Privacy Policy
What this site collects, which is close to nothing. Written for this site rather than adapted from a template, so every claim below is one we can stand behind.
No cookies, no analytics, no tracking
This site sets no cookies. It runs no analytics, no tag manager, no advertising network, no tracking pixel and no session recording. There are no third-party embeds: no maps, no video player, no fonts fetched from someone else's server. The typefaces are files served from this domain.
Nothing here builds a profile of you. The only personal data we ever receive is what you send us yourself - through the contact form, by email or by phone - plus the access data our host has to record in order to serve the page at all. Both are described below, and there is nothing else.
Controller
The controller responsible for data processing on this website is:
Bellemann UG (haftungsbeschränkt)
Robert-Bosch-Str. 56A
69190 Walldorf
Germany
lb@bellemann.com
+4917684176404
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
Hosting
This website is hosted by Netlify, Inc., San Francisco, California, USA. When you open a page your browser connects to Netlify's servers, and Netlify processes the access data described in the next section on our behalf.
Netlify acts as a processor under Art. 28 GDPR on the basis of a data processing agreement. Data may be transferred to the United States; that transfer is covered by the European Commission's Standard Contractual Clauses, which Netlify's data processing agreement incorporates.
The legal basis is Art. 6(1)(f) GDPR. We have a legitimate interest in this site being reliably available and secure, and it cannot be served without a host.
Server log files
Each time a page is opened, Netlify's servers record what your browser transmits: the page or file requested, the date and time of the request, how much data was transferred and whether the request succeeded, the referring URL, your browser type and version, your operating system, and your IP address.
This data is not merged with any other source and is not used to identify you. It exists so the site can be delivered, so faults can be found, and so abuse can be defended against. The legal basis is Art. 6(1)(f) GDPR.
Contact form
The form asks for your first name, last name, email address, company, an optional website, a budget range and a description of what you want built. That is the whole of it, and all of it goes to us.
Submissions are handled by Netlify Forms and stored in our Netlify account. The form carries one hidden field that only an automated script would fill in; if it comes back filled in, the submission is discarded. There is no captcha and no third-party script runs on the page.
We use what you send to answer you and, if it becomes a project, to prepare an offer. The legal basis is Art. 6(1)(b) GDPR where the processing relates to steps taken at your request before entering a contract, and otherwise Art. 6(1)(f) GDPR - our legitimate interest in replying to people who ask us something.
Enquiries by email and phone
If you write or call instead of using the form, your message, your contact details and whatever else you choose to tell us are stored with us so that we can deal with the enquiry. None of it is passed on without your consent. The legal basis is the same as for the form.
Retention
Server log data is kept for a short period and then deleted or anonymised.
Enquiries are kept for as long as we need them to answer you. After that, anything that has become a business record is kept for as long as German commercial and tax law requires, which is up to six or ten years depending on the document. Anything not covered by a retention obligation is deleted once the reason for holding it has gone, or earlier if you ask us to delete it.
Legal basis for processing
Where you have given consent, the legal basis is Art. 6(1)(a) GDPR. Where processing is necessary to perform a contract or to take steps at your request before entering one, it is Art. 6(1)(b) GDPR. Where we are subject to a legal obligation, such as retaining business records, it is Art. 6(1)(c) GDPR.
In every other case named on this page it is Art. 6(1)(f) GDPR: our legitimate interest in operating a secure, available website and in answering the people who contact us.
Withdrawal of consent
Where processing rests on your consent you may withdraw that consent at any time, without giving reasons and at no cost. The withdrawal takes effect from the moment it reaches us; processing carried out before then remains lawful. An informal email to the address above is enough.
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR - see Art. 21(1) GDPR. If you object, we will stop processing the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
We do not use your data for direct marketing, so the separate right of objection under Art. 21(2) GDPR does not arise here.
Right to lodge a complaint with a supervisory authority
If you believe your data is being processed unlawfully you may lodge a complaint with a supervisory authority in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement.
The authority responsible for us is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart. This right is without prejudice to any other administrative or judicial remedy.
Access, correction, deletion, restriction and portability
You may ask us at any time, free of charge, what personal data we hold about you, where it came from, who receives it and why we process it (Art. 15 GDPR). You may have inaccurate data corrected (Art. 16 GDPR) and data deleted (Art. 17 GDPR).
Where the conditions are met you may have processing restricted instead of deleted (Art. 18 GDPR), and you may receive the data you provided to us in a common machine-readable format, or have it transmitted directly to another controller where that is technically feasible (Art. 20 GDPR).
Write to the address in the imprint and we will answer.
SSL/TLS encryption
This site is served over HTTPS using TLS. Everything that passes between your browser and the server - including whatever you type into the contact form - is encrypted in transit and cannot be read by third parties along the way. You can tell it is active from the lock symbol in your browser's address bar and the "https://" at the start of the address.