Burghardt.design← Back to home

Privacy Policy

Last updated: 10 September 2026

Protecting your data matters to us. Below you will find which personal data we process when you visit this website and use our services, why we do so, and what rights you have.

This English text is a convenience translation. The legally binding version is the German Datenschutzerklärung.

1. Controller

The controller for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Paul Burghardt, Burghardt Design, Kaiser-Wilhelm-Ring 29 / 4, 55118 Mainz, Germany. Phone: +49 151 55616772. Email: info@burghardt.design (alternatively: paul-burghardt@outlook.de).

No data protection officer has been appointed, as the conditions of Art. 37 GDPR and § 38 BDSG are not met. For any privacy question, please use the contact details above.

2. Overview and principles

Personal data is any data by which you can be personally identified. We only process it where this is necessary to operate this website, to answer your enquiries or to perform our contracts — or where you have given your consent.

We do not sell your data and do not pass it on to third parties for advertising purposes. Data is shared only with the service providers named in this policy, to the extent required to deliver our services, or where we are legally obliged to do so.

Please note that data transmission over the internet — email in particular — can have security gaps. Complete protection against access by third parties is not possible.

3. Legal bases

Consent: Where we ask for your consent, the legal basis is Art. 6 (1)(a) GDPR and, for storing information on or accessing information in your device, additionally § 25 (1) TDDDG. You may withdraw consent at any time with effect for the future.

Contract: We process data under Art. 6 (1)(b) GDPR to perform a contract or take pre-contractual steps — for example when you create an account, submit a brief, or we deliver a project for you.

Legal obligation: Commercial and tax law obligations are met on the basis of Art. 6 (1)(c) GDPR.

Legitimate interests: Otherwise we rely on Art. 6 (1)(f) GDPR, in particular our interest in the secure, stable and abuse-free operation of this website. Strictly necessary cookies require no consent under § 25 (2) TDDDG.

4. Hosting and server log files

This website runs on a rented server provided by DigitalOcean, LLC (105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA). The server used is located in DigitalOcean's Frankfurt am Main data centre in Germany, where the data is stored. A data processing agreement under Art. 28 GDPR is in place; where access from the USA cannot be ruled out, it is covered by the European Commission's standard contractual clauses (see section 16).

The domain as well as DNS and mail routing are provided by united-domains GmbH (Gautinger Straße 10, 82319 Starnberg, Germany).

On every request the server automatically collects access data in so-called server log files: the address requested, date and time, volume of data transferred, notification of successful retrieval, browser type and version, operating system, referrer URL and IP address. This data is required to serve the website, ensure its stability and security and fend off attacks. The legal basis is Art. 6 (1)(f) GDPR.

Log files are generally deleted after no more than 14 days, unless they are exceptionally needed longer to investigate a specific security incident. This data is not merged with other data sources.

5. Cookies and similar technologies

Cookies are small text files stored by your browser. In normal operation we use strictly necessary cookies only — without them sign-in and the language choice do not work. They require no consent under § 25 (2) TDDDG; the legal basis is Art. 6 (1)(f) GDPR.

Optional cookies and comparable technologies in the statistics and marketing categories are only used with your explicit consent (§ 25 (1) TDDDG, Art. 6 (1)(a) GDPR). In the statistics category, Umami is currently active — a cookieless service that neither sets cookies nor stores identifiers on your device (details in section 10), which is why the table below contains no statistics entry. No service is active in the marketing category. Should that change, we will update this policy and the table before the service is loaded.

You can adjust or withdraw your consent at any time, with effect for the future, via the .

NameProviderPurposeLifetimeCategory
atelier_sessionBurghardt.design (first party)Keeps you signed in (session token). httpOnly, secure, sameSite=lax — not readable by scripts, sent only over HTTPS, protected against cross-site requests.12 hoursNecessary
NEXT_LOCALEBurghardt.design (first party)Remembers your language choice (German/English) so the site opens in the language you picked.12 monthsNecessary

We also use your browser's local storage: “atelier-cookie-consent-v1” records your cookie choice, “atelier-brief-draft-v1” protects a brief you have started against accidental loss (never passwords). These entries stay in your browser, are not transmitted to us and can be deleted at any time via your browser settings.

