Privacy Policy
Protecting your data matters to me. This policy explains which personal data is processed when you visit this website, and on what legal basis. The website is deliberately built to process as little data as possible: no advertising cookies, no third-party tracking, self-hosted fonts.
1. Controller
The controller responsible for data processing on this website is:
Jan Sprenger
werkflow.studio
Weidenweg 75
10247 Berlin
Germany
Phone: +49 176 32275395
Email: contact@werkflow.studio
2. Relevant legal bases
The following is an overview of the legal bases under the GDPR on which I process personal data. Where more specific legal bases apply in an individual case, I state them at the relevant point in this policy.
- Consent (Art. 6(1)(a) GDPR): you have consented to the processing of your data for a specific purpose.
- Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR): processing is necessary to perform a contract or to handle your enquiry prior to entering into a contract.
- Legitimate interests (Art. 6(1)(f) GDPR): processing is necessary to safeguard my legitimate interests or those of a third party, provided your interests and fundamental rights do not override them.
In addition to the GDPR, national data protection rules apply in Germany, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).
3. Security of processing
In accordance with Art. 32 GDPR, I take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
The connection between your browser and this website is secured by TLS/SSL encryption (HTTPS). You can recognise this by the “https://" and the padlock symbol in your browser's address bar. This protects the data transmitted between your device and the server against unauthorised access.
4. Hosting and server log files
This website runs on a dedicated server that I rent from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
When you access the website, information transmitted by your browser is automatically stored in a server log file:
- IP address
- date and time of access
- page or file requested
- amount of data transferred and confirmation of successful retrieval
- browser type and version, operating system, referrer URL
This data is technically necessary for the secure and stable operation of the website. The legal basis is the legitimate interest in a functioning website protected against misuse (Art. 6(1)(f) GDPR). The log files are deleted after a short period unless they are exceptionally needed to investigate a specific security incident. They serve secure operation only: they are not analysed for reach measurement (section 7) and are not combined with its data.
5. Fonts
This website uses fonts that are loaded directly from its own server (self-hosting). No connection is made to third-party servers such as Google Fonts, and no data is transmitted to third parties as a result.
6. Cookies and local storage
This website does not set any cookies for advertising or analytics purposes. Your browser's local storage holds just two technical settings: your choice between light and dark design, and — if you use the language switcher — the language you picked. Both stay on your device, are not transmitted to me or any third party, and are necessary for the display option you selected (Art. 6(1)(f) GDPR). No consent banner is required for this.
If you have not made a choice, the presentation follows your browser settings: the colour scheme follows your system preference, the language follows the language list configured in your browser. Both are evaluated inside your browser only — your IP address is not used for this, and no third-party service is consulted.
7. Reach measurement with Rybbit
To improve the website, I collect anonymous usage statistics using Rybbit, an open-source analytics solution that I run myself on my own server (see section 4). No cookies are set and no data is passed on to third parties.
Your IP address is evaluated once when you access a page, in order to place the request roughly by country. It is then discarded: it is not stored, not logged, and is never visible to me at any point. Only the result is stored, for example “Germany”.
No plain data such as name or email address is stored, only pseudonymous values; no individual user profiles are created and you cannot be identified as a person. Your session is not recorded (no session replay). In addition, technical error messages from the website (such as the message, file and line of a JavaScript error) are recorded so that I can find and fix faults. The legal basis is my legitimate interest in a needs-based design of the website (Art. 6(1)(f) GDPR).
8. Contact form, email and phone
You can send me a message directly via the contact form on this website. The data processed is what you enter: your name, your email address and the text of your message. This data is transmitted encrypted to my server (see section 4) and forwarded from there to me by email; it is only stored as a received message in my mailbox. To protect against automated spam, the form contains a hidden field (honeypot) that stays invisible to you and collects no data about you. The legal basis is the initiation or performance of a contract (Art. 6(1)(b) GDPR) or my legitimate interest in responding to your enquiry (Art. 6(1)(f) GDPR).
