as possible.
Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF). Data transfer to the USA takes place primarily on this basis; in addition, the Standard Contractual Clauses of the EU Commission are applied. Details can be found here: www.cloudflare.com/cloudflare-customer-scc.
Data processing on behalf: We have concluded a data processing agreement (Data Processing Addendum) with Cloudflare to ensure compliance with European data protection standards.
4. Domain & e-mail service
The domains associated with this website and the e-mail mailbox (contact@coreflection.com) are managed by Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (hereinafter “Strato”). Strato does not deliver the content of this website — hosting is provided via Cloudflare Pages (see section 3). Data processing by Strato relates exclusively to domain management and to the e-mail correspondence you send to the above address.
Further information can be found in Strato's privacy policy: www.strato.de/datenschutz.
Use is based on Art. 6 (1) lit. f GDPR (legitimate interest in a reliable domain and e-mail service) and Art. 6 (1) lit. b GDPR, insofar as the communication serves the initiation or performance of a contract.
Data processing on behalf: A data processing agreement (Art. 28 GDPR) is in place with Strato, ensuring that personal data is processed only according to our instructions and in compliance with the GDPR.
5. Contact by e-mail
If you contact us via the e-mail addresses provided on this website or via the contact buttons, your local e-mail program opens with a prepared message. No automatic data transfer to us takes place at this point. You decide yourself, deliberately, what information you provide and whether you send the message.
We process exclusively the data you transmit to us in your message — as a rule your name, your e-mail address and the content and context of your enquiry.
Legal basis: Art. 6 (1) lit. b GDPR (initiation or performance of a contract) and Art. 6 (1) lit. f GDPR (legitimate interest in processing your enquiry).
We store your enquiry and the associated data until the purpose of processing ceases to apply and no statutory retention obligations conflict with deletion.
6. Communication & consulting services
As part of service delivery — not on this website — we use the following services for conversations and collaboration with clients. They are used exclusively after a prior appointment has been arranged and with your knowledge:
Zoom
For video and telephone conferences we use “Zoom” by Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Depending on the configuration, metadata, audio, video and, where applicable, text data are processed during participation.
Legal basis: Art. 6 (1) lit. b GDPR (performance of the commissioned service). A data processing agreement (Art. 28 GDPR) is in place with the provider. Zoom is certified under the EU-U.S. Data Privacy Framework.
Microsoft Teams
Alternatively, we use “Microsoft Teams” by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Here too, the connection and communication data required to conduct the conference are processed.
Legal basis: Art. 6 (1) lit. b GDPR. A data processing agreement (Art. 28 GDPR) is in place with the provider. Microsoft is certified under the EU-U.S. Data Privacy Framework.
Any data transfer to third countries is based primarily on the EU-U.S. Data Privacy Framework and, in addition, on the EU Standard Contractual Clauses. For confidential consulting content, we choose the appropriate channel agreed with you.
7. Use of Artificial Intelligence (AI) & confidentiality
Confidential client content is, as a matter of principle, processed without personal data — identifying details are removed in advance or not collected in the first place. The protection of confidentiality takes absolute priority — over any efficiency consideration.
Where AI is used to support preparation and follow-up, the service anymize serves as an additional technical safeguard: personal data is automatically anonymized before it reaches an AI (e.g. GPT, Claude, Gemini). The anonymization runs on servers in Germany.
The service provider is anymize (anymize.ai). A data processing agreement (Art. 28 GDPR) is in place with the provider, supplemented by an agreement on the obligation to maintain confidentiality.
Collaboration without digital tools: On request, collaboration takes place entirely without digital tools. The choice of working framework is yours.
Confidentiality & professional ethics: As an executive coach and sparring partner, I am bound to confidentiality towards my clients — on the basis of the ethical guidelines of the Systemic Society (Systemische Gesellschaft, SG) and the German Federal Association of Coaching (Deutscher Bundesverband Coaching, DBVC), as well as a contractual ancillary duty of every mandate. Confidential content is treated with the utmost care and discretion.
8. Presence on social networks
We maintain profiles on professional networks. From this website we merely link to these profiles — no social media plugins, buttons or scripts that would transfer data upon merely visiting this website are embedded. Data processing by the networks only takes place once you actively click the link and visit the respective platform.
- LinkedIn – LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
- Xing – New Work SE, Am Strandkai 1, 20457 Hamburg, Germany
The respective privacy policies of the providers apply to data processing on these platforms.
9. Your rights as a data subject
Within the framework of the statutory provisions, you have the following rights:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
To exercise your rights, an informal message to contact@coreflection.com is sufficient.
Right to object
Insofar as we process data on the basis of legitimate interests (Art. 6 (1) lit. f GDPR), you have the right to object at any time for reasons arising from your particular situation.
Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, Germany.
10. Data security (SSL/TLS encryption)
For security reasons, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the “https://” in the address bar of your browser.
11. Image credits
Michael Kessler (photo) · www.coreflection.com
Peter Werner Images (photo) · www.wernerimages.com
12. Currency of this policy
We update this privacy policy as soon as changes to data processing or the legal situation require it.
Status: July 2026