Privacy Policy
Last updated: March 2026
1. Data controller
Isuku Verlag UG (haftungsbeschränkt)
Gabriel Isuku
Achentalstr. 3
81671 München, Germany
- Email: contact@isuku.de
- Phone: +49 (0)89 54.31.68.31
2. Data protection officer
The appointment of a data protection officer is not legally required for our company. For data protection inquiries, please contact us at the address above.
3. General information on data processing
We only process personal data of our users to the extent necessary to provide a functional website and our content and services. Personal data is only processed with the user's consent or when processing is permitted by law.
4. Legal basis
The processing of personal data is based on the following legal grounds:
- Art. 6(1)(a) GDPR — Consent of the data subject
- Art. 6(1)(b) GDPR — Performance of a contract or pre-contractual measures
- Art. 6(1)(c) GDPR — Compliance with a legal obligation (e.g. tax retention requirements)
- Art. 6(1)(f) GDPR — Legitimate interest (e.g. website security)
5. Hosting and content delivery
Cloudflare
Our website is delivered through Cloudflare (Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare acts as a Content Delivery Network (CDN) and provides DDoS protection. A Data Processing Agreement (DPA) is in place with Cloudflare.
Data processed:
- IP address (anonymized)
- Access time
- HTTP request data (URL, referrer, user agent)
Retention period: Log data is stored by Cloudflare for a maximum of 72 hours.
Legal basis: Legitimate interest in the secure and efficient delivery of our website (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework.
More information: Cloudflare's privacy policy
Server log files
Each time our website is accessed, the web server automatically collects data transmitted by your browser (server log files):
- Page visited (URL)
- Time of access
- Amount of data transferred
- Referrer (previously visited page)
- Browser and operating system used
- IP address (anonymized)
This data is not merged with other data sources.
Retention period: Server log files are automatically deleted after 7 days.
Legal basis: Legitimate interest in ensuring trouble-free operation (Art. 6(1)(f) GDPR).
6. Cookies and consent
Necessary cookies
We use technically necessary cookies that are required for the operation of the website. These cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
i18n_redirected | Storing your preferred language | 1 year |
site_consent | Storing your cookie settings | 1 year |
welcome_dismissed | Remembers that you closed the welcome notice | 1 year |
In addition, we store an isuku_theme entry in your browser's session storage if you select a different colour scheme via the ?theme= URL parameter. The entry is deleted when you close the browser tab.
Legal basis: § 25(2)(2) TDDDG (technically necessary) in conjunction with Art. 6(1)(f) GDPR.
Analytics cookies (consent required)
The following cookies and storage technologies are set exclusively after you consented in the cookie banner. Without your consent, none of these entries is created:
| Service | Entry | Purpose | Duration |
|---|---|---|---|
| PostHog | Cookie ph_<project-id>_posthog and a local storage entry of the same name | Recognising your session for usage analytics and session recording | 1 year |
| PostHog | A session storage entry of the same name, ph_<project-id>_posthog | Storing the session and window identifier and the page visited before | Session |
| PostHog | Cookie ph-identify | Storing the identifier assigned by PostHog | Session |
| Sentry | Session storage entry sentryReplaySession | Associating error and session recording data with one session | Session |
If you withdraw your consent, the PostHog entries are removed immediately.
Legal basis: Consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.
Managing cookie settings
On your first visit to our website, you will be informed about the use of cookies via a banner. You can change your settings at any time via the "Cookie Settings" link in the website footer. The "Accept All" and "Reject All" buttons are designed equally (GDPR-compliant, no dark patterns).
7. Analytics and error monitoring
PostHog
We use PostHog (PostHog Inc.) to analyse website usage. All data is processed exclusively on EU servers (eu.posthog.com). Your browser's requests go to our own domain and are forwarded to PostHog by our server. A Data Processing Agreement (DPA) is in place with PostHog.
Without your consent
Without your consent, PostHog transmits no usage data: no page views, clicks, or other events are collected, no session recording takes place, and no cookie, no local storage entry, and no session storage entry is set or read.
In that case the PostHog component is loaded solely to retrieve the configuration of our feature switches, which control which parts of the website are shown. All that is transmitted is an identifier of our project plus a random identifier that only ever exists in your browser's memory and is discarded when you leave the page.
Legal basis: Legitimate interest in operating a functioning website (Art. 6(1)(f) GDPR). Since nothing is stored on or read from your device in this case, § 25(1) TDDDG does not apply to this processing.
Only with your consent
Only once you consented to the PostHog service in the cookie banner do we collect:
- Page views
- Click behaviour and interactions with form elements
- Device type, browser, and operating system
- Screen size
- Time spent on pages
- Session recording (session replay): mouse movement, clicks, scrolling, visited URLs, and the page content displayed
For this, the cookie ph_<project-id>_posthog, a local storage entry of the same name, a session storage entry of the same name, and the cookie ph-identify are set to recognise your session across page views. No sign-in takes place; the data is not linked to any user account.
Retention period: Analytics data is automatically deleted after 12 months, session recordings after 30 days.