If you contact me by email or phone, I process the data you provide (such as your name, contact details and the content of your enquiry) in order to respond to it. The legal basis is the initiation or performance of a contract (Art. 6(1)(b) GDPR) or my legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). I delete this data as soon as it is no longer needed and no statutory retention obligations apply.
Email is sent and received via the provider mailbox.org (Heinlein Support GmbH, Schwedter Str. 8/9b, 10119 Berlin, Germany), with whom a data processing agreement is in place.
9. Contact via WhatsApp
You may contact me via WhatsApp if you wish. The service is operated by WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland, a company of the Meta group. If you message me on WhatsApp, the content of your message and metadata (such as your phone number and connection data) are processed by WhatsApp; this may involve a transfer of data to the USA. For this transfer, WhatsApp/Meta relies on the EU-US Data Privacy Framework, under which the company is certified, and additionally on standard contractual clauses (Art. 46 GDPR).
I have set up WhatsApp so that the app has no access to my device's address book. As a result, no automatic matching of my stored contact data with WhatsApp/Meta takes place.
I have no influence over the processing by WhatsApp itself; the privacy terms of WhatsApp/Meta apply. I process the messages addressed to me via WhatsApp in order to handle your enquiry. The legal basis is your consent, given by actively using this channel (Art. 6(1)(a) GDPR), as well as my legitimate interest in responding (Art. 6(1)(f) GDPR). If you wish to avoid this processing, please use email or phone.
10. Presence on LinkedIn
I maintain a professional profile and, where applicable, a company page on the LinkedIn network. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. This website itself contains no LinkedIn plugin and no LinkedIn tracking — there is merely a simple reference link to my LinkedIn presence, which establishes a connection to LinkedIn only when clicked.
If you interact with my LinkedIn presence (for example by viewing or commenting on posts, following me or sending me a message), LinkedIn processes the resulting data under its own responsibility in accordance with its privacy terms; this may also involve a transfer of data to the USA (based on the EU-US Data Privacy Framework and standard contractual clauses, Art. 46 GDPR). I have only limited influence over this processing by LinkedIn.
Insofar as I operate a company page, LinkedIn provides me with anonymised statistics about interaction with the page. For these page statistics, LinkedIn and I are joint controllers within the meaning of Art. 26 GDPR; the relevant agreement is provided by LinkedIn.
I process the data you send me via LinkedIn in order to communicate with you. The legal basis is my legitimate interest in public presentation and communication (Art. 6(1)(f) GDPR) or your consent (Art. 6(1)(a) GDPR) where you actively make contact.
11. Appointment booking
To arrange an initial call I use meetergo, a scheduling service provided by meetergo GmbH. The booking calendar is embedded on the contact page; when you open that page, content is loaded from meetergo's servers, which transmits your IP address to meetergo. If you book an appointment, meetergo processes the data you provide (such as your name, email address, phone number where applicable and an optional message) on my behalf to organise and carry out the appointment.
meetergo acts as my processor; I have concluded a data processing agreement with meetergo GmbH pursuant to Art. 28 GDPR. Processing takes place on servers within the European Union. The legal basis for processing the appointment data is the initiation of a contractual relationship at your request (Art. 6(1)(b) GDPR); loading the embedded calendar is additionally based on my legitimate interest in straightforward appointment scheduling (Art. 6(1)(f) GDPR). The appointment data is deleted as soon as it is no longer needed. Details of meetergo's processing can be found in its privacy policy.
12. Your rights
You have the following rights regarding your personal data:
- access to the data processed (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing based on legitimate interests (Art. 21 GDPR)
- withdrawal of a given consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, an informal message to contact@werkflow.studio is sufficient.
13. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority. The authority responsible for me is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
14. Currency of this policy
This privacy policy is dated July 2026. As the website evolves or legal requirements change, it may need to be adapted. The version published here always applies.