marcelstypa </Software & Cloud Engineer>
Home
PortfolioBlogAbout

Privacy Policy

With the following Privacy Policy, we would like to inform you about the types of your personal data (hereinafter also referred to as data) that we process, for what purposes, and to what extent. The Privacy Policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as online services). The terms used are not gender-specific. Status: September 17, 2026

Controller

Marcel Stypa Große Bleiche 15 55116 Mainz, Germany Email Address: datenschutz@marcelstypa.com Phone: +49 (0)6131 6240100 Legal Notice: https://marcelstypa.com/de/impressum

Overview of Processing Activities

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

Types of Data Processed

- Inventory data. - Employee data. - Location data. - Contact data. - Content data. - Usage data. - Meta, communication, and process data. - Log data.

Categories of Data Subjects

- Service recipients and clients. - Employees. - Communication partners. - Users. - Third parties. - Whistleblowers.

Purposes of Processing

- Communication. - Security measures. - Reach measurement. - Tracking. - Target group formation. - Organizational and administrative procedures. - Feedback. - Marketing. - Profiles with user-related information. - Provision of our online services and user-friendliness. - Information technology infrastructure. - Whistleblower protection. - Public relations.

Applicable Legal Bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the regulations of the GDPR, national data protection requirements in your or our country of residence or domicile may apply. Should more specific legal bases be applicable in individual cases, we will inform you of them in this Privacy Policy. - Consent (Art. 6 (1) (a) GDPR) - The data subject has given consent to the processing of their personal data for one or more specific purposes. - Performance of a contract and prior inquiries (Art. 6 (1) (b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. - Legal obligation (Art. 6 (1) (c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject. - Legitimate interests (Art. 6 (1) (f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data. National Data Protection Regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes in particular the Federal Data Protection Act (BDSG). The BDSG contains specific provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated individual decision-making including profiling. Furthermore, state data protection laws of individual federal states may apply. Applicability of GDPR and Swiss FADP: This privacy notice serves to provide information under both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For this reason, please note that due to the broader spatial application and legibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss FADP such as processing of personal data, overriding interest, and sensitive personal data, the terms used in the GDPR are processing of personal data, legitimate interest, and special categories of data. However, the legal meaning of the terms continues to be determined in accordance with the Swiss FADP within the scope of its applicability. Applicability of Data Protection Requirements in the Seat Country: In the country where the controller is established, national data protection regulations apply in addition to the General Data Protection Regulation (GDPR).

Security Measures

In accordance with legal requirements, taking into account the state of the art, implementation costs, nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to data as well as access, entry, disclosure, availability, and separation. Furthermore, we have established procedures to ensure the exercise of data subject rights, erasure of data, and responses to data security threats. We also take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default. TLS/SSL Encryption (HTTPS): To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers). When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS in the URL.

Transfer of Personal Data

In the context of our processing of personal data, it may happen that data is transferred to or disclosed to other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, IT service providers or providers of integrated website content. In such cases, we comply with legal requirements and enter into appropriate contracts or agreements that serve to protect your data.

International Data Transfers

Data processing in third countries: If we transfer data to a third country (i.e., outside the European Union (EU) or European Economic Area (EEA)) or if this occurs in the context of using third-party services, this is carried out exclusively in accordance with legal requirements. For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), recognized as a safe legal framework by the EU Commission's adequacy decision of July 10, 2023. Additionally, we have concluded Standard Contractual Clauses with the respective providers. This dual safeguard ensures comprehensive protection: The DPF forms the primary protective layer, while the Standard Contractual Clauses serve as an additional fallback option. For transfers to other third countries, appropriate safeguards apply, including Standard Contractual Clauses, explicit consent, or legally required transfers. Information on adequacy decisions can be found on the EU Commission website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

General Information on Data Retention and Erasure

We erase personal data that we process in accordance with legal provisions as soon as underlying consents are revoked or no further legal bases for processing exist. Exceptions apply if statutory obligations or specific interests require longer retention or archiving. In particular, data that must be retained for commercial or tax reasons or whose storage is necessary for legal prosecution or protecting rights must be archived accordingly. Where multiple retention or erasure periods apply, the longest period is always decisive. Data retained solely due to statutory requirements is processed exclusively for the reasons justifying its retention. Start of period at year-end: If a period does not explicitly start on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the triggering event occurred.

Rights of the Data Subject

Rights under the GDPR: As a data subject, you have various rights under Art. 15 to 21 GDPR: - Right to Object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you based on Art. 6 (1) (e) or (f) GDPR; this also applies to profiling. Where personal data is processed for direct marketing, you have the right to object at any time to processing for such marketing. - Right to Withdraw Consent: You have the right to withdraw given consent at any time. - Right of Access: You have the right to obtain confirmation as to whether data is being processed and access to such data. - Right to Rectification: You have the right to request the completion or correction of inaccurate data. - Right to Erasure and Restriction: You have the right to request erasure of your data or restriction of processing. - Right to Data Portability: You have the right to receive your personal data provided to us in a structured, commonly used, and machine-readable format. - Right to Lodge a Complaint: You have the right to lodge a complaint with a data protection supervisory authority.

