Privacy Notice

Last updated: 31 July 2026

1. Controller and Scope

The controller within the meaning of the General Data Protection Regulation (“GDPR”) is:

Maximilian O. Sutter
Harbatshofen 10 ½
88167 Stiefenhofen
Germany
Email:

This notice explains how I process personal data when you visit maxsutter.de, make an enquiry, enter into a contract, or take part in executive or leadership coaching, team coaching, interviews, workshops, offsites, facilitation, organisational development, or comparable advisory and development formats. It applies in particular to prospective clients, clients, coachees, participants, client contacts and sponsors.

2. Data Categories, Sources and Data-Protection Roles

Depending on the contact or engagement, I process in particular:

  • identity and contact data such as your name, email address and postal address;
  • professional and organisational information such as your employer, position, function, team membership and professional context;
  • contract, billing, payment and tax data;
  • scheduling, communication and participation data;
  • content communicated or developed in coaching, interviews, team formats, workshops or offsites, including my session and working notes, agreed actions and approved outputs;
  • audio and transcript data only where recording or automated transcription has first been authorised;
  • technical and usage data generated when the website or a service is used.

I receive data mainly from the individual concerned. In corporate engagements, names, business contact details, roles, team membership, scheduling information and information about the organisational context may also come from the commissioning organisation, a sponsor, an employer or another project participant. Where data is not obtained directly, I provide this notice within one month after receiving it, no later than the first direct communication if that occurs earlier, no later than the first disclosure where disclosure to another recipient is envisaged, and operationally as a rule before first participation. The client remains responsible for the lawfulness and transparency of its own disclosure.

For corporate engagements, the client and I are generally separate controllers for our respective processing. Where I process data solely on the client’s documented instructions in a specific project, an agreement under Article 28 GDPR will be entered into before processing begins. Joint controllership will be regulated separately where required.

3. Purposes and Legal Bases

I process personal data for the following purposes and on the following legal bases:

  • enquiries, steps before entering into a contract, contract formation and performance of a contract with the person concerned: Article 6(1)(b) GDPR;
  • organisation and professional delivery of corporate engagements for coachees and participants who are not themselves contractual parties, project communication, confidential documentation and continuity of the services: Article 6(1)(f) GDPR;
  • creation, organisation and revision of my session and working notes and preparation and follow-up: Article 6(1)(b) or (f) GDPR;
  • voluntary audio capture, automated transcription and other consent-based processing: Article 6(1)(a) GDPR;
  • compliance with statutory retention, tax and documentation duties: Article 6(1)(c) GDPR;
  • establishment, exercise or defence of legal claims: Article 6(1)(f) GDPR.

My legitimate interests are reliable and consistently high-quality service delivery, secure project organisation and IT use, confidential documentation, and the establishment and defence of legal claims. In balancing interests, I take particular account of the individual’s confidentiality expectations, the sensitivity of the format, data minimisation, limited retention periods and human oversight. Special categories of personal data are additionally subject to section 11.

4. Website Hosting, Cookies and Local Browser Storage

This static website is provided through GitHub Pages, a service provided by GitHub. GitHub documents that when a GitHub Pages website is visited, the visitor’s IP address is logged and stored for security purposes, whether or not the visitor is signed in to GitHub.

Purpose and legal basis: I use this hosting service on the basis of Article 6(1)(f) GDPR. My legitimate interest is the secure, stable and efficient provision of the website and the detection and prevention of misuse.

International processing and retention: GitHub’s general privacy statement describes possible processing in the United States and other countries and the transfer mechanisms used. The GitHub Pages documentation does not specify a fixed retention period for IP logging. The provider’s current information applies in this respect.

I do not use cookies or tracking technologies on this website. The selected language is stored in localStorage until you change the setting or delete your browser data. Dismissal of the language suggestion is stored in sessionStorage until the browser session ends. These values remain in your browser and are not transmitted to me or any third party. Storage and access are permitted under section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG), because they are necessary for the language function you expressly request; where personal data is involved, Article 6(1)(f) GDPR additionally applies.

Further information: GitHub Pages – Data collection and the GitHub General Privacy Statement.

