Privacy Policy | Zohuri Advisory
Zohuri Advisory
ZOHURI ADVISORY
Let’s Connect
Data Protection

Privacy Policy

This Privacy Policy explains how Zohuri Group UG (haftungsbeschränkt) ("we", "us") processes personal data when you visit our website or use our advisory, coaching, and programme services, in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

Zohuri UG
Güntzelstraße 27, 10717 Berlin, Germany
Managing Director: Amir Zohuri
Email: info@zohuri.com

If you have any questions about this Privacy Policy or the processing of your personal data, you may contact us at any time using the details above.

2. Purposes and Legal Bases

We process personal data only where a legal basis under Art. 6 GDPR applies, in particular:

  • Operation, security, and functionality of this website (legitimate interest, Art. 6(1)(f) GDPR)
  • Responding to enquiries and initiating a business relationship (Art. 6(1)(b) or legitimate interest, Art. 6(1)(f) GDPR)
  • Performance of contracts for advisory, coaching, and programme services, including scheduling and delivery (Art. 6(1)(b) GDPR)
  • Marketing communications and newsletters, where you have given consent (Art. 6(1)(a) GDPR)
  • Compliance with legal obligations, e.g. commercial and tax record-keeping (Art. 6(1)(c) GDPR)

3. Hosting & Server Logs

This website is hosted by Hostinger. Our hosting provider automatically processes server log files for technical operation and security, including IP address, date and time of access, referrer URL, and browser/user agent (legitimate interest, Art. 6(1)(f) GDPR). Log data are generally deleted after 30 days unless required for the investigation of a security incident.

4. Cookies & Consent

We use cookies and similar technologies to operate the website and, where applicable, to analyse usage and improve our content. Cookies that are not strictly necessary for operating the website are only set with your prior consent (Art. 6(1)(a) GDPR). You can grant, decline, or withdraw consent at any time via our cookie banner, and you may also manage cookies through your browser settings.

5. Contact Forms, Bookings & Email

When you contact us via a contact form, booking form, or email, we process the personal data you provide (e.g. name, email address, organisation, message content) solely to handle and respond to your enquiry or to prepare and deliver the requested service (Art. 6(1)(b) or (f) GDPR). This data is deleted once it is no longer required for these purposes, unless statutory retention obligations require longer storage.

6. Newsletter

If you subscribe to our newsletter, we use a double opt-in procedure: you will receive a confirmation email and your subscription only becomes active once you confirm it. This processing is based on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time, for example via the unsubscribe link in every newsletter. We use a GDPR-compliant email marketing platform to send our newsletters.

7. Data Recipients & Processors

We engage carefully selected service providers who process personal data on our behalf as processors under Art. 28 GDPR, including providers of website hosting, email communication, video conferencing/scheduling tools, and customer relationship management (CRM) or analytics tools. These providers are contractually bound to process data only in accordance with our instructions and applicable data protection law.

8. International Data Transfers

Where personal data is transferred to service providers located outside the EU/EEA (for example, in the United States), we ensure an adequate level of data protection through appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, an adequacy decision, or your explicit consent, as applicable.

9. Storage Duration

We store personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, to perform our contractual obligations, or as required by statutory retention periods (e.g. under German commercial and tax law, typically 6–10 years for business correspondence and accounting records). Data no longer required is deleted or anonymised.

10. Your Rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR)
  • Request rectification of inaccurate data (Art. 16 GDPR)
  • Request erasure of your data (Art. 17 GDPR)
  • Request restriction of processing (Art. 18 GDPR)
  • Receive your data in a portable format (Art. 20 GDPR)
  • Object to processing based on legitimate interest (Art. 21 GDPR)
  • Withdraw consent at any time, with effect for the future (Art. 7(3) GDPR)

To exercise any of these rights, please contact us using the details in Section 1. You also have the right to lodge a complaint with a supervisory authority, in particular the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or alteration, including TLS/SSL encryption of data in transit, access controls, and regular backups. These measures are reviewed and updated as necessary to reflect technological developments.

12. Changes to This Policy

This Privacy Policy is effective as of 09 September 2025. We may update this policy from time to time to reflect changes in our practices or legal requirements. The current version will always be published on this page.