Privacy
This privacy policy explains which personal data is processed when you visit this website or contact us.
As of:
1. Controller
HMFmedia, proprietor Matthias Frey
Max-Brauer-Allee 36a
22765 Hamburg, Germany
For questions about privacy and to exercise your rights, you can contact us at [email protected].
2. Website delivery and hosting
To operate the website, technical access data is processed on our behalf by a hosting provider in Germany. This includes, in particular, the IP address, time of access, requested address or file, response status, volume of data transferred, and information sent by the browser about the browser, operating system, and referring page.
This processing serves to deliver the website, operate it securely, and detect and resolve errors or attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is in an available and secure website.
According to the hosting provider, website access logs are retained for no more than 14 days; earlier deletion is possible through its log management tools. Data needed to investigate specific security incidents may be retained separately until the investigation is complete and, where necessary, to pursue legal claims.
3. Cloudflare
We use Cloudflare as a proxy in front of our website to deliver it quickly and securely. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Page requests pass through Cloudflare’s network. This involves processing IP addresses, connection and browser data, requested URLs, and security information, among other data; website content may be cached.
We also use Cloudflare’s email address obfuscation to help prevent automated collection of email addresses. Email addresses are obfuscated in the delivered HTML and made readable and clickable again in the browser by a script added by Cloudflare.
This serves to prevent malicious traffic and overloads and to deliver the website reliably. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in security and availability. Cloudflare may also process data outside the EU or EEA, particularly in the United States.
Cloudflare states that it is certified under the EU-US Data Privacy Framework. Transfers covered by that framework are subject to an adequacy decision under Article 45 GDPR. Cloudflare’s data protection terms also provide for Standard Contractual Clauses for applicable transfers under Article 46 GDPR. Information about these safeguards is available through the contractual terms linked below.
Retention of technical data depends on the particular security or operational function, the need to investigate incidents, and legal obligations. Cloudflare does not publish a single retention period covering every type of data. We do not use Cloudflare Web Analytics or Zaraz on this website.
To protect the contact form against spam, we load Cloudflare Turnstile only when a correctly completed form is submitted. In particular, IP addresses and browser and connection signals are assessed. The verification token is sent to Formspark with the inquiry for validation.
Spam protection is based on Art. 6(1)(f) GDPR and our legitimate interest in a usable contact form protected against abuse. Where access to your device is strictly necessary for this purpose, we rely on Section 25(2)(2) TDDDG. Cloudflare processes verification signals on our behalf to protect our website and also as a controller to improve its bot detection.
Cloudflare Turnstile privacy notice
Cloudflare privacy policy · Cloudflare data processing terms
4. Contact by form or email
When you contact us, we process your email address, message, and any other details you choose to provide in order to handle your request and reply. Your name is optional in the form; your email address and message are needed to handle the inquiry. The form cannot be submitted without these details. There is no legal obligation to contact us.
Where an inquiry concerns a contract with you or steps taken at your request before entering into a contract, the legal basis is Article 6(1)(b) GDPR. Other inquiries, including those made as a contact person for a company, are processed under Article 6(1)(f) GDPR. Our legitimate interest is in handling business communications. The email service providers used process the data necessary for transmission and storage.
The form uses Formspark, operated by Trampoline Software SRL, Rue de Marsannay-la-Côte 16, 5032 Mazy, Belgium. Your details are sent to Formspark for storage and forwarding only when you submit the form. Formspark also processes IP addresses, approximate location derived from them, and technical request data for delivery and abuse prevention. The legal bases stated above apply accordingly; abuse prevention is based on Article 6(1)(f) GDPR.
Formspark identifies Ireland and Germany as storage locations. Submission content is stored until deletion and remains recoverable for 30 days afterward. Formspark specifies twelve months for IP addresses, derived location data, and filtered submissions. Technical request data is retained with the associated submission. Its provider information includes further details about subprocessors and possible transfers to third countries.
5. Language preference and browser storage
When you select a language using the language switch, we store only the language code under ‘hmf-language’ in your browser’s local storage. This preserves your choice on subsequent page visits. The entry contains no user identifier, is not sent as form data, and has no fixed expiration date. You can delete it through your browser’s website data settings. Without this storage, you can still switch the language on the current page.
Storage and retrieval serve the language function you have chosen (Section 25(2), point 2, of the German TDDDG). To the extent personal data is involved, processing is based on Article 6(1)(f) GDPR and our interest in providing this function.
During security checks, Cloudflare may use technically necessary cookies, such as ‘cf_clearance’ to recognize a completed check. Whether a cookie is set and how long it lasts depend on the protection function triggered and its configuration. These operations support secure access; where strictly necessary for this purpose, storage is based on Section 25(2), point 2, TDDDG. Cloudflare explains its security cookies in its documentation.
Information about Cloudflare cookies
We do not embed advertising pixels or additional analytics tools in the page code. Fonts and graphics are served with the website; no Google Fonts or external translation services are loaded. The Cloudflare Turnstile script is loaded from Cloudflare only when a correctly completed form is submitted.
6. Retention and deletion of inquiries
Inquiries are retained only for as long as they are needed to handle the request, for foreseeable follow-up communication, or to perform a resulting contract. Once this purpose no longer applies, the data must also be deleted from Formspark and the email inbox, unless legal retention obligations or necessary evidentiary purposes require otherwise.
Where messages must be retained as commercial or business correspondence or as tax-relevant records, further storage follows the applicable statutory periods on the basis of Article 6(1)(c) GDPR. Data necessary to establish, exercise, or defend legal claims may be retained under Article 6(1)(f) GDPR until that purpose no longer applies. The providers’ separate technical retention periods are explained in the relevant sections.
7. Your rights
Subject to the statutory requirements, you have the right of access to your personal data (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), and data portability (Article 20). You may withdraw any consent you have given at any time with effect for the future; this does not affect the lawfulness of processing carried out before withdrawal.
Right to object: Where processing is based on Article 6(1)(f) GDPR, you may object under Article 21 GDPR on grounds relating to your particular situation. We will then stop processing the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves to establish, exercise, or defend legal claims.
You can use the contact address above to exercise your rights. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR.
8. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority, particularly in the place of your habitual residence, place of work, or the alleged infringement (Article 77 GDPR). The supervisory authority responsible for our place of business is the Hamburg Commissioner for Data Protection and Freedom of Information.
Lodge a complaint with the Hamburg data protection authority
Home