Privacy Notice
1. Controller
- Name
- Alexander Rotfuss
- Address
- Langer Anger 107
69115 Heidelberg
Germany - Rotfuss.aro@gmail.com
The controller determines the purposes and means of processing personal data on this website.
2. Hosting and server logs
This website is technically configured for hosting by Vercel Inc.. When the website is accessed, the hosting provider processes connection data that is technically required to deliver the website. This may include the IP address, date and time, requested file or URL, transferred data volume, referrer, browser and operating-system information, and security events.
This processing is necessary to provide the website, maintain stability and security, and prevent misuse. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of the website. Where processing is required to take steps at the request of a visitor before entering into a contract, Article 6(1)(b) GDPR also applies.
Vercel may process data outside the European Union. The data-processing agreements and appropriate safeguards offered by the provider must be reviewed and concluded where required. Further information: Vercel Privacy Notice.
The specific retention period for infrastructure logs depends on the deployed Vercel configuration and the contractual settings. The operator must review those settings before publication and update this notice if the actual configuration differs.
3. Contact form and email communication
The contact form processes the information you enter: name, email address, optional company and URL, project type, project stage, budget range, preferred timing, and your message. The information is used exclusively to review and answer your inquiry.
When direct delivery is used, the information is first transmitted to a same-origin server function of this website and is then delivered through Plus Five Five, Inc. (Resend) to Rotfuss.aro@gmail.com. The IP address is also processed briefly to limit automated or abusive requests. The application does not create its own permanent contact database. The message does, however, remain in the receiving email account and may be processed by the delivery provider as message content or delivery metadata.
The legal basis is Article 6(1)(b) GDPR where your inquiry concerns a contract or possible collaboration. For other inquiries, the legal basis is Article 6(1)(f) GDPR; the legitimate interests are the proper handling of incoming communication and the prevention of misuse.
Contact inquiries are deleted once they are no longer required for processing and no statutory retention, evidentiary, or limitation interests prevent deletion. If the inquiry results in a contractual relationship, relevant records may be retained for the applicable statutory retention periods.
Resend may process personal data in the United States. Further information: Resend Privacy Policy and Resend Data Processing Addendum.
If direct delivery is not configured or cannot be reached, the website provides alternatives through Gmail, the visitor's local email application, or the clipboard. Additional privacy terms of those external applications apply only when you open such an application or send the prepared content yourself.
4. Local browser storage
The website does not use advertising or analytics cookies. Contact details that have not been sent remain only in the current form state and are not stored permanently as a draft. Local and session storage are used only for functions explicitly initiated by the visitor:
- alex-theme: remembers the selected appearance.
- alex-contact-intent-v10: carries the selected contact intent to the form during the current session.
- alex-inventory-demo: stores data created by the visitor in the inventory demo.
- alex-scene-composer-v1: stores a scene only when the visitor explicitly chooses the local save function.
Connected-demo handoffs, including HTML source selected in the repository tool, remain only in current page memory and are cleared on reload. They are not written to persistent browser storage.
According to the current technical implementation, this data remains on your device and is not transmitted to the operator. You can remove it through the deletion controls in the relevant demo or through your browser's website-data settings. Storage is used solely to provide the function you expressly requested; the legal basis is Section 25(2)(2) of the German Telecommunications-Digital-Services Data Protection Act (TDDDG). Where stored content constitutes personal data, processing is based on Article 6(1)(f) GDPR and the legitimate interest in providing a user-friendly website that functions locally.
5. Local demos, files, and inputs
The repository and ZIP analysis, HTML audit, QR tool, 3D demos, and inventory demo are designed to process their inputs in the browser. According to the current source code, selected local folders, ZIP files, and content are not uploaded to the website operator. Confidential or personal data should nevertheless be used only where this is necessary and you are authorised to process it.
6. External links
This website links to GitHub as well as email and Gmail functions. A connection to the respective provider is established only when an external link is opened. The external provider is responsible for subsequent processing. Where technically implemented, external links are opened with protective attributes such as noreferrer.
7. Your data-protection rights
Subject to the statutory requirements, you have rights including access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Consent may be withdrawn at any time with effect for the future. You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
To exercise your rights, send a message to Rotfuss.aro@gmail.com.
8. Security and updates
The website uses technical security measures including HTTPS, restrictive security headers, same-origin checks for the contact form, input validation, request-size limits, and basic rate limiting. Absolute protection of electronic transmissions cannot be guaranteed.
This notice must be updated whenever hosting, email delivery, analytics, cookies, embedded content, or other data flows change.
The principal transparency obligations arise in particular from Articles 12–14 GDPR. Local storage on end-user devices is additionally governed by Section 25 TDDDG. This notice describes the reviewed technical state of the supplied project files and does not constitute individual legal advice.