felixschumann.dev / Legal
Privacy policy
How information is processed when you visit or get in touch.
1. Controller
Felix SchumannGartenstraße 23
97529 Alitzheim
Germany
2. Visiting the website and hosting
This portfolio runs on a virtual server at Hostinger. It provides a contact form, appointment booking and an operator-only dashboard. There is no public account registration or embedded advertising or third-party tracking; its own reach measurement is described in section 5. Visits involve processing technical connection data, including IP address, requested resource, time and request information. This is needed to deliver, troubleshoot and protect the website.
Delivery and technical protection rely on Article 6(1)(f) GDPR. The legitimate interest is the reliable and secure operation of this portfolio. Hosting providers support this operation; Hostinger describes its processing in its privacy policy.
3. Cloudflare and attack protection
Cloudflare acts as an intermediary and security service. Requests pass through its network, which processes IP addresses and technical traffic data to cache content and detect and mitigate attacks. The website gateway also briefly processes the IP address in memory to limit excessive requests; this entry expires after two minutes of inactivity.
Cloudflare may use necessary security cookies, for example following a security check. These do not constitute advertising consent and are not controlled by the banner's preference switch. Cloudflare Web Analytics and Rocket Loader are not included on this website. Technical protection relies on Article 6(1)(f) GDPR; strictly necessary access to terminal equipment is covered by section 25(2) TDDDG.
Cloudflare operates an international network. Its policies explain processing, recipients, international transfers and the safeguards it describes.
Cloudflare Privacy Policy · Cloudflare data processing addendum
4. Consent banner and browser storage
German and English are available through dedicated language paths. On an address without a language prefix, the server uses the language preference sent by your browser. A previously consented preference is then applied in the browser. No location lookup is used. The language control opens the corresponding version; the URL also tells the server which language to deliver.
The banner necessarily stores your decision on your device so it can be respected. It is kept in the browser's local storage and additionally in the cookie “portfolio-consent-v3”; if your browser refuses one of the two, the other is enough to stop the question being asked on every page. Both hold nothing but your answer to this question, no identifier and no other data. The decision lasts 180 days, is then requested again and covers two optional categories: comfort and reach measurement (section 5). Only if you enable the comfort category are your language and light/dark choices stored persistently. Without that consent, the controls still work for the current visit but their choices are not stored persistently.
You can change your decision through Cookie settings in the footer. Stored preferences are removed when consent is withdrawn or expires. Optional preferences rely on your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. Withdrawal takes effect for future processing. Comfort preferences remain in local browser storage. The consent cookie is technically sent with matching HTTP requests and is not used as a visitor identifier.
The operator area uses technically necessary authentication cookies. The dashboard verifies a one-time email code for explicitly authorised operator addresses. The challenge cookie lasts ten minutes; a session ends after at most twelve hours or two hours of inactivity. The existing reach-measurement area uses a separate sign-in. Reading the public website does not create an authenticated session.
When you explicitly change language or appearance, that choice is kept in this tab's sessionStorage under portfolio-session-language or portfolio-session-theme. It therefore survives language changes and reloads. These session preferences do not enable analytics and are not transmitted as visitor identifiers. They provide the requested display under Article 6(1)(f) GDPR and section 25(2) TDDDG. Remembering preferences beyond this browser session still depends on comfort consent.
5. Reach measurement
With your consent, this website measures page views, selected interactions and active visit time to understand which content and contact options are useful. Analytics runs on the website's server. No third-party analytics or advertising service is embedded.
Records contain the public page path without search parameters, interface language, referring hostname or direct, coarse device class, country code from Cloudflare and the server timestamp. Interactions include navigation, contact and booking steps, WhatsApp and email links, FAQ openings and display controls. Targets are limited to public paths, external origins or defined interface choices. Form contents, search terms, names, email addresses and telephone numbers are not part of these records.
After consent, a random visit identifier is stored with its last activity time in sessionStorage under portfolio-analytics-visit. It links page views and clicks within a visit and expires after 30 minutes of inactivity. Page views also have random identifiers. Active time is measured while the tab is visible, pauses after 30 seconds without interaction and is reported periodically and when leaving. It is an estimate and can miss final seconds. Full IP addresses, full user-agent strings and fingerprints are not stored in analytics. IP addresses are only used briefly in memory for request limits.
The legal basis is consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. The expanded measurement introduced with consent version 3 requires a new choice; earlier analytics permission is not reused for it. You can withdraw consent through Cookie settings in the footer. Further measurement stops and the visit identifier is removed where browser storage permits; earlier lawful processing is unaffected. Raw records are deleted automatically after 90 days. Analysis remains on the server described in the hosting section and does not identify a visitor as a particular email recipient.
6. Technical logs, fonts and images
The gateway's own logs are limited to technical information such as time, status, method, path and response time. They do not record full visitor IP addresses or search parameters. This gateway's logs rotate by size and are limited to three files of at most 10 MB each. Cloudflare processes its security and connection data for the purposes and under the rules described in its policies.
Fonts and images are served with the website under this domain. Your browser does not connect directly to Google Fonts to load fonts. Additional AI-generated portrait studies are labelled as such.
7. Contact form, booking, email and telephone
If you get in touch, I process your contact details, message and supplied information to handle your enquiry. The [email protected] mailbox is hosted by Hostinger. Enquiries leading towards a contract rely on Article 6(1)(b) GDPR; other enquiries rely on Article 6(1)(f). Messages are retained as needed to handle the enquiry and maintain relevant correspondence, subject to applicable statutory retention requirements.
The form processes your name, email address, telephone number, optional company, message and, for a booking, the selected time. A mail-server check and a one-time code verify the email address. Unverified requests expire after ten minutes. Verified enquiries and appointments are encrypted on the website's server. Hostinger Mail delivers codes, receipts and appointment changes. Submitting the form does not subscribe you to advertising or newsletters.
To prevent abuse, short-lived values derived from IP and email addresses using a secret key are used for rate limits. Full IP addresses are not stored in the application database for this purpose. Counters expire after 15 minutes, or 24 hours for booking limits. Mail jobs are deleted after 30 days and administrative events after 90 days. Enquiries are removed after 180 days without handling, and appointments 180 days after their end. Cleanup runs regularly. Mailbox correspondence and any separate contractual records remain subject to the handling and retention purposes described above.
8. WhatsApp and contact download
The WhatsApp button is an external link. Clicking it opens WhatsApp or its website, where WhatsApp's privacy policy applies. No WhatsApp widget is embedded here. You can also use the contact form, email or telephone. The contact file contains only my published contact details and downloads directly from this website.
9. Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction and data portability. Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. Consent can be withdrawn for future processing. You may also complain to a supervisory authority, particularly where you live, work or believe an infringement occurred.
Updated: 08.09.2026
