Privacy Policy
Last updated: 14 September 2026
Website: www.finnfaust.com
Controller: Finn Faust, Finn Faust Web Design
1. Controller and contact details
The controller responsible for the processing of personal data on this website is:
Finn Faust Web Design
Finn Faust, Roonstraße 55, 28203 Bremen, Germany
Email: letstalk@finnfaust.com
We have not appointed a Data Protection Officer, because we are not required to do so under Art. 37 GDPR. For any question about this Privacy Policy or about your data, please use the contact details above.
2. What this website does, and what it does not do
This is a marketing website for a freelance web design practice. It has no user accounts, no online shop, no contact form and no newsletter. It sets no cookies, it does not use local storage and it does not use device fingerprinting or cross-site tracking. For that reason it shows no cookie banner.
Personal data is processed in connection with this website for the following purposes:
- Hosting, delivery and security (Webflow and its sub-processors)
- Server log data (operation, troubleshooting and IT security)
- Aggregated website statistics (Plausible Analytics, without cookies)
- Delivery of an open-source library (jsDelivr, for the image slider)
- Communication (when you email us, call us, or book an appointment)
3. Your rights
You have the following rights in relation to the personal data we process about you:
- Access to your data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests, including the server log data and the aggregated statistics described below (Art. 21 GDPR)
- Withdrawal of consent at any time, in the event that processing is ever based on consent (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out beforehand.
To exercise any of these rights, or to object to processing, email letstalk@finnfaust.com. We reply within one month, as required by Art. 12(3) GDPR.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU or EEA country of your residence, your place of work, or the place of the alleged infringement. The authority responsible for us is: Der Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen, Georgstraße 122-124, 27570 Bremerhaven, Germany.
4. Hosting, delivery and log files
4.1 Webflow hosting
This website is built and hosted on the website platform Webflow. When you open a page, your browser connects to Webflow's servers and to its content delivery network.
Provider: Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA
Purpose: reliable operation, delivery, security, performance and administration of this website.
Data processed when you open a page:
- IP address
- Date and time of the request
- Requested page or file
- Referrer URL
- Browser and device information (user agent)
- Technical log data, such as error and security events
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the reliable, secure and performant provision of this website. Webflow acts as our processor under Art. 28 GDPR.
4.2 Data processing agreement and international transfers
We have concluded a data processing agreement (Data Processing Addendum) with Webflow:
https://webflow.com/legal/dpa
Further Webflow privacy resources, including its list of sub-processors:
https://webflow.com/legal/privacy
https://webflow.com/legal/privacy-faqs
https://webflow.com/legal/subprocessors
Personal data may be processed by Webflow in the United States or in other third countries. According to Webflow, such transfers take place only where an adequacy decision applies (Art. 45 GDPR) or on the basis of appropriate safeguards (Art. 46 GDPR), in particular standard contractual clauses.
Webflow's entry in the EU-U.S. Data Privacy Framework list:
https://www.dataprivacyframework.gov/participant/6365
4.3 Sub-processors used by Webflow (AWS and Cloudflare)
To deliver files quickly, Webflow uses infrastructure providers as sub-processors, in particular Amazon Web Services for cloud hosting and Cloudflare as a content delivery network (CDN). Files for this website are served from Webflow's own CDN domains. In this context, connection data such as your IP address, the time of the request and your browser and device information is processed by these providers.
Providers: Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA
Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany)
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and efficient delivery of this website.
Cloudflare privacy information:
https://www.cloudflare.com/privacypolicy/
Amazon Web Services privacy information:
https://aws.amazon.com/privacy/
4.4 Server log files
When you open this website, your device automatically transmits certain data for technical reasons, which may be stored in server log files by our hosting provider. The categories are those listed in section 4.1. We do not combine this data with other sources and we do not use it to identify you. Log data is kept only for as long as it is needed for operation, troubleshooting and IT security.
Purpose: operating and administering the website, ensuring IT security, preventing misuse, and analysing errors and unauthorised access. Legal basis: Art. 6(1)(f) GDPR.
4.5 Open-source CDN (jsDelivr)
This website loads the Swiper slider library from the open-source CDN jsDelivr (requests to cdn.jsdelivr.net). Your browser connects to jsDelivr's servers to fetch these files, so connection data such as your IP address, your browser and device information and the time of the request is processed there.
Provider: Volentio JSD Limited (trading as jsDelivr), Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, United Kingdom. The United Kingdom is covered by an adequacy decision of the European Commission.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the efficient and reliable delivery of static resources.
jsDelivr privacy policy:
https://www.jsdelivr.com/terms/privacy-policy
jsDelivr data processing agreement:
https://www.jsdelivr.com/documents/data-processing-agreement.pdf
Note: you can block this connection with a script blocker. Parts of this website, such as the image slider, may then not work.
5. Website statistics with Plausible Analytics
5.1 What we measure, and how
We use Plausible Analytics, a privacy-focused web analytics tool, to see in aggregate how this website is used, for example which pages are read and which sources bring visitors. Plausible sets no cookies, writes nothing to local storage and does not create a persistent identifier for you.
