Privacy Policy
How we handle personal data on this website. JS Management Inc is your contracting party in the United States; the website itself is operated by PAJO Digital GmbH in Germany, which is why European data protection rules apply to the processing described here.
1. Controller
PAJO Digital GmbH
Stauffenbergstraße 74b
67547 Worms, Germany
represented by the managing directors Patrick Schneider and Jochen Schüttler
Phone: +49 151 540 321 87
Email: kontakt@pajodigital.de
No data protection officer has been appointed, as the statutory conditions for a mandatory appointment are not met.
2. The key points at a glance
This website is deliberately built to minimize data:
- No cookies – neither technical nor marketing cookies. That is why there is no cookie banner either.
- No tracking, no analytics tools – we do not create usage profiles.
- No external content when the page loads – fonts, scripts, images and videos are hosted entirely on our own web space. When you visit the page, no connections to third-party networks (for example font or script CDNs) are established.
- Chat assistant only on request – the assistant is loaded only when you click it. Simply visiting the page establishes no connection to it.
Personal data only arises where it is technically unavoidable (server log data when the page is requested) or where you contact us yourself.
3. Hosting and server log data
This website is hosted by:
Sliplane (owner: Lukas Mauser), Freienwalder Str. 3, 13359 Berlin, Germany
The servers are located in a data center operated by Hetzner Online GmbH (Gunzenhausen, Germany); data processing for hosting takes place exclusively within the European Union.
When you access the website, the hosting provider automatically processes data transmitted by your browser (server log data): IP address, date and time of the request, the file requested, the amount of data transferred, the referrer URL and the browser and operating system identifier. This data is technically necessary in order to deliver the website and to ensure its stability and security (for example detecting abuse and attacks); it is not merged with other data sources.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in providing the website securely and reliably). The log data is stored only for as long as is necessary for those purposes.
Processing on our behalf: A data processing agreement pursuant to Art. 28 GDPR is in place with Sliplane. No transfer to a third country takes place as part of the hosting.
4. Contacting us by email or phone
If you contact us by email or phone, we process the data you provide (name, contact details, content of the inquiry) in order to handle and answer your request.
Legal basis: Art. 6 (1) (b) GDPR insofar as your inquiry is aimed at concluding or performing a contract, otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering inquiries).
Storage period: We delete the data as soon as it is no longer required for processing your request, unless statutory retention obligations (in particular under German commercial and tax law, § 257 HGB, § 147 AO) prevent deletion.
Email infrastructure: For our email communication we use Microsoft 365 / Exchange Online provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, as a processor (Art. 28 GDPR). Data processing generally takes place in data centers within the EU (Microsoft EU Data Boundary). Where data is transferred to Microsoft Corporation in the United States in individual cases, this is done on the basis of the EU-US Data Privacy Framework, under which Microsoft is certified, and the EU standard contractual clauses.
5. Contact form
If you use our contact form, we process the data entered there (name, email address, message and optionally your phone number) in order to handle your inquiry. The details are transmitted exclusively by email to our mailbox (via the email infrastructure described under section 4) and are not stored in a database.
To fend off automated spam submissions we use server-side technical checks only, no captcha service and no cookies. For this purpose your IP address is processed briefly in the server's memory (limiting submissions per hour); it is not logged and not stored together with your inquiry.
Legal basis: Art. 6 (1) (b) GDPR insofar as your inquiry is aimed at a contract, otherwise Art. 6 (1) (f) GDPR; for spam protection Art. 6 (1) (f) GDPR (legitimate interest in the security of the form). Storage period as described under section 4.
6. Our Instagram presence
PAJO Digital GmbH operates a company profile on Instagram at instagram.com/pajo.digital. For users in the European Union the platform is provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland.
Nothing from Meta is embedded on this website. No Instagram content, no buttons that transmit data, no tracking pixel. The link above only takes you to Instagram once you click it. Everything else in this section is about your visit to Instagram, not your visit here.
When you open our profile, Meta processes personal data about you, including:
- Your IP address and information about your device
- Your behaviour on the platform, such as which posts you view
- Information from your Instagram account, if you have one and are signed in
This happens even if you do not have an Instagram account. Meta is responsible for that processing. We have no influence over it and no access to the underlying data, so we cannot tell you exactly what Meta collects or how long it is kept. Meta’s own privacy policy explains it at privacycenter.instagram.com/policy.
