Privacy policy
We treat your personal data confidentially and in accordance with the General Data Protection Regulation (GDPR) and this privacy policy. This website went live on 20 August 2026. Last updated: August 2026.
1. Controller
The controller within the meaning of the GDPR is: 0030 Development, owner Tobias Wewer Königsberger Allee 113b 47058 Duisburg Germany Phone: shown once the page has loaded Email: 0030dev@protonmail.com Website: www.0030development.com Messengers (WhatsApp, Viber, Threema, Signal): see the contact area of our website
We are not legally required to appoint a data protection officer. For any privacy-related questions you can reach us directly using the contact details above.
2. Hosting and server log files
When you access this website, our hosting provider automatically processes technical data (IP address, date and time of access, page requested, volume of data transferred, browser type and version, operating system, referrer URL). This processing is necessary to deliver the website securely and reliably and to defend against attacks.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a secure, functioning website). Log files are deleted regularly after a short period.
3. Contact by email, phone and messenger
If you contact us by email, phone or via a messenger (WhatsApp, Viber, Threema, Signal), we process the data you provide (name, phone number or email address, messenger ID or username, content of your message) in order to respond to your enquiry.
Legal bases: Art. 6 (1) (b) GDPR (pre-contractual measures or performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in responding to enquiries).
Note on messengers: WhatsApp, Viber, Threema and Signal are third-party services. If you contact us through them, these providers process metadata (including phone number, messenger ID, timestamp) under their own privacy policies. A transfer to third countries (in particular the USA in the case of WhatsApp/Meta) is possible. Threema and Signal offer a higher level of data protection through end-to-end encryption and minimised metadata storage. If you wish to avoid transfers to third countries, please use email, our form, or Threema/Signal.
4. Intro-call form (click flow)
You can request a non-binding videocall via our multi-step form. We process the data you provide (e.g. your project, scope, timeframe, budget range, name, email address and optionally phone number and message) in order to assess your enquiry, prepare a suitable proposal and contact you.
Legal bases: Art. 6 (1) (b) GDPR (pre-contractual measures) and your consent pursuant to Art. 6 (1) (a) GDPR, which you give via the privacy checkbox. You may withdraw your consent at any time with effect for the future.
To protect against automated abuse (spam) we use an invisible honeypot field, a server-side timing and content check, a short-lived signed form token and a limit on requests per sender. The form token is kept exclusively in your browser's memory – no cookies are set for this purpose, no data is transmitted to third parties (e.g. Google reCAPTCHA) and no tracking takes place. Your IP address is stored solely as a non-reversible hash value.
The information is stored in our project database and used exclusively to process your enquiry. No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
5. Appointment booking via Proton Calendar
For booking the 30-minute videocall we use the booking service of Proton Calendar (Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland). The calendar is not embedded in our website: you are only redirected to Proton's pages after clicking the booking link. Until then, no data is transmitted to Proton.
On the booking page, Proton processes the data you enter (name, email address, preferred appointment, optional message) as well as technical connection data (including IP address) under its own responsibility and privacy policy. For Switzerland, an adequacy decision of the European Commission is in place.
Legal basis for scheduling: Art. 6 (1) (b) GDPR (pre-contractual measures at your request) or Art. 6 (1) (f) GDPR (legitimate interest in efficient scheduling).
6. External content and graphics
All graphics and logos displayed on this website – including the logos of the technologies we use – are served exclusively from our own server. No third-party image CDNs, social media plugins, map or video embeds are loaded. Simply visiting the website therefore does not transmit your IP address to any third-party provider.
7. Fonts and assets
All fonts used are served locally from our own server. No connection to Google Fonts or other font CDNs is established.
8. Consent management (cookies & consent)
On your first visit, our website displays a consent banner that lets you control the use of cookies and local storage. Before you actively consent, we only use strictly necessary storage functions (e.g. your language selection and the storage of the consent decision itself). Analytics and marketing cookies are switched off by default (no pre-checking), and declining is just as easy as accepting.
In accordance with Art. 7 (1) GDPR we store your consent verifiably with a timestamp in your browser's local storage. You can withdraw it at any time with effect for the future via the settings panel (available at /cookies#einstellungen); on withdrawal we actively delete known tracking cookies.
Legal basis for storage functions that do not require consent: Art. 6 (1) (f) GDPR (legitimate interest in a functioning website) and Section 25 (2) no. 2 TDDDG. Should analytics or marketing technologies be added in the future, they will only be used on the basis of your consent pursuant to Art. 6 (1) (a) GDPR. Details on the technologies used can be found in our cookie policy.
9. Recipients and processors
For hosting, content delivery (CDN), database and email delivery we use carefully selected service providers that process data exclusively on our behalf and on our instructions (processing pursuant to Art. 28 GDPR).
Categories and providers currently used:
- Hosting, website delivery and edge/CDN: Lovable Labs Incorporated, San Francisco, USA (platform operation) together with Cloudflare, Inc., San Francisco, USA (edge network, delivery via EU locations). Processed data: server log files and connection data.
- Database and backend infrastructure: Lovable Cloud (Lovable Labs Incorporated, San Francisco, USA); data is stored in data centres within the EU. Processed data: the details submitted through the intro-call form.
- Email mailbox and email transport: Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland (mailbox 0030dev@protonmail.com). Processed data: sender details and message content.
- Appointment booking/calendar: Proton AG, Switzerland (Proton Calendar Bookings). Processed data: name, email address and appointment details – only once you actively open the booking link.
- Messenger communication (independent recipients, not processors): WhatsApp Ireland Limited, Ireland (Meta group), Viber Media S.à r.l., Luxembourg, Threema GmbH, Switzerland, and Signal Messenger LLC / Signal Technology Foundation, USA.
9a. Third-country transfers
Where personal data is transferred to a third country (in particular the USA), this takes place on the basis of appropriate safeguards, in particular the EU standard contractual clauses pursuant to Art. 46 (2) (c) GDPR and – where the provider is certified – the EU-US Data Privacy Framework (adequacy decision of 10 July 2023).
For Switzerland (Proton AG) an adequacy decision of the European Commission applies, so no additional safeguards are required. Any changes to the list of processors are maintained in this privacy policy; on request we will send you the current data processing agreements.
10. Retention periods
We store personal data only for as long as necessary for the purposes stated or as required by statutory retention periods (in particular commercial and tax law periods of 6 or 10 years). Enquiries that do not lead to a contractual relationship are deleted no later than 12 months after receipt.
This deletion is automated: a daily system routine permanently removes enquiries older than 12 months from our database. The hashed access identifier stored for spam protection (rate limiting) is deleted after just 7 days, because its purpose is fulfilled by then. On request we of course delete individual enquiries earlier (Art. 17 GDPR).
11. Your rights
- Access to the personal data we process about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
- Complaint to a data protection supervisory authority (Art. 77 GDPR) – the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
12. Security
The website is delivered exclusively over an encrypted TLS connection (HTTPS). We implement technical and organisational measures to protect your data against loss, manipulation and unauthorised access, and continuously adapt them to the state of the art.
13. Changes
We update this privacy policy when website features or the legal situation change. The version published on this page applies.
This is a translation for your convenience. In case of discrepancies, the German version of this document prevails.