DigitalArtDeco Labs
Privacy Policy
English translation of the German privacy policy.
1. Controller and contact
DigitalArtDeco Labs UG (haftungsbeschränkt)
Sperberweg 27
86609 Donauwörth
Germany
Represented by Managing Director Harun Aktas.
Email: info@dadlabs.de
Telephone: +49 176 48296275
You can use these contact details for privacy enquiries and to exercise your rights. This policy applies to our corporate website at dadlabs.de and www.dadlabs.de, including result views and documentation.
2. Website delivery and hosting
The website is hosted on webspace provided by united-domains GmbH, Gautinger Straße 10, 82319 Starnberg, Germany. When a page is requested, the server receives your IP address and the requested address. Depending on the request and server configuration, this may also include the time, response status, volume transferred, browser and operating system information, and a referring address supplied by the browser. Failed requests and sign in attempts may also generate technical logs.
Purposes and legal basis: We need this processing to deliver requested pages and files, investigate errors and prevent unauthorised access. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is an accessible corporate website protected against misuse. Without the data required for the connection, the server cannot deliver the website.
Recipients and processing on our behalf: The hosting provider and technical providers involved in operation and security may process these data. Processing on our behalf is subject to Article 28 GDPR. We have concluded a data processing agreement with united-domains. The agreement in version 1.5.11 addresses processing under instructions, confidentiality, assistance with data subject rights and security measures. Annex 1 lists the following subprocessors for the services described there:
- NorthC Deutschland GmbH, Nuremberg: accommodation of servers for webspace and email.
- IONOS SE, Montabaur: webspace, website builders and domain name servers.
- Akamai Technologies GmbH, Garching: in connection with protection against DDoS attacks.
- Open-Xchange GmbH, Olpe: for some of the provider's email services.
This list covers the services described by the hosting provider as a whole. It does not mean that every listed provider receives data on every visit to our website, or that we use a website builder. The product notice confirms IONOS SE as the webspace provider, with servers in Germany. This does not establish involvement of all other listed providers in every processing operation.
Webspace and retention: The united-domains product privacy notice, Webspace section, specifies 8 weeks of retention at IONOS for the access data described there, for security and stability. According to the provider, the stored IP address is anonymised. The linked IONOS webhosting documentation confirms that period. It covers requested pages or files, referring address, browser, operating system, device type and access time.
Distinction from the general agreement: Annex 2, section 1.5 of the data processing agreement refers to partial pseudonymisation or deletion after 7 days without identifying individual log types. This general wording is not presented as a seven day period for the webspace access data described above. It does not establish a separate product period for other error, security or authentication logs. The provider's statement about anonymisation is not our own technical verification of that process.
Contract termination: Under clause 13(2), email and webspace hosting data are deleted automatically and immediately upon termination of the respective contract.
Provider backups: Under the same provision, any backups are normally deleted automatically within 14 days after contract termination or deletion of the original data. This period does not start simply when you visit the website or send a message. It concerns the provider's backup copies and is not a general retention period for our business correspondence.
The 14 day access log period listed under the website builder on the same provider page is not applied to this website. We do not use that builder. The page specifies no separate routine deletion period in days for the email mailbox.
3. Cookies, browser storage and consent
Our website code does not set or read cookies. It does not use Local Storage, Session Storage or IndexedDB. Our own code embeds no analytics tools, advertising pixels or techniques to recognise your device and creates no user profiles.
Hosting provider functions: In its Webspace section, united-domains reports that IONOS uses technically necessary cookies by default. Cookie names and lifetimes are not listed there. We therefore do not claim that the entire hosting environment is cookie free. The provider information does not specify which cookies are used for individual requests to our website.
The linked IONOS documentation also mentions WebAnalytics. Its product description describes collection through log files or a pixel without cookies. Whether and how this additional function operates in the package purchased through united-domains is not yet confirmed. Our own code contains no such pixel. The statement about our own code is not an assurance about every internal provider analysis.
The cookie notice explains this position. You can expand further information directly on the page. This does not save a cookie choice, identifier or consent record, and sends no data to a consent management provider.
Section 25 TDDDG generally requires informed consent before information is stored on or accessed from your device. Paragraph 2 provides narrowly defined exceptions, including operations strictly necessary for a digital service expressly requested by the user. Where delivery of our requested pages requires such operations, this exception applies. It does not authorise tracking.
Because our own website code uses no optional cookies or equivalent optional device access, there is no choice to accept or reject such services. The notice does not request consent. It also does not change the processing of technically required connection data on the server, which is explained separately in section 2.
