Legal
Privacy policy
Here you can find out which data is processed when you visit this website – in short: as little as possible.
Please note: This English version is a courtesy translation. Only the German version is legally binding.
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Codemoon Studio
Owner: Patrick Walter
Karl-Engelhardt-Straße 5
34286 Spangenberg
Germany
E-mail: info@codemoonstudio.de
2. The key points at a glance
- The website sets no cookies and stores nothing in your browser – the only exception: after logging in to the client portal, a technically necessary session cookie.
- There is no tracking, no analytics tools and no advertising.
- Fonts, icons, images and videos are loaded from my own server – there are no connections to Google Fonts, CDNs or social networks.
- Personal data is only processed when you contact me (contact form with appointment booking or e-mail) – and for technical reasons when the page is accessed (server log files).
3. Hosting and server log files
This website is operated on my own servers (data centre: Hyonix, location: Frankfurt am Main, Germany).
When you access the website, information transmitted by your browser is automatically recorded (server log files):
- IP address
- Date and time of the request
- Page or file accessed and amount of data transferred
- Browser type and version, operating system
- Referrer URL (previously visited page)
Processing is based on Art. 6 (1) (f) GDPR. My legitimate interest lies in the secure, stable and error-free provision of the website and in defending against attacks. The log files are not merged with other data and are automatically deleted after a short period.
4. SSL/TLS encryption
For security reasons, this website uses SSL or TLS encryption. You can recognise an encrypted connection by “https://” and the lock symbol in your browser’s address bar. This means that data you transmit – for example via the contact form – cannot be read by third parties.
5. Contact form and appointment booking
If you send me an enquiry via the contact form, I process the following information: whether you are enquiring as a private individual or a company, company name if applicable, first and last name, address, phone number, e-mail address, project type, your project description, budget, desired timeline as well as the appointment you selected and the preferred language (German or English) for the free initial phone call. The call is conducted by a suitable contact person from my team; your enquiry is passed on internally for this purpose.
I use this data to process your enquiry, to call you at the selected time and, if applicable, to prepare a quote for you. Mandatory fields are marked with *; without this information I cannot process your enquiry.
The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures at your request) and otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries).
The data is transmitted in encrypted form directly to my own server and stored there (see section 3). No third-party providers are used for the form or appointment booking. To display available appointments, the form merely retrieves the available times from my server; no personal data is transmitted in the process.
After submitting, you will receive a confirmation by e-mail with your details and the appointment (incl. calendar entry); at the same time I am informed of the new enquiry by e-mail. To send these e-mails I use the Brevo service of Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris (France). Brevo processes your name, e-mail address and the content of the e-mail exclusively on my behalf; a data processing agreement has been concluded (Art. 28 GDPR). More information: Brevo privacy policy. My mailbox, through which I receive your replies, is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur (Germany).
Using a personal link in the confirmation e-mail, you can reschedule or cancel your appointment yourself; I am informed of any change by e-mail.
Customer database and client portal
Your details are stored in my customer database so that I can keep track of your enquiries, appointments and the services provided to you (Art. 6 (1) (b) GDPR). When you book an appointment, an account for the client portal may be created for you; you will receive the login details by e-mail. Your password is only stored in encrypted form (as a hash). You can request the deletion of your account and your data at any time.
For commissioned projects, I provide quotes, invoices, development progress and the finished project files in the client portal. I store these documents on my server so that both you and I can access them at any time; I keep invoices and quotes in accordance with the statutory retention periods (§ 147 AO, § 257 HGB – up to 10 years). If you pay an invoice via PayPal or with cryptocurrency, the privacy policy of the respective provider also applies (for PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg). Crypto payments are permanently stored in a public blockchain. I myself only store whether, when and how you paid.
Occasionally I inform customers about news by e-mail (newsletter). Every newsletter contains a link with which you can unsubscribe with one click; in the client portal you can switch these updates off and on again at any time. You can also object to the use of your e-mail address for this purpose at any time by sending a message to info@codemoonstudio.de, without incurring any costs other than the transmission costs according to the basic rates (§ 7 (3) UWG).
To protect against spam, the form contains a field that is invisible to humans, and the number of enquiries per IP address is briefly limited in the server’s memory (at most one hour, no permanent storage).
6. Contact by e-mail
If you contact me by e-mail, I process the data you provide (e.g. name, e-mail address, content of the enquiry) to handle your request. The legal basis is Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR.
7. Fonts, icons and videos
The fonts used on this website (Plus Jakarta Sans, Caveat), icons, images and videos are embedded locally and are loaded exclusively from this website’s server. There is no connection to third-party servers (e.g. Google).
8. No cookies, no tracking
The public pages of this website do not use cookies and do not store any information on your device (§ 25 TDDDG). No analytics, tracking or marketing services are used.
Only when you log in to the client portal is a session cookie set so that you stay logged in (at most 7 days or until you log out). This cookie is strictly necessary for the service you requested (§ 25 (2) no. 2 TDDDG) and is not used for any other purpose. A cookie banner is therefore not required.
9. Links to social networks
This website contains simple links to my profiles on social networks (e.g. GitHub, LinkedIn, Instagram). These are not embedded plugins: data is only transmitted to the respective provider when you click a link and visit its website. The privacy policy of the respective provider applies there.
10. Storage period
I only store personal data for as long as is necessary for the respective purpose. I delete enquiries as soon as they have been finally processed and no contract is concluded – at the latest after six months. If a contract is concluded, the data is stored for the performance of the contract and thereafter in accordance with the statutory retention obligations (usually 6 or 10 years under HGB and AO).
11. Your rights
You have the right at any time to:
- Access the data I have stored about you (Art. 15 GDPR)
- Rectification of incorrect data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdraw consent given, with effect for the future (Art. 7 (3) GDPR)
Right to object (Art. 21 GDPR)
Insofar as I process data on the basis of a legitimate interest (Art. 6 (1) (f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation.
An informal message to info@codemoonstudio.de is sufficient to exercise your rights.
12. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for me is: Hessian Commissioner for Data Protection and Freedom of Information (Hessischer Beauftragter für Datenschutz und Informationsfreiheit).
An overview of all German supervisory authorities can be found at the Datenschutzkonferenz.
13. Miscellaneous
No automated decision-making including profiling (Art. 22 GDPR) takes place. You are not legally or contractually obliged to provide me with personal data – without contact details, however, I cannot answer an enquiry.
I adapt this privacy policy when the website or the legal situation changes. The version published here applies.
Last updated: October 2026