/privacy
Privacy policy
In short: this website sets no cookies, uses no tracking and loads no third-party content. We only process what you send us yourself, and only for as long as necessary.
This is a courtesy translation. The German Datenschutzerklärung is legally binding.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Felix Wodlei
Cloudlei
Kolonnenstr. 8
10827 Berlin
Germany
E-mail: datenschutz@cloudlei.de
No data protection officer has been appointed because the legal requirements for one (Art. 37 GDPR, § 38 BDSG) are not met. For any privacy question, write to us at the address above.
2. Overview
- No cookies, no local storage: we store nothing on your device and read nothing from it. That is why there is no cookie banner.
- No tracking, no analytics: we use no analytics, advertising or social media tools.
- No third parties when pages load: fonts, graphics and scripts are served from our own server. No data is sent to Google or any other service when you load a page.
- What we process: technically necessary access data (section 3) and whatever you send us through the contact form, by e-mail or when booking a call (sections 5 and 6).
3. Hosting and access data
This website is delivered through Cloudflare Pages, provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. On every request Cloudflare processes technically necessary data: IP address, date and time, requested address, amount of data transferred, referrer, browser and operating system. This data is needed to deliver the website, secure the connection and fend off attacks. We do not analyse it ourselves or combine it with other data.
The legal basis is our legitimate interest in a secure, fast and stable website (Art. 6 (1) (f) GDPR). A data processing agreement under Art. 28 GDPR is in place with Cloudflare. Cloudflare is certified under the EU-US Data Privacy Framework, so transfers to the USA are covered by an adequacy decision of the European Commission (Art. 45 GDPR); EU standard contractual clauses apply in addition. Cloudflare keeps access data only briefly, according to its own policies.
4. Encryption
The entire website is served exclusively over encrypted HTTPS (TLS), so data you send through forms cannot be read by third parties in transit.
5. Contact form and e-mail
When you write to us through the contact form or by e-mail, we process your details: name, e-mail address, optionally company, the selected topic and your message. We use them solely to answer your enquiry and, where applicable, to prepare an offer.
The legal basis is Art. 6 (1) (b) GDPR where your enquiry aims at a contract, otherwise our legitimate interest in answering enquiries (Art. 6 (1) (f) GDPR). Form messages are delivered to our inbox through the e-mail service Postmark, provided by AC PM LLC (ActiveCampaign), 1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA, acting as a processor under Art. 28 GDPR on servers in the USA. The transfer is based on the EU standard contractual clauses (Art. 46 (2) (c) GDPR); ActiveCampaign is also certified under the EU-US Data Privacy Framework (Art. 45 GDPR). Open and link tracking are switched off.
We delete your enquiry once it has been dealt with, at the latest after six months. If an engagement results, we keep business correspondence for as long as commercial and tax law requires (§ 257 HGB, § 147 AO, up to ten years).
To keep bots out, the form contains a field that is invisible to people. If it is filled in, we discard the message.
6. Booking a call
On the contact page you can book a first call through our own booking calendar. No external booking service is involved. Available times are loaded from our server without storing any personal data.
When you book, we process: the selected time, name, e-mail address, optionally company and message, and the selected language. To prevent abuse, such as blocking many slots at once, we also store a hash of your IP address. The hash is formed together with the current date; we do not store the IP address itself.
Booking data is kept in a Cloudflare database (Cloudflare D1) contractually restricted to the European Union. Confirmations to you and to us are sent through Postmark (see section 5) and contain a calendar entry and a link to cancel the call at any time. The "Google" and "Outlook" buttons open that calendar service with the appointment details; only with this click do Google or Microsoft receive them, and their privacy policies apply.
The legal basis is Art. 6 (1) (b) GDPR (arranging and holding the appointment). The abuse protection is based on our legitimate interest in a working calendar (Art. 6 (1) (f) GDPR). We delete the booking automatically 30 days after the appointment, or immediately if you cancel. If an engagement results, section 5 applies accordingly.
7. Fonts
This website uses the typefaces Atkinson Hyperlegible Next and Atkinson Hyperlegible Mono. They are served from our own server; no connection to Google Fonts or any other provider is made.
8. External links
Links to other websites, such as LinkedIn, are plain links. No data is sent to these providers when our pages load. Their privacy policies apply only once you follow a link.
9. Recipients and third countries
Apart from us, only the processors named above receive your data: Cloudflare (sections 3 and 6) and Postmark (sections 5 and 6). We do not sell data or pass it on for advertising. Transfers to the USA take place only as described in sections 3 and 5 and on the bases named there.
10. Obligation to provide data and automated decisions
You are under no legal or contractual obligation to provide data. Without a name and e-mail address, however, we cannot handle your enquiry or booking. There is no automated decision-making, including profiling (Art. 22 GDPR).
11. Your rights
You have the right at any time to:
- access the data we hold about you (Art. 15 GDPR),
- have inaccurate data rectified (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdraw consent with effect for the future (Art. 7 (3) GDPR).
Right to object: where we process data based on legitimate interests (Art. 6 (1) (f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds.
For any of this, just write to datenschutz@cloudlei.de.
12. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany
www.datenschutz-berlin.de
13. Changes
We update this policy when the website or the law changes. The version published here applies.
Last updated: October 2026