Provision of Online Services and Web Hosting

We process user data to provide our online services. For this purpose, we process the user's IP address, which is necessary to transmit content to the browser. - Processed Data Types: Usage data (e.g., page views, duration, device types); Meta, communication, and process data (e.g., IP addresses, time stamps); Log data (e.g., login logs, access times); Content data. - Categories of Data Subjects: Users (e.g., website visitors). - Purposes and Legitimate Interests: Provision of online services and user-friendliness; IT infrastructure; Security measures. - Retention and Erasure: Erasure according to general retention section. - Legal Bases: Legitimate interests (Art. 6 (1) (f) GDPR). Further Notices on Processing: - Provision of Online Services on Rented Storage Space: We rent storage space and computing capacity from a web host; Legal Basis: Legitimate interests (Art. 6 (1) (f) GDPR). - Server Logfiles: Logfile information is stored for a maximum of 30 days and then deleted or anonymized; Legal Basis: Legitimate interests (Art. 6 (1) (f) GDPR). - Email Sending and Hosting: Web hosting includes processing sender/recipient addresses and email contents for communication and SPAM detection; Legal Basis: Legitimate interests (Art. 6 (1) (f) GDPR).

Use of Cookies

Cookies store and read information on user devices to ensure performance, security, and user convenience, as well as traffic analysis. We obtain consent where required (Art. 6 (1) (a) GDPR). Otherwise, processing relies on legitimate interests (Art. 6 (1) (f) GDPR) for essential features. Storage Duration: - Temporary Cookies (Session Cookies): Deleted after leaving the service and closing the browser. - Permanent Cookies: Stored after closing the end device (e.g., for login status or analytics), lasting up to two years. Consent Management Solution: We use a consent management tool to collect, log, manage, and withdraw consents. Storage of consent state lasts up to two years.

Blogs and Publication Media

We use blogs or publication media. Reader data is processed only to the extent required for display, communication, and security. - Processed Data Types: Inventory data, Contact data, Content data, Usage data, Meta/Communication data. - Categories of Data Subjects: Users. - Purposes: Feedback, Provision of online services and user-friendliness. - Legal Bases: Legitimate interests (Art. 6 (1) (f) GDPR).

Contact and Request Management

When contacting us (e.g., via contact form, email, or telephone), user details are processed to handle the request. - Processed Data Types: Contact data, Content data, Meta/Communication data. - Categories of Data Subjects: Communication partners. - Purposes: Communication, Administration, Feedback, User-friendliness. - Legal Bases: Legitimate interests (Art. 6 (1) (f) GDPR), Contract performance and prior inquiries (Art. 6 (1) (b) GDPR).

Web Analysis, Monitoring, and Optimization

Web analysis evaluates visitor traffic and pseudonymized user behavior. We apply IP masking (pseudonymization through IP truncation). - Processed Data Types: Usage data, Meta/Communication data. - Categories of Data Subjects: Users. - Legal Bases: Consent (Art. 6 (1) (a) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR). Further Notices: - Google Analytics: We use Google Analytics with pseudonymized user IDs and automatic IP truncation on EU-based servers before traffic is routed to Analytics servers. Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6 (1) (a) GDPR); Website: https://marketingplatform.google.com/intl/en/about/analytics/; Privacy Policy: https://business.safety.google/privacy/; Data Processing Terms: https://business.safety.google/adsprocessorterms/; Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=en.

Social Media Presences

We maintain online presences in social networks to communicate with users. User data may be processed outside the European Union. - Processed Data Types: Contact data, Content data, Usage data. - Categories of Data Subjects: Users. - Legal Bases: Legitimate interests (Art. 6 (1) (f) GDPR). Further Services: - LinkedIn: Joint controller arrangement with LinkedIn Ireland Unlimited Company for Page Insights data; Service Provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - YouTube: Video platform; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Privacy Policy: https://business.safety.google/privacy/; Opt-Out: https://myadcenter.google.com/.

Plug-ins and Embedded Content

We embed functional elements (e.g., maps, fonts, videos) from third-party providers. Integration requires processing user IP addresses. - Processed Data Types: Usage data, Meta/Communication data, Location data. - Legal Bases: Consent (Art. 6 (1) (a) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR). Embedded Services: - Google Fonts: Fetching fonts to ensure technical stability and display consistency. IP addresses are neither logged nor saved on Google servers; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Website: https://fonts.google.com/; Privacy Policy: https://business.safety.google/privacy/. - Google Maps: Map embedding; Service Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal Basis: Consent (Art. 6 (1) (a) GDPR); Privacy Policy: https://business.safety.google/privacy/. - YouTube Videos: Video content; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6 (1) (a) GDPR); Privacy Policy: https://business.safety.google/privacy/.

Changes and Updates

We ask you to regularly inform yourself about the content of our Privacy Policy. We adapt it as soon as changes to our data processing make it necessary. Competent Supervisory Authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz Hintere Bleiche 34 55116 Mainz, Germany Phone: +49 (0) 6131 8920-0 Fax: +49 (0) 6131 8920-299 Email: poststelle@datenschutz.rlp.de

marcelstypa </Software & Cloud Engineer>

Software Engineer who builds web apps and the cloud infrastructure to run them

Navigation

  • Home
  • Portfolio
  • Blog
  • About
© 2026 marcelstypa. All rights reserved.
Privacy Policy Impressum Cookie Settings

Privacy & Cookies

We use cookies and analytics tools to analyze the usage of our website. You can find further information in our privacy policy.