Privacy policy
20.09.2026
This policy describes what happens to personal data when you visit this site. The General Data Protection Regulation (GDPR) and the Spanish data protection act LOPDGDD (Ley Orgánica 3/2018) apply.
The short version
This site is built so that merely viewing it produces as little data as possible. What the site does not do:
- It sets no cookies and reads none. That is why there is no cookie banner.
- It stores nothing in the browser, neither in local storage nor in session storage nor in an in browser database.
- It embeds no analytics, no audience measurement, no advertising networks and no social media buttons.
- It loads nothing from external servers. Fonts, styles, images and the script are on the same server as the site. There is no request to Google Fonts or any other content delivery network.
- It contains exactly one form, the enquiry in the configurator. It sends only to this server, not to a third party service. Details below.
Controller
The controller within the meaning of the GDPR is:
- Name
- Lutz Eckelmann
- Address
- Partida Les Barqueres S/N
43365 Alforja
Tarragona, Spain - lutz@eckelmann.biz
- Phone
- +34 690 770 674
- Data protection officer
- There is no obligation to appoint a data protection officer, and none has been appointed.
What this application records
This section describes conclusively what the application itself records, that is the site and the endpoint that receives the enquiry form. What the web server records beyond that is covered in the next section.
The application writes no content to files. Neither your message nor your email address, your name or your company is written to a log file or a database. There is no database, no session and no cookie.
Into the error log the endpoint writes technical messages only, for example that a setting is missing or that sending mail failed. These messages contain no details from your enquiry.
For the limit on requests per origin, see the next section, a single counter file is kept. It contains:
- a shortened check value calculated from your IP address and a key that changes daily. The IP address itself is not stored, and it cannot be derived back from the check value.
- the times of the requests within the current window of one hour.
- Nothing else. No content, no address, no identifier that stays the same beyond the day.
How long the counter file is kept
Times outside the window are discarded on the next request from the same origin. The file itself is deleted after two days at the latest. Since the check value changes daily, a file from the previous day can no longer be matched to any origin anyway.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in protecting the form against abusive bulk sending.
Server logs
When you open a page, your browser transmits technically necessary data to the server so that the page can be delivered. This includes the IP address, the date and time, the address requested, the status code returned, the amount of data transferred, and details about your browser and operating system.
The web server keeps an access log, but without your full IP address. It is shortened before it is written: for IPv4 the last quarter is dropped, so 203.0.113.47 becomes 203.0.113.0. For IPv6 only the first four groups remain. The entry still identifies a range of connections, but no individual device, and the full address cannot be recovered from it.
Recorded are: the shortened address, the date and time, the address requested, the status code, the amount of data transferred, the page you came from if your browser sends it, and your browser's identification. A forwarding address sent by the browser is deliberately not logged, because it can contain the full IP address.
Logs are kept for seven days. The log is rotated daily and older files are deleted automatically. The logs are not matched against other sources, and they are not analysed to distinguish or recognise visitors.
The legal basis for processing this data is Article 6(1)(f) GDPR. The legitimate interest lies in the technically correct operation and the security of the site.
Hosting
The site is hosted by a German provider. It processes the data arising in the course of hosting on instruction, as a processor under Article 28 GDPR.
For clarity: the data processing agreement with the provider was concluded by Plan Digital Now S.L. The controller for this website is Lutz Eckelmann, sole trader, see the legal notice.
- Provider
- Hetzner Online GmbH
- Address
- Industriestr. 25
91710 Gunzenhausen
Germany - Server location
- Nuremberg, Germany
- Data processing agreement
- Agreement under Article 28 GDPR dated 20 September 2026
- Party to the agreement with the provider
- Plan Digital Now S.L.
Getting in touch
This site offers two ways to get in touch, neither of them a form:
If you write or call, I process the data you send, that is your name, your address or number and the content of your message, solely in order to deal with your enquiry.
The legal basis is Article 6(1)(b) GDPR where the enquiry is directed at a contract, and otherwise Article 6(1)(f) GDPR based on the legitimate interest in answering enquiries.
- A link to an email address. Clicking it opens your own mail application. No data is transmitted to this site in the process.
- A link to a telephone number.
- The configurator produces a prefilled email in your own mail application. The hours you set are calculated solely in your browser and are only transmitted if you send the message yourself.
Enquiry form
In the configurator you can send an enquiry directly from the page. The details you enter are processed: email address and message are required, name and company are optional. Added to that is the split of hours you set, which is visible in the form before you send it.
Purpose: solely handling and answering your enquiry. There is no evaluation for advertising purposes, and you are not added to any mailing list without separate consent.
Legal basis: Article 6(1)(b) GDPR where the enquiry is directed at a contract, and otherwise Article 6(1)(f) GDPR based on the legitimate interest in answering enquiries.
Recipients: the details are written into an email and sent to the address named above. The email provider is involved in this. No third party form processing service is used, the data does not leave the path between this site and the mailbox.
Retention: the details are not stored in a database on the server. Afterwards they exist only as an email in the mailbox and are deleted there once they are no longer needed to answer the enquiry and no statutory retention obligation stands in the way.
Voluntary: you do not have to use the form. An email address and a telephone number are shown alongside so that you can write or call in the usual way.
Protecting the form against misuse
So that the form is not misused for bulk sending, three measures are built in. None of them uses a third party service, in particular there is no captcha and nothing from Google.
No content and no IP address in clear text is stored for the limit. What is stored is only a shortened check value calculated from the origin and a key that changes daily, together with the times of the requests. The check value therefore changes every day and is not a permanent identifier. It is deleted once the time window has passed.
What the web server records beyond this in its access logs is a matter of its configuration, see the section on server logs.
- A field invisible to you that only automated programs fill in.
- A check that a minimum time has passed between opening the page and sending. It only applies when JavaScript is running.
- A limit on the number of requests per origin and time window.
Links to external sites
This site links to web-creativo.es and to a profile on LinkedIn. These are ordinary links, not embedded content. Data is only transmitted to those providers once you click the link. From that point their own privacy policy applies.
Retention
Enquiries and the related correspondence are deleted once they are no longer needed to answer them and no statutory retention obligation stands in the way. Statutory periods apply to documents of tax or commercial significance.
For the retention of server logs see the section on server logs.
Recipients of the data
No data is passed on to third parties, other than to the server provider as a processor and to the email provider insofar as you write by email.
No data is transmitted for advertising purposes, and no data is sold.
No automated decision making
There is no automated decision making and no profiling within the meaning of Article 22 GDPR.
The diagnosis and the configurator on this site calculate solely in your browser. Your answers are not transmitted, not stored and not evaluated.
Your rights
Under the GDPR you have the following rights:
- Access to the data processed about you, Article 15
- Rectification of inaccurate data, Article 16
- Erasure, Article 17
- Restriction of processing, Article 18
- Data portability, Article 20
- Objection to processing based on legitimate interests, Article 21
- Withdrawal of consent with effect for the future, Article 7(3)
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the one at the controller's place of establishment, which is the Spanish data protection authority Agencia Española de Protección de Datos (AEPD), www.aepd.es.
You may equally turn to the supervisory authority of your habitual residence or your place of work.
Changes to this policy
This policy will be adjusted as soon as the actual circumstances change, in particular once the server is set up. The version published on this page at any given time is the one that applies.