Privacy Policy

Effective: October 8, 2025. This privacy policy explains how personal data is processed in connection with the use of this website.

Data controller

Controller: Henning Kubatzsch (voluntary). Contact for data protection inquiries: henningkb@outlook.com. Postal address is not published but is available on request.

Data Protection Officer

No data protection officer has been appointed.

What data do we process?

  • Technical information (e.g. IP address, browser type, access times) — only to the extent necessary for operation and security of the website.
  • Data submitted through forms (e.g. contact form, registrations) if provided by the user (e.g. name, email, message).
  • Consent information (e.g. cookie preferences) which may be stored locally in the browser (localStorage).

Purposes & legal bases

We process personal data for various purposes, e.g. to answer contact requests, to provide and manage user accounts, to operate the website, for security and error analysis and — with your consent — for analytics. Legal bases depend on the processing and may be Art. 6(1)(b) (contract/pre-contractual), (f) (legitimate interest) or (a) (consent) GDPR.

Hosting, third parties & transfers

Technical infrastructure:

The application uses a Prisma database hosted in Frankfurt am Main (EU). The domain is registered and hosted at Strato; DNS functions are managed at Strato. Parts of the site are deployed via Vercel; Vercel operates a Frankfurt region, but the exact distribution can depend on platform configuration.

Email sending:

For sending emails we use the service Resend (USA). Resend is operated for our domain as a subdomain under Strato. Emails, email contents and related metadata may be transferred to and processed/stored in the USA. Where applicable, transfers from the EU/EEA to the USA are based on a Data Processing Addendum; Resend states it provides safeguards such as Standard Contractual Clauses (SCCs).

Sharing personal data with third parties only occurs where technically necessary or if you have previously consented.

Cookies, tracking & consent

We use a cookie banner. Your cookie and tracking preferences are stored locally in the browser under the key hearttimes_consent (localStorage). Necessary cookies (e.g. for language selection) are set regardless of consent. Analytics/statistics features are only loaded if you explicitly agree.

Optional consent logging: If enabled, the cookie banner may POST your consent decision to /api/consent to create a server record (e.g. timestamp and chosen options). These logs do not contain payment data.

Server log data & IP pseudonymization

Server logs may contain technical information such as access time, requested resource and, in exceptional cases, IP addresses. If IP addresses are processed, this is done pseudonymized/hashed where possible. Full IP addresses are not stored permanently.

Retention periods

Personal data is retained only as long as needed for the respective purpose or where legal retention periods exist. Form/registration data is usually kept until account deletion or until the processing purpose ceases. Consent records are typically retained for 1–3 years unless another legal period applies.

Rights of data subjects

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection & withdrawal (Art. 21 GDPR)

To exercise your rights, please contact henningkb@outlook.com. You also have the right to lodge a complaint with a supervisory authority.

Children

Registration/account features are intended only for persons aged 16 or older. If you are under 16, we require parental consent.

Security

We take appropriate technical and organizational measures to protect personal data (e.g. access restrictions, encryption during transmission). Absolute security cannot be guaranteed.

Changes to this privacy policy

This privacy policy is effective as of October 8, 2025. If we change it, we will update the date and, if applicable, inform affected users.

Contact

For data protection questions: henningkb@outlook.com. Phone number is not published. Postal address: available on request.