Legal
Privacy Policy
How I process personal data on this website — completely, and as clearly as possible.
Courtesy translation
This page is provided in English for your convenience. The German version is the legally binding original — only the German text has been legally reviewed. If this translation differs from the German version in any way, the German version governs.
1. Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
Felix Schattenberg
evoyo.la
Striesener Straße 4
01307 Dresden
Deutschland
Phone: 0155 63336535
Email: info@evoyo.la
No data protection officer has been appointed for this website, as there is no legal obligation to do so.
2. Hosting and Server Log Files
This website is hosted by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany (server location: data center in Nuremberg, Germany). A data processing agreement pursuant to Article 28 GDPR is in place with netcup.
Every time this website is accessed, the server automatically collects data and information in so-called server log files, which your browser transmits. The following is collected: IP address, date and time of the request, the URL accessed, the referrer URL, and browser type and version (user agent). This data is not combined with data from any other source.
The legal basis is Article 6 (1)(f) GDPR. The legitimate interest arises from the stated purposes of the data collection: ensuring the trouble-free operation of this website and the security of the underlying IT systems. For security reasons (e.g. to investigate cases of abuse), the log files are stored for a period of 14 days and are then deleted or anonymized, unless they are needed for longer to defend against or assert legal claims.
3. Cloudflare (Proxy/CDN)
This website sits behind Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, as a proxy/CDN. Every access to this website is technically routed through Cloudflare's network first, before reaching the server at netcup — this enables, among other things, DDoS protection, TLS termination and faster delivery of static content. In doing so, Cloudflare inevitably processes the same technical connection data described in Section 2 above (in particular the IP address, time of the request, and requested URL).
A data processing agreement pursuant to Article 28 GDPR is in place with Cloudflare, including EU Standard Contractual Clauses for any transfer of data to the USA. The legal basis is my legitimate interest in providing this website securely and with good performance, Article 6 (1)(f) GDPR.
4. TLS/SSL Encryption
For security reasons and to protect the transmission of confidential content, this website uses TLS/SSL encryption. You can recognize an encrypted connection by the fact that your browser's address bar changes from "http://" to "https://" and by the lock icon in the address bar.
5. Contact Form
If you send me an inquiry via the contact form, the data you enter — name, email address, optionally your phone number, your message, optional details about project type, budget range and timeframe, as well as your IP address — is stored in a database, so that your inquiry is not lost if email delivery fails for technical reasons. In parallel, the complete message is delivered to me by email via server-side mail infrastructure, with your email address set as the reply-to address. I do not share this data with third parties without your consent.
The IP address is collected solely for abuse and spam prevention (honeypot/time-trap checks), not for tracking purposes.
The processing is based on Article 6 (1)(b) GDPR, insofar as your inquiry serves to initiate or perform a contract. In all other cases, the processing is based on my legitimate interest in handling inquiries addressed to me effectively and in preventing automated spam submissions (Article 6 (1)(f) GDPR).
I store the data collected via the contact form for as long as your inquiry or a resulting project is active, so I can process it and work with you on it. On request, I delete it earlier, unless mandatory statutory retention periods (e.g. for invoicing records under German tax law) require otherwise.
6. Email Delivery (Zoho Mail)
For sending emails triggered by the contact form or by automated notifications on this website (e.g. the confirmation of receipt of your inquiry, quote links, or client-portal links), I use Zoho Mail, provided by Zoho Corporation B.V., Beneluxlaan 4b, 3527 HT Utrecht, Netherlands, as email infrastructure. Zoho processes the message content as well as the sender and recipient addresses solely on my behalf for technical delivery.
A data processing agreement pursuant to Article 28 GDPR is in place with Zoho. The legal basis is the same as for the respective underlying processing (see Section 5) — the email delivery itself merely serves technical execution.
7. Plausible Analytics
This website exclusively uses Plausible Analytics — a privacy-friendly alternative to Google Analytics that I run myself on my own infrastructure (self-hosted). No Google Analytics or any other third-party service is used. Plausible Analytics does not set cookies, does not use persistent identifiers, and does not allow cross-session or cross-device tracking of individual visitors. Only aggregated, anonymous statistics are generated (e.g. page views, referrers, coarsely rounded location data at the country/region level); re-identification of individual visitors is not possible.
Because Plausible Analytics does not set cookies and does not build personal profiles, consent under Section 25 of the German Telecommunications-Digital Services Data Protection Act (TDDDG) is, according to prevailing legal opinion, not required — which is why this website does not display a cookie banner. The legal basis is my legitimate interest in the needs-based design and ongoing optimization of this website, Article 6 (1)(f) GDPR. Since the analysis takes place entirely on my own infrastructure, no data is transferred to third parties.
