Privacy Policy
Last updated: 2026-03-24 (UTC). This notice describes how we process personal data when you use this website and related services. German version: Datenschutzerklärung.
1. Controller
The controller is based in the United States. This website and related services are primarily operated using infrastructure in Germany.
The controller responsible for processing personal data in connection with this application is:
ProjectXUnited States
2. What data we process and why
- Website delivery and security: We process technical data (e.g. IP address, browser type, time of access, requested content) to provide the site, prevent abuse, and keep logs as permitted by law. Legal basis: Art. 6(1)(f) GDPR (legitimate interests in secure, reliable operation).
- Accounts and sign-in (if offered): If you use an account, we process the data needed to provide it (e.g. credentials, session information). Technically necessary cookies or similar means may be used; they are not used for marketing. Legal basis: Art. 6(1)(b) GDPR (contract) where applicable, and where necessary Art. 6(1)(f) GDPR.
- Cookie consent: We store your choice about non-essential cookies in an essential cookie so your preference is remembered on later visits. Non-essential cookies are used only on the basis of your consent (Art. 6(1)(a) GDPR) and, where applicable, national rules such as the ePrivacy framework in your country.
- Contact form: If you use the contact form, we process the information you provide (e.g. name, email, message, optional fields) solely to handle your request. Fields marked as required are necessary to process the inquiry. Legal basis: Art. 6(1)(b) GDPR if contractual or pre-contractual, otherwise Art. 6(1)(f) GDPR (legitimate interest in responding).
- Optional third-party sign-in (if offered): If you use an offered sign-in via an external provider, that provider processes the data required for authentication under its own privacy notice. We receive the information needed to operate your account (for example an email address and a stable identifier).
If personal data is transferred to a third country, we do so only where an adequate level of protection exists, appropriate safeguards apply, or a legal exception applies (Art. 44 et seq. GDPR). We do not carry out solely automated decision-making within the meaning of Art. 22 GDPR.
3. Cookies & similar technologies
We distinguish essential cookies (needed to run the site, including sign-in and consent storage) from non-essential cookies (e.g. analytics or comfort features). Non-essential cookies are only set after you opt in via our cookie banner or cookie settings.
4. Third-party services (subprocessors)
Depending on what we offer and how systems are configured, third parties may process personal data on our behalf or as independent controllers. Only data needed for the respective purpose is processed or shared. The list below describes typical categories and may be updated before go-live.
- Hosting and infrastructure — Operation of the website, storage, and backups; location and providers depend on configuration.
- Optional identity provider (sign-in) — If offered, handles authentication; we receive only what is needed to maintain your account.
- Content delivery (if used) — May deliver static assets such as scripts or fonts to your browser when enabled.
- Optional external processing (e.g. AI or integrations) — If such features are enabled, limited content you submit may be processed by external services to provide the function.
5. Storage periods
We keep personal data only as long as necessary for the purposes above or as required by law (e.g. commercial or tax retention). Contact messages are stored until they are no longer needed for the conversation, unless longer retention is legally required.
6. Your rights (GDPR)
Subject to legal conditions, you have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectification (Art. 16)
- Erasure (“right to be forgotten”) (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, where processing is based on consent (Art. 7(3))
- Lodge a complaint with a supervisory authority (Art. 77), in particular in the Member State of your habitual residence or place of work
To exercise your rights, use the contact details under Controller when configured. You can also use the cookie settings on this page to withdraw consent for non-essential cookies.
7. German Telemedia Act (TMG) & information duties
For business-related information (e.g. company identification), see our Impressum. This privacy notice supplements but does not replace statutory transparency requirements.