Pageartist
  • Packages
  • Services
  • Hosting
  • Work
  • Blog
  • Contact
0214 / 86097937 DE Start a project
PackagesServicesHostingWorkBlogContact DE · Auf Deutsch ansehen → 0214 / 86097937 Start a project
Legal

Privacy policy.

This website processes as little personal data as possible. No advertising cookies, no selling of data. Traffic measurement runs anonymously on our own server, without cookies and without storing IP addresses. Beyond that we ask you once whether we may analyse how you use the site — say no and nothing at all happens. The legally binding version is the German one; this English translation is for convenience only.

Data controller

Daniel Piculjan, Pageartist, Leverkusen, Germany. Contact: info@pageartist.de · 0214 / 86097937. Full address in the legal notice.

Cookies and similar technologies

Without your consent we only set strictly necessary cookies required to operate this website (Section 25 (2) TDDDG, Art. 6 (1)(f) GDPR). No marketing or advertising cookies run here — neither with nor without consent.

Without consent, strictly necessary:

  • cf_clearance — Cloudflare Turnstile, spam and bot protection on the contact form. Lifetime: session. Provider: Cloudflare, Inc.
  • pa-consent — stores in your browser's local storage how you answered the analytics prompt. Without it we would have to ask again on every page view. It contains only your answer and a timestamp, no identifier. Lifetime: until you delete it.

Only after your explicit consent (see the "Behavioural analytics" section below):

  • ph_<id>_posthog and the related entries …_posthog_cpm and …_posthog__flags — cookies and local storage, set by PostHog. They contain a randomly generated device identifier, the current session ID, the origin of the visit, and the scroll progress on the page. Lifetime: 12 months. Provider: PostHog, Inc.
  • __ph_opt_in_out_<id> — records that consent was granted or withdrawn. Lifetime: 12 months.

Hosting

The website is hosted in Germany (Hetzner Online GmbH, Gunzenhausen). Static files are served by the web server without database-backed profiling. The host processes only technically necessary server logs (IP address, timestamp, requested URL, user agent) on the basis of Art. 6 (1)(f) GDPR for the legitimate interest in stable operation and attack prevention. Logs are deleted after 14 days, are not analyzed for traffic measurement, and are not combined with other data.

Fonts

The Geist and Geist Mono fonts are served directly from our server in Germany. No connection is established to Google Fonts or any other external font service — your IP address is not transmitted to any third party when loading the fonts.

Traffic measurement (Umami)

We use Umami, an open-source, privacy-friendly analytics tool, to see how often pages are viewed and from which sources visitors arrive. Umami runs on our own server within the EU (analytics.adriahub.de) — the data does not leave our infrastructure. No data is transmitted to third parties, and in particular no data is transferred to the United States.

Umami operates without cookies and without persistent recognition: your IP address is used only briefly to identify a visitor's path within a single day (hashed with a daily-rotating salt) and is not stored in the database. Only aggregated metrics are collected, such as page viewed, approximate location (country, region and city — derived from the IP, which itself is not stored; accuracy is typically at the ISP-node level and does not reflect the actual location), browser, and screen resolution. Tracking across days or across websites is technically impossible.

Legal basis: Art. 6 (1)(f) GDPR — legitimate interest in privacy-friendly traffic measurement to improve the site. Because no personal profile is created and no cookies are set, no consent is required under the position of the German Data Protection Conference (DSK). We respect the Do-Not-Track signal of your browser — if enabled there, no measurement takes place. You can additionally block the tracker via browser extensions; the site remains fully functional.

Behavioural analytics (PostHog) — only with your consent

Umami tells us that a page was viewed, but not how it is used. To understand where visitors get stuck, which buttons go unnoticed, and at what point someone leaves, we additionally use PostHog — only if you have explicitly agreed via the prompt at the edge of the page. Without your consent not a single record is sent to PostHog, and the PostHog script is never even loaded.

