Privacy Policy
Last Updated: 05.05.2025
1. Data Controller
István Ékes
Preußenstraße 15, 66111 Saarbrücken, Germany
Email: contact@istvanekes.com
As a freelance developer based in Germany, I comply with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
2. Data I Collect
a) Automatically Collected Data (Website Analytics):
-
Cookies: My website uses essential cookies (e.g., for session management). For analytics (like Google Analytics), I anonymize IP addresses and only process data with your consent.
-
Log files: IP address, browser type, pages visited (stored for 30 days for security purposes).
b) Data You Provide (Contact Forms/Projects/Calendly):
-
Contact form: Name, email, message content.
-
Client projects: Billing details (name, address, tax ID) for contracts and invoices.
-
Calendly appointments: Name, email, phone (optional), and any details you provide when scheduling a call. Calendly acts as a data processor under GDPR.
3. Legal Basis & Purpose
I process your data only:
-
To fulfill contracts (Art. 6(1)(b) GDPR) for project inquiries.
-
With your consent (Art. 6(1)(a) GDPR) for cookies/newsletters/Calendly scheduling.
-
For legitimate interests (Art. 6(1)(f) GDPR), like website security or improving services.
4. Data Sharing
I do not sell your data. Limited sharing may occur with:
-
Payment processors (e.g., PayPal, Stripe) for invoices.
-
Hosting providers (e.g., Netlify, Vercel) with GDPR-compliant contracts.
-
Calendly: Stores your scheduling data in the U.S. under GDPR-compliant Standard Contractual Clauses (SCCs). Review Calendly’s GDPR compliance here.
-
Legal authorities if required by German law.
5. Data Retention
-
Contact form data: Deleted after 1 year unless a contract is signed.
-
Client data: Retained for 10 years (German tax law requirement).
-
Cookies: Session cookies expire when you close your browser.
-
Calendly data: Stored until you request deletion or after 2 years of inactivity.
6. Your Rights Under GDPR
You have the right to:
-
Access, correct, or delete your data (including Calendly appointments).
-
Export your data in a machine-readable format.
-
Withdraw consent (e.g., for analytics/Calendly).
-
Lodge a complaint with a supervisory authority (e.g., German State Data Protection Office).
To exercise these rights, email me at contact@istvanekes.com
7. Security Measures
-
SSL encryption (HTTPS) on my website and Calendly.
-
Two-factor authentication for tools handling sensitive data.
8. Third-Party Services
-
Google Analytics: Anonymized data, opt-out via browser add-on.
-
Calendly: Processes appointments under GDPR. You can delete scheduled events via Calendly’s interface or by contacting me.
-
Fonts/Embeds: Hosted locally or by GDPR-compliant providers.
9. Updates to This Policy
I will notify users of significant changes via email or a website notice.
Contact Me
For privacy-related questions or to delete Calendly data:
contact@istvanekes.com
