Privacy Policy

Information on the processing of personal data on this website, pursuant to Art. 13 GDPR (DSGVO) and German TDDDG. Plain language — no dark patterns.

Document
Privacy Policy / Datenschutzerklärung
Basis
Art. 13 GDPR · § 25 TDDDG
Jurisdiction
Germany · EU
Last update
2026-05-24
§ 1

Controller // Art. 4 No. 7 GDPR · data controller

The controller responsible for the processing of personal data on this website is:

// controller.identityactive
Name
Andreas Riesener
Address
Britzer Str. 10
12439 Berlin
Email
mail@andreasriesener.com
Phone
+49 176 21317712

A separate Data Protection Officer (DPO) is not required and has not been appointed (§ 38 BDSG).

§ 2

Scope & principles // data minimization · Art. 5 GDPR

This website is a personal portfolio. It does not run a shop, a booking flow, a member area, a comments section, or any paid feature. There is no sign-up and no payment.

Personal data is only processed where it is technically unavoidable (server access logs) or where you actively initiate it yourself (sending an email). All data processing follows the principles of data minimization and purpose limitation set out in Art. 5 GDPR.

§ 3

Server log files // Art. 6 (1)(f) GDPR · legitimate interest

When you visit this website, my hosting provider STRATO automatically collects information that your browser transmits to the server, and stores it in so-called server log files. The following data is recorded:

// log.fields
IP address
processed during the request; retained by STRATO for max. 7 days for attack defence, then deleted
Timestamp
date & time of the request
Request
URL, HTTP method, status code, bytes transferred
Referrer
previously visited page (if transmitted)
User-Agent
browser type, version, operating system

Legal basis: Art. 6 (1)(f) GDPR. The legitimate interest is to ensure the security and stability of the site, troubleshoot errors, and defend against abuse.

Retention: Raw IP addresses are kept by STRATO for a maximum of 7 days for attack detection and defence; afterwards they are deleted. Depending on the hosting package, log files may also be accessible to me via the STRATO Kunden-Login for the same period.

The data is not merged with any other data sources and is not used to identify visitors.

§ 4

Contact by email // Art. 6 (1)(b) & (f) GDPR

This site provides only a mailto: link — there is no on-page contact form. If you send an email to mail@andreasriesener.com, your message and the data it contains (name, email address, message body, any attachments) is transmitted to my email provider and stored there in order to process your request.

Legal basis: Art. 6 (1)(b) GDPR if the contact is related to a (potential) contract; otherwise Art. 6 (1)(f) GDPR for the legitimate interest of replying to inbound business correspondence.

Retention: Correspondence is retained for as long as the business relationship requires, and afterwards in accordance with statutory retention obligations (§ 147 AO, § 257 HGB — up to 10 years for tax-relevant correspondence).

No contact form is currently deployed. If one is added later, this section will be updated to disclose the form fields, the backend processor, any anti-spam measures (honeypot, not reCAPTCHA), and IP-logging behaviour.
§ 5

Self-hosted fonts // no Google Fonts, no external font CDN

All fonts used on this website are served from the same origin as the site itself, as locally bundled .woff2 files via @font-face. No request is made to fonts.googleapis.com, fonts.gstatic.com, or any other third-party font CDN.

This means: no external party receives your IP address simply for the purpose of loading a typeface.

§ 6

Outbound links // social platforms · Vimeo showreel

This website links to external profiles (Vimeo, Behance, LinkedIn, YouTube, X / Twitter). These are plain text links — no social-plugin scripts, no share buttons, no pixel, no Insight Tag. No data is transmitted to those platforms unless you actively click a link and navigate to them.

The “Play Showreel” button on the homepage opens an embedded Vimeo player in a modal overlay — but only after you actively click it. No Vimeo request is made on the initial page visit. When you trigger the player, it loads from player.vimeo.com with Vimeo’s Do-Not-Track parameter (?dnt=1) enabled, which disables analytics and audience tracking for that playback. Vimeo will still receive standard request data (IP address, User-Agent, referrer) for the duration of the playback session — this is unavoidable for any video stream. For details, see Vimeo’s privacy policy.

I have no influence over the data handling of these third-party platforms once you click through to them.

§ 7

Processors // Art. 28 GDPR · AVV / DPA partners

The following processor handles personal data on my behalf within the meaning of Art. 28 GDPR. A separate Auftragsverarbeitungsvertrag (AVV) is currently being concluded via the STRATO Kunden-Login.

// processor.01 — hosting & email providerEU · AVV pending
RoleWeb hosting, file storage, inbound / outbound mail ProviderSTRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin LocationGermany / EU DataServer log files (see § 3), file delivery, email correspondence (see § 4) CertificationISO 27001 (TÜV) · data centres in Berlin and Karlsruhe AVVIn conclusion via STRATO Kunden-Login (Art. 28 GDPR)
§ 8

Your rights // Art. 15 – 21 GDPR

You have the following rights with respect to your personal data:

// data-subject.rights
  • Art. 15Accessconfirmation & copy
  • Art. 16Rectificationcorrect inaccurate data
  • Art. 17Erasure"right to be forgotten"
  • Art. 18Restrictionlimit processing
  • Art. 20Portabilitymachine-readable export
  • Art. 21Objectionstop legitimate-interest use

To exercise any of these rights, please contact me via email (mail@andreasriesener.com). I will respond without undue delay and at the latest within one month.

§ 9

Right to lodge a complaint // Art. 77 GDPR

You have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your personal data violates the GDPR. The supervisory authority responsible for me is:

// supervisory.authority
Authority
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Address
Alt-Moabit 59-61, 10555 Berlin
Web
datenschutz-berlin.de
§ 10

Retention periods // per data category

Personal data is only stored for as long as is necessary for the respective purpose or as long as statutory retention obligations require:

// retention.matrix
Server logs
max. 7 days at STRATO (raw IPs), then deleted · § 3
Email correspondence
duration of business need; up to 6 / 10 years for tax-relevant mail (§ 147 AO)
Contract data
up to 10 years (§ 257 HGB, § 147 AO)
Marketing data
n/a — no marketing data is collected
Tracking data
n/a — none collected
§ 11

Changes to this policy // versioning

I may update this Privacy Policy to reflect changes in technical practices or in the legal framework. The current version is always the one published on this page; the date of the last update is shown at the top of this document.

// end-of-document · governed by German law · v1.0