Privacy Policy

Last updated: April 16, 2026

Who we are

edvone.dev is operated by Edvard Grei, a freelance system architect based in Aachen, Germany. Contact: [email protected].

What data we collect

We collect only what is necessary to provide our services:

  • Booking requests: name, email, company (optional), message, selected time slot, timezone.
  • Email subscriptions: email address and the page you subscribed from.
  • Contact form submissions: name, email, company, message.
  • Co-founder pitch submissions: the information you provide in the pitch form, plus any attachments you upload.
  • Client portal: project-related data (secrets, server info, files, invoices) shared between you and Edvard within your project scope.
  • Analytics: anonymous page views with path, referrer, UTM parameters, and approximate location (country and city from Cloudflare headers). No cookies are used for tracking beyond an anonymous session identifier that contains no personal information.

How we use your data

  • To process and respond to your booking requests.
  • To send you the letters you subscribed to.
  • To respond to contact and pitch submissions.
  • To provide project management services via the client portal.
  • To understand how visitors use the site (anonymous analytics).

We do not sell, rent, or share your personal data with third parties for marketing purposes.

Where your data is stored

  • Database: Neon Postgres (EU region, eu-central-1).
  • File storage: Cloudflare R2 (private bucket with encrypted access). Pitch attachments and project files are accessible only via short-lived presigned URLs.
  • Email: sent via Resend (US-based, GDPR DPA available).
  • Hosting: Hetzner Cloud (Germany and Finland).

Data encryption

Client portal secrets and server credentials are encrypted at rest using AES-256-GCM. The encryption key is stored separately from the database and is never transmitted to the client in cleartext outside of authenticated portal sessions.

Your rights (GDPR and UK GDPR)

As a resident of the EU or the United Kingdom, you have the right to access, correct, delete, or export your personal data. To exercise any of these rights, email [email protected]. We will respond within 30 days.

California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion of your personal information, and to opt out of the sale of your personal information. We do not sell personal information to third parties. To exercise your rights, email [email protected].

Cookies

We use only functional cookies: session cookies for authentication (admin and client portal) and an anonymous analytics cookie that contains a random identifier with no personal information. We do not use advertising or third-party tracking cookies.

Third-party services

  • Google Calendar API: used to check availability for booking. We request read-only access to your free/busy status. No calendar content is stored.
  • Cloudflare: CDN and DNS. Cloudflare may set its own cookies for security purposes.

Data retention

We retain your data only as long as necessary to provide the service you requested. Booking data is kept for 12 months after the booking date. Email subscriptions are kept until you unsubscribe. Client portal data is retained for the duration of the project engagement plus 6 months, unless a longer retention period is required by German tax law (10 years for invoices per AO §147). Anonymous analytics data is retained for 24 months.

Data breach notification

In the event of a data breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33/34.

Legal basis for processing (GDPR Art. 6)

  • Contract performance (Art. 6(1)(b)): booking requests, client portal data, invoicing.
  • Legitimate interest (Art. 6(1)(f)): anonymous analytics, security logging, spam prevention.
  • Consent (Art. 6(1)(a)): email subscriptions. You can withdraw consent at any time by emailing [email protected].

International data transfers

Some data processors (Resend for email delivery) are based in the United States. Transfers are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission. All primary data storage (database, file storage, hosting) remains within the EU.

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the most recent revision. Continued use of the site after changes constitutes acceptance.

Contact & supervisory authority

For any privacy-related questions: [email protected]

Edvard Grei · Aachen, Germany

You have the right to lodge a complaint with the competent supervisory authority. For North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit NRW