Legal
Privacy & Cookies
This privacy notice explains which personal data may be processed when you visit kulicadvisory.com, contact Kulic Advisory, request documents, or use an intake form.
Controller
Dario Kulic, trading as KULIC Advisory, Hansaring 28, 50670 Cologne, Germany. Email: dario@kulicadvisory.com, phone: +49 157 852 34224.
Purposes and legal bases
Personal data is processed to provide the website securely, answer requests, send requested documents or information, assess advisory fit, prepare meetings, and meet legal obligations. Depending on the context, the legal bases may include pre-contractual requests, legitimate interests in secure website delivery and business communication, legal obligations, or consent where you explicitly provide it.
Contact, document requests, and Executive Intake
When you use the Executive Intake, the browser submits the form inside this website to a same-origin endpoint after client-side and server-side validation. An accepted request is stored first in Cloudflare D1 and the browser receives a short KA reference. Email is a secondary notification only; email delivery does not determine whether the Intake was recorded. Preview and Production use separate databases. No attachments are accepted, records expire after 30 calendar days, and scheduled cleanup removes expired records. Intake fields are not sent to Matomo or written to Analytics Engine, and the Intake record does not store an IP address, user agent, cookie or analytics identifier. Do not submit confidential information before a separate NDA or written agreement. Direct email contact remains available for general questions and is separate from the in-site Executive Intake.
Signal Letter
Public Signal Letter signup and email collection are currently inactive. The site directs visitors to the Signal Library or the normal contact route until a verified consent and double-opt-in process is available.
Website delivery and hosting
When the website is loaded, technically necessary access data may be processed, such as IP address, time of request, requested file, browser type, operating system, and security events. Hosting and infrastructure providers may process such data to deliver the site, detect attacks, analyze errors, and maintain availability. Where providers process data on behalf of Kulic Advisory, appropriate contractual arrangements are used. The static site is delivered through Cloudflare Pages/CDN; full-length homepage films are served from the KULIC Advisory media domain on Cloudflare R2. Web fonts are served locally from this website and are not requested from Google Fonts at page load.
Cookies and local functions
The current website does not intentionally set marketing cookies. It stores the consent
choice under kulic_cookie_choice in local browser storage so the banner can
remember Accept or Reject for up to 180 days. The preference can be reset through the
Privacy settings control in the footer. The site does not store UTM parameters or LinkedIn
campaign identifiers in local or session browser storage. See the
Cookie Policy for the current key and purpose inventory.
Cloudflare security cookie
Cloudflare may set a security cookie such as cf_clearance after a visitor
passes a security or bot-protection challenge. It allows Cloudflare to recognize that
the browser has completed the challenge and helps protect the website from abusive or
automated traffic. The cookie is provided and controlled by Cloudflare and is not used
by KULIC Advisory for advertising or campaign attribution. Its duration depends on the
active Cloudflare security configuration.
Optional analytics and consent
Matomo is optional and currently inactive unless an approved Matomo URL and site ID are configured and you have accepted optional analysis. No Matomo script or event is queued before consent. Any later activation requires a separate technical and legal preflight.
KULIC Signal Guide™
The AICTIONBOT™ Signal Guide combines deterministic routing with an optional generative-AI signal read. Processing starts only after you deliberately submit free text. Your message, the page language, the current page and up to six recent conversation turns may then be transmitted through Cloudflare infrastructure to Anthropic as our AI provider when the feature is configured and enabled. The API key stays server-side. This website does not persistently store your transcript and writes no chat cookies, localStorage or sessionStorage; the in-page /clear command resets the visible session but does not delete provider-side records. Do not enter confidential, personal, employee, supplier, contract or commercially sensitive information. AI output may be incomplete or incorrect and no automated decision with legal or contractual effect is made. A deterministic offline fallback exists and the feature can be disabled.
Stripe payments
Paid public offers are for business clients and professional organizations only. Payments are handled through approved Stripe Checkout links. KULIC Advisory does not process card data directly on this site. Stripe applies its own privacy information when you open its Checkout domain.
Retention
Executive Intake records are assigned a 30-calendar-day expiry and scheduled cleanup removes expired records. Other inquiries that do not lead to work are generally reviewed and deleted when they are no longer needed. Contract and invoice documents may be retained according to statutory obligations. Consent records may be retained as evidence where required. Server-log retention depends on provider settings and security needs.
Recipients
Personal data is shared only where necessary to answer a request, where you have consented, where a legal duty applies, or where technical service providers are used for website delivery, communication, or security.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, data portability, or object to certain processing. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
Complaint right
You have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the member state of your habitual residence, workplace, or the place of the alleged infringement.
Status
Status of this privacy notice: July 2026. It may be updated if the website, contact paths, or service providers change.