Legal · Privacy

Privacy policy

Effective: 21 April 2026 · Applies to cevelar.com · GDPR · BDSG · TDDDG

Protecting personal data matters to us. This notice explains which data we process when you visit cevelar.com and use the early-access form, on what legal basis, and what rights you have. The legal framework is the EU General Data Protection Regulation (GDPR), together with the German Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

Who processes your data

The controller within the meaning of Art. 4(7) GDPR is:

Max Beitler

Hedemannstraße 27

10963 Berlin

Germany

Email: [email protected]

Full legal disclosure (Impressum): maxbeitler.com/impressum (German).

What data we process

2.1 Visiting the website (server logs)

When you open this site, the hosting provider (see section 3) collects technically necessary connection data. This typically includes:

Purpose: operating and securing the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning web presence). We do not merge this data with personal data from other sources.

2.2 Early-access form (waitlist)

If you submit your email via the early-access form, we process only the email address you enter, the time of submission, and a technical source label (landing_page or landing_page_en) to detect duplicate sign-ups. We also generate a personal referral code; if you submit a referral code, we process it to attribute your sign-up to the referring participant. This lets us track which sign-ups came from which code. In addition, your address is stored in a contact audience with our email delivery provider Resend to manage early-access communication.

Purpose: adding you to the early-access list, sending an automated submission confirmation, notifying our team about new sign-ups, prioritising queue position based on valid referrals, and contacting you individually about Cevelar before public launch. Legal basis: Art. 6(1)(a) GDPR (your consent by actively submitting the form). Without this information we cannot offer early access, no other processing occurs.

You may withdraw consent at any time without giving reasons by sending an informal message to [email protected]. Lawfulness of processing before withdrawal remains unaffected.

2.3 Local storage in the browser

After a successful sign-up, your browser may store an entry in localStorage (key cevelar_waitlist). It contains the submitted email and a timestamp and is used solely to recognise repeat submissions in the same browser. It never leaves your device.

We also store your language preference (cevelar_lang: de or en) when you use the language switcher, so we can respect your choice on later visits.

Legal basis: Art. 6(1)(f) GDPR in conjunction with § 25(2) no. 2 TDDDG (strictly necessary to provide a service you explicitly request). You can remove these entries in your browser settings at any time.

We do not use cookies for tracking, analytics, or advertising.

Sub-processors and third-party services

We use carefully selected providers to operate the website. Data processing agreements pursuant to Art. 28 GDPR are in place with processors.

Supabase (database) DB: EU · Frankfurt

Emails captured via the early-access form are stored in a managed PostgreSQL database. Data is hosted in the Frankfurt region (Germany). Provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 (service control entity). Art. 28 DPA in place, see supabase.com/privacy.

Purpose: waitlist storage · Legal basis: Art. 6(1)(a) · DPA: Art. 28 GDPR
Resend (email delivery and contacts) Company: USA · transactional email

We use Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, to handle early-access emails. For each new sign-up, Resend sends a confirmation email to the submitted address, sends an internal notification to our team, and stores the address in a dedicated contact audience to manage early-access communication. Privacy policy: resend.com/legal/privacy-policy.

Purpose: transactional confirmation, internal notification, contact management · Legal basis: Art. 6(1)(a) · Transfer: Art. 45 / 46 GDPR
Vercel (hosting) Company: USA · Edge: EU

Static site files are delivered via Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Traffic from Europe is often served from EU edge locations; control instances and logs may be in the USA. Art. 28 DPA in place, see vercel.com/legal/privacy-policy. Transfers to the USA rely on the EU–US Data Privacy Framework (where certified) and the EU Commission’s Standard Contractual Clauses.

Purpose: technical delivery · Legal basis: Art. 6(1)(f) · Transfer: Art. 45 / 46 GDPR
Fonts (self-hosted) EU · no Google

All fonts (Spectral, IBM Plex Sans/Mono) are served exclusively from our own server in Frankfurt. No connection to Google servers (fonts.googleapis.com, fonts.gstatic.com) is made; your IP address is not transmitted to Google.

Purpose: typography / display · Legal basis: Art. 6(1)(f) · Transfer: none (EU hosting)
jsDelivr (CDN) Global CDN

The client library that connects to the waitlist database (@supabase/supabase-js) is loaded from the public CDN jsDelivr (operated by Prospect One Sp. z o.o., Poznań, Poland; technically delivered via e.g. Fastly/Cloudflare). Your IP address is sent to the CDN node. Details: jsdelivr.com/terms/privacy-policy-jsdelivr-net.

Purpose: deliver client library · Legal basis: Art. 6(1)(f)

How long we keep data

Transfers outside the EEA

Personal data may be transferred to third countries as described in section 3 (notably the USA). Such transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework (Art. 45 GDPR), where the provider is certified, supplemented by the Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR).

Data subject rights

You have the following rights regarding your personal data:

To exercise these rights, contact us informally at [email protected].

Supervisory authority

Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). For this controller:

Supervisory authority

Berlin Commissioner for Data Protection and Freedom of Information

Alt-Moabit 59–61, 10555 Berlin, Germany

www.datenschutz-berlin.de

Updates to this notice

We may update this privacy policy to reflect legal requirements or changes to our services (e.g. new features). The version published here applies on your next visit.