1. Controller

Privacy requests can be submitted through the secure contact form.
2. Website access
The web server processes technically necessary information such as IP address, time, requested file, referrer, browser and operating system. This is required for secure delivery, fault analysis and abuse prevention under Art. 6(1)(f) GDPR. Server logs are retained only as long as necessary for operation and security.
3. Contact and test-user form
When you submit a form, we process your name, reply address, message, form type, time and the IP address used for abuse prevention. The purpose is to process your request or application for testing. The legal basis is Art. 6(1)(b) GDPR for pre-contractual enquiries and otherwise Art. 6(1)(f) GDPR.
Messages are sent through our configured mail server to an internal mailbox. Recipient addresses are not included in publicly delivered website code. Requests are deleted when they are no longer needed and no statutory obligation requires retention.
4. Account deletion request
For a deletion request we process the account email address, name and additional details to verify ownership and carry out deletion. Once verified, the account and related cloud data are deleted. Billing or business records required by law may be retained for statutory periods.
5. Optional audience measurement with Umami
After your explicit consent, the website and dashboard use the open-source Umami software hosted on our own server. It processes page views, page title, referrer, time and technical information about browser, operating system, device, screen size, language and approximate geographic region. Umami does not set analytics cookies, receive form content, serve advertising or create personally identifiable user profiles. Dynamic record IDs are removed from dashboard paths before transfer; no user ID or email address is sent. Session replay and heatmaps are not used.
Processing occurs only after consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG. Without consent, the analytics script is not loaded. You can withdraw your choice under Consent settings or “Analytics settings” in the dashboard. Analytics data remains on our Hetzner server.
6. Consent and local storage
The website uses no analytics or marketing cookies and does not automatically load external media. Only your consent selection and its time are stored locally in your browser.
7. Images and fonts
Fonts, stylesheets, scripts, app screenshots and landscape images are served from our own server. Linked image credits are opened only when selected.
8. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority. Use the contact form or Delete account and data.
9. Version
Last updated: 3 August 2026. This policy is updated if functions or legal grounds change.