PRIVACY POLICY
Privacy Policy
Welcome to my Privacy Policy.
In the following text, you will find all the information about how I process your data, as well as any other details you are entitled to under the GDPR.
Responsible Party
Let's start with the responsible party. I am responsible for collecting and processing your data.
My name is Sarah — you can reach me at: hi@mokkaa.at
If you prefer postal mail, I am happy to provide you with our full business address in 8046 Zurich, Switzerland, upon request.
In case you’re wondering why our domains sometimes end with ".ch" and other times with ".at": this is because I originally started building the business in Austria, and later expanded it in Switzerland. The main email address has remained with the AT domain, but for our website, we prefer to use the CH domain.
Purposes of Data Processing
If you are interested in my work or products, you can sign up for my associated newsletter. The data collected for this purpose is shown in the corresponding form. Newsletters are only sent with your consent. You can unsubscribe at any time — either by contacting me directly or via the unsubscribe button in each email.
The main purpose of data processing is the fulfillment of our contractual agreement. If you purchase a product or service from me, I require the necessary data in order to fulfill the contract. The required data is clearly indicated in the form or contract.
For all supporting applications, the principle of data minimization applies — only the data necessary for the task is collected and processed.
Cookies
Cookies are text files that are stored on your computer system via an internet browser. Using cookies allows me to offer you more user-friendly services that would not be possible without cookies, and to improve the site experience.
You can prevent the setting of cookies at any time by adjusting your browser settings and can also delete cookies at any time. Please note that blocking cookies may result in some functions on my website not being fully available.
Where else is your data processed?
1. Digistore24
I use Digistore24 to process payments. When you purchase or book a product or service, your data is processed via Digistore24’s servers and software, in accordance with EU standards.
When you click on one of my product buttons, you will leave my website and be redirected to my individual sales page hosted by Digistore24.
Digistore24 GmbH
St.-Godehard-Straße 32
31139 Hildesheim, Germany
Digistore24 Privacy Policy: https://news.digistore24.com/privacy
I have signed a Data Processing Agreement with this provider.
Please also refer to Digistore24’s privacy notice on their sales pages.
2. Purposes of Data Processing
If you are interested in my work or products, you can sign up for my associated newsletter. The data collected for this purpose is displayed in the relevant form. Emails and newsletters are only sent with your consent. You can unsubscribe at any time — either by contacting me directly or by clicking the unsubscribe button in the email.
The primary purpose of data processing is to fulfill the contract between us. If you purchase a product or service from me, I need certain data to perform this contract. The required data is shown in the respective form or contract.
For all supporting applications, I always follow the principle of data minimization: each processor receives and processes only the data necessary for the specific purpose.
3. Cookies
Cookies are text files that are stored on your computer system via an internet browser. By using cookies, I can provide you with a more user-friendly service that would not be possible without cookies, and I can optimize my offerings for you as a user.
You can prevent the setting of cookies at any time by configuring your browser settings accordingly and can also delete cookies at any time through your browser or other software. If you block cookies, it is possible that some functions of my website may not be fully available.
4. Where else is your data processed?
1. Digistore24
To offer you a seamless purchase experience, I use Digistore24 as my payment processor. If you purchase a product or service from me, your data will be processed via Digistore24’s servers in accordance with EU standards.
When you click on one of my product buttons, you will leave my website and be redirected to my individual sales page hosted by Digistore24.
Digistore24 GmbH
St.-Godehard-Straße 32
31139 Hildesheim, Germany
Privacy Policy: https://news.digistore24.com/privacy
I have signed a Data Processing Agreement with this provider.
Please also review Digistore24’s privacy policy on their sales page.
2. ActiveCampaign
I use ActiveCampaign to send you newsletters and email updates — both free and paid. You can unsubscribe from any email or newsletter at any time using the unsubscribe link in the email.
This company is based outside the EU (third country). I have reviewed their data protection policies and taken appropriate safeguards.
ActiveCampaign
1 North Dearborn Street
5th Floor
Chicago, IL 60602, USA
Privacy Policy: https://www.activecampaign.com/legal/privacy-policy
I have signed a Data Processing Agreement with this provider.
ActiveCampaign also sets the following cookie on my website:
prism_650629335 — Duration: 30 days — This helps me deliver more relevant newsletter content to my subscribers.
3. WhatsApp Business
For fast and easy communication, I use WhatsApp Business. You can contact me by text or voice call through this service, and we may also arrange discovery calls via WhatsApp Business.
Your phone number will not be visible to or shared with other users.
