Privacy policy

Last updated: 16.06.2026

This is a courtesy translation. The legally binding version is the German one.

1. Controller

The controller within the meaning of the GDPR is:
Nikita Moritz, Stiftstr. 39, 52062 Aachen, Germany
Email: [email protected]

2. General information on data processing

We process personal data only where this is necessary to provide this website and its functions, or where another legal basis under Art. 6 GDPR applies. Data is passed on to third parties only in the cases described below.

3. Hosting and server logs

The application runs on a server in Germany (Hetzner Online GmbH, Frankfurt/Falkenstein location). The database is hosted on a managed PostgreSQL service inside the EU. When the pages are accessed, technically necessary data (IP address, timestamp, requested resource, user agent) is processed for a short time in order to ensure delivery and security. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure operation). Data processing agreements pursuant to Art. 28 GDPR are in place with the processors.

4. Reach measurement (first-party statistics)

We use our own privacy-friendly statistics to measure how the site is used. An anonymous session cookie (nikone_anon, stored for up to 1 year) is set, which does not allow direct identification. We record the page visited, the referrer, a coarse origin (country) and, if present, campaign parameters (UTM). IP addresses are not stored permanently for statistics. The legal basis is Art. 6 (1) (f) GDPR; the cookie is technically necessary for reach measurement in the privacy-friendly form we have chosen.

5. Contact and booking forms

If you contact us through a form (contact, enquiry, appointment booking), we process the data you provide (for example name, email, message) in order to handle your request. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR. The data is deleted as soon as it is no longer required for that purpose and no statutory retention periods prevent deletion. For sending email we use Resend (Resend, Inc., USA); the transfer takes place on the basis of the EU-US Data Privacy Framework or standard contractual clauses (Art. 44 et seq. GDPR).

6. Client portal and account

For the client portal we process the data required to sign in. Sign-in is passwordless, using a link sent by email (magic link). Technically necessary session cookies are set. The legal basis is Art. 6 (1) (b) GDPR (contract and use of the portal).

7. Services used and recipients

  • Hetzner Online GmbH, Germany: server and hosting (Art. 28 GDPR).
  • Managed PostgreSQL service, EU: database (Art. 28 GDPR).
  • Resend, Inc., USA: sending transactional email (DPF/SCC).
  • Cloudflare, Inc., USA: CDN, DNS and security (DPF/SCC).

8. Fonts

Fonts are served locally from our own server (self-hosted). No connection is made to Google Fonts or any other external font provider.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). A message to the email address given above is sufficient to exercise them. You also have the right to lodge a complaint with a supervisory authority, in North Rhine-Westphalia with the State Commissioner for Data Protection and Freedom of Information NRW.

10. Changes to this policy

We adapt this privacy policy as soon as changes to our processing make it necessary. The version published on this page at the time applies.