Legal
Privacy Policy
This page is an informational translation of the legally authoritative German original. If the versions differ or a question of interpretation arises, the German text applies.
1. Controller
The controller within the meaning of the General Data Protection Regulation is:
Roman Zhuchenko c/o Block Services Stuttgarter Str. 106 70736 Fellbach Germany
Email: kontakt@phantom-creator.com
2. Hosting
This website is hosted by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, and delivered through its content delivery and security network. When the website is accessed, Cloudflare processes technical access data, including IP addresses, to deliver the content and ensure security and stability.
The legal basis is Article 6(1)(f) GDPR, namely the legitimate interest in secure and efficient website delivery. Data may be transferred to the United States. Cloudflare relies on the EU Standard Contractual Clauses and participates in the EU-US Data Privacy Framework. A data processing agreement under Article 28 GDPR is in place with Cloudflare.
3. Server logs
When the website is accessed, Cloudflare automatically processes technical access data, in particular:
- browser type and version
- operating system
- referrer URL
- date and time of access
- IP address
- requested URL and technical security information
I do not maintain my own server log files. Cloudflare processes this data for delivery, technical stability and protection against abusive access. The legal basis is Article 6(1)(f) GDPR. Retention depends on the Cloudflare function used, account configuration and legal obligations. Data is deleted or anonymised when it is no longer required for these purposes.
4. Contact form
When you use the contact form, I process the details you enter (name, email address, optionally company, website or Instagram profile, product or service, the selected topic and your message) as well as the page language and the time of the enquiry. The purpose is to process and answer your enquiry. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract) or Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
The enquiry is delivered to my mailbox as an email (for sending and the mailbox see section 6). The address you entered also receives an automatic confirmation of receipt. It contains only a fixed text, neither your name nor your message.
Protection against abuse. To prevent the form from being used for automated or mass submissions,
- it contains a check field that is invisible to you and checks a minimum time for filling it in;
- the number of enquiries per IP address is limited: three per minute and five per hour. Cloudflare (section 2) counts the per-minute limit only transiently for 60 seconds. For the hourly limit, your IP address is not stored; instead a check value formed with a secret key (HMAC), from which the address cannot be recovered, is stored together with a counter. The entry is deleted automatically after one hour at the latest;
- the confirmation is sent to the same email address at most once in 24 hours. For this, too, only an HMAC check value of the address is stored for 24 hours;
- every submission is checked with Cloudflare Turnstile (section 5).
Once the hourly limit is reached, your browser remembers the end of the waiting time in local storage (entry “pc-contact-limit”) so that the form can show the remaining time. The entry contains only a point in time, never leaves your device and is removed once the time has passed.
The legal basis for these protective measures is Art. 6(1)(f) GDPR (legitimate interest in a working contact form protected against spam and abuse). Storing the entry in local storage is strictly necessary for the service you are using and does not require consent under Section 25(2)(2) TDDDG.
5. Spam protection with Cloudflare Turnstile
To protect the contact form against bots, I use Cloudflare Turnstile, a service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Turnstile is not loaded when you open the website. Only when you start filling in the form does your browser load a script from challenges.cloudflare.com. When you send the form, Turnstile checks invisibly and without picture puzzles whether the enquiry comes from a human. For this, Cloudflare processes technical signals from your browser and device, according to Cloudflare in particular the IP address, the TLS fingerprint, the browser identifier (user agent) and the website on which the check takes place. Your browser solves small computational tasks in the process. Turnstile does not receive the content of what you enter in the form. The result is a single-use verification code that my server has Cloudflare confirm before the enquiry is forwarded.
The legal basis is Art. 6(1)(f) GDPR. My legitimate interest is protecting the form against automated spam submissions. The access to information on your device that the check requires is permitted without consent under Section 25(2)(2) TDDDG because it is strictly necessary to provide the transmission of your enquiry that you requested in a secure way. According to Cloudflare, the signals are not used to identify individuals, build profiles or serve advertising.
For the check itself, Cloudflare acts as my processor; the data processing agreement mentioned in section 2 applies. In addition, according to its own information, Cloudflare uses the signals as an independent controller to improve Turnstile’s bot detection, relying on its own legitimate interest. For the transfer to the USA, the information in section 2 applies. Details are available in the Turnstile Privacy Addendum.
You can object to this processing under Art. 21 GDPR. The form can then not be used, but you can always reach me by email.
6. Contact by email, forwarding and mailbox
When you write to kontakt@phantom-creator.com or use the form, your sender address, the subject, the content of your message, any attachments and technical metadata (in particular header lines with timestamps, the mail servers involved and IP addresses) are processed. Purpose and legal basis are the same as in section 4. The following service providers are involved in email communication.
