PRIVACY POLICY
Privacy Policy
Information about the processing of personal data on this website
1. Overview & Data Controller
The following information provides a clear overview of what happens to your personal data when you visit this website. Personal data refers to any information that can personally identify you.
The data controller responsible for processing data on this website under the General Data Protection Regulation (GDPR) is:
Andrii Gudz Webentwicklung & Design Owner: Andrii Gudz Marktplatz 15 96148 Baunach Germany Email: andriigudz.de@gmail.com
2. General Information & Legal Bases
We only process personal data of our users to the extent necessary to provide a functional website and our content and services.
Personal data is processed in accordance with the GDPR and the German Telecommunications-Digital-Services-Data-Protection-Act (TDDDG):
• Art. 6(1)(a) GDPR / § 25(1) TDDDG serve as the legal basis for processing operations where we obtain consent for a specific purpose (e.g., optional analytics or marketing services).
• Art. 6(1)(b) GDPR serves as the legal basis for processing required to fulfill a contract or pre-contractual measures (e.g., project inquiries submitted via the contact form).
• Art. 6(1)(f) GDPR serves as the legal basis for processing necessary for our legitimate interests (e.g., secure operation of the website, prevention of cyber attacks, handling general business inquiries).
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content.
3. Hosting & Infrastructure (Netlify)
This website is hosted by Netlify (Netlify, Inc., 510 20th Street, Suite 206, San Francisco, CA 94107, USA).
When you visit our website, Netlify automatically collects technical connection data in server log files, including:
• IP address of the requesting device
• Date and time of the request
• Name and URL of the retrieved file
• Amount of data transferred
• Browser type and version
• Operating system used
• Referrer URL
This data is processed based on Art. 6(1)(f) GDPR. We have a legitimate interest in the technically error-free, secure operation and optimization of our website.
Netlify is certified under the EU-US Data Privacy Framework (DPF) and complies with Standard Contractual Clauses (SCC) to ensure an adequate level of data protection.
4. Contact Inquiries & Netlify Forms
When you send us inquiries via the contact form or email, your details and contact information are processed to handle your inquiry and any follow-up questions.
The contact form may collect the following information:
• Service area / project type (optional)
• Project description / requirements (required)
• Budget & timeline expectations (optional)
• Link to project brief or materials (optional, e.g. cloud storage or Figma links; submitted purely as text without automatic external previews)
• Name (required)
• Email address (required)
• Company name (optional)
• Phone number (optional)
• Confirmation of having read the Privacy Policy
Form data is securely transmitted via Netlify Forms (Netlify, Inc.) using encryption. An anti-spam honeypot field is used to filter automated submissions.
The legal basis for processing project-related inquiries is Art. 6(1)(b) GDPR (pre-contractual measures). For other general inquiries, the legal basis is Art. 6(1)(f) GDPR (legitimate interest in business correspondence).
Your submitted data remains stored until the purpose for data storage no longer applies (e.g. after concluding the inquiry) or you request its deletion, provided statutory retention periods do not apply.
5. Browser Storage (LocalStorage & SessionStorage)
This website uses browser storage features (LocalStorage and SessionStorage) to store user preferences locally on your device. No tracking profiles are created and no data is transferred to third parties.
The following entries are stored in the browser:
• andrii-gudz-theme-preference (LocalStorage): Stores your selected appearance choice (system, light, or dark) to display the website in your preferred theme on subsequent visits and prevent visual flickering.
• andrii-gudz-locale-preference (LocalStorage / SessionStorage): Stores your language/locale preference or the dismissal of the locale suggestion.
• andrii-gudz-consent (LocalStorage): Stores your consent decision (acceptance or rejection of optional categories) and the consent version.
You can inspect and clear data stored in your browser at any time through your browser settings.
6. Consent Management
To protect your privacy, this website implements a lightweight, first-party Consent Manager.
Optional analytics or marketing services are blocked by default and will only load if you explicitly grant consent via the banner or settings dialog.
You can view, change, or withdraw your consent at any time via the "Cookie Settings" link in the footer of this website.
7. Planned Analytics & Marketing Services (Google Analytics & Meta Pixel)
Interfaces for Google Analytics (Google Ireland Limited) and Meta Pixel (Meta Platforms Ireland Limited) are architecturally prepared but currently inactive.
If these services are activated in the future, the following principles apply strictly:
• Scripts will load only after your explicit opt-in consent (Art. 6(1)(a) GDPR / § 25(1) TDDDG).
• Without configuration and explicit consent, no scripts are loaded and no data is transferred to Google or Meta.
• You can revoke consent at any time using the Cookie Settings link in the footer.
8. Data Subject Rights
Under applicable data protection laws, you have the right to:
• Request access to your personal data (Art. 15 GDPR)
• Request rectification of inaccurate or incomplete data (Art. 16 GDPR)
• Request erasure of your stored data (Art. 17 GDPR)
• Request restriction of processing (Art. 18 GDPR)
• Data portability in a structured, common format (Art. 20 GDPR)
• Object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
• Withdraw any given consent at any time with future effect (Art. 7(3) GDPR)
To exercise these rights, please contact us by email at: andriigudz.de@gmail.com
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), such as the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).