Courtesy translation; the German version is legally binding.

Privacy Policy

1. Controller

The controller within the meaning of the GDPR is:
André Deiss · Studio Deiss, Leutenbergstraße 19, 78532 Tuttlingen, Germany
Email: [email protected]

2. Your rights

You have the right at any time to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw any consent given at any time. You also have the right to lodge a complaint with a data protection supervisory authority.

3. Hosting

This website is delivered via Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA); a data processing agreement (Art. 28 GDPR) is to be concluded with the provider. Where data is transferred to the USA, this is based on the EU-US Data Privacy Framework or standard contractual clauses. Legal basis: Art. 6(1)(f) GDPR (secure, efficient operation of the website).

4. Server log files

When the site is accessed, data is automatically recorded in server log files (IP address, date/time, file requested, browser type, referrer). Purpose: technical operation and security. Legal basis: Art. 6(1)(f) GDPR. Storage period: typically 7 days.

5. Contact (form & email)

If you contact us via the form or by email, we process the data you provide (e.g. name, email, message) to handle your enquiry. Legal basis: Art. 6(1)(b) GDPR (pre-contractual) or (f) (communication). The data is deleted once it is no longer required, at the latest after 6 months, unless statutory retention obligations apply.

6. Fonts

All fonts are served locally from our own server. There is no connection to third parties (e.g. Google Fonts, Fontshare) and therefore no transfer of your IP address to third parties.

7. Embedded media

Video and audio content is also delivered directly from our own server. No external players (e.g. YouTube/Vimeo) that transfer data to third parties are embedded.

8. Cookies & consent

This website uses only technically necessary mechanisms and no tracking and no analytics or marketing cookies. Consent under § 25 TDDDG is therefore not required. Should non-essential services be used in future, we will obtain your consent beforehand.

9. Encryption

The website is delivered exclusively over an encrypted HTTPS (TLS) connection.

Last updated: 15 June 2026