5. Contact Form and Formcarry

I use Formcarry, a service provided by Teijal, Inc. d/b/a Formcarry (“Formcarry”), for the contact form. Formcarry processes the submitted information on my behalf, filters spam and forwards the enquiry to me by email.

Data processed: Name, email address, role and organisation, leadership challenge, optional information about the referral source and readiness to start, and technically necessary connection data such as the IP address.

Purpose and legal basis: I process the data to answer your enquiry and, where applicable, take steps before entering into a contract under Article 6(1)(b) GDPR. If the person making the enquiry is not the potential contractual party, processing is based on Article 6(1)(f) GDPR; my interest is the efficient handling of business enquiries and protection of the form against misuse.

Recipients and international transfers: Formcarry acts as a processor. According to the provider, form data is stored in Frankfurt; remote access from the United States and US-based subprocessors may be involved and are covered by Standard Contractual Clauses or other safeguards identified by the provider.

Retention: Persistent storage of incoming messages in the Formcarry database is disabled. If no contract is entered into, I generally delete the enquiry received by me no later than twelve months after correspondence ends, unless a statutory duty or specific evidentiary interest requires longer retention.

Please do not submit health information or other particularly sensitive information through the contact form. Further information: Formcarry Data Processing Agreement and Formcarry Privacy Policy.

6. Coaching, Team and Corporate Engagements

To prepare, deliver and follow up on the services, I process the necessary contact, organisational, scheduling and communication data and the content communicated or developed in the relevant format. I may create my own written session and working notes. They support professional continuity, preparation and follow-up, agreed documentation and, to a limited extent, legitimate evidentiary needs.

Content from individual coaching and interviews is not disclosed to the client, sponsor, employer or other participants without prior consent relating to the specific information and recipient. A sponsor receives only administrative project information, sufficiently aggregated themes and outputs expressly approved for documentation or disclosure. In a small team, removing a name alone does not automatically anonymise information.

Coaching notes are not personnel or performance appraisals and are not created or used by me for decisions about recruitment, promotion, remuneration, performance or termination of employment. Co-facilitators and assistants who are required for an engagement receive data only on a need-to-know basis and are bound to confidentiality.

7. Recording and Transcription with Granola

For individual conversations or events, I may use Granola, a service provided by Granola, Inc. and Granola Labs Ltd., for automated transcription and AI-assisted conversation notes.

Granola captures microphone and system audio for this purpose. Technical capture and transcription take place only after every person whose spoken words will be captured has been informed of the purpose, operation, recipients, international processing and retention, and has given documented consent. Consent is voluntary. If consent is declined or withdrawn, no further recording or transcription takes place; I do not subject the person to any adverse consequence, and the conversation can proceed with manual notes. For corporate engagements, the client is responsible for ensuring voluntary participation without adverse consequences within its own sphere of responsibility.

Legal basis: Article 6(1)(a) GDPR and, where special categories of personal data are processed, additionally Article 9(2)(a) GDPR.

Processing and transfers: According to Granola, audio is cached only temporarily for transcription and is deleted from Granola’s and its third-party providers’ systems once transcription is complete. Transcripts and notes are processed on AWS systems in the United States. Granola processes customer data as a processor under a data processing agreement that includes the EU Standard Contractual Clauses and uses contractually bound subprocessors for cloud, transcription and AI functions. Under its data processing agreement, Granola acts as a limited independent controller for certain system, account, security and compliance data.

Use of data processed through my account for Granola’s model improvement is disabled. Granola also states that its external AI and transcription providers may not use the submitted data for their own model training. Because Granola otherwise retains transcripts and notes indefinitely unless the customer deletes them, I delete them actively in accordance with section 12 or use an available retention rule.

Further information: Granola Security, Privacy & Data FAQs, the Granola Data Processing Addendum and the Granola Privacy Policy.

8. AI-Assisted Notes, OpenAI and Local Models

I may use AI-assisted tools to organise, summarise or edit the wording of my session and working notes. AI output is reviewed and, where necessary, corrected before it is used in any substantive assessment or project output.

