Privacy Policy — Contact Form
Last updated:
This privacy notice explains how we process your personal data when you use the contact form on jozapf.de. We process your data in accordance with the EU General Data Protection Regulation (GDPR).
1. Controller
Jo Zapf
Berliner Str. 45
13189 Berlin, Germany
2. Purposes & Legal Bases
We process contact form data for:
- Responding to your inquiry
- Preventing abuse and spam (rate limiting, captcha validation)
- Maintaining service security
Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)
3. Data Categories Collected
3.1 Contact Form Data
- Name, email address, phone (optional)
- Message subject and content
- Captcha answer (local arithmetic challenge)
- Privacy policy acceptance (checkbox)
3.2 Technical Metadata
- IP address (stored 14 days, then anonymized)
- Timestamp, User-Agent, Browser fingerprint
- Spam score and validation results
Your IP is stored for 14 days for abuse prevention. After 14 days, it's automatically anonymized (e.g., 192.168.1.100 becomes 192.168.1.XXX).
5. Recipients & Processing
Your message is processed by:
- Hetzner Online GmbH — Email transmission (Germany/EU)
These are sub-processors under Art. 28 GDPR with appropriate data processing agreements.
6. International Transfers
Contact form data is not intentionally transferred outside the EU/EEA.
7. Storage Periods
Contact messages: 12 months
Technical logs:
- Full IP address: 14 days
- Anonymized IP: Retained for statistics
- Other metadata: Indefinite (non-identifying)
8. Your Rights (GDPR)
You have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Request erasure (Art. 17)
- Request restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
Contact us at the address above to exercise these rights.
9. Consent & Withdrawal
By checking the privacy policy checkbox, you consent to our processing. You may withdraw consent at any time by contacting us.
10. Data Requirements
Providing data is voluntary, but we need essential information (name, email, message) to respond to you.
11. Security
We protect your data with:
- TLS 1.3 encryption for all transmission
- Rate limiting and spam detection
- HMAC-signed authentication tokens
- Automatic IP anonymization after 14 days
- Security audit logging
12. Repository Overview (gitea.jozapf.de)
Our home page displays an overview of public software projects. To do so, your browser requests a static file containing project metadata from gitea.jozapf.de — a subdomain operated by the same controller (see section 1). No third parties are involved.
- Your IP address: Recorded in the web server logs of gitea.jozapf.de when the file is requested (standard HTTP logging) — not shared with third parties
- Requested data: Exclusively public project metadata (name, description, topics, programming languages) — no personal data, no cookies
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest: presenting the portfolio)
- Opt-out: You can block requests to gitea.jozapf.de using browser extensions — the overview will then display a notice
13. Complaints
You have the right to lodge a complaint with a supervisory authority:
Berlin, Germany:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstr. 219, 10969 Berlin
www.datenschutz-berlin.de
14. Changes to This Notice
We may update this notice to reflect legal or technical changes. The "Last updated" date indicates the current version.
Summary for Users
What we collect via contact form:
- Your contact details (to respond)
- IP address (14 days, then anonymized)
- Technical metadata for security
What we collect via the repository overview:
- Your IP address in our own web server logs when the project metadata is requested
- Only public project metadata is requested — no personal data
- No third parties involved — gitea.jozapf.de is operated by the same controller
Your rights: Request access, correction, or deletion at any time.