If you no longer wish to receive messages via WhatsApp, you may notify me at any time by WhatsApp, email, or postal mail. I will then immediately stop sending messages.
WhatsApp does not read the content of messages. However, please be aware that WhatsApp may create user profiles and use this data for targeted advertising on platforms such as Instagram or Facebook (Meta). Additionally, WhatsApp is owned by Meta.
As WhatsApp servers may be located outside the EU, your data may be processed in third countries.
WhatsApp Ireland Limited
4 Grand Canal Square
Grand Canal Harbour
Dublin 2, Ireland
Privacy Policy: https://www.whatsapp.com/legal/privacy-policy-eea
I have signed a Data Processing Agreement with WhatsApp.
4. Showit
My website is hosted on Showit. This means that any data entered on my website www.mokkaa.at is processed via Showit’s servers. Showit uses third-party service providers for hosting, backups, and storage. Where appropriate, Showit has signed Data Processing Agreements with these third-party providers to ensure data security.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Showit, Inc.
2490 S Gilbert Rd #200
Chandler, AZ 85286, USA
Privacy Policy: https://showit.co/privacy
5. Checkdomain
My emails are hosted via Checkdomain. This means that any email data you send to me is processed via Checkdomain’s servers, in accordance with EU standards.
checkdomain GmbH
Große Burgstraße 27/29
23552 Lübeck, Germany
Privacy Policy: https://www.checkdomain.de/agb/datenschutz/
I have signed a Data Processing Agreement with this provider.
6. Atlanto
I use Atlanto for my accounting. This means that all invoices I issue or receive are stored and processed via Atlanto’s servers. To streamline my accounting process, I have automated part of this workflow via Atlanto.
Atlanto AG
Dufourstrasse 40
9001 St. Gallen, Switzerland
Privacy Policy: https://www.atlanto.ch/api/regulation/DownloadDataProtectionPolicy
I have signed a Data Processing Agreement with this provider.
7. Notion.so
I use Notion for internal project management and organization. I plan content, maintain client dashboards for project organization, collect ideas, track orders, and take meeting notes here. I may also note your name and email address in preparation for calls or proposals.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Notion Labs, Inc.
548 Market St
74567, San Francisco, CA 94104-5401, USA
Privacy Policy: https://www.notion.so/Terms-and-Privacy
I have signed a Data Processing Agreement with this provider.
8. Zoom
I use Zoom for video calls as part of my services, discovery calls, and digital meetings. Please note that if you participate in a group call, your name may be visible to other participants, and sessions may be recorded (e.g., for coaching, group programs, or trainings).
When you first join a Zoom call, your video and audio will be turned off by default — you can choose whether to activate them. If the session is recorded, Zoom will display a visible notification.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Zoom Video Communications, Inc.
Data Privacy Officer
55 Almaden Blvd, Suite 600
San Jose, CA 95113, USA
Privacy Policy: https://explore.zoom.us/de-de/privacy.html
I have signed a Data Processing Agreement with this provider.
9. Facebook
I use Facebook Insights to gain insights about my target audience and improve my content and services.
My virtual assistant also has access to my Facebook Insights to support me with marketing tasks. I have signed a Data Processing Agreement with this assistant.
I do not control the data collected by Facebook — I can only access the aggregated reports provided via Insights. My primary interest is understanding posting times, age, and gender demographics of my audience.
10. Google Forms
I use Google Forms to collect information through forms — for example during onboarding, feedback rounds, or market research. When you submit a form, your data is processed via Google Forms.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland
Privacy Policy: https://cloud.google.com/terms/data-processing-terms
I have signed a Data Processing Agreement with this provider.
11. Calendly
I use Calendly so that you can easily book calls with me via my website.
Calendly uses the following cookies to provide full functionality:
OptanonAlertBoxClosed
OptanonConsent
_cfruid
I rely on these cookies as a legitimate interest to enable you to conveniently schedule calls through my website.
If you do not wish to use Calendly, you can contact me by email and we will arrange a call manually.
Calendly LLC
271 17th St NW, Suite 1000
Atlanta, GA 30363, USA
Privacy Policy: https://calendly.com/de/pages/privacy
I have signed a Data Processing Agreement with this provider.
12. Google Workspace, Google Drive, Gmail
I use Google Workspace tools to run my business: for document management, form creation, email communication, and more.
When I provide you with documents (e.g. via Google Drive), you may access them directly or via your Google account. I do not have access to your private data — only to the files you share with me voluntarily.
Privacy Policy: https://policies.google.com/privacy
I have signed a Data Processing Agreement with Google.
13. Cloudflare
I use Cloudflare on my website to make it faster and more secure. Cloudflare uses cookies and processes user data.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Cloudflare, Inc.
