Privacy Policy

This policy explains what happens to personal data when you use this website. It describes only the processing that actually takes place here.

Last updated: 18 September 2026

1. Controller

Refinery One UG (haftungsbeschränkt)

Immanuelkirchstraße 33, 10405 Berlin, Germany

Represented by Dr. Elisa Minou Zarbafi

Email: info@refinery.one

The controller decides on the purposes and means of processing personal data in connection with this website and the coaching services offered on it.

2. Hosting and server log data

This website is hosted and delivered through the hosting infrastructure of Lovable (lovable.app), which serves the site via a content delivery network. When you visit the site, the infrastructure necessarily processes technical information, in particular:

IP address · date and time of access · the pages and files requested · browser type and version · operating system and device information · referring website · transferred data volume and status information.

This data is processed to deliver the website reliably, to maintain stability and to protect it against misuse and attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and functional provision of the website). Log data is not used to identify you personally and is not merged with other data sources.

3. Fonts

The Montserrat typeface used on this website is hosted locally and delivered from the same hosting infrastructure as the website itself. No font files are requested from Google Fonts or any other external provider, and no data is transmitted to Google when you visit this site.

4. Appointment scheduling with Calendly

Appointments are booked through Calendly, a scheduling service of Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. Calendly is a third-party service and an independent recipient of the data you enter.

The booking pages used are:

Introductory session: calendly.com/minoo-refinery/introductory-session
Coaching session: calendly.com/minoo-refinery/coaching-session

Depending on what you provide, Calendly may process your name, email address, the selected date and time, your time zone, answers to booking questions, any information you voluntarily enter, and technical data such as your IP address and browser information. Calendly also sets cookies and similar storage in its own frame.

Calendly is only loaded after you actively agree. Until then, no data is transmitted to Calendly. The legal basis for loading Calendly and any related cookies is your consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw your consent at any time with effect for the future; withdrawal does not affect processing that already took place.

Data may be transferred to the United States. Calendly relies on the EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Further information: calendly.com/privacy.

Current status of your Calendly consent on this device: not granted

5. Contact form and contact by email

The contact form on this website collects your name, your email address and the content of your message. The time of submission and the technical information necessary for secure processing of the request are also processed. The data is used to respond to your enquiry and, where relevant, to prepare or perform a contractual relationship. The legal basis is Art. 6(1)(b) GDPR for contractual or pre-contractual communication and otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).

Submissions are transmitted server-side; no email address of the controller is exposed in the form and no data is sent to a third-party form service. The message is then delivered by email using the email infrastructure of our hosting provider, Lovable (Lovable Labs Incorporated, 2261 Market Street, San Francisco, CA 94114, USA), acting as a processor under Art. 28 GDPR. Depending on the delivery route this can involve processing in the United States on the basis of the EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Emails are sent from a subdomain of refinery.one and delivered to the mailbox info@refinery.one. Enquiries received by email are stored until they are no longer needed and statutory retention periods have expired.

To prevent automated spam, the form contains a hidden field that is not visible to you and checks how quickly the form was submitted. No cookies, tracking, profiling or CAPTCHA service are used for this. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in protecting the form against misuse).

You can of course also write directly to the email address stated in the Imprint. Please only provide what is necessary for your enquiry and do not submit sensitive personal information through the form.

6. Coaching bookings and the coaching relationship

Information supplied when booking is used to arrange the appointment, to communicate with you, to prepare appropriately for the requested session and to perform the coaching relationship. The legal basis is Art. 6(1)(b) GDPR.

Please only provide what is needed to arrange the appointment. There is no need to submit sensitive personal information such as health data through the website or the booking form — anything you wish to discuss can be addressed in the conversation itself. Coaching conversations are treated confidentially.

7. Payments

No payment provider is integrated into this website at present, and no payment data is collected here. If online payment is added in future, this policy will be updated before it goes live.

8. Cookies and local storage

This website does not set advertising or tracking cookies. Apart from the technically necessary operation of the site, the only storage used is a single entry in your browser's local storage that remembers whether you agreed to load Calendly. It contains no identifier and is only read on this website. The legal basis is Art. 6(1)(f) GDPR / § 25(2) TDDDG, as it is strictly necessary to respect your choice.

Cookies and similar technologies of Calendly are only set inside the Calendly frame after you have consented (see section 4).

9. Analytics

No web analytics or advertising tools such as Google Analytics or Meta Pixel are used on this website. The hosting platform may process technical error and availability information in order to operate the site securely, as described under hosting above.

10. LinkedIn

The footer contains a plain hyperlink to a LinkedIn profile. No LinkedIn plugin, button or tracking code is embedded, so no data is transmitted to LinkedIn until you actively click the link and leave this website. From that point, LinkedIn's own privacy policy applies.

11. Recipients and processors

Personal data is only disclosed where necessary: to the hosting provider that operates this website, to Calendly for appointments you book, and to the email provider used for correspondence. Where these act on instructions, data processing agreements under Art. 28 GDPR are in place. Data may also be disclosed where required by law.

12. Retention

Personal data is kept only as long as needed for the purpose it was collected for. Enquiries and booking data are deleted once the matter is concluded and no longer needed. Where statutory retention obligations apply — in particular commercial and tax law periods of six or ten years — data is retained for that period and processing is restricted to that purpose.

13. Your rights

Under the GDPR you have the right of access (Art. 15), the right to rectification (Art. 16), the right to erasure (Art. 17), the right to restriction of processing (Art. 18), the right to data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7(3)).

To exercise your rights, write to info@refinery.one. You also have the right to lodge a complaint with a competent data protection supervisory authority, for example the authority in your place of residence or workplace, or the authority responsible for the controller.

14. Security

Appropriate technical and organisational measures are in place to protect personal data against loss, misuse and unauthorised access — including encrypted transmission via TLS/HTTPS, access limited to those who need it, and services selected for their security standards. No system can be entirely secure, but the measures are reviewed as technology develops.

15. Updates to this policy

This policy may be updated when the website, the services used or the legal requirements change. The current version always applies, with the date shown at the top of this page.