Privacy Policy
Last updated: 8 April 2026 (update when you change this document)
Language note
This English text is a non-binding convenience translation only. For this German provider, the German Datenschutzerklärung (privacy policy) is legally authoritative. Please select “DE” in the language switcher above to read it.
This privacy policy applies to the website served under this domain and built with Next.js. It describes which personal data may be processed given the functionality implemented in the current source code.
It builds on 01art’s previous privacy notice but has been updated to match this application’s technical implementation.
Controller
The controller responsible for processing personal data on this website within the meaning of the GDPR is:
[PLACEHOLDER: company name / legal form]
[PLACEHOLDER: street and number]
[PLACEHOLDER: postal code and city]
Email: diego@01art.de
Note: Replace placeholders with your real company details. The email address matches the contact address used in the project for mailto links.
General information on processing
Personal data means any information relating to an identified or identifiable natural person (e.g. name, email address, IP address).
We only process personal data to the extent necessary to operate this website, provide our services, pursue legitimate interests, where you have given consent, or where another legal basis under the GDPR applies.
Unless stated otherwise below, you are not legally or contractually required to provide personal data.
Hosting and server log files
The site is hosted on servers of a hosting provider. Server log files are created. The provider may process access data (e.g. requested resource, date and time, data volume, IP address in truncated or full form depending on configuration, user agent, referrer).
[PLACEHOLDER: hosting provider name and address; DPA documentation if applicable]
Processing serves the secure, stable operation of the site (security, stability, abuse prevention) and is based on Art. 6(1)(f) GDPR (legitimate interests). Where necessary for performing a contract, Art. 6(1)(b) GDPR may apply.
This application is a Next.js app; depending on configuration, requests may be routed via an edge/CDN network — refer to your provider’s documentation.
Fonts (Manrope, Sora) are loaded via Next.js “next/font/google”: font files are fetched at build time and served from the same site, so visitors’ browsers do not open a separate connection to Google servers to download the webfonts on each page view.
Contact by email and mailto contact forms
The site uses mailto links and short forms on the home page and on the “/landing” and “/ads” routes.
No server-side processing by this website: form data are not sent to a server operated for this site and are not processed or temporarily stored there. There is no server-side form endpoint and no storage of form contents in a database or similar storage on this project’s web server.
Sending via your email client: name, email and message are assembled in the browser. Submitting usually opens your email program (desktop client, webmail or app) with a prefilled message (mailto). The email is sent by you through your mail client and your email provider — not through a server-side send function on this website.
Storage: this website does not permanently store form contents. Data are stored on our side only once the message arrives in the recipient’s mailbox and remains there (including any usual backups or archiving in the recipient’s email system). Until then, data exist only on your device or in your mail program if it keeps local drafts or similar.
If you email us directly, we process the data you send (at least your email address, and any name or other content) to handle your request.
Legal basis: Art. 6(1)(b) GDPR for (pre-)contractual requests; otherwise Art. 6(1)(f) GDPR (responding to enquiries). Where consent is required and obtained, Art. 6(1)(a) GDPR.
Retention: data from mailto forms are not kept on this website; on our side they exist only in the recipient’s mailbox as part of normal email handling. Data are deleted when no longer needed, subject to statutory retention duties.
Legal bases (overview)
Depending on the situation, including:
Art. 6(1)(a) GDPR (consent) where you have explicitly consented.
Art. 6(1)(b) GDPR (contract / pre-contractual steps) where processing is necessary to enter into or perform a contract.
Art. 6(1)(f) GDPR (legitimate interests) where processing is necessary to run the site, maintain IT security, or handle enquiries and your interests do not override ours.
Retention
We keep personal data only as long as needed for the purpose or as required by law.
Server logs are deleted or anonymised after a rotation period defined by the hosting provider ([PLACEHOLDER: provider details]).
Email correspondence may be subject to commercial/tax retention periods where applicable.
Google Analytics (Google Tag / gtag) — only if enabled
A “GoogleAnalytics” component is included. It loads Google Analytics / gtag scripts only when NEXT_PUBLIC_GA_ID is set and you have opted in to statistics in the cookie banner. Without the variable or without consent, no analytics scripts are loaded.
When NEXT_PUBLIC_GA_ID is set, a script is loaded from “www.googletagmanager.com” and initialised with your measurement ID (GA4 / gtag). Google may use cookies or similar technologies and process data such as pages viewed, events, device/browser information and shortened IP addresses. See Google’s privacy policy: https://policies.google.com/privacy
The file “lib/gtag.ts” defines helpers for events (e.g. mailto CTA clicks, lead form submits on “/landing” and “/ads”). Events are sent only if statistics consent is active and “gtag” is loaded.
Legal basis: for GA-style analytics, consent under Art. 6(1)(a) GDPR together with § 25 TTDSG is typically required. Consent is obtained via the cookie banner and cookie settings; without consent, analytics scripts are not loaded.
IP addresses and anonymisation: When Google Analytics is used, connection data and IP addresses may be processed in particular. Depending on the product generation (e.g. Google Analytics 4) and the privacy options offered by Google and selectable in the relevant Google account, IP addresses may be truncated or anonymised (in older Universal Analytics configurations, a setting such as “anonymizeIp” is commonly referred to; for GA4, see Google’s current documentation). We do not know which settings are active in the controller’s account; the controller must configure this in their Google account.
Processor agreement: Where Google Analytics is used as processing on behalf of the controller within the meaning of Art. 28 GDPR, the controller may conclude a data processing agreement with Google. Google provides, among other things, the “Google Ads Data Processing Terms” or comparable terms for Google services; see Google’s help and contract materials for details.
Transfers to third countries (in particular the USA): Processing may also take place in third countries if data are transferred there. For the USA, an adequacy decision by the EU Commission (e.g. under the EU–US Data Privacy Framework) applies only to certified organisations; otherwise transfers require appropriate safeguards (see next paragraph) or another legal basis.
Standard Contractual Clauses: Where required, Google relies on the Standard Contractual Clauses (SCC) adopted by the EU Commission, together with supplementary technical and organisational measures. Further information on transfers, recipients and safeguards is available in Google’s privacy policy at https://policies.google.com/privacy and linked product information.
Withdrawal of consent
You may withdraw consent to processing at any time with effect for the future. Withdrawal does not affect lawfulness of processing before withdrawal.
You can withdraw consent using the cookie settings on this site (disable statistics) or by contacting us at the email address above.
Data subject rights
Subject to legal requirements, you have in particular:
Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20).
Objection: you may object on grounds relating to your particular situation to processing based on Art. 6(1)(f) GDPR (Art. 21). For direct marketing, objection results in cessation of processing for that purpose.
Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, workplace or the place of the alleged infringement (Art. 77 GDPR).
[PLACEHOLDER: competent authority for the controller — e.g. for North Rhine-Westphalia, the state commissioner: https://www.ldi.nrw.de/ ]
Security of processing
We use appropriate technical and organisational measures. The site is usually served over TLS/HTTPS when hosting and DNS are configured correctly.
[PLACEHOLDER: additional organisational measures if applicable.]
Changes to this privacy policy
We update this policy when the site, technologies or legal requirements change.
Replace all “[PLACEHOLDER: …]” sections with your actual company, hosting and analytics details.