Back to home

Privacy policy

1. Privacy at a glance

General information

The protection of your personal data is important to us. The following notes provide an overview of which personal data is processed when you visit this website and use our offerings.

Personal data is any information that can be used to personally identify you.

2. Controller

The party responsible for data processing on this website is:

Designcore Consulting FZCO represented by Diana Hirt
Building A1, Dubai Digital Park, Dubai Silicon Oasis
Dubai, United Arab Emirates
License No.: 62719
Email: info@dianahirt.com

3. Collection and processing of personal data

Personal data is collected, on the one hand, when you provide it to us — for example via a contact form, by email, or as part of booking an appointment.

Other data is collected automatically by our IT systems when you visit the website. This may include, in particular, your IP address, browser type, operating system, referrer URL, and the date and time of access.

This processing serves in particular the technical provision and security of the website, the handling of enquiries, appointment scheduling, and the initiation and performance of contracts, as well as — where consent has been given — analysis or marketing purposes.

4. Legal bases

Where the General Data Protection Regulation (GDPR) applies, the processing of personal data is based in particular on:

Where consent is required for certain technologies, they are only used after such consent has been given.

5. Hosting

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.

When you visit the website, the hosting provider may process technical data, in particular IP addresses, server log files, and information about the browser and operating system used.

This processing serves the purpose of providing the website securely, reliably and efficiently.

Vercel may process personal data in the USA. The applicable data-protection requirements apply to such transfers, for example appropriate safeguards such as standard contractual clauses.

Where required, corresponding data-protection agreements are concluded with the service providers used.

6. Getting in touch

If you contact us via the contact form, email, or other means of communication, the data you provide is processed to handle your enquiry and any follow-up questions.

Where your enquiry serves the initiation or performance of a contract, processing is based on Art. 6(1)(b) GDPR. Otherwise, processing may be based on our legitimate interest in handling business enquiries pursuant to Art. 6(1)(f) GDPR.

7. Contact form via Resend

For the technical delivery of our contact form by email, we use the service Resend (Resend, Inc., USA).

When you use the contact form, the data you enter — in particular name, email address, phone number, your message, and any documents you upload — is delivered to us by email via Resend.

This processing serves the purpose of handling your enquiry pursuant to Art. 6(1)(b) or (f) GDPR.

Resend may process personal data in the USA. The applicable data-protection requirements apply to such transfers, for example appropriate safeguards such as standard contractual clauses.

8. Booking via Calendly

We use Calendly for online appointment booking.

When you book an appointment, the data you enter — such as name, email address, appointment details and any further information you provide — is transmitted to Calendly and processed to organise and carry out the appointment.

This processing is based in particular on the initiation or performance of a contract pursuant to Art. 6(1)(b) GDPR.

Calendly may process personal data outside the European Union or the European Economic Area. The applicable data-protection requirements apply to such transfers.

9. Payment processing via Stripe

We use Stripe for payment processing.

When a payment is made, the data required for payment processing is processed directly by Stripe. This may include, in particular, name, contact details, payment information, billing data, and technical transaction data.

This processing serves the purpose of payment processing and contract performance pursuant to Art. 6(1)(b) GDPR, and where applicable, the fulfilment of legal obligations.

Payment data is generally processed by the payment service provider. We only receive the information required to process and allocate the payment.

10. Cookies and similar technologies

This website may use cookies and comparable technologies.

Technically necessary technologies are used insofar as they are required to provide the website and ensure its functionality.

Non-essential cookies or technologies, in particular for analysis, tracking or marketing purposes, are only used — where legally required — after you have given your consent.

Consent given can be withdrawn at any time with future effect, or adjusted via the cookie settings.

11. Transfers to third countries

In the course of using individual service providers, personal data may be processed outside the European Union or the European Economic Area.

Any such transfer takes place only in compliance with the applicable data-protection requirements, for example on the basis of an adequacy decision, appropriate safeguards, or other legally provided transfer mechanisms.

As the responsible company is based in the United Arab Emirates, personal data may also be processed in the United Arab Emirates.

12. Recipients of personal data

Personal data is only disclosed where this is required for the performance of contractual or legal obligations, where corresponding consent has been given, or where another legal basis for disclosure exists.

Recipients may include, in particular, hosting, IT, appointment-booking and payment service providers, as well as other service providers required for contract performance.

13. Retention period

Personal data is only stored for as long as necessary for the respective processing purpose, or as required by statutory retention periods.

Once the purpose of processing no longer applies and no statutory retention obligations remain, the relevant data is deleted.

14. Your rights

Where the GDPR applies, you have in particular the right to access your stored personal data, to rectify inaccurate data, to erasure, to restriction of processing, and to data portability.

You also have the right to object, under the statutory requirements, to processing based on legitimate interests.

Consent given can be withdrawn at any time with future effect. The lawfulness of processing carried out until the withdrawal remains unaffected.

In addition, you have the right, under the statutory requirements, to lodge a complaint with a competent data-protection supervisory authority.

15. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption.

You can recognise an encrypted connection in particular by the fact that the browser's address bar begins with "https://".

16. Objection to promotional emails

We hereby object to the use of the contact details published within this legal notice and this privacy policy for sending unsolicited advertising and information material.

The operator expressly reserves the right to take legal action in the event of unsolicited advertising, in particular through spam emails.

Last updated: September 2026