OpenAI Business and API: Personal or confidential engagement content is processed by OpenAI only through services intended for business customers or the API and covered by a data processing agreement with OpenAI Ireland Limited. OpenAI acts as a processor for this content. According to OpenAI, inputs and outputs from its business services are not used by default to train or improve its models; optional data sharing remains disabled. With the API, certain log and application data may be retained for limited periods depending on the endpoint used.

Personal ChatGPT: A personal ChatGPT account is used only for content that is genuinely anonymised or otherwise contains no personal data, and is also non-confidential. No personal or confidential coaching, team or corporate content is entered there. “Improve the model for everyone” is disabled. The personal account is not used as a processor for client data.

Local open-source models: Local models run solely on my own Mac. No content is transmitted to a cloud provider or other external recipient.

Purpose and legal basis: Processing ordinary personal data supports efficient and consistently high-quality preparation and follow-up and is based on Article 6(1)(b) or (f) GDPR. Special categories are subject to the additional rules in section 11.

International transfers: OpenAI may use affiliates and subprocessors outside the EEA for its business services. Its data processing agreement provides for adequacy decisions or the EU Standard Contractual Clauses.

Further information: OpenAI – How your data is used to improve model performance, OpenAI Business Data and the OpenAI Data Processing Addendum.

9. Google Workspace and Shared Session Notes

I use a business Google Workspace account, in particular Gmail, Google Calendar, Google Drive and Google Docs, for communication, scheduling, and creating, storing and sharing prepared session notes. Google processes the customer data contained there as a processor under the Google Cloud Data Processing Addendum. Internal raw and working notes are not shared as such.

Prepared session notes are generally shared only with the specifically named Google account of the coachee concerned. If the recipient has no Google account, an unlisted sharing link without sign-in may be used. The link is sent only and directly to that person. Technically, however, anyone who receives the link or to whom it is forwarded can access the document. I explain this risk before using such a link and ask the recipient not to forward it. Particularly sensitive information is not shared through such a link; another access-restricted transmission method is used instead. Link access is revoked as soon as it is no longer required for the agreed purpose.

Individual coaching notes are not shared with a sponsor or employer unless the individual concerned has specifically consented. This does not affect expressly agreed team outputs that are intended to be shared.

Purpose and legal basis: Communication, scheduling, service delivery and access to agreed notes are based on Article 6(1)(b) or (f) GDPR. Google may process customer data worldwide. Its data processing agreement provides in particular for adequacy decisions and the EU Standard Contractual Clauses for transfers outside the EEA. Under the terms for Google Workspace, customer data is not used to train or fine-tune generative AI models without permission.

Further information: the Google Cloud Data Processing Addendum, Google – International Data Transfer Frameworks and Google Workspace Subprocessors.

10. Other Recipients and International Transfers

I disclose personal data only to recipients that need it for the relevant purpose. In addition to the providers identified above, this may include co-facilitators and other assistants bound to confidentiality, lawyers or tax advisers subject to professional confidentiality, insurers, and public authorities or courts where a statutory duty or binding order applies. Clients or sponsors receive data only within the limits described in section 6. Personal data is not sold or disclosed for third-party advertising.

GitHub, Formcarry, Google Workspace, Granola and OpenAI may process data in the United States or other countries outside the European Economic Area. Depending on the provider and processing, transfers are based on an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework, or on the EU Standard Contractual Clauses and supplementary safeguards. Countries outside the EEA may provide a different level of data protection. Information about the safeguards applicable in a specific case may be requested using the contact details above.

11. Special Categories of Personal Data and Consent

Information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health, or a person’s sex life or sexual orientation is not actively requested. Such information may nevertheless be disclosed voluntarily in a confidential coaching conversation.

I include special-category data in lasting notes or process it further only where this is necessary for the agreed purpose and an exception under Article 9(2) GDPR applies. As a rule, I obtain explicit consent under Article 9(2)(a) GDPR. Where data is required solely for the establishment, exercise or defence of legal claims, Article 9(2)(f) GDPR may apply. Sensitive detail that is not needed is not documented or is removed as early as possible.

Before cloud AI is used, such information is effectively anonymised or removed, processed locally, or transmitted to the provider identified above only after separate explicit consent. This Privacy Notice does not itself replace the required consent.

