1. Data Controller
The party responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
DDC – FJ Donner Von-Bodelschwingh-Str. 14, 33175 Bad Lippspringe, Deutschland Email: fj-donner@projecttechnic.de Phone: +49 175 59 41 367
2. Overview
Protecting your personal data is important to us. This Privacy Policy explains what data we collect, the purposes and legal bases for processing it, with whom we share it, and the rights available to you. It applies to this website and its associated administration area.
3. What Data We Process
3.1 Contact Form
When you send us a message through the contact form, we process the data you provide: name, email address, company (optional) and the content of your message, together with the time of submission. We use this data solely to handle your enquiry and any follow-up.
3.2 Sign-in with Google (administrators only)
Access to the administration area may be granted via Google OAuth. When an authorized person signs in with Google, we receive basic profile information from Google — in particular name, email address and, where available, profile picture. We use this information solely to verify that the person is on our list of authorized administrators and to manage the login session. We do not request any broader access to your Google account.
3.3 Server Log Files
When the website is accessed, the hosting provider automatically processes technical access data (e.g. IP address, date and time, page requested, browser type). This data is necessary to provide and secure the website.
3.4 Cookies
We use a strictly necessary session cookie that serves only to keep you signed in to the administration area. It contains no advertising identifiers and expires when you log out or the session ends. Ordinary browsing of the website requires no consent to non-essential cookies, as we do not use any.
4. Purposes and Legal Bases
We process personal data on the following GDPR legal bases:
- Art. 6(1)(b) GDPR – to handle enquiries and manage administrator access;
- Art. 6(1)(f) GDPR – our legitimate interest in the secure, uninterrupted operation of the website;
- Art. 6(1)© GDPR – where processing is required by law.
5. Use of Google User Data (Google API Services User Data Policy)
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use the data received via Google solely to authenticate and authorize eligible administrators.
- We do not transfer this data to third parties except as necessary to provide the service, as required by law, or as expressly requested by you.
- We do not use this data for advertising.
- We do not allow humans to read the data, except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized.
6. Recipients and Processors
To operate the website we use carefully selected service providers that process data on our behalf:
- Supabase – database hosting (content and contact messages).
- Google LLC – provision of sign-in via Google OAuth.
- Our hosting provider – operating the server and delivering the website.
Where required, data processing agreements are in place with these providers.
7. International Transfers
Some of the providers above may process data outside the European Union (e.g. in the USA). In such cases an adequate level of protection is ensured through appropriate safeguards, in particular the EU Commission’s Standard Contractual Clauses.
8. Retention
We store personal data only for as long as necessary for the relevant purposes or as required by statutory retention periods. Contact messages are deleted once your enquiry has been handled and no legal obligations require retention.
9. Your Rights
Under the GDPR you have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You also have the right to lodge a complaint with a data protection supervisory authority.
To exercise your rights or to request deletion of your data, contact us at fj-donner@projecttechnic.de.
10. Data Security
We implement technical and organizational measures to protect your data against unauthorized access, loss or manipulation. Data is transmitted encrypted via HTTPS.
11. Children
This website is not directed at children. We do not knowingly collect personal data from anyone under the age of 16.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in the law or in our services. The version published on this page at any given time applies.
13. Contact
For any privacy questions or to exercise your rights, contact: DDC – FJ Donner, Von-Bodelschwingh-Str. 14, 33175 Bad Lippspringe, Deutschland, email: fj-donner@projecttechnic.de.