Legal
Privacy
How personal data is handled when you visit this portfolio or send an inquiry.
Controller
The controller under the General Data Protection Regulation (GDPR) is:
Lennard Makosch
Wrangelstr. 79
10997 Berlin
Germany
Email: lennard(at)makosch.eu
Overview
This website processes data needed to deliver and protect the site, understand its aggregate use through objection-based basic analytics, receive and organise professional inquiries, and respond to them. Enhanced analytics is disabled.
Contact inquiries are reviewed and organised manually. They are not scored by an artificial-intelligence service, and there is no solely automated decision-making that produces legal or similarly significant effects.
Hosting and server logs
This website and its contact-form database are hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany.
When the site is requested, STRATO may process technical data such as the IP address, date and time, requested URL, referrer, browser and device information, request status, and diagnostic or security data. This processing is necessary to deliver the website, maintain the security and stability of the hosting service, and investigate misuse.
The legal basis for processing under my responsibility is Article 6(1)(f) GDPR. The legitimate interests are secure and reliable website delivery and protection against abuse. STRATO processes website-visitor and hosted-database data on my behalf under a data-processing agreement pursuant to Article 28 GDPR.
Technical logs are retained only for as long as required for operation and security. STRATO states that log files and temporary storage data are commonly retained for periods ranging from a few days to a maximum of 60–90 days, depending on the relevant security or operational need. See STRATO’s Privacy Notice and Data Processing Agreement.
Contact form
If you submit the form, the following data may be processed: first and last name, company size, company stage, email address, product category, the message you provide, submission time, and technical delivery data.
The purpose is to review, answer, and organise your inquiry and, where requested, take steps toward a possible engagement. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication and otherwise Article 6(1)(f) GDPR, based on the legitimate interest in responding to professional inquiries.
Required fields are necessary to assess and answer the inquiry. You are not legally required to provide them, but the form cannot be processed without them. Please do not send special-category, confidential, or otherwise sensitive information through the form.
Submissions are received by a server-side form endpoint on the STRATO webspace and stored in a MySQL database provided by STRATO. They are not automatically forwarded to an email or external CRM service. Access is restricted to a protected lead-management area. Identifying and free-text inquiry data is encrypted before database storage.
For abuse prevention, a short-lived pseudonymous identifier derived from the submitting IP address may be stored for rate limiting. The raw IP address is not added to the lead record for this purpose. The identifier is deleted after no more than 24 hours; independent server-log processing by STRATO is described above.
Inquiry data is normally deleted six months after the final response if no engagement follows. If an engagement begins, relevant correspondence may be kept for the duration of the relationship and applicable statutory retention periods. Data needed to establish, exercise, or defend legal claims may be kept until those claims are time-barred.
Form protection with Cloudflare Turnstile
The contact form uses Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, to distinguish legitimate submissions from automated abuse.
When Turnstile is used, Cloudflare processes technical signals including the IP address, TLS fingerprint, user-agent header, site key, and associated website origin. These signals are used to detect and block bots, not to evaluate the content of an inquiry or for advertising by me.
The legal basis under my responsibility is Article 6(1)(f) GDPR. The legitimate interests are preventing spam and automated attacks and protecting the availability and security of the contact form. Any access to or storage of information on the visitor’s device that is strictly necessary for this security function is based on § 25(2) no. 2 TDDDG. Turnstile is used without Cloudflare pre-clearance.
See Cloudflare’s Turnstile Privacy Addendum and Data Processing Addendum.
Direct email
If you contact me directly by email, I process your address, message, metadata, and any voluntarily supplied information to handle the communication. The same legal bases and retention criteria described for the contact form apply.
Browser storage
The site uses the session-storage entry portfolio-route-direction to preserve the direction of a cross-page navigation animation. It contains only “forward” or “back”, is removed when the destination page opens, and is otherwise cleared when the browser session ends. It is not shared with third parties.
The local-storage entry portfolio-enhanced-analytics-consent-v1 stores whether enhanced analytics was accepted or declined. The entry portfolio-basic-analytics-opt-out-v1 is stored only when a visitor disables basic analytics. These choices remain until the visitor changes them through the switches below or clears browser storage.
