001✓ copiedprivacy

Privacy

Art. 13 GDPR

This notice describes what clemence.io does with personal data, under Art. 13 and Art. 14 of the General Data Protection Regulation (GDPR).

Two processors are involved and both are named below. The site sets no cookies, loads no fonts or scripts from a third-party network, and runs no advertising or tracking pixels.

Who is the controller?

Clemence W. Chee is the controller under Art. 4 No. 7 GDPR for all processing described on this page.

Clemence W. Chee
Scharnhorststraße 8b
10115 Berlin
Germany

Contact runs through the form at /contact. No email address is published on this site.

No data protection officer has been appointed. The thresholds in Art. 37 GDPR and § 38 BDSG are not met by a sole trader operating a static website.

What happens when you load a page?

Netlify, the hosting provider, records a server log entry for each request.

That entry contains the requested URL, the time of the request, the HTTP status, the volume of data transferred, the referring page, and the browser and operating system as reported by the user agent. The IP address is processed as part of delivering the response.

  • Purpose: delivering the site, and detecting and defending against attacks.
  • Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is operating a website that stays online.
  • Retention: Netlify’s standard log retention applies. Logs are not exported, combined with other data, or used to build a profile.
  • Processor: Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA.

Netlify is based in the United States, so this involves a transfer under Chapter V GDPR. The transfer relies on the EU-US Data Privacy Framework where Netlify is certified, and on the European Commission’s Standard Contractual Clauses in addition. A data processing agreement under Art. 28 GDPR is in place.

What happens when you use the contact form?

The contact form is processed by Netlify Forms, and Netlify keeps a copy of every submission.

This is the part most privacy policies leave out, so it is stated plainly. A submission is emailed to Clemence W. Chee, and it is also stored in the Netlify dashboard for the site. Two copies exist, in two places, until both are deleted.

  • Data collected: the name, the organisation, the email address and the message you type into the form. Nothing else is requested and no hidden fields collect anything beyond a spam honeypot that stays empty for real visitors.
  • Purpose: answering your enquiry and any resulting business conversation.
  • Legal basis: Art. 6(1)(b) GDPR for steps taken at your request before entering a contract, and Art. 6(1)(f) GDPR for general enquiries that do not lead to one.
  • Retention in the Netlify dashboard: submissions are deleted from the Netlify dashboard within 90 days.
  • Retention in the mailbox: correspondence is kept as long as the conversation is live, then deleted, unless commercial or tax law requires it to be retained under § 147 AO or § 257 HGB.
  • Processor: Netlify, Inc., under the same Art. 28 agreement and the same transfer basis described above.

Netlify’s built-in spam filtering evaluates submissions. Providing the form data is voluntary, and without it an enquiry cannot be answered.

What does the analytics tool record?

Cloudflare Web Analytics counts page views without setting a cookie and without storing anything on your device.

The beacon reports the page URL, the referrer, the browser and the country, and Cloudflare derives a visit count from them. No identifier is written to the browser, no cross-site profile is built, and no data is used for advertising.

  • Purpose: knowing which pages are read.
  • Legal basis: Art. 6(1)(f) GDPR. The legitimate interest is understanding whether the site is useful.
  • Consent: none is required. § 25 Abs. 1 TDDDG applies to storing information on, or reading information from, a device. This tool does neither, which is why clemence.io has no cookie banner.
  • Processor: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, under Art. 28 GDPR with Standard Contractual Clauses for the transfer.

If the analytics beacon is absent from the page source, analytics is switched off and this section describes nothing.

What is deliberately absent?

Six things this site does not do, listed because their absence is the reason there is no consent banner.

Not usedConsequence
Cookies of any kindNo consent banner under § 25 TDDDG
Google Fonts or any font CDNNo IP address is sent to a third party on page load
Third-party JavaScript or tag managersNothing loads that this site does not serve itself
Advertising and remarketing pixelsNo profile is built and none is sold
Social media embeds and share buttonsVisiting a page does not tell a social network you were here
Session recording and heatmapsNo recording of what you click or type exists

Fonts, styles and scripts are served from clemence.io. Contact form submissions and server logs are the only processing that leaves this site’s own infrastructure, and both go to the processors named above.

What rights do you have?

You can exercise the rights in Art. 15 to Art. 21 GDPR at any time through the contact form.

  • Art. 15, access to the personal data held about you.
  • Art. 16, correction of inaccurate data.
  • Art. 17, erasure.
  • Art. 18, restriction of processing.
  • Art. 20, portability in a machine-readable format.
  • Art. 21, objection to processing based on Art. 6(1)(f), which covers the server logs and the analytics described above.

You can also complain to a supervisory authority under Art. 77 GDPR. For a controller established in Berlin that authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin. This is the competent supervisory authority for a controller based in Berlin.

No automated decision-making or profiling under Art. 22 GDPR takes place on this site.

When did this notice last change?

This notice was last updated on the date shown at the top of the page and applies from that date.

Changes are made when the processing changes, for example when a processor is added or removed. Older versions are not archived publicly, so the date at the top is the version identifier.