Privacy Policy
Short version: this website uses a single, technically necessary cookie (language preference) and no tracking, analytics or advertising cookies. Contact-form submissions are transmitted to our backend over an encrypted connection and stored in our self-hosted CRM on our own server in Germany. Part of the processing is AI-assisted, and for that purpose content including message texts is transferred to a provider in the United States (section 6). No decision with legal effect is made in a fully automated way.
1. Controller
Controller within the meaning of the GDPR:
- Artyom Zemchenko
- Altmühlstraße 6, 33689 Bielefeld, Germany
- hallo@zemchenko.de
- +49 155 65531434
2. Principles of data processing
We process personal data only to the extent necessary to provide a functioning website and our content and services. Legal bases in particular are:
- Art. 6(1)(b) GDPR – pre-contractual measures and processing of your enquiry (contact form)
- Art. 6(1)(f) GDPR – legitimate interest (server log files for security, abuse/spam prevention, efficient handling of enquiries)
- Art. 6(1)(a) GDPR – consent, should future optional features require it
We do not use tracking, analytics or advertising cookies. No data is processed for advertising purposes or shared with ad networks.
3. Hosting & server log files
This website and the associated infrastructure (backend, CRM) run on our own, self-managed server with FastVPS, located in Germany. This is a self-hosted environment: your data does not sit with a cloud CRM or a third-party application provider.
For individual purposes that are named explicitly in this policy, data does nevertheless leave this infrastructure: AI-assisted processing (section 6), storage of files in a connected cloud storage account (section 5), use of the CRM through an external assistant (section 6) and communication via messenger services (section 7). No transfer takes place beyond that.
The web server automatically stores the following data in server log files on every access:
- IP address of the requesting device
- date and time of access
- URL accessed
- HTTP status code and amount of data transferred
- referrer URL (previous page, if transmitted)
- browser and operating system (user agent)
This data is processed solely to ensure operation, for error analysis and to defend against attacks (Art. 6(1)(f) GDPR), and is deleted once it is no longer required for those purposes, unless it is needed to investigate a specific security incident. It is not shared with third parties.
4. Contact form
When you use the contact form on our website, the data you provide is transmitted to our backend (/api/lead) over an encrypted HTTPS connection and stored in our CRM system to process your enquiry (see section 5).
Data processed from the form:
- name
- email address
- company (optional)
- content of your message
- selected language
- technical metadata for abuse detection: IP address, user agent, timestamp of submission, plus a hidden anti-spam field (honeypot) and a timing check between form load and submission
- origin details of the current visit: the address of the page the form was submitted from, the referring website (referrer) where available, and campaign parameters from the address you opened (utm_source, utm_medium, utm_campaign, utm_content, utm_term)
These origin details relate solely to the current page view and are read only from the address you opened and your browser's referrer header. No cookies, no local storage and no other information are stored on or read from your device for this purpose; there is no recognition across visits and no profiling. The details are stored together with your enquiry and serve exclusively to understand which route the enquiry came through (Art. 6(1)(f) GDPR).
Your email address is used exclusively to send you an automatic confirmation of receipt and to reply to your enquiry — not for advertising or newsletters.
In addition to being stored, the content of your enquiry is forwarded by email to our internal inbox (hallo@zemchenko.de) so that we can respond promptly. This inbox is hosted on our own infrastructure in Germany and is not shared with third parties.
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in handling enquiries and preventing spam). The data is used exclusively to process your enquiry; no automated decision-making takes place. Data is deleted once it is no longer required for processing – see section 5 for retention periods.
5. CRM & customer management
Enquiries submitted via the contact form, and any resulting customer relationships, are managed in a self-hosted CRM system on our own infrastructure in Germany. Data is not transferred to cloud CRM providers outside this infrastructure.
Data processed: contact details, communication history, and project-related information you share with us as part of an enquiry or collaboration.
Files you send us, or that we file against your case, are stored in the CRM system. If a cloud storage account is connected there, these files are placed in that connected Google Drive account; the operator is Google Ireland Limited, and processing may also take place in the United States. If no cloud storage is connected, the files remain in the database on our server in Germany.
Only authorised individuals have access to the CRM (Artyom Zemchenko and, where applicable, contractually bound, confidentiality-obligated processors).
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures and contract performance) and Art. 6(1)(f) GDPR (legitimate interest in structured customer management). Retention period: for the duration of the business relationship plus statutory retention periods (generally 6–10 years under German commercial/tax law once a contract is concluded); enquiries that do not lead to a contract are deleted once it is apparent that no engagement will follow, and no later than after 3 years.
6. AI-assisted processing (AI agents)
We use AI-assisted systems to pre-qualify and categorise enquiries, to analyse correspondence and to draft replies. We do not operate these systems ourselves: the content is transferred to the provider of the language model for processing.
Recipients, place of processing and third-country transfer
The provider currently used is Google, with the Gemini API service, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Processing takes place in the United States. This third-country transfer is based on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR together with the provider's data processing terms. According to the provider, content transferred under the paid tier we use is not used to train its models; we do not use free tiers.
Which content is transferred
Which data the system is allowed to transfer is released group by group in the CRM system. Correspondence is currently released. This means that the texts of messages from all connected channels, including WhatsApp, are transferred to the provider named above. File attachments themselves are not transferred; a file's name, size and date may be.
Regular automated processing
Part of this processing runs regularly and by itself, without a person selecting the individual message: the system checks newly received and sent messages across all channels for commitments left open and questions left unanswered, and transfers the message texts to the language model provider for that purpose. The result is a work list for a human being, not a decision about you.
No decision is made in a solely automated way that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR. All communication with you remains the responsibility of Artyom Zemchenko and is reviewed manually where necessary.
