Privacy Policy
This is an English translation for convenience. In case of any discrepancy, the German version is legally binding.
Last updated: July 2026. This website is deliberately data-minimal: no advertising cookies, no data to Google or Meta, no external fonts or embeds. For analytics we ask once — without your consent nothing is loaded and nothing is stored.
1. Controller
Fischer Websites, owner Fabian Fischer
Dorfstraße 58, 98663 Schweickershausen, Germany
Phone: 0151 5889 6050 · Email: info@fischer-websites.de
2. Hosting
This website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When you access the website, Vercel processes technically necessary connection data (in particular IP address, date and time of access, the file requested, user agent) in server log files. This processing is necessary for the provision, stability and security of the website (Art. 6(1)(f) GDPR). Vercel also processes data in the USA; the transfer is based on the EU Standard Contractual Clauses (SCC).
3. Analytics with PostHog — only with your consent
If you agree in the notice at the bottom of the page, we use PostHog to analyse how the website is used. Without your consent the analytics software is not loaded at all; nothing is stored on your device and nothing is read from it.
Purpose: We want to understand which content helps and where visitors get stuck, in order to improve the website and find errors. This includes a recording of the session (session replay): page views, mouse movement, scrolling and clicks are reconstructed into a replayable sequence.
What is excluded: All text you type and all page text are masked in your browser — they never leave your device. The contact form is excluded from recording entirely. We create no person profiles and capture no automatic click events.
Legal basis: Your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may withdraw your consent at any time with effect for the future, using the “Analytics settings” button in the footer. This does not affect the lawfulness of processing carried out before the withdrawal. For analytics, an identifier is stored on your device for up to 90 days; it is deleted when you withdraw.
Recipient and storage location: The provider is PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA (privacy contact: privacy@posthog.com), acting as a processor under a data processing agreement pursuant to Art. 28 GDPR. Processing takes place on servers within the European Union (Frankfurt am Main). Access from the USA cannot be ruled out; any such transfer is based on the EU Standard Contractual Clauses, supplemented by participation in the EU-US Data Privacy Framework.
Data processed: Page views and requested addresses, time spent, approximate origin of the visit, device type and browser, referring page, and the masked session sequence. Your IP address is not stored.
Retention: Session recordings are deleted automatically after 30 days.
4. Contacting us
If you contact us by phone, email, WhatsApp or via the contact form, we process the information you provide (name, contact details, content of your inquiry) solely to handle your request and any follow-up questions (Art. 6(1)(b) GDPR). The data is deleted as soon as it is no longer required for this purpose and no statutory retention obligations apply.
Information submitted through the contact form is delivered to our mailbox by email. Sending and the mailbox itself are operated by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, with whom a data processing agreement is in place. No user account is created, and the information is not used for advertising.
Note on WhatsApp: if you contact us via WhatsApp, the privacy terms of WhatsApp Ireland Ltd. additionally apply. Use is voluntary — you can reach us just as well by phone or email.
5. Your rights
Regarding your personal data, you have the following rights: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing (Art. 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the authority responsible for Thuringia is the Thuringian State Commissioner for Data Protection and Freedom of Information.
6. SSL/TLS encryption
This website uses TLS encryption throughout (https). Data you transmit to us cannot be read by third parties.