TFDS Logo
HomeServicesBlogAboutContact
HomeServicesBlogAboutContact
TFDS LogoTimo Fuchs Digital Services

Design for authors who mean business.

Navigation

HomeServicesBlogAboutContact

Legal

ImprintPrivacyTerms

© 2026 Timo Fuchs Digital Services. All rights reserved.

Privacy Policy

Last updated: April 2026

1. Privacy at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

Data collection on this website

Data processing on this website is carried out by the website operator. Their contact details can be found in the imprint of this website.

2. Responsible party

Timo Fuchs

operating as Timo Fuchs Digital Services

c/o Impressumservice Dein-Impressum

Stettiner Straße 41, 35410 Hungen

Email: noreply@trap.invalidme@timo-fuchs.com

3. Hosting & Infrastructure

Vercel

This website is hosted by Vercel Inc., 340 Pine Street, Suite 701, San Francisco, CA 94104, USA. When you visit the website, technical data (IP address, browser type, time of access) is automatically recorded in server logs. This data is technically necessary for operating the website and is not merged with other data sources.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the secure and stable operation of the website). Vercel processes data under the EU-US Data Privacy Framework. More information: vercel.com/legal/privacy-policy.

Cloudflare (CDN, DNS, Security)

This website uses services provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare acts as a Content Delivery Network (CDN) and DNS provider. All requests to this website are routed through Cloudflare servers. In doing so, Cloudflare processes technical data such as IP addresses, HTTP headers, and timestamps for the purposes of security (DDoS protection), performance optimisation, and availability. Cloudflare retains log data for a maximum of 24 hours. No merging with personal data takes place. Cloudflare is certified under the EU-US Data Privacy Framework and has concluded Standard Contractual Clauses (SCCs). Legal basis: Art. 6 (1) (f) GDPR (legitimate interest). More information: cloudflare.com/privacypolicy.

Cloudflare Web Analytics

We use Cloudflare Web Analytics to analyse website usage. This service is deliberately privacy-friendly: no cookies are set, no persistent identifiers are used, and no cross-device tracking takes place. Only aggregated data is collected, such as page views, country of origin (derived from the IP address, which is not stored itself), browser type, and referring pages. As no cookies or comparable tracking technologies within the meaning of § 25 TDDDG are used, no separate consent is required. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in improving the service). More information: cloudflare.com/web-analytics.

Umami Analytics

In addition to Cloudflare Web Analytics, we use Umami, a privacy-friendly open-source analytics service operated by Umami Software, Inc. We use Umami Cloud with data storage exclusively within the European Union. Umami sets no cookies, uses no persistent identifiers, and creates no cross-device profiles. Only aggregated usage data is collected (page views, session duration, country of origin), which cannot be attributed to any individual. As no cookies or comparable tracking technologies within the meaning of § 25 TDDDG are used, no separate consent is required. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest). More information: umami.is/privacy.

legal.ds3H6

We use Cloudinary to deliver and optimise images on this website. Cloudinary is a service provided by Cloudinary Ltd. with operations in the USA. When images are loaded, your browser establishes a direct connection to Cloudinary servers, during which technical data such as your IP address is processed. Cloudinary automatically optimises images with regard to format and quality (e.g. WebP conversion) and delivers them via a global CDN. No personal profiles are created. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in fast and optimised image delivery). Cloudinary processes data in accordance with the EU-US Data Privacy Framework. More information: cloudinary.com/privacy.

4. Data collection on this website

Contact form

When you send us inquiries via the contact form, your information (name, email, message, project type) is stored for the purpose of processing your request and contacting you. Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures).

Data storage (Supabase)

Your contact submissions are stored in a database provided by Supabase, Inc., San Francisco, USA. Supabase acts as a data processor pursuant to Art. 28 GDPR and processes your data solely for the purpose of storing your enquiry. Supabase is certified under the EU-US Data Privacy Framework and provides server capacity within the EU. Data stored includes: name, email address, message, project type, and submission date and time. More information: supabase.com/privacy.

