Privacy Policy
Privacy Policy
Data processing when using this website.
1. Controller
- The Controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable national data protection laws is:
- Kai Krauthausen Madeira, Portugal Email: kontakt@kaimadeira.tech Telephone: +49 163 8924570
2. General Information
- Protecting your personal data is a matter of great importance to me. Personal data refers to any information relating to an identified or identifiable natural person. This Privacy Policy informs you about the nature, scope, and purposes of processing personal data when using this website, as well as your rights as a data subject.
3. Hosting and Website Provision
- This website is hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, on servers located in data centers within Germany. Hosting includes webspace provision, MariaDB databases, email service, and domain infrastructure.
- When accessing the website, connection data is automatically transmitted by your web browser to the provider's servers to retrieve and display the content. Data transmission is secured using TLS encryption.
- A Data Processing Agreement (DPA) pursuant to Art. 28 GDPR has been concluded with STRATO GmbH.
- Legal Basis: Art. 6(1)(f) GDPR. Legitimate Interest: Secure, stable, error-free, and efficient operation of the online service.
4. Server and Error Logs
- When accessing this website, the web server automatically collects log data (access logs). These logs serve to ensure technical operations and defend against attacks. IP addresses and host specifications in logs made available to the operator are provided by STRATO in anonymized form.
- Access logs are retained by the hosting provider for up to six weeks. Error logs are made available by the hosting provider for a limited period. The specific period of availability depends on the STRATO platform in use and the provider information applicable at the time.
- Legal Basis: Art. 6(1)(f) GDPR. Legitimate Interest: Technical error analysis, system stability, and IT security.
5. Backups
- To guarantee system availability and data integrity, automated daily backups of the webspace and MariaDB databases are generated. Webspace backups remain available for the last 14 days. Database backups are retained for up to two weeks.
- Data deleted from active systems may remain in backups until routine overwriting occurs. Backups serve exclusively for emergency recovery and system restoration and are not used for regular data processing.
- Legal Basis: Art. 6(1)(f) GDPR. Legitimate Interest: Disaster recovery capabilities and system integrity.
6. Contact Form
- When using the contact form, the data you enter (name, email address, request category, message text, and language choice) is collected to process your inquiry. Additionally, creation timestamp, selected locale, browser user agent, a public transaction ID, and notification status are stored.
- Plaintext IP addresses are explicitly omitted (stored as NULL) in contact form database entries. Privacy policy acknowledgment before submission is verified as a submission condition but is not stored as a permanent consent record.
- Purposes: Inquiry processing, communication, service attribution, and abuse prevention. Legal Basis: Art. 6(1)(b) GDPR for contractual or pre-contractual inquiries; Art. 6(1)(f) GDPR for general inquiries and technical form security.
- Legitimate interest: Efficient handling of general inquiries and secure operation of the contact form protected against misuse.
7. Abuse Prevention (Rate Limiting)
- To limit abusive submissions, an HMAC value is generated from the IP address using a secret key. The plain IP address is not stored. Rate-limit records that are not blocked are deleted after the active 15-minute window expires. If a temporary block is applied, the record is retained until the block expires.
- Legal Basis: Art. 6(1)(f) GDPR. Legitimate Interest: Protection of systems against automated attacks, overload, and spam.
8. Email Contact
- If you contact me via email, your email along with all transmitted content and contact details will be processed and stored via STRATO GmbH email infrastructure.
- Standard email inquiries are reviewed for ongoing necessity six months after the last communication. In the absence of active contracts, statutory retention obligations, or legitimate interests, data is erased.
- Legal Basis: Art. 6(1)(b) GDPR (contractual context) or Art. 6(1)(f) GDPR (general business inquiries).
- Legitimate interest: Efficient handling of voluntary business inquiries through the communication channel selected by the person making the inquiry.
9. Telephone Contact
- When contacting me by telephone, your phone number and details provided during the conversation are processed to the extent necessary to handle your request.
- Automated recording of telephone conversations does not take place.
- Legal Basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
- Legitimate interest: Efficient handling of voluntary business inquiries through the communication channel selected by the person making the inquiry.
10. WhatsApp Contact
- According to the current WhatsApp privacy policy, the WhatsApp service for users in the European Region is provided by WhatsApp Ireland Limited. WhatsApp is part of the Meta group of companies and may involve other Meta companies and service providers in providing the service.
- Contacting via WhatsApp is voluntary. The link provided on this website is configured as an external link. Merely loading the website does not trigger any call to WhatsApp servers. You leave this website only upon actively clicking the WhatsApp link.
- Personal messages, media within personal messages, and calls are end-to-end encrypted according to WhatsApp. WhatsApp also processes account, usage, device, and connection information depending on usage. Processing may occur within global WhatsApp and Meta infrastructure.
- WhatsApp does not act as a data processor for the website operator during its independent platform processing. The website operator does not control platform processing completely. Operator-side WhatsApp messages are reviewed for necessity six months after the last communication and erased if retention grounds no longer apply. Contractual content may be incorporated into business records.
- Legal Basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
- Legitimate interest: Efficient handling of voluntary business inquiries through the communication channel selected by the person making the inquiry.
