You agree to the privacy policy below, and the Privacy Policy for Substack, the technology provider.
Last updated: December 7, 2025
This Privacy Policy explains how Andreas Horn, located in Germany (”we,” “us,” or “our”), collects, uses, discloses, and protects your personal data when you subscribe to or interact with our newsletter hosted on Substack ( https://hornandreas.substack.com, the “Newsletter”). We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
As the data controller, our contact details are:
Andreas Horn
Email: hornandreas@substack.com
1. Personal Data We Collect
We collect the following personal data when you subscribe or interact with our Newsletter:
Contact Information: Name, email address, and any other details you provide during subscription.
Payment Information (if applicable for paid subscriptions): Processed securely by Substack (as our data processor) and not stored by us.
Usage Data: Automatically collected information such as IP address, browser type, device information, and interaction data (e.g., opens, clicks) via Substack’s tools.
Other Data: Any information you voluntarily provide, such as comments or feedback.
We do not collect sensitive personal data unless explicitly provided by you.
2. How We Collect Your Data
Directly from You: When you sign up for the Newsletter, make a payment, or contact us.
Automatically: Through cookies and similar technologies on Substack’s platform (see Substack’s Privacy Policy at https://substack.com/privacy for details).
From Third Parties: Substack may share subscriber data with us as necessary for Newsletter delivery.
3. Purposes and Legal Basis for Processing
We process your personal data for the following purposes:
To Provide the Newsletter: Sending emails, managing subscriptions, and delivering content (Legal basis: Performance of a contract – Art. 6(1)(b) GDPR).
To Improve Our Services: Analyzing usage to enhance content and user experience (Legal basis: Legitimate interests – Art. 6(1)(f) GDPR; our interest in service improvement balanced against your privacy rights).
Marketing: Sending promotional emails about updates or related content, only with your consent (Legal basis: Consent – Art. 6(1)(a) GDPR). You can withdraw consent anytime via unsubscribe links or by emailing us.
Compliance and Protection: To comply with legal obligations, prevent fraud, or enforce our terms (Legal basis: Legal obligation – Art. 6(1)(c) GDPR; Legitimate interests – Art. 6(1)(f) GDPR).
We only process data as necessary and do not use it for automated decision-making that significantly affects you.
4. Sharing Your Data
We share your personal data with:
Substack Inc.: As our data processor for hosting, email delivery, and payments. Substack is based in the US and complies with the EU-U.S. Data Privacy Framework (see their Privacy Policy).
Service Providers: Third-party tools for analytics or email services, bound by data processing agreements ensuring GDPR compliance.
Legal Authorities: If required by law, such as for tax or regulatory purposes.
We do not sell your data to third parties.
5. International Data Transfers
Your data may be transferred outside the EU/EEA, primarily to the US via Substack. We ensure adequate safeguards, such as EU Standard Contractual Clauses or reliance on the EU-U.S. Data Privacy Framework. For more details, contact us.
6. Data Retention
We retain your personal data only as long as necessary:
Subscription data: Until you unsubscribe or we delete inactive accounts (e.g., after 2 years of inactivity).
Payment data: As required by tax laws (e.g., 10 years in Germany).
Usage data: Up to 1 year for analytics.
Data is securely deleted or anonymized when no longer needed.
7. Your Rights Under GDPR
You have the following rights:
Access, rectification, erasure, restriction of processing, data portability, and objection to processing.
Withdraw consent at any time (without affecting prior processing).
Lodge a complaint with a supervisory authority, such as the German Federal Commissioner for Data Protection and Freedom of Information (BfDI).
To exercise these rights, email us at [Your Contact Email]. We respond within one month.
8. Security
We implement appropriate technical and organizational measures to protect your data, such as encryption and access controls. However, no system is completely secure, so we cannot guarantee absolute protection.
9. Children’s Privacy
Our Newsletter is not intended for children under 16. We do not knowingly collect data from them.
10. Changes to This Policy
We may update this Policy. Changes will be posted here with the updated date. Significant changes will be notified via email.
If you have questions, contact us at hornandreas@substack.com