Incoming messages: forwarding via Cloudflare. No mailbox of its own is operated on the domain phantom-creator.com. Incoming messages are accepted by Cloudflare Email Routing and delivered directly to my mailbox under a fixed forwarding rule. The complete message passes through Cloudflare’s systems but is not stored there permanently; log and delivery data may arise. For the provider, the data processing agreement and the transfer to the USA, the information in section 2 applies.
Mailbox at Google. The mailbox in which messages arrive and are stored and processed is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may use Google LLC in the USA for this. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is based on the European Commission’s adequacy decision of 10 July 2023 (Art. 45 GDPR). More information: policies.google.com/privacy.
Sending via SMTP2GO. The emails generated by the form (your enquiry to me and the confirmation to you) and my replies from this address are sent via SMTP2GO, a service of Sand Dune Mail Ltd, 96-106 Manchester Street, Christchurch 8011, New Zealand. The account is assigned to the provider’s EU region; according to the provider, messages are processed via European mail servers in the data centre in Amsterdam. A data processing agreement under Art. 28 GDPR is in place with the provider. The European Commission has issued an adequacy decision for New Zealand (2013/65/EU), so the transfer is based on Art. 45 GDPR. More information: smtp2go.com/privacy.
Storage period. Messages are deleted as soon as they are no longer needed for processing. I delete enquiries that do not lead to a contract no later than six months after the last contact, unless statutory retention obligations apply. Emails between mail servers are usually transmitted with transport encryption (TLS); there is no end-to-end encryption.
7. External social media links
This website contains links to external social networks such as Instagram. No content from these networks is embedded and no data is transferred to them until you actively follow a link. The privacy rules of the respective provider then apply, for example those of Meta Platforms Ireland Ltd.
8. Social media profiles
This policy also applies to my profiles on Instagram and Threads, operated by Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland, YouTube, operated by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, and TikTok, operated by TikTok Technology Ltd., 10 Earlsfort Terrace, Dublin 2, Ireland.
When you visit one of these profiles, the platform operator processes personal data such as your IP address and usage behaviour under its own responsibility. For certain processing, including the creation of reach statistics, joint controllership under Article 26 GDPR may apply. I have only limited influence on this processing. Data may be transferred to third countries, especially the USA.
The profiles are used on the basis of Article 6(1)(f) GDPR, namely the legitimate interest in effective information and communication. You may exercise your data subject rights against me or the relevant platform operator. Details are provided in the policies of Instagram/Meta, YouTube/Google and TikTok.
9. YouTube videos
Videos offered on this website may be hosted by YouTube, operated by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Merely opening the website or the privacy notice does not transfer data to YouTube. Preview images are loaded locally from my server, not from Google.
A first click on a video card opens only a locally hosted preview and does not transfer data to YouTube. Next to the “Watch video” button, the preview states that starting the video loads YouTube and sends data to Google in the USA. Only when you choose that button is the YouTube player loaded in enhanced privacy mode from youtube-nocookie.com. Data, in particular your IP address and device and browser information, is then sent to YouTube or Google and may be transferred to the USA. I have no control over this processing.
The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Your decision is stored locally in your browser only (local storage, entry “yt-consent”) so that you are not asked again for every video. This storage serves solely to carry out your consent and transfers no data to third parties. You can withdraw consent at any time with effect for the future: use the “Withdraw consent” button below the running video, or clear this site’s data in your browser. The local preview is then shown again. Further information is available in Google’s privacy policy.
10. No own cookies or tracking
Apart from the functions described above, this website sets no cookies of its own and uses no analytics, tracking, advertising or marketing technologies (such as Google Analytics). Fonts are loaded locally from my own server; your IP address is not transmitted to Google Fonts.
The website stores only the entries named in sections 4 and 9 in your browser’s local storage (“pc-contact-limit” and “yt-consent”). It connects to third-party servers only when you use the contact form (Cloudflare Turnstile, section 5) or start a YouTube video (section 9).
The hosting provider Cloudflare (see section 2) may set technically necessary cookies in certain security situations. Insofar as these are strictly necessary for the operation and security of the website, they do not require consent under Section 25(2)(2) TDDDG. With the current technical configuration, a general cookie banner is therefore not required.
11. Your rights
Within the limits of applicable law, you have the right to:
- access your data under Article 15 GDPR
- rectify inaccurate data under Article 16 GDPR
- erase your data under Article 17 GDPR
- restrict processing under Article 18 GDPR
- data portability under Article 20 GDPR
- object to processing under Article 21 GDPR
- withdraw consent for the future under Article 7(3) GDPR
To exercise these rights, send an email to the address above. You also have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. The authority generally responsible for me is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg. You may also contact another supervisory authority competent under Article 77 GDPR.
Last updated: October 2026