7. Contacting us

If you contact us by email, phone or through a form, we process the details you provide — name, contact details and the content of your enquiry — to handle your request and in case of follow-up questions. The legal basis is Art. 6 (1)(b) GDPR for contract-related enquiries, otherwise Art. 6 (1)(f) GDPR in effective handling.

Email sent to our Outlook address is received and stored via Microsoft Ireland Operations Ltd. We delete enquiries once they have been dealt with conclusively and no statutory retention periods apply.

8. Account, sign-in and brief

When you create an account or submit a brief, we store the data you provide: your email address, your password solely as a cryptographic hash (bcrypt — never in plain text), the time of registration, and all details from your brief (including company, industry, goals, scope, style, budget, timeline, name, email address and optionally phone number).

The purpose is to handle your request, produce a quote or draft and manage your project. The legal basis is Art. 6 (1)(b) GDPR.

To protect against abuse — brute-force attacks or spam — we additionally process your IP address for a short time as the key of a rate limit, along with the number of failed sign-in attempts. The legal basis is Art. 6 (1)(f) GDPR; this data is held in memory only and expires automatically after a short period.

You can have your account deleted at any time — an informal email is enough. We then delete the account and the associated briefs, unless statutory retention obligations prevent this.

9. Transactional email

To confirm your email address and for project-related notifications we send email via the service provider Resend, Inc. (2261 Market Street, San Francisco, CA 94114, USA). Your email address and the content of the message are transmitted to the provider and processed there for delivery.

The legal basis is Art. 6 (1)(b) GDPR for contract-related messages, otherwise Art. 6 (1)(f) GDPR. A data processing agreement is in place with the provider; the transfer to the USA is covered by the European Commission's standard contractual clauses.

10. Web analytics and reach measurement

We use analytics or reach-measurement services only if you have previously consented to the “Statistics” category (§ 25 (1) TDDDG, Art. 6 (1)(a) GDPR). Without consent no such service is loaded; no corresponding cookies are set and no identifiers are read from your device.

We use Umami, a web analytics service provided by Umami Software, Inc. (28 Geary St, Suite 650 #243, San Francisco, CA 94108, USA). Umami is cookieless: it sets no cookies and stores or reads no identifiers on your device. It processes the pages you view, the referrer URL, approximate origin at country level, device type, browser and operating system. Your IP address is used solely to derive that information and is not stored; no cross-device profile is created.

The legal basis is your consent (Art. 6 (1)(a) GDPR). Our account is set to the EU (Germany) data region, and the data collected is stored there. As the provider is based in the USA and access from there cannot be entirely ruled out, such access is safeguarded by the European Commission's standard contractual clauses (see section 16). An Art. 28 GDPR data processing agreement is in place with the provider. You can withdraw your consent at any time with effect for the future via the cookie settings, and the service is unloaded immediately.

11. Marketing, retargeting and conversion measurement

Advertising technologies — such as ad pixels, conversion tracking, retargeting or audience building — are used only with your consent to the “Marketing” category (§ 25 (1) TDDDG, Art. 6 (1)(a) GDPR).

Such services may use cookies or similar identifiers to record your use of this website and, where applicable, of other websites across devices, to measure advertising performance and to show you interest-based advertising. This may involve profiling. We will name the provider, purpose, retention period and any third-country transfer in this policy before such a service goes live.

At the time of the last update of this policy, no marketing or tracking service is active. You can withdraw your consent at any time via the cookie settings.

12. Newsletter and email marketing

If you subscribe to our newsletter, we process your email address and voluntary details such as your name in order to send you editorial information and offers. Sending starts only after you have verified your subscription via a confirmation link (double opt-in).

For evidence purposes we log the time of subscription and confirmation and the IP address used. The legal basis is your consent under Art. 6 (1)(a) GDPR; towards existing customers, advertising for our own similar services may additionally be based on § 7 (3) UWG.

Newsletters may include performance measurement recording whether a message was opened and which links were clicked, so that we can improve the content. Where such measurement is used it is covered by your consent, and you can object at any time by unsubscribing.

You can unsubscribe at any time via the link in every email or by an informal message to us. After unsubscribing we delete your data from the distribution list; the subscription logs are kept as evidence for as long as claims can be brought against us. Any sending service provider is listed in section 15.

At the time of the last update of this policy, we do not send a newsletter.

13. Embedded content, fonts and maps

Fonts are served from our own server. No connection is made to Google Fonts or comparable font services.