Email notification (Gmail API)

To notify us of new contact enquiries, your submitted data (name, email, message, project type) is transmitted via the Gmail API to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and delivered as an email to the website operator. If you requested a copy of your enquiry, this will also be sent to your email address via this route. Google processes the transmitted content as part of email delivery. No further use of your data by Google takes place. Google LLC is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures). More information: policies.google.com/privacy.

Spam protection (Cloudflare Turnstile)

To protect the contact form from spam and misuse, we use Cloudflare Turnstile, a privacy-friendly CAPTCHA alternative provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile analyses technical browser signals in the background (e.g. user agent, time zone, language) and interaction patterns to distinguish automated requests from human users. Unlike conventional CAPTCHA services, Turnstile does not set tracking cookies and does not create cross-device profiles. For challenge processing, data is temporarily transmitted to Cloudflare servers in the USA (covered by the EU-US Data Privacy Framework and SCCs). Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in protection against spam and abuse). More information: cloudflare.com/privacypolicy.

Storage period

Your personal data will remain with us until the purpose for data processing ceases to apply or you request deletion. Statutory retention periods remain unaffected.

5. Newsletter (Brevo)

Email service provider

The newsletter is sent via Brevo SAS (formerly Sendinblue), 7 rue de Madrid, 75008 Paris, France. Brevo processes your data on servers within the European Union and acts as a data processor pursuant to Art. 28 GDPR. More information: brevo.com/en/legal/privacypolicy.

What data is stored?

When you sign up, your email address and optionally your first name are transmitted to and stored by Brevo. Signup uses a double opt-in process: after signing up, you will receive a confirmation email that you must actively confirm before being added to the mailing list.

Legal basis

The legal basis is your explicit consent pursuant to Art. 6 (1) (a) GDPR. You may withdraw your consent at any time - either via the unsubscribe link in any newsletter email or through the page timo-fuchs.com/newsletter/abmelden. The lawfulness of data processing carried out prior to the withdrawal remains unaffected.

No cookie requirement

The newsletter signup works via a direct API connection to Brevo. The newsletter form does not set any cookies and does not require separate cookie consent.

6. Appointment booking (cal.eu)

What is cal.eu?

For booking free introductory calls, we use cal.eu, operated by Cal.com Europe GmbH, based in the European Union.

What data is processed?

When you use the cal.eu widget and book an appointment, cal.eu processes: your name, email address, time zone, selected appointment, and technical information (IP address, browser data). cal.eu may set its own cookies once the widget is loaded.

Consent required

The cal.eu widget is only loaded after you consent to the 'Marketing' cookie category. Without this consent, no data is transmitted to cal.eu. You may withdraw your consent at any time via the cookie settings in the footer.

Data processing

cal.eu processes data on servers within the European Union. More information on data processing can be found in cal.eu's privacy policy: cal.com/privacy.

Legal basis

Art. 6 (1) (a) GDPR (consent).

7. Cookie consent

Our cookie consent system

This website uses its own cookie consent system. Your settings are stored locally in your browser (localStorage). No consent data is transmitted to external servers. You can adjust your settings at any time via 'Cookie settings' in the footer.

Cookie categories

  • Necessary: Required for the technical function of the website, including Cloudflare Turnstile (spam protection for the contact form). No consent required, Art. 6 (1) (f) GDPR.
  • Analytics: Cloudflare Web Analytics and Umami Analytics for aggregated, cookie-free analysis of website usage. No tracking cookies, no persistent identifiers, no consent required. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest).
  • Marketing: Third-party services such as cal.eu that may set their own cookies and process data. Art. 6 (1) (a) GDPR.

8. Your rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7 (3) GDPR)

To exercise your rights, please contact: noreply@trap.invalidme@timo-fuchs.com

You also have the right to lodge a complaint with the competent data protection supervisory authority. The responsible authority is the Hessian Commissioner for Data Protection and Freedom of Information (datenschutz.hessen.de).