PRIVACY
What this site does with your data — derived from the code that does it, not from a template.
01Note on this translation
This is a courtesy translation. The German version is the legally binding one — see /impressum and /datenschutz.
02Controller
The controller for processing under the GDPR is:
- Name
- Kevin Feiler Einzelunternehmen, trading under the brand energetiq
- Owner
- Kevin Feiler
- Address
- Talstr. 19, 71229 Leonberg, Germany
- info@energetiq.eu
- Phone
- +49 711 25267505
03The short version
- There are no analytics, advertising or tracking services. That is also why there is no consent banner: there would be nothing to consent to.
- There is exactly one cookie, and it only comes into being when you sign in.
- The fonts are served from this server. Loading the page sends no request to Google.
- The database runs on a second machine operated by the same person. The two machines are linked by an encrypted direct connection; the database has no publicly reachable port. Your details are not handed to a database provider.
- Without placing an order and without signing in, you leave nothing here that could be attributed to you.
04Visiting the site
The site sits behind Cloudflare's network. To establish the connection, Cloudflare processes technical connection data — including your IP address, date and time, the address requested and details of your browser. This is the same process that takes place whenever an encrypted website is opened; without it the site could not be delivered.
The legal basis is my legitimate interest in a secure and available service, Article 6 (1) (f) GDPR. Cloudflare is based in the USA; the transfer relies on the European Commission's standard contractual clauses.
The server that delivers the site writes an access log without IP addresses. It records the time, the address requested, the response code, the size of the response and what your browser states about itself. It cannot be traced back to a person. Connection data including IP addresses arises at Cloudflare and is subject to their retention periods.
05Enquiry and account
When you submit an order through the enquiry form, I process the details you enter:
- Name and e-mail address — required, because otherwise I can neither attribute nor answer your enquiry.
- Company and phone number — optional.
- Your password — only ever as a scrypt hash with a random salt. The word itself is stored nowhere and cannot be recovered from the hash. I cannot read it either.
- Your description of the project, plus the chosen package, payment method and add-ons.
06Purpose and legal basis
One enquiry creates three things at once: an account, the order and a case with the first message. That is deliberate — it gives you a place where the status is visible from the start, instead of waiting for an e-mail.
The legal basis is Article 6 (1) (b) GDPR: the processing serves the initiation and performance of a contract. The consent you give in the form sits alongside it and can be withdrawn at any time with future effect.
Your details are not used for advertising, not analysed and not passed on.
07Cases and messages
Inside the customer area we continue the conversation in writing. The messages, their time and their author are stored.
Internal notes on a case are not visible to you. Your right of access under Article 15 GDPR covers them nonetheless — ask, and you will receive them.
08The one cookie
It comes into being when you sign in and disappears when you sign out. A cookie that carries a sign-in needs no consent — it is strictly necessary for the service you explicitly requested, § 25 (2) no. 2 TDDDG.
This site sets no other cookies.
- Name
- ddev_neu_sitzung
- Purpose
- Keeps you signed in
- Content
- Your account ID and an expiry date, signed
- Lifetime
- 30 days
- Readable by JavaScript
- no (httpOnly)
09Protection against mass requests
So that nobody can flood the enquiry form or the sign-in with attempts, the application counts attempts per sender. For that it needs a feature that distinguishes senders — and that feature is deliberately not your IP address.
The address is passed through a hash function together with a random value generated when the application starts and stored nowhere. Only the hash is kept, in memory, and after a restart it can no longer be matched to any address. The legal basis is Article 6 (1) (f) GDPR.
10Fonts and embedded services
The site uses the typefaces Archivo and JetBrains Mono. Both are downloaded when the application is built and served from this server. Your browser makes no connection to Google — not to fonts.gstatic.com either.
There are no maps, video players, social media buttons, chat services or third-party font services embedded. There are no tracking pixels and no ad networks.
11System monitoring
For systems under my care, the application calls their status address at intervals and records the result: reachable, degraded or down, together with the response time. These checks concern servers, not people; no personal data arises from them.
The check log expires automatically after 30 days.
12Recipients
Should anyone else become involved in order to fulfil a contract, you will be told beforehand.
- Cloudflare, Inc. — the network in front of the site and connection encryption. Without it the site would not be reachable.
- ‹Server provider› — the machine the site runs on. The provider can technically reach the data but processes it only in order to operate the machine.
- Nobody else. There is no newsletter service, no CRM and no external database provider.
13AI tools in development
This site and the software behind it were built with an AI tool — specifically Claude Code by Anthropic. That is stated here not as a confession but because it is the reason for both the speed and the price, and because it can be checked anyway: the work log shows the measured consumption.
What that looks like in practice: a person sits alongside and decides what gets built, reviews what comes out, and answers for what goes live. The AI writes the code. It does not decide how a business appears online, and it releases nothing.
This concerns only how the code comes into being, not how it runs. The live application sends nothing to an AI service, and in your cases — enquiry, order, account, credit — no automated process decides anything about you.
The work happens on source code, not on your data. ‹If content from the database is ever to reach an AI tool during debugging, it belongs here explicitly — with provider, purpose and legal basis. If that does not happen, delete this sentence.›
14Retention
- Account, orders and cases: for as long as the account exists. They are deleted on your request.
- Where a contract comes about, the commercial and tax retention periods apply to the associated records. They take precedence over a deletion request, but only for those records and only for the duration of the period.
- Monitoring check log: 30 days, then automatically.
15Your rights
You have the right of access (Article 15), rectification (16), erasure (17), restriction of processing (18), data portability (20) and objection to processing based on legitimate interests (21). Consent once given can be withdrawn at any time with future effect.
An informal message to info@energetiq.eu is enough. Access and erasure are granted without follow-up questions.
You may also lodge a complaint with a data protection supervisory authority. Competent is the authority at my place of business — the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (baden-wuerttemberg.datenschutz.de) — or the authority where you live.
16No automated decision-making
There is no automated decision-making and no profiling within the meaning of Article 22 GDPR. I decide on your enquiry, not a procedure.
17Changes
When what the application does changes, this statement changes with it. The date above says which version is in force.
Stand: 11.08.2026