If features requiring consent are introduced, they must remain inactive until appropriate prior consent is obtained. Equivalent rejection and straightforward withdrawal must then be provided, and this policy must be updated.
4. Interactive results and locally served content
Fonts, images, styles, scripts and result files are served from our webspace. We do not embed external font services, videos, maps or social plugins. This website has no contact form, newsletter or embedded chat.
Result selection, image enlargement, searching source records and verification of file hashes run in your browser. Search terms in the source register are not sent to us. Loading additional result files generates the server requests described in section 2. View parameters in an address you open are part of that requested address. We do not use them to create personal usage profiles.
Downloaded files and history or caching managed by the browser itself are subject to your browser settings. Our website code does not access these information stores for analytics.
5. Access to the website
The website is publicly accessible without an account or sign in. We do not collect usernames or passwords for access and set no login cookie of our own. The hosting provider processes the connection data described in section 2 when you request a page.
6. Contact by email or telephone
If you contact us, we process the information you provide, such as your name, contact details, time of contact, message and attachments. This serves to handle your enquiry and the related business correspondence. Responsible persons in our company and the email, telecommunications and IT providers used for that communication may receive these data.
Mailbox at united-domains: Our mailbox provider for info@dadlabs.de is united-domains GmbH, Gautinger Straße 10, 82319 Starnberg, Germany. The service receives and stores messages so that we can handle your enquiry. The provider processes sender and recipient details, message content, attachments and technical delivery data for this purpose. The new setup is not intended to forward messages to a personal mailbox. The supplied agreement for processing on our behalf described in section 2 also covers email services.
Article 6(1)(b) GDPR applies to a contract with you or steps taken at your request before entering into a contract. General enquiries and communication with representatives of other businesses are based on Article 6(1)(f) GDPR and our interest in providing an appropriate response. Statutory retention duties are based on Article 6(1)(c) GDPR.
Providing contact details and message content is voluntary. We may be unable to respond without the necessary information. Certain details may be required to enter into a contract. Please agree a suitable transmission method with us before sending confidential documents.
Deletion: Enquiry data are deleted once the matter is resolved and no further retention ground exists. Contract records or business correspondence may be subject to statutory retention duties. Information needed for a specific legal dispute may be retained until the matter is resolved and the relevant periods expire. The contractual rules for termination and backups are described in section 2. Neither the eight week retention of webspace access data nor the general log and backup periods constitute a deletion period for ongoing correspondence.
7. Processing locations and external links
The website contains ordinary links to external services, including GitHub as a source for development records. Our code does not automatically load embedded content from those providers. Opening an external link makes your browser connect to its destination. The destination provider's privacy information then applies; processing outside the European Economic Area may occur.
GitHub is used to develop and transfer our website, not to deliver it to visitors. The transfer process is not configured to read visitor logs or contact enquiries. A normal page request loads no resource from GitHub.
For processing on behalf of customers by united-domains, annex 2, section 4.1 of the supplied agreement expressly specifies processing exclusively within the European Union. This statement concerns the processing covered by that agreement. It is not an assurance about external websites you open through links or the providers used by people who communicate with us. IONOS and servers in Germany are identified for webspace; this does not automatically confirm every other provider service.
8. Your privacy rights
Subject to the applicable conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18) and portability (Article 20). Where processing is based on consent, you may withdraw it at any time for the future. Withdrawal does not affect processing carried out before it. You do not have to agree to this privacy policy.
Please contact info@dadlabs.de. If we have reasonable doubts about your identity, proportionate additional information may be needed to handle your request. The time limits and requirements of Article 12 GDPR apply.
Your right to object under Article 21 GDPR
You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will then stop processing the data concerned unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or processing serves to establish, exercise or defend legal claims.
9. Complaints
Under Article 77 GDPR, you may complain to a supervisory authority, particularly in the country of your habitual residence, place of work or the alleged infringement. You do not have to contact us first.
The authority generally responsible for private businesses at our location is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
Postal address: Postfach 1349, 91504 Ansbach, Germany.
Visitor address: Promenade 18, 91522 Ansbach.
BayLDA contact and complaint options.
10. Security and further information
The website is delivered over HTTPS. Encryption protects data in transit; it does not replace the required legal bases or privacy information. We do not make automated decisions with legal or similarly significant effects within the meaning of Article 22 GDPR on this website.
This policy will be updated when actual processing or legal requirements change. Relevant legislation includes the General Data Protection Regulation and section 25 TDDDG.
Updated: 21 September 2026.