Plausible records the following information about a page view:
- The page URL
- The referrer, that is the page or source you came from
- Browser and browser version
- Operating system
- Device type
- Country, region and city, derived from the IP address
- Campaign parameters in the URL, such as utm_source, where present
- Date and time of the request
No cookies and no persistent identifiers: unique visitors are counted using a hash of a daily rotating salt, the website domain, your IP address and your user agent. The salt is deleted every 24 hours and the IP address itself is not stored, so visitors cannot be recognised across days, devices or websites, and the statistics cannot be traced back to you.
All statistics are processed and stored inside the European Union, on servers located in Germany. No data is transferred to a third country.
Provider: Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible acts as our processor on the basis of a data processing agreement under Art. 28 GDPR. Details of what Plausible collects are set out in its data policy at https://plausible.io/data-policy
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is understanding in aggregate how this website is used so that we can improve it, using a tool that does not track individuals. Because no information is stored on your device and no information stored on your device is accessed, no consent under § 25(1) TDDDG is required. You can object at any time under Art. 21 GDPR, and you can prevent the measurement by blocking the script in your browser or with an extension.
6. Cookies, local storage and consent
6.1 What this website stores on your device
Nothing. This website sets no cookies, uses no local or session storage and does not use device fingerprinting. Because no technologies requiring consent are in use, there is no cookie banner and no consent management tool on this website.
- No analytics, advertising or tracking cookies. Statistics are collected without cookies, as described in section 5.
- No third-party embeds. Videos, maps and booking widgets are not embedded here. Where we point to such services, we use plain links, so nothing is loaded from them unless you click.
If this changes in future, for example if we embed a video or a booking widget, we will introduce a consent mechanism and update this Privacy Policy before doing so.
6.2 What you can control in your browser
- Block scripts
You can block JavaScript and third-party connections with your browser settings or an extension. - Clear site data
You can delete data stored by any website at any time in your browser settings. - Expect some impact
Blocking scripts may stop parts of this website working, for example the image slider. - Server logs are separate
Log data recorded by our hosting provider is not affected by these browser settings.
7. Contact by email and phone
- What we process: your email address or phone number, the content of your message, and any details you choose to share with us.
- Legal basis: Art. 6(1)(b) GDPR where your enquiry concerns a contract or steps prior to a contract, otherwise Art. 6(1)(f) GDPR, our legitimate interest being to respond to enquiries.
8. Appointment booking (Calendly)
This website does not embed a booking widget. It links to our Calendly page. Nothing is sent to Calendly before you click that link, and when you do, you leave this website.
If you book a call, Calendly processes the details you enter on our behalf, as our processor under Art. 28 GDPR, and we receive the booking. The provider is Calendly, LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA.
Data processed when you book:
Your name, your email address, the date, time and time zone of the appointment, anything you enter in the booking form, and technical data such as your IP address and browser information.
Legal basis: Art. 6(1)(b) GDPR, steps taken at your request prior to entering into a contract.
Transfers to the United States are based on Calendly's certification under the EU-U.S. Data Privacy Framework and, where applicable, on standard contractual clauses with additional safeguards.
Calendly privacy notice:
https://calendly.com/legal/privacy-notice
9. Links to social profiles
This website links to our profiles on LinkedIn, Instagram and YouTube. These are plain links, not embedded widgets or social plugins, so no data is sent to those providers while you are on this website. If you click one, you leave this website and the provider processes your data as an independent controller under its own privacy policy.
Legal basis: Art. 6(1)(f) GDPR, our legitimate interest being to present our work and make our profiles easy to find.
Privacy information of these providers:
LinkedIn
Instagram
YouTube (Google)
10. Who receives your personal data
We do not sell personal data and we do not share it for advertising. Access is limited to the providers named in this policy, which act as our processors, and to platforms you choose to visit yourself, which act as independent controllers. In addition, our tax adviser and the tax authorities may receive business correspondence and invoices where statutory retention or reporting duties apply.
11. International data transfers
Website statistics stay inside the European Union. Hosting, content delivery and appointment booking involve providers in the United States and the United Kingdom. Transfers to the United Kingdom rely on the adequacy decision of the European Commission. Transfers to the United States rely on the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise on standard contractual clauses under Art. 46 GDPR, with additional measures where required. You can request details of these safeguards using the contact details in section 1.
12. How long we keep data
We keep personal data only for as long as it is needed for the purpose it was collected for:
- Server log data: only as long as necessary for operation, troubleshooting and IT security.
- Correspondence and booking data: for the duration of the enquiry or project, and afterwards for the statutory retention periods under German tax and commercial law, which are generally six to ten years for business correspondence and invoices.
Website statistics are aggregated and contain no personal identifiers, so they are not linked to you as an individual.
13. Automated decision-making and profiling
We do not use automated decision-making within the meaning of Art. 22 GDPR and we do not build profiles of individual visitors.
14. Whether you have to provide personal data
You are not obliged to provide personal data. Simply visiting this website involves only the technically necessary data described above. If you contact us or book a call, providing the requested details is voluntary, but without them we cannot reply or schedule a meeting.
15. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted transport (HTTPS/TLS), access controls, and two-factor authentication on the accounts used to administer this website.
16. Changes to this Privacy Policy
We update this Privacy Policy when this website, the tools we use or the legal requirements change. The current version is always the one published on this page.
Version of 14 September 2026.