These limited storage operations provide requested navigation and preserve the visitor’s privacy choice. They are treated as technically necessary under § 25(2) no. 2 TDDDG; related processing is based on Article 6(1)(f) GDPR.
Fonts and external media
The Geist font and portfolio imagery are served locally with the website. Loading a page does not contact Google Fonts or another font provider.
Website analytics
This website uses Umami Cloud, provided by Umami Software, Inc., 28 Geary St, Suite 650 #243, San Francisco, California, United States. The account uses Umami’s EU region. Umami does not set analytics cookies or use browser storage to identify visitors.
Basic analytics runs unless the visitor has enabled a browser Do Not Track signal or objects using the control below. It processes the visited page path without query parameters or URL fragments, page title, referrer, timestamp, browser language, browser and operating-system type, device type, screen dimensions, and approximate country, region, and city. The requesting IP address and user-agent header are used to derive rotating pseudonymous session and visit hashes and to determine approximate location; Umami states that the raw IP address is not stored.
The purpose of basic analytics is to understand aggregate traffic, determine which portfolio pages are useful, and measure whether the contact path works. The legal basis is the legitimate interest in measuring and improving this professional website under Article 6(1)(f) GDPR. The site operator has balanced that interest against visitors’ interests by using cookie-free analytics, excluding query strings and fragments, respecting Do Not Track, avoiding distinct IDs and form values, and providing an immediate objection.
The only custom event in basic analytics is contact-form-success, sent after the server confirms that a contact inquiry was accepted. Its default page context contains no form values.
Enhanced analytics, including heatmaps and session replay, is currently disabled because it is unavailable on the active Umami plan. It will not be activated without first enabling an explicit “Allow Analytics” choice. If introduced, contact forms and other sensitive interface areas must remain excluded and input values must remain masked. Its legal basis would be consent under Article 6(1)(a) GDPR and § 25(1) TDDDG.
Basic analytics can be disabled using the switch below. Any future enhanced consent would be voluntary and could be withdrawn separately.
Enhanced analytics is unavailable on the current Umami plan.
Analytics records are retained in the Umami Cloud account only while needed to review aggregate website performance, and that need is reviewed at least annually. Umami states that account information is kept no longer than the account exists, subject to limited legal, security, and fraud-prevention retention after termination.
See Umami’s Privacy Policy, Data Processing Agreement, and metric definitions.
Recipients
Data is disclosed only where necessary to STRATO as hosting and database provider, Cloudflare for contact-form abuse prevention, Umami for basic website analytics, professional advisers bound by confidentiality, or authorities where legally required. Enhanced analytics is disabled; if it becomes available, it will disclose data to Umami only after explicit consent. Contact submissions are not sold or used for unrelated advertising.
International transfers
STRATO states in its data-processing agreement that contracted processing takes place in the European Union or another state of the European Economic Area unless a third-country transfer is required to provide the service, in which case the requirements of Articles 44 et seq. GDPR apply.
Cloudflare is established in the United States and may process Turnstile signals in the United States or other countries. Its Data Processing Addendum incorporates the European Commission’s 2021 Standard Contractual Clauses where required.
Umami Software, Inc. is established in the United States. The analytics account is assigned to Umami’s EU region, but provider administration, support, or other limited processing may involve the United States. Umami’s Data Processing Agreement provides contractual safeguards, including the European Commission’s Standard Contractual Clauses where required.
Your rights
Subject to the applicable legal conditions, you may request access, rectification, erasure, restriction, and portability of your personal data. You may object to processing based on Article 6(1)(f) GDPR for reasons arising from your particular situation.
You may object to basic analytics using its switch above. If enhanced analytics is introduced later, any consent can be withdrawn there with effect for the future. Withdrawal or objection does not affect processing carried out before it.
You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for Berlin is the Berlin Commissioner for Data Protection and Freedom of Information.
Security and updates
Protective measures include encrypted HTTPS transmission, restricted server and database access, encryption of identifying and free-text inquiry data before database storage, password-protected lead management, input validation, bot verification, and submission rate limiting. Internet transmission can nevertheless never be guaranteed to be completely secure.
This notice will be updated when the website, its providers, or its processing activities change. The version shown here is the current one.