Consent may be withdrawn at any time with future effect. This does not affect the lawfulness of processing before withdrawal. Data processed solely on the basis of the withdrawn consent is generally deleted without undue delay unless another legal basis permits or requires continued processing. I do not subject anyone to adverse consequences for declining or withdrawing consent to recording, transcription or cloud AI processing of personal data; an alternative without the relevant processing will be used where required.

12. Retention and Deletion

I retain personal data only for as long as required for the relevant purpose, continuation of the engagement, legitimate evidentiary needs or statutory duties. The following periods generally apply:

  • According to the provider, Granola audio data is deleted once transcription is complete.
  • Raw transcripts and temporary AI drafts are deleted from my active systems once the final note is complete and no later than 90 days after creation. Following withdrawal of consent, consent-based raw data is generally deleted earlier unless another legal basis permits continued processing.
  • Final coaching notes and shared Google documents managed by me are generally retained until 31 December of the third calendar year following the end of the engagement and are then deleted from my active systems; existing sharing permissions are revoked. This does not apply where earlier deletion is required or longer retention is necessary in the specific case.
  • Enquiries that do not result in a contract are generally deleted no later than twelve months after correspondence ends.
  • Business and commercial correspondence is retained for six years where legally required, accounting records and invoices for eight years, and books, financial statements and comparable tax records for ten years.
  • If a legal dispute exists or claims are specifically expected, the data required for that matter may be retained until it is finally resolved.

I also delete data earlier when it is no longer required and no duty or overriding evidentiary interest prevents deletion. The periods refer to my active systems. Final deletion by a provider depends on the product used, its configuration and the applicable contractual deletion cycles. Under its data processing agreement, Google implements deletion instructions as soon as reasonably practicable and within no more than 180 days. Statutory, security and abuse-prevention exceptions and limited provider backup cycles may apply.

Deleted local data may temporarily remain in encrypted backups until overwritten in the regular backup cycle. It is not restored for other purposes. Copies of a shared document made independently by a recipient are subject to that recipient’s responsibility.

13. Required Data and No Automated Decisions

Data required for enquiries, scheduling, performance or billing must be provided; otherwise I may be unable to handle the enquiry or provide the service. Audio capture, automated transcription and cloud AI processing of personal data are not requirements for participation.

I do not make decisions based solely on automated processing within the meaning of Article 22 GDPR and do not carry out profiling. AI systems support only the creation and organisation of working material. I review AI output before using it in any substantive assessment or project output and remain responsible for those results. AI output, coaching notes and transcripts are not used for automated personnel, performance or employment decisions.

14. Your Data Protection Rights

Subject to the statutory conditions, you have the right of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR and data portability under Article 20 GDPR.

Right to object: Where processing is based on Article 6(1)(f) GDPR, you may object under Article 21 GDPR on grounds relating to your particular situation. I will then no longer process the relevant data unless I demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.

You may withdraw consent at any time with future effect. Requests are generally answered within one month. Where a request is particularly complex or numerous requests are received, this period may be extended by up to two further months where the statutory conditions are met.

You also have the right to lodge a complaint with a data-protection supervisory authority. The supervisory authority generally responsible for supervising my processing is the Bavarian Data Protection Authority for the Private Sector (BayLDA), Promenade 18, 91522 Ansbach, Germany. You may also contact another competent supervisory authority.

15. Data Security

I use technical and organisational measures appropriate to the risk, including access restrictions, secured accounts, encrypted transmission channels and data minimisation.

Local project files are stored on an access-controlled Mac whose system drive is protected by macOS FileVault full-disk encryption. Backups are stored in encrypted form. Local open-source models process content only on that device and do not transmit it to a cloud provider.

Cloud processing is also protected by the providers’ contractual and technical safeguards. Despite appropriate measures, absolute protection cannot be guaranteed for electronic transmission or storage.

16. Changes and Contact

I update this Privacy Notice when the processing, services used or legal requirements change. The current version and its new revision date will be published on this page.

For questions or to exercise your rights, contact or use the postal address in section 1.