Privacy policy

Last updated: 2 July 2026

This is an English courtesy translation. The German version is legally authoritative.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

[Company name, e.g. Bricksta GmbH (in formation)], represented by Christoph Klett
[Address]
Email: hallo@bricksta.com

2. Your rights as a data subject

With regard to your personal data, you have in particular the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)

You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR).

3. Data collected when visiting the website (server log files)

When you access this website, the hosting provider automatically processes information in server log files that your browser transmits. This usually includes: IP address, date and time of access, page/file requested, amount of data transferred, referrer URL, and browser and operating system information.

The legal basis is our legitimate interest in providing the website securely and stably (Art. 6 (1) (f) GDPR). Storage period: [e.g. state the host’s log retention].

4. Hosting and delivery (Vercel)

This website is hosted by Vercel Inc. and delivered via its content delivery network. Personal data (in particular access data) may be processed in the process. A data processing agreement is in place; for transfers to third countries, appropriate safeguards (including EU standard contractual clauses) are used.

Provider: [Vercel Inc., add address]. Verify and reference the DPA.

5. Application and user accounts (Supabase)

For the logged-in application area (registration, sign-in, operation of the software) we use Supabase as a backend and authentication service. Account and usage data are processed insofar as this is necessary to provide the application (Art. 6 (1) (b) GDPR). A data processing agreement is in place.

Provider: [Supabase operating company, add address].

6. Contacting us

If you contact us by email, we process your details to handle the enquiry. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures/contract) or Art. 6 (1) (f) GDPR (legitimate interest in responding). The data are deleted once they are no longer required to achieve the purpose and no statutory retention obligations conflict with deletion.

7. Cookies and reach measurement

The public marketing pages of this website do not set tracking or analytics cookies and currently do not embed any web analytics services. In the logged-in application area, technically necessary cookies are used for session and login management; these are required for operation (Art. 6 (1) (f) GDPR or § 25 (2) TDDDG).

Should analytics/marketing tools be used in future, they must be added here and, where applicable, consent obtained via a consent banner (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG).

8. Email delivery (Resend)

For sending and, where applicable, receiving emails, we use the Resend service. The data required for delivery (e.g. email address, content) are processed. The legal basis is Art. 6 (1) (b) or (f) GDPR. A data processing agreement is in place.

Provider: [Resend operating company, add address].

9. Encryption (SSL/TLS)

For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” in your browser’s address bar.

10. Changes to this privacy policy

We adjust this privacy policy as soon as changes to the data processing we carry out make it necessary. The current version available on this page applies in each case.