Privacy policy
What this website does with personal data, which is close to nothing.
1. Controller
The controller for processing on this website is:
- Controller
- TODO registered name including legal form, e.g. DPP Studio GmbH
- Address
- TODO street and house number, TODO postcode TODO city
- contact@dpp-studio.eu
- Data protection officer
- TODO data protection officer contact, or the words not appointed
2. The short version
This site sets no cookies, runs no analytics, embeds no third-party content and loads no external fonts. Nothing here tracks you across sites and nothing builds a profile. The only personal data that arises is what any web server unavoidably receives in order to send you a page, plus whatever you choose to hand us yourself: an email, or the data request form.
3. Server log data
When you open a page, your browser transmits data that our content delivery network processes to deliver it and to keep the service secure:
- IP address
- Date and time of the request
- The page or file requested, and the response status
- Referring page, where your browser sends one
- Browser type, version and operating system
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is delivering the site reliably and defending it against attack. This data is not used to identify you, and it is not combined with other sources.
Retention: our content delivery network retains request logs for a limited period for security and abuse handling, after which they are deleted or aggregated. We do not keep a separate copy.
4. Network error reports
Our content delivery network sends a Network Error Logging header. If a request to this site fails at the network level, your browser may transmit a report about that failure, including your IP address, to Cloudflare's reporting endpoint. Successful requests are not reported. The legal basis is Art. 6 (1) (f) GDPR, our interest being to detect connectivity faults that would otherwise be invisible to us.
5. Contacting us
If you write to us, or use the enquiry form, we process your name, your email address and the content of your message, in order to answer. The form asks for nothing beyond those three things. The legal basis is Art. 6 (1) (b) GDPR where your enquiry concerns a contract or steps prior to one, and otherwise Art. 6 (1) (f) GDPR. We keep such correspondence for as long as needed to deal with the matter, and longer only where statutory retention periods under commercial or tax law require it. We do not use it to send you anything you did not ask for.
6. The data request form
If you use the data request form, we process the right you invoke, your name, your email address and anything you write in the details field, in order to identify your records and answer you. The legal basis is Art. 6 (1) (c) GDPR: responding is a legal obligation under Art. 12 GDPR. The form submits directly to our own endpoint; no form service, captcha provider or analytics sits in between, and the page runs no scripts. Submissions are delivered to us by email through the processor named below and kept only as long as needed to handle the request and to evidence that we handled it.
Email delivery
Form submissions are delivered by Resend, Inc., acting as our processor under Art. 28 GDPR. Delivery is configured to their EU region, so message content is processed on servers in the European Union. They then pass through the mail providers named in section 7 before reaching us.
7. Processors and recipients
Cloudflare
This site is hosted and delivered by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, acting as our processor under Art. 28 GDPR. Cloudflare operates edge servers worldwide, so requests are usually served from within the EU, but a transfer to the United States cannot be ruled out. Such transfers are covered by the European Commission's standard contractual clauses and by Cloudflare's certification under the EU-U.S. Data Privacy Framework, adopted as adequate by the Commission on 10 July 2023.
Mail we receive
Mail addressed to this domain is routed by Cloudflare Email Routing and forwarded to a mailbox we hold with Heinlein Hosting GmbH(mailbox.org), Schwedter Str. 8/9b, 10119 Berlin, Germany, acting as our processor under Art. 28 GDPR and processing on servers in Germany. Anything you send us, including a data subject request, is stored there until we have dealt with it.
Beyond that we disclose personal data only where we are legally obliged to, for instance to law enforcement.
8. No cookies and no tracking
We store nothing on your device and read nothing from it, so no consent under § 25 TDDDG is required and you will not be shown a consent banner. Concretely, this site contains:
- no cookies of our own and none set by anyone else
- no analytics or measurement of any kind
- no advertising, remarketing or conversion tracking
- no social media plugins or embedded video
- no externally hosted fonts. Typefaces are served from our own domain, so no request reaches Google Fonts or any comparable service
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have data erased (Art. 17)
- have processing restricted (Art. 18)
- receive your data in a portable form (Art. 20)
- object to processing based on legitimate interest, on grounds relating to your particular situation (Art. 21)
The quickest route is the data request form, which asks only for what we need to find your records. Writing to contact@dpp-studio.eu works just as well; no particular form is required. We answer within one month (Art. 12 (3) GDPR).
You also have the right to complain to a supervisory authority (Art. 77 GDPR), either where you live, where you work, or where the alleged infringement took place. The authority competent for us is:
- Supervisory authority
- TODO competent supervisory authority for your seat
10. Is providing data required?
No. You are not obliged to provide any personal data. The log data described above arises unavoidably from the technical act of requesting a page; if you do not want it processed, do not open the site. Not writing to us has no consequence other than that we cannot answer.
11. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
12. Changes
We update this policy when the site changes or the legal position does. The date below marks the current version.
Last updated 2026-07-25