Legal

Privacy Policy

Last updated: August 2026

1. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):
happycolorz GmbH
Zeppelinstr. 73, 81669 München, Germany
Managing Director: Mathias Ziegler
Email: hallo@hc-digitalsysteme.de, Phone: +49 89 215 390 58

2. Principles

This website is deliberately built to be data-minimal: no advertising tracking, no marketing cookies, no embedded ad networks. We process personal data only to the extent required to operate the website and handle your enquiries.

3. Hosting (Cloudflare)

This website is delivered via Cloudflare Pages. The provider is Cloudflare Germany GmbH, Rosental 7, 80331 Munich, as the European establishment of Cloudflare, Inc. A data processing agreement under Art. 28 GDPR is in place with Cloudflare. Cloudflare is certified under ISO 27001, ISO 27701 and ISO 27018, among others, and has joined the EU Cloud Code of Conduct.

When you access the website, Cloudflare processes technically necessary access data (in particular IP address, date and time of access, requested URL, user agent, referrer) to deliver the website, ensure stability and defend against attacks. The legal basis is our legitimate interest in secure and performant operation (Art. 6(1)(f) GDPR). We do not combine this data with other data sources.

4. Contact form and contact

If you use our contact form or contact us by email or phone, we process the data you provide (name, company, role, email address, phone number, message content) to handle your enquiry and for follow-up questions. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).

Your enquiry is received via a server function of our hosting provider and forwarded to our email inbox. We delete enquiries once they are conclusively handled and no statutory retention obligations apply.

5. Spam protection

To protect the form against automated abuse we use technical measures (including an invisible honeypot field and, optionally, Cloudflare Turnstile). Turnstile works without advertising tracking; technically necessary data (e.g. IP address, device information) may be transmitted to Cloudflare. The legal basis is our legitimate interest in preventing abusive requests (Art. 6(1)(f) GDPR); storage of or access to device information only occurs to the extent strictly necessary to protect the service (Section 25(2) no. 2 of the German TDDDG).

6. Web analytics

Where used, we employ Cloudflare Web Analytics. The service works without cookies, without fingerprinting and without cross-device tracking, and provides us only with aggregated statistics (e.g. page views, load times). The legal basis is our legitimate interest in measuring reach and improving the offering (Art. 6(1)(f) GDPR).

7. Cookies

This website does not set cookies for advertising or analytics purposes. Details – including technically necessary cookies that security functions may set in individual cases – can be found on the cookie settings page.

8. Recipients and third-country transfers

Recipients of personal data are the processors named in this policy (in particular Cloudflare). Where data is transferred to third countries in this context, this takes place on the basis of adequacy decisions of the EU Commission or EU standard contractual clauses under Art. 46 GDPR.

9. Retention

We process personal data only for as long as necessary for the stated purposes or as required by statutory retention obligations. Server logs are deleted automatically by the hosting provider after a short period.

10. Your rights

  • Access to the data processed (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Complaint to a supervisory authority (Art. 77 GDPR) – the authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany

To exercise your rights, an informal message to hallo@hc-digitalsysteme.de is sufficient.

11. Encryption

All content and form data is transmitted exclusively via TLS encryption (HTTPS).

Note: This privacy policy will be reviewed by legal counsel before the public launch and amended where necessary. The German version is authoritative.