Privacy Policy

1. Privacy at a Glance

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is all data with which you can be personally identified. Detailed information on the subject of data protection can be found in this privacy policy below.

2. Data Collection on this Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find their contact details in the section "Note on the responsible party" in this privacy policy.

How is your data collected?

Your data is collected on the one hand by you providing it to me. This can be, for example, data that you enter in a contact form.

Other data is collected automatically or after your consent when you visit the website by my IT systems. These are mainly technical data (e.g., internet browser, operating system or time of page access). The collection of this data takes place automatically as soon as you enter this website.

What is your data used for?

Some of the data is collected to ensure error-free provision of the website. Other data can be used to analyze your user behavior.

3. Hosting

I host this website with Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel processes data as part of providing the hosting service. For more information, see Vercel's privacy policy: https://vercel.com/legal/privacy-policy

Transfers to third countries

Where data is processed in the USA, I rely on appropriate safeguards under Art. 46 GDPR (e.g., EU Standard Contractual Clauses offered by the providers) in addition to technical and organizational measures.

4. AI Chatbot (Google Gemini)

This website uses an optional AI chatbot based on Google Gemini via the Gemini API. When you send a message, it is transmitted to Google for response generation. According to Google's API terms, prompts sent through the API are not used to improve Google's models.

EU AI Act Compliance

AI Transparency Notice

This website uses artificial intelligence to provide assistance. You are interacting with an AI system, not a human. This disclosure is required under the EU AI Act (Regulation (EU) 2024/1689).

AI Data Processing

Your messages are processed by AI systems for response generation. No personal data is permanently stored or used for AI training purposes beyond the current session.

AI Limitations

AI responses are for informational purposes only and should not be considered as professional advice. The AI system may occasionally provide inaccurate or incomplete information.

Your Rights Regarding AI

You have the right to know when you are interacting with AI systems, understand how your data is processed, and request information about AI decision-making processes.

What data is processed?

  • Your messages to the chatbot
  • IP address (for rate limiting)
  • Timestamps of interactions

Purpose of data processing

  • Provision of chatbot service
  • Prevention of abuse (rate limiting and CAPTCHA)
  • Technical operation of the website

Legal basis

Processing is based on Art. 6 Para. 1 lit. f GDPR (Legitimate interest in providing the service).

Storage period

Chat data is only stored temporarily for the duration of the session. IP data for rate limiting is stored for a maximum of 24 hours.

For more information on data processing by Google, see Google's privacy policy: https://policies.google.com/privacy

5. Protected Resume Download

If you request access to the resume (CV), I process the data you provide to verify your request, send access codes by email after manual approval, and enable a secure PDF download.

What data is processed?

  • Name, company, and email address from the request form
  • Hashed access code and expiry (not the plain code in my database)
  • Technical metadata such as IP address for abuse prevention
  • Email content when sending approval and access messages

Service providers (processors)

  • Vercel Inc. (USA) – hosting and API execution
  • Resend Inc. (USA) – transactional email delivery
  • Upstash Inc. (USA/EU depending on region) – storage of request and token metadata

Purpose

Controlled release of the resume to protect private contact details (e.g., phone number, address); prevention of abuse.

Legal basis

Art. 6 Para. 1 lit. f GDPR (legitimate interest in controlled sharing of application documents) and, where applicable, Art. 6 Para. 1 lit. b GDPR (steps prior to entering into a contract at your request).

Storage period

Request data and access metadata are stored until the access code expires (24 hours after approval) or until manual deletion. Rate-limit data is retained for up to 24 hours.

Transfers to third countries

Processing may involve the USA (Vercel, Resend, Upstash). I use provider safeguards under Art. 46 GDPR (e.g., Standard Contractual Clauses) where applicable.

6. Web Analytics (Vercel Analytics)

I use Vercel Web Analytics to measure aggregated page views and performance. This helps me understand how the website is used. Vercel states that Web Analytics does not use cookies for tracking and does not collect personal identifiers for profiling.

What data may be processed?

  • Page URL and referrer
  • Device type, browser, and operating system (aggregated)
  • Approximate geolocation (country/region level)
  • Timestamps of page views

Legal basis

Art. 6 Para. 1 lit. f GDPR (legitimate interest in a privacy-friendly, aggregated understanding of website usage).

Opt-out

You can block analytics by using browser tracking protection, ad blockers, or by disabling JavaScript. You can also contact me to object to this processing under Art. 21 GDPR.

Vercel Analytics privacy information

Note on the responsible party

The responsible party for data processing on this website is:

Dominik Kinzel
Software Developer
E-Mail: dominik_kinzel@t-online.de

Responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

8. Your Rights

You have the following rights regarding your personal data:

  • Right of access: You can request information about the processed data
  • Right of rectification: You can request the correction of incorrect data
  • Right of erasure: You can request the deletion of your data
  • Right of restriction: You can request the restriction of processing
  • Right of objection: You can object to the processing
  • Data portability: You can receive your data in a structured format

To exercise these rights, please contact me at: dominik_kinzel@t-online.de

9. Changes to this Privacy Policy

I reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to reflect changes to my services, e.g., when introducing new features. For your next visit, the updated privacy policy will then apply.

10. Contact

If you have questions about the collection, processing or use of your personal data, please contact:

Dominik Kinzel
E-Mail: dominik_kinzel@t-online.de

Dominik Kinzel - Microsoft 365 Developer