Meta provides us with statistics about how our profile is used, such as how many people saw a post and which age groups and regions they come from. For that processing we are joint controllers with Meta within the meaning of Art. 26 GDPR. Meta has taken on the essential obligations under the General Data Protection Regulation for this data in the Page Insights Addendum, available at facebook.com/legal/terms/page_controller_addendum. We only ever receive these statistics in aggregate and cannot identify individual people in them.
Purpose and legal basis: We use the profile to show what we do and to stay reachable for prospects and clients. The legal basis is our legitimate interest in presenting ourselves and communicating, under Art. 6 (1) (f) GDPR. We use the statistics to judge which content actually gets read.
If you message us on Instagram or comment on a post, we process what you send in order to reply. The legal basis is Art. 6 (1) (f) GDPR, or Art. 6 (1) (b) GDPR where your inquiry concerns a possible engagement. We do not store messages outside Instagram and we do not analyse them automatically. For anything confidential, please use email or the phone rather than an Instagram message.
Meta also processes data in the United States. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework, which the European Commission recognized as providing an adequate level of protection by decision of 10 July 2023. Meta additionally relies on the European Commission's standard contractual clauses. A residual risk remains: authorities in the United States may access data under certain conditions, and you do not have the same legal remedies against that there as you would in the European Union.
You can exercise the rights listed in section 9 against us and against Meta. For the data Meta processes during your visit, Meta is best placed to answer, because that is where the data sits. You are still welcome to come to us first. We will pass your request on and help you with it.
You do not have to visit our profile. Everything shown there is also on this website, and you can reach us by email and phone without Meta learning about it.
Deleting your data
To publish our own posts we use an application we built ourselves, which works through Meta's Instagram interface. It only ever publishes posts that we wrote and approved by hand beforehand.
This application stores nothing about you. It does not retrieve profiles, comments, messages or follower details. All it stores is our own post texts, our own images, the time of publication and the name of the person at our company who approved the post. There is therefore no data about you there that we could delete.
If you would still like to request deletion, an informal message to kontakt@pajodigital.de with the word “deletion” is enough. We confirm receipt, check every place where data about you could be held, and tell you the result within one month (Art. 12 (3) GDPR). If there is nothing to delete, we will tell you that too.
Comments and messages you have left on Instagram are held by Meta, not by us. You can delete them in Instagram yourself. Meta explains how to view, download and delete the data it holds about you at privacycenter.instagram.com.
7. AI chat assistant
You can open a chat assistant on our pages. It loads only when you click it. Before that, no data is transmitted to us or to third parties.
When you send a question, we transmit your question, the conversation so far and the address of the page you are on to our server in Germany. From there the request goes to Amazon Web Services EMEA SARL, which operates the language model in data centres within the European Union. Your input is not used to train models. The legal basis is our legitimate interest in providing a fast answer (Art. 6(1)(f) GDPR).
We store your question and the answer for 30 days in order to improve the assistant. We do not store your IP address. We do not set cookies for the assistant. The conversation is held in your browser's session storage during your visit and is deleted when you close the tab.
The assistant is an AI system. This is also stated in the chat window itself. Please do not enter personal data there. If you would like to send us your contact details, please use the contact form.
8. Encryption
This website uses TLS encryption (recognizable by "https://" and the padlock symbol in your browser's address bar). This protects data you transmit to us from being read by third parties while in transit.
9. Your rights
As a data subject you have the following rights:
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7 (3) GDPR)
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6 (1) (f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation.
An informal message is enough to exercise your rights: kontakt@pajodigital.de.
Right to lodge a complaint: You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, Hintere Bleiche 34, 55116 Mainz, Germany.
10. No automated decision-making
Automated decision-making including profiling (Art. 22 GDPR) does not take place. You are neither legally nor contractually obliged to provide us with personal data; without your contact details, however, we cannot answer inquiries.
11. Version and changes
Version: August 2026. We update this privacy policy when the legal situation or our website changes. The version published here at any given time applies.