8. Error Monitoring (GlitchTip)
To detect technical errors early, I use GlitchTip — a self-hosted error-monitoring solution compatible with the Sentry protocol, which runs exclusively on my own infrastructure. In the event of an error, technical diagnostic data is collected, in particular the error message, stack trace, the URL accessed, and the time of the error.
Transmission of additional personal data (including IP address) is disabled by default in the configuration; no personal data beyond what is needed for technical error diagnosis is collected. The legal basis is my legitimate interest in ensuring the trouble-free and secure operation of this website, Article 6 (1)(f) GDPR. Since GlitchTip runs exclusively on my own infrastructure, no data is transferred to third parties.
9. Payment Processing (Paddle)
If I send you a quote as part of a collaboration and you pay for it via the checkout link provided, I do not process the payment myself but through Paddle.com Market Limited, Judd House, 18-29 Mora Street, London EC1V 8BT, United Kingdom (referred to below as "Paddle"). Paddle acts as the "merchant of record": the payment contract for the service I provide is formed between you and Paddle, and Paddle issues the invoice to you. This arrangement concerns payment processing only — the agreed service itself continues to be provided by me.
When you open the checkout link, the data required for payment processing — in particular your name, email address, billing address, and the payment details you choose — is transmitted directly to Paddle and processed there. I myself only receive confirmation from Paddle of the time, amount, and status of the payment (e.g. "paid"), not any payment details such as card numbers. Paddle, as an independent controller, may process this data for fraud prevention and to fulfil its own statutory obligations (in particular tax obligations); further details can be found in Paddle's privacy policy.
The legal basis for the transfer of data to Paddle is Article 6 (1)(b) GDPR (performance of the payment contract you enter into with Paddle) as well as my legitimate interest in reliable, PCI-DSS-compliant payment processing without storing payment data myself (Article 6 (1)(f) GDPR). No data is transferred to Paddle without an active payment process under way — the checkout link is only generated once I send you a quote.
The same Paddle payment processing applies to ongoing maintenance/support agreements (Retainers) billed monthly as a subscription: Paddle also processes the payment data for these and collects the recurring amounts on its own. You can pause or cancel a subscription at any time in the customer portal; the corresponding request is sent directly to Paddle.
10. Internal Notifications (ntfy)
To keep myself informed about new inquiries and incoming payments, I use ntfy, a self-hosted push notification service that runs exclusively on my own infrastructure. These notifications contain no customer data (no name, no email address, no message content), only a technical indicator of the event itself (e.g. "new inquiry received"). No data is transferred to third parties.
11. Cookies and Local Storage
This website uses only strictly necessary cookies and your browser's local storage (localStorage). There are no cookies requiring consent and therefore no cookie banner — the following overview is exhaustive:
| Name | Purpose | Retention |
|---|---|---|
| laravel_session | Server-side session management | End of session |
| XSRF-TOKEN | Protection against cross-site request forgery | End of session |
| evoyola-theme (localStorage) | Stores your light/dark display preference, strictly local, never transmitted to the server | until deleted by you |
These cookies and stored values cannot be disabled, as the website would not function without them, or your display preference could otherwise not be remembered.
12. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
- Right of access (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object to processing based on Article 6 (1)(f) GDPR (Article 21 GDPR)
To exercise these rights, you may contact me at any time, without any particular form, using the contact details given above in Section 1.
You also have the right to lodge a complaint with a data protection supervisory authority. Since my registered place of business is in Dresden, Saxony, the competent supervisory authority is:
Saxon Commissioner for Data Protection and Transparency (Sächsische Datenschutz- und
Transparenzbeauftragte)
Maternistraße 17
01067 Dresden, Germany
Phone: +49 351 85471-101
Email: post@sdtb.sachsen.de
13. AI-Assisted Tools
In delivering my services (not in operating this website) I use AI-assisted tools, for instance for code generation, analysis and text drafts. Personal data of clients or third parties is only entered into an AI system where a legal basis under data-protection law exists (Art. 6(1)(b) or (f) GDPR) and the respective provider is contractually bound to confidentiality and GDPR-compliant processing (data processing agreement, Art. 28 GDPR). Wherever possible I work with anonymised or pseudonymised data. Responsibility for all work results remains with me; details are set out in the terms (§ 3).
14. Last Updated
Last updated: August 14, 2026