Privacy Notice

Effective date: 28. October 2025

This Privacy Notice explains how personal data is processed on the website of Denis Schlusche (“Website”), what your rights are, and how to contact us.

1. Controller (Art. 4(7) GDPR)

Name: Denis Schlusche
Email: hey@denis-schlusche.dev
No Data Protection Officer has been appointed.

2. Purposes, data categories, legal bases

2.1 Visiting the website / server log files

Data: IP address, date/time, requested URL, referrer, user agent, error codes (if any).
Purpose: Delivering the website, stability and security (e.g., preventing attacks).
Legal basis: Art. 6(1)(f) GDPR (legitimate interests in secure and stable operation).
Retention: 365 days (longer only in case of security incidents).

2.2 Contact via form or email

Data: Name, email address, your message, metadata.
Purpose: Handling your inquiry and communicating with you.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) or Art. 6(1)(f) GDPR (balancing of interests).
Retention: until deletion upon your request and/or until the purpose ceases and statutory retention ends.

2.3 Google reCAPTCHA (v3) – spam protection

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (with possible transfers to Google LLC, USA).
Data: IP address, browser/device information, mouse/keyboard interactions, referrer URL; analysed by Google to detect bots.
Purpose: Protect forms against automated abuse.
Legal basis: Art. 6(1)(a) GDPR (consent) via the consent banner before loading reCAPTCHA.
Note: Data may be transferred to third countries (incl. the USA); safeguards include EU Standard Contractual Clauses / adequacy decisions.
Withdrawal: at any time via the cookie/privacy settings.

2.4 Google Fonts (loaded from Google servers)

Provider: Google Ireland Limited, Dublin, Ireland.
Data: When fonts are requested, your IP address is transmitted to Google.
Purpose: Consistent, performant font rendering.
Legal basis: Art. 6(1)(a) GDPR (consent) via the consent banner, as fonts are fetched from Google servers.

3. Cookies & consent management

This Website uses only technically necessary means and – if you consent – Google reCAPTCHA (v3) and Google Fonts (CDN).

  • Legal basis: necessary elements: Art. 6(1)(f) GDPR; reCAPTCHA/Google Fonts: Art. 6(1)(a) GDPR (consent).
  • Settings/withdrawal: you can change your choices at any time via the cookie/privacy settings.

4. Recipients / processors

  • Hosting/server operation: STRATO AG, Otto-Ostrowski-Str. 7, 10249 Berlin, Germany (processing under Art. 28 GDPR).
  • Email/communication: depending on the controller’s infrastructure (e.g., hoster mail servers).
  • reCAPTCHA & Google Fonts: Google Ireland Limited (with possible transfers to Google LLC, USA).

Data Processing Agreements are in place with service providers where required (Art. 28 GDPR).

 

5. International data transfers

Using Google reCAPTCHA and Google Fonts (CDN) may involve transfers to third countries (incl. the USA). Legal safeguards include adequacy decisions and/or EU Standard Contractual Clauses and additional measures. Consent is required; see Sections 2.3/2.4 and 3.

 

6. Retention

We keep personal data only as long as necessary for the respective purposes or as required by law. Specific periods: server log files 365 days; contact inquiries until deletion upon request and/or until the purpose ceases.

 

7. Your rights (Arts. 12–22, 77 GDPR)

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to certain processing (Art. 21 GDPR)
  • Withdrawal of consent with future effect (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a supervisory authority. For our location, this is:

Unabhängiges Datenschutzzentrum Saarland (Supervisory Authority)
Fritz-Dobisch-Str. 12, 66111 Saarbrücken, Germany
Phone +49 681 94781-0 · Email: poststelle@datenschutz.saarland.de · Website: datenschutz.saarland.de

8. Obligation to provide data / automated decisions

You are not legally required to provide personal data; however, some functions (e.g., contact form) will not work without certain details. There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.

 

9. Security

We implement appropriate technical and organisational measures (e.g., TLS encryption, access controls, backups) to protect personal data against loss, misuse and unauthorised access.

 

10. Changes

We may update this Privacy Notice when services, legal requirements or technical conditions change. The current version is always available here.

Cookie-Privacy-Information