101 Townsend St.
San Francisco, CA 94107, USA
Privacy Policy: https://www.cloudflare.com/de-de/privacypolicy/
Cloudflare services are provided through my Showit website provider. I have signed a Data Processing Agreement with Showit.
14. Google Tag Manager and Google Analytics
I use Google Analytics to optimize my marketing activities.
I also use Google Tag Manager for this purpose.
This company is based in the EU but uses servers that may be located outside the EU (e.g. in the USA). I have reviewed their data protection practices and taken appropriate safeguards.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland
Privacy Policy: https://policies.google.com/privacy
I have signed a Data Processing Agreement with this provider.
The following cookies from Google Analytics are used on my website:
_ga — Duration: 2 years
_gid — Duration: 1 day
_gat_gtag_UA_194339526_1 — Duration: 1 minute
These cookies generate anonymous statistical data about how visitors use my website, so I can analyze whether my site is well structured and whether it achieves its goals.
15. Facebook Pixel
To analyze and optimize my advertising activities, I use Facebook Pixel.
This company is based in the EU but uses servers that may be located outside the EU (e.g. in the USA). I have reviewed their data protection practices and taken appropriate safeguards.
Meta Platforms Ireland Ltd.
4 Grand Canal Square
Dublin 2, Ireland
Privacy Policy: https://www.facebook.com/policy.php
Explanation of Facebook Pixel: https://www.facebook.com/business/help/742478679120153?id=1205376682832142
I have signed a Data Processing Agreement with this provider.
The following cookies from Facebook are used on my website:
_fbp — Duration: 3 months
fr — Duration: 3 months
These cookies help with website analysis, ad measurement, and displaying ads on Facebook/Meta platforms.
16. Pinterest
I maintain an online presence on Pinterest to showcase my products and services and to communicate with customers and potential customers.
This company is based outside the EU (third country). I do not have access to individual user data — I only see aggregated insights regarding the performance of my pins (e.g. ranking and engagement).
Pinterest Inc.
651 Brannan Street
San Francisco, CA 94107, USA
Privacy Policy: https://policy.pinterest.com/de/privacy-policy
17. Google reCAPTCHA and Google Ads
I use Google reCAPTCHA to make my website as secure as possible for you. reCAPTCHA helps me verify that you are a human and not a bot or spam software.
Usually, this verification is done with a simple checkbox or similar method.
This company is based in the EU but uses servers that may be located outside the EU (e.g. in the USA). I have reviewed their data protection practices and taken appropriate safeguards.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland
Privacy Policy (Google Ads): https://policies.google.com/privacy?hl=de&tid=331648726902
If you wish to deactivate Google Analytics, you can use this plugin: https://tools.google.com/dlpage/gaoptout?hl=de
I have signed a Data Processing Agreement with this provider.
18. Dropbox
I occasionally use Dropbox to provide documents to you as part of my services. You may access the documents directly or via your Dropbox account. You must have your own Dropbox account to access these materials. I do not have access to your personal Dropbox data — only to files you voluntarily share with me.
Privacy Policy: https://www.dropbox.com/de/security/GDPR
19. WeTransfer
To exchange documents with you during our project, I may use WeTransfer. This allows us to transfer files over the internet. All such transfers comply with EU standards.
WeTransfer BV
Oostelijke Handelskade 751
Amsterdam, 1019 BW
Netherlands
Privacy Policy: https://wetransfer.com/legal/privacy
20. Facebook Plugin, Instagram Plugin, Meta Plugins
These plugins allow you to easily share, for example, one of my blog posts on your social media channels or display my current Instagram posts directly on my website.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Meta Platforms Ireland Ltd.
4 Grand Canal Square
Dublin 2, Ireland
Privacy Policy: https://www.facebook.com/about/privacy
21. Google Fonts
I may use Google Fonts on my website.
This company is based in the EU but may use servers located outside the EU (e.g. in the USA). I have reviewed their data protection practices and taken appropriate safeguards.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland
Privacy Policy: https://cloud.google.com/terms/data-processing-terms
I have signed a Data Processing Agreement with this provider.
22. YouTube
I may embed YouTube videos on my website or within my services. These may include videos where I provide more detailed information about my services and products.
YouTube is part of Google. This company is based in the EU but may use servers located outside the EU (e.g. in the USA). I have reviewed their data protection practices and taken appropriate safeguards.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland
Privacy Policy: https://cloud.google.com/terms/data-processing-terms
I have signed a Data Processing Agreement with this provider.
