Privacy policy

Last updated: 9 September 2026

This site processes personal data only as needed to run the website, reply to enquiries and project briefs and - with consent - measure traffic. I do not describe services this site does not use (for example there is no Supabase database here).

Data controller

The controller is Piotr Kulbacki (sole proprietorship / Einzelunternehmen, Berlin).

Bendastr. 11, 12051 Berlin
Germany

Email: kontakt@piotrkulbacki.com

Phone: +49 157 35166871

Data protection officer

I am not required to appoint a data protection officer (Datenschutzbeauftragter / IOD) and have not appointed one. For privacy requests use the controller contact details above.

What data I process

For each service actually used: which data, for what purpose, legal basis, recipient, whether a transfer outside the EEA occurs, and how long it is kept. Only technologies on piotrkulbacki.com.

Hosting (Vercel)

Data: IP address, user agent, timestamp, requested URL, possible error logs.

Purpose: delivering the site, security, incident diagnosis.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable, secure hosting).

Recipient: Vercel Inc., USA.

Transfer outside the EEA: yes (USA), based on Vercel’s standard contractual clauses.

Retention: technical logs usually short, following Vercel practice (typically a few weeks unless a security incident requires longer).

Form protection (Cloudflare Turnstile)

Data: challenge token, IP address, limited browser signals used to tell humans from bots.

Purpose: protecting the contact form and brief from spam and abuse.

Legal basis: Art. 6(1)(f) GDPR.

Recipient: Cloudflare, Inc., USA.

Transfer outside the EEA: yes (USA), Cloudflare SCCs.

Retention: verification is short-lived; Cloudflare may keep limited security logs under its own policy.

Contact form

Data you provide: name, email, optional phone, message; plus locale and the Turnstile result.

Purpose: contact, clarifying the request and - if we talk - preparing an offer and performing a contract. Submitting the form does not conclude a contract.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request) and (f).

Recipient: me as controller; email delivery via Brevo (Sendinblue GmbH, Germany).

Transfer outside the EEA: the form is not designed for that; Brevo processes in the EU.

Retention: enquiries without a contract - up to 12 months after last contact, then deletion unless longer storage is needed to defend claims. If we work together, correspondence and accounting rules below apply.

Project brief

Data: name, email, optional phone and answers about the project (type, names, goals, scope, materials, languages, integrations, timeline).

Purpose: understanding the project and preparing an individual proposal. The brief is not an order.

Legal basis: Art. 6(1)(b) or (f) GDPR.

Recipient and transfer: same as the contact form (Brevo in the EU).

Retention: same as contact enquiries. A browser draft (sessionStorage) stays on your device until you send or leave the session; after a successful send it is cleared. The draft is not uploaded beforehand.

No marketing use without separate consent.

Branded reply from notification emails

When you write via the contact form or brief, the notification in my inbox may include a reply button. It opens a private /reply page (not indexed) with a signed HMAC token: your name, email, enquiry source, language and an expiry (90 days). The token lives in the link; it is not stored in a database.

The form sends my reply through Brevo in the site email template to your address; a copy may go to my inbox (BCC). Legal basis: Art. 6(1)(b) or (f) GDPR. The reply page is not protected by Turnstile (only the link holder can open it); requests are rate-limited. After sending, correspondence retention below applies.

Special categories of data (Art. 9 GDPR)

The forms, brief and reply channel are not meant to collect special categories of personal data (Art. 9 GDPR) - for example health, racial or ethnic origin, political opinions, religion, trade-union membership, genetic or biometric data, or data concerning sex life or sexual orientation. Please do not send those data.

If they appear incidentally in a message, I process them only to handle the enquiry or to ask you to resend without them, then delete them when they are no longer needed. I do not collect Art. 9 data on purpose and do not rely on explicit Art. 9(2)(a) consent for this site.

Transactional email (Brevo)

Data: email addresses, name, message/brief content, delivery metadata.

Purpose: delivering mail to my inbox, an automatic acknowledgement, and any follow-up on that channel.

Legal basis: Art. 6(1)(b) or (f) GDPR.

Recipient: Sendinblue GmbH (Brevo), Germany, as processor.

Transfer outside the EEA: generally no - processing in the EU.

Retention: operational copies at Brevo as long as needed for delivery and handling, then according to correspondence retention.

Analytics (Vercel Analytics and Google Analytics 4)

Vercel Analytics: minimised traffic metrics (no classic tracking cookies).

GA4 (only after consent): cookie IDs (_ga / _ga_*), approximate region, device, page views, traffic source.

Purpose: understanding which pages help and improving the site - not ads.

Legal basis: Art. 6(1)(a) GDPR (banner consent). Until you choose, Google Consent Mode v2 sets analytics_storage and ad_* to “denied”. After “Accept all” I set only analytics_storage=granted; ad_storage, ad_user_data and ad_personalization stay denied. “Necessary only” or a later footer change keeps GA off.

Recipients: Vercel Inc.; Google Ireland Ltd. / Google LLC.

Transfer outside the EEA: Vercel and Google LLC (USA) - SCCs / the providers’ transfer frameworks.

Retention: consent in pk_cookie_consent - 12 months. GA cookies according to Google (typically up to 14 months in default GA4 retention unless I shorten it).

Recipients of personal data

Depending on the feature:

• Vercel Inc. - hosting and optional analytics after consent • Cloudflare, Inc. - Turnstile • Sendinblue GmbH (Brevo) - email sending, including branded replies from the notification link • Google Ireland Ltd. / Google LLC - GA4 only after analytics consent

I do not sell data. No Meta Pixel, Google Ads or external CMP.

Transfers outside the EEA

Vercel, Cloudflare and Google LLC have establishments or subprocessors in the USA and use standard contractual clauses or an equivalent transfer tool. Brevo (Sendinblue GmbH) processes in the EU.

There is no generic “data may be sent worldwide” clause without naming the recipient.

How long I keep data

• Enquiries and briefs without a contract: up to 12 months after last contact. • Signed reply-form tokens: 90 days in the link, then invalid. • Business correspondence during an offer / project: up to 3 years after the matter ends (possible claims), unless a shorter period is enough. • Client data and invoices / accounting records: 10 years if tax duties arise. • Hosting logs: short, per Vercel, unless a security incident. • Analytics consent: 12 months or until withdrawn. • Cookie choice: until the consent cookie expires or you clear the browser. • Brief sessionStorage: locally, until send or tab close.

After that I delete or anonymise, unless the law requires keeping the data.

Cookies and consent

I use first-party cookies that are necessary for the site and to remember your analytics choice. Analytics (Vercel Analytics + GA4) is blocked before consent. Refusal (“Necessary only”) is as available as acceptance. You can change the choice anytime via the footer. Consent lifetime: 12 months.

  • NEXT_LOCALE - necessary - remembers the selected language (next-intl), 12 months.
  • pk_cookie_consent - necessary - stores your analytics choice (version, flag, date), 12 months.
  • _ga / _ga_* - analytics (only after consent) - Google Analytics 4, e.g. _ga / _ga_*.

No advertising cookies or marketing trackers (e.g. Meta Pixel). This site does not run a Supabase database.

Your rights

Under the GDPR you may:

  • access your data
  • rectify it
  • have it erased
  • restrict processing
  • receive it in a portable format
  • object to processing based on legitimate interests
  • withdraw consent (analytics) at any time, without affecting the lawfulness of earlier processing
  • lodge a complaint with a supervisory authority

Supervisory authority

You may lodge a complaint with the competent data protection authority. For the Berlin establishment:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin

www.datenschutz-berlin.de