Transparency under the EU AI Act (Regulation (EU) 2024/1689): where you interact directly with an AI system (e.g. a chat or voice agent rather than a natural person), you will be informed of this separately in accordance with Art. 50 AI Act.
Use of the CRM system through an external assistant
We partly work with the CRM system through an interface for AI assistants. Where the Claude application is used for this, the content retrieved is transferred to its provider, Anthropic PBC, San Francisco, California, USA, and processed there. This recipient is independent of the language model provider named above, so it is a second transfer to the United States. It, too, is based on Standard Contractual Clauses under Art. 46(2)(c) GDPR. Only what is released in the CRM system can be retrieved, currently including correspondence.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in efficient and timely handling of enquiries). You may object to this processing at any time under Art. 21 GDPR. We will then no longer transfer any content concerning you to the providers named above; an email to hallo@zemchenko.de is sufficient.
7. Communication channels
We generally use the channels you choose to communicate with prospects and customers (e.g. email, phone).
We additionally offer a contact option via WhatsApp on the website (button in the bottom-right corner). This is a plain wa.me link with no embedded WhatsApp script or SDK on our site: clicking it opens WhatsApp with a pre-filled message text, and at that point no data is transmitted from our website to WhatsApp. If you continue the chat, you leave our website and the message is transmitted via the app or web service of WhatsApp Ireland Limited (part of Meta); WhatsApp/Meta's own privacy policy then applies, which we have no influence over (https://www.whatsapp.com/legal/privacy-policy). The legal basis for offering this contact option is Art. 6(1)(f) GDPR (legitimate interest in a low-barrier contact channel).
Should further communication channels (e.g. a chat widget from our CRM) be connected in production, we will inform you separately at this point, before active use, about the respective provider, the data transmitted and the legal basis.
8. Communication via WhatsApp
You can contact us via WhatsApp. Using it is voluntary. You can equally reach us by email at hallo@zemchenko.de, by phone or through the contact form on this website.
Data processed
If you write to us on WhatsApp, we process your mobile number, the profile name you have set, the content of your messages including any files sent with them, and the time, delivery status and read receipt of those messages.
If you change a message you have already sent, we take over the changed version with a note that it was edited. If you delete a message for everyone, it is no longer displayed on our side; the entry nevertheless remains in the system until it is removed as part of an erasure under section 10 or once the retention period has expired.
Where our CRM system is connected to a mobile phone, WhatsApp may additionally transfer that phone's existing chat history to us. Messages from the period before the connection are then also stored in the CRM system. The contacts stored on the phone are transferred as well, with name and phone number. Those entries do not become customer records; they are used solely to display the corresponding name for an incoming number.
Purpose and legal basis
The processing serves to answer your enquiry and to support existing business relationships. The legal basis is Art. 6(1)(b) GDPR where the communication serves the initiation or performance of a contract, and otherwise Art. 6(1)(f) GDPR, based on our legitimate interest in being reachable quickly and conveniently for you.
We do not contact you on WhatsApp unsolicited. We only send messages if you have contacted us beforehand or have expressly agreed.
Storage in the CRM system
We use the WhatsApp Business Platform. Your messages are additionally stored in our CRM system, which runs on a server in Germany. Messages we send from the WhatsApp Business app on a mobile phone are stored there as well. For you this means that the conversation is stored regardless of whether we reply from the CRM system or from the phone. Access is limited to the people involved in handling your enquiry.
Files sent with a message are retrieved from WhatsApp and filed in the CRM system. If a cloud storage account is connected there, section 5 applies to those files accordingly.
Recipients and third-country transfer
The service is operated by WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. WhatsApp is independently responsible for operating the platform under data protection law. Data may be transferred to Meta Platforms, Inc. in the USA and processed there. For details, see WhatsApp's privacy policy at https://www.whatsapp.com/legal/privacy-policy-eea
Please note that WhatsApp processes connection and usage data independently of the content of your message. We have no influence over that processing.
Beyond WhatsApp, the texts of your messages are received by the recipients named in section 6: the language model provider (Google, United States) as part of the AI-assisted processing and, where we use the CRM system through the external assistant described there, Anthropic PBC (United States). Both transfers are based on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR.
Retention period
Messages from business enquiries are kept for the duration of the business relationship and beyond that within the statutory retention periods. Enquiries that do not lead to a business relationship are deleted after six months at the latest.
Your rights
You may object to the processing at any time and request the erasure of your data. How to do so is described at zemchenko.de/datenloeschung (in German).
10. Your rights
As a data subject, you have the following rights under the GDPR:
- Access (Art. 15 GDPR): you may request information about the data we hold about you.
- Rectification (Art. 16 GDPR): you may request correction of inaccurate data.
- Erasure (Art. 17 GDPR): you may request deletion of your data, unless a statutory retention obligation applies.
- Restriction (Art. 18 GDPR): you may request restriction of processing.
- Data portability (Art. 20 GDPR): you may receive your data in a structured, commonly used format.
- Objection (Art. 21 GDPR): you may object to processing based on Art. 6(1)(f) GDPR.
- Withdrawal of consent (Art. 7(3) GDPR): any consent given may be withdrawn at any time with effect for the future.
A step-by-step description of how to request the erasure of your data is available at zemchenko.de/datenloeschung (in German).
Right to lodge a complaint: you have the right to lodge a complaint with a data protection supervisory authority. The competent authority for North Rhine-Westphalia is the Landesbeauftragte für Datenschutz und Informationsfreiheit NRW, Postfach 20 04 44, 40102 Düsseldorf, www.ldi.nrw.de.
For all data protection enquiries, please contact hallo@zemchenko.de.
11. Changes to this policy
We reserve the right to amend this privacy policy where required due to changes in law, new features (e.g. further communication channels, AI providers) or changes to the website. The current version is always available on this page.