Cookies set by YouTube on my website:
VISITOR_INFO1_LIVE – duration: 180 days
YSC – duration: session
These cookies help determine your internet speed to display videos appropriately and improve your user experience.
23. Spotify
I may embed Spotify links or the Spotify player on my website or in my services. Spotify is a service that allows you to listen to and stream music. You must have your own Spotify account to access these features. All processing complies with EU standards.
Spotify AB
Regeringsgatan 19
SE-111 53 Stockholm
Sweden
Privacy Policy: https://www.spotify.com/de/legal/privacy-policy/
24. Adobe & Creative Cloud
To design and create various files — for marketing, internal use, and client projects — I use the Adobe Suite and Creative Cloud, especially Photoshop, Illustrator, Lightroom, and InDesign.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Adobe Inc.
345 Park Avenue
San Jose, CA 95110-2704
USA
Privacy Policy: https://www.adobe.com/ch_de/privacy/policy.html
I have signed a Data Processing Agreement with this provider.
25. Canva
To design and create various files — for marketing, internal use, and client projects — I sometimes use the Canva online tool. I may also provide certain designs through Canva.
You will need your own Canva account to use shared designs. I will only have access to files you voluntarily share with me.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Canva Pty Ltd
110 Kippax St
Surry Hills NSW Australia 2021
Privacy Policy: https://www.canva.com/policies/privacy-policy/
I have signed a Data Processing Agreement with this provider.
26. Stripe
To facilitate payments, I may use Stripe.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Stripe, Inc.
510 Townsend Street
San Francisco, CA 94103
USA
Privacy Policy: https://stripe.com/de/privacy
27. Iubenda
I use Iubenda as my Cookie Consent tool. It displays the cookie banner and helps block non-essential cookies until you consent.
All processing complies with EU standards.
Iubenda s.r.l
Via San Raffaele, 1
20121 Milan, Italy
Privacy Policy: https://www.iubenda.com/privacy-policy/78728009/legal
I have signed a Data Processing Agreement with this provider.
28. WordPress Blog
On my website, you may also read a blog. This is operated via WordPress.
This company is based outside the EU (third country). I have reviewed their data protection practices and taken appropriate safeguards.
Aut O’Mattic A8C Ireland Ltd.
25 Herbert Place, Dublin 2
Dublin
Ireland
Privacy Policy: https://de.wordpress.org/about/privacy/
I have signed a Data Processing Agreement with this provider.
29. Consent Manager
I use Consent Manager to make my website GDPR-compliant. This tool manages cookie consent, displays the cookie banner, and blocks cookies before you have given consent.
All processing complies with EU standards.
consentmanager AB
Haltegelvägen 1b
72348 Västeras
Sweden
Privacy Policy: https://www.consentmanager.de/datenschutz/
I have signed a Data Processing Agreement with this provider.
Affiliate Programs and Affiliate Links
On my website and in my online services, I use affiliate links and other references (such as discount codes, widgets) to third-party services and products. This is based on my legitimate interests (i.e. economic operation of my online business according to Art. 6 para. 1 lit. f GDPR).
If you follow an affiliate link (usually a text or image link) and then purchase or use the offer, I may receive a commission or other benefit from the third party.
To track whether you have reached the third-party provider through my recommendation, certain values may be stored or cookies set. This is solely for the purpose of commission tracking.
I participate in the Canva Affiliate Program.
Canva Pty Ltd
110 Kippax St
Surry Hills NSW Australia 2021
Privacy Policy: https://www.canva.com/policies/privacy-policy/
I have signed a Data Processing Agreement with this provider.
Duration of Data Storage
After the contract is fulfilled, I do not actively use your data further. Your data will be stored only for the legally required period under tax and commercial law retention obligations. Once this period has expired, your data will be permanently deleted.
If you have consented to the further processing of your data, I may continue to do so until you request deletion. You may request deletion at any time. Please contact me via email or post at the addresses provided above.
Right to Information
You may exercise your right to information at any time. This means you may contact me at any of the above addresses and request information about all data I have collected and processed about you.
If you wish to withdraw your consent to data processing, please do so via the same channels.
This also applies if you wish to request deletion of your data or exercise your right to data portability.
Right to Lodge a Complaint
You have the right to lodge a complaint with the appropriate supervisory authority at any time if you believe I have violated data protection regulations.
Disclaimer
This privacy policy has been created by me, Sarah from Mokkaa, and is specifically tailored to my business and website.
Please note: simply copying this privacy policy does not guarantee that it will be suitable for your business.
Last updated: June, 2025
Mentoring and Resources for Designers
Design Mentoring
Design Ressources