Where are the servers physically?
Ours — in Hetzner data centres in Germany and Finland. Data never leaves the European Union, so you need no additional safeguards for transfers to third countries.
With “cloud” platforms outside the EU you must ask explicitly: where data is stored, where backups are made and whose servers the forms pass through.
Is there a data processing agreement?
Art. 28 of the GDPR requires the controller and the processor to have a written contract with specific content: subject matter, duration, types of data, security obligations, sub-processors. We provide such an agreement (DPA) on request with every hosting package.
If your provider cannot show such a document, that is an answer in itself.
Which cookies and tracking are there?
By default — none. The demos and the portfolio have no cookies, no Google Analytics and no external scripts; that is why they have no consent banner either. If you want analytics, we offer a privacy-first option that needs no consent, or the classic one with a proper banner.
The rule is simple: do not collect what you do not need, and you will have nothing to lose.
Who has access to the server and how?
Access is by SSH key only, no passwords, for a limited circle of people, with fail2ban against automated attempts. System updates are automatic, backups daily, kept for 30 days on a separate server.
These are the concrete measures under Art. 32 (security of processing) that you can also describe in your own record of processing activities.
What happens if you terminate?
You get all code and data as an archive, free of charge, and the site can run anywhere. Data on the server is deleted after your confirmation; backups expire on schedule.
This is not legal advice — for your own records and policies consult a lawyer. We provide the technical part and the documents for it.





