Privacy Notice
As of September 2026 · This site sets no cookies. · Deutsche Fassung (legally binding)
1. Controller
Paul Bock
Schweffelstr. 19
24118 Kiel, Germany
Email: p.r.bock@proton.me
No data protection officer has been appointed; the conditions of § 38 BDSG are not met.
2. Hosting and server log files
This website is built with and hosted by Framer, a service of Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands. When a page is requested, Framer processes technically necessary access data on my behalf:
IP address of the requesting device
date and time of access
file requested and volume of data transferred
referrer URL and browser identification (user agent)
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is the technically faultless delivery and the security of the website. Framer is my processor; the data processing agreement under Art. 28 GDPR forms part of Framer’s terms of service. Framer runs its hosting on Amazon Web Services, so data may also be processed in the USA. The transfer relies on the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023) where the recipient is certified, and otherwise on standard contractual clauses. I have no influence on how long these logs are kept. Details: Framer Privacy Statement.
3. Fonts
The fonts used on this site are hosted by Framer together with the website (see section 2). There is no connection to Google Fonts or any other font service, and your IP address is not passed to a font provider.
4. Reach measurement (Framer Analytics)
To see how many people visit which page, I use the analytics built into Framer. It sets no cookies and stores nothing in your browser. To count unique visitors, Framer combines your IP address and browser identification (user agent) into a hash with a secret that changes and is deleted every day, so no visit can be linked to you or to a later visit. I only see aggregated figures such as page views, referrers, countries and device types.
The legal basis is Art. 6(1)(f) GDPR, my legitimate interest in understanding how the website is used and improving it. Framer processes the data as my processor (see section 2). You can object at any time (Art. 21 GDPR); an email is enough.
5. Contact by email
If you write to me, I process what you send in order to deal with your enquiry. The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR. The email service is Proton Mail (Proton AG, Geneva, Switzerland); an adequacy decision of the EU Commission exists for Switzerland. I delete enquiries once they are settled and no statutory retention period stands in the way, as a rule after six months, and for commissioned work after the commercial and tax retention periods of six and ten years respectively.
6. Contact form
On submit, the form on the contact page sends the filled-in fields (name, email address, type of project, budget range, message) to Framer, which forwards them to my mailbox by email. Framer acts as my processor (see section 2) and also processes technical data belonging to the submission, including your IP address, to prevent spam and abuse. Details: Framer Privacy Statement.
The legal basis is Art. 6(1)(b) GDPR where your message concerns a project or steps taken prior to a contract, otherwise Art. 6(1)(f) GDPR (my legitimate interest in answering enquiries addressed to me). Providing the data is voluntary; without it I cannot answer you. From the moment it reaches my mailbox, section 5 applies.
You do not have to use the form. Underneath the send button there is a link that opens a draft in your own mail client with the same answers filled in. Nothing leaves your device on that route, and no processor is involved — the email then reaches me the ordinary way and section 5 applies from the start.
7. Appointment booking
For the 15-minute intro call I link to Calendly (Calendly LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA). Nothing from Calendly is embedded in this website. No widget, no script, no tracking pixel. Without a click on the link, no data flows.
Clicking the link opens the provider’s page. Data is collected there: name, email address, the slot you pick and your time zone, plus Calendly’s own access data and cookies. Name, email address and phone number are required: the meeting takes place by phone, so without a number I cannot call you, and the confirmation goes to the email address. I use your number for that one call only. It is not used for advertising, not passed on to third parties, and deleted together with the rest of the booking data. The field asking about your request is optional; the booking works if you leave it empty, and you decide how much to put in it. I receive that data as the controller in order to hold the meeting. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).
A data processing agreement under Art. 28 GDPR is in place with Calendly. The transfer to the USA relies on Calendly’s certification under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and, in addition, on standard contractual clauses. I delete booking data once the call has taken place, at the latest after six months, unless a project follows; in that case the periods in section 5 apply. Details: Calendly Privacy Notice.
Calendly’s representative in the Union under Art. 27 GDPR is DPO Centre Europe, Friedrichstraße 88, 10117 Berlin, Germany, eurep@calendly.com.
8. External links
The links to Instagram, Threads, Bluesky and GitHub are plain hyperlinks. No counting pixels, social plugins or buttons that would transfer data while the page loads are embedded. A connection is made only once you click the link.
9. No advertising, no profiling
Apart from the reach measurement in section 4, no analytics tools, advertising networks or profiling are in use. There is no automated decision-making within the meaning of Art. 22 GDPR.
10. Your rights
You have the right at any time to
access the data stored about you (Art. 15 GDPR),
rectification of inaccurate data (Art. 16 GDPR),
erasure (Art. 17 GDPR),
restriction of processing (Art. 18 GDPR),
data portability (Art. 20 GDPR),
object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
An informal email to the address above is enough.
11. Right to lodge a complaint
You can complain to a supervisory authority. The competent one is
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany
datenschutzzentrum.de
12. Changes
If the website changes technically, this notice changes with it. The version published here is the one that applies.