Legal
Privacy
How personal data is handled when you visit this portfolio or send an inquiry.
Controller
The controller under the General Data Protection Regulation (GDPR) is:
Lennard Makosch
Wrangelstr. 79
10997 Berlin
Germany
Email: available when JavaScript is enabled
Overview
This website processes only the data needed to deliver the site, protect its operation, receive and organise professional inquiries, and respond to them. Optional analytics is not active.
Contact inquiries may be summarised and prioritised with the assistance of an artificial-intelligence service. The resulting assessment is an internal organisational aid, is reviewed by me, and does not automatically accept or reject an inquiry. There is no solely automated decision-making that produces legal or similarly significant effects.
Hosting and server logs
This website and its contact-form database are hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany.
When the site is requested, STRATO may process technical data such as the IP address, date and time, requested URL, referrer, browser and device information, request status, and diagnostic or security data. This processing is necessary to deliver the website, maintain the security and stability of the hosting service, and investigate misuse.
The legal basis for processing under my responsibility is Article 6(1)(f) GDPR. The legitimate interests are secure and reliable website delivery and protection against abuse. STRATO processes website-visitor and hosted-database data on my behalf under a data-processing agreement pursuant to Article 28 GDPR.
Technical logs are retained only for as long as required for operation and security. STRATO states that log files and temporary storage data are commonly retained for periods ranging from a few days to a maximum of 60–90 days, depending on the relevant security or operational need. See STRATO’s Privacy Notice and Data Processing Agreement.
Contact form
If you submit the form, the following data may be processed: first and last name, company size, company stage, email address, product category, the message you provide, submission time, and technical delivery data.
The purpose is to review, answer, and organise your inquiry and, where requested, take steps toward a possible engagement. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication and otherwise Article 6(1)(f) GDPR, based on the legitimate interest in responding to professional inquiries.
Required fields are necessary to assess and answer the inquiry. You are not legally required to provide them, but the form cannot be processed without them. Please do not send special-category, confidential, or otherwise sensitive information through the form.
Submissions are received by a server-side form endpoint on the STRATO webspace and stored in a MySQL database provided by STRATO. They are not automatically forwarded to an email or external CRM service. Access is restricted to a protected lead-management area. Identifying and free-text inquiry data is encrypted before database storage.
For abuse prevention, a short-lived pseudonymous identifier derived from the submitting IP address may be stored for rate limiting. The raw IP address is not added to the lead record for this purpose. The identifier is deleted after no more than 24 hours; independent server-log processing by STRATO is described above.
Inquiry data is normally deleted six months after the final response if no engagement follows. If an engagement begins, relevant correspondence may be kept for the duration of the relationship and applicable statutory retention periods. Data needed to establish, exercise, or defend legal claims may be kept until those claims are time-barred.
Form protection with Cloudflare Turnstile
The contact form uses Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, to distinguish legitimate submissions from automated abuse.
When Turnstile is used, Cloudflare processes technical signals including the IP address, TLS fingerprint, user-agent header, site key, and associated website origin. These signals are used to detect and block bots, not to evaluate the content of an inquiry or for advertising by me.
The legal basis under my responsibility is Article 6(1)(f) GDPR. The legitimate interests are preventing spam and automated attacks and protecting the availability and security of the contact form. Any access to or storage of information on the visitor’s device that is strictly necessary for this security function is based on § 25(2) no. 2 TDDDG. Turnstile is used without Cloudflare pre-clearance.
See Cloudflare’s Turnstile Privacy Addendum and Data Processing Addendum.
AI-assisted inquiry assessment
To help organise incoming professional inquiries, selected form information is transmitted through the OpenAI API to OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. The information sent consists of company size, company stage, product category, and the inquiry message. First name, last name, and email address are excluded from the API request.
OpenAI is instructed to return a structured internal assessment such as a summary, relevance score, confidence level, and reasons. This output is stored with the inquiry and used only to help sort and review leads. I review the submission myself and do not use the score to make a solely automated decision with legal or similarly significant effects.
The legal basis is Article 6(1)(f) GDPR. The legitimate interests are efficiently organising professional inquiries, identifying apparent spam or irrelevant submissions, and prioritising timely personal review. You may object to processing based on legitimate interests as described under “Your rights” below.
The API request is configured not to create persistent application state. OpenAI states that API data is not used to train its models unless the customer expressly opts in. Under OpenAI’s default API controls, prompts and responses may nevertheless be retained in abuse-monitoring logs for up to 30 days, unless a longer period is legally required. See OpenAI’s API Data Controls, EU Privacy Policy, and Data Processing Addendum.
Direct email
If you contact me directly by email, I process your address, message, metadata, and any voluntarily supplied information to handle the communication. The same legal bases and retention criteria described for the contact form apply.
Browser storage
The site uses the session-storage entry portfolio-route-direction to preserve the direction of a cross-page navigation animation. It contains only “forward” or “back”, is removed when the destination page opens, and is otherwise cleared when the browser session ends. It is not shared with third parties.
This limited access is used to provide the navigation state requested by the visitor. It is treated as technically necessary under § 25(2) no. 2 TDDDG; related processing is based on Article 6(1)(f) GDPR.
Fonts and external media
The Geist font and portfolio imagery are served locally with the website. Loading a page does not contact Google Fonts or another font provider.
Optional analytics
Current status: Google Analytics is not loaded in this build, and no analytics cookies are set.
If Google Analytics 4 is introduced later, it must remain blocked until the visitor gives informed, voluntary, active consent. The legal bases would be consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. Refusing analytics must not restrict access to the website, and consent must be as easy to withdraw as it is to give.
Before activation, this section must be updated with the Google entity used, measurement purpose, events and identifiers collected, cookie names and lifetimes, configured retention period, data-sharing settings, recipients, possible processing outside the EEA, transfer safeguards, and a persistent link for reopening privacy settings.
Recipients
Data is disclosed only where necessary to STRATO as hosting and database provider, Cloudflare for contact-form abuse prevention, OpenAI for the limited AI-assisted assessment described above, professional advisers bound by confidentiality, or authorities where legally required. Contact submissions are not sold or used for unrelated advertising.
International transfers
STRATO states in its data-processing agreement that contracted processing takes place in the European Union or another state of the European Economic Area unless a third-country transfer is required to provide the service, in which case the requirements of Articles 44 et seq. GDPR apply.
Cloudflare is established in the United States and may process Turnstile signals in the United States or other countries. Its Data Processing Addendum incorporates the European Commission’s 2021 Standard Contractual Clauses where required.
For customers located in the EEA, the OpenAI API service is contracted through OpenAI Ireland Limited. OpenAI and its subprocessors may process data outside the EEA; OpenAI’s Data Processing Addendum provides for appropriate transfer mechanisms, including the European Commission’s Standard Contractual Clauses where applicable.
Your rights
Subject to the applicable legal conditions, you may request access, rectification, erasure, restriction, and portability of your personal data. You may object to processing based on Article 6(1)(f) GDPR for reasons arising from your particular situation.
Where processing relies on consent, you may withdraw that consent at any time with effect for the future. Withdrawal does not affect processing carried out before it.
You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
Security and updates
Protective measures include encrypted HTTPS transmission, restricted server and database access, encryption of identifying and free-text inquiry data before database storage, password-protected lead management, input validation, bot verification, and submission rate limiting. Internet transmission can nevertheless never be guaranteed to be completely secure.
This notice will be updated when the website, its providers, or its processing activities change. The version shown here is the current one.