Privacy.
Courtesy translation. The German version is legally binding.
In one sentence: This website sets no cookies, loads no external trackers or scripts and uses no fingerprinting. We process personal data only insofar as this is technically necessary to deliver the website, or when you write to us or apply as a design partner.
§ 1 Controller
Christian Schappeit — protagx
Nußbaumallee 27
14050 Berlin
Germany
Email: hello@protagx.com
§ 1a Data Protection Officer and CMP42 as GDPR expertise
For the processing described on this website — server logs, applications and email contact — the formal appointment thresholds under § 38(1) BDSG are not met: fewer than twenty people are permanently engaged in automated processing (sentence 1), no Data Protection Impact Assessment is required (sentence 2 in conjunction with Art. 35 GDPR), and no commercial transmission or market/opinion research takes place (sentence 3). The triggers under Art. 37(1) GDPR — public authority, large-scale regular and systematic monitoring, large-scale processing of special categories — do not apply to the operation of this website either.
We therefore do not appoint a data protection officer for website operations. Where customers use CMP42 as a processing solution (see § 13), the data protection responsibilities are regulated concretely in the data processing agreement — including impact assessment, notification procedures and sub-processors. As soon as protagx — with any single customer or across customers — reaches processing volumes that trigger a DPO under the above criteria, a data protection officer will be appointed and named here.
For data protection enquiries, the contact in § 10 is responsible in any case.
§ 2 Overview: purposes, data, legal bases
| Purpose | Data | Legal basis | Retention period |
|---|---|---|---|
| Delivery and security of the website | Truncated IP address, date/time, requested URL, status code, user agent, referrer | Art. 6(1)(f) GDPR (legitimate interest in operation and security) | 7 days |
| Design partner application | Form data (see § 6) | Art. 6(1)(b) GDPR (pre-contractual measures at your request) | see § 6 |
| Replying to your email | Name, email address, content of the message | Art. 6(1)(b) or (f) GDPR (communication at your request) | until the matter is resolved, thereafter statutory retention periods |
| Performance of contracts and accounting | Master, contract and billing data | Art. 6(1)(b) and (c) GDPR | statutory periods (§ 257 HGB, § 147 AO: up to 10 years) |
§ 3 No cookies, no access to your device
This website sets no cookies and uses neither local storage, session storage nor IndexedDB. It loads no scripts, fonts, maps or videos from third parties; all files are served from our own server. A Content Security Policy technically prevents external resources from being loaded.
As no information is stored in or read from your terminal equipment, consent pursuant to § 25 TDDDG is not required — which is also why there is no cookie banner.
§ 4 Server logs
When you access the website, our web server processes technically necessary access data:
- IP address, truncated before storage (IPv4: last octet, IPv6: to /48)
- date and time of the request
- requested URL and HTTP status code
- user agent (browser identifier)
- referrer (referring page)
The logs serve exclusively for secure operation (e.g. error analysis, defence against attacks) and are automatically deleted after 7 days. They are not combined with other data sources or analysed to create usage profiles. IP truncation and 7-day rotation are implemented in nginx. The upstream Traefik reverse proxy logs requests only for operational purposes and does not itself store client IP addresses beyond the active connection.
§ 5 Hosting
This website and the application endpoint are operated on a server provided by:
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
The server is located in Germany (Falkenstein or Nuremberg data centres). A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner, dated 24 April 2025, covering both data centre locations.
§ 6 Design partner application
If you apply using the form on the design partner page, we process the data you provide there: name, company, role, email address, company website, team size, CRM and AI tool in use, and your free-text entries. Mandatory fields are name, company, email address and the description of your workflow; all other information is voluntary.
The purpose is to review your application, arrange the 15-minute call and, where applicable, admit you to the design partner programme. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request).
How the transmission works: The form is transmitted to our server in encrypted form (HTTPS). A small service validates the information and forwards it as an email to our mailbox hello@protagx.com. The application is not stored on the web server; the server logs contain no form content. We do not send any automated emails to the address provided and do not add you to any mailing list.
Retention period: If no collaboration results, we delete your application no later than twelve months after completion of the application process. This period covers the six-month programme term and a subsequent replacement phase during which vacated places may be filled from the original applicant pool. If a contract is concluded, the periods set out in § 2 apply.
§ 7 Contact by email
If you send us an email, we process your information in order to deal with your enquiry (Art. 6(1)(b) GDPR for contract-related enquiries, otherwise point (f)). We delete the correspondence once the matter has been resolved, unless statutory retention obligations prevent this.
§ 8 Recipients
We disclose personal data only insofar as this is necessary for the purposes stated:
- Hosting provider: Hetzner Online GmbH (Germany), see § 5.
- Email mailbox hello@protagx.com: Google Workspace, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place. Google Ireland engages sub-processors of its parent company Google LLC (USA); the transfer is safeguarded by EU Commission Standard Contractual Clauses and supplementary technical measures. Google LLC is additionally certified under the EU-U.S. Data Privacy Framework.
- Sending of application notifications: Twilio SendGrid, operated by Twilio Ireland Limited, 25-28 North Wall Quay, Dublin 1, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place. Twilio Ireland engages sub-processors of its parent company Twilio Inc. (USA); the transfer is safeguarded by Standard Contractual Clauses and supplementary technical measures. Twilio Inc. is likewise certified under the EU-U.S. Data Privacy Framework.
- Tax advisory services and accounting software within the scope of statutory retention obligations (§ 257 HGB, § 147 AO). The specific recipients will be named on request under the right of access (§ 10).
§ 9 Transfers to third countries
The processing by the email mailbox (Google Workspace) and the mail-delivery service (Twilio SendGrid) takes place primarily in the European Union. Both providers engage sub-processors of their US parent companies. Transfers to the USA are safeguarded by EU Commission Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with supplementary technical and organisational measures; both parent companies are additionally certified under the EU-U.S. Data Privacy Framework (adequacy decision of the EU Commission dated 10 July 2023, Art. 45 GDPR). For the operation of the website itself (hosting, server logs), no transfer outside the EEA takes place.
§ 10 Your rights
You have the following rights at any time:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR), unless a retention obligation prevents this
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
An informal message is sufficient: hello@protagx.com — Art. 15 GDPR request. We will respond within the statutory period of one month.
§ 11 Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you may lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59–61, 10555 Berlin
datenschutz-berlin.de
§ 12 Security
All connections to this website are encrypted via TLS; HTTP Strict Transport Security (HSTS) enforces HTTPS. A restrictive Content Security Policy prevents external scripts and resources from being loaded.
§ 13 CMP42 as a product
This policy relates to the website cmp42.com. Where companies use CMP42 as a design partner or customer, we process the data entered there as a processor on behalf of the respective company. For this purpose we conclude a data processing agreement pursuant to Art. 28 GDPR; the customer company is the controller.
§ 14 Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
§ 15 Changes
We will amend this policy if the legal situation or the functions of the website change. The version published here at any given time applies.
Last updated: 19 September 2026