Privacy Policy — Contact Form

Last updated:

This privacy notice explains how we process your personal data when you use the contact form on jozapf.de. We process your data in accordance with the EU General Data Protection Regulation (GDPR) and applicable German data protection law.

1. Controller

Jo Zapf
Berliner Str. 45
13189 Berlin, Germany

3. Data Categories Collected via the Contact Form

3.1 Form Data

3.2 Technical Metadata (Extended Logging)

To protect our service from automated abuse, spam, and security threats, we log the following technical metadata when you submit the contact form:

IP Address Processing:
Your IP address is stored in full for 14 days to enable abuse prevention measures (blocking repeated spam attacks, identifying coordinated abuse patterns). After 14 days, the last segment of your IP address is automatically anonymized (e.g., 192.168.1.100 becomes 192.168.1.XXX), making it no longer personally identifiable while preserving statistical data.

3.3 Blocklist & Whitelist

If your IP address is associated with abusive behavior (e.g., spam, repeated failed submissions, automated attacks), we may add it to a blocklist to protect our service. Conversely, trusted IP addresses may be whitelisted. Blocklist entries can be temporary (with expiration date) or permanent, and include a reason for blocking.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in maintaining service security and preventing abuse).

4. Cookies

4.1 Technical Cookies (No Consent Required)

We use strictly necessary cookies for essential website functionality. These cookies are required for the operation of our services and do not require consent under ePrivacy law.

Authentication Cookie
Purpose: Secure access to administrative areas.
Duration: 24 hours.
Legal basis: Art. 6(1)(b) GDPR (necessary for service provision).

4.2 No Tracking or Analytics Cookies

We do not use third-party tracking, analytics, advertising, or social media cookies.

5. Recipients & Processing

Your message is delivered to us by email. For this we use our email provider and hosting services:

These service providers act as (sub-)processors under Art. 28 GDPR on the basis of appropriate data processing agreements. Within our organization, access is limited to persons who need the data to process your inquiry (need-to-know principle).

6. Third-Country Transfers

We do not intentionally transfer contact form data to countries outside the EU/EEA. If an exceptional transfer is necessary (e.g., you request contact via a non-EU channel), we will ensure appropriate safeguards under Art. 44 ff. GDPR.

7. Storage Periods & Anonymization

7.1 Message Content

7.2 Technical Logs (GDPR-Compliant)

Data Type Full Storage After Anonymization
IP Address 14 days Anonymized (last segment replaced with XXX) — retained for statistics
User-Agent, Fingerprint 14 days Retained for statistics (non-identifying)
Spam Score, Timestamps Indefinite Not personally identifiable
Blocklist Entries Until manually removed or expired

7.3 Automatic Anonymization Process

We employ an automated anonymization system that runs periodically to anonymize IP addresses older than 14 days. This process is irreversible and ensures compliance with data minimization principles (Art. 5(1)(c) GDPR). An audit log records all anonymization actions for accountability.

7.4 Whitelist/Blocklist Storage

8. Your Rights (GDPR)

You have the right to request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), and data portability (Art. 20), and to object to processing based on Art. 6(1)(f) (Art. 21). Where processing is based on consent, you may withdraw consent at any time (see Section 9).

To exercise your rights, please contact us at the address provided in Section 1.

8.1 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data. Note that:

10. Obligation to Provide Data

You are not legally obliged to provide personal data. However, without essential information (first name, last name, email address, and message text), we cannot process your inquiry. Optional fields (phone, subject) are marked accordingly.

The privacy policy checkbox must be checked to submit the form (contractual requirement).

11. Security

We implement appropriate technical and organizational measures to protect your data (Art. 32 GDPR), including:

12. Complaints

You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

In Berlin, Germany, the competent authority is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstr. 219, 10969 Berlin
www.datenschutz-berlin.de

13. Changes to This Notice

We may update this notice to reflect legal, technical, or operational changes. The "Last updated" date at the top indicates the current version. Material changes will be communicated appropriately (e.g., via website notice).


Summary for Users

What we collect:

What we DON'T do:

Your rights: You can request access, correction, or deletion of your data at any time.