With your consent we collect:

  • Click and scroll behaviour ("heatmaps"): where on a page people click and how far they scroll — aggregated across all visitors.
  • Whether the contact form was submitted successfully, or what kind of error a failed attempt ran into. Only the fact that it worked, or the category of failure (such as bot protection or a server error), is recorded — never the content of the fields and never the verbatim error message.
  • Session recordings ("session replay"): a reconstruction of your visit from which mouse movement, clicks, scrolling, and page changes can be followed. This is not a video recording of your screen but a recording of the changes made to the page.
  • Pages viewed, time on page, origin of the visit, browser, operating system, screen size, and approximate location — country, region, city, and postcode area, derived from the IP address, which is not itself stored alongside it. Accuracy is typically at the level of an ISP node and does not correspond to your actual whereabouts.

What we deliberately do not collect: all input fields are masked in the recordings. What you type into the contact form — name, email address, message — appears in no recording. There is no user account on this site; we transmit no name, no email address, and nothing else to PostHog by which a person could be named. PostHog does, however, group the captured events under the randomly generated device identifier into a record holding technical attributes (browser, operating system, approximate location, origin of the visit). Your IP address is anonymised by PostHog and not stored alongside it.

Provider and storage location: PostHog, Inc., 2261 Market Street, San Francisco, CA 94114, USA. We use PostHog's EU Cloud exclusively; data is stored and processed in a data centre in Frankfurt am Main, Germany. PostHog acts as our processor under Art. 28 GDPR. Access from the US by support and maintenance staff cannot be entirely ruled out; it is covered by the EU Commission's Standard Contractual Clauses. Retention: session recordings are deleted automatically after 30 days; that period is configured in the project and enforced by PostHog. For all other event data, retention follows the subscribed plan, where 12 months are configured. Automatic deletion at that point is not currently enforced, however, so the data may also persist for longer. We therefore deliberately give no fixed deletion deadline for this event data. On request we delete the data held about you at any time.

Legal basis: Art. 6 (1)(a) GDPR (consent) and Section 25 (1) TDDDG for storing the identifier on your device. Consent is voluntary; the website works exactly the same without it.

Withdrawal: you can change your decision at any time with effect for the future. This does not affect the lawfulness of processing carried out until then.

If Do Not Track or Global Privacy Control is enabled in your browser, we treat that as an objection: you are not asked in the first place and PostHog stays off.

Contact form

When you use our contact form, the following data is transmitted:

  • Name
  • Email address
  • Message content
  • Acknowledgment that this privacy policy has been read

This data is processed on a server in Germany, sent to us by email and additionally stored locally on the same server so requests can be reliably tracked. The data is not shared with third parties. Legal basis: Art. 6 (1)(b) GDPR (pre-contractual measures) and/or (1)(a) (consent via the mandatory checkbox). Providing this data is voluntary; without it, however, we cannot process your request.

Storage period: until the request is resolved plus a reasonable follow-up period (typically 12 months). You can request deletion at any time by email.

Cloudflare Turnstile

We use Cloudflare Turnstile as spam protection on the contact form. Turnstile checks in the background whether the request comes from a human, without showing classic CAPTCHAs; for this it establishes a connection to challenges.cloudflare.com. Cloudflare processes limited technical browser data (user agent, IP address, telemetry for bot detection). Legal basis: Art. 6 (1)(f) GDPR — protection against automated abuse. Cloudflare is certified under the EU-US Data Privacy Framework.

SSL/TLS encryption

This website uses TLS (HTTPS) throughout. Content and form submissions are protected from being read by third parties.

Your rights

You have the right at any time to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21). You also have the right to file a complaint with the competent supervisory authority — in NRW: the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, ldi.nrw.de.

Changes to this policy

We update this privacy policy whenever functionality or applicable law changes. Last updated: September 2026.

Pageartist
© 2026 page artist · Leverkusen Legal notice · Privacy policy · Cookie settings

A quick question about statistics

We would like to see how this site is actually used — where people click, how far they scroll, where they get stuck. That needs storage on your device and records your interactions with the page. Text you type into forms is never recorded. Details in the privacy policy.