- WhatsApp describes adequacy decisions, the EU-US Data Privacy Framework, and Standard Contractual Clauses (SCCs) as safeguards for transfers outside the EEA. Further details are available in the current WhatsApp Privacy Policy (EEA).
11. Telegram Contact
- Contacting via Telegram is voluntary via the provided telephone number. Loading the website initiates no connection to Telegram.
- Telegram is operated by Telegram Messenger Inc., located outside the EEA. The EEA representative is the European Data Protection Office (EDPO). According to Telegram statements, data of users registered from the EEA or UK is stored in data centers in the Netherlands. However, this does not imply that all processing takes place exclusively in the Netherlands. Telegram describes potential inter-group transfers to companies in the British Virgin Islands and Dubai and cites Standard Contractual Clauses (SCCs) as a protection mechanism.
- Regular Cloud Chats are processed on Telegram servers. Only Secret Chats may be designated as end-to-end encrypted. Operator-side evaluation occurs six months post last communication for ongoing necessity. Contractual or statutory content may be transferred to business records beforehand.
- Legal Basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
- Legitimate interest: Efficient handling of voluntary business inquiries through the communication channel selected by the person making the inquiry.
- Telegram describes Standard Contractual Clauses (SCCs) for certain inter-group transfers. Further details regarding EDPO, storage locations, transfers, and data subject rights are available in the official Telegram Privacy Policy.
12. Published Customer Reviews
- Customer reviews displayed on the website (name, company, rating, and review text) are published based on publication permission granted by the customer.
- New review submissions are currently disabled. Existing reviews remain published with author consent. You may revoke consent for review publication at any time with future effect.
- Legal Basis: Art. 6(1)(a) GDPR (Consent).
13. Fonts and External Resources
- When accessing the page, no fonts, maps, videos, captcha services, or JavaScript libraries are loaded from external third-party servers.
14. Cookies, Analytics, and Advertising
- The website itself does not currently use any analytics or marketing cookies and uses no tracking or advertising services. Therefore, no cookie consent banner is currently displayed. Should the technical usage of cookies or external services change, this Privacy Policy will be updated accordingly and consent obtained if necessary.
15. Recipients and Processors
- Recipients or categories of recipients of personal data are:
- STRATO GmbH (Germany) – Web hosting, database, and email infrastructure processor.
- WhatsApp / Telegram – Exclusively upon voluntary usage of these communication channels by you.
- Authorities / Advisors – Exclusively within statutory obligations or legal claim enforcement.
16. International Data Transfers
- The website and associated MariaDB database are hosted via the German web hosting infrastructure of STRATO GmbH. The email service is also operated via STRATO. According to current technical status, the website does not load content from WhatsApp, Telegram, or other third-country services during standard page visits. However, processing outside the EEA may occur if you voluntarily use WhatsApp or Telegram or insofar as the respective platform providers process data within their global infrastructure.
17. Retention Period and Erasure
- Personal data is retained only as long as necessary for the respective purpose:
- Contact Form: Evaluated 6 months post-submission for ongoing necessity.
- Rate Limit Entries: Unblocked entries after 15 minutes; blocked entries upon expiry of block period.
- Emails, WhatsApp & Telegram: Evaluated for erasure 6 months post-last communication.
- Telephone: Data communicated by telephone is erased as soon as it is no longer required to handle the request. Information relevant to contracts or statutory duties may be retained longer.
- Reviews: Published reviews remain visible until consent for publication is withdrawn or the purpose for publication ceases. Following withdrawal, they are removed from public display unless demonstrable legal grounds exist for further non-public retention.
- Logs and Backups: Regarding retention and overwriting of log files and backups, reference is made to Sections 4 and 5.
- Statutory Records: Stored according to applicable statutory retention periods.
18. Data Subject Rights
- You have the following rights under GDPR regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR, where statutory requirements are met)
- To exercise your rights, contact: `kontakt@kaimadeira.tech`.
- Requests to exercise data subject rights are generally processed within statutory timeframes. Where necessary for clear identification and data protection, appropriate proof of identity may be requested.
19. Withdrawal of Consent
- Where processing is based on your consent (e.g. publication of a review), you have the right to withdraw this consent at any time with future effect. The lawfulness of processing carried out prior to withdrawal based on consent remains unaffected.
20. Right to Object
- You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you based on Art. 6(1)(f) GDPR.
21. Right to Lodge a Complaint
22. Obligation to Provide Data
- Providing data in the contact form is necessary to process your inquiry. Without the required information, your inquiry cannot be processed via the contact form. Alternative channels are voluntary.
23. Automated Decision-Making and Profiling
- Automated decision-making or profiling pursuant to Art. 22 GDPR does not take place. Technical rate limiting serves purely system defense purposes.
24. Security
- Data transmission between your browser and this website is protected using TLS encryption. Technical and organizational measures (TLS encryption, data minimization, server-side validation, parameterized database queries, access restrictions, rate limiting, controlled erasure processes, backups) protect your data from unauthorized access.
- Despite these measures, absolute security in electronic data transmission or storage cannot be guaranteed.
25. Changes to this Privacy Policy
- This Privacy Policy may be updated to reflect legal or technical changes. The current version is available on the website.
26. Effective Date
- Last updated: 1 August 2026
Last updated: 1 August 2026