Third-party content — videos, maps, booking widgets or scripts from content delivery networks — is embedded only with your consent. Loading such content necessarily discloses your IP address to the respective provider and may set cookies. We mark such content before it loads and name the provider in this policy before it is used.

14. Social media presences

This website embeds no social media plugins that transmit data to a network merely because you open a page. Links to profiles take you to the respective provider only after you click.

Where we operate profiles on social networks, the privacy policies and terms of the respective provider additionally apply, and we have only limited influence on their processing. Data you send us there — comments or messages — is processed to communicate with you on the basis of Art. 6 (1)(f) GDPR.

15. Recipients and processors

We pass personal data only to carefully selected service providers who act on our instructions and with whom we have concluded data processing agreements under Art. 28 GDPR. These are currently:

ServiceProvider & locationPurposeBasis
HostingDigitalOcean, LLC, Broomfield, CO, USA — server in Frankfurt am Main, GermanyOperating and serving the website, server log filesArt. 28 GDPR (DPA), standard contractual clauses
Domain, DNS & mail routingunited-domains GmbH, Starnberg, GermanyDomain availability and mail deliveryArt. 28 GDPR (DPA)
Transactional emailResend, Inc., San Francisco, CA, USASending confirmation and notification emailsArt. 28 GDPR (DPA), standard contractual clauses
Web analyticsUmami Software, Inc., San Francisco, CA, USA — EU (Germany) data regionCookieless reach measurement — only after consentArt. 28 GDPR (DPA), standard contractual clauses
MailboxMicrosoft Ireland Operations Ltd., Dublin, IrelandReceiving and storing messages sent to our contact addressArt. 6 (1)(f) GDPR

Beyond that, we transmit data to our tax advisor, bank or public authorities where this is necessary to perform a contract or to meet legal obligations.

16. Transfers to third countries

Some of the providers used are established in, or have group ties to, the USA. Personal data is transferred to a third country only where the requirements of Art. 44 et seq. GDPR are met — in particular on the basis of an adequacy decision (such as the EU-US Data Privacy Framework, where the provider is certified) or the European Commission's standard contractual clauses together with supplementary safeguards.

Please note that in third countries a level of data protection equivalent to European law cannot be guaranteed and that authorities there may be able to access data.

17. Retention periods

We store personal data only for as long as is necessary for the respective purpose. Specifically: server log files for at most 14 days, the session cookie for 12 hours, email confirmation links for 24 hours, account and brief data until you delete your account.

After that we delete the data unless statutory retention obligations apply: commercial letters must be kept for six years and accounting records for ten years (§ 257 HGB, § 147 AO). For that period, processing is restricted — the data is blocked and no longer used for other purposes.

For resilience, our host creates encrypted backup copies of the server daily, which are automatically overwritten after no more than seven days. If you delete your data it disappears from live operation immediately and from the backups at the latest when that period expires. Backups are used solely to restore service after a failure.

18. Your rights

You have, at any time, the right of access to the data we hold about you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and the right to object under Art. 21 GDPR.

You may withdraw consent at any time under Art. 7 (3) GDPR; this does not affect the lawfulness of processing carried out beforehand. An informal message to info@burghardt.design is enough to exercise your rights.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.

19. Right to object under Art. 21 GDPR

Where we process data on the basis of Art. 6 (1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to that processing. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where your data is processed for direct marketing, you may object at any time and without giving reasons. After your objection we will no longer use it for that purpose. An informal email to info@burghardt.design is sufficient.

20. Data security

This website is served exclusively over an encrypted TLS connection (HTTPS); you can recognise the encryption by the padlock in your browser's address bar. In addition we use HSTS and a strict Content Security Policy to make manipulation harder.

Passwords are stored only as a bcrypt hash, and session and confirmation tokens only as a SHA-256 hash — so neither a password nor a usable token can be reconstructed from our database. Access to the database is limited to the operator; systems and dependencies are updated regularly.

21. No automated decision-making

Decisions based solely on automated processing, including profiling within the meaning of Art. 22 GDPR, do not take place.

22. Minors

Our services are aimed at businesses and at adults. People under the age of 16 should not send us personal data without the consent of a parent or guardian.

23. Changes to this privacy policy

We adapt this policy whenever the legal situation, our services or our data processing change — for example when an analytics, marketing or newsletter service is activated. The version published here at the time of your visit applies.