Privacy Policy
Last updated: 23 August 2026
This privacy policy explains what personal data is collected when you use this website, how it is used, and what your rights are under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for data processing on this website is:
Ram Bambani (trading as Quadra)
Stralauer Platz 35, 10243 Berlin
Email: quadramethod@gmail.com
Phone: +49 15510466576
See also the Legal Notice.
2. General information
Quadra takes the protection of your personal data seriously. Personal data is processed confidentially, in accordance with statutory data protection regulations and this privacy policy.
Please note that data transmission over the internet (e.g. communication by email) can have security gaps. Complete protection of data against access by third parties is not possible.
3. Hosting
This website is hosted by Netlify, Inc., 101 2nd Street, Suite 575, San Francisco, CA 94105, USA. When you visit this website, Netlify automatically collects and stores information in server log files that your browser transmits, including:
- browser type and version
- operating system used
- referrer URL
- IP address
- date and time of the server request
This data is processed on the basis of Art. 6 (1) (f) GDPR for the technical operation, stability, and security of the website. A data processing agreement (DPA) under Art. 28 GDPR is in place with Netlify. Netlify processes data in the USA; the transfer is based on the EU–US Data Privacy Framework, see Data Privacy Framework. For details on Netlify's own privacy practices, see netlify.com/privacy.
4. Contact form
If you send an enquiry using the contact form on this website, the information you provide (name, email address, message, and any voluntary details) will be processed to respond to your request and, where applicable, to prepare a session or booking.
Form submissions are processed via Netlify Forms and stored on Netlify's infrastructure in the USA. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in responding to enquiries). Please do not include health-related information in the contact form. Such details are discussed with you directly — see section 14 below.
The form uses a simple math question as a spam protection measure. No cookies are set by the form itself.
Data submitted via the contact form is retained only as long as necessary to respond to your enquiry, or as required by applicable retention obligations. You may request deletion at any time by contacting quadramethod@gmail.com.
5. Online booking (Setmore)
Online booking is handled through Setmore, a third-party scheduling service operated by Setmore Inc. When you use the booking function, you are redirected to Setmore's own booking page, and your data (name, email, phone, appointment details) is processed by Setmore under its own privacy terms. No Setmore code is loaded on this website. Data is only transmitted to Setmore once you click the booking link and use the booking page.
The legal basis for using this service is Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures) and, where applicable, Art. 6 (1) (a) GDPR (your consent).
As Setmore Inc. is based in the USA, transfers are based on the EU Standard Contractual Clauses. Setmore is not certified under the EU–US Data Privacy Framework.
Please review Setmore's privacy policy before booking: setmore.com/privacy-policy.
6. WhatsApp, Instagram, and external channels
If you contact Quadra via WhatsApp, Instagram, email, or any other third-party platform, your data will be processed by those providers according to their own privacy policies. Please only use these services if you agree to their terms.
Messages received through these channels are used solely to respond to your enquiry and are not shared with third parties beyond what is technically necessary to operate the respective platform.
7. Web fonts (Bunny Fonts)
This site uses Bunny Fonts, a privacy-friendly, GDPR-compliant web font service provided by BunnyWay d.o.o., Cesta komandanta Staneta 4A, 4260 Bled, Slovenia. Bunny Fonts does not set cookies, does not track users, and does not log IP addresses beyond what is technically required to deliver the fonts.
Fonts are served from fonts.bunny.net. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a consistent, professional presentation of the website). More information: bunny.net/privacy.
8. Cookies and local storage
This website does not use tracking, analytics, or marketing cookies. No third-party trackers, no Google Analytics, no Meta Pixel, no advertising cookies are set.
The site may use your browser's local storage for strictly necessary functionality, for example to detect your language preferences or to remember whether you have dismissed the cookie information banner, so it is not shown to you repeatedly. This does not involve any personal data and is not shared with third parties.
The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the technically correct and user-friendly operation of the website) and § 25 para. 2 No. 2 TDDDG (strictly necessary storage on the terminal equipment).
9. SSL / TLS encryption
For security reasons and to protect the transmission of confidential content — such as enquiries you send via the contact form — this site uses SSL/TLS encryption. You can recognise an encrypted connection by the https:// prefix in the address bar and the padlock symbol in your browser.
10. Data retention
Personal data is retained only as long as necessary for the purpose it was collected for, or as required by law. The following periods apply:
- Contact form enquiries that do not lead to a booking: deleted after 6 months
- Booking data in Setmore: deleted 12 months after the appointment
- Invoices and accounting records: retained for the statutory periods under German tax law (§ 147 AO, § 14b UStG)
- Health-related session information: deleted 3 years after your last session
- Server log files: in accordance with Netlify's own retention periods
Where a statutory retention obligation applies, data is restricted from further processing rather than deleted until the period expires.
11. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — obtain confirmation and a copy of your data
- Right to rectification (Art. 16 GDPR) — correct inaccurate data
- Right to erasure (Art. 17 GDPR) — request deletion of your data
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, please contact quadramethod@gmail.com.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Berlin is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin
Website: datenschutz-berlin.de
13. Payments
Card and contactless payments are processed by Stripe Technology Company Limited (STC), One Wilton Park,Wilton Place, Dublin 2, D02 FX04, Ireland. Stripe processes your payment data (card details, name, amount, date and time). Card data is entered directly with Stripe and is not accessible to Quadra.
Stripe acts partly as an independent controller for fraud prevention and regulatory purposes. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (compliance with legal obligations under tax law). Stripe may transfer data to the USA; details and applicable safeguards are set out in Stripe's privacy policy: stripe.com/privacy.
Payment receipts are issued electronically. Accounting records are retained for the statutory periods described in section 10. No Stripe code is loaded on this website.
In-person payments may also be made via PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg (R.C.S. Luxembourg B 118 349). PayPal acts as an independent controller. The legal basis is Art. 6 (1) (b) and Art. 6 (1) (c) GDPR. See PayPal's privacy policy.
14. Health-related information
Where a session requires it, information about your physical condition (for example injuries, pain, pregnancy, medication, or physical limitations) may be processed. This constitutes data concerning health under Art. 9 GDPR and is subject to special protection.
Such information is collected in person at your first session on the basis of your explicit consent under Art. 9 (2) (a) GDPR. It is not collected through this website, the contact form, the online booking system, or messaging services such as WhatsApp or Instagram.
This information is stored separately from the online tools used for booking and enquiries, and is deleted three years after your last session. You may withdraw your consent at any time with effect for the future, without giving reasons. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
15. Changes to this policy
This privacy policy may be updated from time to time to reflect changes in the services offered, in the tools used on this website, or in applicable legal requirements. The current version is always available on this page, with the "Last updated" date at the top.
16. Contact regarding privacy
For privacy-related questions, please contact:
Ram Bambani
Email: quadramethod@gmail.com