Privacy Policy

This is a translation for convenience. The German Datenschutzerklärung is the legally binding version and must be completed with your real data before publishing.

1. Controller

The controller responsible for data processing on this website is:

[First and last name / company name]
[Street, number]
[Postcode, city]
Email: hallo@callista-studio.com

2. General

We process personal data only to the extent necessary to provide a functional website and our content and services. This website is built data-minimal: it uses no tracking cookies and no analytics services.

3. Hosting (Cloudflare)

This website is delivered via Cloudflare Pages, provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. As a processor, Cloudflare handles technical data (including server log data and your IP address) to deliver the site securely and quickly.

The legal basis is our legitimate interest in secure, efficient delivery (Art. 6(1)(f) GDPR). A data processing addendum under Art. 28 GDPR is in place with Cloudflare. Any transfer to the USA is based on the EU-U.S. Data Privacy Framework (Cloudflare is certified) and, additionally, the EU Standard Contractual Clauses. Processing exclusively within the EU is not guaranteed on the plan used.

4. Server log files

The hosting provider automatically collects and stores information in server log files which your browser transmits automatically: browser type and version, operating system, referrer URL, time of the request and IP address (shortened/anonymised where technically possible). The legal basis is Art. 6(1)(f) GDPR.

5. Contact form and email

If you contact us via the form or by email, your details (name, email address, optionally company and the content of your message) are stored to process the enquiry and for follow-up questions. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract or pre-contractual measures, otherwise our legitimate interest (Art. 6(1)(f) GDPR) and your consent (Art. 6(1)(a) GDPR) where requested. The form submission is processed via a Cloudflare Pages Function; your enquiry is delivered to our inbox via the email service Resend (Resend, Inc., USA), with which a data processing agreement incl. Standard Contractual Clauses is in place (Resend is also EU-U.S. Data Privacy Framework certified).

To protect the form against automated abuse (spam, bots) we use Cloudflare Turnstile. This transmits technical information (incl. IP address and browser characteristics) to Cloudflare for evaluation. Turnstile uses no tracking cookies and no advertising tracking. The legal basis is our legitimate interest in preventing spam and abuse (Art. 6(1)(f) GDPR); for the US transfer the mechanisms named under “Hosting” (DPF / SCC) apply.

6. Storage period

We store personal data only for as long as necessary to achieve the purpose, or as required by statutory retention periods.

7. Your rights

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

8. SSL/TLS encryption

For security reasons this site uses SSL/TLS encryption, recognisable by the “https://” in the address bar.

9. Cookies

This website uses no tracking or marketing cookies. Only technically necessary settings (e.g. your light/dark theme choice) are stored locally in your browser (localStorage) and not transmitted to us.

→ To the imprint