Privacy policy
Protecting personal data matters to us. This notice explains which data we process when you visit cevelar.com and use the early-access form, on what legal basis, and what rights you have. The legal framework is the EU General Data Protection Regulation (GDPR), together with the German Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).
Who processes your data
The controller within the meaning of Art. 4(7) GDPR is:
Full legal disclosure (Impressum): maxbeitler.com/impressum (German).
What data we process
2.1 Visiting the website (server logs)
When you open this site, the hosting provider (see section 3) collects technically necessary connection data. This typically includes:
- IP address of the requesting device
- Date and time of access
- Requested URL / HTTP method and status code
- Amount of data transferred
- User-Agent (browser and OS identifier)
- Referrer URL (if sent by the browser)
Purpose: operating and securing the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning web presence). We do not merge this data with personal data from other sources.
2.2 Early-access form (waitlist)
If you submit your email via the early-access form, we process only the email address you enter, the time of submission, and a technical source label (landing_page or landing_page_en) to detect duplicate sign-ups. We also generate a personal referral code; if you submit a referral code, we process it to attribute your sign-up to the referring participant. This lets us track which sign-ups came from which code. In addition, your address is stored in a contact audience with our email delivery provider Resend to manage early-access communication.
Purpose: adding you to the early-access list, sending an automated submission confirmation, notifying our team about new sign-ups, prioritising queue position based on valid referrals, and contacting you individually about Cevelar before public launch. Legal basis: Art. 6(1)(a) GDPR (your consent by actively submitting the form). Without this information we cannot offer early access, no other processing occurs.
You may withdraw consent at any time without giving reasons by sending an informal message to [email protected]. Lawfulness of processing before withdrawal remains unaffected.
2.3 Local storage in the browser
After a successful sign-up, your browser may store an entry in localStorage (key cevelar_waitlist). It contains the submitted email and a timestamp and is used solely to recognise repeat submissions in the same browser. It never leaves your device.
We also store your language preference (cevelar_lang: de or en) when you use the language switcher, so we can respect your choice on later visits.
Legal basis: Art. 6(1)(f) GDPR in conjunction with § 25(2) no. 2 TDDDG (strictly necessary to provide a service you explicitly request). You can remove these entries in your browser settings at any time.
We do not use cookies for tracking, analytics, or advertising.
Sub-processors and third-party services
We use carefully selected providers to operate the website. Data processing agreements pursuant to Art. 28 GDPR are in place with processors.
Emails captured via the early-access form are stored in a managed PostgreSQL database. Data is hosted in the Frankfurt region (Germany). Provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 (service control entity). Art. 28 DPA in place, see supabase.com/privacy.
We use Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, to handle early-access emails. For each new sign-up, Resend sends a confirmation email to the submitted address, sends an internal notification to our team, and stores the address in a dedicated contact audience to manage early-access communication. Privacy policy: resend.com/legal/privacy-policy.
Static site files are delivered via Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Traffic from Europe is often served from EU edge locations; control instances and logs may be in the USA. Art. 28 DPA in place, see vercel.com/legal/privacy-policy. Transfers to the USA rely on the EU–US Data Privacy Framework (where certified) and the EU Commission’s Standard Contractual Clauses.
All fonts (Spectral, IBM Plex Sans/Mono) are served exclusively from our own server in Frankfurt. No connection to Google servers (fonts.googleapis.com, fonts.gstatic.com) is made; your IP address is not transmitted to Google.
The client library that connects to the waitlist database (@supabase/supabase-js) is loaded from the public CDN jsDelivr (operated by Prospect One Sp. z o.o., Poznań, Poland; technically delivered via e.g. Fastly/Cloudflare). Your IP address is sent to the CDN node. Details: jsdelivr.com/terms/privacy-policy-jsdelivr-net.
How long we keep data
- Email, referral code and referral attribution (waitlist): until you withdraw consent, at longest until the Cevelar project ends. We delete on informal request without undue delay.
- Server logs: typically deleted or anonymised by the host within a few days.
- Statutory retention periods (e.g. commercial or tax law) remain unaffected; they rarely apply in this context.
Transfers outside the EEA
Personal data may be transferred to third countries as described in section 3 (notably the USA). Such transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework (Art. 45 GDPR), where the provider is certified, supplemented by the Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Data subject rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
To exercise these rights, contact us informally at [email protected].
Supervisory authority
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). For this controller:
Supervisory authority
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61, 10555 Berlin, Germany
Updates to this notice
We may update this privacy policy to reflect legal requirements or changes to our services (e.g. new features). The version published here applies on your next visit.