This privacy policy explains which personal data is processed when you visit and use projekt38.io. Personal data is any information relating to an identified or identifiable person.
1. Controller
Christopher Hellwig
projekt38
c/o Postflex #10017
Emsdettener Str. 10
48268 Greven
Germany
Email: hello@projekt38.io
2. Purposes and legal bases
We process personal data only where necessary to provide this website securely, handle project enquiries, communicate, measure reach after consent, or comply with legal obligations.
Depending on the processing, we rely in particular on Article 6(1)(a) GDPR where consent has been given, Article 6(1)(b) GDPR for contracts and pre-contractual steps taken at the data subject’s request, Article 6(1)(c) GDPR for compliance with legal obligations, and Article 6(1)(f) GDPR for our legitimate interests, in particular the secure, stable and commercially viable operation of this website.
Consent may be withdrawn at any time with future effect. Processing carried out before withdrawal remains lawful.
3. Hosting, email and server logs
This website and its email accounts are hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When the website is accessed, IONOS processes technically necessary access data. This may include the IP address, date and time, requested address or file, transferred data volume, HTTP status code, referrer, browser type and version, and operating system.
The processing serves delivery, stability, error analysis and attack prevention. The legal basis is Article 6(1)(f) GDPR. Log data is deleted or anonymised according to the retention periods applicable to the hosting product unless it must exceptionally be retained to investigate a specific security incident. A data processing agreement pursuant to Article 28 GDPR is in place with IONOS. More information is available in the IONOS privacy policy.
4. Encrypted transmission
The website uses TLS encryption. This protects data transmitted between the browser and server against unauthorised interception while in transit.
5. Technically necessary functions and language selection
WordPress may set technically necessary cookies, particularly when authorised users are signed into the administration area. We use Polylang for language selection. Depending on its configuration, the selected language may be stored in a technically necessary cookie so that the requested language version can be delivered. The legal basis is Article 6(1)(f) GDPR; access to the device is permitted by Section 25(2)(2) TDDDG.
6. Consent management with Borlabs Cookie
We use Borlabs Cookie to manage consent and cookie settings. The selected settings, a consent identifier, the version and time of consent, and technical domain, path and lifetime information are stored. Borlabs Cookie runs on our website; according to the provider, consent data is not transmitted to Borlabs.
The necessary consent preference is stored on the basis of Section 25(2)(2) TDDDG and Article 6(1)(c) and (f) GDPR. Optional services are activated only after consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR. Choices can be changed for the future at any time through the cookie settings provided by Borlabs. Further information is available from Borlabs.
7. Project enquiries and contact
When you use the project enquiry form, we process your name, email address, requested service and message. Company or brand and budget range are optional. We process this data to review your enquiry, clarify questions, prepare a proposal and continue communication. The legal basis is Article 6(1)(b) GDPR. Where an enquiry is not directed towards a contract, processing may be based on our legitimate interest in answering business enquiries under Article 6(1)(f) GDPR.
The enquiry is sent by email to our IONOS mailbox and is not additionally stored by the theme in the WordPress database. To prevent automated or excessive submissions, a non-reversible check value is derived from the IP address and temporarily stored for rate limiting for no more than one hour. It is not used for advertising or profiling.
If you contact us by email, we process the sender address, content, time and technical delivery information in order to respond. Enquiries are deleted when their handling is complete unless statutory retention duties or legitimate evidentiary interests require longer storage. If an enquiry results in a contract, necessary business records are retained for the statutory periods.
8. Website security with Wordfence
We use Wordfence Security to protect against malware, unauthorised access and automated attacks. The provider is Defiant, Inc., USA. Wordfence may inspect security-relevant requests and process the IP address, requested URL, referrer, user agent, time, login attempts and detected security events. Processing is exclusively for IT security and is based on Article 6(1)(f) GDPR.
Security logs are regularly retained for no more than 30 days according to the Wordfence configuration unless a specific incident requires longer retention. Certain Wordfence features may transfer data to the United States. Where required, transfers are based on appropriate safeguards, in particular the EU Standard Contractual Clauses. Further information is available in the Wordfence privacy policy and Data Processing Addendum.
9. Backups
UpdraftPlus may be used for regular backups. In the intended live configuration, backup files are stored within the hosting infrastructure provided by IONOS and are accessible only to authorised administrators. They may contain website content, configuration data and personal data temporarily contained in email or security logs. Backups are overwritten or deleted according to the defined backup cycle. If an external storage provider is used in the future, this policy will be updated before that provider is enabled.
10. Google Analytics 4
After you consent, we use Google Analytics 4 to measure website usage statistically. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics may process page views, interactions, session data, approximate location, referrer, browser and device information, and random online identifiers. A cookie such as _ga may be used for recognition.
Google Analytics is loaded through Borlabs Cookie only after consent. The legal basis for storing or accessing information on your device is Section 25(1) TDDDG; subsequent processing is based on Article 6(1)(a) GDPR. Consent can be withdrawn at any time through the cookie settings.
According to Google, individual IP addresses of users in the EU are not logged or stored. The IP address is used to derive coarse location information and discarded before logging. We limit user-level event data retention to 14 months and disable Google Signals and advertising personalisation unless separate consent and documentation have been implemented.
Processing by Google LLC in the United States cannot be ruled out. According to Google, applicable safeguards are used for international transfers. More information is available in the Google Analytics privacy information and Google privacy policy.
11. Google Search Console
We use Google Search Console to monitor how the website is found in Google Search and to identify technical issues. Domain ownership is verified by DNS record or a static verification marker. This does not load an analytics script or set an additional cookie for visitors on this website. Google provides us with aggregated information about search queries, impressions, clicks and technical website properties. Google is independently responsible for data it already processes when its search engine is used. More information is available in the Google privacy policy.
12. Locally hosted media and fonts; external links
Fonts, images and videos used on this website are generally delivered from our own web space. Simply loading a page therefore does not create an additional connection to a font, video or social media provider.
Links to projects, clients, Instagram, Facebook and LinkedIn are ordinary external links. A connection to the respective provider is made only after the link is clicked. From that point, the provider’s privacy terms apply.
13. Recipients and processors
We disclose personal data only where necessary for the purposes described, where required by law, or where consent has been given. Processors and technical recipients may in particular include hosting, email, security and analytics providers. Where required, we enter into agreements with processors pursuant to Article 28 GDPR.
14. Retention
Unless a specific period is stated in this policy, we delete personal data when the purpose of processing no longer applies. Data is retained for longer only where statutory retention duties apply or where it is required to establish, exercise or defend legal claims.
15. Your rights
Subject to the statutory requirements, you have rights including access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), data portability (Article 20 GDPR), objection to processing based on Article 6(1)(f) GDPR (Article 21 GDPR), and withdrawal of consent with future effect (Article 7(3) GDPR).
To exercise your rights, email hello@projekt38.io. We may request reasonable proof of identity to avoid disclosure to unauthorised persons.
You also have the right to lodge a complaint with a data protection supervisory authority. Our competent authority is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, P.O. Box 20 04 44, 40102 Düsseldorf, Germany, telephone +49 (0)211 38424-0. Information and the complaint form are available at www.ldi.nrw.de.
16. Automated decisions
No solely automated decision producing legal or similarly significant effects within the meaning of Article 22 GDPR takes place on this website.
17. Updates to this policy
We update this privacy policy when the website, the services used or legal requirements change. The version published on this page applies.