Privacy policy
1. Who is responsible?
This policy explains how personal data is processed when you visit max-fritsch.de or contact me through this website.
Maximilian FritschGrögersweg 12
22307 Hamburg
Germany
Email: max.fritsch@icloud.com
2. Hosting and access data
This website is hosted by ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The hosting provider processes technical data needed to deliver and protect the website, including your IP address, request time, requested URL, response status, data volume, browser information and, where transmitted, the referring page.
The legal basis is Article 6(1)(f) GDPR. The legitimate interests are reliable delivery, troubleshooting and protection against misuse. Technical connection data is needed to respond to your request. The retention of access logs depends on the hosting configuration; the relevant criteria are the period needed to detect and investigate technical faults or security incidents and any applicable legal requirements.
Provider information: ALL-INKL privacy information.
3. Contact form and email
If you contact me, I use your name, email address and message to respond to your enquiry and discuss possible work. These fields are required to send the form; providing them is voluntary, but without them the form cannot submit your enquiry.
For enquiries about a contract with you, the legal basis is Article 6(1)(b) GDPR. For other enquiries, it is Article 6(1)(f) GDPR, based on the legitimate interest in responding to professional correspondence. The form sends an email through the website server. It does not keep a separate database of message contents in WordPress.
Messages arrive in my iCloud Mail mailbox and are processed by Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, and relevant Apple service providers. Processing may take place outside the EEA, including in the United States. Apple describes standard contractual clauses as safeguards for international transfers; details and a way to request a copy are available in Apple’s privacy policy.
Correspondence is kept for as long as needed to handle the enquiry and any resulting working relationship. It is then deleted unless statutory retention obligations or the establishment, exercise or defence of legal claims require further retention. Where such obligations apply, processing is also based on Article 6(1)(c) GDPR. This depends on the nature of the correspondence rather than a single retention period for every message.
4. Protection against spam
The contact form uses a self-hosted ALTCHA security check, a hidden spam-trap field, a request validation token and local rate limits. When you activate the check, your browser solves a short computational task. This website generates and verifies the challenge itself; the CAPTCHA does not contact an external provider, set tracking cookies or collect a behavioural interaction signature. JavaScript is required. If you cannot use the check, you may contact me using the details above. Verification data includes a random challenge identifier, an expiry time and a cryptographic solution. Challenges expire after 20 minutes and can be accepted only once. Used identifiers are retained until expiry and then removed by scheduled WordPress cleanup; they contain no message content. To limit repeated submissions, the server temporarily stores counters linked to keyed hashes of your IP address and email address. These are pseudonymous identifiers, not anonymous data. The raw IP address is not included in the enquiry email.
Counters expire 15 minutes after the last submission counted by the rate limiter. Expired records are removed through WordPress transient cleanup. This processing is based on Article 6(1)(f) GDPR and the legitimate interest in preventing abuse and keeping the contact form available.
5. Fonts, images and videos
DM Sans and Manrope are served locally from this website. Your browser does not contact Google Fonts to display them. Portfolio images and uploaded videos are also served from this website’s hosting. Loading these files involves the technical connection data described above.
Where a project links to an external video service such as YouTube, the link opens that provider’s website only after you select it. External video players are not loaded automatically on this website. Once you follow an external link, that provider’s privacy rules apply.
6. Cookies and tracking
The public portfolio uses Koko Analytics, hosted on this website, to count pageviews and referring websites. It is configured without cookies, local browser storage or fingerprinting and does not recognise returning visitors. Only aggregated pageview statistics are shown; they do not represent a count of distinct people. The browser sends the page path and, if available, the referring URL to this website's server. IP addresses and browser information are technically transmitted with the request, but are not stored in the analytics records or used to create visitor identifiers in this configuration. The data is not sent to an external analytics provider. Statistics are accessible only to authorised administrators and are automatically deleted after 12 months through scheduled cleanup. Signed-in users are excluded. The legal basis for any personal-data processing involved in delivering this measurement is Article 6(1)(f) GDPR, based on the legitimate interest in understanding overall use and improving this portfolio. You may object using the contact details above. No advertising pixels or marketing cookies are used. The contact form’s security check runs locally in your browser and is verified on this website's server. Player controls do not create a persistent visitor profile. The selected language is part of the page address and is not stored in cookies or local browser storage. WordPress may use necessary authentication and security cookies for people signing into the administration area; these are separate from ordinary portfolio browsing.
Where technically necessary storage or access to your device is used for a service you expressly request, the relevant exception is Section 25(2) TDDDG. Any related personal-data processing requires its own GDPR legal basis. No optional tracking service is enabled by this policy.
7. Your rights
Subject to the applicable conditions, you have rights of access, rectification, erasure, restriction of processing and data portability under Articles 15–20 GDPR. If processing is based on consent, you may withdraw it at any time with effect for the future.
Right to object: Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. Processing will then stop unless there are compelling legitimate grounds that override your interests, rights and freedoms, or it is needed for legal claims.
Contact me using the details above to exercise your rights. You may also complain to a supervisory authority, including the authority in your place of habitual residence, workplace or the alleged infringement. The local authority is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.
This website does not use automated decision-making with legal or similarly significant effects or profiling.
8. Updates
This policy reflects the website functions described above. It will need updating if those functions or the services used change.
Last updated: 2 October 2026.