Legal basis: Consent (Art. 6(1)(a) GDPR) in conjunction with § 25(1) TDDDG. You may withdraw your consent at any time via the cookie settings. Session recording then stops immediately, collection ceases, and the entries that were set are removed.
More information: PostHog's privacy policy
Sentry
We use Sentry (Functional Software Inc. d/b/a Sentry, 132 Hawthorne Street, San Francisco, CA 94107, USA) for error detection and performance monitoring. Data is collected via Sentry's EU endpoint (ingest.de.sentry.io). A Data Processing Agreement (DPA) is in place with Sentry.
In your browser (consent required)
The Sentry SDK is only loaded and started if you consented to the Sentry service in the cookie banner.
Data collected:
- Error messages and stack traces
- Page views and load times (performance tracing)
- Anonymized session recordings (Session Replay — text is masked, media is blocked)
- Browser, operating system, and device type
- URL of the visited page
Legal basis: Consent (Art. 6(1)(a) GDPR) in conjunction with § 25(1) TDDDG. You may withdraw your consent at any time via the cookie settings.
On our server (independent of your consent)
Errors and response times of our server are recorded independently of your cookie settings. No cookies are set and no information is stored on or read from your device; § 25 TDDDG therefore does not apply to this processing.
Data collected:
- Error messages and stack traces of our server
- The requested path without query parameters — parameters such as
session_idorpaymentare removed before transmission - Response times and HTTP status code
The sendDefaultPii option is disabled; IP addresses, cookies, and request headers are not transmitted to Sentry.
Legal basis: Legitimate interest in the trouble-free and secure operation of our website (Art. 6(1)(f) GDPR).
Retention period: Error data is stored for 90 days, session replay data for 30 days.
Data transfer: Sentry is a US company; transfer to the USA cannot be ruled out. Sentry is certified under the EU-US Data Privacy Framework.
More information: Sentry's privacy policy
8. Payment processing
Stripe
We use the payment service provider Stripe (Stripe Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA) to process payments. Stripe is only loaded when you start the checkout process. A Data Processing Agreement (DPA) is in place with Stripe.
Data transmitted during a purchase:
- Payment data (credit card number, expiration date, CVC)
- Transaction information (amount, currency, order reference)
- Delivery country (for shipping cost calculation)
Retention period: Stripe stores transaction data in accordance with statutory retention requirements (typically 10 years).
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) in conjunction with § 25(2)(2) TDDDG (technically necessary for the payment process requested by the user). Stripe is certified under the EU-US Data Privacy Framework.
More information: Stripe's privacy policy
9. Order processing and customer data
When placing an order through our online shop, we process the following data:
- Name
- Email address
- Delivery address (for physical products)
- Order details (product, quantity, price)
Purpose: Contract fulfillment, shipping, and customer service.
Retention period: Order data is stored for 10 years in accordance with commercial and tax law retention requirements (§ 257 HGB, § 147 AO). After expiration, the data is deleted.
Recipients: Payment data is transmitted to Stripe (see section 8). For physical shipments, the name and delivery address are shared with the commissioned shipping provider.
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
Note: Providing your personal data is necessary for the conclusion of the contract. Without this data, we cannot process your order.
10. Recipients and data transfers
Your personal data is shared with the following categories of recipients:
| Recipient | Purpose | Location | Basis for third-country transfer |
|---|---|---|---|
| Cloudflare Inc. | Hosting, CDN, DDoS protection | USA | EU-US Data Privacy Framework |
| PostHog Inc. | Website analytics; collection, cookie and session recording only with consent | EU (Frankfurt) | — (no third-country transfer) |
| Sentry (Functional Software Inc.) | Error monitoring; in the browser only with consent, server-side based on legitimate interest | USA | EU-US Data Privacy Framework |
| Stripe Inc. | Payment processing | USA | EU-US Data Privacy Framework |
Beyond this, we only share data when legally obligated to do so (e.g. with tax authorities).
11. Your rights
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR) — You may request information about the personal data we process.
- Right to rectification (Art. 16 GDPR) — You may request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR) — You may request the deletion of your data, provided no statutory retention obligations apply (e.g. § 257 HGB: 10 years for commercial records). Deletion requests can be sent via email to the contact address above. We will respond within one month (Art. 12(3) GDPR).
- Right to restriction (Art. 18 GDPR) — You may request the restriction of processing of your data.
- Right to data portability (Art. 20 GDPR) — You may request that we provide your data in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21 GDPR) — You may object to the processing of your data at any time where the processing is based on legitimate interest.
- Right to withdraw consent (Art. 7(3) GDPR) — You may withdraw any given consent at any time with future effect, e.g. via the cookie settings in the footer.
12. Automated decision-making
No automated decision-making including profiling pursuant to Art. 22 GDPR takes place.
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.
Competent supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach, Germany https://www.lda.bayern.de
14. Changes
We reserve the right to update this privacy policy to reflect changes in legal requirements or our data processing practices. The current version can always be found on this page.