The contact form at /contact collects the following data:
- ·name (required)
- ·email address (required)
- ·company (optional)
- ·website (optional)
- ·project type (required)
- ·budget range (optional)
- ·preferred project start (optional)
- ·message text (required)
Submitting requires your explicit consent to processing this data (a checkbox). You can withdraw that consent at any time with effect for the future, for example informally by email.
For spam protection, your IP address is held in server memory solely for time-limited rate limiting (sliding 15-minute window, max 5 requests per IP, plus a per-email-address limit). It is neither included in the notification email nor stored permanently. Hidden honeypot fields and a server-side timing check are used to detect bots; submitted data is not stored client-side in local storage or cookies.
Submission happens encrypted (HTTPS) via a server action to my mail server. I use the data exclusively to process and, where appropriate, reply to your inquiry.
Legal basis is Art. 6 (1) (a) GDPR (your consent via the checkbox), Art. 6 (1) (b) GDPR (steps prior to entering into a contract, or contract performance), and Art. 6 (1) (f) GDPR (legitimate interest in efficient handling of business inquiries and protection of the form against abuse).
Data is retained as long as it is needed to handle the request — typically while the inquiry and any resulting engagement are active and no retention obligations apply. Statutory retention periods under tax and commercial law (up to 10 years per §147 AO, §257 HGB) remain unaffected.