Privacy Policy
Data protection policy pursuant to the European General Data Protection Regulation (GDPR / DS-GVO) and the German Federal Data Protection Act (BDSG n.F.)
In accordance with statutory data protection regulations (in particular the BDSG and the European General Data Protection Regulation 'GDPR'), we inform you below about the nature, scope, and purpose of the processing of personal data by our company. This privacy policy applies to our websites and social media profiles. With regard to terms such as "personal data" or "processing", we refer to Art. 4 GDPR.
Data Controller
Zerna.io GmbH
Managing Director: Michael Zerna, Managing Director
E-Mail Address: [email protected]
Phone: +49 15255694273
Information Regarding Data Processing
Types of Data We Process:
- Contact details (phone number, e-mail address, postal address, etc.)
- Usage and technical metadata (IP addresses, access timestamps, visited pages)
Purposes of Processing (Art. 13 para. 1 lit. c GDPR):
- Customer care and inquiries
- Handling direct communication and requests
- Ensuring safe, stable, and functional website delivery
Categories of Data Subjects (Art. 13 para. 1 lit. e GDPR):
- Visitors / users of the website
- Clients, partners, and interested parties
Affected individuals are collectively referred to as "users".
Legal Bases for Processing
The processing of personal data is carried out on the following legal bases under the GDPR:
- Consent: Insofar as we obtain your consent for processing personal data,
Art. 6 para. 1 sentence 1 lit. a GDPRserves as the legal basis. - Performance of Contract & Pre-contractual Inquiries: If processing is necessary for the performance of a contract or for the implementation of pre-contractual measures,
Art. 6 para. 1 sentence 1 lit. b GDPRserves as the legal basis. - Legal Obligation: If processing is necessary to comply with a legal obligation to which we are subject (e.g. statutory retention duties),
Art. 6 para. 1 sentence 1 lit. c GDPRserves as the legal basis. - Vital Interests: If processing is necessary to protect vital interests of the data subject or another natural person,
Art. 6 para. 1 sentence 1 lit. d GDPRapplies. - Legitimate Interests: If processing is necessary to protect our legitimate interests or those of a third party, and your interests or fundamental rights and freedoms do not override our interests,
Art. 6 para. 1 sentence 1 lit. f GDPRserves as the legal basis.
Disclosure of Data to Third Parties and Processors
As a matter of principle, we do not pass on data to third parties without your consent. Should this nevertheless occur, it will only take place on the basis of the aforementioned legal grounds, e.g.:
- Passing on data to payment providers for contract fulfillment
- Pursuant to a binding court order or subpoena
- Pursuant to a statutory obligation for law enforcement, threat prevention, or enforcement of rights
Data Processors: We also engage data processors (external service providers, e.g. for hosting our websites and infrastructure). Where data is disclosed to processors under a data processing agreement (DPA), this is always done in strict compliance with Art. 28 GDPR.
Transfers to Third Countries
The European GDPR provides a unified standard for data protection across Europe. Your data is therefore predominantly processed by companies subject to the GDPR.
However, where processing takes place via third-party services located outside the European Union or European Economic Area, they must fulfill the special requirements of Art. 44 et seq. GDPR. This means processing takes place on the basis of recognized safeguards, such as an official EU Commission adequacy decision (e.g. EU-US Data Privacy Framework) or Standard Contractual Clauses (SCC).
Storage Duration and Data Erasure
Unless expressly stated in this privacy policy, your personal data will be erased or blocked as soon as the purpose of storage ceases to apply, unless further storage is required for evidence purposes or statutory retention requirements prevent deletion.
This includes, for example:
- Commercial retention obligations for business correspondence (§ 257 para. 1 HGB): 6 years
- Tax retention obligations for invoices and accounting records (§ 147 para. 1 AO): 10 years
When the statutory retention period expires, your data will be blocked or deleted unless further storage is necessary for concluding or performing a contract.
Automated Decision-Making
We do not use any automated decision-making or profiling mechanisms.
Provision of Website and Creation of Log Files
When you visit our website purely for informational purposes (i.e. without registering or submitting information), we only collect the personal data that your browser automatically transmits to our server:
These data are used for the reliable, secure, and functional delivery of our website, as well as for security optimization and server infrastructure maintenance.
The legal basis is our legitimate interest in secure data processing pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR. For security reasons (e.g. investigation of cyber attacks or abuse), server log files are stored for a limited period and then deleted.
🛡️ Commitment to Zero Tracking and No Advertising Cookies
As advocates of digital sovereignty, local-first engineering, and privacy, we take the protection of your personal space seriously. This website employs zero tracking cookies, zero advertising cookies, and zero behavioral analytics suites (such as Google Analytics, Meta Pixel, Matomo, etc.). No behavioral analysis, conversion tracking, or profiling takes place.
Only technically strictly necessary data are processed to deliver the static pages cleanly and securely to your browser. No persistent cookies are placed on your terminal device.
Direct Contact (Form / E-Mail / Mail)
When you contact us by e-mail, mail, or contact form, your details are processed to handle the inquiry. Because we do not operate an automated third-party form backend, the form merely pre-fills an e-mail in your local client. Form data is not stored in a web database on our server.
Legal Bases:
- Art. 6 para. 1 sentence 1 lit. a GDPR based on your consent
- Art. 6 para. 1 sentence 1 lit. f GDPR based on our legitimate interest in effective communication
- Art. 6 para. 1 sentence 1 lit. b GDPR where communication concerns contract initiation
Deletion: Inquiry data are deleted as soon as the conversation is concluded, provided no statutory retention duties (e.g. 6 years under commercial law or 10 years under tax law) apply.
Social Media Presence
We maintain verified profiles on external social networks to engage with viewers and announce new essays and architectural analyses. When you access these networks, the terms and privacy notices of the respective platform operators apply.
Networks we operate on:
- YouTube / Google: Privacy Policy: policies.google.com/privacy
- X (Twitter): Privacy Policy: twitter.com/en/privacy
- LinkedIn: Privacy Policy: linkedin.com/legal/privacy-policy
- Instagram: Privacy Policy: help.instagram.com
Your Rights as a Data Subject
Right to Object and Revocation of Consent
Where processing is based on your consent (Art. 6 para. 1 lit. a, Art. 7 GDPR), you have the right to revoke your consent at any time. Where processing is based on legitimate interests (Art. 6 para. 1 lit. f GDPR), you may object at any time:
Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation as to whether personal data concerning you are being processed and to receive access to such data.
Right to Rectification (Art. 16 GDPR)
You have the right to obtain the rectification of inaccurate data or the completion of incomplete personal data.
Right to Erasure (Art. 17 GDPR)
You have the right to obtain the erasure of your personal data without undue delay, provided no statutory retention duties apply.
Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request restriction of processing under the conditions set out in Art. 18 GDPR.
Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
Security Measures & Encryption
To protect all personal data submitted to us and to ensure that data protection regulations are observed by our infrastructure, we have implemented appropriate technical and organizational measures. All communication between your browser and our web servers is securely transmitted via TLS/SSL encryption.